# Inspection Access Rights and Cooperation Obligations — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/inspection-access-rights-obligations
> Sources are cited per item. Verify against the official texts before relying on them.

A dedicated topic is needed to address the specific rights of inspectors to access facilities, systems, and documents, and the corresponding obligations of AI providers and deployers to cooperate with inspections.

## Overview

## Legal Framework

Article 82 of the Digital Services Act (DSA) governs the interaction between access restrictions and cooperation with national judicial authorities. This provision establishes that providers must cooperate with national courts when addressing requests for access restrictions, ensuring that judicial oversight is integrated into the operational framework of digital services. The rationale is to balance the operational realities of digital platforms with the necessity of judicial intervention, ensuring that access can be restricted only when justified and properly mandated by a competent court.

In the broader context of data protection, Articles 15 and 12 of the GDPR establish the baseline for access rights and the obligation to facilitate them. While these provisions directly address data subject access, they establish a normative framework that extends to regulatory inspections: controllers must provide access to information and systems without undue delay, and cannot systematically refuse access based on generalized privacy concerns.

## Key Developments

The Court of Justice of the European Union has established that access rights cannot be categorically denied on the grounds of privacy violations without a specific, contextual analysis of the circumstances. In the *Jehovah's Witnesses* case, the Court clarified that a blanket refusal to grant access is impermissible; controllers must evaluate each request individually. This principle translates directly to regulatory inspections: authorities must be granted access unless a specific, legally sound justification for refusal exists in the individual case.

The *Bara* ruling further reinforces that national law cannot serve as a substitute for specific information obligations. Controllers cannot rely on general legal frameworks to dispense with their duty to inform or provide access to specific data transfers or processing operations.

Data Protection Authorities have actively enforced these cooperation standards. The Hellenic Data Protection Authority sanctioned an insurance company for failing to provide adequate access to data subjects, demonstrating that non-cooperation with access requests—whether from individuals or regulators—carries significant liability. Similarly, the Croatian Data Protection Authority penalized a hospital for failing to implement adequate technical and organizational measures, highlighting that the ability to grant access is contingent upon having the proper infrastructure in place.

The Council's recent articulation of new powers for the AI Office signals an expansion of inspection capabilities. Regulators are poised to gain enhanced authority to access the facilities, systems, and documentation of AI providers and deployers, making proactive cooperation a central compliance requirement.

## Practical Guidance

- Establish a dedicated protocol for responding to regulatory inspection requests within the timelines mandated by Article 82 DSA and relevant GDPR provisions, ensuring that judicial orders are processed and executed without undue delay.
- Implement an individualized assessment mechanism for all access requests, whether from data subjects or regulators, to comply with the *Jehovah's Witnesses* standard; avoid blanket refusals based on generalized privacy or confidentiality concerns.
- Maintain comprehensive technical and organizational measures that ensure the immediate retrievability of documents and system logs, as demonstrated by the Croatian DPA enforcement action; the inability to produce requested materials due to poor infrastructure constitutes a violation.
- Ensure that all data processing records clearly document the recipients and purposes of data transfers, satisfying the information requirements established in *Bara* and preventing disputes during inspections.
- Monitor the evolving mandate of the AI Office and prepare internal systems for expanded inspection access, anticipating that new powers will require granular documentation of AI system training data, models, and deployment logs.

