# Identification — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/identificatie
> Sources are cited per item. Verify against the official texts before relying on them.

Methods and processes for identifying individuals

## Overview

## Legal Framework

Identification sits at the heart of the GDPR's scope. [Article 4(1)](/laws/gdpr/art-4#par-1) defines "personal data" by reference to whether a natural person is identified or identifiable, directly or indirectly, through identifiers such as a name, identification number, location data, or online identifier. This definitional threshold determines whether the Regulation applies at all. Once data qualifies as personal, [Article 5(1)(e)](/laws/gdpr/art-5#par-1-pnt-e) imposes a temporal constraint: data may be kept in a form permitting identification only as long as necessary for the processing purpose.

> "an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person"
> — [GDPR Art. 4(1)](/laws/gdpr/art-4#par-1)

[Article 11](/laws/gdpr/art-11#par-1) provides a narrow relief valve: where the controller's purposes do not require identification, the controller need not acquire additional information solely to comply with GDPR obligations. However, data subject rights under Articles 15–20 remain exercisable if the individual provides supplementary information enabling identification.

## Key Developments

The CJEU's ruling in *Breyer* established the controlling test for indirect identifiability. The Court held that a dynamic IP address constitutes personal data for a website operator if that operator has legal means enabling it to identify the user through third parties. The threshold turns on whether identification is legally permissible and practically feasible:

> "that would not be the case if the identification of the data subject was prohibited by law or practically impossible on account of the fact that it requires a disproportionate effort in terms of time, cost and man-power, so that the risk of identification appears in reality to be insignificant."
> — [Breyer ¶46](/posts/6143#seg-46)

Crucially, the Court in *Breyer* clarified that the mere existence of legal channels — even indirect ones, such as contacting authorities who can compel an ISP to disclose subscriber data — suffices to render data personal:

> "in the event of cyber attacks legal channels exist so that the online media services provider is able to contact the competent authority, so that the latter can take the steps necessary to obtain that information from the internet service provider"
> — [Breyer ¶47](/posts/6143#seg-47)

Earlier, *Rijkeboer* confirmed that storage limitation under Article 5(1)(e) requires controllers to fix time limits calibrated to the period during which identification remains necessary for the stated purpose. *Rynes* reinforced the broad scope of "personal data," covering information relating to physical identity and any factor specific to the individual.

## Status of the Debate

This topic is actively contested in court. The core fault line concerns the boundary of indirect identifiability — specifically, how to weigh the theoretical availability of legal channels against practical impossibility. *Breyer* adopted a relatively expansive reading, treating the existence of legal pathways to identification as sufficient, even where the controller itself cannot directly access the linking data. National courts and DPAs continue to grapple with applying this standard to new contexts such as pseudonymised datasets, hashed identifiers, and biometric templates. What would resolve the open question is further CJEU guidance on whether the "disproportionate effort" test should account for the controller's own operational capacity or only objective legal and technical constraints — a distinction *Breyer* left ambiguous.

## Practical Guidance

- **Assess identifiability contextually, not abstractly.** Determine whether your organisation, alone or through lawful channels involving third parties, can link data to an individual. The *Breyer* standard looks at legal possibility, not just technical ease.
- **Document the identification analysis.** [Article 30(1)](/laws/gdpr/art-30#par-1-pnt-e) records must reflect whether transfers involve data that permits identification, and [Article 11(2)](/laws/gdpr/art-11#par-2) requires informing data subjects when you claim inability to identify them.
- **Apply storage limitation by purpose.** Under [Article 5(1)(e)](/laws/gdpr/art-5#par-1-pnt-e), set and document erasure time limits tied to when identification ceases to be necessary for each processing purpose, following *Rijkeboer*.
- **Re-evaluate when circumstances change.** If new legal channels, technical capabilities, or additional data sources emerge that make identification feasible, data previously treated as non-personal may cross the threshold — triggering GDPR obligations retroactively.
- **Use pseudonymisation as a risk mitigant, not an exemption.** [Article 4(5)](/laws/gdpr/art-4#par-5) defines pseudonymised data as still personal where additional information exists that could re-identify the subject; it reduces risk but does not remove the data from the GDPR's scope.

## Legislation (full text of key provisions)

### Processing which does not require identification

*Source: GDPR, gdpr-art-11-en, 2016-04-27 — https://overview.legal/posts/90324*

### Processing of the national identification number

*Source: GDPR, gdpr-art-87-en, 2016-04-27 — https://overview.legal/posts/91433*

Member States may further determine the specific conditions for the processing of a national identification number or any other identifier of general application. In that case the national identification number or any other identifier of general application shall be used only under appropriate safeguards for the rights and freedoms of the data subject pursuant to this Regulation.

### Presentation and restriction of calling and connected line identification

*Source: ePrivacy, eprivacy-art-8-en, 2002-07-12 — https://overview.legal/posts/132191*

### Identification numbers and lists of notified bodies

*Source: AI Act, aiact-art-35-en, 2024-06-12 — https://overview.legal/posts/92528*

### Exceptions

*Source: ePrivacy, eprivacy-art-10-en, 2002-07-12 — https://overview.legal/posts/132202*

ExceptionsMember States shall ensure that there are transparent procedures governing the way in which a provider of a public communications network and/or a publicly available electronic communications service may override:the elimination of the presentation of calling line identification, on a temporary basis, upon application of a subscriber requesting the tracing of malicious or nuisance calls. In this case, in accordance with national law, the data containing the identification of the calling subscriber will be stored and be made available by the provider of a public communications network and/or publicly available electronic communications service;the elimination of the presentation of calling line identification and the temporary denial or absence of consent of a subscriber or user for the processing of location data, on a per-line basis for organisations dealing with emergency calls and recognised as such by a Member State, including law enforcement agencies, ambulance services and fire brigades, for the purpose of responding to such calls.

### Services concerned

*Source: ePrivacy, eprivacy-art-3-en, 2002-07-12 — https://overview.legal/posts/132170*

Services concernedThis Directive shall apply to the processing of personal data in connection with the provision of publicly available electronic communications services in public communications networks in the Community, including public communications networks supporting data collection and identification devices.

### Definitions

*Source: ePrivacy, eprivacy-art-2-en, 2002-07-12 — https://overview.legal/posts/132169*

DefinitionsSave as otherwise provided, the definitions in Directive 95/46/EC and in Directive 2002/21/EC of the European Parliament and of the Council of 7 March 2002 on a common regulatory framework for electronic communications networks and services (Framework Directive) ( 8 ) shall apply.The following definitions shall also apply:‘user’ means any natural person using a publicly available electronic communications service, for private or business purposes, without necessarily having subscribed to this service;‘traffic data’ means any data processed for the purpose of the conveyance of a communication on an electronic communications network or for the billing thereof; ▼M2 ‘location data’ means any data processed in an electronic communications network or by an electronic communications service, indicating the geographic position of the terminal equipment of a user of a publicly available electronic communications service; ▼B ‘communication’ means any information exchanged or conveyed between a finite number of parties by means of a publicly available electronic communications service. This does not include any information conveyed as part of a broadcasting service to the public over an electronic communications network except to the extent that the information can be related to the identifiable subscriber or user receiving the information; ▼M2 ————— ▼B ‘consent’ by a user or subscriber corresponds to the data subject's consent in Directive 95/46/EC;‘value added service’ means any service which requires the processing of traffic data or location data other than traffic data beyond what is necessary for the transmission of a communication or the billing thereof;‘electronic mail’ means any text, voice, sound or image message sent over a public communications network which can be stored in the network or in the recipient's terminal equipment until it is collected by the recipient; ▼M2 ‘personal data breach’ means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed in connection with the provision of a publicly available electronic communications service in the Community.

