# Human Resources — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/human-resources
> Sources are cited per item. Verify against the official texts before relying on them.

Processing of employee and HR data

## Overview

## Legal Framework

Processing employee and HR data falls squarely within the scope of the GDPR, with Article 6(1)(b) GDPR serving as the primary lawful basis for most employment-related processing—personal data necessary for the performance of a contract to which the data subject is party. Where processing goes beyond what is strictly contractual, Article 6(1)(c) GDPR (compliance with a legal obligation) and Article 6(1)(f) GDPR (legitimate interests) may apply, though the latter requires careful balancing under Article 6(1)(f) and is subject to additional constraints for public authorities under Article 6(1)(f)'s final sentence. Article 9 GDPR governs special categories of data frequently present in HR contexts—sickness records, occupational health data, and disability information—requiring an Article 9(2) condition such as 9(2)(b) (employment and social security law obligations) alongside the Article 6 basis. Member States may further specify these conditions under Article 9(2)(b), making national labor law a critical layer. Articles 15 and 17 GDPR establish employee rights of access and erasure, while Article 32 GDPR imposes security obligations on HR systems.

## Key Developments

The CJEU's ruling in *Schrems I* confirmed that supervisory authorities must independently verify whether transfers of employee data to third countries comply with GDPR requirements—a principle with direct relevance to multinational HR operations. The *Rīgas satiksme* case established a demanding three-part test for legitimate interest processing by public authorities, holding that even where a legitimate interest exists, a public-sector controller may also need a specific legal obligation to lawfully process—narrowing the Article 6(1)(f) avenue for public employers. Dutch enforcement illustrates the operational stakes. The AP fined the Municipality of Ede €25,000 for unlawful processing, and in a separate matter involving ABN AMRO, the AP addressed retention of sickness data after an employee's sick-leave report should have been deleted—highlighting that HR systems must actively purge data when the legal basis expires. A Dutch administrative tribunal further addressed incomplete subject access responses where documents from a legacy HR system were never migrated to the replacement platform (Afas), with the court accepting the controller's explanation but underscoring the evidentiary burden to demonstrate genuine efforts to locate records. The Italian DPA's 2026 fine for post-sick-leave questionnaires signals heightened scrutiny of excessive health-data collection under Article 9 GDPR.

## Practical Guidance

- **Map each HR processing activity to a specific legal basis**: Contractual necessity under Article 6(1)(b) covers payroll and basic personnel administration; sickness and occupational health data require an Article 9(2)(b) condition tied to national employment law, not merely a legitimate interest assessment.

- **Implement deletion protocols for time-limited HR data**: The ABN AMRO matter demonstrates that sickness records lingering in employee files after the relevant period constitutes ongoing unlawful processing—automate retention schedules tied to the expiry of each legal basis.

- **Ensure subject access requests cover legacy systems**: When migrating between HR platforms, either migrate all historical records or maintain searchable archives; controllers bear the burden of proving documents are genuinely unavailable, as the Afas migration case illustrates.

- **Limit health-data questionnaires to what is strictly necessary**: The Italian DPA's fine for post-sick-leave questionnaires establishes that collecting health information beyond what a specific legal obligation requires violates Article 9 GDPR proportionality principles.

- **For public-sector employers, avoid reliance on Article 6(1)(f)**: The *Rīgas satiksme* ruling effectively requires a statutory mandate for processing; public employers should anchor HR processing in specific legislative provisions rather than legitimate-interest balancing tests.

## Legislation (full text of key provisions)

### Recital 111 — regulatory authority resources and expertise

*Source: DSA, dsa-rec-111-en, 2022-10-19 — https://overview.legal/posts/95619*

The Digital Services Coordinator, as well as other competent authorities designated under this Regulation, play a crucial role in ensuring the effectiveness of the rights and obligations laid down in this Regulation and the achievement of its objectives. Accordingly, it is necessary to ensure that those authorities have the necessary means, including financial and human resources, to supervise all the providers of intermediary services falling within their competence, in the interest of all Union citizens. Given the variety of providers of intermediary services and their use of advanced technology in providing their services, it is also essential that the Digital Services Coordinator and the relevant competent authorities are equipped with the necessary number of staff and experts with specialised skills and advanced technical means, and that they autonomously manage financial resources to carry out their tasks. Furthermore, the level of resources should take into account the size, complexity and potential societal impact of the providers of intermediary services falling within their competence, as well as the reach of their services across the Union. This Regulation is without prejudice to the possibility for Member States to establish funding mechanisms based on a supervisory fee charged to providers of intermediary services under national law in compliance with Union law, to the extent that it is levied on providers of intermediary services having their main establishment in the Member State in question, that it is strictly limited to what is necessary and proportionate to cover the costs for the fulfilment of the tasks conferred upon the competent authorities pursuant to this Regulation, with the exclusion of the tasks conferred upon the Commission, and that adequate transparency is ensured regarding the levying and the use of such a supervisory fee.

### Recital 136 — Board operational support and arrangements

*Source: DSA, dsa-rec-136-en, 2022-10-19 — https://overview.legal/posts/95669*

In view of the need to ensure support for the Board’s activities, the Board should be able to rely on the expertise and human resources of the Commission and of the competent national authorities. The specific operational arrangements for the internal functioning of the Board should be further specified in the rules of procedure of the Board.

### Recital 120 — supervisory authority resources and budget

*Source: GDPR, gdpr-rec-120-en, 2016-04-27 — https://overview.legal/posts/91755*

Each supervisory authority should be provided with the financial and human resources, premises and infrastructure necessary for the effective performance of their tasks, including those related to mutual assistance and cooperation with other supervisory authorities throughout the Union. Each supervisory authority should have a separate, public annual budget, which may be part of the overall state or national budget.

### Recital 141 — enhanced ENISA role and increased budget

*Source: NIS2, nis2-rec-141-en, 2022-12-14 — https://overview.legal/posts/96810*

This Directive creates new tasks for ENISA, thereby enhancing its role, and could also result in ENISA being required to carry out its existing tasks under Regulation (EU) 2019/881 to a higher level than before. In order to ensure that ENISA has the necessary financial and human resources to carry out existing and new tasks, as well as to meet any higher level of execution of those tasks resulting from its enhanced role, its budget should be increased accordingly. In addition, in order to ensure the efficient use of resources, ENISA should be given greater flexibility in the way that it is able to allocate resources internally for the purpose of effectively carrying out its tasks and meeting expectations.

### Recital 138 — national AI regulatory sandboxes for innovation

*Source: AI Act, aiact-rec-138-en, 2024-06-12 — https://overview.legal/posts/93958*

AI is a rapidly developing family of technologies that requires regulatory oversight and a safe and controlled space for experimentation, while ensuring responsible innovation and integration of appropriate safeguards and risk mitigation measures. To ensure a legal framework that promotes innovation, is future-proof and resilient to disruption, Member States should ensure that their national competent authorities establish at least one AI regulatory sandbox at national level to facilitate the development and testing of innovative AI systems under strict regulatory oversight before these systems are placed on the market or otherwise put into service. Member States could also fulfil this obligation through participating in already existing regulatory sandboxes or establishing jointly a sandbox with one or more Member States’ competent authorities, insofar as this participation provides equivalent level of national coverage for the participating Member States. AI regulatory sandboxes could be established in physical, digital or hybrid form and may accommodate physical as well as digital products. Establishing authorities should also ensure that the AI regulatory sandboxes have the adequate resources for their functioning, including financial and human resources.

