# Integrity and Confidentiality Principle — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/integrity-confidentiality-principle
> Sources are cited per item. Verify against the official texts before relying on them.

While security and beveiliging topics exist, there is no dedicated topic for the integrity and confidentiality principle specifically as articulated in GDPR Article 5(1)(f), which is a distinct foundational principle requiring separate coverage.

## Overview

## Legal Framework

Article 5(1)(f) GDPR establishes the integrity and confidentiality principle, requiring controllers to process personal data in a manner that ensures appropriate security of personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage. This principle is operationalized primarily through Article 32 GDPR, which mandates appropriate technical and organizational measures, and Article 28 GDPR, which extends these obligations to processor relationships.

The principle is broader than mere "security" in the technical sense. Recital 75 makes clear that the risk to rights and freedoms encompasses physical, material, and non-material damage — including identity theft, fraud, financial loss, reputational damage, loss of confidentiality of professionally protected data, and unauthorized reversal of pseudonymisation. Recital 85 reinforces that personal data breaches, if not addressed appropriately and timely, can produce precisely these harms. The doctrinal commentary underscores that the scope of required guarantees extends to expertise, reliability, and resources of processors — a wider standard than existed under the 1995 Data Protection Directive, which spoke narrowly of security measures.

Article 28(1) GDPR obligates controllers to engage only processors offering sufficient guarantees regarding appropriate technical and organizational measures. Article 28(3) prescribes in considerable detail what must be contractually binding between controller and processor — a marked expansion from the Directive era.

## Key Developments

Enforcement practice confirms that controllers bear full risk when they cannot identify the source of unauthorized access. In the Beekdaelen case, the court held that the municipality's inability to identify who consulted a data subject's personal data, and for what purpose, was a circumstance falling entirely at the controller's risk. Absent a lawful basis for the processing, the court presumed unlawful processing — a demanding standard for organizations with inadequate access logging.

The Dutch DPA (AP) has actively enforced against unlawful processing, including imposing administrative fines and penalty payments on controllers who failed to cease unauthorized livestreaming of personal data. The AP confirmed that administrative fines can be imposed on public authorities for data breaches, signaling that no sector receives preferential treatment.

At the EU level, the CJEU in *Weltimmo* confirmed that national DPAs may hear claims from data subjects who consider themselves victims of unlawful processing, even where establishment questions remain unresolved. The *Dennekamp* ruling established that data protection rights and access-to-document rights must both be fully applied without one enjoying primacy over the other — relevant where confidentiality obligations intersect with transparency duties.

The Spanish DPA's enforcement against ENDESA (€60,000 fine) and Free Technologies Excom (€10,000 fine) illustrates that inadequate password management and insufficient verification of processing purposes constitute direct violations of the integrity and confidentiality principle.

## Practical Guidance

- **Implement comprehensive access logging and monitoring**: The Beekdaelen ruling makes clear that inability to identify who accessed personal data and why shifts the burden of proof to the controller. Maintain audit trails sufficient to demonstrate lawful processing of every access event.

- **Conduct processor due diligence on expertise, reliability, and resources**: Article 28(1) requires more than contractual representations — assess the processor's actual operational capacity, security certifications, and organizational stability before engaging them.

- **Execute Article 28(3) processor agreements with full mandatory content**: The contractual regime is prescriptive; ensure every required element — subject matter, duration, nature and purpose of processing, type of data, categories of data subjects, and technical/organizational measures — is explicitly addressed.

- **Map confidentiality obligations against transparency duties**: Where sectoral professional secrecy or access-to-information regimes apply, document the balancing analysis to demonstrate full application of both legal frameworks, as required under *Dennekamp*.

- **Establish breach response procedures calibrated to Recital 85 harm categories**: Assessment of breach severity must account for the full spectrum of potential damages — not just technical compromise but identity theft, financial loss, reputational harm, and reversal of pseudonymisation.

## Legislation (full text of key provisions)

### Recital 75 — personal data processing risks to individuals

*Source: GDPR, gdpr-rec-75-en, 2016-04-27 — https://overview.legal/posts/91665*

The risk to the rights and freedoms of natural persons, of varying likelihood and severity, may result from personal data processing which could lead to physical, material or non-material damage, in particular: where the processing may give rise to discrimination, identity theft or fraud, financial loss, damage to the reputation, loss of confidentiality of personal data protected by professional secrecy, unauthorised reversal of pseudonymisation, or any other significant economic or social disadvantage; where data subjects might be deprived of their rights and freedoms or prevented from exercising control over their personal data; where personal data are processed which reveal racial or ethnic origin, political opinions, religion or philosophical beliefs, trade union membership, and the processing of genetic data, data concerning health or data concerning sex life or criminal convictions and offences or related security measures; where personal aspects are evaluated, in particular analysing or predicting aspects concerning performance at work, economic situation, health, personal preferences or interests, reliability or behaviour, location or movements, in order to create or use personal profiles; where personal data of vulnerable natural persons, in particular of children, are processed; or where processing involves a large amount of personal data and affects a large number of data subjects.

### Recital 85 — personal data breach notification requirements

*Source: GDPR, gdpr-rec-85-en, 2016-04-27 — https://overview.legal/posts/91685*

A personal data breach may, if not addressed in an appropriate and timely manner, result in physical, material or non-material damage to natural persons such as loss of control over their personal data or limitation of their rights, discrimination, identity theft or fraud, financial loss, unauthorised reversal of pseudonymisation, damage to reputation, loss of confidentiality of personal data protected by professional secrecy or any other significant economic or social disadvantage to the natural person concerned. Therefore, as soon as the controller becomes aware that a personal data breach has occurred, the controller should notify the personal data breach to the supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the controller is able to demonstrate, in accordance with the accountability principle, that the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where such notification cannot be achieved within 72 hours, the reasons for the delay should accompany the notification and information may be provided in phases without undue further delay.

## Case law

### SG Nürnberg - S 5 SF 65/24 DS

*Source: Social Court Nuremberg, 2026-06-10 — https://overview.legal/posts/122874 — original: https://gdprhub.eu/index.php?title=SG_Nürnberg_-_S_5_SF_65/24_DS*

Facts — The data subject (a child born in 2018), represented by her parents, was insured with the controller (a statutory health insurance provider) and participated in its digital bonus programme. The bonus programme was managed via an app. To handle the information technology operations of this programme, the controller hired the processor (an IT service provider), establishing a data processing agreement under Article 28 GDPR alongside specific information security guidelines. To provide these services, the processor utilised "MOVEit Transfer," a market-leading file transfer software developed by Progress Software Corp. On 31 May 2023, the software developer publicly announced a critical, previously unknown "zero-day" vulnerability in the software (later assigned CVE-2023-34362). At that exact moment, no security patch was available. On the very same day, 31 May 2023, the processor – alongside thousands of other companies worldwide – became the victim of a global cyberattack carried out by the hacker group "Clop." The hackers exploited this zero-day vulnerability to install a "web-shell" backdoor (typically named human2.aspx), bypassing authentication to exfiltrate database records. The compromised data included the data subject's first and last name, health insurance number, bonus points balance, and a bank account number (IBAN) belonging to her mother. No medical, health, or social security data was exfiltrated. On 1 June 2023, the developer released a security patch, which the processor installed immediately. On 2 June 2023, the German Federal Office for Information Security (BSI) issued a formal IT security warning (No. 2023-240133-1100, Version 1.1). The BSI classified the IT threat level as "3 / Orange" (business-critical), confirming active exploitation with data exfiltration. The BSI recommended immediately blocking all HTTP and HTTPS traffic to MOVEit environments, checking for specific Indicators of Compromise (IoCs) in the web server directories, and applying the newly released patch before reconnecting systems to the network. On 16 June 2023, the processor informed the controller about the incident. On 17 June 2023, the controller issued a public press release confirming that its external service provider for the bonus programme had been targeted on 31 May 2023. The release stated that the security vulnerability had been closed, that there was never any connection to the controller's internal IT systems, and that relevant supervisory authorities had been notified. The controller subsequently notified the data subject's parents. On 27 March 2024, the data subject, via legal counsel, sent a formal warning letter to the controller demanding an injunction, a declaration of liability for all potential future damages, and non-material damages of at least €3,000. Following the controller's refusal, the data subject filed a lawsuit with the Nuremberg Social Court (Sozialgericht Nürnberg), later expanding the claim to the processor as a joint defendant. Holding — The Court dismissed the lawsuit as partly inadmissible and otherwise unfounded, establishing the following legal principles: First, the Court held that a successful third-party cyberattack does not establish an irrebuttable presumption that a controller or processor failed to implement appropriate security measures under Article 32(1) GDPR and Article 5(1)(f) GDPR. To escape liability under Article 82(3) GDPR, an operator must prove they implemented robust baseline security controls (such as multi-factor authentication, encryption, and lockout policies) and applied a security patch immediately upon its release by the vendor, even if this occurred before formal alerts were issued by national IT security authorities. Second, the Court held that a claim for non-material damages under Article 82(1) GDPR based on the fear or distress of future data misuse cannot be established if the data subject is a minor who has no subjective knowledge or cognitive awareness of the data breach. Furthermore, if the compromised financial data (such as an IBAN) does not belong to the data subject personally, there is no direct risk of financial harm to them, rendering the alleged fear of financial damage unfounded. Third, the Court held that an injunction claim is inadmissible due to a lack of specificity if it merely demands that a controller stop making personal data accessible to third parties without implementing "state-of-the-art" security measures, without specifying the concrete technical or organisational measures the controller is required to take. Fourth, the Court held that a declaratory claim for potential future material damages is inadmissible under national procedural law (§ 55(1) SGG) if there is no realistic probability of future financial harm, particularly because the compromised bank account belonged to a third party (the mother) and the software vulnerability was immediately patched.