### Recital 15 — biometric identification definition

*Source: AI Act, aiact-rec-15-en, 2024-06-12 — https://overview.legal/posts/93712*

The notion of ‘biometric identification’ referred to in this Regulation should be defined as the automated recognition of physical, physiological and behavioural human features such as the face, eye movement, body shape, voice, prosody, gait, posture, heart rate, blood pressure, odour, keystrokes characteristics, for the purpose of establishing an individual’s identity by comparing biometric data of that individual to stored biometric data of individuals in a reference database, irrespective of whether the individual has given its consent or not. This excludes AI systems intended to be used for biometric verification, which includes authentication, whose sole purpose is to confirm that a specific natural person is the person he or she claims to be and to confirm the identity of a natural person for the sole purpose of having access to a service, unlocking a device or having security access to premises.

### Recital 17 — remote biometric identification system definition

*Source: AI Act, aiact-rec-17-en, 2024-06-12 — https://overview.legal/posts/93716*

The notion of ‘remote biometric identification system’ referred to in this Regulation should be defined functionally, as an AI system intended for the identification of natural persons without their active involvement, typically at a distance, through the comparison of a person’s biometric data with the biometric data contained in a reference database, irrespectively of the particular technology, processes or types of biometric data used. Such remote biometric identification systems are typically used to perceive multiple persons or their behaviour simultaneously in order to facilitate significantly the identification of natural persons without their active involvement. This excludes AI systems intended to be used for biometric verification, which includes authentication, the sole purpose of which is to confirm that a specific natural person is the person he or she claims to be and to confirm the identity of a natural person for the sole purpose of having access to a service, unlocking a device or having security access to premises. That exclusion is justified by the fact that such systems are likely to have a minor impact on fundamental rights of natural persons compared to the remote biometric identification systems which may be used for the processing of the biometric data of a large number of persons without their active involvement. In the case of ‘real-time’ systems, the capturing of the biometric data, the comparison and the identification occur all instantaneously, near-instantaneously or in any event without a significant delay. In this regard, there should be no scope for circumventing the rules of this Regulation on the ‘real-time’ use of the AI systems concerned by providing for minor delays. ‘Real-time’ systems involve the use of ‘live’ or ‘near-live’ material, such as video footage, generated by a camera or other device with similar functionality. In the case of ‘post’ systems, in contrast, the biometric data has already been captured and the comparison and identification occur only after a significant delay. This involves material, such as pictures or video footage generated by closed circuit television cameras or private devices, which has been generated before the use of the system in respect of the natural persons concerned.

### Recital 34 — responsible use of real-time biometric identification

*Source: AI Act, aiact-rec-34-en, 2024-06-12 — https://overview.legal/posts/93750*

In order to ensure that those systems are used in a responsible and proportionate manner, it is also important to establish that, in each of those exhaustively listed and narrowly defined situations, certain elements should be taken into account, in particular as regards the nature of the situation giving rise to the request and the consequences of the use for the rights and freedoms of all persons concerned and the safeguards and conditions provided for with the use. In addition, the use of ‘real-time’ remote biometric identification systems in publicly accessible spaces for the purpose of law enforcement should be deployed only to confirm the specifically targeted individual’s identity and should be limited to what is strictly necessary concerning the period of time, as well as the geographic and personal scope, having regard in particular to the evidence or indications regarding the threats, the victims or perpetrator. The use of the real-time remote biometric identification system in publicly accessible spaces should be authorised only if the relevant law enforcement authority has completed a fundamental rights impact assessment and, unless provided otherwise in this Regulation, has registered the system in the database as set out in this Regulation. The reference database of persons should be appropriate for each use case in each of the situations mentioned above.

## Case law

### Amsterdam Court of Appeal: Controller may reject watermarked ID copy for verification

*Source: Court of Appeal Amsterdam, 2024-04-30 — https://overview.legal/posts/125642 — original: https://gdprhub.eu/index.php?title=GHAMS_-_200.324.736/01*

Facts — The data subject had a business credit card issued by the controller. In 2021, the controller asked the data subject to identify themselves online by taking a picture of the ID and then taking a selfie of themselves. The data subject wanted to upload a copy of the ID with a watermark on it for fraud prevention purposes (saying, for example: “copy for [the controller]”). The controller, on the other hand, rejected this copy, arguing that the data subject should upload a copy without any writing on it. Therefore, the data subject brought legal proceedings before the District Court of Amsterdam (Rechtbank Amsterdam - Rb. Amsterdam), seeking the court to declare that the controller cannot request an ID copy without the watermark and that the controller should not block the credit card. On 20 April 2022, the District Court of Amsterdam dismissed the data subject’s request. The data subject appealed the decision before the Court of Appeal of Amsterdam (Gerechtshof Amsterdam - GHAMS). They argued that the provisions of the Money Laundering and Terrorist Financing Prevention Act (Wet ter voorkoming van witwassen en financieren van terrorisme – Wwft) do not require that the identification process is performed in the way envisaged by the controller. Therefore, the legal basis provided for by Article 6(1)(c) GDPR cannot be used, since there is no legal obligation to require this kind of identification. Moreover, they argued that the controller should not store the copy of the ID. The controller pointed out that the electronic technique used in the scanning of the ID has currently the highest reliability in the field of authentication and that the use of this technique enables it to recognize high value forgeries of IDs better than with the use of persons trained and educated for this purpose. Holding — First of all, the court noted that the Wwft does not prescribe a way in which the identification should be conducted. Moreover, it pointed out that neither the GDPR nor the Wwft confer the data subject a right to a non-online identification. Secondly, the court noted that Article 13(1)(a) Directive 2015/849 allows the controller to perform the identification through electronic means. Thirdly, the court agreed with the controller’s argument. It held that, since there is an added value in using this ID scanning tool, this use may be considered necessary within the meaning of Article 6(1)(c) GDPR in order to comply with its obligation to conduct a customer due diligence under the Wwft. The court pointed out that, due to the large amount of customers, the controller has a legitimate interest in organizing the identification and verification procedure as uniformly as possible. Fourthly, as for the retention issue, the court noted that the controller is obliged to keep a copy of the proof of identity whose authenticity it has verified by means of the scan pursuant to Article 33(1) Wwft. However, the court highlighted that the controller is obliged to store this data securely. Therefore, the court dismissed the appeal and upheld the judgement of the District Court of Amsterdam.

### Judgment of the Court (Full Court) of 30 April 2024.#La Quadrature du Net and Others v Premier ministre and Ministère de la Culture.#Request for a preliminary ruling from the Conseil d'État (France).#Reference for a preliminary ruling – Processing of personal data and the protection of privacy in the electronic communications sector – Directive 2002/58/EC – Confidentiality of electronic communications – Protection – Article 5 and Article 15(1) – Charter of Fundamental Rights of the European Unio

*Source: Court of Justice of the European Union, C-470/21, 2024-04-30 — https://overview.legal/posts/132259 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0470*

In Case C-470/21, the CJEU addressed a preliminary reference from the French Conseil d'État concerning La Quadrature du Net and others v. Premier ministre and Ministre de la Culture, which challenged France's "graduated response" system allowing public authorities to access civil identity data associated with IP addresses retained by ISPs for the purpose of combating online copyright infringement. The Court ruled that while such access may be justified under Article 15(1) of Directive 2002/58/EC (the ePrivacy Directive) for intellectual property protection, it requires strict safeguards including prior review by a court or independent administrative body, and must be limited to what is strictly necessary, proportional, and subject to substantive and procedural protections against abuse. No fine was imposed as this was a preliminary ruling.