### Recital 101 — Commission supervisory fees very large platforms

*Source: DSA, dsa-rec-101-en, 2022-10-19 — https://overview.legal/posts/95599*

The Commission should be in possession of all the necessary resources, in terms of staffing, expertise, and financial means, for the performance of its tasks under this Regulation. In order to ensure the availability of the resources necessary for the adequate supervision at Union level under this Regulation, and considering that Member States should be entitled to charge providers established in their territory a supervisory fee to in respect of the supervisory and enforcement tasks exercised by their authorities, the Commission should charge a supervisory fee, the level of which should be established on an annual basis, on very large online platforms and very large online search engines. The overall amount of the annual supervisory fee charged should be established on the basis of the overall amount of the costs incurred by the Commission to exercise its supervisory tasks under this Regulation, as reasonably estimated beforehand. Such amount should include costs relating to the exercise of the specific powers and tasks of supervision, investigation, enforcement and monitoring in respect of providers of very large online platforms and of very large online search engines, including costs related to the designation of very large online platforms and of very large online search engines or to the set up, maintenance and operation of the databases envisaged under this Regulation. It should also include costs relating to the set-up, maintenance and operation of the basic information and institutional infrastructure for the cooperation among Digital Services Coordinators, the Board and the Commission, taking into account the fact that in view of their size and reach very large online platforms and very large online search engines have a significant impact on the resources needed to support such infrastructure. The estimation of the overall costs should take into account the supervisory costs incurred in the previous year including, where applicable, those costs exceeding the individual annual supervisory fee charged in the previous year. The external assigned revenues resulting from the annual supervisory fee could be used to finance additional human resources, such as contractual agents and seconded national experts, and other expenditure related to the fulfilment of the tasks entrusted to the Commission by this Regulation. The annual supervisory fee to be charged on providers of very large online platforms and of very large online search engines should be proportionate to the size of the service as reflected by the number of its active recipients of the service in the Union. Moreover, the individual annual supervisory fee should not exceed an overall ceiling for each provider of very large online platforms or of very large online search engines taking into account the economic capacity of the provider of the designated service or services.

### Recital 42 — single electronic point of contact

*Source: DSA, dsa-rec-42-en, 2022-10-19 — https://overview.legal/posts/95481*

In order to facilitate smooth and efficient two-way communications, including, where relevant, by acknowledging the receipt of such communications, relating to matters covered by this Regulation, providers of intermediary services should be required to designate a single electronic point of contact and to publish and update relevant information relating to that point of contact, including the languages to be used in such communications. The electronic point of contact can also be used by trusted flaggers and by professional entities which are under a specific relationship with the provider of intermediary services. In contrast to the legal representative, the electronic point of contact should serve operational purposes and should not be required to have a physical location. Providers of intermediary services can designate the same single point of contact for the requirements of this Regulation as well as for the purposes of other acts of Union law. When specifying the languages of communication, providers of intermediary services are encouraged to ensure that the languages chosen do not in themselves constitute an obstacle to communication. Where necessary, it should be possible for providers of intermediary services and Member States' authorities to reach a separate agreement on the language of communication, or to seek alternative means to overcome the language barrier, including by using all available technological means or internal and external human resources.

### Recital 79 — all-hazards cybersecurity risk management measures

*Source: NIS2, nis2-rec-79-en, 2022-12-14 — https://overview.legal/posts/96686*

As threats to the security of network and information systems can have different origins, cybersecurity risk-management measures should be based on an all-hazards approach, which aims to protect network and information systems and the physical environment of those systems from events such as theft, fire, flood, telecommunication or power failures, or unauthorised physical access and damage to, and interference with, an essential or important entity’s information and information processing facilities, which could compromise the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data or of the services offered by, or accessible via, network and information systems. The cybersecurity risk-management measures should therefore also address the physical and environmental security of network and information systems by including measures to protect such systems from system failures, human error, malicious acts or natural phenomena, in line with European and international standards, such as those included in the ISO/IEC 27000 series. In that regard, essential and important entities should, as part of their cybersecurity risk-management measures, also address human resources security and have in place appropriate access control policies. Those measures should be consistent with Directive (EU) 2022/2557.

## Case law

### CJEU - Case C 312/24 - Darashev

*Source: GDPRhub, 2025-09-04 — https://overview.legal/posts/158443 — original: https://gdprhub.eu/index.php?title=CJEU_-_Case_C_312/24_-_Darashev*

Facts — The data subject is a police officer, holding various positions at the Internal Security directorate-general of the Bulgarian Ministry of the Interior (controller). In March 2016, investigative proceedings were commenced concerning an unknown offender in connection with an offence of theft. A few days later, the data subject was arrested and after being detained in police custody for 24 hours, he was released. Subsequently, he was neither placed under formal investigation nor charged, but he was the subject of several investigative measures, which in the course of 2016, were suspended without the offender having been identified. The controller stored the data about the criminal investigation on his personnel file, as provided by the ministerial instruction relating to personnel files, issued as a regulatory act pursuant to the statutory authorisation provided for in the Law on the Ministry of the Interior (ZMVR). The data subject continued his duties as a police officer and took part in selection procedures for promotion to other posts within the Ministry but he was rejected. The data subject brought an action before the Sofia District Court (Sofiyski rayonen sad) seeking compensation for non-material damage for the fact that he has not been promoted or transferred to other duties on account of his having been a suspect in the investigation. In addition, he asked that his name be erased from the database kept by the controller, in which he is mentioned as a suspect. In this context the court decided to stay the proceedings and to refer some questions to the CJEU for a preliminary ruling, regarding the interplay of the GDPR with the Law Enforcement Directive (LED), and more specifically regarding the storage of data concerning the official in his personnel file. The questions were combined and reformulated by the AG as follows: whether Article 2(1) GDPR and Article 9(1) LED are to be interpreted as meaning that the GDPR applies to the storing, by a public authority in the personnel file of one of its officials, of data regarding that official’s status as a suspect in a criminal investigation, where the data have been collected by an organisational unit within that public authority in the performance of its duties as a competent authority within the meaning of LED. whether Article 17(3) GDPR, read in conjunction with Article 6(1)(c) and Article 6(3) thereof, is to be interpreted as meaning that the storage, in a police officer’s personnel file, of personal data relating to a criminal investigation in which that officer was the subject of investigative measures, as a suspect, and which was discontinued, may be considered lawful for the purposes of compliance with a legal obligation to which the public authority that is his employer is subject under national law, as controller, merely on account of the nature of the duties which that officer is required to perform. Holding — Regarding the first question about the scope of the GDPR, the AG responded positively, that the GDPR does apply in this case, provided that the storage of that data pursues purposes other than those set out in Article 1(1) LED, purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties. Regarding the second question, the AG responded negatively, that the storage of the data subject’s data in this case was not lawful. First, he clarified that within the meaning of Article 6(3) GDPR, the storage of personal data could be based on a legal obligation being defined in a national law other that a law stricto sensu, though in accordance with national constitutional law. Therefore, in this case, the ministerial instruction was considered an appropriate legal basis. Nevertheless, the AG expressed doubts as to the foreseeability of the purposes of the processing, which, in accordance with Article 6(3) GDPR must be determined by the legal basis of the processing. As laid down in the ministerial instruction, the purpose of the storage was for reasons of ‘change of duties’. The AG considered that this, did not appear to meet an objective of public interest, for the purposes of Article 6(3) GDPR. Furthermore, he failed to see how the nature of the duties of maintaining public order, which fall to the data subject, could justify the storage of the data at issue in his personnel file. In conclusion, the AG opined that the storage of the data at issue was not lawful and that the data subject had the right to have them erased, pursuant to Article 17(1)(d) GDPR.

