# Insurance — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/insurance
> Sources are cited per item. Verify against the official texts before relying on them.

Processing by insurance companies

## Overview

## Legal Framework

Insurance companies operate at the intersection of several data protection regimes. Under the GDPR, insurers processing personal data must establish a valid legal basis under Article 6(1), and where special categories of data are involved—particularly health data in claims assessment—Article 9 applies. Recital 52 permits derogations from the prohibition on processing special categories of data when Union or Member State law provides suitable safeguards, particularly in fields such as social protection and health security. This is the primary gateway enabling insurers to process health-related information for coverage and claims decisions.

The AI Act adds a further layer. Recital 96 designates insurance entities as deployers of certain high-risk AI systems who must conduct a fundamental rights impact assessment before deployment. Insurers using automated systems for risk assessment, pricing, or claims triage fall squarely within this scope.

Where insurers share data with public authorities—such as health insurance funds or tax authorities—the transfer must be expressly authorized by law, and the data subject must have been informed of the recipients, as required under Articles 13 and 14 GDPR.

## Key Developments

The CJEU's ruling in *Bara* (C-201/14, 1 October 2015) established a critical principle: national law authorizing data transfers between public bodies does not automatically satisfy the controller's information obligations. The Romanian government argued that Article 315 of Law No 95/2006 required tax authorities to transfer income data to health insurance funds. The Court rejected this, clarifying that the relevant provision did not actually encompass income data, and more fundamentally, that the existence of a legal basis for transfer cannot substitute for the Article 13/14 obligation to inform data subjects about recipients. Insurers receiving data from public sources must independently verify the scope of the authorizing law and ensure transparency.

The *Columbus* line of cases before Dutch courts addresses insurer claims registers (EVR). The Rechtbank Den Haag (C/09/608204 / HA RK 21-96) confirmed that registration in incident registers requires a sufficient factual basis—specifically, evidence that the claimant made intentionally false statements about the extent of damage. The court also clarified that Article 35 UAVG (Dutch GDPR Implementation Act) procedures are limited to granting or denying requests under Articles 15–22 GDPR; claims for immaterial damages or payout obligations are inadmissible in that procedural track.

The Dutch DPA's guidance on health insurance declaration data (*Toets Regeling declaratiegegevens ziektekostenverzekeraars*) and the EDPB's Guidelines 01/2022 on data subject access rights further define the boundaries: victims retain the freedom to withhold specific medical information from insurers, and the Medical Paragraph of the GBL code of conduct limits what medical information insurers may require.

## Practical Guidance

- **Verify the scope of statutory data-sharing mandates before processing.** *Bara* makes clear that a national law referencing transfers to insurers does not automatically cover all data categories transferred. Confirm that the specific data fields match what the authorizing provision actually permits.

- **Conduct a fundamental rights impact assessment before deploying AI systems** for underwriting, pricing, or claims assessment, as required by Recital 96 of the AI Act. Document the assessment prior to operational use.

- **Ensure claims register entries rest on demonstrable evidence of intentional misrepresentation.** The *Columbus* standard requires that insurers can substantiate that a claimant deliberately provided false information about damage scope before registering them in incident or fraud databases.

- **Respect data subjects' freedom to withhold medical information** beyond what is strictly necessary for claims handling. Limit medical data collection to the indicative guidelines in the GBL code, calibrated to expected claim duration.

- **Separate GDPR procedural requests from damages claims.** Article 35 UAVG proceedings address access, rectification, and erasure requests only; pursue compensation through the appropriate civil procedural track.

## Legislation (full text of key provisions)

### Recital 54 — public interest health data processing safeguards

*Source: GDPR, gdpr-rec-54-en, 2016-04-27 — https://overview.legal/posts/91623*

The processing of special categories of personal data may be necessary for reasons of public interest in the areas of public health without consent of the data subject. Such processing should be subject to suitable and specific measures so as to protect the rights and freedoms of natural persons. In that context, ‘public health’ should be interpreted as defined in Regulation (EC) No 1338/2008 of the European Parliament and of the Council (11), namely all elements related to health, namely health status, including morbidity and disability, the determinants having an effect on that health status, health care needs, resources allocated to health care, the provision of, and universal access to, health care as well as health care expenditure and financing, and the causes of mortality. Such processing of data concerning health for reasons of public interest should not result in personal data being processed for other purposes by third parties such as employers or insurance and banking companies.

### Recital 96 — fundamental rights impact assessment deployers

*Source: AI Act, aiact-rec-96-en, 2024-06-12 — https://overview.legal/posts/93874*

In order to efficiently ensure that fundamental rights are protected, deployers of high-risk AI systems that are bodies governed by public law, or private entities providing public services and deployers of certain high-risk AI systems listed in an annex to this Regulation, such as banking or insurance entities, should carry out a fundamental rights impact assessment prior to putting it into use. Services important for individuals that are of public nature may also be provided by private entities. Private entities providing such public services are linked to tasks in the public interest such as in the areas of education, healthcare, social services, housing, administration of justice. The aim of the fundamental rights impact assessment is for the deployer to identify the specific risks to the rights of individuals or groups of individuals likely to be affected, identify measures to be taken in the case of a materialisation of those risks. The impact assessment should be performed prior to deploying the high-risk AI system, and should be updated when the deployer considers that any of the relevant factors have changed. The impact assessment should identify the deployer’s relevant processes in which the high-risk AI system will be used in line with its intended purpose, and should include a description of the period of time and frequency in which the system is intended to be used as well as of specific categories of natural persons and groups who are likely to be affected in the specific context of use. The assessment should also include the identification of specific risks of harm likely to have an impact on the fundamental rights of those persons or groups. While performing this assessment, the deployer should take into account information relevant to a proper assessment of the impact, including but not limited to the information given by the provider of the high-risk AI system in the instructions for use. In light of the risks identified, deployers should determine measures to be taken in the case of a materialisation of those risks, including for example governance arrangements in that specific context of use, such as arrangements for human oversight according to the instructions of use or, complaint handling and redress procedures, as they could be instrumental in mitigating risks to fundamental rights in concrete use-cases. After performing that impact assessment, the deployer should notify the relevant market surveillance authority. Where appropriate, to collect relevant information necessary to perform the impact assessment, deployers of high-risk AI system, in particular when AI systems are used in the public sector, could involve relevant stakeholders, including the representatives of groups of persons likely to be affected by the AI system, independent experts, and civil society organisations in conducting such impact assessments and designing measures to be taken in the case of materialisation of the risks. The European Artificial Intelligence Office (AI Office) should develop a template for a questionnaire in order to facilitate compliance and reduce the administrative burden for deployers.

### Recital 52 — public interest special data processing exceptions

*Source: GDPR, gdpr-rec-52-en, 2016-04-27 — https://overview.legal/posts/91619*

Derogating from the prohibition on processing special categories of personal data should also be allowed when provided for in Union or Member State law and subject to suitable safeguards, so as to protect personal data and other fundamental rights, where it is in the public interest to do so, in particular processing personal data in the field of employment law, social protection law including pensions and for health security, monitoring and alert purposes, the prevention or control of communicable diseases and other serious threats to health. Such a derogation may be made for health purposes, including public health and the management of health-care services, especially in order to ensure the quality and cost-effectiveness of the procedures used for settling claims for benefits and services in the health insurance system, or for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes. A derogation should also allow the processing of such personal data where necessary for the establishment, exercise or defence of legal claims, whether in court proceedings or in an administrative or out-of-court procedure.