### Judgment of the Court (Grand Chamber) of 21 March 2024.#RL v Landeshauptstadt Wiesbaden.#Request for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Regulation (EU) 2019/1157 – Strengthening the security of identity cards of EU citizens – Validity – Legal basis – Article 21(2) TFEU – Article 77(3) TFEU – Regulation (EU) 2019/1157 – Article 3(5) – Obligation for Member States to include two fingerprints in interoperable digital formats in the stora

*Source: Court of Justice of the European Union, C-61/22, 2024-03-21 — https://overview.legal/posts/132266 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0061*

The Court of Justice of the European Union (Grand Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden in proceedings between RL and the Landeshauptstadt Wiesbaden concerning RL's request for an identity card without fingerprints, which the city rejected. The core issue was the validity of Regulation (EU) 2019/1157, particularly Article 3(5), which obliges Member States to include two fingerprints in the storage medium of EU citizens' identity cards, and whether the regulation was validly adopted under Articles 21(2) and 77(3) TFEU and complies with Articles 7 and 8 of the Charter of Fundamental Rights. The Court upheld the regulation's validity, finding the legal basis appropriate and the fingerprint storage requirement a proportionate interference with fundamental rights that is justified by the objective of strengthening identity document security and preventing fraud, while also clarifying Member States' obligation to conduct data protection impact assessments under Article 35 of GDPR for the national implementing measures.

### CJEU - C-205/21 - Ministerstvo na vatreshnite raboti

*Source: GDPRhub, 2023-01-26 — https://overview.legal/posts/158437 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-205/21_-_Ministerstvo_na_vatreshnite_raboti*

Facts — A data subject was accused of a criminal offence and refused to consent to the collection of her genetic and biometric data (Photographs and fingerprints), which the Bulgarian Police required to create a record. The data subject also refused to let the police take a sample for the purpose of creating a DNA profile. In the end, the police did not collect this data. The police went to a Bulgarian Criminal court (Spetsializiran nakazatelen sad), which was also the referring court in this case. Here, the police asked the court to authorise the forced collection of the genetic and biometric data, considering there was enough evidence to convict the data subject of the crime. The police position was mostly based on Bulgatian law (ZMVR, Law of the ministry of Home affairs) authorising the collection of biometric and genetic data for, among the others, law and order purposes. However, the referring court had doubts whether the such law was actually compliant with EU law. This Bulgarian law did refer to Article 9 GDPR, but did not refer to EU directive 2016/680. The latter is an EU directive which concerns the protection of personal data regarding processing of competent authorities for the purposes of prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties. This directive states that the processing of certain special category data, including genetic and biometric data, can be lawful if this is compliant with EU law or national law. The Bulgarian law had even taken over some of the wording from Article 10(a) of this directive for its national provision. The court determined that there were two problems resulting from the fact that this national law contained a reference to the GDPR, but did not mention the aforementioned directive. The first problem was the fact that the GDPR was not applicable to the processing of personal data with regard to criminal investigations, pursuant to Article 2(2)(d) GDPR. The second problem was the fact that Article 9 GDPR prohibited the processing of genetic and biometric data. The court also reiterated that a law enforcement purpose could not fall under one of the exceptions under Article 9(2) GDPR. The referring court referred several questions to the CJEU. The main issue was to know whether the processing of genetic and biometric data for purposes of criminal investigations in this case was permissible under the national law, despite the mention of Article 9 GDPR, and despite the fact that EU directive 2016/680 was not mentioned in the national law. Holding — First, The CJEU determined that both Article 9 GDPR and Article 10 of the directive contain provisions regarding the processing of special categories of personal data, including biometric en genetic data. Second, The CJEU determined that processing of biometric and genetic data by the police authorities could be permissible, as long as this processing fell under Article 10(a) of the directive. This meant that the processing had to be strictly necessary, with adequate safeguards and was provided for in national / EU law, pursuant to Article 52 CFR. However, it could still be unlawful to process this data, when this processing also fell within the scope of the GDPR. Third, The court stated that the requirement of authorised by Union or Member State' law in Article 10a of the directive must be interpreted pursuant to Article 52(1) CFR, which states that any limitation on the exercise of a fundamental right "must be ‘provided for by law". The legal basis which is used for this limitation (in this case, the legal basis was the Bulgarian law), must define the scope of the limitation sufficiently clearly and precisely. This meant that there should not be any uncertainty about the laws concerning - or the conditions of the processing of genetic and biometric data. However, The CJEU also noted that these conditions of processing could vary between the GDPR and the directive. In this context, The CJEU determined that the member states were free to organise their processing operations under either the GDPR or the aforementioned directive. However, member states would have to make sure that there would be no uncertainty about the fact which law would be applicable to different kinds of processing of biometric/genetic data. Fourth, The court also determined that member states were not obligated to cite the directive in the national law itself when they were transposing this directive into national law. It was therefore not necessary for the Bulgarian legislature to mention directive 2016/680 in its transposed national provisions. Fifth, the CJEU noted that national courts had the obligation to explain the national law. For this explanation, the national court had to consider the wording of the directive and the context of the directive. This was an obligation pursuant to Article 288 TFEU, which was applicable to all public bodies of a member state, including national courts. In the present case, where there was an obvious conflict between the GDPR and the directive, the national court had to provide an explanation which would keep the useful working of the directive intact. The CJEU stated that it was up to the national court to determine if the reference to Article 9 GDPR in the Bulgarian law was even correct. The court concluded that it was up to the national court to assess the case. In summary, the Court noted that the processing of the biometric and genetic data by the police could be lawful in this case if it fell under Article 10(a) of the directive. Also, the national implementation of the directive needed to have a sufficiently clear and precise legal basis for the processing of biometric/genetic data by the Bulgarian police. The fact that Article 9 GDPR was mentioned in this law was of no consequence for the legality of this processing, nor was the fact that the directive was not mentioned in the national implementation. However, the explanation by the national court of this Bulgarian law had to be sufficiently precise and clear. Also, this explanation of the national court should state in an unequivocal manner whether certain processing of biometric and genetic data would fall under the directive, or would fall under the GDPR.

### Judgment of the Court (Fifth Chamber) of 26 January 2023.#Criminal proceedings against V.S.#Request for a preliminary ruling from the Spetsializiran nakazatelen sad.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Directive (EU) 2016/680 – Article 4(1)(a) to (c) – Principles relating to processing of personal data – Purpose limitation – Data minimisation – Article 6(a) – Clear distinction between personal data of different categ

*Source: Court of Justice of the European Union, C-205/21, 2023-01-26 — https://overview.legal/posts/132297 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0205*

In Case C-205/21, the Court of Justice of the European Union (Fifth Chamber) issued a preliminary ruling responding to a request from the Spetsializiran nakazatelen sad (Specialised Criminal Court, Bulgaria) in criminal proceedings against V.S., who refused to consent to the collection of her biometric and genetic data by police. The Court interpreted Directive (EU) 2016/680, addressing the principles of purpose limitation and data minimisation, the lawful processing of biometric and genetic data under Member State law, the concept of "strictly necessary," and the requirement to maintain a clear distinction between personal data of different categories of data subjects in light of Articles 7, 8, 47, 48, and 52 of the EU Charter of Fundamental Rights. No fine was imposed, as the ruling solely provides interpretive guidance on the compatibility of coercive data collection from accused persons with EU data protection law.