### CJEU - C‑755/21 P - Kočner v Europol

*Source: GDPRhub, 2024-03-05 — https://overview.legal/posts/122879 — original: https://gdprhub.eu/index.php?title=CJEU_-_C‑755/21_P_-_Kočner_v_Europol*

Facts — Following the murder of a Slovak journalist and his fiancée, Mr Ján Kuciak and Ms Martina Kušnírová, in Slovakia on 21 February 2018, the Slovak authorities (Národná kriminálna agentúra (National Crime Agency, Slovakia; ‘NAKA’)) conducted an extensive investigation. At the request of those authorities, the European Union Agency for Law Enforcement Cooperation (‘Europol’) extracted the data stored on two mobile telephones allegedly belonging to Mr Marian Kočner, the data subject, who was prosecuted as an accomplice to that murder for having ordered the killings, following the investigation. Europol sent its scientific reports to those authorities and delivered to them a hard disk containing the encrypted data it had extracted. In one of its reports, Europol stated that Mr Kočner had been detained on suspicion of a financial offence since 2018 and that his name was, inter alia, directly linked to the ‘so-called mafia lists’ and the ‘Panama Papers’. In May 2019, the Slovak press and international network of investigative journalists published a large amount of information relating to Mr Kočner from his mobile telephones, including transcripts of intimate communications exchanged between him and his girlfriend. The conversation was carried by means of encrypted messaging service. For the reasons stated above, Mr Kočner sent a complaint to Europol seeking compensation in the amount of €100,000 as a reparation for the non-material damage on the bases of Article 50(1) Regulation 2016/794. The sought compensation consisted of €50,000 for the unlawful disclosure of data subject's intimate conversation with his girlfriend and €50,000 for the inclusion of his name on the 'mafia list'. Europol and Slovak Republic contended that the arguments are unfounded as, firstly, Regulation 2016/794 (setting up the rules for the Europol) does not provide for such joint liability of Europol and the Member State. Secondly, Europol rejects any liability due to the absence of unlawful conduct on its part given that alleged harmful events occurred during storage of the national investigation file. As such, these circumstances do not constitute ‘unlawful data processing operations’ within the meaning of Article 50(1) Regulation 2016/794. Lastly, Europol stated that even if joint liability was applicable, the absence of any unlawful conduct on its part and of a causal link between such conduct and the damage suffered could not give rise to a liability. Holding — Firstly, the CJEU ruled that there is no need to establish additionally to which of these two entities - Europol or the Member State - that unlawful processing was attributable. In order for such joint and several liability to be incurred in the first stage, the individual concerned must show only that, in the course of cooperation between Europol and the Member State concerned, unlawful data processing that caused him or her to suffer damage has been carried out. Secondly, concerning specifically the leak of the 'so-called mafia list', the CJEU found that the data subject had failed to establish that the ‘mafia lists’ on which his name had allegedly been included had been drawn up and kept by Europol. The data subject's claim contradicted the evidence whereby it was apparent that the leaked Europol report containing Mr Kočner’s name on the ‘mafia list’ was subsequent to and, thus, unrelated to Slovak press publications where he was represented as ‘member of the mafia’. Thirdly, the CJEU rejected the Europol’s argument that it met its obligations and implemented appropriate technical and organizational measures to protect personal data against any form of unauthorized access. The Court observed that the data of such intimate nature bears out the need for its protection to be strictly ensured in cooperation with Member States under Regulation 2016/794. As an unauthorized access took place it constituted a sufficiently serious breach of a rule of EU law intended to confer rights on individuals. Fourthly, the Court held that European Union can incur non-contractual liability in the present case, as the result of publication of data subject’s intimate conversations. The leak of this information adversely affected his honour and professional reputation, and violated his rights to privacy, family life and respect for his communications guaranteed by Article 7 of the Charter of Fundamental Rights of the European Union. As a result, the CJEU held Europol and the Slovak Republic jointly and severally liable for the unlawful data processing which caused the data subject to suffer non-material damage. The Court stated that Europol has the possibility to refer the matter to its Management Board so that it can determine who has the ultimate responsibility for the compensation awarded to the data subject. However, this exclusively concerns the internal allocation of responsibilities between the two jointly liable controllers. The compensation attributed to the data subject for the inclusion of his name on the ‘mafia list’ by Europol was firstly set at €50,000. As this claim was dismissed, the Court only examined the damage regarding the compensation of €50,000 for disclosure of the data subject’s conversation with his girlfriend. The Court decided that the alleged damage resulted solely from the disclosure of transcripts of the conversation and no evidence established that any photographs have been disclosed. As a result, the CJEU granted Mr Kočner compensation in the amount of €2,000 as reparation for that damage.

### CJEU - C‑199/24 - Legal Newsdesk Sweden AB

*Source: GDPRhub, 2026-07-09 — https://overview.legal/posts/108998 — original: https://gdprhub.eu/index.php?title=CJEU_-_C‑199/24_-_Legal_Newsdesk_Sweden_AB*

Facts — The legal context: Article 85 GDPR and Swedish law — Under Swedish law the Swedish Agency for the Media can issue publications certificates which confers constitutional protection to the activities of the holder. Such certificates can also be issued for the publication and maintenance of databases of personal data . Swedish law provides for broad GDPR derogations for certain activities covered by the permit, as an implementation of Article 85 GDPR ("Processing and freedom of expression and information"): The GDPR and the Swedish Law on data protection do not apply when they would conflict with the constitutional protection afforded by a publication certificate. Additionally, specific Articles of the GDPR and the Law on data protection - including all of Chapter VIII of the GDPR (Remedies, liabilities and penalties)- do not apply to the processing of personal data that takes place for journalistic purposes or for academic, artistic or literary creation. As a result of these broad exemption, data subjects have limited remedies available when the processing of their data is covered by a publication certificate. In particular, Swedish law provides that in such cases, controllers can only be held liable for damages when the processing of personal data constitutes defamation. The case at hand — Legal Newdesk Sweden AB, formerly Garrapatica AB (the controller), holds such a certificate. The controller maintained a database (Lexbase) where personal data, including criminal convictions, are stored. The data were made available to third parties for payment. A data subject challenged the processing of his data on Lexbase. In particular, he claimed that the controller could not lawfully make information about his criminal convictions available after the same information was removed from the public register of criminal records. After sending an unsuccessful erasure request, the data subject initiated civil proceedings before the District Court of Attunda and requested SEK 300,000 (about €26,000) in damages over the allegedly unlawful processing of their data on the Lexbase database. The controller, on the other hand, claimed that its activities were exempt from the GDPR because they were covered by the constitutional protection of the publishing certificate. The questions referred — The District Court referred three somewhat complex questions to the Court of Justice about the interpretation of Article 85 GDPR: Does Article 85(1) of the GDPR make it possible for the Member States to adopt legislative measures in addition to those which they must adopt under Article 85(2) of the regulation relating to the processing of personal data for purposes other than journalistic ones or the purposes of academic, artistic or literary expression? If the previous question is answered in the affirmative: Does Article 85(1) of the GDPR allow a reconciliation of the right to the protection of personal data pursuant to that regulation with the freedom of expression and of information which means that the only legal remedy available to a person whose personal data are processed by making criminal convictions involving that person available to the public on the internet in return for payment is the initiation of criminal proceedings for defamation or the claiming of damages for defamation? If the first question is answered in the negative or the second question is answered in the negative: Can an activity which consists of making available to the public on the internet in return for payment, without any processing or editing, public documents in the form of criminal convictions constitute processing of personal data for the purposes set out in Article 85(2) of the GDPR? Advocate General Opinion — The Advocate General opined that a data processing activity, such as that carried out by the controller in the case at hand, did not constitute a journalistic activity and did not fall under Article 85(2) GDPR. Furthermore, the Advocate General opined that Article 85(2) GDPR did not allow for legal derogations to Chapter VIII GDPR. Finally, the Advocate opined that neither paragraph (1) nor (2) of Article 85 allowed for derogations to all of the GDPR. Holding — The CJEU held that Article 85(1) GDPR does not allow Member States to create derogations from the GDPR beyond those expressly permitted by Article 85(2). Article 85(1) requires Member States to reconcile data protection with freedom of expression and information. However, it does not itself authorise exemptions from the GDPR. Such exemptions may only be introduced under Article 85(2) and only for processing carried out for journalistic purposes or for academic, artistic or literary expression. The CJEU therefore found that Member States cannot rely on Article 85(1) to exclude other forms of processing from the application of the GDPR. The CJEU also held that Article 85 GDPR does not permit Member States to restrict the remedies available to data subjects under Chapter VIII GDPR. National law cannot limit a data subject whose criminal-conviction data is published online to defamation proceedings only. Accordingly, the data subject must retain access to the remedies provided under Articles 77, 78, 79 and 82 GDPR, including the right to lodge a complaint with the DPA, seek an effective judicial remedy and claim compensation. Regarding journalistic purposes, the CJEU confirmed that the concept must be interpreted broadly. The fact that processing is carried out online, for payment or in relation to criminal convictions does not, by itself, exclude the application of Article 85(2). However, the mere publication of information is not sufficient. Processing qualifies as journalistic only where it is intended to inform the public and is carried out in accordance with journalistic professional and ethical standards. It must involve editorial work or adaptation, or at least follow an editorial policy, and the relevant factual information must be verified. The CJEU found that making unedited criminal judgements available to any paying user did not appear to satisfy those requirements. In particular, the activity did not appear to involve editorial assessment, adaptation or a journalistic policy. The fact that the documents could be useful to journalists was not enough to bring the processing within Article 85(2). It was for the referring Court to verify whether the controller’s activity met the conditions for processing for journalistic purposes. The CJEU did not impose a fine, award compensation or order corrective measures. Those issues remained for the referring Court to decide.