## Legislation (full text of key provisions)

### Requests for access restrictions and cooperation with national courts

*Source: DSA, dsa-art-82-en, 2022-10-19 — https://overview.legal/posts/95297*

## Case law

### VG Düsseldorf - 29 K 3490/24

*Source: Administrative Court Düsseldorf, 2026-06-22 — https://overview.legal/posts/108992 — original: https://gdprhub.eu/index.php?title=VG_Düsseldorf_-_29_K_3490/24*

Facts — A district (the controller), acting as the lower water authority, initiated administrative proceedings after identifying unauthorised riverbank works and a private jetty on two riverside properties. One property belonged to a water utility company, while the other belonged to a municipality and was leased to the data subjects. During those proceedings, the controller shared the data subjects' personal data with various participants, including the owners of the affected properties, other public authorities and a lawyer who claimed to represent the data subjects. The data subjects lodged a complaint with the competent supervisory authority (LDI NRW), alleging that the controller had unlawfully processed and disclosed their personal data. They argued that their personal data had been shared with uninvolved third parties, that the controller had communicated with a lawyer whom they had not authorised, recorded a telephone conversation with an unknown person, and transmitted personal data by unencrypted email. The controller's data protection officer addressed each allegation and provided additional factual information concerning the disputed processing operations. The DPA initially informed the data subjects that no GDPR infringement was apparent, invited them to provide any additional factual information, and explained that it would obtain extracts from the controller's administrative file if there were concrete indications that it contained relevant facts not already available. The data subjects did not identify any additional facts and instead reiterated their legal position that the controller had breached its GDPR accountability obligations. The DPA rejected the complaint, concluding that no GDPR infringement could be established. The data subjects then brought an action before the Verwaltungsgericht Düsseldorf (Administrative Court Düsseldorf), seeking a fresh decision on their complaint on the basis that the DPA had failed to adequately investigate the complaint because it had not obtained the controller's administrative file before reaching its decision. Holding — The court held that Articles 57(1)(f) and 77(1) GDPR give rise to an enforceable right requiring a supervisory authority to investigate a complaint to the extent appropriate in the circumstances before determining whether a GDPR infringement has occurred. Recital 141 GDPR requires the investigation to extend as far as is appropriate in light of the circumstances of the individual case, including the significance of the complaint and the seriousness of the alleged infringement. Applying these principles, the court held that the DPA had adequately investigated the complaint. It had considered each allegation together with the detailed response provided by the controller's data protection officer, invited the data subjects to provide any additional factual information, and explained that it would obtain extracts from the administrative file if concrete indications emerged that further relevant facts required clarification. As the data subjects did not provide any additional facts and there were no objective indications that the information already available was inaccurate or incomplete, the court held that the DPA was not required to obtain the controller's administrative file or undertake further investigations in the absence of concrete indications that additional factual clarification was necessary. The court further held that the DPA had correctly concluded that no GDPR infringement had occurred. The court held that the disputed processing was lawful under Article 6(1)(e) GDPR, read together with Article 6(3) GDPR and § 88 of the German Water Resources Act (WHG), which provided the legal basis for the processing. The court also held that the transmission of personal data by email did not infringe Article 5(1)(f) GDPR because, in the circumstances of the case, transport encryption provided an appropriate level of security.

### Österreichische Datenschutzbehörde v CRIF

*Source: CJEU, C-487/21, 2023-10-26 — https://overview.legal/posts/51486 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0487*

Right of access includes obtaining a copy in commonly used electronic form.

### HvJ EU: Privacy Shield ongeldig verklaard (Schrems II)

*Source: Hof van Justitie EU, 2020-07-16 — https://overview.legal/posts/1 — original: https://eur-lex.europa.eu/legal-content/NL/TXT/?uri=CELEX:62018CJ0311*

Het Hof van Justitie verklaart het Privacy Shield-akkoord ongeldig wegens onvoldoende waarborgen voor Europese burgers tegen toegang door Amerikaanse inlichtingendiensten.

### Bundesverband der Verbraucherzentralen v Planet49 GmbH

*Source: CJEU, C-673/17, 2019-10-01 — https://overview.legal/posts/51473 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62017CJ0673&ref=51473*

Pre-ticked checkboxes do not constitute valid consent. Consent must be active.

### Google LLC v CNIL

*Source: CJEU, C-507/17, 2019-09-24 — https://overview.legal/posts/51476 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62017CJ0507&ref=51476*

Right to delisting does not require global de-referencing under EU law.