### CE - 439360

*Source: CE, 2021-04-13 — https://overview.legal/posts/125663 — original: https://gdprhub.eu/index.php?title=CE_-_439360*

Facts — In February 2020 the French minister of the interior enacted the Decree No. 2020-151 of 20 February 2020 authorising the automated processing of personal data known as "mobile note-taking application" (Décret n° 2020-151 du 20 février 2020 portant autorisation d'un traitement automatisé de données à caractère personnel dénommé «application mobile de prise de notes» (GendNotes)). The app should be used on the occasion of preventive actions, investigations or interventions necessary for the exercise of judicial or administrative police missions. Among the data that can be collected is information relating to alleged racial or ethnic origin, political, philosophical or religious opinions, trade union membership, health or sexual activities or orientation. A group of human rights organisations filed a complaint with the French Constitutional Court. Dispute — Is the "GendNotes" App of the French national police force (Gendarmerie nationale) unlawfully processing special category personal data? Holding — The French Highest Administrative Court held that the decree infringed Article 4 of the Law of 6 January 1978, implementing GDPR in France, the Council of Europe Convention No. 108 for the Protection of Individuals with regard to Automatic Processing of Personal Data and Article 8 CFR, as it excessively infringed upon the right to respect for private life and the correlative right to protection of personal data, without providing appropriate safeguards for their protection in terms of the purpose of the processing and the nature of the data collected, as well as excessive data retention period, data sharing and data security. The Court discussed whether the decree violated Article 4 (a) GDPR, Article 4 (b) GDPR, Article 4 (c) GDPR, and Article 4 (e) GDPR and Article 9 GDPR. According to the Court, the processing of data did not comply with the principle of purpose limitation, as data is collected for future investigations or proceedings. However, the Court did not find a violation on the collect of special category data, given the fact that the decree establishes that this data can only be processed in case of "absolute necessity". Additionally, the Court noted that, even if the decree provides a limitation for the storage of the data, in practice this can be ignored, as the data may be used in different or further investigations, that would impede its erasure. However, they found that the decree was lawful in this regard, given that it clearly stated a retention period of 3 months to 1 year. Taken the above-mentioned into account, the French Highest Administrative Court decided that the data processed by the French national police force can no longer be used "in other data processing, in particular by means of a pre-information system". Therefore, the Court held: In Article 1° of the decree, the words "in other data processing, in particular by means of a pre-information system," are cancelled out. The State will pay €3,000 to every claimant. The rest of the application is rejected. The allowance to collect special category data is not overruled, as the Court argues that the decree only allows it when it is "absolutely necessary". This decision will be notified to the claimants: the Ligue des droits de l'homme, the associations Homosexualités et socialismes and Internet Society France, the associations Mousse, Stop Homophobie, Adheos and Familles A, the association AIDES, the Syndicat de la magistrature, the Syndicat des avocats de France, the Conseil national des barreaux, the Quadrature du Net and the International League against Racism and Anti-Semitism, the Prime Minister and the Minister of the Interior.

### Judgment of the Court (First Chamber) of 3 October 2019.#Staatssecretaris van Justitie en Veiligheid v A and Others.#Request for a preliminary ruling from the Raad van State.#Reference for a preliminary ruling — EEC-Turkey Association Agreement — Decision No 2/76 — Article 7 — Decision No 1/80 — Article 13 — ‘Standstill’ clauses — New restriction — Collection, registration and retention of biometric data of Turkish nationals in a central filing system — Overriding reasons of public interest — Ob

*Source: Court of Justice of the European Union, C-70/18, 2019-10-03 — https://overview.legal/posts/132337 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0070*

The CJEU ruled on a preliminary reference from the Dutch Council of State in Case C-70/18, Staatssecretaris van Justitie en Veiligheid v. A, B, and P, addressing whether the Netherlands' obligation for Turkish nationals to provide biometric data for residence permits constitutes a "new restriction" under the standstill clauses of Article 7 of Decision No. 2/76 and Article 13 of Decision No. 1/80 of the EEC-Turkey Association Agreement. The Court held that requiring the collection, registration, and retention of biometric data in a central filing system does amount to a new restriction within the meaning of those provisions, but may be justified by the overriding public interest objective of preventing identity and document fraud, provided the measure is proportionate and complies with Articles 7 and 8 of the Charter of Fundamental Rights regarding respect for private life and protection of personal data. No fine was imposed, as the ruling was limited to interpretive guidance for the referring national court.

### RYNES V. ÚŘAD PRO OCHRANU OSOBNICH ÚDAJŮ, 11.12.2014 (“RYNES”)

*Source: CJEU, 2014-12-11 — https://overview.legal/posts/6155 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62013CJ0212&ref=6155*

Personal data: The image of a person recorded by a camera constitutes personal data because it makes it possible to identify the person concerned. (¶ 22)

### CJEU C-473/12 IPI: Member States need not transpose all Directive 95/46 Article 13

*Source: GDPRhub, 2013-11-07 — https://overview.legal/posts/158436 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-473/12_-_IPI*

Facts — The Belgian Professional Institute of Real Estate Agents (IPI) had used private detectives to collect information on a real estate company that allegedly breached regulatory rules. The admissibility of the private detectives’ evidence in court was questioned on the grounds that the company’s agents had not been informed that their personal data would be processed by third parties in accordance with Article 11(1) of the Data Protection Directive 95/46. IPI argued that the use of private detectives fell within the exception under Article 13(1)(d) of Directive 95/46, which permits the collection of data without consent for the prevention, investigation, detection and prosecution of breaches for regulated professions. Belgian law had specified exceptions for journalistic purposes, artistic or literary expression, public authorities exercising judicial police duties, police services and the European Centre for Missing and Sexually Abused Children. The Belgian Constitutional Court considered that the Belgian law did not strictly transpose exceptions comparable to Article 13 of Directive 95/46/EC. It referred three questions to the ECJ for clarification on the obligations for Member States to implement Article 13 in national law: Does Article 13(1)(d) of Directive 95/46 leave Member States free to choose whether or not to provide for an exception to the immediate obligation to inform under Article 11(1) to protect others’ rights and freedoms? Do professional activities of private detectives (governed by national law) come within an exception referred to in Article 13(1)(d) and (g) of Directive 95/46? If they do not, is Article 13(1)(d) and (g) of Directive 95/46 compatible with Article 6(3) TEU – specifically, with the principle of equality and non-discrimination? Holding — With regard to the first question, the Court ruled that Member States have the option, but not an obligation, to transpose the list of exceptions provided under Article 13 of the Data Protection Directive 95/46/EC. Article 13 permits Member States to adopt exemptions allowing the collection and processing of personal data without notifying the data subject in seven circumstances: To safeguard national security. For defence. For public security. For the prevention, investigation, detection and prosecution of criminal offenses or breaches of ethics for regulated professions. For an important economic or financial interests of a Member State. For monitoring, inspection or regulatory functions. For the protection of the data subject or the rights and freedoms of others. The CJEU based its interpretation on the emphasis on a high level of protection found in recitals 3, 8 and 10 of Directive 95/46. In provisions such as these, Directive 95/46's aim of harmonisation must be balanced against the applicability of the Directive's general language in specific situations and the need to afford Member States some flexibility in this regard. With regard to the second question, the CJEU considered that the activity of a private investigator on behalf of a regulated body – in this case, the IPI – falls within the scope of Article 13(1)(d) of Directive 95/46. Thus, if a Member State has chosen to implement an exception pursuant to Article 13(1)(d) of Directive 95/46, the professional body concerned and the private detectives acting on its behalf may rely on it. Accordingly, they need not inform the data subject pursuant to Article 10 and 11 of Directive 95/46.