### OLG München - 36 U 1054/25 e

*Source: Higher Regional Court Munich, 2026-06-26 — https://overview.legal/posts/184545 — original: https://gdprhub.eu/index.php?title=OLG_München_-_36_U_1054/25_e*

Facts — The data subject had used a social media platform operated by the controller, an Irish company, since 2013. The controller provided “Business Tools” to third-party website operators and app providers. These tools enabled the controller to obtain data concerning how users interacted with third-party websites and apps, including information about page visits, purchases and advertisements clicked. In November 2023, the data subject requested that the controller recognize that the processing of his personal data was contrary to the parties’ contract, erase or anonymize the personal data, provide access to the personal data and pay compensation. The data subject subsequently brought an action before the Regional Court of Munich II, seeking a declaration that the parties’ user contract did not permit the processing, cessation of the processing of personal data collected through the Business Tools on third-party websites and apps, restriction of further processing, erasure or anonymization of previously collected data and at least €5,000 in non-material damages. The relevant data included direct and indirect identifiers, such as his name, contact details, IP address and internal identifiers, as well as website URLs, visit times, app names and information about his interactions with websites and apps. The Regional Court of Munich II dismissed the action, holding that the declaratory and erasure or anonymization claims were inadmissible, the cessation claims were legally unavailable and the damages claim had not been sufficiently substantiated. In relation to the damages claim, it found that the data subject had not identified specific third-party websites or apps through which his personal data had been processed. The data subject accordingly appealed to the Higher Regional Court of Munich. Holding — The Higher Regional Court of Munich partially upheld the appeal. First, the court held that the Controller processed the data subject’s personal data under Articles 4(1) and 4(2) GDPR by receiving data transmitted through its Business Tools, associating it with a user account and storing it. The data subject was not required to identify every website, app or individual transmission because the relevant information was principally within the controller’s knowledge and it was sufficiently probable that he had been affected. Second, referring to CJEU C‑40/17 concerning the broad interpretation of “controller”, the court held that the controller was a joint controller under Articles 4(7) and 26 GDPR for the collection and transmission of the personal data. It controlled the programming of the Business Tools and participated in determining the purposes and means of processing. Allocating certain obligations to third-party website and app operators did not remove its responsibility. Third, referring to CJEU C‑252/21, the court held that the controller had not established a lawful basis for the processing of the personal data. The processing was not justified by consent under Article 6(1)(a), contractual necessity under Article 6(1)(b), a legal obligation under Article 6(1)(c), a public-interest task under Article 6(1)(e), or legitimate interests under Article 6(1)(f) GDPR. Accordingly, the court held that the controller's processing infringed Articles 5(1)(a), 5(1)(b), 5(1)(c) and 6 GDPR. Relying on CJEU C‑655/23, the court granted an injunction against future unlawful processing under German law. It also ordered restriction pending erasure under Article 18(1)(b) and erasure under Article 17(1)(d) GDPR. The court upheld the dismissal of the separate declaratory claim and also rejected anonymization of the website and app interaction data. Finally, relying on BGH VI ZR 10/24, the court awarded €1,500 in non-material damages under Article 82(1) GDPR for the data subject’s loss of control over his personal data.

### BGH awards non-material GDPR damages for erroneous disclosure of applicant salary data

*Source: Federal Court of Justice, 2026-06-23 — https://overview.legal/posts/184554 — original: https://gdprhub.eu/index.php?title=BGH_-_VI_ZR_97/22*

Facts — An employee of a private bank (the controller) erroneously sent a third party a message that was intended for a candidate in the controller’s staff selection process (the data subject) in October 2018. The message contained the data subject’s full name and information about their salary expectations. After the data subject was informed they were no longer considered for the position, they brought court proceedings requesting injunctive relief in order to prohibit the controller from processing the data subject’s personal data in connection with their job application. In addition, the data subject claimed non-material damages. The court of first instance granted the injunction and awarded the data subject € 1,000 in damages. The appellate court upheld the injunction but rejected the damages claim. The Federal Court of Justice (BGH) referred several questions to the CJEU regarding the interpretation of Article 82 GDPR. The CJEU rendered its judgment in the case C-655/23 Quirin Privatbank in September 2025. It held that Member States may provide for injunctive relief in national law in cases of unlawful processing. According to the CJEU, negative feelings caused by a loss of control over personal data can also constitute non-pecuniary damages. Holding — First, the Federal Court of Justice held that the data subject was entitled to non-material damages in accordance with Article 82 GDPR. The court confirmed the appellate court had correctly found that sending the message containing personal data to a third party had been unlawful due to the lack of a legal basis under Article 6(1) GDPR – the data subject had not consented to the processing. Furthermore, the controller had not argued that the processing would have been lawful under a different legal basis. The court also confirmed that the data subject had suffered non-material damage as a result of this GDPR violation. In the present case, the data subject’s concern that the recipient of the message might use the personal data contained in it for their own job applications already constituted loss of control of the data subject’s personal data and was therefore enough to establish a claim for damages under Article 82 GDPR. The court referred the case back to the appellate court so that it could determine the amount of non-material damages. Finally, the court held that the appellate court had erroneously upheld the data subject’s claim for injunctive relief: there was no risk of recurrence required for such a claim in German law. As the staff selection process in which the data subject had participated had already been completed, there was no likelihood whatsoever that such an infringement of the data subject’s rights would recur.

### VG Düsseldorf - 29 K 3490/24

*Source: Administrative Court Düsseldorf, 2026-06-22 — https://overview.legal/posts/108992 — original: https://gdprhub.eu/index.php?title=VG_Düsseldorf_-_29_K_3490/24*

Facts — A district (the controller), acting as the lower water authority, initiated administrative proceedings after identifying unauthorised riverbank works and a private jetty on two riverside properties. One property belonged to a water utility company, while the other belonged to a municipality and was leased to the data subjects. During those proceedings, the controller shared the data subjects' personal data with various participants, including the owners of the affected properties, other public authorities and a lawyer who claimed to represent the data subjects. The data subjects lodged a complaint with the competent supervisory authority (LDI NRW), alleging that the controller had unlawfully processed and disclosed their personal data. They argued that their personal data had been shared with uninvolved third parties, that the controller had communicated with a lawyer whom they had not authorised, recorded a telephone conversation with an unknown person, and transmitted personal data by unencrypted email. The controller's data protection officer addressed each allegation and provided additional factual information concerning the disputed processing operations. The DPA initially informed the data subjects that no GDPR infringement was apparent, invited them to provide any additional factual information, and explained that it would obtain extracts from the controller's administrative file if there were concrete indications that it contained relevant facts not already available. The data subjects did not identify any additional facts and instead reiterated their legal position that the controller had breached its GDPR accountability obligations. The DPA rejected the complaint, concluding that no GDPR infringement could be established. The data subjects then brought an action before the Verwaltungsgericht Düsseldorf (Administrative Court Düsseldorf), seeking a fresh decision on their complaint on the basis that the DPA had failed to adequately investigate the complaint because it had not obtained the controller's administrative file before reaching its decision. Holding — The court held that Articles 57(1)(f) and 77(1) GDPR give rise to an enforceable right requiring a supervisory authority to investigate a complaint to the extent appropriate in the circumstances before determining whether a GDPR infringement has occurred. Recital 141 GDPR requires the investigation to extend as far as is appropriate in light of the circumstances of the individual case, including the significance of the complaint and the seriousness of the alleged infringement. Applying these principles, the court held that the DPA had adequately investigated the complaint. It had considered each allegation together with the detailed response provided by the controller's data protection officer, invited the data subjects to provide any additional factual information, and explained that it would obtain extracts from the administrative file if concrete indications emerged that further relevant facts required clarification. As the data subjects did not provide any additional facts and there were no objective indications that the information already available was inaccurate or incomplete, the court held that the DPA was not required to obtain the controller's administrative file or undertake further investigations in the absence of concrete indications that additional factual clarification was necessary. The court further held that the DPA had correctly concluded that no GDPR infringement had occurred. The court held that the disputed processing was lawful under Article 6(1)(e) GDPR, read together with Article 6(3) GDPR and § 88 of the German Water Resources Act (WHG), which provided the legal basis for the processing. The court also held that the transmission of personal data by email did not infringe Article 5(1)(f) GDPR because, in the circumstances of the case, transport encryption provided an appropriate level of security.

### CJEU - T‑183/23 - Ballmann v European Data Protection Board

*Source: GDPRhub, 2025-07-16 — https://overview.legal/posts/184572 — original: https://gdprhub.eu/index.php?title=CJEU_-_T‑183/23_-_Ballmann_v_European_Data_Protection_Board*

Facts — The ruling relates to the procedural aspects of a cross-border case involving Meta Platforms Ltd. The full summary for the case is available here. Context: The case against Meta — In May 2018 a Facebook user (the complainant) lodged a complaint against Meta Platforms Ireland Ltd with the Austrian DPA. In her complaint, she claimed that the collection of personal data via Facebook violated several rules of the GDPR, including Articles 6 and 9. Short after the complaint was filed, the Austrian DPA held that the case was cross-border in nature and forwarded the complaint to the Irish DPA as the lead supervisory authority. In 2021 the Irish DPA submitted a draft decision to all EEA supervisory authorities. Some of them raised “reasoned and relevant objections” to the draft within the meaning of Article 4(24) GDPR. The DPC decided not to follow some of those objections and, therefore, referred the matter to the EDPB under the GDPR’s consistency mechanism. The EDPB decided the matter in December 2022 with its Binding Decision 3/2022. Following the Binding Decision, the Irish DPA decided the complaint and fined Meta €210,000,000 over the unlawful processing of personal data for targeted advertising on Facebook. The case against the EDPB — After the dispute resolution procedure of the EDPB the complainant requested access to the case file relating to her complaint. She invoked several provisions of EU primary and secondary law, including Article 41(2)(b) of the EU Charter of Fundamental Rights (“Right to good administration”). The EDPB replied with an email to the complainant (from now on: “the Contested Decision”), granting the complainant access to some of the documents relative to the procedure based on EU Regulation 1049/2001. However, the EDPB held that the complainant had no right of access under Article 41(2)(b) CFREU. As a result, the EDPB only granted the complainant access to parts of the file. The complainant considered that the EDPB violated her rights and filed an action for the annulment of the contested decision under Article 263 TFEU. The complainant claimed that under Article 41(2)(b) CFREU, she had a right to access the EDPB case file in relation to her complaint. On this ground, she requested that the Court of Justice (General Court) set aside the Contested Decision. The EDPB, in turn, requested that the Court declare the complainant’s action inadmissible or, in the alternative, unfounded. Meta was granted the status of intervening party and put forwards the same demands as the EDPB. Holding — The Court upheld the complainant's demands and annulled the contested decision from the EDPB. The action was admissible — First, the Court held that the action was admissible. In this regard, the Court considered that the contested decision "contains a refusal to grant access to the file requested" under Article 41(2)(b) CFREU. It "immediately and irreversibly affects the applicant’s legal position" to access the EDPB case file. According to the settled case law of the CJEU, it follows that the complainant could bring an action for annulment under Article 263 TFEU. In response to an argument from the EDPB, the Court also clarified that it was not relevant that the contested decision acknowledged the complainant's limited right of access under Regulation 1049/2001. In the case at hand, the complainant would have had a broader right of access under Article 41(2)(b) CFREU than she did under the Regulation (as the EDPB itself conceded). The right of access is independent from the right to be heard — The parties put forward different interpretations of Article 41 CFREU – in particular, with regard to the relationship between paragraphs (2)(a) and (2)(b) of the provision. The EDPB claimed that paragraph (2)(a) and (2)(b) embody corollary aspects of the rights of the defence. In this interpretation, the complainant’s right of access was not protected under paragraph (2)(b) because the requirements of paragraph (2)(a) (being adversely affected), was not fulfilled. Therefore, the EDPB claimed the contested decision rightfully denied access to the file. The complainant claimed that the two paragraphs are independent from each other and embody autonomous rights. In other words: proving that the file concerned her, should have been sufficient grounds for accessing the file. The Court confirmed the complainant’s interpretation: “everyone has the right of access to his or her file based on Article 41(2)(b) of the Charter, including where that file is not linked to a procedure liable to culminate in a measure adversely affecting him or her” . Therefore, the EDPB erroneously applied the requirements of Article 41(2)(a) CFREU to the right to access the file under Article 41(2)(b) CFREU, as the complainant claimed. The file concerned the complainant — After clarifying the interpretation of Article 41 CFREU, the Court assessed whether the file for the Article 65 GDPR procedure concerned the complainant. The Court held that even though the complainant is not a formal party to the procedure under Article 65(1)(a) GDPR, the complaint plays an essential role in that procedure as it constitutes the starting point of the entire decision-making process. The Court also pointed out that the relevant and reasoned objections (of supervisory authorities concerned) form part of the procedure initiated following the complaint. In particular, these objections determine the scope of the EDPB’s binding decisions under Article 65(1)(a) GDPR. For this reason, a complainant may legitimately want to ascertain whether elements of the complaint were reproduced in the objections or the extent they have been taken into account in the binding decision. Finally, the Court held that complainants have a direct interest in the outcome of procedure, as it relates to the processing of their personal data. For these reasons, the Court held that in the case at hand, the EDPB’s file “concerned” the complainant. In consequence, the Court annulled the contested decision.