### Judgment of the Court (Eighth Chamber) of 19 December 2024.#MK v K GmbH.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 88(1) and (2) – Processing in the context of employment – Employees’ personal data – More specific rules provided for by a Member State pursuant to that Article 88 – Obligation to comply with Article 5, Article 6

*Source: Court of Justice of the European Union, C-65/23, 2024-12-19 — https://overview.legal/posts/132156 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0065*

In a preliminary ruling requested by the German Federal Labour Court (Bundesarbeitsgericht), the Court of Justice of the European Union interpreted Article 88 of the GDPR regarding Member States' ability to adopt more specific rules for processing employee data in the employment context. The case arose from a dispute between an employee (MK) and his employer (K GmbH) over compensation for non-material damage allegedly caused by the processing of personal data based on a works agreement. The Court held that Article 88 does not grant Member States or social partners a margin of discretion to deviate from the core GDPR requirements of Article 5, Article 6(1), and Article 9, meaning national courts must conduct full judicial review of whether such data processing complies with these fundamental GDPR provisions.

### Data Protection Commissioner v Facebook Ireland and Maximillian Schrems

*Source: CJEU, C-311/18, 2020-07-16 — https://overview.legal/posts/51470 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0311&ref=51470*

Invalidated Privacy Shield adequacy decision and upheld validity of Standard Contractual Clauses with additional safeguards required.

### Data Protection Commissioner v. Facebook Ireland Ltd, and Maximillian Schrems

*Source: CJEU, 2020-07-16 — https://overview.legal/posts/5945 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0311*

“the national supervisory authorities are responsible for monitoring compliance with the EU rules concerning the protection of natural persons with regard to the processing of personal data. Each of those authorities is therefore vested with the power to check whether a transfer of personal data from its own Member State to a third country complies with the requirements laid down in that regulation” / “The exercise of that responsibility is of particular importance where personal data is tra

### Maximillian Schrems v Data Protection Commissioner

*Source: CJEU, C-362/14, 2015-10-06 — https://overview.legal/posts/51471 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0362&ref=51471*

Invalidated Safe Harbor adequacy decision. National supervisory authorities can examine adequacy decisions.

### Judgment of the Court (First Chamber) of 30 March 2023.#Hauptpersonalrat der Lehrerinnen und Lehrer beim Hessischen Kultusministerium v Minister des Hessischen Kultusministeriums.#Request for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 88(1) and (2) – Processing of data in the employment context – Regional school system – Teaching by videoconference due to the COVID-19 pandemic –

*Source: Court of Justice of the European Union, C-34/21, 2023-03-30 — https://overview.legal/posts/132292 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0034*

In Case C-34/21, the Hauptpersonalrat der Lehrerinnen und Lehrer beim Hessischen Kultusministerium challenged the Hessian Ministry of Education's introduction of mandatory videoconference teaching during the COVID-19 pandemic without the express consent of the teachers concerned. The Verwaltungsgericht Wiesbaden referred the matter to the Court of Justice for a preliminary ruling on the interpretation of Article 88(1) and (2) GDPR regarding the processing of employee data in the employment context. The Court held that Member States may authorize employers, including public authorities, to implement such processing under national law providing for suitable safeguards, without requiring the employees' express consent, provided the processing relies on a legal basis other than Article 6(1)(a) GDPR; no fine was imposed.

### Meta Platforms v noyb

*Source: CJEU, C-252/21, 2023-01-12 — https://overview.legal/posts/51484 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0252*

GDPR consent requirements and lead supervisory authority mechanism.

### Korkein hallinto-oikeus (Finland) - KHO:2021:125

*Source: Supreme Administrative Court of Finland, 2021-09-10 — https://overview.legal/posts/122863 — original: https://gdprhub.eu/index.php?title=Korkein_hallinto-oikeus_(Finland)_-_KHO:2021:125*

Facts — The Regional Government of Åland had appointed Mr A as head of the regional Ålandic DPA for a probationary period of one year. Pursuant to section 10(2) of the Act on Public Officials in the Region of Åland, the Government of Åland stated that they would not propose the appointment of A to a permanent post and that A's term of office would therefore automatically come to and end after the one-year probationary period. At the end of the probationary period, the Government of Åland issued a notice confirming that Mr A's term of office had ended. Mr A however applied to the Supreme Administrative Court of Finland for the annulment of this decision, which he considered contrary to the GDPR. Holding — The Supreme Administrative Court considered that the notice issued by the Government of Åland constituted an administrative decision terminating Mr A's mandate. The Supreme Administrative Court found that, in addition to national legislation, A's role as head of the data protection authority is also regulated by EU law, and in particular by the GDPR. Although the GDPR does not contain explicit provisions regarding probationary period, the minimum length of the term of any member of any data protection authority is "no less than four years", as set in Article 54(1)(d) GDPR. As a consequence, the termination of A's mandate at the end of the probationary period could not be considered in line with the GDPR. The Supreme Administrative Court further noted that leaving Mr A without any possibility of appeal against that decision would be contrary to the right to a fair trial as protected under the Finnish Constitution, Article 19 TFEU and Article 47 CFR. As Mr A's mandate and termination had not been assessed in the light of the provisions of the GDPR, the Supreme Administrative Court concluded that the decision to terminate Mr A's mandate had to be annulled and the matter referred back to the Government of Åland for reconsideration.

### Unabhängiges Landeszentrum für Datenschutz v Wirtschaftsakademie Schleswig-Holstein

*Source: CJEU, C-210/16, 2018-06-05 — https://overview.legal/posts/51477 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62016CJ0210&ref=51477*

Facebook fan page administrators are joint controllers with Facebook.

### Data Protection Commissioner v. Schrems and Facebook

*Source: CJEU, 2015-10-06 — https://overview.legal/posts/6144 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0362&ref=6144*

Independence of DPA: The Directive seeks to ensure an effective, complete, and high level of protection of the fundamental rights and freedoms of natural persons. The guarantee of a DPA’s independence is intended to ensure effectiveness and reliability of the monitoring of compliance, and is an essential component of data protection. DPAs powers extend to their own Member State, but not to processing in third countries. However, DPAs are responsible for monitoring transfers from a Member State t

### Judgment of the Court (Third Chamber), 30 May 2013.#Worten — Equipamentos para o Lar SA v Autoridade para as Condições de Trabalho (ACT).#Request for a preliminary ruling from the Tribunal do Trabalho de Viseu.#Processing of personal data — Directive 95/46/EC — Article 2 — Concept of ‘personal data’ — Articles 6 and 7 — Principles relating to data quality and criteria for making data processing legitimate — Article 17 — Security of processing — Working time — Record of working time — Access by t

*Source: Court of Justice of the European Union, C-342/12, 2013-05-30 — https://overview.legal/posts/132375 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62012CJ0342*

The Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from a Portuguese labor court in proceedings between Worten—Equipamentos para o Lar SA and the Autoridade para as Condições de Trabalho (ACT) concerning whether employer working time records constitute personal data under Directive 95/46/EC and must be made available to labor authorities. The Court held that working time records containing information identifying individual workers constitute personal data within the meaning of Article 2 of Directive 95/46/EC, and that employers must maintain such records in a form allowing immediate consultation by competent national authorities responsible for monitoring working conditions, as this processing is necessary for compliance with legal obligations and the performance of tasks carried out in the public interest under Articles 7(c) and 7(e).