### VOLKER UND MARKUS SCHECKE GBR V. LAND HESSEN, EIFERT V. LAND HESSEN AND BUNDESANSTALT FUR LANDWIRTSCHAFT UND ERNAHRUNG, 9.Nov.2010 (“SCHECKE”)

*Source: CJEU, 2010-11-09 — https://overview.legal/posts/6180 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62009CJ0092&ref=6180*

Purpose for processing: The legislation at issue does base the processing on consent. Rather, it provides that they are to be informed. Thus, processing is not based on their consent. (¶ 54)

### VG München - M 26a K 25.5210

*Source: Administrative Court Munich, 2026-05-18 — https://overview.legal/posts/108991 — original: https://gdprhub.eu/index.php?title=VG_München_-_M_26a_K_25.5210*

Facts — The data subject had been liable to pay broadcasting contributions to the Controller, a German regional public broadcasting authority, since 2007. Following objections to several contribution assessment notices, the data subject submitted a request under Article 15 GDPR seeking a copy of all personal data processed about him by the Controller. The Controller responded by providing the categories of personal data and related information specified under § 11(8) of the German Broadcasting Contribution Treaty (RBStV), which governs data subject access requests relating to broadcasting contribution records, together with general privacy information. The data subject argued that the response was incomplete because it did not include copies of all documents containing his personal data, including correspondence with him and third parties. The Controller maintained that it had fully complied with its obligations under the RBStV. After the Controller declined to provide additional information, the data subject brought proceedings seeking disclosure of all personal data concerning him processed by the Controller. Holding — The Court held that § 11(8) of the German Broadcasting Contribution Treaty (RBStV) constituted a lawful restriction of the broader right of access under Article 15 GDPR pursuant to Article 23(1)(e) GDPR. It found that the national provision was a valid legislative measure, respected the essence of the fundamental right to data protection, and pursued an important public interest by ensuring the effective financing and administration of the public broadcasting system. The Court further held that the restriction was necessary and proportionate, noting that requiring the Controller to comply with the full scope of Article 15 GDPR across more than 44 million broadcasting contribution accounts would impose a disproportionate administrative and financial burden capable of undermining that public interest. The Court also held that § 11(8) RBStV satisfied the safeguards required under Article 23(2) GDPR by specifying the purposes of processing, categories of personal data, scope of the restriction, safeguards against misuse and unlawful access, the identity of the Controller, applicable storage periods and other statutory protections. Accordingly, while the Controller was required to disclose the categories of information specified under § 11(8) RBStV, it was not required to provide a copy of all personal data processed under Article 15(3) GDPR. As the Controller had already provided all information required under the national provision, the court dismissed the action.

### GC and Others v CNIL

*Source: CJEU, C-136/17, 2019-09-24 — https://overview.legal/posts/51475 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62017CJ0136*

Conditions for delisting sensitive data from search results.

## Guidance

### Opinion 11/2024 on the use of facial recognition to streamline airport passengers’ flow (compatibility with Articles 5(1)(e) and(f), 25 and 32 GDPR)

*Source: EDPB, opinion-112024-on-the-use-of-facial-recognition-to-streamline-en, 2024-05-24 — https://overview.legal/posts/125750 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-112024-on-the-use-of-facial-recognition-to-streamline_en*

A dopted Opinion 11/2024 on the use of facial recognition to streamline airport passengers’ flow (compatibility with Articles 5(1)(e) and(f), 25 and 32 GDPR Version 1.1 Adopted on 23 May 20 24 Adopted 1 Version 1.1 28 May 2024 Grammatical correction in the E xecutive summary (pages 3 and 4) and paragraphs 77 and 90 of the Opinion Version 1.0 23 May 2024 Adoption of the Opinion Adopted 2 Executive summary The French Supervisory Authority requested the European Data Protection Board to issue an…

### EDPB-EDPS Joint Opinion 5/2021 on the proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)

*Source: EDPB, edpb-edps-joint-opinion-52021-on-the-proposal-for-a-regulation-of-the-en, 2021-06-18 — https://overview.legal/posts/126016 — original: https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-52021-on-the-proposal-for-a-regulation-of-the_en*

1 Adopted EDPB - EDPS Joint Opinion 5 /2021 on the proposal for a Regulation of the European Parliament and of the Council laying down harmo nised rules on artificial i ntelligence (Artificial Intelligence Act) 18 June 2021 2 Adopted Executive Summary On 2 1 April 2021, the European Commission presented its Proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (hereinafter “the Proposal”) . The EDPB and the EDPS welcome…

### Guidelines 05/2022 on the use of facial recognition technology in the area of law enforcement

*Source: EDPB, edpb-guidelines-on-the-use-of-facial-recognition technology-in-the-area-of-law-enforcement, 2023-05-17 — https://overview.legal/posts/38075 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-052022-on-the-use-of-facial-recognition-technology-in-the-area-of_en*

More  and  more  law  enforcement  authorities  (LEAs)  apply  or  intend  to  apply  facial  recognition technology (FRT). It may be used to authenticate or to identify a person and can be applied on videos (e.g. CCTV) or  photographs. It may be used for various purposes, including to search for persons  in police watch lists or to monitor a person's movements in the public space. FRT is  built on the processing of biometric data , therefore, it encompasses the processing of special categories ...

### Guidelines 3/2019 on processing of personal data through video devices

*Source: EDPB, edpb-guidelines-on-processing-of-personal-data-through-video-devices, 2020-01-30 — https://overview.legal/posts/38059 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-32019-on-processing-of-personal-data-through-video-devices_en*

The European Data Protection Board (EDPB) adopted Guidelines 3/2019 to provide comprehensive guidance on the processing of personal data through video devices,including CCTV and smart camera systems, under the GDPR. The guidelines address key issues such as the scope of application, the household exemption, lawfulness of processing under Article 6(1)(f) GDPR (legitimate interests), data subjects' rights, and obligations of controllers, while also clarifying the boundary with the Law Enforcement Directive (EU 2016/680). The guidelines were adopted on 29 January 2020 following public consultation and do not impose fines but serve as interpretative guidance for controllers and supervisory authorities.

### Guidelines 2/2023 on Technical Scope of Art. 5(3) of ePrivacy Directive

*Source: EDPB, edpb-guidelines-on-technical-scope-of-art-53-of-eprivacy-directive, 2024-10-16 — https://overview.legal/posts/38063 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-22023-on-technical-scope-of-art-53-of-eprivacy-directive_en*

The European Data Protection Board (EDPB) issued Guidelines 2/2023 to clarify the technical scope of Article 5(3) of the ePrivacy Directive, focusing on its application to emerging tracking technologies that operate as alternatives to cookies. The guidelines establish three key elements—information, terminal equipment, and gaining access/storage—to determine whether specific technical operations require user consent. The document applies this framework to common use cases such as URL and pixel tracking, local processing, IP-based tracking, intermittent IoT reporting, and the use of unique identifiers.