### Judgment of the Court (Eighth Chamber) of 4 October 2024.#A v Patērētāju tiesību aizsardzības centrs.#Request for a preliminary ruling from the Augstākā tiesa (Senāts).#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 82(1) – Right to compensation and liability – Unlawful processing of data – Infringement of the right to protection of personal data – Concept of ‘damage’ – Compensation for non-material damage in the form of apologies – Whether

*Source: Court of Justice of the European Union, C-507/23, 2024-10-04 — https://overview.legal/posts/132162 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0507*

The Court of Justice of the European Union issued a preliminary ruling on a reference from the Latvian Supreme Court in Case C-507/23, involving an individual ("A") and the Patērētāju tiesību aizsardzības centrs (Consumer Rights Protection Centre, Latvia) regarding compensation for non-material damage allegedly suffered from unlawful processing of personal data under Article 82(1) GDPR. The Court addressed whether apologies can constitute compensation for non-material damage and whether the controller's attitude and motivation may be considered in assessing the form and level of compensation. No fine was imposed, as the ruling clarifies interpretive questions of EU law for the referring national court.

### Judgment of the Court (Third Chamber) of 21 December 2023.#ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, Körperschaft des öffentlichen Rechts.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 6(1) – Conditions for lawful processing – Article 9(1) to (3) – Processing of special categories of data – Data concerning heal

*Source: Court of Justice of the European Union, C-667/21, 2023-12-21 — https://overview.legal/posts/132276 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0667*

The CJEU (Third Chamber) ruled on a preliminary reference from the Bundesarbeitsgericht in a case where ZQ sought compensation from his employer, Medizinischer Dienst der Krankenversicherung Nordrhein, for allegedly unlawful processing of his health data in connection with an assessment of his working capacity. The Court addressed the conditions under which a health insurance medical service may lawfully process special categories of health data of its own employees under GDPR Articles 6(1) and 9(2)(h)/(3), and clarified the scope of the right to compensation for non-material damage under Article 82(1), including the relevance of the controller's negligence. No fine was imposed, as the ruling concerns the interpretation of GDPR provisions for the referring court's application.

### Judgment of the Court (Fifth Chamber) of 4 May 2023.#UZ v Bundesrepublik Deutschland.#Request for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 5 – Principles relating to processing – Controllership – Article 6 – Lawfulness of processing – Electronic file compiled by an administrative authority relating to an asylum application – Tra

*Source: Court of Justice of the European Union, C-60/22, 2023-05-04 — https://overview.legal/posts/132289 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0060*

In Case C-60/22, the CJEU (Fifth Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden concerning UZ, a third-country national, and the Bundesrepublik Deutschland regarding the processing of personal data in an asylum application file. The Court held that an administrative authority transmitting an electronic asylum file to a competent national court via an electronic mailbox constitutes processing under the GDPR, and that where both the authority and the court determine the purposes and means of processing, they are joint controllers under Article 26, requiring an arrangement allocating responsibility and maintaining records of processing activities under Article 30. The Court further clarified that transmission of personal data without the data subject's consent constitutes unlawful processing, triggering the right to erasure under Article 17(1)(d) and the right to restriction under Article 18(1)(b), and that national courts must disregard such unlawfully processed data. No fine was imposed.

### CJEU - C-526/24 - Brillen Rottler

*Source: GDPRhub, C-526/24, 2026-07-13 — https://overview.legal/posts/96819 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-526/24_-_Brillen_Rottler*

Facts — On 16 March 2023, the data subject (a private individual living in Vienna) subscribed to the ‘newsletter’ on the website of the controller (a family run optician company established in North Rhine-Westphalia) by entering his personal data in the registration form, confirming his consent to data processing by ticking a box and submitting the form. On 29 March 2023, the data subject sent by fax an information request pursuant to Article 15 GDPR. The controller acknowledged receipt of the request and stated that it would respond to it within the one-month period. However, by letter of 26 April 2023, the controller refused to provide the information since it classified the information request as an abuse of right for the purposes of the second sentence of Article 12(5)(b) GDPR. The controller sought a declaration from the referring court that the data subject is not entitled to compensation in the amount of €1000. The court decided to refer the following questions set out in point I. to the CJEU for a preliminary ruling pursuant to Article 267 TFEU: Is the second sentence of Article 12(5) GDPR to be interpreted as meaning there cannot be an excessive information request from the data subject when the first request is made to the controller? Is the second sentence of Article 12(5) GDPR to be interpreted as meaning that the controller can refuse an information request from the data subject if the data subject intends to use the information request to provoke claims for damages against the controller? Is the second sentence of Article 12(5) GDPR to be interpreted as meaning that grounds for refusing to provide information can be provided by publicly available information about the data subject which suggests that the data subject is asserting claims for damages against the controller in a large number of cases of infringement of the law relating to the protection of personal data? Is Article 4(2) GDPR to be interpreted as meaning that an information request from a data subject to the controller pursuant to Article 15(1) GDPR and/or a response to that request constitutes processing within the meaning of Article 4(2) GDPR? In view of the first sentence of recital 146 GDPR, is Article 82(1) GDPR to be interpreted as meaning that only damage which the data subject suffers or has suffered as a result of processing is eligible for compensation? Does this mean that for there to be a claim for damages under Article 82(1) GDPR – assuming causal damage to the data subject exists – there must necessarily have been processing of the data subject’s personal data? If the answer to Question 5 is in the affirmative: Does this mean that the data subject – assuming causal damage exists – has no claim for compensation under Article 82(1) GDPR solely on the basis of an infringement of his or her right to information under Article 15(1) GDPR? Is Article 82(1) GDPR to be interpreted as meaning that the controller’s objection relating to an abuse of right in relation to an information request from the data subject cannot, in view of EU law, consist in the fact that the data subject brought about processing of his or her personal data solely or inter alia in order to assert claims for damages? If the answers to Questions 5 and 6 are in the negative: Does the mere loss of control and/or uncertainty about the processing of the data subject’s personal data associated with an infringement of Article 15(1) GDPR constitute non-material damage to the data subject within the meaning of Article 82(1) GDPR or does it also require a further (objective or subjective) restriction and/or (significant) damage to the data subject? Advocate General Opinion — In addressing the first, second, third, and seventh questions referred by the national court: — The excessive character of an initial access request Advocate General emphasized that while an initial access request can, in theory, be considered "excessive," this must be limited to exceptional circumstances since the right of access is fundamental and linked to other GDPR rights. The circumstances that allow a request to be characterized as ‘excessive’ The Advocate General analyzed when a data access request under Article 15 GDPR could be considered excessive under Article 12(5) GDPR . He concluded that such a request may only be treated as excessive if the controller can demonstrate an abusive intention. However, merely having a pattern of making similar claims in many cases does not, on its own, prove abuse, and strict criteria must be applied to ensure that the fundamental right of access is not unduly restricted. In addressing the the fourth, fifth and sixth questions referred by the national court : — The event giving rise to the damage within the meaning of Article 82 of the GDPR The Advocate General analyzed whether only data processing that violates the GDPR can give rise to compensation under Article 82 GDPR. He concluded that not just unlawful processing, but any infringement of the GDPR can be a basis for compensation, provided that damage and a causal link are proven. The concept of ‘processing’ for the purposes of the right to compensation The Advocate General explains that although sending an access request is not "processing" under the GDPR, a controller’s act of responding to such personal data , which can fall under the scope of the GDPR. However, the actual damage arises not from this technical processing, but from the unjustified refusal to fulfill the access request. To ensure the effectiveness of Article 15 GDPR and the right to compensation under Article 82, the concept of “processing that caused the damage” should be interpreted broadly. The existence of non-material damage The Advocate General clarifies that a violation of Article 15 GDPR alone does not automatically entitle a data subject to compensation; the individual must prove actual non-material harm resulting from the infringement. The Court has recognized that even temporary loss of control over personal data may qualify as non-material damage, without requiring a minimum severity threshold. Conclusion — In the Advocate General’s view, an initial access request under Article 15 GDPR can only be considered “excessive” where the data controller can clearly demonstrate, based on all relevant circumstances, that the data subject acted with abusive intent, specifically, where the individual consented to the processing of their personal data solely to submit an access request and subsequently claim compensation. Importantly, the mere fact that a data subject has frequently exercised their right to compensation in similar cases does not, in itself, justify classifying the request as excessive. Moreover, under Article 82(1) GDPR, a data subject is entitled to compensation for damage resulting from a violation of the Regulation, even if that damage was not directly caused by the processing of personal data. Holding — Is a first access request excessive in accordance with Article 12(5) GDPR, and under what circumstances is it possible to establish such an excessive nature? (Questions 1, 2, 3 and 7) — The court first noted that the GDPR guarantees the right to access in Article 15(1) GDPR. However, Article 12(5) GDPR allows the controller to charge a reasonable fee or refuse the request if it is “manifestly unfounded or excessive”. Given the fact that the GDPR does not define these terms, the concept must be understood through its wording and objectives pursued . The court stated that Article 12(5) GDPR does not rule out the possibility that a first request may be considered excessive. This is because the repetitive character referred to in this article is an example, meaning “excessive” is not necessarily limited to the number of requests. However, this must be interpreted strictly; therefore, the controller may only rely on this in exceptional cases, and the controller bears the burden of demonstrating the excessive nature of the request. In terms of circumstances, the court noted that proof of an abusive practice must meet objective and subjective requirements. The court noted that the data subject’s access request met the formal requirements, as the data subject exercised the right to access to be aware of the processing and verify its lawfulness in accordance with the aim of Article 15 GDPR. The subjective element, on the other hand, concerns the intention of the data subject; in this case the controller must unequivocally demonstrate that the data subject has made the request for a purpose other than being aware of the processing and verifying its lawfulness (such as artificially creating conditions to obtain compensation). The court stated that it is necessary to take into consideration all the circumstances of the case, including the fact that the data subject provided the data voluntarily, or the time elapsed between providing the data and requesting access. The court noted that the controller may use publicly available information, provided that it is supported by other material. The court concluded that it was for the referring court to determine whether the controller demonstrated that the data subject made the access request with abusive intentions. Does Article 82(1) confer the right to compensation for damages resulting from an infringement of the right to access? (questions 5 and 6) — The court first noted that under Article 82(1) GDPR data subjects that have suffered (non)material damages as a result of an infringement of the GDPR are entitled to compensation. Since the Article does not refer to “processing”, the right to compensation is not limited to damage resulting from the processing of personal data. In this case, an infringement is liable for damages from the refusal to act, rather than from the actual processing of personal data as such. The court also noted that the right of access would be significantly weakened if Article 82(1) GDPR was limited solely to unlawful acts involving data processing. In light of the answer to these questions, the court saw no need to answer question 4. Does non-material damage for data subjects include loss of control or uncertainty over how their data is processed? (question 8) — The court noted that the GDPR does not define “(non)material damages” or “compensation for damages suffered”. Therefore, they must be considered autonomous concepts of EU law, and interpreted in a uniform manner . The court referred to previous case law, and highlighted the fact that “non material damage” cannot be limited by the degree of seriousness. However, an infringement on its own does not give data subjects the right to compensation, as it is one of the three conditions that must be met cumulatively. Therefore, the data subject must also establish that the infringement caused them harm, and that there is a causal link between the damage and the infringement. This applies to loss of control, as well as data subjects’ fears regarding the misuse of their data. Finally, the court stated that the causal link may be broken by the behaviour of the data subject; this means a data subject may not receive compensation for damages when the loss of control or fears over misuse of data were caused by the data subject submitting this data to the controller with the aim of artificially creating conditions to obtain compensation).