### GC - T-318/24

*Source: Gereral Court, T-318/24, 2025-12-03 — https://overview.legal/posts/122878 — original: https://gdprhub.eu/index.php?title=GC_-_T-318/24*

Facts — An applicant (the data subject) participated in several EU staff selection procedures administered by the European Personnel Selection Office (EPSO), acting as controller, and created an EPSO account in the Talent system. After he successfully passed one selection procedure, EPSO also stored his data in its recruitment portal. EPSO managed recruitment through two IT systems, both of which generated access logs, although those logs contained limited technical information regarding the purpose of each access. Between 2022 and 2024, the data subject submitted several requests to EPSO under Article 17 of Regulation (EU) 2018/1725, seeking access to all personal data concerning him. He requested, in particular, full access logs, minutes of meetings, internal and external communications containing his personal data, information on data recipients, and the restoration of personal data deleted after the expiry of retention periods. EPSO stated that certain data did not exist, that it could not restore lawfully deleted data, and that it had already disclosed all available log data. After the data subject lodged a complaint, the European Data Protection Supervisor (EDPS) reconsidered the matter in light of the CJEU’s judgment in Pankki. The EDPS ordered EPSO to provide all available log data relating to consultations of the data subject’s profile. EPSO complied with that order by disclosing the available logs but withheld the identities of individual staff members who had accessed the data. EPSO later rejected further access requests submitted by the data subject. As a result, the data subject brought two actions before the General Court (Cases T-318/24 and T-362/24), seeking the annulment of EPSO’s decisions. The General Court joined the two cases and examined together all the pleas in law raised by the data subject. Holding — The General Court dismissed both actions in their entirety. It held that the controller did not infringe Article 17(1) or (3) of Regulation 2018/1725, as the right of access concerns personal data undergoing processing and not documents as such, nor does it require the controller to restore lawfully deleted data. The Court confirmed that Regulation 2018/1725 contains no obligation for a controller to reinstate personal data once deleted in compliance with applicable retention rules. The Court further held that the controller had no obligation to disclose additional log data, meeting minutes, or communications where it credibly asserted that no such personal data existed. The data subject failed to rebut the presumption of legality attaching to the controller’s statements regarding the non-existence of further data. Moreover , The Court held that access logs constitute personal data to which a data subject is entitled, as they reveal the existence, frequency and purpose of processing. However, employees of a controller acting under its authority are not “recipients” within the meaning of the GDPR or Regulation 2018/1725, and controllers are not required to log or disclose their identities. Disclosure of such identities is only required if strictly necessary for the effective exercise of data protection rights and subject to safeguarding employees’ rights. Since the data subject had already been informed of the purposes and recipients of processing, the absence of staff identities or detailed purposes in the logs did not infringe the right of access. It is not further apparent from the Pankki that Article 15 GDPR requires the controller to set up a logging mechanism containing information on the identity of employees who have carried out consultation operations in respect of the personal data of a person. In addition, the Court found no infringement of the principles of lawfulness, fairness, transparency, accuracy, integrity, confidentiality, or accountability under Article 4 of Regulation 2018/1725. The deletion of the data subject’s data after the expiry of retention periods was lawful and the data subject’s rights to restriction of processing and objection under Articles 20 and 23 were not applicable, as the deletion was based on a legal obligation rather than consent or legitimate interests.

## Guidance

### Statement 6/2024 on the Second Report on the Application of the General Data Protection Regulation - Fostering Cross-Regulatory Consistency and Cooperation

*Source: EDPB, statement-62024-on-the-second-report-on-the-application-of-en, 2024-12-03 — https://overview.legal/posts/125698 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-62024-on-the-second-report-on-the-application-of_en*

1 Statement 6/2024 on the Second Report on the Application of the General Data Protection Regulation - Fostering Cross - Regulatory Consistency and Cooperation Adopted on 3 December 2024 Executive summary The European Data Protection Board welcomes the reports from the European Commission and the Fundamental Rights Agency and takes this opportunity to confirm several ongoing initiatives which would help address some recommendations on cooperation under the GDPR, the future R egulation laying…

### EU-US Data Privacy Framework FAQ for European individuals

*Source: EDPB, eu-us-data-privacy-framework-faq-for-european-individuals-en, 2024-07-16 — https://overview.legal/posts/125730 — original: https://www.edpb.europa.eu/documents/other-guidance/eu-us-data-privacy-framework-faq-for-european-individuals_en*

Adopted EU - U.S. DATA PRIVACY FRAMEWORK F.A.Q. FOR EUROPEAN INDIVIDUALS 1 Adopted on 16 July 2024 1 In this context, European individuals means any natural person, regardless of their nationality, whose personal data have been transferred to a U . S . company under the EU - U . S . Data Privacy Framework . A dopted 2 A dopted 3 Q1. WHAT IS THE EU - U.S. DATA PRIVACY FRAMEWORK? The EU - U.S. Data Privacy Framework (“DPF”) is a self - certification mechanism for companies in the U.S. The…

### EU-US Data Privacy Framework FAQ for European businesses

*Source: EDPB, eu-us-data-privacy-framework-faq-for-european-businesses-en, 2024-07-16 — https://overview.legal/posts/125734 — original: https://www.edpb.europa.eu/documents/other-guidance/eu-us-data-privacy-framework-faq-for-european-businesses_en*

Adopted EU - U.S. DATA PRIVACY FRAMEWORK F.A.Q. FOR EUROPEAN BUSINESSES 1 Adopted on 16 July 2024 1 In this context, European businesses refer to businesses in the EEA, which transfer or may transfer personal data to companies in the U.S. certified under the DPF. Adopted 2 Adopted 3 Q1. WHAT IS THE EU - U.S . DATA PRIVACY F RAMEWORK? The EU - U.S. Data Privacy Framework (“DPF”) is a self - certification mechanism for companies in the U.S. Companies that have self - certified under the DPF must…

### Overview on resources made available by Member States to the Data Protection Authorities and on enforcement actions by the Data Protection Authorities

*Source: EDPB, overview-on-resources-made-available-by-member-states-to-en, 2021-08-11 — https://overview.legal/posts/125988 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/overview-on-resources-made-available-by-member-states-to_en*

1 Overview on resources made available by Member States to the Data Protection Authorities and on enforcement actions by the Data Protection Authorities 05 August 2021 2 Table of co n tent Background ................................ ................................ ................................ ................................ ......... 3 Introduction ................................ ................................ ................................ ................................ ........ 3…

### Opinion 22/2023 on the draft decision of the Belgian Supervisory Authority regarding the Controller Binding Corporate Rules for employee data of the UPS Group

*Source: EDPB, opinion-222023-on-the-draft-decision-of-the-belgian-en, 2023-11-16 — https://overview.legal/posts/125817 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-222023-on-the-draft-decision-of-the-belgian_en*