### Opinion 26/2018 on the draft list of the competent supervisory authority of Luxembourg regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-262018-on-the-draft-list-of-the-competent-supervisory-en, 2018-12-04 — https://overview.legal/posts/126264 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-262018-on-the-draft-list-of-the-competent-supervisory_en*

1 Adopted EDPB Plenary meeting, 04/05.12.2018 Opinion 26 /2018 on the draft list of the competent supervisory authority of Luxembourg regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 4 December 2018 2 Adopted TABLE OF C ONTENTS 1 Summary of the Facts ................................ ................................ ................................ ..................... 4 2 Assessment…

### Opinion 20/2021 on Tobacco Traceability System

*Source: EDPB, opinion-202021-on-tobacco-traceability-system-en, 2021-06-18 — https://overview.legal/posts/126018 — original: https://www.edpb.europa.eu/documents/legislative-opinion/opinion-202021-on-tobacco-traceability-system_en*

Ad opted 1 Opinion 20/2021 on Tobacco Traceability System Adopted on 18 June 2021 Ad opted 2 Contents 1. BACKGROUND ................................ ................................ ................................ ........................ 3 2. SCOPE OF THE OPINION ................................ ................................ ................................ ..... 4 3. ASSESSMENT ................................ ................................ ................................…

### Report on stakeholder event on anonymisation and pseudonymisation of 12 December 2025

*Source: EDPB, report-on-stakeholder-event-on-anonymisation-and-en, 2026-02-18 — https://overview.legal/posts/125688 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/report-on-stakeholder-event-on-anonymisation-and_en*

Report on stakeholder event on anonymisation and pseudonymisation of 12 December 2025 1. Background The EDPB organise d a remote stakeholder event on 12 December 2025 to collect stakeholders’ input on anonymisation and pseudonymisation , following the Court of Justice of the European Union ( “ CJEU ” ) judgment in case EDPS v SRB 1 . The objective was to engage with stakeholders to inform the EDPB’s ongoing work on its guidelines 01/2025 on pseudonymisation and f orthcoming guidelines on…

## Enforcement decisions

### Tietosuojavaltuutetun toimisto (Finland) - TSV/4630/2023

*Source: Tietosuojavaltuutetun toimisto (Finland), 2026-07-22 — https://overview.legal/posts/184713 — original: https://gdprhub.eu/index.php?title=Tietosuojavaltuutetun_toimisto_(Finland)_-_TSV/4630/2023*

Facts — A company that provides comparison services for loans and financial products (the controller) received a loan application submitted on the data subject’s behalf in October 2022. The data subject made an access request in November 2022 – they suspected the misuse of their personal data as they had not submitted the loan application themselves. The data subject provided their name, phone number, and email address as identifying information in connection with the access request. The controller did not provide the requested information; instead, it asked the data subject to disclose their residential address and personal identification number as well as to sign the access request electronically using strong authentication in order to verify their identity. The data subject refused to comply with this request and filed a complaint with the DPA, stating that the controller’s procedure for verifying the identity of the data subject in connection with an access request violated Articles 5(1)(c), 12(2) and (6), and 25(2) GDPR. The controller considered the additional information necessary to identify the correct individual and avoid providing the data subject’s information to an unauthorised third party. Holding — The DPA found no GDPR violation and held that the controller was entitled to request the data subject to provide additional information necessary to verify their identity pursuant to Article 12(6) GDPR. The controller’s procedure was also in line with the principle of data minimisation laid down in Article 5(1)(c) GDPR. According to the DPA, the personal data originally provided by the data subject when making the access request could not be considered sufficient identifying information since several people might have the same name and the email address and the phone number of the data subject could also be known to third parties. The DPA considered that the controller had a legitimate reason to request that the data subject provide additional information to verify their identity, as the controller processes personal data concerning the financial status of its customers.

### DPC (Ireland) - 06/SIU/2018

*Source: DPC (Ireland), 2023-08-22 — https://overview.legal/posts/125614 — original: https://gdprhub.eu/index.php?title=DPC_(Ireland)_-_06/SIU/2018*

Facts — The Irish DPC started an own volition inquiry into processing operations carried out by the Galway County Council (the controller), focusing mainly into the surveillance technologies deployed by state authorities, including the Galway County Council and by the An Garda Síochána (the Irish police). More specifically, the Galway County Council Officials make use of CCTV systems, body-worn cameras and automated number plate recognition (ANPR) technologies for various purposes including law enforcement purposes. The DPC carried out its assessment both on the basis of the GDPR and of the Law Enforcement Directive (LED) for activities meant to prevent, investigate, detect and prosecute crime or for the execution of criminal penalties. Holding — In its inquiry, the DPC assessed the legitimacy of processing activities by the controller in light of both the GDPR and the Irish Data Protection Act and the LED, as different processing activities pursued different purposes. The DPC held with respect to body-worn cameras and ANPR systems that the GDPR applies to these processing activities as they mainly serve health and safety and traffic management purposes respectively, thus no law enforcement purposes. Making reference to the strict interpretation in CJEU jurisprudence, the DPC held that in order for a processing activity to fall under the scope of the LED, it must be specifically and concretely used for law enforcement purposes and it does not suffice that the data could potentially (emphasis added) be processed for law enforcement purposes. Firstly, as regards ANPR cameras used for traffic management, the DPC held that the latter enable identification of data subjects within the vehicle and thus constitutes processing of personal data. The legal basis referred to by the Council is Article 6(1)(e) GDPR. The DPC held that processing ex Article 6(1)(e) GDPR, read in light of Article 6(3) GDPR and Recital 41 GDPR requires a legal basis to set out the conditions for processing clearly, precisely and in a foreseeable way. In this case, the DPC held that the use of ANPR cameras does aid to the traffic management function of officials but it may also have significant impacts on the rights and freedoms of data subjects. The DPC concluded that the national provisions relied on by the controller to make use of such cameras are too broad and cannot constitute a legal basis for the Council to deploy APNR cameras for traffic management purposes. Hence, the DPC found the Council had acted in violation of Article 5(1)(a) GDPR. In addition to this, the DPC considered whether the controller complied with its Article 24(1) GDPR obligation to adopt appropriate technical and organizational measures to ensure and demonstrate GDPR-compliant processing activities, also by means of a data protection policy as per Article 24(2) GDPR. The DPC held that the controller failed to comply with its obligation under Article 24(1) GDPR with respect to the use of ANPR cameras for traffic management purposes as it failed to demonstrate compliance with the GDPR. Further, the DPC also found the controller had failed to comply with its obligation to carry out a Data Protection Impact Assessment by virtue of Article 35(1) GDPR for the use of APNR cameras for the systematic monitoring, tracking and observing of individuals. Secondly, the DPC considered the use of a body-worn camera by a Housing Tenacy Officer who had been threatened while conducting official activities. The legal basis relied upon by the Council in this case was Article 6(1)(d) GDPR, which allows for processing activities that are necessary to protect the vital interest of an individual. Further the Council also relied on Article 6(1)(e) GDPR as it is required to comply with health and safety obligations towards its employees set out in two specific Acts. As regards the use of body-worn cameras on the basis of Article 6(1)(d) GDPR, the DPC held that the controller failed to carry out a test for proving the necessity of the use of such cameras before their actual use. Hence, the controller failed to prove that such measure was necessary to protect the vital interest of the officer or to perform a task in the public interest. As for the use of such cameras on the basis of Article 6(1)(e) GDPR, the DPC held that again the controller did not rely on a clear, precise and foreseeable provision in the law allowing specifically for the body-worn cameras to be used. In this case too, the DPC held that the Council had infringed Article 5(1)(a) GDPR. Lastly, the DPC held that the controller infringed Article 24(1) GDPR to the extent that it failed to raise staff awareness on the principles of data processing, which counts as an organizational measure to be adopted by the controller under Article 24(1) GDPR. With respect to all the above mentioned violations, the DPC decided to adopt the following corrective powers: it provisionally banned the use of body-worn cameras and APNR cameras until a valid legal basis is identified and issued a reprimand concerning the violation of Article 24 GDPR. The rest of the activities carried out by the Galway County Council were assessed in light of the provisions of the LED, and the DPC found several violations in that respect too.