### BVwG - W137 2327171-1

*Source: Federal Administrative Court, 2026-07-08 — https://overview.legal/posts/184712 — original: https://gdprhub.eu/index.php?title=BVwG_-_W137_2327171-1*

Facts — The controller, an assistant professor at a private university (the appellant), was engaged in an employment dispute with her university employer before a labour and social court. The data subject, a senior legal counsel employed by the university gave testimony as a witness in that employment proceeding. On 23 January 2025, the labour and social court ruled in the controller's favour, finding that her employment relationship continued beyond the university's purported termination date. The judgment referred to the data subject several times by her academic title and surname in connection with her witness testimony. In April 2025, the controller published the unredacted judgment in full, including the data subject's title and surname on social media. She shared a downloadable link (first via Dropbox, later via Adobe) on her public Facebook profile and in a closed Facebook group of around 230 members connected to the university community. The files were later removed by Dropbox and Adobe after the data subject reported them. The data subject's full first name and additional details could also be found by combining her academic title and surname with the university's name in a Google search, which surfaced her LinkedIn profile. The data subject filed a complaint with the Austrian DPA, arguing that the controller had no justification for naming her and had drawn her into a public dispute with her employer. The controller argued that the judgment concerned matters of wider relevance to university staff, that the Facebook group was closed and that the data subject's name and role were already public via the university directory and LinkedIn. On 15 October 2025, the DPA upheld the complaint, finding that the controller had violated the data subject's right to secrecy under §1(1) of the Austrian Data Protection Act (DSG) by publishing the judgment without a legal basis. The DPA found that a legitimate interest existed in principle, but that both publications were excessive as the judgment was made accessible to an uninvolved and disproportionately wide audience and that disclosing the data subject's name was not necessary to achieve the controller's stated purpose of informing colleagues in similar situations. The DPA noted that publishing the judgment with the data subject's name redacted would have been an equally effective, less intrusive alternative. The controller appealed, arguing that the data subject had no protectable secrecy interest because she had participated in the proceeding in a public professional capacity and had made comparable information about herself public on LinkedIn and that the DPA had failed to weigh her freedom of expression rights under Article 10 ECHR against the data subject's secrecy interest. Holding — The court dismissed the appeal in full and confirmed the DPA's decision. First, the court rejected the controller's argument that no protectable secrecy interest existed because the data subject had acted in a professional capacity. It held that, under settled national case-law, appearing in a professional role does not by itself remove a person's right to secrecy under §1(1) DSG. Second, applying the three-part test for legitimate interest under Article 6(1)(f) GDPR, the court accepted that the controller had, in principle, a legitimate interest in informing colleagues in comparable employment situations about the judgment. However, it held that publishing the data subject's surname failed the necessity requirement under this test and therefore also breached the data minimisation principle under Article 5(1)(c) GDPR. The court noted that the data subject was a witness testifying about legal matters, not the person responsible for the controller's employment contract and that naming her added nothing to the comprehensibility or persuasive value of the information the controller sought to share. Because necessity was lacking, the court found it unnecessary to conduct any further balancing of the parties' respective rights. Third, the court rejected the controller’s argument that her freedom of expression justified the full disclosure of the judgment, for which she relied on the CJEU’s judgment in Case C-345/17 (Buivids). The court held that Buivids concerned whether processing could be regarded as being carried out solely for journalistic purposes, whereas there was no indication of journalistic activity in the present case. It further held that §9 DSG, which implements Article 85 GDPR in relation to journalistic activity, was therefore inapplicable. In any event, the court stated that §9 DSG does not entirely override the principle of proportionality but establishes a different standard for balancing the competing interests. Finally, the court agreed with the DPA that redacting the data subject's name and title would have been an equally effective and only minimally burdensome alternative that would not have undermined the controller's informational purpose and held that the controller had not plausibly explained why such redaction would have been insufficient. The court accordingly found no unlawfulness in the DPA's decision and dismissed the appeal. It declared that an appeal on points of law (Revision) was not admissible, since the case did not raise a legal question of fundamental importance and was consistent with existing case-law.

## Guidance

### Recommendations 02/2021 on the legal basis for the storage of credit card data for the sole purpose of facilitating further online transactions

*Source: EDPB, recommendations-022021-on-the-legal-basis-for-the-storage-of-credit-card-en, 2021-05-19 — https://overview.legal/posts/126030 — original: https://www.edpb.europa.eu/documents/recommendation/recommendations-022021-on-the-legal-basis-for-the-storage-of-credit-card_en*

adopted 1 Recommendations 02/2021 on the legal basis for the storage of credit card data for the sole purpose of facilitating further online transactions Adopted on 19 May 2021 adopted 2 The European Data Protection Board Having regard to Article 70(1)(e) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the fre e movement of such data, and repealing Directive…

### Art. 29 WP Guidelines on GDPR transparency requirements (WP260 rev.01)

*Source: EDPB, edpb-guidelines-on-transparency, 2025-11-21 — https://overview.legal/posts/38076 — original: https://www.edpb.europa.eu/system/files/2023-09/wp260rev01_en.pdf*

The Article 29 Data Protection Working Party issued these guidelines (WP260 rev.01), adopted on 29 November 2017 and last revised on 11 April 2018, to provide interpretive and practical guidance on the transparency requirements under the GDPR (Articles 12–14). The document addresses the form, timing, content, and modalities of information provided to data subjects, including issues such as plain language, layered privacy notices, information for children, and exceptions to the obligation to provide information. No fines or enforcement actions are imposed, as this is a guidance document rather than an enforcement decision.

### Guidelines 02/2024 on Article 48 GDPR

*Source: EDPB, edpb-guidelines-022024-on-article-48-gdpr, 2025-06-05 — https://overview.legal/posts/38045 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-022024-on-article-48-gdpr_en*

Article  48  GDPR  provides  that:  ' Any  judgment  of  a  court  or  tribunal  and  any  decision  of  an administrative authority of a third country requiring a controller or processor to transfer or disclose personal data  may  only  be  recognised  or  enforceable  in  any  manner  if  based  on  an  international agreement, such as a mutual legal assistance treaty, in force between the requesting third country and the Union or a Member State, without prejudice to other grounds for transfer...

### Opinion 07/2025 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data by the European Patent Organisation

*Source: EDPB, edpb-opinion-202507-epo-adequacydecision-en, 2025-05-06 — https://overview.legal/posts/50823 — original: https://www.edpb.europa.eu/documents/adequacy/opinion-072025-regarding-the-european-commission-draft-implementing-decision_en*

EDPB, Opinion 07/2025 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data by the European Patent Organisation, 2025.

### Guidelines 2/2023 on Technical Scope of Art. 5(3) of ePrivacy Directive

*Source: EDPB, edpb-guidelines-on-technical-scope-of-art-53-of-eprivacy-directive, 2024-10-16 — https://overview.legal/posts/38063 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-22023-on-technical-scope-of-art-53-of-eprivacy-directive_en*

The European Data Protection Board (EDPB) issued Guidelines 2/2023 to clarify the technical scope of Article 5(3) of the ePrivacy Directive, focusing on its application to emerging tracking technologies that operate as alternatives to cookies. The guidelines establish three key elements—information, terminal equipment, and gaining access/storage—to determine whether specific technical operations require user consent. The document applies this framework to common use cases such as URL and pixel tracking, local processing, IP-based tracking, intermittent IoT reporting, and the use of unique identifiers.