Adopted Opinion 22/2023 on the draft decision of the Belgian Supervisory Authority regarding the Controller Binding Corporate Rules for employee data of the UPS Group Adopted on 16 November 2023 2 Adopted 3 Adopted The European Data Protection Board Having regard to Article 63, Article 64(1)(f) and Article 47 of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the…

### Opinion 4/2018 on the draft list of the competent supervisory authority of Czech Republic regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-42018-on-the-draft-list-of-the-competent-supervisory-en, 2018-10-03 — https://overview.legal/posts/126288 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-42018-on-the-draft-list-of-the-competent-supervisory_en*

Opinion 4 /2018 on the draft list of the competent supervisory authority of Czech Republic regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 25th September 2018 2 Contents 1. Summary of the Facts ................................ ................................ ................................ ........ 4 2. Assessment ................................ ................................…

### Opinion 14/2018 on the draft list of the competent supervisory authority of Latvia regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-142018-on-the-draft-list-of-the-competent-supervisory-en, 2018-10-03 — https://overview.legal/posts/126270 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-142018-on-the-draft-list-of-the-competent-supervisory_en*

Opinion 14 /2018 on the draft list of the competent supervisory authority of Latvia regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 25th September 2018 2 Contents 1. Summary of the Facts ................................ ................................ ................................ ........ 4 2. Assessment ................................ ................................ ................................…

### Opinion 2/2018 on the draft list of the competent supervisory authority of Belgium regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-22018-on-the-draft-list-of-the-competent-supervisory-en, 2018-10-03 — https://overview.legal/posts/126274 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-22018-on-the-draft-list-of-the-competent-supervisory_en*

Opinion 2 /2018 on the draft list of the competent supervisory authority of Belgium regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 25th September 2018 2 Contents 1. Summary of the Facts ................................ ................................ ................................ ........ 4 2. Assessment ................................ ................................ ................................…

## Enforcement decisions

### HDPA (Greece) - 23/2020

*Source: HDPA (Greece), 2020-07-30 — https://overview.legal/posts/158445 — original: https://gdprhub.eu/index.php?title=HDPA_(Greece)_-_23/2020*

Facts — The data subject filed an application to the Human Resources Directorate of the Hellenic Electricity Distribution Network Operator S.A. [HEDNO S.A.] for the purposes of obtaining an up-to-date certificate of employment that was needed in view of their transfer to another position at the National Centre of Audiovisual Media and Communication S.A. [NCAM S.A.]. The HEDNO S.A. denied the issuing of such a certificate. The company's response to the application focused on the fact that HEDNO S.A. is no longer a legal person of public law, but has been transformed into a legal person of private law (already from the 1st of May of 2012) and its employees' relation to the company is governed by private law and, thus, its employees do not fall under the categories of employees that can be consider for a job post in NCAM S.A. (namely all employees serving either permanently or under an open-ended contract of private law at institutions of the General Government or of the Broader Public Sector or of the Local Authorities of the first or second degree). Therefore, according to the HEDNO S.A. the issuing of any such certificate of employment or the consideration of their employee for such a job post is not in accordance with the legal framework governing the company itself and the employee's relation to it. Eventually, during the consideration of the complaint by the HDPA, the HEDNO S.A. provided the complainant with the requested certificate of employment, an event that was confirmed both by the HEDNO S.A. and by the complainant themselves. Dispute — The HDPA considered the following legal issues; Did the HDPA have the necessary jurisdiction to rule on the complaint under question regarding the possible violation of the data subject's right to access their data based on Article 15 GDPR and the jurisdiction to rule on the issue of the legality of the complainant's candidacy for a job transfer to NCAM S.A.? Was the complainant's right to access their data (Article 15 GDPR) violated by the HEDNO S.A.? Does the issuing on the data subject's request of a certificate regarding personal data based on the record held by the data processor fall within the protection of the data subject's right to access their data under Article 15 GDPR? Holding — The HDPA held that it had the necessary jurisdiction to rule only upon the complaint of the complainant regarding a possible violation of their right to access their data (Article 15 GDPR), and not on the issue of the legality of the complainant's candidacy for a job transfer to NCAM S.A. The HDPA, having taken into account the principles relating to the processing of data (Article 5 GDPR) and having underlined that the data subject's right to access their data is not an absolute right, but a right that is estimated in relation to its function within the society and a right that can be cogitated in relation to other fundamental rights but always on the basis of the principle of proportionality (Article 8(1) CFR, Article 9A Greek Constitution, Recital 64 GDPR), underlined that the GDPR totally respects all fundamental rights and freedoms included in the European Charter of Fundamental Rights and in the [European Union] Conventions. Additionally, the HDPA analysed in detail the content of the data subject's right to access their data and came to highlight that the data subject has the right to know whether their personal data are being processed, the right to access these data without having to prove a special legal interest for doing so, and the right to exercise these rights easily and frequently so as to be informed of the data processing and to be able to verify its legality (Articles 12 & 15 GDPR, Recital 63 GDPR). Furthermore, the HDPA underlined that a certificate of employment contains, on a first basis, personal data referring to a certain employee and, thus, this employee as a data subject has the right to access these data. The HDPA, though, made it clear that issuing a certificate of employment in order to fulfil such an employee's request requires the further processing of the personal data of the employee under question already existing in the data processor's records. Thus, every time an employee requests the issuing of a certificate of employment, they are actually asking the employer/data processor to further process their data in order to create a new document that did not exist in the records up until then. Therefore, the HDPA noted that the refusal to issue a certificate of employment, meaning a document that has not yet been created, cannot constitute the rejection of a data subject's request to access personal data, since the respective legal provisions protect the data subject's right to have knowledge of all the data already existing within the data processor's records at the time of the issuing request and the right to be able to examine the legality of the collection and storing of the data concerned. It was due to the complexity and the greater importance of this issue that the HDPA decided to refer to the HDPA plenary the part of the case concerning the question whether the issuing on the data subject's request of a certificate regarding personal data based on the record held by the data processor falls within the protection of the data subject's right to access their data under Article 15 GDPR, while the HDPA also noted that the subject-matter of the specific complaint of the case was no longer existent, since the HEDNO S.A. did eventually provide the complainant with the requested certificate of employment.

### Austrian DSB rules 360-degree feedback unlawful without specific works agreement

*Source: DSB (Austria), 2026-03-20 — https://overview.legal/posts/187479 — original: https://gdprhub.eu/index.php?title=DSB_(Austria)_-_2025-0.960.016*