### GC and Others v CNIL

*Source: CJEU, C-136/17, 2019-09-24 — https://overview.legal/posts/51475 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62017CJ0136*

Conditions for delisting sensitive data from search results.

### Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV

*Source: CJEU, C-40/17, 2019-07-29 — https://overview.legal/posts/51478 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62017CJ0040*

Website operators using Facebook Like button are joint controllers for data collection.

### Peter Nowak v Data Protection Commissioner

*Source: CJEU, C-434/16, 2017-12-20 — https://overview.legal/posts/51480 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62016CJ0434&ref=51480*

Examination scripts constitute personal data of the candidate.

### CJEU Bavarian Lager: Disclosing personal data in access-to-documents requests is

*Source: CJEU, 2010-06-29 — https://overview.legal/posts/6182 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62008CJ0028&ref=6182*

Processing: Communication of personal data in response to a request for access to documents constitutes processing. (¶69)

### Jehovah’s Witnesses

*Source: CJEU, 2018-02-01 — https://overview.legal/posts/5950 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62016CJ0025*

Access: Exercise of the right to access cannot be systematically denied on the basis of privacy violations without analyzing the specific circumstances. (¶¶ 89-94)

### RYNES V. ÚŘAD PRO OCHRANU OSOBNICH ÚDAJŮ, 11.12.2014 (“RYNES”)

*Source: CJEU, 2014-12-11 — https://overview.legal/posts/6155 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62013CJ0212&ref=6155*

Personal data: The image of a person recorded by a camera constitutes personal data because it makes it possible to identify the person concerned. (¶ 22)

### Bulgarian SAC upholds DPA finding on neighbour's CCTV covering adjacent property

*Source: Supreme Administrative Court of Bulgaria‎, 2026-07-13 — https://overview.legal/posts/184723 — original: https://gdprhub.eu/index.php?title=BAC_(Bulgaria)_-_7890/2026*

Facts — A data subject lodged a complaint with the Bulgarian DPA (CPDP), alleging that her neighbour (the controller) was unlawfully monitoring her property through CCTV. She claimed that a camera had been mounted on a metal structure on a third-floor terrace of the neighbouring building and installed in a manner that extended into the space above her property. According to the data subject, the camera had the technical capacity to identify individuals and objects throughout her property. The controller did not deny installing the camera but argued that it was directed towards the fence and an outbuilding on his own property. He also stated that a second camera had been installed on the western façade of the building. The controller claimed that both cameras were used solely to monitor his own property and the processing was lawful under the GDPR. The DPA carried out an on-site investigation and found that the CCTV system consisted of two independent cameras operated through separate software applications. Both cameras could be rotated in all directions and could use an automatic tracking function. The recordings were stored on memory cards for approximately 15 days before being automatically deleted, and only the controller had access to the system. The DPA noted that Camera 1 recorded the northern part of the controller’s yard, his house and the fence bordering the data subject’s property and Camera 2 recorded the roof of the controller’s house and a small part of the data subject’s yard. The DPA reviewed the oldest available footage and noticed that Camera 2 had recorded the data subject’s house and yard. The inspection report stated that the system could process personal data relating to individuals on both properties, but did not allow the identification of individuals or facial recognition. The DPA pointed out that warning stickers informing individuals of the video surveillance were displayed at the property. It found the complaint well founded in relation to Camera 1 and established a violation of Article 5(1)(c) GDPR, for which it issued an official warning to the controller. However, it found the complaint unfounded in relation to Camera 2, considering that the surveillance was permissible on the basis of the controller’s legitimate interest in protecting his property. The data subject appealed the part of the decision concerning Camera 2. The court of first instance annulled that part of the DPA’s decision and remitted the case to the DPA for reconsideration. It found that the DPA had relied entirely on the findings of the inspection team without carrying out a thorough, objective and independent examination of the relevant facts. Both the DPA and the controller appealed that judgment before the Bulgarian Supreme Administrative Court. Holding — The Supreme Administrative Court rejected the appeals and upheld the judgment of the court of first instance. The court noted that Camera 2 recorded the roof of the controller’s building and part of the data subject’s yard. It further pointed out that the DPA had found that, due to their technical characteristics, both cameras could alter their surveillance coverage and process personal data relating to individuals on both properties, while the CCTV system allowed individuals to be identified. Moreover, the court agreed with the first-instance court that the DPA had failed to provide adequate reasons for treating the two cameras differently. In particular, the DPA had not explained how the partial recording of the data subject’s yard contributed to the protection of the controller’s legitimate interest in safeguarding his property. It determined that it had also failed to establish whether adjusting the field of view of Camera 2 could expand its recording perimeter and allow it to capture a larger part of the data subject’s property.