### EDPB Annual Report 2023

*Source: EDPB, edpb-annual-report-2023-en, 2024-04-23 — https://overview.legal/posts/125756 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-annual-report-2023_en*

EDPB Annual Report 2023 1 2023 ANNUAL REPORT SAFEGUARDING INDIVIDUALS' DIGITAL RIGHTS 2 FOREWORD 4 HIGHLIGHTS 2023 6 1. THE EDPB SECRETARIAT 8 1.1. MISSION AND ACTIVITIES IN 2023 9 1.2. RE-ORGANISING THE SECRETARIAT IN 2023 12 2. EUROPEAN DATA PROTECTION BOARD - ACTIVITIES IN 2023 14 2.1. BINDING DECISIONS 14 2.2. CONSISTENCY OPINIONS 19 2.3. GENERAL GUIDANCE 21 2.3.1. Guidelines 03/2022 on deceptive design patterns in social media platform interfaces: how to recognise and avoid them 21 2.3.2.…

### Opinion 7/2024 on the draft decision of the German North Rhine Westphalia Supervisory Authority regarding the EU Cloud Service Data Protection (Auditor) certification criteria

*Source: EDPB, opinion-72024-on-the-draft-decision-of-the-german-north-rhine-en, 2024-04-19 — https://overview.legal/posts/125759 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-72024-on-the-draft-decision-of-the-german-north-rhine_en*

Adopted 1 Opinion 7/2024 on the draft decision of the German North Rhine Westphalia Supervisory Authority regarding the EU Cloud Service Data Protection (Auditor) certification criteria Adopted on 17 April 2024 Adopted 2 Adopted 3 The European Data Protection Board Having regard to Article 63, Article 64(1)(c) and Article 42 of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal…

### Statement 1/2023 on the first review of the functioning of the adequacy decision for Japan

*Source: EDPB, statement-12023-on-the-first-review-of-the-functioning-of-en, 2023-07-18 — https://overview.legal/posts/125837 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-12023-on-the-first-review-of-the-functioning-of_en*

1 Statement 1/2023 on the first review of the functioning of the adequacy decision for Japan Adopted on 18 July 2023 The European Data Protection Board has adopted the following statement: On 3 April 2023, the European Commission issued the report on the first review of the functioning of the adequacy decision for Japan adopted on 23 January 2019, along with a Commission Staff Working Document (SWD(2023) 75) 1 . In its Implementing Decision (EU) 2019/419, the European Commission found, pursuant…

## Enforcement decisions

### AEPD fines Alkora, S.A. for ransomware breach exposing 40,000 individuals' data

*Source: AEPD (Spain), 2026-07-16 — https://overview.legal/posts/53655 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS-00020-2025*

Facts — Alkora, S.A., the controller, is an insurance broker that was victim of a ransomware attack. The controller notified the DPA of a personal data breach after a ransomware attack affected its servers, databases, email systems and employee devices. The controller first estimated that 25,000 persons were affected. It later stated that the incident had affected around 40,000 persons, including 75 minors. The incident affected confidentiality, availability and integrity. The attacker encrypted systems and exfiltrated between 3.5 and 4 TB of information from the document management server. The affected data included identification and contact data, ID numbers, dates of birth, financial and insurance data, bank account numbers, health data, employee data and access credentials. The controller also processed data relating to minors in accident claims. A data subject complained to the DPA after being informed that their personal data had been exposed. The data subject was concerned about identity theft and requested additional information from the controller. During the investigation, the DPA found that the controller had known that its IT systems faced an extreme cybercrime risk before the breach. The forensic report could not determine the initial entry point because the servers had been encrypted, but it showed that attackers could move laterally through the infrastructure, obtain privileged access, install tools, exfiltrate data and encrypt systems. The controller had carried out a risk analysis in 2019, but this document concluded that no DPIA was necessary. After the breach, a later analysis found that a DPIA was necessary for treatments involving health data and minors. The controller did not prove that it had carried out the required DPIA. Holding — The DPA held that the controller violated Article 5(1)(f) GDPR. It considered that the controller had failed to ensure the integrity and confidentiality of the personal data under its responsibility. The DPA emphasised that the principle in Article 5(1)(f) GDPR is not limited to the existence of isolated security measures. Rather, the controller must implement adequate technical and organisational measures capable of ensuring that personal data is protected against unauthorised or unlawful processing, loss, destruction or damage. The DPA rejected the controller’s argument that the attack was an external criminal act that could not be attributed to it. The DPA found that the controller was aware of an extreme cyber risk and that its internal vulnerabilities and security posture allowed the attackers to move through the systems, access personal data and encrypt files. The DPA therefore considered that the controller’s measures were clearly insufficient. The DPA also held that the controller violated Article 35 GDPR. The controller processed high-risk categories of data, including health data and data concerning minors. In these circumstances, it should have carried out a DPIA before the processing. The DPA found that the controller’s 2019 risk analysis wrongly concluded that no high risk existed, while its later documentation acknowledged that a DPIA was necessary. The DPA proposed a fine of €150,000 for the infringement of Article 5(1)(f) GDPR and €100,000 for the infringement of Article 35 GDPR, totalling €250,000. The controller paid voluntarily without acknowledging liability, obtaining a 20% reduction under Spanish Administrative Law (39/2015). The final payable amount was therefore €200,000. The DPA also ordered the controller, under Article 58(2)(d) GDPR, to prove within three months from the enforceability of the decision that it had carried out the mandatory DPIA required under Article 35 GDPR.

### APDCAT sanctions Madremanya City Council for exposing applicants' sensitive data in tender

*Source: APDCAT (Catalonia), 2026-07-17 — https://overview.legal/posts/184715 — original: https://gdprhub.eu/index.php?title=APDCAT_(Catalonia)_-_PS-0036/2026*

Facts — On 8 May 2025, Madremanya City Council, acting as controller, published on its notice board two administrative acts concerning a tender procedure for the award of a social housing lease. The documents expressly disclosed the identities of the applicants. On 9 May 2025, the controller replaced the original documents with revised versions in which the applicants’ names and surnames were partially redacted, leaving only their initials visible. However, the redaction was performed manually and did not effectively conceal the information, as it remained possible to infer the length of the names and surnames and to identify some of their letters. In addition to the applicants’ identifying information, the documents disclosed detailed financial data, including the exact annual net income of each household. They also revealed information concerning particularly sensitive personal circumstances, including dependency, gender-based violence and addiction, which had been used to calculate the applicants’ respective scores. No adequate anonymisation or redaction measures had been implemented. In July and November 2025, the DPA requested that the controller provide specific information concerning certain aspects of the processing. The controller’s failure to respond or cooperate hindered the DPA’s ability to exercise its investigative powers. Holding — The DPA held that the controller violated Article 5(1)(c) GDPR by publishing personal data that were not necessary for the purpose pursued. The DPA acknowledged that publishing information about the procedure could serve the objective of administrative transparency. However, transparency did not justify disclosing identifying data together with detailed financial information and sensitive personal or family circumstances. The controller had to limit the processing to data that were necessary and proportionate to that objective and consider less intrusive alternatives. The DPA found that the controller’s subsequent redaction did not amount to effective anonymisation. Although most of the characters had been concealed, the applicants could still potentially be reidentified from their initials, the length of their names and surnames and other contextual information. This risk was particularly significant because the municipality had only 277 inhabitants. The controller should therefore have applied complete anonymisation or a pseudonymisation method preventing direct or indirect identification. The DPA also held that the controller violated Article 5(1)(f) GDPR and the duty of confidentiality under Article 5 LOPDGDD. The published documents disclosed the applicants’ exact household income, household composition and scores linked to circumstances such as dependency, addiction, gender-based violence, single-parent status and age. Although this information was relevant to assessing the applications, it was unnecessary to make it publicly accessible in a form linked to identifiable individuals. The DPA considered that the violations of the data-minimisation and confidentiality principles constituted a medial concurrence of infringements. The failure to anonymise the applicants’ identities was the necessary means through which their sensitive personal and family circumstances were disclosed. Nevertheless, the DPA formally declared separate violations of Articles 5(1)(c) and 5(1)(f) GDPR. Additionally, the DPA held that the controller violated Article 31 GDPR by failing to respond to two information requests. This failure breached the controller’s duty to cooperate with the supervisory authority and obstructed the exercise of the DPA’s investigative powers.

### AEPD: Digi Telecom violated Art 6(1) GDPR by issuing duplicate SIM to impersonator

*Source: AEPD (Spain), 2026-07-13 — https://overview.legal/posts/109001 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_EXP202310345*

Facts — On December 28, 2022, DIGI Telecom, the controller, delivered a duplicate SIM card to an unauthorized third party without the consent of the original line holder (the data subject) The duplicate SIM card was delivered to an impersonator after they passed the established protocols for verifying the applicant's identity. The controller appealed the decision by the Spanish DPA to impose a fine because they claimed that they had appropriate security measures. The controller claims that, by focusing on the result, the Spanish DPA is acting under strict liability. The mere fact that identity theft occurred does not equal a lack of due diligence on the part of the controller. The controller also requested a reduction of the fine on the basis of Article 83(5)(a) GDPR because there were no aggravating circumstances and no special categories of data were processed Holding — The Spanish DPA found a violation of Article 6(1) GDPR because issuing a duplicate SIM card and delivering it to a person other than the telephone line holder constitutes the processing of personal data within the meaning of Article 4(1) GDPR without a legal basis because the data subject did not give consent. The DPA ruled that the controller violated their duty of care because the security measures lacked the dilligence required. According to Article 5(2) GDPR (principle of proactive responsibility) the controller must demonstrate compliance to the GDPR. Proactive responsibility means that the measures are compliant to the GDPR under normal circumstances. The controller must also demonstrate that the measures are compliant with the GDPR and that they are effective in the specific context and purposes of processing (Article 24 en 25 GDPR). The controller had a higher standard of care because of a documented risk to SIM swap attacks and the high scale of processing. Recital 74 GDPR states that the controller’s must implement effective and appropriate measures that take into account the nature, scope and context, and purposes of processing. The card allows an impersonator to access additional data through which they can carry out actions with grave consequences. The controller did not demonstrate that their security measures sufficiently protected the data subject. Factual circumstances should have alerted DIGI to the fraud: the SIM card replacement was processed at a physical store in a different province from where the data subject resided. The Spanish DPA flagged that the controller did not ask the reason for issuing the card and they did not verify whether the old SIM card was functioning. Therefore the security measures were not appropriate to prevent'SIM swap attacks' that are prevalent in the telecom context. With regard to to the height of the fine, the Spanish DPA found that no new legal arguments were made that would lead to the reduction of the fine.