### Recital 58 — AI essential public services access

*Source: AI Act, aiact-rec-58-en, 2024-06-12 — https://overview.legal/posts/93798*

Another area in which the use of AI systems deserves special consideration is the access to and enjoyment of certain essential private and public services and benefits necessary for people to fully participate in society or to improve one’s standard of living. In particular, natural persons applying for or receiving essential public assistance benefits and services from public authorities namely healthcare services, social security benefits, social services providing protection in cases such as maternity, illness, industrial accidents, dependency or old age and loss of employment and social and housing assistance, are typically dependent on those benefits and services and in a vulnerable position in relation to the responsible authorities. If AI systems are used for determining whether such benefits and services should be granted, denied, reduced, revoked or reclaimed by authorities, including whether beneficiaries are legitimately entitled to such benefits or services, those systems may have a significant impact on persons’ livelihood and may infringe their fundamental rights, such as the right to social protection, non-discrimination, human dignity or an effective remedy and should therefore be classified as high-risk. Nonetheless, this Regulation should not hamper the development and use of innovative approaches in the public administration, which would stand to benefit from a wider use of compliant and safe AI systems, provided that those systems do not entail a high risk to legal and natural persons. In addition, AI systems used to evaluate the credit score or creditworthiness of natural persons should be classified as high-risk AI systems, since they determine those persons’ access to financial resources or essential services such as housing, electricity, and telecommunication services. AI systems used for those purposes may lead to discrimination between persons or groups and may perpetuate historical patterns of discrimination, such as that based on racial or ethnic origins, gender, disabilities, age or sexual orientation, or may create new forms of discriminatory impacts. However, AI systems provided for by Union law for the purpose of detecting fraud in the offering of financial services and for prudential purposes to calculate credit institutions’ and insurance undertakings’ capital requirements should not be considered to be high-risk under this Regulation. Moreover, AI systems intended to be used for risk assessment and pricing in relation to natural persons for health and life insurance can also have a significant impact on persons’ livelihood and if not duly designed, developed and used, can infringe their fundamental rights and can lead to serious consequences for people’s life and health, including financial exclusion and discrimination. Finally, AI systems used to evaluate and classify emergency calls by natural persons or to dispatch or establish priority in the dispatching of emergency first response services, including by police, firefighters and medical aid, as well as of emergency healthcare patient triage systems, should also be classified as high-risk since they make decisions in very critical situations for the life and health of persons and their property.

### Recital 158 — financial services authorities for AI oversight

*Source: AI Act, aiact-rec-158-en, 2024-06-12 — https://overview.legal/posts/93998*

Union financial services law includes internal governance and risk-management rules and requirements which are applicable to regulated financial institutions in the course of provision of those services, including when they make use of AI systems. In order to ensure coherent application and enforcement of the obligations under this Regulation and relevant rules and requirements of the Union financial services legal acts, the competent authorities for the supervision and enforcement of those legal acts, in particular competent authorities as defined in Regulation (EU) No 575/2013 of the European Parliament and of the Council (46) and Directives 2008/48/EC (47), 2009/138/EC (48), 2013/36/EU (49), 2014/17/EU (50) and (EU) 2016/97 (51) of the European Parliament and of the Council, should be designated, within their respective competences, as competent authorities for the purpose of supervising the implementation of this Regulation, including for market surveillance activities, as regards AI systems provided or used by regulated and supervised financial institutions unless Member States decide to designate another authority to fulfil these market surveillance tasks. Those competent authorities should have all powers under this Regulation and Regulation (EU) 2019/1020 to enforce the requirements and obligations of this Regulation, including powers to carry our ex post market surveillance activities that can be integrated, as appropriate, into their existing supervisory mechanisms and procedures under the relevant Union financial services law. It is appropriate to envisage that, when acting as market surveillance authorities under this Regulation, the national authorities responsible for the supervision of credit institutions regulated under Directive 2013/36/EU, which are participating in the Single Supervisory Mechanism established by Council Regulation (EU) No 1024/2013 (52), should report, without delay, to the European Central Bank any information identified in the course of their market surveillance activities that may be of potential interest for the European Central Bank’s prudential supervisory tasks as specified in that Regulation. To further enhance the consistency between this Regulation and the rules applicable to credit institutions regulated under Directive 2013/36/EU, it is also appropriate to integrate some of the providers’ procedural obligations in relation to risk management, post marketing monitoring and documentation into the existing obligations and procedures under Directive 2013/36/EU. In order to avoid overlaps, limited derogations should also be envisaged in relation to the quality management system of providers and the monitoring obligation placed on deployers of high-risk AI systems to the extent that these apply to credit institutions regulated by Directive 2013/36/EU. The same regime should apply to insurance and re-insurance undertakings and insurance holding companies under Directive 2009/138/EC and the insurance intermediaries under Directive (EU) 2016/97 and other types of financial institutions subject to requirements regarding internal governance, arrangements or processes established pursuant to the relevant Union financial services law to ensure consistency and equal treatment in the financial sector.

## Case law

### CJEU - C-667/21 - Krankenversicherung Nordrhein

*Source: GDPRhub, 2023-12-21 — https://overview.legal/posts/156362 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-667/21_-_Krankenversicherung_Nordrhein*

Facts — The Medical Service of Health Insurance (the controller) is Germany's public health insurance medical review service. It provides expert reports when people say they are unable to work, as well as for its own staff. Before becoming unable to work, the data subject worked for the controller. The insurance company that was paying their benefits requested an expert opinion from the controller. The controller obtained health information from the data subject's doctor in the form of a medical report, which was then distributed to the data subject's coworkers. The data subject believed that their medical data had been unlawfully processed and sought €20,000 in damages from the controller, who rejected the claims. According to the data subject, the evaluation should have been performed by another organisation in order to prevent coworkers from accessing their medical data. Furthermore, they considered the security procedures around their medical report's archiving to be inadequate. After being rejected at first and second (Landesarbeitsgericht Düsseldorf) instance, the the data subject appealed to the Federal Labour Court, who referred the case to the CJEU with the following questions: On the topic of health data 1) Does Article 9(2)(h) GDPR prohibit a medical service of a health insurance fund from processing its employee’s health data when it is a prerequisite for the assessment of that employee’s working capacity? 2) If the Court answers Question 1 in the negative (with the consequence that an exception to the prohibition on the processing of data concerning health laid down in Article 9(1) GDPR is possible under Article 9(2)(h) GDPR) in a case such as the present one, are there further data protection requirements, beyond the conditions set out in Article 9(3) GDPR, that must be complied with, and, if so, which ones? 3) If the Court answers Question 1 in the negative, does the permissibility or lawfulness of the processing of data concerning health depend on the fulfilment of at least one of the conditions set out in Article 6(1) GDPR? On the topic of non-material damages 4) Does Article 82(1) GDPR have a specific or general preventive character, and must that be taken into account in the assessment of the amount of non-material damage to be compensated at the expense of the controller or processor on the basis of Article 82(1) GDPR? 5) Is the degree of fault on the part of the controller or processor a decisive factor in the assessment of the amount of non-material damage to be compensated on the basis of Article 82(1) GDPR? In particular, can non-existent or minor fault on the part of the controller or processor be taken into account in their favour? Advocate General Opinion — Advocate General Manuel Sánchez Bordona requested that the Court answer that Articles 9(2)(h) and (3) of the GDPR, as well as Articles 82(1) and (3), be understood as: Not barring a medical service of a health insurance fund from processing data about the health of an employee of such service, when those data are required for determining that employee's working capacity. Allowing an exception to the prohibition on processing personal data relating to health where such processing is required for the purposes of assessing the employee's working capacity and complies with the principles outlined in Article 5 GDPR as well as one of the conditions for lawfulness outlined in Article 6 GDPR. Making the degree of fault on the part of the controller or processor have no bearing on establishing the liability of either of them or quantifying the amount of non-material damage to be compensated on the basis of Article 82(1) GDPR. Allowing the data subject's participation in the incident that gave rise to the compensation duty to trigger, (depending on the circumstances) an exemption from liability for the controller or processor provided for in Article 82(3) GDPR. Holding — On the topic of health data On the first question, the exception under Article 9(2)(h) GDPR applies to situations where a public organisation for medical expertise processes health data of one of its employees not as employer but as a medical service, under the condition that the concerned processing fulfils the expressly prescribed preconditions and guarantees in subparagraph (h) and Article 9(3) GDPR. The purpose of Article 9 GDPR is to ensure a high level of protection in case of processing personal data whose level of sensitivity is especially high, involving an especially strong intrusion into the fundamental rights guaranteed by Articles 7 and 8 of the Charter. Therefore, the list in Article 9(2) is exhaustive and among others Article 9(3) prescribes a number of guarantees in the case of processing based on subparagraph (h). However, there is no reason to assume that subparagraph (h) is limited to cases of processing by independent third parties. This is supported by Recital 52 which states that derogation from Article 9 is permitted when it is in the public interest to do so. The quality and cost-effectiveness of the procedures used for settling claims for benefits and services in the health-insurance system can be said to be in the public interest. On the second question, it was held that because the exemption applies, the controller can share the health data to other colleagues. When health data is processed under subparagraph (h) it also has to be processed according to Article 9(3) GDPR. Article 9(3) requirements cannot be read widely as it is explicit in its requirements. Therefore, there is no legal ground to require that colleagues of the data subject should be excluded from the processing. Having said this, member states can derogate from this rule and create higher national standards under the opening clause provided in Article 9(4) GDPR. If a Member State would do this, the CJEU recommends using the principles of intergrity and confidentiality outlined in Article 5(1)(f) and 32(1)(a) and (b) to justify it. These higher standards should be proportionate to allow the relevant organisations outlined in Article 9(2), who may not have the technical and organisational resources to fulfil these conditions, to process health data. It is for a national court to determine whether the technical and organisational measures, according to Article 32 GDPR, are satisfactory and sufficient. On the third question, if 9(2)(h) applies, it must not only comply with the provisions set out in the article, but also fulfill at least one legal bases from Article 6(1) to be considered lawful processing. This can be inferrred from Articles 5, 6 and 9 GDPR which are all included in the Chapter titled “Principles” and concern “Principles relating to processing of personal data”, “Lawfulness of processing” and “Processing of special categories of personal data”. Recital 51 GDPR expressly mentions that “the general principles and other rules of this Regulations should apply, in particular as regards the condition for lawful processing". The Court has also decided multiple times that the all processing of personal data has to comply with the preconditions of lawfulness in Article 6 and that all preconditions of Chapter II GDPR have to be complied with. On the topic of non-material damages On the fourth question, Article 82(1) GDPR has a compensatory instead of deterrant or penalising function. Compensation should fully compensate the damage suffered caused by the infraction of the GDPR. The Court reffered to the established case law that compensation can only be required based on Article 82 GDPR, when all of three cumulative conditions are fulfilled; 1) the existence of a damage, 2) an infringement of the Regulation, 3) a causal relationship exists between the infringement and the damage. The GDPR does not contain rules to define the amount of damages. National courts have to apply domestic rules of the individual Member States as far as the principles of equivalence and effectivity are complied with. Based on Recital 146, the Court states that the objective of this rule is to provide for “full and effective for the damage they have suffered”. Different from the sanctions in Articles 83 and 84, this sanction has not a penalising, but a compensating function. It has nevertheless an effect to deter from repeating the unlawful behaviour as well. On the fifth question, Article 82 GDPR needs causation (which is presumed unless the controller can prove otherwise) and does not require an assesment as to the degree of the controller's responsibility when calculating the amount of compensation awarded for a non-material damage. A controller has to compensate for a damage which arose as the consequence of an infringement of the GDPR. Recitals 4 to 8 GDPR indicate that the aim of the Regulation is to establish a balance between the rights of the controller and of the data subject. On one hand the responsibility of the controller depends on the existence on an infringement which is to be attributable to it. On the other, this is to be assumed unless the controller can prove that they have not caused it. An obligation to pay damages without causation would contradict the principle of legal certainty. However, once the existence of a damage is ascertained, Article 82 does not require national courts to take into account the gravity of the infringement or the extent of the controller's responsibility to quantify damages. Instead, the amount should be calculated to compensate fully the damage suffered.