Facts — The data subject was employed by an Austrian stock corporation (the controller) from August 2018 to June 2025. They worked as a manager in the controller’s finance department, with technical and disciplinary responsibility for up to five employees. The controller operated a 360-degree feedback process under which the data subject completed a self-assessment and 17 other individuals, including their supervisor, three subordinates and other employees, evaluated their leadership behaviour across 27 categories. Both the data subject and their supervisor had access to the results. The process was also used for other managers within the company. On 1 August 2025, the data subject lodged a complaint with the Austrian DPA, alleging a violation of their right to confidentiality. They argued that the processing carried out as part of the 360-degree feedback process required a specific works agreement and was therefore unlawful in the absence of one. The controller had concluded a framework works agreement with the central works council on the processing of employee data, as well as a supplementary agreement concerning its HR system. However, there was no specific works agreement covering the 360-degree feedback process. The controller alleged that it relied on its legitimate interests under Article 6(1)(f) GDPR and on the performance of the employment contract under Article 6(1)(b) GDPR. It argued that a works agreement would merely specify its legitimate interests and that the absence of such an agreement did not render the processing unlawful. It further maintained that whether a works agreement was required was a labour-law issue that could not be determined in the proceedings before the DPA The data subject responded that the processing of personal data in a 360-degree feedback process served to evaluate employees and therefore constituted a measure within the meaning of § 96 of the Austrian Labour Constitution Act (ArbVG). Section 96 ArbVG lists certain workplace measures that can be introduced only with the works council’s consent through a works agreement. Holding — The DPA first found that the data subject was an employee covered by the Austrian Labour Constitution Act, rather than a senior executive excluded from its scope. It further held that the assessments of the data subject’s leadership behaviour constituted personal data. The DPA explained that Article 88 GDPR enables Member States to adopt, through legislation or collective agreements, more specific rules protecting the rights and freedoms of individuals in the context of employment-related processing. Such rules must include appropriate safeguards for, among other things, human dignity, legitimate interests and the fundamental rights of data subjects. Recital 155 GDPR expressly refers to works agreements as a possible instrument for implementing such rules. It further stated that Austria had made use of the opening clause in Article 88 GDPR and that § 96 ArbVG constituted one of the more specific national rules protecting employees in the context of personal data processing. It determined that the 360-degree feedback process constituted a systematic and standardised assessment of employees falling under both § 96(1)(2) ArbVG, concerning personnel questionnaires, and § 96(1)(3) ArbVG, concerning monitoring measures affecting human dignity. It held that under § 96 ArbVG, the processing therefore required the works council’s consent through a valid works agreement. It pointed out that the controller’s existing works agreements did not cover the 360-degree feedback process or the categories of personal data collected through it. It therefore held that the processing could not be based on a works agreement under Article 88(1) GDPR in conjunction with § 96 ArbVG. The DPA held that the controller could not rely on Article 6(1)(f) GDPR. It stated that although personnel management and improving employee performance might generally constitute legitimate interests, an interest pursued through processing contrary to national law could not be regarded as lawful. It concluded that since the mandatory works council consent had not been obtained, the interest could not be regarded as legitimate under Article 6(1)(f) GDPR. Moreover, it pointed out that Article 6(1)(b) GDPR was also inapplicable because the feedback process was not necessary for the performance of the employment contract. It reasoned that the employment relationship could be performed without it, and the process was not applied to all employees. The DPA therefore found that the processing was unlawful and violated the data subject’s right to confidentiality. It prohibited the controller from continuing the 360-degree feedback process for employees covered by the ArbVG until a valid works agreement was concluded.

### Datatilsynet (Denmark) - 2020-431-0061 (Helsingor decision no. 4)

*Source: Datatilsynet (Denmark), 2022-09-28 — https://overview.legal/posts/6313 — original: https://gdprhub.eu/index.php?title=Datatilsynet_(Denmark)_-_2020-431-0061_(Helsingor_decision_no._4)*

Facts — This is the Danish DPA's fourth decision in the case relating to Helsingor municipality's processing of personal data in primary and lower secondary school. Helsingor municipality, the controller, has been using Google Chromebooks and Workspace for Education in violation of several GDPR requirements, as detailed in the first decision of September 2021, the second decision of 14 July 2022 and the third decision of 18 August 2022. Following the third decision, the municipality submitted more documentation and also requested a consultation with the DPA as per Article 36 GDPR. Holding — The DPA temporarily suspended its processing ban against Helsingor municipality until 5 November 2022, and also ordered the municipality to: Change the data processing agreement with Google so that the DPA's remarks in their 14 July and 18 August decisions, are implemented. This includes, at a minimum, a clarification of where and if Google acts as a sole controller and any uncertainties that may entail that Google acts beyond their role as a processor, see Article 28(3)(a) GDPR. Document that all transfers of personal data to insecure third countries, are in line with the GDPR. Describe all data flows and identify the personal data that are shared with the vendor, and clarify when the vendor acts as a sole or joint controller. This documentation must include the whole technology stack used by the municipality (for this processing activity). Update their data protection impact assessment based on all identified risks. Consult the DPA if the DPIA shows any high risks the municipality is not able to mitigate. If any processing activities are still not in line with the GDPR before the DPA's deadline 3 November 2022, present a final plan for bringing them in line with the GDPR.

### AEPD fines Alkora, S.A. for ransomware breach exposing 40,000 individuals' data

*Source: AEPD (Spain), 2026-07-16 — https://overview.legal/posts/53655 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS-00020-2025*

Facts — Alkora, S.A., the controller, is an insurance broker that was victim of a ransomware attack. The controller notified the DPA of a personal data breach after a ransomware attack affected its servers, databases, email systems and employee devices. The controller first estimated that 25,000 persons were affected. It later stated that the incident had affected around 40,000 persons, including 75 minors. The incident affected confidentiality, availability and integrity. The attacker encrypted systems and exfiltrated between 3.5 and 4 TB of information from the document management server. The affected data included identification and contact data, ID numbers, dates of birth, financial and insurance data, bank account numbers, health data, employee data and access credentials. The controller also processed data relating to minors in accident claims. A data subject complained to the DPA after being informed that their personal data had been exposed. The data subject was concerned about identity theft and requested additional information from the controller. During the investigation, the DPA found that the controller had known that its IT systems faced an extreme cybercrime risk before the breach. The forensic report could not determine the initial entry point because the servers had been encrypted, but it showed that attackers could move laterally through the infrastructure, obtain privileged access, install tools, exfiltrate data and encrypt systems. The controller had carried out a risk analysis in 2019, but this document concluded that no DPIA was necessary. After the breach, a later analysis found that a DPIA was necessary for treatments involving health data and minors. The controller did not prove that it had carried out the required DPIA. Holding — The DPA held that the controller violated Article 5(1)(f) GDPR. It considered that the controller had failed to ensure the integrity and confidentiality of the personal data under its responsibility. The DPA emphasised that the principle in Article 5(1)(f) GDPR is not limited to the existence of isolated security measures. Rather, the controller must implement adequate technical and organisational measures capable of ensuring that personal data is protected against unauthorised or unlawful processing, loss, destruction or damage. The DPA rejected the controller’s argument that the attack was an external criminal act that could not be attributed to it. The DPA found that the controller was aware of an extreme cyber risk and that its internal vulnerabilities and security posture allowed the attackers to move through the systems, access personal data and encrypt files. The DPA therefore considered that the controller’s measures were clearly insufficient. The DPA also held that the controller violated Article 35 GDPR. The controller processed high-risk categories of data, including health data and data concerning minors. In these circumstances, it should have carried out a DPIA before the processing. The DPA found that the controller’s 2019 risk analysis wrongly concluded that no high risk existed, while its later documentation acknowledged that a DPIA was necessary. The DPA proposed a fine of €150,000 for the infringement of Article 5(1)(f) GDPR and €100,000 for the infringement of Article 35 GDPR, totalling €250,000. The controller paid voluntarily without acknowledging liability, obtaining a 20% reduction under Spanish Administrative Law (39/2015). The final payable amount was therefore €200,000. The DPA also ordered the controller, under Article 58(2)(d) GDPR, to prove within three months from the enforceability of the decision that it had carried out the mandatory DPIA required under Article 35 GDPR.