### AEPD (Spain) - ps-00148-2025

*Source: AEPD (Spain), 2026-08-13 — https://overview.legal/posts/291264 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_ps-00148-2025*

Facts — XFERA MÓVILES, S.A.U. (XFERA), the controller, is a telecommunications provider. The data subject was a customer of the controller and held a mobile telephone line. On 24 July 2023, an unauthorised third party requested a duplicate SIM card for the data subject's mobile line through one of the controller's distributors. The third party presented a copy of an identity document purportedly belonging to the data subject. An agent of the controller identified the third party as the account holder following an in-person visual verification of the identity document. The document was subsequently scanned and a duplicate SIM card was issued. However, a comparison between the identity document presented by the third party and the data subject's actual information showed several discrepancies. Although the identification number, name, surnames and nationality matched, other information, including the place and date of birth, address and parents' names, did not. The controller acknowledged that its agent had not verified all the information contained in the identity document and had therefore departed from the controller's internal procedure. However, it argued that this was an isolated human error, that it had appropriate procedures in place and that the processing was lawful under Article 6(1)(b) GDPR because of its contractual relationship with the data subject. Holding — The DPA held that the controller violated Article 6(1) GDPR. The DPA considered that issuing a duplicate SIM card constituted processing of personal data, since both the information used to issue the card and the SIM card itself were linked to an identifiable subscriber. It held that the controller had processed the data subject's personal data without a valid legal basis because it failed to adequately verify the identity of the person requesting the duplicate SIM card. The contractual relationship with the data subject could not legitimise processing carried out on the basis of a request made by an unauthorised third party. In particular, the DPA noted that the controller had failed to carry out checks required by its own procedures. Consequently, the duplicate SIM card was issued to a third party who was neither the account holder nor demonstrated that they were authorised to act on the account holder's behalf. The DPA rejected the controller's argument that the infringement resulted exclusively from third-party fraud. It considered that the fraudulent conduct of a third party did not exempt the controller from exercising sufficient diligence to verify the identity of persons requesting the processing of personal data. The mere existence of internal procedures was insufficient if those procedures were not effectively implemented. The DPA also rejected the argument that imposing a fine would amount to strict liability. It found that the controller's liability resulted from its lack of due diligence in ensuring that the processing had a lawful basis, rather than merely from the occurrence of the fraudulent SIM swap. When determining the fine, the DPA took into account, among other factors, the nature of the infringement, the controller's negligence, the categories of personal data concerned, a previous infringement involving an unauthorised SIM duplication and the close connection between the controller's business activities and the processing of personal data. Consequently, the DPA imposed a fine of €200,000 for the violation of Article 6(1) GDPR. Pursuant to Article 58(2)(d) GDPR, it also ordered the controller, within six months from the decision becoming final and enforceable, to provide evidence that it had adopted measures to prevent similar incidents and ensure compliance with the principle of lawfulness.

### Merchant: Non-compliance with general data processing principles

*Source: Belgian Data Protection Authority (APD), 2019-09-17 — https://overview.legal/posts/46195 — original: https://www.enforcementtracker.com/ETid-80*

The Belgian data protection authority has imposed a fine of 10,000 euros on a merchant who wanted to use an electronic identity card (eID) to create a customer card. The DPA's investigation revealed that the merchant required access to personal data located on the eID, including the photo and barcode which is linked to the data subject's identification number. In the meantime, the decision of the data protection authority has been annulled by a court: link

### AEPD: Digi Telecom violated Art 6(1) GDPR by issuing duplicate SIM to impersonator

*Source: AEPD (Spain), 2026-07-13 — https://overview.legal/posts/109001 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_EXP202310345*

Facts — On December 28, 2022, DIGI Telecom, the controller, delivered a duplicate SIM card to an unauthorized third party without the consent of the original line holder (the data subject) The duplicate SIM card was delivered to an impersonator after they passed the established protocols for verifying the applicant's identity. The controller appealed the decision by the Spanish DPA to impose a fine because they claimed that they had appropriate security measures. The controller claims that, by focusing on the result, the Spanish DPA is acting under strict liability. The mere fact that identity theft occurred does not equal a lack of due diligence on the part of the controller. The controller also requested a reduction of the fine on the basis of Article 83(5)(a) GDPR because there were no aggravating circumstances and no special categories of data were processed Holding — The Spanish DPA found a violation of Article 6(1) GDPR because issuing a duplicate SIM card and delivering it to a person other than the telephone line holder constitutes the processing of personal data within the meaning of Article 4(1) GDPR without a legal basis because the data subject did not give consent. The DPA ruled that the controller violated their duty of care because the security measures lacked the dilligence required. According to Article 5(2) GDPR (principle of proactive responsibility) the controller must demonstrate compliance to the GDPR. Proactive responsibility means that the measures are compliant to the GDPR under normal circumstances. The controller must also demonstrate that the measures are compliant with the GDPR and that they are effective in the specific context and purposes of processing (Article 24 en 25 GDPR). The controller had a higher standard of care because of a documented risk to SIM swap attacks and the high scale of processing. Recital 74 GDPR states that the controller’s must implement effective and appropriate measures that take into account the nature, scope and context, and purposes of processing. The card allows an impersonator to access additional data through which they can carry out actions with grave consequences. The controller did not demonstrate that their security measures sufficiently protected the data subject. Factual circumstances should have alerted DIGI to the fraud: the SIM card replacement was processed at a physical store in a different province from where the data subject resided. The Spanish DPA flagged that the controller did not ask the reason for issuing the card and they did not verify whether the old SIM card was functioning. Therefore the security measures were not appropriate to prevent'SIM swap attacks' that are prevalent in the telecom context. With regard to to the height of the fine, the Spanish DPA found that no new legal arguments were made that would lead to the reduction of the fine.

### AEPD (Spain) - EXP202306354 (PS/00312/2024)

*Source: AEPD (Spain), 2026-02-11 — https://overview.legal/posts/52464 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_EXP202306354_(PS/00312/2024)*

Facts — The Spanish Data Protection Agency (AEPD) investigated Vodafone España, S.A.U. as controller after a SIM swapping incident. On 21 September 2021, an unknown third party requested a duplicate SIM card for the mobile line of a data subject. The request was made through Vodafone’s internal telephone support channel for retail stores. The caller impersonated staff and provided several data elements, including the store user code, the data subject’s identification number, the mobile phone number and digits of the ICC number of the new SIM card. Vodafone processed the request and activated the duplicate SIM card. On the same day, the data subject’s phone stopped working. Shortly afterwards, four unauthorised transactions totalling €1,996 were carried out from their bank account. The data subject contacted Vodafone, their bank and the police. Vodafone confirmed that a duplicate SIM card had been issued through a physical point of sale. After the data subject presented a complaint, during the investigation, Vodafone explained that its internal policy required store staff to call a dedicated support channel and provide identifying information before a duplicate SIM could be issued. Vodafone stated that the fraudster had provided the required information and that the security protocol in force at the time had been followed. The controller also informed the AEPD that it later adopted additional measures to reinforce the security of the duplicate SIM procedure. On the basis of these facts, the AEPD opened sanctioning proceedings against Vodafone for an alleged infringement of Article 6(1) GDPR. Holding — The AEPD found that Vodafone infringed Article 6(1) GDPR by processing the personal data of the data subject without a valid legal basis. The AEPD held that the issuance and activation of a duplicate SIM card involved the processing of personal data. Vodafone carried out this processing without the knowledge or consent of the data subject and without any other legal basis under Article 6(1) GDPR. As a result, the processing was unlawful. The AEPD rejected the controller’s argument that it had complied with its internal security protocols. The DPA stated that the existence of internal procedures did not remove the obligation to ensure that processing had a valid legal basis. The intervention of a criminal third party did not exempt the controller from responsibility where the unlawful processing occurred within its own systems and procedures. The AEPD considered that Vodafone acted at least negligently. It took into account the nature of the infringement and the link between the processing and the controller’s core business activity. The DPA imposed an administrative fine of €150,000 on Vodafone for the infringement of Article 6(1) GDPR.