### NSS - 1 As 183/2023-62

*Source: Supreme Administrative Court, 2026-08-04 — https://overview.legal/posts/184683 — original: https://gdprhub.eu/index.php?title=NSS_-_1_As_183/2023-62*

Facts — OAKS Consulting s.r.o. (the company) provided consulting services concerning market access conditions for medicinal products and medical devices. Pursuant to the Czech Act on Free Access to Information, it requested information from the General Health Insurance Company of the Czech Republic concerning the treatment of patients with iron deficiency and related conditions for the period from 1 January 2010 to 31 October 2017. The request covered 183 types of diagnoses, 18 types of medical procedures, 96 DRG codes and 13 types of medications. The company stated that it wished to analyse how specific diagnoses were treated, the number of patients treated, and the frequency of related medical procedures, in order to compare clinical practice against the relevant theoretical background. The public health insurer rejected the request on the grounds that granting it would require the creation of new information. Following an appeal by the company, the Prague Municipal Court overturned the decision. The public health insurer provided then the company with five separate tables regarding the diagnoses, diagnoses in conjunction with medical procedures, the DRG codes and prescribed medications. It aggregated the parameters of the provided data as follows: five-year age groups, dates were given only at the monthly level, and healthcare providers were classified into broad geographic regions. However, it refused to add a unique random identifier which would allow linking the individual records and tables pertaining to the same patient. The public health insurer considered that providing the code would result in the disclosure of special categories of personal data. The company lodged a complaint with the Czech DPA (UOOU), which rejected it. The company filed another appeal with the Municipal Court of Prague, which dismissed the appeal. It ruled that the combination of factors such as gender, year of birth, the time and place of care, diagnoses, medications, and medical procedures could, with the addition of other information, lead to the identification of specific patients. According to the court, the random identifier would result in pseudonymisation rather than anonymisation, so the information would remain personal data pursuant to Article 4(1) GDPR. The Municipal Court also relied on modern technical capabilities for linking different sources and on the availability of a large volume of information in the media and on social media. It cited the CJEU’s decision in the Breyer case (C-582/14), according to which in order to determine whether a person is identifiable, account must be taken of all the means that could reasonably be used, both by the controller and by any other person, to identify that person. It did not follow the approach taken by the General Court in Case T-557/20 (SRB v. EDPS), which the company had cited. It ruled that the data were pseudonymised and that the requested information could not be disclosed in its entirety. The company filed a cassation appeal with the Supreme Administrative Court, arguing that the information had been anonymised. It alleged that the addition of a random code with no independent meaning would not alter their anonymous nature. It claimed that the Municipal Court had not explained what specific additional information could be used to identify the patients and had relied on hypothetical scenarios. The company stated that it was objectively impossible to obtain such data through other requests in a detailed and non-aggregated form. It also argued that iron deficiency was not a rare disease, but was associated with a large number of patients and various conditions and that the data had undergone both randomisation and generalisation so the risk of identification was therefore low. Finally, the company emphasized that the tables without the random identifier could not be used effectively for the intended analysis. It further argued that the DPA and the Municipal Court had not adequately balanced the right of access to information against the right to the protection of personal data. The DPA argued that the random identifier constituted personal data when considered in conjunction with the health data to which it would be linked. It stated that the concept of personal data was not limited to information that directly identifies an individual nor did it require that all necessary additional information be held by the same entity. Replacing direct identifiers with a code did not anonymise the data, but made it pseudonymised. Moreover, it argued that certain categories contained a relatively small number of records and that combining them with other data could make it possible to select and identify a specific insured person and their treatment history. It further argued that, even if identifiability was relative, it should be assessed in relation to all potential information applicants and their ability to obtain contextual information. The Supreme Administrative Court stayed the proceedings in the case pending the CJEU’s decision in Case C-413/23 P (EDPS v. SRB). After the judgment was issued, the company argued that whether the data were pseudonymised or anonymised should be assessed in relation to the specific recipient of the data and the means that it could reasonably use. It stated that it did not have any means of re-identification and that only specific and practically available cross-referencing possibilities should be taken into account. Holding — The court relied on Case C-413/23 and noted that pseudonymised data under Article 4(5) GDPR does not automatically constitute personal data in relation to every person. Therefore, it examined whether the company had lawful means that could reasonably be expected to be used to identify the patients directly or indirectly. The court found that the tables, without the random identifier, did not allow for the identification of specific insured individuals. It held that the requested random identifier would link the records from the different tables and allow for the aggregation of information on the diagnoses, medical procedures, hospitalizations, and medications for the same patient during the eight-year period. Certain combinations of these data, along with age group, gender, and region, could be unique and allow for the identification of patients using information from public sources. It pointed out that although iron deficiency was a very common diagnosis and some tables contained a very large number of entries, other categories were not sufficiently generalised. According to the court, in certain cases, such as rare diseases, unusual treatment combinations, or particularly young or old age, knowing even a few details about a person could make it possible to identify the corresponding record. The risk was not negligible, given that information about a person’s age, gender, hospitalization, diagnosis, or treatment could be available in the media or on social media. Consequently, the court held that adding the random identifier, in conjunction with the data already provided, would make the dataset personal data in relation to the company under Article 4(1) GDPR, including health data falling under Article 9 GDPR. The court clarified that classifying the information as personal data was not sufficient in itself to reject the request. It noted that the right of access to the information must also be balanced against patients’ right to privacy through an assessment of suitability, necessity and proportionality. It determined that the decision not to provide the random identifier was appropriate for the protection of privacy, because without it, it was impossible to link the tables and identify individual patients. It was also deemed necessary because the company insisted on receiving that specific code along with the existing tables and there was no other procedure that would constitute a lesser infringement of its right to information. The court also recognized the public interest in accessing information related to the operation of the healthcare system, but ruled that this did not outweigh the need to protect the detailed health data of potentially hundreds of thousands of insured individuals. It concluded that the refusal to provide the code was therefore proportionate. The Supreme Administrative Court therefore upheld the Municipal Court’s ruling, but partially corrected its reasoning regarding the relative nature of identifiability and the need to conduct a proportionality review. It dismissed the appeal.