## Guidance

### Report on stakeholder event on anonymisation and pseudonymisation of 12 December 2025

*Source: EDPB, report-on-stakeholder-event-on-anonymisation-and-en, 2026-02-18 — https://overview.legal/posts/125688 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/report-on-stakeholder-event-on-anonymisation-and_en*

Report on stakeholder event on anonymisation and pseudonymisation of 12 December 2025 1. Background The EDPB organise d a remote stakeholder event on 12 December 2025 to collect stakeholders’ input on anonymisation and pseudonymisation , following the Court of Justice of the European Union ( “ CJEU ” ) judgment in case EDPS v SRB 1 . The objective was to engage with stakeholders to inform the EDPB’s ongoing work on its guidelines 01/2025 on pseudonymisation and f orthcoming guidelines on…

### Art. 29 WP Guidelines on GDPR transparency requirements (WP260 rev.01)

*Source: EDPB, edpb-guidelines-on-transparency, 2025-11-21 — https://overview.legal/posts/38076 — original: https://www.edpb.europa.eu/system/files/2023-09/wp260rev01_en.pdf*

The Article 29 Data Protection Working Party issued these guidelines (WP260 rev.01), adopted on 29 November 2017 and last revised on 11 April 2018, to provide interpretive and practical guidance on the transparency requirements under the GDPR (Articles 12–14). The document addresses the form, timing, content, and modalities of information provided to data subjects, including issues such as plain language, layered privacy notices, information for children, and exceptions to the obligation to provide information. No fines or enforcement actions are imposed, as this is a guidance document rather than an enforcement decision.

### Guidelines 04/2022 on the calculation of administrative fines under the GDPR

*Source: EDPB, edpb-guidelines-on-the-calculation-of-administrative-fines-under-the-gdpr, 2023-05-24 — https://overview.legal/posts/38068 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-042022-on-the-calculation-of-administrative-fines-under-the-gdpr_en*

The European Data Protection Board (EDPB) has adopted these guidelines to harmonise the methodology supervisory  authorities use  when calculating of the amount of the fine. These Guidelines complement the previously  adopted Guidelines on the application and setting of administrative fines  for the purpose  of the Regulation 2016/679 (WP253), which focus on the circumstances in which to impose a fine. The calculation of the amount of the fine is at the discretion of the supervisory  authority, ...

### Guidelines 03/2021 on the application of Article 65(1)(a) GDPR

*Source: EDPB, edpb-guidelines-on-the-application-of-article-651a-gdpr, 2023-05-24 — https://overview.legal/posts/38137 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-032021-on-the-application-of-article-651a-gdpr_en*

The European Data Protection Board (EDPB) adopted Guidelines 03/2021 to clarify the dispute resolution mechanism under Article 65(1)(a) GDPR, which governs the EDPB's authority to issue binding decisions when a Lead Supervisory Authority receives relevant and reasoned objections from Concerned Supervisory Authorities that it does not follow. The Guidelines address the procedural framework, the threshold for "relevant and reasoned" objections, the scope of the EDPB's substantive competence, and applicable procedural safeguards including the right to be heard, access to the file, and available judicial remedies.