### Persónuvernd examines BL ehf over alleged unlawful employee monitoring via shared OneDrive

*Source: Persónuvernd (Island), 2026-07-01 — https://overview.legal/posts/83499 — original: https://gdprhub.eu/index.php?title=Persónuvernd_(Island)_-_2025010358*

Facts — The data subject was an employee of the enterprise BL ehf (the controller). When she started working there, she was provided with a computer set up by the controller’s IT department. The controller had a Microsoft Office 365 subscription, which included OneDrive and Delve for each employee. OneDrive is a cloud storage service linked to a user account, where files may be stored online rather than only locally. The data subject lodged a complaint with the Icelandic DPA (Persónuvernd) against the controller. She argued that she had been subject to unlawful electronic surveillance during her employment and that colleagues had gained unauthorised access to her computer. According to the data subject, the controller had configured her work computer and the software installed on it in such a way that colleagues and supervisors could monitor her work and view personal data stored on her desktop. She claimed that all of her data was automatically saved to a shared OneDrive of the controller and integrated into Delve. According to the data subject, through Delve her personal data was accessible to her colleagues, including passwords, personal work documents, employee-related documents, payslips and a medical certificate. She also claimed that she had witnessed a colleague opening those documents on the colleague’s own work computer. The controller denied that it had subjected the data subject to electronic surveillance or that the access controls for her file storage areas were inadequate. It argued that OneDrive was a personal file storage area assigned to each employee, that employees could access other employees’ documents only if those documents had been shared with them, and that the data subject’s personal data had been adequately secured through access controls. Holding — The DPA found no evidence that a shared enterprise OneDrive existed to which the data subject’s personal data had been automatically copied or linked. Instead, it found that the relevant OneDrive was the data subject’s personal OneDrive, assigned to her as an employee under the controller’s corporate Microsoft 365 subscription. The DPA also discovered no indication that the data subject’s colleagues or supervisors had access to her OneDrive desktop folder through permissions in the folder’s security settings. Although the “Everyone” group appeared in the list of users or groups in the security settings, the evidence submitted with the complaint did not show that this group had any defined access rights. Nor did the fact that the data subject had access to a colleague’s file prove that the controller’s access controls were defective, since the evidence indicated that employees could grant each other access to files stored in their respective file storage areas. The DPA further held that Delve view counts could not, on their own, prove that unauthorised third parties had viewed the data subject’s documents. The view count was not broken down by user and could include views by the document owner herself. It could therefore only show that the relevant document had been opened a certain number of times by users who had access to it, not that unauthorised access had occurred. The DPA therefore concluded that it was unproven that the controller had carried out electronic monitoring of the data subject or that unauthorised colleagues had accessed personal data stored in her file storage areas. It also held that the controller had ensured appropriate security of the data subject’s personal data through access controls, in accordance with Article 5(1)(f) GDPR, Article 5(2) GDPR and Article 32(1) GDPR.

### Italian DPA: Justice Ministry unlawful disclosure of employee health data in service order

*Source: Garante per la protezione dei dati personali (Italy), 2026-07-20 — https://overview.legal/posts/144019 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_10254256*

Facts — The data subject was an employee at a detention facility run by the Italian Ministry of Justice (the controller). Following an assessment by the occupational health physician, who certified that the data subject was fit for service but had to be exempted from wearing a duty belt and could not hold fixed postures for long periods, the facility issued a service order assigning him to a specific operational unit. The service order referred to the data subject's "physical conditions", his "health needs" and the need for an "alternation of posture". The service order itself provided that a copy would be posted on the institute's noticeboard for publicity purposes. Copies were displayed on the noticeboard located in the bar/canteen area and in the TV/relax area, both accessible to all staff on duty but not to outsiders. Further copies were sent to the head of department, the services office, the coordinator of the records office and the penitentiary police secretariat, as well as to the trade unions, and the document was filed in the official collection of service orders. The data subject filed a complaint with the DPA. During the investigation, the controller argued that the reference to the alternation of posture did not disclose any sensitive data and merely justified the assignment decision to other staff. It also argued that, as an administrative act, the service order had to state the reasons of fact and law behind it under Article 3 of Law 241/1990, that its display and communication to the trade unions followed from transparency rules on administrative acts and from the National Framework Agreement for Penitentiary Police Personnel, and that the data subject had been notified of the order and had not objected at the time. The controller added that the order was replaced on the noticeboard after a short period and that all internal recipients were instructed and authorised to process personal data. Holding — First, the DPA held that the information in the service order constituted health data under Article 4(15) GDPR. The references to the data subject's physical conditions, health needs and the need to alternate his posture related unequivocally to his overall psychophysical state, even without any express diagnosis, and the order had been issued precisely to implement the measures prescribed by the occupational health physician under Article 42 of Legislative Decree 81/2008. The DPA also noted that the reference to the alternation of posture allowed anyone to infer the nature of the data subject's condition. Second, the DPA recalled that an employer may access the fitness-for-duty assessment and the working conditions prescribed by the occupational health physician, but only through staff specifically appointed and authorised to process such data. Making data available to persons who are not authorised to process it, even where they belong to the controller's own organisation, amounts to a communication of personal data that requires a legal basis under Article 2-ter of the Italian Data Protection Code and, for health data, under Article 9 GDPR. The DPA found that the display of the order on a noticeboard accessible to all staff, and its transmission to the trade unions, made the data available to colleagues and third parties who had no need to know it. Access should have been restricted, on strict proportionality grounds, to the staff responsible for actually implementing the measures in the exercise of managerial and organisational functions. Therefore, the DPA found a violation of Articles 5(1)(a), 6 and 9 GDPR and Article 2-ter of the Italian Data Protection Code. Third, the DPA rejected the controller's justification based on the duty to give reasons for an administrative act. The document remained in full in the administration's files and was accessible to anyone demonstrating a direct, concrete and current interest under Articles 22 of Law 241/1990 and Articles 59 and 60 of the Italian Data Protection Code. A generic reference to transparency rules on administrative acts was not sufficient either, since those rules do not provide for disclosure by way of noticeboard display. Fourth, the DPA held that collective agreements cannot constitute an appropriate legal basis for a communication of personal data. Collective agreements may only specify, in favour of employees, a framework already laid down by national legislation and cannot introduce a new processing operation not provided for by law. The DPA added that, even where union prerogatives do entail communications to trade unions, these must comply with the necessity principle and be accompanied by specific safeguards, all the more so where the data concern the most intimate sphere of the person. Finally, the DPA classified the gravity of the violation as medium. It considered that the case concerned a single data subject and that the order remained on the noticeboard for a very short time, but also that the conduct reflected an ordinary practice based on collective agreements. The violation was negligent, as the controller had acted in the mistaken belief that it was complying with the applicable rules. As mitigating factors, the DPA took into account the controller's full cooperation during the investigation and the absence of relevant previous violations at the facility concerned. On these grounds, the DPA fined the controller €12,000.