### X - BA-6S/221/2019

*Source: Regional Administrative Court Bratislava, 2025-06-25 — https://overview.legal/posts/132105 — original: https://gdprhub.eu/index.php?title=X_-_BA-6S/221/2019*

Facts — Sociálna poisťovňa, the social insurance agency (the controller), processes applications for foreign invalidity pensions and forwards related documents to the social insurance institutions of other EU Member States. A data subject applied for a Danish invalidity pension. On 22 October 2018, the controller sent the data subject's sensitive personal data (including health data, personal identification number and a Danish personal identifier) to the Danish social insurance institution by ordinary (uninsured, untracked) second-class mail rather than by registered mail. The data subject could not confirm delivery and, in November 2018, filed a request with the Slovak DPA alleging that sending sensitive data by ordinary mail, without any proof of dispatch or protection against loss, violated their data protection rights. The controller resent the documents by the same method in December 2018. The DPA's first-instance decision (13 June 2019) found that the controller had violated Article 24(1) in conjunction with Article 32(1) and (2) GDPR, because sending sensitive personal data by ordinary rather than registered mail did not ensure a level of security appropriate to the risk. The DPA ordered the controller to use registered mail for such dispatches going forward and imposed a fine of €50,000. The controller's appeal was rejected, and the Slovak DPA president upheld the first-instance decision. The controller then brought an action before the Regional Administrative Court Bratislava, arguing among other things that: the parcel had in fact been delivered (as confirmed by the Danish institution by email), registered mail offers no greater protection against loss of confidentiality than ordinary mail, only one data subject was concerned and no damage had occurred and the decision's operative part improperly referred to the data of pension applicants generally, not just the individual data subject who had filed the complaint. Holding — The court did not rule on the substance of the security measures dispute, since it found the DPA's decision unreviewable on procedural grounds. First, the court held that the operative part of the DPA's decision was contradictory and imprecise. The administrative proceedings had been triggered by, and the evidence had concerned, an alleged violation of rights of one specific data subject (loss of their parcel). However, the decision extended the finding of violation to the controller's general practice of sending all pension applicants' data by ordinary mail. The court noted that a systemic pattern affecting other data subjects could, at most, be taken into account as an aggravating circumstance when setting the fine, but it could not itself form part of the sanctioned conduct in a proceeding limited to one individual's complaint. Second, the court found that the DPA had failed to properly assess evidence submitted by the controller showing that the parcel had actually been delivered to the Danish institution. The DPA only addressed this evidence for the first time in its written observations in the court proceedings, not in the administrative decision itself, even though the decision's entire reasoning rested on the (contested) premise that the parcel had been lost. Third, the court observed that the fine had been imposed under a provision of the national Data Protection Act that only permits fines for breaches of Articles 25 to 32 GDPR, whereas the DPA's decision had also relied on Article 24(1) GDPR, which is not covered by that provision. Because of these defects, the court annulled the DPA's decision and remanded the case for further proceedings, without addressing the parties' remaining arguments on the merits . The court instructed the DPA to first clearly establish the specific conduct underlying the alleged offence and then decide the case again, addressing all evidence submitted by the controller. The court awarded the controller full reimbursement of costs.

### VG Ansbach - 14 K 19.01274

*Source: VG Ansbach, 2021-09-22 — https://overview.legal/posts/158450 — original: https://gdprhub.eu/index.php?title=VG_Ansbach_-_14_K_19.01274*

Facts — In December 2018, the data subject filed with the DPA (the defendant in this case), a complaint under Article 77 GDPR against a lawyer who had represented the data subject in a traffic accident, before he terminated the mandate. In court proceedings after this termination, in which the lawyer's fee claim was at issue, the lawyer had submitted to the court a volume of documents containing extracts of all correspondence with the opposing insurance company, in which personal data and business secrets had not been blacked out. Since data subject had not released the lawyer from data protection and confidentiality, the data subject perceived this to be a breach of confidentiality. By letter dated 30 March 2016, the data subject contacted the lawyer regarding this breach. The data subject also complained to the Court about the lawyer's conduct, but this did not lead to any action undertaken by the Court. DPA acknowledged receipt of the complaint by letter dated 7 January 2019. In response to this complaint dated 31 May 2019, the DPA informed the data subject that it did not see any breach of data protection law in the conduct complained of and that there was therefore no reason for further supervisory measures pursuant to Article 58 GDPR. The lawyer was under no obligation to make the data subject's data unidentifiable when forwarding it to the court. According to the DPA, this processing was legitimised under Article 6(1)(f) GDPR since the pursuit of fee claims undoubtedly constitutes a legitimate interest of the lawyer. Moreover, the DPA held that, insofar as the personal data transferred were data belonging to special categories of data within the meaning of Article 9(1) GDPR (such as information on the consequences of the accident/injuries suffered by the data subject in the accident), the additional requirements of Article 9(2) GDPR were also met, as the transfer had been necessary for the assertion of legal claims. The data subject then brought the action to the Court, requesting her complaint to be accepted pursuant to Article 77 GDPR. Holding — The Court dismissed the action and found that the data subject's complaint of 29 December 2018 did not constitute a complaint under Article 77 GDPR, but a "submission" within the meaning of Article 28(4) of Directive 95/46/EC. In the present case the data subject claimed that a data protection breach occured in March 2016. As the GDPR has only been applicable since 25 May 2018, the conduct of the lawyer could therefore not have infringed the GDPR, as it was not yet applicable at that time. There was no transitional provision in German law stipulating that the GDPR also applied to facts before the above-mentioned date. The Court noted that the entry-into-force of the GDPR according to Article 99 GDPR represents a clear break between the old and the new law. Since the German legislator - unlike the Austrian legislator, for example - did not enact a transitional provision which, under certain circumstances, ordered the application of the new law also to breaches of data protection provisions committed before its entry into force, breaches committed before that date are fully subject to the old law.

### SO Warszawa - III C 904/23

*Source: Regional Court in Warsaw, 2026-02-16 — https://overview.legal/posts/53100 — original: https://gdprhub.eu/index.php?title=SO_Warszawa_-_III_C_904/23*

Facts — The Financial Ombudsman’s office (the controller) sent a letter containing the name, the address, and the case reference number of a customer (the data subject) to 28,366 public institutions and entities registered on an official government platform in February 2021. The data subject demanded compensation for the unauthorised disclosure of his personal data from the controller in November 2021. The controller refused to accept liability for the incident. The supervisory authority issued the controller a reprimand in September 2022 for disclosure of personal data in violation of Article 6(1) GDPR. The data subject brought a lawsuit for damages under Article 82 GDPR before the Regional Court in Warsaw in August 2023. The data subject stated that they had experienced severe stress and lost the sense of security and control over their data as a result of the unauthorised disclosure of the letter. The controller argued it was not at fault for the incident as it was caused by a temporary IT system failure that the controller could not have foreseen. Holding — The Regional Court in Warsaw held that the controller was undoubtedly liable for the unauthorised disclosure of the data subject’s personal data pursuant to Article 82 GDPR: the controller was an administrator for the government platform and had not taken adequate measures to secure the data. Second, the court held that the data subject had suffered non-material damage in connection with the aforementioned incident. It took into account that the data had been disclosed to numerous entities. In addition, the deterioration of the data subject’s mental state was confirmed by a witness. The court awarded the data subject PLN 40,000 in damages. It considered the data subject’s claim of PLN 50,000 to be excessive in light of established case law.