### Guidelines 01/2022 on data subject rights - Right of access

*Source: EDPB, edpb-guidelines-on-data-subject-rights---right-of-access, 2023-04-17 — https://overview.legal/posts/38055 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-012022-on-data-subject-rights-right-of-access_en*

The right of access of data subjects is enshrined in Art. 8 of the EU Charter of Fundamental Rights. It has been a part of the European data protection legal framework since its beginning and is now further developed by more specified and precise rules in Art. 15 GDPR.

### Guidelines 03/2022 on Deceptive design patterns in social media platform interfaces: how to recognise and avoid them

*Source: EDPB, edpb-guidelines-on-deceptive-design-patterns-in-social-media-platform-interfaces-how-to-recognise, 2023-02-24 — https://overview.legal/posts/38056 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-032022-on-deceptive-design-patterns-in-social-media-platform_en*

These Guidelines offer practical recommendations to social media providers as controllers of social media, designers and users of social media platforms on how to assess and avoid so-called 'deceptive design patterns' in social media interfaces that infringe on GDPR requirements. To this end, the EDPB recommends  that  controllers  make  use  of  interdisciplinary  teams,  consisting,  among  others,  of designers,  data  protection  officers  and  decision-makers.  It  is  important  to  note  ...

### Guidelines 06/2022 on the practical implementation of amicable settlements

*Source: EDPB, edpb-guidelines-on-the-practical-implementation-of-amicable-settlements, 2022-05-12 — https://overview.legal/posts/38072 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-062022-on-the-practical-implementation-of-amicable-settlements_en*

The EDPB adopted Guidelines 06/2022 to provide practical guidance on the implementation of amicable settlements between supervisory authorities and controllers or processors under the GDPR. The guidelines address the scope and definition of amicable settlements, the legal basis for this power, and its procedural operation within the one-stop-shop mechanism, including the roles of the complaint-receiving competent supervisory authority and the lead supervisory authority. No fines are imposed as this is a guidance document rather than an enforcement decision.

### Toolbox on essential data protection safeguards for enforcement cooperation between EEA data protection authorities and competent data protection authorities of third countries

*Source: EDPB, toolbox-on-essential-data-protection-safeguards-for-enforcement-en, 2022-03-14 — https://overview.legal/posts/125962 — original: https://www.edpb.europa.eu/documents/other-guidance/toolbox-on-essential-data-protection-safeguards-for-enforcement_en*

Adopted Toolbox on essential data protection safeguards for enforcement cooperation between EEA data protection authorities and competent data protection authorities of third countries Adopted on 14 Mar c h 2022 2 Adopted The European Data Protection Board Having regard to Article 70 (1)(u) and Article 50(a) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the…

## Enforcement decisions

### APDCAT sanctions Madremanya City Council for exposing applicants' sensitive data in tender

*Source: APDCAT (Catalonia), 2026-07-17 — https://overview.legal/posts/184715 — original: https://gdprhub.eu/index.php?title=APDCAT_(Catalonia)_-_PS-0036/2026*