### UODO (Poland) - DKN.5131.5.2025

*Source: UODO (Poland), 2026-05-25 — https://overview.legal/posts/184680 — original: https://gdprhub.eu/index.php?title=UODO_(Poland)_-_DKN.5131.5.2025*

Facts — A provincial government unit carrying out land consolidation and exchange work (the controller) had entrusted tasks involving the processing of landowners’ (the data subjects’) personal data to a specialised entity established for this purpose (the processor). In January 2023, a work laptop belonging to an employee of the processor was stolen from the trunk of a car parked in a parking garage. This resulted in a breach of confidentiality of the data subjects’ personal data, including names, addresses, ID numbers, and land registry numbers. The controller notified this data breach to the DPA later in January 2023. The DPA conducted an investigation and initiated administrative proceedings regarding the GDPR compliance of the processing operations carried out by the controller and the processor in March 2025. Holding — The DPA issued the controller a fine of PLN 21,000 (€4,900) and the processor a fine of PLN 12,500 (€2,900). First, the DPA held that the controller had violated Articles 24(1), 25(1), 32(1), and 32(2) GDPR by failing to implement appropriate technical and organisational measures to ensure the security of personal data processing – the controller had failed to demonstrate that it had conducted a thorough risk assessment in a manner that would have allowed for the selection of adequate security measures. These infringements resulted in the violations of the principles of integrity, confidentiality and accountability laid down in Articles 5(1)(f) and 5(2) GDPR. Second, the DPA found that the controller had also violated Article 28(1) GDPR: it had failed to verify the adequacy of the technical and organisational measures implemented by the processor. Finally, the DPA came to the conclusion that the processor had infringed Articles 32(1) and 32(2) GDPR in conjunction with Articles 28(3)(c) and 28(3)(f) GDPR. The DPA held that the processor had failed to assist the controller in fulfilling its obligations and contributed to the controller’s GDPR violations. Unlike the controller, the processor had conducted a risk assessment covering the processing operations at issue; however, the processor had not implemented security measures to protect data stored on laptops used outside of its office premises, such as encryption.

### Permanent TSB: Insufficient technical and organisational measures to ensure information security

*Source: Data Protection Authority of Ireland, 2026-05-08 — https://overview.legal/posts/53597 — original: https://www.enforcementtracker.com/ETid-3146*

Data Protection Authority of Ireland fined Permanent TSB €277,500 on 2026-05-08 for: Insufficient technical and organisational measures to ensure information security.

## Recent developments

### Italian SA fines a company for post-sick leave questionnaires

*Source: European Data Protection Board, 2026-06-04 — https://overview.legal/posts/53063 — original: https://www.edpb.europa.eu/news/italian-sa-fines-a-company-for-post-sick-leave-questionnaires_en*

Background informationDate of final decision: 10 July 2025National caseController: Magna PT S.p.A.Legal Reference(s): Article 5 (Principles relating to processing of personal data), Article 6 (Lawfulness of processing), Article 9 (Processing of special categories of personal data), Article 13 (Information to be provided where personal data are collected from the data subject)Decision: Administrative fine, Definitive ban on data processingKey words: Administrative fine, Principles relating to pro

### Article 41 of the GDPR (General Data Protection Regulation).

*Source: GDPRhub, 2026-01-05 — https://overview.legal/posts/51996*

(a) Demonstrable independence and expertise (a) Demonstrable independence and expertise (a) Demonstrable independence and expertise It is clear from Article 41(1) of the GDPR that the supervisory authority must possess a "suitable level of expertise" in the area to which the code of conduct applies, with the aim of ensuring effective compliance. This is also a requirement of the process described in Article 41(2)(a) of the GDPR, according to which the supervisory authority "may be..."

### ICO Publishes Draft Employee Monitoring Guidance for Consultation

*Source: Hunton Andrews Kurth, 2022-10-18 — https://overview.legal/posts/6255 — original: https://www.huntonprivacyblog.com/2022/10/18/uk-ico-publishes-draft-employee-monitoring-guidance-for-consultation/#entry-1081*

> On October 14, 2022, the Federal Trade Commission announced it is extending the deadline by one month to submit comments on its Advanced Notice of Proposed Rulemaking on commercial surveillance and lax data security practices.

### The EU-US Data Privacy Framework: A new era for data transfers?

*Source: IAPP, 2022-10-07 — https://overview.legal/posts/6264 — original: https://iapp.org/news/a/the-eu-u-s-data-privacy-framework-a-new-era-for-data-transfers/#entry-996*

> Legally, until an adequacy determination is granted, companies should continue to follow the European Data Protection Board’s recommendations on measures that supplement transfer tools.
But, once the EU is named as a “qualifying state” (assuming it will be) and complaints can be summited, this should become less daunting. The EDPB recommendations state that companies must “assess if there is anything in the law or practice of the third country that may impinge on the effectiveness of the appro

### EU-US Privacy Framework needs a long hard look

*Source: EURactiv, 2022-10-14 — https://overview.legal/posts/6256 — original: https://www.euractiv.com/section/data-protection/opinion/eu-us-privacy-framework-needs-a-long-hard-look/#entry-1054*

The Commission has endorsed enthusiastically a recent US order to implement a new framework to protect the privacy of personal data shared between the US and Europe. Dick Roche begs to differ.

https://iapp.org/news/a/the-redress-mechanism-in-the-privacy-shield-successor-on-the-independence-and-effective-powers-of-the-dprc/

## Literature

### Building data management capabilities to address data protection regulations: Learnings from EU-GDPR

*Source: Journal of Information Technology, 2023-01-19 — https://overview.legal/posts/132524 — original: https://doi.org/10.1177/02683962221141456*

The European Union’s General Data Protection Regulation (EU-GDPR) has initiated a paradigm shift in data protection toward greater choice and sovereignty for individuals and more accountability for organizations. Its strict rules have inspired data protection regulations in other parts of the world. However, many organizations are facing difficulty complying with the EU-GDPR: these new types of data protection regulations cannot be addressed by an adaptation of contractual frameworks, but requir

### Collective Damages for GDPR Breaches: A Feasible solution for the GDPR Enforcement Deficit?

*Source: European Data Protection Law Review, 2022-01-01 — https://overview.legal/posts/132504 — original: https://doi.org/10.21552/edpl/2022/4/8*

### General Data Protection Regulation (GDPR) ambiguity, national diversity and data protection officer certification: Implementing Art. 39(1) GDPR in France, Italy, Luxembourg and Spain

*Source: Journal of Data Protection Privacy, 2021-09-01 — https://overview.legal/posts/132409 — original: https://doi.org/10.69554/uukl8163*

The General Data Protection Regulation (GDPR) of the European Union (EU) does not always make legally binding provisions with unambiguous implications. The implementation of Art. 39(1) GDPR regarding the certification of Data Protection Officers (DPOs) is left to the discretion of Member States. This paper will show what action has been taken by the national data protection authorities (DPAs) of France, Italy, Luxembourg and Spain. Insights gained from examining the four national frameworks, whi

### GDPR Implementation Series ∙ Malta: An Overview of the GDPR Implementation

*Source: European Data Protection Law Review, 2020-01-01 — https://overview.legal/posts/132480 — original: https://doi.org/10.21552/edpl/2020/4/15*

### GDPR Implementation Series ∙ Romania: Overview of the GDPR Implementation

*Source: European Data Protection Law Review, 2018-01-01 — https://overview.legal/posts/132479 — original: https://doi.org/10.21552/edpl/2018/3/16*

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Law Enforcement** — https://overview.legal/topics/law-enforcement
  Processing for law enforcement purposes
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **IP Address** — https://overview.legal/topics/ip-adres
  Internet protocol addresses as personal data
- **Public Authority** — https://overview.legal/topics/overheid
  Government bodies and their data processing activities
- **Scientific Research** — https://overview.legal/topics/scientific-research
  Processing for scientific research purposes

---
Generated by overview.legal · https://overview.legal/topics/human-resources · 2026-08-22