### Judgment of the Court (Second Chamber) of 4 May 2017.#Valsts policijas Rīgas reģiona pārvaldes Kārtības policijas pārvalde v Rīgas pašvaldības SIA "Rīgas satiksme".#Request for a preliminary ruling from the Augstākās tiesas Administratīvo lietu departaments.#Reference for a preliminary ruling — Directive 95/46/EC — Article 7(f) — Personal data — Conditions for the lawful processing of personal data — Concept of ‘necessity for the realisation of the legitimate interests of a third party’ — Reques

*Source: Court of Justice of the European Union, C-13/16, 2017-05-04 — https://overview.legal/posts/132348 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62016CJ0013*

In Case C-13/16, the Court of Justice of the European Union (Second Chamber) addressed a preliminary ruling from the Latvian Supreme Court in proceedings between the Riga Regional Police Board and the municipal transit company SIA "Rīgas satiksme" concerning whether the police could compel disclosure of personal data identifying the perpetrator of a road accident. The Court interpreted Article 7(f) of Directive 95/46/EC, holding that while a third party's request to process personal data for the purpose of pursuing a legal claim may fall within the scope of legitimate interests, the directive does not impose an obligation on the data controller to grant such a disclosure request, as the controller must balance the legitimate interests against the data subject's fundamental rights and freedoms. No fine was imposed, as the ruling solely provided interpretative guidance on the conditions for lawful processing under the directive.

### Judgment of the Court (Third Chamber) of 21 December 2023.#ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, Körperschaft des öffentlichen Rechts.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 6(1) – Conditions for lawful processing – Article 9(1) to (3) – Processing of special categories of data – Data concerning heal

*Source: Court of Justice of the European Union, C-667/21, 2023-12-21 — https://overview.legal/posts/132276 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0667*

The CJEU (Third Chamber) ruled on a preliminary reference from the Bundesarbeitsgericht in a case where ZQ sought compensation from his employer, Medizinischer Dienst der Krankenversicherung Nordrhein, for allegedly unlawful processing of his health data in connection with an assessment of his working capacity. The Court addressed the conditions under which a health insurance medical service may lawfully process special categories of health data of its own employees under GDPR Articles 6(1) and 9(2)(h)/(3), and clarified the scope of the right to compensation for non-material damage under Article 82(1), including the relevance of the controller's negligence. No fine was imposed, as the ruling concerns the interpretation of GDPR provisions for the referring court's application.

### SG Nürnberg - S 5 SF 65/24 DS

*Source: Social Court Nuremberg, 2026-06-10 — https://overview.legal/posts/122874 — original: https://gdprhub.eu/index.php?title=SG_Nürnberg_-_S_5_SF_65/24_DS*

Facts — The data subject (a child born in 2018), represented by her parents, was insured with the controller (a statutory health insurance provider) and participated in its digital bonus programme. The bonus programme was managed via an app. To handle the information technology operations of this programme, the controller hired the processor (an IT service provider), establishing a data processing agreement under Article 28 GDPR alongside specific information security guidelines. To provide these services, the processor utilised "MOVEit Transfer," a market-leading file transfer software developed by Progress Software Corp. On 31 May 2023, the software developer publicly announced a critical, previously unknown "zero-day" vulnerability in the software (later assigned CVE-2023-34362). At that exact moment, no security patch was available. On the very same day, 31 May 2023, the processor – alongside thousands of other companies worldwide – became the victim of a global cyberattack carried out by the hacker group "Clop." The hackers exploited this zero-day vulnerability to install a "web-shell" backdoor (typically named human2.aspx), bypassing authentication to exfiltrate database records. The compromised data included the data subject's first and last name, health insurance number, bonus points balance, and a bank account number (IBAN) belonging to her mother. No medical, health, or social security data was exfiltrated. On 1 June 2023, the developer released a security patch, which the processor installed immediately. On 2 June 2023, the German Federal Office for Information Security (BSI) issued a formal IT security warning (No. 2023-240133-1100, Version 1.1). The BSI classified the IT threat level as "3 / Orange" (business-critical), confirming active exploitation with data exfiltration. The BSI recommended immediately blocking all HTTP and HTTPS traffic to MOVEit environments, checking for specific Indicators of Compromise (IoCs) in the web server directories, and applying the newly released patch before reconnecting systems to the network. On 16 June 2023, the processor informed the controller about the incident. On 17 June 2023, the controller issued a public press release confirming that its external service provider for the bonus programme had been targeted on 31 May 2023. The release stated that the security vulnerability had been closed, that there was never any connection to the controller's internal IT systems, and that relevant supervisory authorities had been notified. The controller subsequently notified the data subject's parents. On 27 March 2024, the data subject, via legal counsel, sent a formal warning letter to the controller demanding an injunction, a declaration of liability for all potential future damages, and non-material damages of at least €3,000. Following the controller's refusal, the data subject filed a lawsuit with the Nuremberg Social Court (Sozialgericht Nürnberg), later expanding the claim to the processor as a joint defendant. Holding — The Court dismissed the lawsuit as partly inadmissible and otherwise unfounded, establishing the following legal principles: First, the Court held that a successful third-party cyberattack does not establish an irrebuttable presumption that a controller or processor failed to implement appropriate security measures under Article 32(1) GDPR and Article 5(1)(f) GDPR. To escape liability under Article 82(3) GDPR, an operator must prove they implemented robust baseline security controls (such as multi-factor authentication, encryption, and lockout policies) and applied a security patch immediately upon its release by the vendor, even if this occurred before formal alerts were issued by national IT security authorities. Second, the Court held that a claim for non-material damages under Article 82(1) GDPR based on the fear or distress of future data misuse cannot be established if the data subject is a minor who has no subjective knowledge or cognitive awareness of the data breach. Furthermore, if the compromised financial data (such as an IBAN) does not belong to the data subject personally, there is no direct risk of financial harm to them, rendering the alleged fear of financial damage unfounded. Third, the Court held that an injunction claim is inadmissible due to a lack of specificity if it merely demands that a controller stop making personal data accessible to third parties without implementing "state-of-the-art" security measures, without specifying the concrete technical or organisational measures the controller is required to take. Fourth, the Court held that a declaratory claim for potential future material damages is inadmissible under national procedural law (§ 55(1) SGG) if there is no realistic probability of future financial harm, particularly because the compromised bank account belonged to a third party (the mother) and the software vulnerability was immediately patched.

### BVwG - W252 2247042-1

*Source: Federal Administrative Court, 2024-01-22 — https://overview.legal/posts/132104 — original: https://gdprhub.eu/index.php?title=BVwG_-_W252_2247042-1*