### ANSPDCP fines Banca Transilvania RON 26,172 for inadequate security over unauthorized

*Source: ANSPDCP (Romania), 2026-07-03 — https://overview.legal/posts/53660 — original: https://gdprhub.eu/index.php?title=ANSPDCP_(Romania)_-_02/07/2026*

Facts — The Romanian DPA (ANSPDCP) launched an investigation into a bank, Banca Transilvania S.A. (the controller), following a data subject’s complaint. The data subject claimed that their personal data associated with their bank account had been processed without their consent. During the investigation the DPA found that an employee of the controller had accessed the data subject's bank account statements without authorisation and outside the scope of their official duties, at the request of a third party. The personal data included the data subject’s surname, first name, IBAN, account type, client code, transaction data and account balances. Holding — The DPA found that the controller had failed to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. It noted that the controller had not sufficiently ensured that employees acting under its authority and having access to customers’ personal data processed those data only on its instructions. It held that this failure resulted in the unauthorised access to the data subject’s personal data for personal purposes. The DPA therefore found that the controller infringed Article 32(1) GDPR, Article 32(2) GDPR and Article 32(4) GDPR and imposed a fine of RON 26,172 (€5,000). Furthermore, the DPA ordered the controller to implement appropriate technical and organisational measures to prevent employees from unlawfully accessing personal data for personal purposes.

### Italian Garante: Employer's recording of locker opening and destruction of contents

*Source: Garante per la protezione dei dati personali (Italy), 2026-06-18 — https://overview.legal/posts/184562 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_462/2026*

Facts — The case involves a worker (the data subject), his former employer (the controller), and the staffing agency that had provided the company with the worker. In late 2023 the data subject learned that its working relationship with the controller would soon end. The data subject called in sick and did not show up to work again. When his contract ran out, some of his belongings were still in a locker in its workplace. Over the month of January, the data subject booked and annulled several appointments with the controller to empty his locker. In this phase, communications between the controller and the data subject were mediated by the staffing agency. Eventually, the controller opened and emptied the locker. The opening took place the day before the last planned appointment and roughly one month since the data subject had last worked for the controller. A collaborator of the controller (specifically, a member of the external security staff) recorded the opening of the locker with her personal smartphone, in order to defend the controller from possible claims over missing items. Inside the locker, the controller found some of its own products which could no longer be sold, along with personal items of intimate use which could not be preserved due to hygiene concerns. All the contents were destroyed. The data subject later learned that the controller had opened his locked and filed a complaint. He claimed that the opening of its locker constituted an unlawful processing of his personal data. In its defense, the controller protested that the content of the data subject’s locker, did not constitute personal data as defined under Article 4(1) GDPR. The controller also put forward the alternative argument that the emptying of the locker, did not fall under Article 2(1) GDPR (i.e.: it was neither an automated processing of personal data, nor a non-automated processing of personal data “which form part of a filing system or are intended to form part of a filing system”). Finally, the controller claimed that in any case, the processing would have been justified under its legitimate interest to free up the data subject’s locker and make it available to other employees. Holding — On the position of the former employer — The DPA issued a €6,600 fine over the violation of Articles 5, 6, and 13 GDPR. On the material scope of the GDPR — First, the DPA found that the personal items in the locker constituted personal data under Article 4(1) GDPR because they provided information about an identified natural person (i.e.: the data subject). Second, the DPA held that the opening of the locker, the filming of the operation, and the subsequent destruction of the employee's belongings, constituted data processing operations for the purpose of Article 4(2) GDPR. In this regard, the DPA clarified that the notion of “data processing” is to be understood broadly and that the data processing operations, listed in the Article, are mere examples. Finally, the DPA held that the notion of a “filing system” under Article 2(1) GDPR, must also be construed broadly. On these grounds, the DPA held that the case fell within the material scope of the GDPR. On lawfulness — The DPA held that legitimate interest was not a viable legal basis in the case at hand. Furthermore, the DPA held that the controller did not balance its legitimate interest correctly anyway. In this regard, the DPA observed that the reasonable expectation of data subjects are relevant to the balancing of legitimate interests. In the case at hand, the data subject had agreed to an appointment in order to empty his locker and, therefore, could not reasonably expect that the locker would be opened beforehand. On these grounds, the DPA held that the processing of personal data was unlawful. On transparency and fairness — The DPA held that the controller failed to provide workers with written information on its locker room policy. Furthermore, the DPA found that the controller failed to inform the worker about the urgency of clearing out his locker. In the DPA’s view, the controller should have communicated this urgency more clearly and should have given the data subject an ultimatum to clear his locker within a specific deadline. The DPA also found that the controller failed to inform the data subject about the opening of his locker, even after it had taken place. On these grounds, the DPA found a violation of Article 13 GDPR. The DPA also clarified that within the employment relationship the obligation to provide information to data subjects is a consequence of the general principle of fairness. On these grounds, the DPA found a violation of Article 5(1)(a) GDPR. Other findings — The DPA held that the controller processed personal data very invasively by viewing items of personal and intimate nature. On these grounds, the DPA found a violation of the principle of data minimization. On the position of the staffing agency — As explained above, the staffing agency was not directly involved in the opening of the locker but served as a messenger between the data subject and the controller, in order to help solve the locker issue. During the procedure, the staffing agency claimed that it had no role in the processing of personal data at hand, as it was not part of the employment relationship between the data subject and the controller. In this regard, the agency pointed out to a professional code of conduct for the sector. The DPA did not counter the argument and did not issue any findings with regards to the position and responsibilities of the staffing agency.

### UODO (Poland) - DKN.5131.7.2022

*Source: UODO (Poland), 2026-04-13 — https://overview.legal/posts/53109 — original: https://gdprhub.eu/index.php?title=UODO_(Poland)_-_DKN.5131.7.2022*

Facts — An electricity sales company (the controller) had outsourced some of its operations to two processors and one sub-processor. Employees of the sub-processor had used a smartphone application between July 2020 and March 2021 to send pictures of customer contracts containing the personal data of individuals residing at addresses visited during door-to-door sales (the data subjects). The controller had not authorised this practice, and former employees of the sub-processor could still access the personal data through the app. The controller identified the use of the app as a data breach and notified the supervisory authority about it in April 2021. The DPA initiated administrative proceedings in March 2022. Holding — First, the DPA held that the controller had violated the principles of integrity and confidentiality enshrined in Article 5(1)(f) and the principle of accountability laid down in Article 5(2) GDPR. It had also violated Articles 24(1), 25(1), 28(1), 32(1) and 32(2) GDPR, which specify these principles. The DPA issued the controller a reprimand. The DPA found the controller had failed to implement appropriate technical and organisational measures itself and also failed to properly verify whether the (sub-)processors had provided sufficient guarantees that they had implemented such measures. The data protection agreements required in Article 28(1) GDPR were very general in nature, and none of the parties in the chain of contracts had conducted a risk analysis to select appropriate security measures. In addition, the controller had not continuously monitored the processing activities. Second, the DPA held that the two processor and the sub-processor had violated Articles 32(1) and 32(2) GDPR read in conjunction with Article 28(4) GDPR. They had all failed to implement appropriate technical and organisational measures to ensure the security of personal data processing. The sub-processor was largely held responsible for the data breach – it had started using the app to process customers’ personal data without authorisation from the controller or the processors. Furthermore, the DPA pointed out the sub-processor should have verified whether the application would allow access to the personal data through it even after the termination of the employment relationship. The DPA reprimanded the processors and fined the sub-processor €2,415.

### AEPD (Spain) - EXP202306354 (PS/00312/2024)

*Source: AEPD (Spain), 2026-02-11 — https://overview.legal/posts/52464 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_EXP202306354_(PS/00312/2024)*

Facts — The Spanish Data Protection Agency (AEPD) investigated Vodafone España, S.A.U. as controller after a SIM swapping incident. On 21 September 2021, an unknown third party requested a duplicate SIM card for the mobile line of a data subject. The request was made through Vodafone’s internal telephone support channel for retail stores. The caller impersonated staff and provided several data elements, including the store user code, the data subject’s identification number, the mobile phone number and digits of the ICC number of the new SIM card. Vodafone processed the request and activated the duplicate SIM card. On the same day, the data subject’s phone stopped working. Shortly afterwards, four unauthorised transactions totalling €1,996 were carried out from their bank account. The data subject contacted Vodafone, their bank and the police. Vodafone confirmed that a duplicate SIM card had been issued through a physical point of sale. After the data subject presented a complaint, during the investigation, Vodafone explained that its internal policy required store staff to call a dedicated support channel and provide identifying information before a duplicate SIM could be issued. Vodafone stated that the fraudster had provided the required information and that the security protocol in force at the time had been followed. The controller also informed the AEPD that it later adopted additional measures to reinforce the security of the duplicate SIM procedure. On the basis of these facts, the AEPD opened sanctioning proceedings against Vodafone for an alleged infringement of Article 6(1) GDPR. Holding — The AEPD found that Vodafone infringed Article 6(1) GDPR by processing the personal data of the data subject without a valid legal basis. The AEPD held that the issuance and activation of a duplicate SIM card involved the processing of personal data. Vodafone carried out this processing without the knowledge or consent of the data subject and without any other legal basis under Article 6(1) GDPR. As a result, the processing was unlawful. The AEPD rejected the controller’s argument that it had complied with its internal security protocols. The DPA stated that the existence of internal procedures did not remove the obligation to ensure that processing had a valid legal basis. The intervention of a criminal third party did not exempt the controller from responsibility where the unlawful processing occurred within its own systems and procedures. The AEPD considered that Vodafone acted at least negligently. It took into account the nature of the infringement and the link between the processing and the controller’s core business activity. The DPA imposed an administrative fine of €150,000 on Vodafone for the infringement of Article 6(1) GDPR.