Facts — On 8 May 2025, Madremanya City Council, acting as controller, published on its notice board two administrative acts concerning a tender procedure for the award of a social housing lease. The documents expressly disclosed the identities of the applicants. On 9 May 2025, the controller replaced the original documents with revised versions in which the applicants’ names and surnames were partially redacted, leaving only their initials visible. However, the redaction was performed manually and did not effectively conceal the information, as it remained possible to infer the length of the names and surnames and to identify some of their letters. In addition to the applicants’ identifying information, the documents disclosed detailed financial data, including the exact annual net income of each household. They also revealed information concerning particularly sensitive personal circumstances, including dependency, gender-based violence and addiction, which had been used to calculate the applicants’ respective scores. No adequate anonymisation or redaction measures had been implemented. In July and November 2025, the DPA requested that the controller provide specific information concerning certain aspects of the processing. The controller’s failure to respond or cooperate hindered the DPA’s ability to exercise its investigative powers. Holding — The DPA held that the controller violated Article 5(1)(c) GDPR by publishing personal data that were not necessary for the purpose pursued. The DPA acknowledged that publishing information about the procedure could serve the objective of administrative transparency. However, transparency did not justify disclosing identifying data together with detailed financial information and sensitive personal or family circumstances. The controller had to limit the processing to data that were necessary and proportionate to that objective and consider less intrusive alternatives. The DPA found that the controller’s subsequent redaction did not amount to effective anonymisation. Although most of the characters had been concealed, the applicants could still potentially be reidentified from their initials, the length of their names and surnames and other contextual information. This risk was particularly significant because the municipality had only 277 inhabitants. The controller should therefore have applied complete anonymisation or a pseudonymisation method preventing direct or indirect identification. The DPA also held that the controller violated Article 5(1)(f) GDPR and the duty of confidentiality under Article 5 LOPDGDD. The published documents disclosed the applicants’ exact household income, household composition and scores linked to circumstances such as dependency, addiction, gender-based violence, single-parent status and age. Although this information was relevant to assessing the applications, it was unnecessary to make it publicly accessible in a form linked to identifiable individuals. The DPA considered that the violations of the data-minimisation and confidentiality principles constituted a medial concurrence of infringements. The failure to anonymise the applicants’ identities was the necessary means through which their sensitive personal and family circumstances were disclosed. Nevertheless, the DPA formally declared separate violations of Articles 5(1)(c) and 5(1)(f) GDPR. Additionally, the DPA held that the controller violated Article 31 GDPR by failing to respond to two information requests. This failure breached the controller’s duty to cooperate with the supervisory authority and obstructed the exercise of the DPA’s investigative powers.

### Telefónica: Insufficient cooperation with supervisory authority

*Source: Spanish Data Protection Authority (aepd), 2020-03-18 — https://overview.legal/posts/46355 — original: https://www.enforcementtracker.com/ETid-240*

Telefonica had failed to comply with decision TD / 00127/2019 of the Director of the AEPD, which states that it had to reply to data subjects' request for right of access and erasure of data.

### AEPD (Spain) - E/03783/2020

*Source: AEPD (Spain), 2026-07-15 — https://overview.legal/posts/108996 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_E/03783/2020*

Facts — The Directorate for National Security of the Ministry of Interior issued guidelines for the police forces to monitor news and social networks to spot fake news and misinformation, to prevent some actors from causing social stress, in light of the covid-19 pandemic. This came to the Spanish DPA (AEPD) knowledge, that launched an investigation to verify that such behaviour complied with the personal data regulations. Such guidelines were issued to prevent and minimize the effects of misinformation, with extreme vigilance and monitoring of networks and websites where false messages and information aimed at increasing social stress are disseminated, and, where appropriate, calling for the intervention measures provided for in the applicable legislation". According to the guidelines, within the surveillance and monitoring of networks and web pages, intervention shall only be carried out in accordance with the aforementioned purposes and principles and always under the protection of the applicable legislation. Also, personal data will only be processed when there is sign of a criminal offence, in accordance with the Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data. If such activities were related to national security, then the processed would be carried out with basis on the national legislation regarding state secrets and classified matters. In their response to the DPA, the Directorate for National Security also stated that they do not collect personal data, but only carry out a daily observation of news or public information from social networks, where the information collected relates to data of a public nature, shared by its authors through social networks and public media, consisting primarily of the content of the communication and the medium of dissemination. For this, specialized officers from the Spanish Civil Guard ("Guardia Civil") browse the news and create anonymous users to monitor (read) social networks such as Twitter, Facebook, Instagram, Badoo and other websites. Afterwards, reports with reference to cybercrime, cyberterrorism, hacktivism, cyberattacks, misinformation and news summaries are issued. If there is a sign of a criminal offence, evidence is gathered. Such reports are stored for 5 years. Holding — The DPA concluded that there was no violation of the GDPR, that is not applicable in accordance with its Article 2, nor with the Directive (EU) 2016/680, as personal data were not processed, as the reports showed, and there was no evidence that there was any illegal additional processing. Therefore, the presumption of innocence principle applied. Hence, the AEPD archived the case.