Facts — The controller, an Public Employment Service Austria, processed the personal data of the data subject in connection with his file. On 21 February 2019, 15 March 2019 and 25 November 2020, the data subject sent access requests to the controller by fax, each time explicitly insisting on delivery of the response by registered post, addressed personally and refusing delivery by email. With the November 2020 request, he also sent a blank DVD-R by post, asking the controller to copy the data onto it. The controller responded to each request with a printed access response sent by registered letter, the responses were substantially identical and the DVD-R was returned unused. The controller's usual practice is to provide access electronically through an online account. The access responses included the data subject's basic data, insurance and benefit periods and a chronological log of case notes "Informationen/Gesprächsnotizen/Vermerke", which listed attachments where relevant but did not include copies of entire documents. The data subject was aware of the content of the documents listed as attachments, since he himself had submitted them to the controller. None of the three responses referred to a specific case note dated 17 October 2018, recording a phone call between the controller and the data subject's family doctor about his health. The data subject repeatedly and specifically requested this note. The controller only produced it during the proceedings before the Federal Administrative Court, in a submission of 29 June 2023, which the Court forwarded to the data subject in July 2023. The data subject lodged a complaint with the Austrian DPA in February 2020, arguing that the access provided was deficient because copies of documents were missing, unexplained abbreviations were used, the response was not delivered in a common electronic format and it contained incorrect data. The DPA partially upheld the complaint (ordering the controller to explain certain abbreviations) but rejected the remainder, holding that the right of access does not include a right to copies of documents. The data subject appealed only the rejecting part of the DPA's decision to the Federal Administrative Court. Holding — First, the court held that the data subject was entitled, in the specific circumstances, to receive a copy of the case note of 17 October 2018. Citing CJEU case-law, the court noted that "personal data" must be interpreted broadly and that a "copy" means a faithful reproduction, not a mere general description or reference to categories of data. Because the data subject had specifically identified and requested this particular note as early as February 2019, the controller's asserted practice of a staged, multi-step access process could not be relied on to justify withholding it. However, the court held that this part of the complaint became moot once the controller supplied the missing note during the court proceedings, since the data subject's interest in access was thereby satisfied, even though the note reached him via the court rather than directly from the controller. Referring to national case-law, the court noted that there is no separate right to a formal declaration that a past infringement of the right of access occurred, once the substantive right has been satisfied. It also stated that any dispute about the accuracy of the date shown on the note was a matter for the right to rectification, not the right of access. Second, the court held that the right of access does not, in general, entitle a data subject to copies of entire documents or file attachments. Reproduction of extracts or whole documents is only necessary where needed to make the disclosed personal data intelligible. Since the data subject already knew the content of the referenced attachments (he had submitted them himself and had annotated copies of the responses identifying their content), the court held that further disclosure of the attachments was not necessary for comprehensibility and the access already given was complete. Third, the court rejected the data subject's argument that the access responses should have been delivered in a "common electronic format." While the GDPR provides that a request submitted electronically should, in principle, be answered electronically unless the data subject indicates otherwise, the court held that the data subject himself had explicitly and repeatedly requested delivery by registered post rather than email and this constituted "otherwise" within the meaning of that provision. The court also held that there is no obligation on a controller to use a physical data carrier (such as the data subject's own DVD-R) to provide access. It rejected the argument that paper delivery was designed to prevent the data being machine-searchable, noting that the right of access, unlike the right to data portability, does not guarantee a right to further processing of the data. The appeal was dismissed and the court declared that an appeal on points of law (Revision) was not admissible, since the relevant questions were already settled by existing CJEU and national supreme administrative court case-law.

### SMARANDA BARA ET AL. V. PRESEDINTELE CASEI NATIONALE DE ASIGURARI DE SANATATE (CNAS) ET AL., 1.10.2015 (“BARA”)

*Source: CJEU, 2015-10-01 — https://overview.legal/posts/6149 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0201&ref=6149*

Principle of fairness and lawfulness: The requirement of fair processing laid down in Article 6 of Directive 95/46 requires a public administrative body to inform the data subjects of the transfer of their data to another public administrative body for the purpose of their processing by the latter in its capacity as recipient of those data. (¶¶ 34–38)

### SMARANDA BARA ET AL. V. PRESEDINTELE CASEI NATIONALE DE ASIGURARI DE SANATATE (CNAS) ET AL., 1.10.2015 (“BARA”)

*Source: CJEU, 2015-10-01 — https://overview.legal/posts/5957 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0201*

Right to be informed: National law that does not require the specific transfer involved in the case cannot constitute “prior information” under Article 10 of Directive 95/46 (information requirement where data is collected from the data subject), enabling the controller to dispense with his obligation to inform the data subject of the recipients of the data. (¶¶ 34–38). Article 11 (information requirement where data is not collected from data subject) requires that specified information be provi

### Spanish court reviews DPA decision on KFC Spain website privacy information and DPO

*Source: National Court, 2026-07-16 — https://overview.legal/posts/184690 — original: https://gdprhub.eu/index.php?title=AN_-_SAN_3154/2026*

Facts — In May 2021, a data subject lodged a complaint with the DPA against KFC Restaurants Spain, S.L.U., the controller, concerning the processing of personal data through its website. The data subject claimed that the privacy information applicable to users in the EEA was not easily accessible, as the main privacy link led to a global policy. The data subject also alleged that users could not create an account without apparently accepting promotional communications, that the registration form did not correctly link to the privacy policy and that the controller had not appointed a data protection officer. The complaint further identified deficiencies in the privacy information, including insufficient details about the identity of the controller, recipients, international transfers and retention periods. During the investigation, the controller acknowledged that certain links and checkbox descriptions had been incorrectly configured and undertook to correct them. It maintained, however, that its privacy information was provided through several interconnected documents and that it was not required to appoint a DPO. According to the controller, it did not engage in profiling, its marketing communications were based on opt-in consent and the processing of personal data was ancillary to its restaurant business. The DPA found that the information provided on the website was excessively generic and did not comply with Article 13 GDPR. It imposed a €5,000 fine and ordered the controller to bring its website into compliance. The DPA also concluded that the controller’s processing activities required the appointment of a DPO under Article 37(1)(b) GDPR. It imposed a further €20,000 fine and ordered the controller to appoint a DPO. The controller appealed both the sanctioning decision and a subsequent resolution requiring it to demonstrate that it had implemented corrective measures. Holding — The Court dismissed the appeal and upheld the total fine of €25,000. Regarding Article 13 GDPR, the Court found that the controller’s privacy information was excessively generic and did not clearly explain the purposes, legal bases and relevant circumstances of the processing. It also held that the DPA was not limited to investigating only the exact issues identified in the initial complaint. The €5,000 fine was proportionate despite the controller’s subsequent corrective action. Regarding Article 37(1)(b) GDPR, the Court held that the controller was required to appoint a DPO. Although its primary business was the provision of restaurant services, the processing of customer data was inseparable from its online ordering, marketing, loyalty and customer-management activities. The processing also involved regular and systematic monitoring, as the controller continuously collected data such as customer preferences, browsing history, IP addresses, cookies and geolocation for commercial and operational purposes. Considering the number of data subjects, the volume and variety of data, the duration of the processing and its nationwide scope, the Court concluded that the processing was carried out on a large scale.

## Guidance

### Report on stakeholder event on anonymisation and pseudonymisation of 12 December 2025

*Source: EDPB, report-on-stakeholder-event-on-anonymisation-and-en, 2026-02-18 — https://overview.legal/posts/125688 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/report-on-stakeholder-event-on-anonymisation-and_en*

Report on stakeholder event on anonymisation and pseudonymisation of 12 December 2025 1. Background The EDPB organise d a remote stakeholder event on 12 December 2025 to collect stakeholders’ input on anonymisation and pseudonymisation , following the Court of Justice of the European Union ( “ CJEU ” ) judgment in case EDPS v SRB 1 . The objective was to engage with stakeholders to inform the EDPB’s ongoing work on its guidelines 01/2025 on pseudonymisation and f orthcoming guidelines on…

### Guidelines 07/2020 on the concepts of controller and processor in the GDPR

*Source: EDPB, edpb-guidelines-on-the-concepts-of-controller-and-processor-in-the-gdpr, 2021-07-07 — https://overview.legal/posts/38069 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-072020-on-the-concepts-of-controller-and-processor-in-the-gdpr_en*

The concepts of controller, joint controller and processor play a crucial role in the application of the General Data Protection Regulation 2016/679 (GDPR), since they determine who shall be responsible for compliance with different data protection rules, and how data subjects can exercise their rights in practice. The precise meaning of these concepts and the criteria for their correct interpretation must be sufficiently clear and consistent throughout the European Economic Area (EEA). The conc...