### Telecommunications Operator: Non-compliance with general data processing principles

*Source: Bulgarian Commission for Personal Data Protection (KZLD), 2023-03-16 — https://overview.legal/posts/48999 — original: https://www.enforcementtracker.com/ETid-2884*

The Bulgarian DPA has imposed a fine of EUR 1,020 on a telecommunications operator. The controller did not implement sufficient identification methodes, resulting in a customer profile being created for an individual who neither knew nor wanted a profile to be made.

### UAB VS FITNESS: Non-compliance with general data processing principles

*Source: Lithuanian Data Protection Authority (VDAI), 2021-06-21 — https://overview.legal/posts/46847 — original: https://www.enforcementtracker.com/ETid-732*

The Lithuanian DPA (VDAI) has imposed a fine of EUR 20,000 on UAB VS FITNESS. After receiving a notification from an individual stating that scanning a fingerprint was necessary to use the services of a sports club owned by the controller, the DPA started an investigation against the controller. The DPA's review found that the consent given by customers to have their fingerprint patterns processed was not voluntary as there were no other identification measures. In addition, the DPA found that t

## Recent developments

### De Griekse toezichthouder heeft Clearview AI een boete van 20 miljoen euro opgelegd.

*Source: IAPP, 2022-10-20 — https://overview.legal/posts/51829*

Een overzicht van de boete die aan IAPP is opgelegd: https://iapp.org/news/a/a-rundown-of-the-greek-dpas-clearview-ai-fine-findings

### Enforcement in public transportation.

*Source: Government, 2025-07-10 — https://overview.legal/posts/52140*

Report: Enforcement in Public Transportation. Analysis of the legal framework regarding identification and data exchange. Also see the joint response from the Ministry of Justice and Security (Iens) and the Ministry of Internal Affairs and Kingdom Relations (JenV) to the report.

### Greek SA fines Clearview AI for EUR 20M

*Source: IAPP, 2022-10-20 — https://overview.legal/posts/6252 — original: https://iapp.org/news/a/greek-dpa-imposes-20m-euro-fine-on-clearview-ai-for-unlawful-processing-of-personal-data#entry-1098*

A rundown of the fine on IAPP: https://iapp.org/news/a/a-rundown-of-the-greek-dpas-clearview-ai-fine-findings

### Data brokers: Identification possible to sell ads, not to exercise fundamental rights

*Source: noyb - European Center for Digital Rights, 2023-02-28 — https://overview.legal/posts/53249 — original: https://noyb.eu/en/data-brokers-identification-possible-sell-ads-not-exercise-fundamental-rights*

Today, noyb filed a series of complaints against websites and data brokers that did not correctly address access requests using cookies as an authentication factor. The companies had shown obstructive approaches when authenticating users; ranging from denying the right to access, to requiring additional information, unnecessary to authenticate the user. Complaint against data broker: machine translated EN [PDF] Complaint against website: machine translated EN [PDF] Exercising fundamental rights

### A-G: rechtmatig verzamelde en opgeslagen persoonsgegevens mogen onder voorwaarden tijdelijk in een extra interne databank worden bewaard

*Source: NL EU Court Expert, 2022-04-09 — https://overview.legal/posts/6307 — original: https://ecer.minbuza.nl/-/a-g-rechtmatig-verzamelde-en-opgeslagen-persoonsgegevens-mogen-onder-voorwaarden-tijdelijk-in-een-extra-interne-databank-worden-bewaard?redirect=%2Fecer%2Fnieuws%3Fq%3Dprivacy%2520OR%2520avg%26f%3D%26t%3D#entry-306*

Lawfully collected and stored personal data may be retained in an additional internal database, to the extent that it pursues the same data processing purposes as the original data collection. That is the opinion of Advocate General Pikamäe to the EU Court in response to questions from a Hungarian judge.

## Literature

### Use of Artificial Intelligence Tools by Law Enforcement Services in Light of the Artificial Intelligence Act

*Source: Zeszyt Prawniczy UAM, 2025-12-22 — https://overview.legal/posts/132565 — original: https://doi.org/10.14746/zpuam.2025.15.4*

Celem artykułu jest wskazanie przestępstw, w przypadku których służby państwowe mogą korzystać z systemów zdalnej identyfikacji biometrycznej w czasie rzeczywistym w przestrzeni publicznej. Zostanie to uczynione przez analizę przesłanek umożliwiających posługiwanie się tą technologią oraz przyrównanie ich do czynów zabronionych przez polski kodeks karny. Rezultatem powyższego jest stworzenie katalogu przestępstw, odnośnie do których służby mogą zastosować system zdalnej identyfikacji biometryczn

### The Artificial Intelligence Act (AI Act) as the basis for legal regulation of artificial intelligence in the EU: review of the main provisions

*Source: Analytical and Comparative Jurisprudence, 2025-07-12 — https://overview.legal/posts/132431 — original: https://doi.org/10.24144/2788-6018.2025.03.3.44*

This article reviews the main provisions of the Artificial Intelligence Act (AI Act), which entered into force as an EU Regulation in 2014. It is indicated that one of the main global trends in recent years is the active development of artificial intelligence and its application, and it is argued that since the AI Act is one of the first legal acts in the world designed to regulate artificial intelligence, and also taking into account Ukraine’s course towards European integration, it is importan

### Artificial Intelligence in Decision-making: A Test of Consistency between the “EU AI Act” and the “General Data Protection Regulation”

*Source: Athens Journal of Law, 2025-01-02 — https://overview.legal/posts/132443 — original: https://doi.org/10.30958/ajl.11-1-3*

The recent Regulation that sets down harmonised rules on Artificial Intelligence in the European Union, known as the "AI Act," includes a significant requirement for human oversight in high-risk AI systems during their use (art. 14). This requirement embodies the "human-in-command" approach, ensuring both legal and ethical compliance. The AI Act is intended to complement the General Data Protection Regulation (hereinafter GDPR), thereby forming a consistent and comprehensive legal framework. Thi

### HOW GDPR TREATS AUTOMATED DECISION-MAKING

*Source: Journal Scientific and Applied Research, 2025-11-14 — https://overview.legal/posts/132599 — original: https://doi.org/10.46687/jsar.v28i1.435*

This article examines how the General Data Protection Regulation (GDPR) regulates automated decision-making, including profiling, in the context of personal data processing. It analyzes the main provisions of Article 22 of the Regulation, as well as the conditions under which fully automated decisions that produce legal effects or significantly affect data subjects are permitted. The article highlights the rights of data subjects – the right to human intervention, the right to express their poin

### POJAM OSOBNOG PODATKA U TUMAČENJU SUDA EUROPSKE UNIJE

*Source: Zbornik radova. Aktualnosti građanskog i trgovačkog zakonodavstva i pravne prakse, 2026-07-06 — https://overview.legal/posts/83510 — original: https://doi.org/10.47960/2744-2918.23.2026.281*

U radu se istražuje evolucija pojma osobnih podataka u kontekstu pseudonimizacije kroz analizu recentne sudske prakse i regulatornih smjernica. Središnji dio rada fokusiran je na presudu Suda Europske Unije u predmetu EDPS protiv SRB, kojom se potvrđuje kontinuitet relativnog poimanja pojma osobnog podatka u kontekstu provođenja postupka pseudonimizacije osobnih podataka. Hoće li se određeni podatak smatrati osobnim ovisi, tako, o tome tko podatak obrađuje i raspolaže li i kojim dodatnim informa

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities
- **Public Authority** — https://overview.legal/topics/overheid
  Government bodies and their data processing activities
- **Consent** — https://overview.legal/topics/toestemming
  Freely given, specific, informed indication of data subject wishes

---
Generated by overview.legal · https://overview.legal/topics/identificatie · 2026-08-22