### Club Náutico el Estacio: Insufficient technical and organisational measures to ensure information security

*Source: Spanish Data Protection Authority (aepd), 2022-10-04 — https://overview.legal/posts/47536 — original: https://www.enforcementtracker.com/ETid-1421*

The Spanish DPA (AEPD) has imposed a fine of EUR 6,000 on Club Náutico el Estacio. A data subject filed a complaint against the controller with the AEPD. The complaint is based on the fact that the controller has published the announcement and the record of the club's ordinary meeting on its website, disclosing personal data without access restrictions.

### Club Náutico el Estacio: Insufficient technical and organisational measures to ensure information security

*Source: Spanish Data Protection Authority (aepd), 2021-08-02 — https://overview.legal/posts/46904 — original: https://www.enforcementtracker.com/ETid-789*

The Spanish DPA (AEPD) has imposed a fine of EUR 3,000 on Club Náutico el Estacio. A data subject filed a complaint against the controller with the AEPD. The complaint is based on the fact that the controller has published the announcement and the record of the club's ordinary meeting on its website, disclosing personal data without access restrictions.

### Department of Home Affairs: Insufficient fulfilment of data subjects rights

*Source: Information Commissioner of Isle of Man, 2020-06-25 — https://overview.legal/posts/46433 — original: https://www.enforcementtracker.com/ETid-318*

Fines for failure to comply with the right of access to personal data under Articles 12 and 15 GDPR. The Isle of Man has declared the GDPR - although it is not an EU state - to be applicable.

### ANSPDCP (Romania) - Fine against Orange Romania SA of July 17, 2026

*Source: ANSPDCP (Romania), 2026-07-29 — https://overview.legal/posts/144034 — original: https://gdprhub.eu/index.php?title=ANSPDCP_(Romania)_-_Fine_against_Orange_Romania_SA_of_July_17,_2026*

Facts — The investigation was initiated after Orange Romania SA (the controller) notified the Romanian DPA (ANSPDCP) of a personal data breach pursuant to Article 33 GDPR, related to its mobile application. A customer (the data subject) of the controller was able to access and download invoices belonging to other customers. As a result, personal data such as names, addresses, delivery addresses, ID document details, and invoice information were disclosed. The incident was caused by a mismatch between two interconnected applications, which incorrectly linked the data subject's account to an employee account. During the investigation, another vulnerability was identified in the controller's ticketing application. The platform was publicly accessible and lacked adequate security measures, such as VPN protection, multi-factor authentication, and IP-based access restrictions. This vulnerability enabled a cyberattack that resulted in the theft of a large volume of personal data, including names, contact details, national identification numbers, copies of identity documents, banking-related information, login credentials, customer codes, and IBAN numbers. Holding — First, the DPA found that the controller infringed Article 25 GDPR by failing to implement appropriate technical and organisational measures when designing and operating its digital platforms. The DPA considered that these shortcomings enabled unauthorised access to personal data and failed to adequately protect data subjects' rights. For this infringement, the DPA imposed a fine of RON 104,780 (€20,000). Second, the DPA found that the controller infringed Article 32 GDPR by failing to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. The DPA noted that the controller had not adequately secured its platforms and had failed to regularly test and assess the effectiveness of its security measures. For this infringement, the DPA imposed a fine of RON 419,120 (€80,000). In addition, as a corrective measure, the DPA ordered the controller to implement a monitoring and testing process for all IT applications used in its activities. The process must include controls over software changes and vulnerability testing.