### Guidelines 01/2020 on processing personal data in the context of connected vehicles and mobility related applications

*Source: EDPB, guidelines-012020-on-processing-personal-data-in-the-context-of-connected-en, 2021-03-09 — https://overview.legal/posts/126056 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-012020-on-processing-personal-data-in-the-context-of-connected_en*

Adopted 1 Guidelines 0 1 / 2020 on processing personal data in the context of connected vehicles and mobility related applications Version 2 .0 Adopted on 9 March 2021 Adopted 2 Version h istory Version 2.0 9 March 2021 Adoption of the Guidelines after public consultation Version 1.0 2 8 January 2020 Adoption of the Guidelines for public consultation Adopted 3 Adopted 4 The European Data Protection Board Having regard to Article 70 (1 ) ( e) of the Regulation 2016/679/EU of the European…

### Guidelines 1/2020 on processing personal data in the context of connected vehicles and mobility related applications

*Source: EDPB, edpb-guidelines-on-processing-personal-data-in-the-context-of-connected-vehicles-and-mobility-rel, 2020-01-01 — https://overview.legal/posts/38135*

The EDPB adopted Guidelines 1/2020 to provide guidance on the application of the GDPR to the processing of personal data in connected vehicles and mobility-related applications. The guidelines address key issues including data minimisation, data protection by design and by default, transparency obligations, data subjects' rights, security, third-party data sharing, and international transfers, with practical case studies covering services provided by third parties, eCall, accidentology, anti-theft measures, and rental car information. The document does not impose fines but offers recommendations to help controllers and processors in the automotive ecosystem comply with their GDPR obligations.

### Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020

*Source: EDPB, edpb-guidelines-on-data-protection-by-design-and-by-default, 2020-10-20 — https://overview.legal/posts/38054 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-42019-on-article-25-data-protection-by-design-and-by-default_en*

The European Data Protection Board (EDPB) adopted these guidelines (Version 2.0) to provide interpretive guidance on Article 25 of the GDPR, which mandates data protection by design and by default. The guidelines address controllers' obligations to implement appropriate technical and organizational measures and necessary safeguards into processing operations, including the dimensions of data minimization required by default. No fines or enforcement actions are at issue, as this is a guidance document intended to assist controllers in complying with their Article 25 obligations.

### Opinion 11/2019 on the draft list of the competent supervisory authority of the Czech Republic regarding the processing operations exempt from the requirement of a data protection impact assessment (Article 35(5) GDPR)

*Source: EDPB, opinion-112019-on-the-draft-list-of-the-competent-supervisory-en, 2019-07-12 — https://overview.legal/posts/126216 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-112019-on-the-draft-list-of-the-competent-supervisory_en*

Adopted 1 Opinion 11 /2019 on the draft list of the com petent supervisory authority of the Czech Republic regarding the processing operations exempt from the requirement of a data protection impact assessment (Article 35(5) GDPR) Adopted on 10 July 2019 Adopted 2 Adopted 3 The European Data Protection Board Having regar d to Article 63, Article 64(2) and Article 35 (1) , (5), (6) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of…

### Opinion 6/2024 on the draft list of the Latvian SA on pro-cessing operations exempt from the data protection impact assessment requirement (Art. 35.5 GDPR)

*Source: EDPB, opinion-62024-on-the-draft-list-of-the-latvian-sa-on-pro-en, 2024-04-18 — https://overview.legal/posts/125762 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-62024-on-the-draft-list-of-the-latvian-sa-on-pro_en*

Adopted 1 Opinion 6/2024 on the draft list of the Latvian SA on pro- cessing operations exempt from the data protection impact assessment requirement (Art. 35.5 GDPR) Adopted on 16 April 2024 Adopted 2 Adopted 3 The European Data Protection Board Having regard to Article 63, Article 64 (2) and Article 35 (1), (5) and (6) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data…

### Guidelines 01/2022 on data subject rights - Right of access

*Source: EDPB, edpb-guidelines-on-data-subject-rights---right-of-access, 2023-04-17 — https://overview.legal/posts/38055 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-012022-on-data-subject-rights-right-of-access_en*

The right of access of data subjects is enshrined in Art. 8 of the EU Charter of Fundamental Rights. It has been a part of the European data protection legal framework since its beginning and is now further developed by more specified and precise rules in Art. 15 GDPR.

## Enforcement decisions

### LÍNEA DIRECTA ASEGURADORA, S.A.: Insufficient legal basis for data processing

*Source: Spanish Data Protection Authority (aepd), 2024-12-23 — https://overview.legal/posts/48643 — original: https://www.enforcementtracker.com/ETid-2528*

The Spanish DPA has imposed a fine of EUR 300,000 on LÍNEA DIRECTA ASEGURADORA, S.A.. A data subject had filed a complaint with the DPA stating that they had inquired about a car insurance quote with Línea Directa and were subsequently contacted by one of Línea Directa's processors. Without their consent, the processor had accessed their driving license points via the website of a traffic authority.

### Motor insurance center: Non-compliance with general data processing principles

*Source: Deputy Data Protection Ombudsman, 2021-12-16 — https://overview.legal/posts/47127 — original: https://www.enforcementtracker.com/ETid-1012*

The Finnish DPA has fined a motor insurance center EUR 52,000. The controller had excessively requested patient data from within the healthcare system for the purpose of processing claims. However, much of the data was not necessary to process the claims. For example, the DPA found that the motor vehicle insurance center had also collected patient visit notes to determine whether the health care provider had billed for visits that were not related to the examination or treatment of injuries caus

### CEDICO, CENTRO DE DIAGNÓSTICO POR LA IMÁGEN, S.L.: Non-compliance with general data processing principles

*Source: Spanish Data Protection Authority (aepd), 2021-09-20 — https://overview.legal/posts/46959 — original: https://www.enforcementtracker.com/ETid-844*

The Spanish DPA (AEPD) has imposed a fine on CEDICO, CENTRO DE DIAGNÓSTICO POR LA IMÁGEN, S.L.. The data subject filed a complaint with the AEPD. He had requested an MRI scan of his knee due to an accident at work. In addition, he had contacted his insurance company in order to obtain a sick leave. The insurance company then contacted the controller, who transmitted the data subject's medical records. In doing so, the controller also provided the insurer with the report of a previous MRI scan of

### Linea Directa Aseguradora: Insufficient legal basis for data processing

*Source: Spanish Data Protection Authority (aepd), 2019-12-03 — https://overview.legal/posts/46261 — original: https://www.enforcementtracker.com/ETid-146*

The insurance company has sent advertising e-mails for the 'Reto Nuez' platform without the required consent.

### ACTIVE ASSURANCES (car insurer): Insufficient technical and organisational measures to ensure information security

*Source: French Data Protection Authority (CNIL), 2019-07-25 — https://overview.legal/posts/46179 — original: https://www.enforcementtracker.com/ETid-64*

Large amount of customer accounts, clients' documents (including copies of driver's licences, vehicle registration, bank statements and documents to determine whether a person had been the subject of a licence withdrawal) and data were easily accesible online. The CNIL, between others, critizised the password management (unauthorized access was possible without any authentication).

### Bank: Insufficient legal basis for data processing

*Source: Bulgarian Commission for Personal Data Protection (KZLD), 2019-01-17 — https://overview.legal/posts/46123 — original: https://www.enforcementtracker.com/ETid-8*

A bank gained personal data concernign a student wihtout a legal basis.

### AEPD fines Alkora, S.A. for ransomware breach exposing 40,000 individuals' data

*Source: AEPD (Spain), 2026-07-16 — https://overview.legal/posts/53655 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS-00020-2025*