### AEPD sanctions 23andMe for security failures in credential-stuffing breach

*Source: AEPD (Spain), 2025-10-10 — https://overview.legal/posts/158429 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS-00140-2025*

Facts — 23ANDME, INC., the controller, is a personal genomics and biotechnology company established in the United States which offered genetic testing services to individuals in Spain. In October 2023, the controller suffered a personal data breach following a credential-stuffing attack. Attackers accessed customer accounts by using login credentials that customers had reused on other services previously compromised. The breach affected 2,642 customers residing in Spain and exposed identity, contact and location data, images, genetic data, health data and data revealing ethnic origin. A sample of the data was published on an online forum, while a file containing the compromised data was offered for sale on the dark web. At the time of the breach, customers accessed their accounts using a username and password. Multi-factor authentication was available but optional. The controller had not established specific password-strength requirements or periodic password changes and had not implemented limits on access requests or downloads based on IP addresses. Once an account had been accessed, there were no additional controls limiting the viewing or downloading of sensitive data, including information relating to potential relatives. On 1 October 2023, the controller detected a Reddit post offering information allegedly belonging to its customers. On 5 October, it confirmed that one of the published records belonged to a customer. It published an alert on its website on 6 October, reported the incident to US authorities on 7 October and required customers to reset their passwords on 9 October. The controller informed all customers about the incident on 10 October. It identified 799 affected customers residing in Spain on 12 October and notified them on 13 October. It subsequently identified and notified another 1,843 customers residing in Spain on 24 October. However, the controller did not notify the DPA until 17 October 2023 and submitted additional information on 30 October. Holding — The DPA held that the GDPR applied pursuant to Article 3(2) GDPR because the controller, although not established in the EU, offered genetic testing and analysis services to data subjects in the Union. First, the DPA found a violation of Article 5(1)(f) GDPR. The controller had failed to process personal data in a manner ensuring appropriate integrity and confidentiality. The adequacy of its security measures had to be assessed in light of Articles 24(1) and 32 GDPR and the risk-based approach established by the GDPR. The DPA emphasised that the affected information included genetic data, health data and data revealing ethnic origin, which constitute special categories of personal data under Article 9 GDPR. Given the sensitivity of this information and the potential consequences of unauthorised disclosure, the controller was required to implement particularly robust security measures. Nevertheless, the controller did not impose specific password-strength requirements or require passwords to be changed periodically. Although it had implemented multi-factor authentication, its use remained optional. Moreover, it had not introduced additional controls or limits concerning account access, access requests or the downloading of sensitive information. These deficiencies made unauthorised access more difficult to detect and facilitated the extraction of the compromised data. The DPA rejected the suggestion that responsibility could be shifted to customers because they had reused their credentials. Although customers were responsible for using their credentials appropriately, the controller remained responsible for assessing the risks and implementing security measures appropriate to the nature of the processing. Credential theft was a well-known attack vector, particularly relevant where account access allowed users to view or download genetic and health information. Second, the DPA found a violation of Article 33 GDPR. It considered that the controller became aware of the personal data breach on 5 October 2023, when it confirmed that one of the records published online belonged to one of its customers. At that point, it had a reasonable degree of certainty that a security incident involving personal data had occurred. The controller’s subsequent actions, including publishing an alert, notifying US authorities and requiring password resets, further demonstrated that it was already aware of the breach. However, it did not notify the DPA until 17 October, substantially exceeding the 72-hour deadline. The DPA stressed that notification cannot be postponed until all affected individuals and all details of the incident have been identified. Article 33(4) GDPR expressly permits information to be provided in phases when it cannot be submitted simultaneously. The controller’s need to assess its notification obligations across several jurisdictions therefore did not justify the delay, particularly because the breach involved sensitive data posing a high risk to the affected individuals. The DPA imposed a total administrative fine of €2,400,000: - €2,000,000 for the violation of Article 5(1)(f) GDPR; - €400,000 for the violation of Article 33 GDPR.

## Recent developments

### ICO (UK) - ACRO Criminal Records Office

*Source: GDPRhub, 2026-08-21 — https://overview.legal/posts/291401 — original: https://gdprhub.eu/index.php?title=ICO_(UK)_-_ACRO_Criminal_Records_Office*

The ICO reprimanded ACRO for failing to implement appropriate security measures, including effective patch management and security monitoring, resulting in prolonged unauthorised access to systems containing sensitive personal data. English Summary. Facts. ACRO Criminal Records Office, the processor, is a national police unit providing public services including Police Certificates, International Child Protection Certificates, Subject Access Requests and Record Deletion Requests. It processes per

### ANSPDCP (Romania) - AMATO BESTSELLER S.R.L.

*Source: GDPRhub, 2026-08-18 — https://overview.legal/posts/291260 — original: https://gdprhub.eu/index.php?title=ANSPDCP_(Romania)_-_AMATO_BESTSELLER_S.R.L.*

The DPA imposed a 54,300 fine to a controller for violations of Article 32(4), Article 14 and Article 5(1)(c) in conjunction with Article 9 GDPR and ePrivacy Directive.The DPA imposed a RON 285,395 (€54,300) fine on a wholesale company for, amongst others, failing to implement appropriate security measures, allowing former employees to access personal data as well as for unlawfully using automated dialing and communication systems to call a significant number of data subjects. English Summary. E

### Three recommendations from the AP (Autoriteit Persoonsgegevens - Dutch Data Protection Authority) compiled together.

*Source: Government, 2025-03-10 — https://overview.legal/posts/52247*

Three recommendations from the Dutch Authority for the Financial Markets (Autoriteit Financiële Markten - AP) combined: (regarding the handling of data breaches; a task to improve the privacy organization of the Tax Authority; and exemption from the obligation of tax confidentiality in cases of suspected violations of tax integrity under Article 67, paragraph 3, of the Act on Financial Supervision).

### AEPD publishes GDPR Risk Assessment

*Source: AEPD, 2022-10-11 — https://overview.legal/posts/6259 — original: https://evalua-riesgo.aepd.es/index_en.html#entry-1032*

> GDPR RISK ASSESSMENT is intended to assist controllers and processors to identify the risk factors for the rights and freedoms of data subjects whose data are present in the processing, to make an initial assessment of the intrinsic risk, including the need to perform a DPIA, and to estimate the residual risk if measures and safeguards are used to mitigate the specific risk factors.

### An analysis of Dutch case law: what factors play a role in awarding (or not) and determining the extent of damages under the GDPR?

*Source: News, 2022-11-17 — https://overview.legal/posts/6245 — original: https://www.vast-online.nl/art/4442/een-analyse-van-de-nederlandse-rechtspraak-welke-factoren-spelen-een-rol-bij-het-al-dan-niet-toekennen-en-vaststellen-van-de-omvang-van-een-schadevergoeding-op-grond-van-de-avg#entry-1349*

Since May 2018, the GDPR has been directly applicable in the European Economic Area, including the member states of the European Union, Liechtenstein, Norway, and Iceland. Four years later, awarding damages for GDPR violations is still not a common practice in the Netherlands, despite the fact that news reports regularly mention data breaches and other GDPR violations. This article analyzes Dutch case law over the past four years to see what factors may influence the awarding of damages under th

## Literature

### The Court of Justice on the Excessiveness of Access Requests under the GDPR

*Source: European Journal of Risk Regulation, 2026-07-09 — https://overview.legal/posts/83502 — original: https://doi.org/10.1017/err.2026.10117*

Abstract This case note comments on the preliminary ruling of the Court of Justice of the EU in Case C-526/24 Brillen Rottler v TC of 19 March 2026, which addresses the abuse of rights under the General Data Protection Regulation (GDPR), specifically in the context of requests for access to personal data under Article 15 GDPR and compensation under Article 82 GDPR. First, the Court held that even a first access request may be regarded as “excessive” where the controller demonstrates that it was

### Privacy vs. business convenience: the Mousse judgment and the future of data protection in the EU

*Source: Unio - EU Law Journal, 2025-06-18 — https://overview.legal/posts/53865 — original: https://doi.org/10.21814/unio.11.1.6632*

The Mousse ruling represents a pivotal moment in EU data protection law, reinforcing strict limitations on personal data processing and clarifying the legal standards under the General Data Protection Regulation (GDPR). The Court of Justice of the European Union (CJEU) reaffirmed that data collection must be objectively indispensable for a specified legal basis, rejecting broad interpretations of contractual necessity and legitimate interest. Additionally, the ruling confirms that the right to o

### Collective Damages for GDPR Breaches: A Feasible solution for the GDPR Enforcement Deficit?

*Source: European Data Protection Law Review, 2022-01-01 — https://overview.legal/posts/132504 — original: https://doi.org/10.21552/edpl/2022/4/8*

### All Talk, No Action? The Effect of the GDPR Accountability Principle on the EU Data Protection Paradigm

*Source: European Data Protection Law Review, 2022-01-01 — https://overview.legal/posts/132554 — original: https://doi.org/10.21552/edpl/2022/1/6*

ED P L 1 | 2 0 2 2 1 9 A l l T al k, N o A ct i o n ? T h e Ef f ect o f t h e G D P R A cco u n t ab i l i t y P r i n ci p l e o n t h e EU D at a P r o t ect i o n P ar ad i gm T u u l i a K a r j a l a i n e n * T h e G e n e r a l D a t a P r o t e c t i o n R e g u l a t i o n ( 679/ 201 6, ’ G D P R ’ ) i n t r o d u c e d t h e a c c o u n t a b i l i t y p r i n c i p l e t o t h e f i e l d o f E U d a t a p r o t e c t i o n l a w . T h e p r i n c i p l e a i m s t o i n c r e a s e t h e c o n t r o l l e r ’ s r e s p o n s i b i l i t y f o r i t s p e r s o n a l d a t a p r o c e s s i n g a n d t o p r o m o t e a r i s k - b a s e d a p p r o a c h t o d a- t a p r o t e c t i o n . H o w e v e r , a c c o u n t a b i l i t y , a s i m p l e m e n t e d i n t h e G D P R , f a i l s t o m e e t t h e s e o b- j e c t i v e s . A c c o u n t a b i l i t y i s s o m e t i m e s s e e n a s a s i g n i f i c a n t p a r a d i g m s h i f t – a s a m o v e a w a y f r o m t r a n s p a r e n c y a n d c h o i c e - b a s e d d a t a s u b j e c t c o n t r o l t o w a r d s c o m p a n y l i a b i l i t y . H o w- e v e r , t h e p r i n c i p l e d o e s n o t t r u

### GDPR Implementation Series ∙ Malta: An Overview of the GDPR Implementation

*Source: European Data Protection Law Review, 2020-01-01 — https://overview.legal/posts/132480 — original: https://doi.org/10.21552/edpl/2020/4/15*

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Security** — https://overview.legal/topics/beveiliging
  Technical and organizational measures to protect personal data
- **Law Enforcement** — https://overview.legal/topics/law-enforcement
  Processing for law enforcement purposes
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers

---
Generated by overview.legal · https://overview.legal/topics/integrity-confidentiality-principle · 2026-08-22