### Il Sole 24 Ore S.p.a.: Insufficient fulfilment of data subjects rights

*Source: Italian Data Protection Authority (Garante), 2022-04-28 — https://overview.legal/posts/47343 — original: https://www.enforcementtracker.com/ETid-1228*

The Italian DPA has fined the newspaper Il Sole 24 Ore S.p.a. EUR 40,000. The newspaper had published an article on the recognition by the Italian authorities of a U.S. judge's decision on the adoption of a child by a same-sex couple. By mistake, the newspaper also published personal data on the couple and the adopted child. The couple then demanded the deletion of the personal data and access to information about the processing of the personal data. The newspaper deleted the personal data, but

## Recent developments

### Greek SA fines Clearview AI for EUR 20M

*Source: IAPP, 2022-10-20 — https://overview.legal/posts/6252 — original: https://iapp.org/news/a/greek-dpa-imposes-20m-euro-fine-on-clearview-ai-for-unlawful-processing-of-personal-data#entry-1098*

A rundown of the fine on IAPP: https://iapp.org/news/a/a-rundown-of-the-greek-dpas-clearview-ai-fine-findings

### AEPD publishes GDPR Risk Assessment

*Source: AEPD, 2022-10-11 — https://overview.legal/posts/6259 — original: https://evalua-riesgo.aepd.es/index_en.html#entry-1032*

> GDPR RISK ASSESSMENT is intended to assist controllers and processors to identify the risk factors for the rights and freedoms of data subjects whose data are present in the processing, to make an initial assessment of the intrinsic risk, including the need to perform a DPIA, and to estimate the residual risk if measures and safeguards are used to mitigate the specific risk factors.

### Europol told to hand over personal data to Dutch activist

*Source: Fair Trials, 2022-09-15 — https://overview.legal/posts/6280 — original: https://www.fairtrials.org/articles/news/fair-trials-welcomes-a-decision-by-the-european-data-protection-supervisor-edps-ordering-europol-to-hand-over-personal-data-to-dutch-activist-frank-van-der-linde/#entry-356*

The European Data Protection Supervisor ordered Europol to hand over personal data to Dutch activist Frank van der Linde. The decision is the result of a two-year investigation into Europol's possession and storage of van der Linde's personal data.

### De Autoriteit Persoonsgegevens publiceert een rapport over de risicoanalyse van de AVG (Algemene Verordening Gegevensbescherming).

*Source: AEPD, 2022-10-11 — https://overview.legal/posts/51791*

De GDPR-risicoanalyse is bedoeld om controllers en verwerkers te helpen bij het identificeren van de risicofactoren voor de rechten en vrijheden van de betrokkenen, wiens gegevens worden verwerkt. Het doel is om een eerste inschatting te maken van het inherente risico, inclusief de noodzaak om een Privacy Impact Assessment (DIA) uit te voeren, en om het resterende risico te schatten als maatregelen en beveiligingsmechanismen worden gebruikt om specifieke risicofactoren te verminderen.

### Council spells out possible new powers for AI Office

*Source: EURactiv, 2026-02-13 — https://overview.legal/posts/52650 — original: https://www.euractiv.com/news/council-spells-out-possible-new-powers-for-ai-office/*

Second compromise text for the AI simplification package, obtained by Euractiv, details beefed up inspection powers

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Right of Access** — https://overview.legal/topics/inzagerecht
  Data subject right to access their personal data
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Right of Access Procedures** — https://overview.legal/topics/article-15-gdpr-access-procedures
  This new topic is needed because Article 15 GDPR deserves dedicated coverage for its specific procedures, requirements, timelines, formats, and exceptions relat

---
Generated by overview.legal · https://overview.legal/topics/inspection-access-rights-obligations · 2026-08-22