Facts — Alkora, S.A., the controller, is an insurance broker that was victim of a ransomware attack. The controller notified the DPA of a personal data breach after a ransomware attack affected its servers, databases, email systems and employee devices. The controller first estimated that 25,000 persons were affected. It later stated that the incident had affected around 40,000 persons, including 75 minors. The incident affected confidentiality, availability and integrity. The attacker encrypted systems and exfiltrated between 3.5 and 4 TB of information from the document management server. The affected data included identification and contact data, ID numbers, dates of birth, financial and insurance data, bank account numbers, health data, employee data and access credentials. The controller also processed data relating to minors in accident claims. A data subject complained to the DPA after being informed that their personal data had been exposed. The data subject was concerned about identity theft and requested additional information from the controller. During the investigation, the DPA found that the controller had known that its IT systems faced an extreme cybercrime risk before the breach. The forensic report could not determine the initial entry point because the servers had been encrypted, but it showed that attackers could move laterally through the infrastructure, obtain privileged access, install tools, exfiltrate data and encrypt systems. The controller had carried out a risk analysis in 2019, but this document concluded that no DPIA was necessary. After the breach, a later analysis found that a DPIA was necessary for treatments involving health data and minors. The controller did not prove that it had carried out the required DPIA. Holding — The DPA held that the controller violated Article 5(1)(f) GDPR. It considered that the controller had failed to ensure the integrity and confidentiality of the personal data under its responsibility. The DPA emphasised that the principle in Article 5(1)(f) GDPR is not limited to the existence of isolated security measures. Rather, the controller must implement adequate technical and organisational measures capable of ensuring that personal data is protected against unauthorised or unlawful processing, loss, destruction or damage. The DPA rejected the controller’s argument that the attack was an external criminal act that could not be attributed to it. The DPA found that the controller was aware of an extreme cyber risk and that its internal vulnerabilities and security posture allowed the attackers to move through the systems, access personal data and encrypt files. The DPA therefore considered that the controller’s measures were clearly insufficient. The DPA also held that the controller violated Article 35 GDPR. The controller processed high-risk categories of data, including health data and data concerning minors. In these circumstances, it should have carried out a DPIA before the processing. The DPA found that the controller’s 2019 risk analysis wrongly concluded that no high risk existed, while its later documentation acknowledged that a DPIA was necessary. The DPA proposed a fine of €150,000 for the infringement of Article 5(1)(f) GDPR and €100,000 for the infringement of Article 35 GDPR, totalling €250,000. The controller paid voluntarily without acknowledging liability, obtaining a 20% reduction under Spanish Administrative Law (39/2015). The final payable amount was therefore €200,000. The DPA also ordered the controller, under Article 58(2)(d) GDPR, to prove within three months from the enforceability of the decision that it had carried out the mandatory DPIA required under Article 35 GDPR.

### Social Insurance Agency: Insufficient technical and organisational measures to ensure information security

*Source: Slovak Data Protection Office, 2025-12-30 — https://overview.legal/posts/49105 — original: https://www.enforcementtracker.com/ETid-109*

Applications for social benefits from Slovak citizens were sent by post to foreign authorities. These were lost by post, with the result that the whereabouts of these personal data could not be clarified.

## Recent developments

### Over 40,000 CRIF queries: Klarna, banks and telecoms entangled in CRIF network

*Source: noyb - European Center for Digital Rights, 2025-09-25 — https://overview.legal/posts/53137 — original: https://noyb.eu/en/over-40000-crif-queries-klarna-banks-and-telecoms-entangled-crif-network*

Credit Scoring Following an initiative by noyb, more than 2,400 affected individuals requested their data from the credit agency CRIF and have now received it. An evaluation by noyb shows that many well-known Austrian companies, such as Erste Bank, Verbund and Drei, evaluate their customers using CRIF data. Some companies, such as T-Mobile, the online retailer Otto, and the insurance company Allianz, also seem to provide their customer data to CRIF. The initial evaluation of over 40,000 queries

### The Italian SA fined Poste Vita for data breach

*Source: European Data Protection Board, 2026-06-04 — https://overview.legal/posts/53061 — original: https://www.edpb.europa.eu/news/the-italian-sa-fined-poste-vita-for-data-breach_en*

Background informationDate of final decision: 10 July 2025National caseController: Poste Vita s.p.a.Legal Reference(s): Article 5 (Principles relating to processing of personal data), Article 33 (Notification of a personal data breach to the supervisory authority)Decision: Administrative fineKey words: Administrative fine, Clients, Data security, Insurance, Personal data breachSummary of the DecisionOrigin of the case The investigation was initiated following a complaint from an insurance compan

### UK data protection reform: How the UK's GDPR may change

*Source: Hogan Lovells, 2022-09-06 — https://overview.legal/posts/6285 — original: https://www.engage.hoganlovells.com/knowledgeservices/news/uk-data-protection-reform-how-the-uk-gdpr-may-change#entry-214*

> The current version of the Bill seeks to maintain the majority of key principles that underpin the UK data protection law framework, while at the same time modifying certain key provisions in relation to accountability, lawful grounds for processing, data subject access requests and cookies, amongst others.

A [consolidated redline version of the UK GDPR by Hogan Lovells](https://www.engage.hoganlovells.com/knowledgeservices/attachment_dw.action?attkey=FRbANEucS95NMLRN47z%2BeeOgEFCt8EGQJsWJiCH

### Who Is Collecting Data from Your Car?Who Is Collecting Data from Your Car?

*Source: The Markup, 2022-07-27 — https://overview.legal/posts/6295 — original: https://themarkup.org/the-breakdown/2022/07/27/who-is-collecting-data-from-your-car#entry-321*

> A firehose of sensitive data from your vehicle is flowing to a group of companies you’ve probably never heard of

### Big Data Analytics, Insurtech and Consumer Contracts: A European Appraisal

*Source: Kluwer Law, 2022-10-27 — https://overview.legal/posts/6327 — original: https://kluwerlawonline.com/journalarticle/European+Review+of+Private+Law/30.4/ERPL2022030#entry-1169*

Automated personalization in consumer insurance contracts is not yet a reality in Europe, but mass customization and robotization of insurance contracts are a growing problem, according to this article in European Review of Private Law.

## Literature

### HOW GDPR TREATS AUTOMATED DECISION-MAKING

*Source: Journal Scientific and Applied Research, 2025-11-14 — https://overview.legal/posts/132599 — original: https://doi.org/10.46687/jsar.v28i1.435*

This article examines how the General Data Protection Regulation (GDPR) regulates automated decision-making, including profiling, in the context of personal data processing. It analyzes the main provisions of Article 22 of the Regulation, as well as the conditions under which fully automated decisions that produce legal effects or significantly affect data subjects are permitted. The article highlights the rights of data subjects – the right to human intervention, the right to express their poin

### Dalla guida assistita alle driverless cars: rischio tecnologico e responsabilità civile

*Source: European Journal of Privacy Law & Technologies, 2026-01-01 — https://overview.legal/posts/53847 — original: https://doi.org/10.57230/ejplt261eam*

Lo sviluppo di tecnologie che consentono l’implementazione della guida assistita e automatizzata – foriere di un significativo aumento della sicurezza e della conseguente riduzione degli incidenti – comporta la necessità di testare le nuove tecnologie non solo in ambienti protetti e controllati, ma anche in condizioni reali. Il contributo, analizzando le norme che disciplinano la responsabilità civile anche alla luce dell’AI Act, ricostruisce i possibili scenari che si concretizzeranno nella lun

### The data subject’s right to access to information under GDPR and the right of the data controller to protect its know-how

*Source: Przegląd Prawniczy Uniwersytetu im. Adam Mickiewicza, 2023-12-30 — https://overview.legal/posts/132546 — original: https://doi.org/10.14746/ppuam.2023.15.09*

The data subject’s right to access information on data processing has a very broad meaning. Considering the latest developments in this field (mainly the CJEU ruling on Austrian posts and EDPB guidelines) one can draw the conclusion that the controller’s right to protect its confidential in-formation is limited and less valuable than the data subject’s rights. However, this may lead to unfair and unequal treatment of companies and data subjects. When looking at this right in a more systematic pe

### Collective Damages for GDPR Breaches: A Feasible solution for the GDPR Enforcement Deficit?

*Source: European Data Protection Law Review, 2022-01-01 — https://overview.legal/posts/132504 — original: https://doi.org/10.21552/edpl/2022/4/8*

### Recommendations for Creating Codes of Conduct for Processing Personal Data in Biobanking Based on the GDPR art.40

*Source: Frontiers in Genetics, 2021-11-12 — https://overview.legal/posts/132560 — original: https://doi.org/10.3389/fgene.2021.711614*

Personal data protection has become a fundamental normative challenge for biobankers and scientists researching human biological samples and associated data. The General Data Protection Regulation (GDPR) harmonises the law on protecting personal data throughout Europe and allows developing codes of conduct for processing personal data based on GDPR art. 40. Codes of conduct are a soft law measure to create protective standards for data processing adapted to the specific area, among others, to bi

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Law Enforcement** — https://overview.legal/topics/law-enforcement
  Processing for law enforcement purposes
- **Processing Agreement** — https://overview.legal/topics/verwerkersovereenkomst
  Contract between controller and processor defining processing terms
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing

---
Generated by overview.legal · https://overview.legal/topics/insurance · 2026-08-22
