# IP Address — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/ip-adres
> Sources are cited per item. Verify against the official texts before relying on them.

Internet protocol addresses as personal data

## Overview

## Legal Framework

Recital 30 GDPR explicitly identifies internet protocol addresses as online identifiers that may be associated with natural persons. When combined with unique identifiers and other server-side information, IP addresses can generate traces used to create profiles and identify individuals. This places IP addresses squarely within the definition of personal data under Article 4(1) GDPR, provided the data subject is identifiable—directly or indirectly—by the controller or by any other person.

Recital 64 GDPR reinforces that controllers must use all reasonable measures to verify data subject identity in the context of online services and online identifiers, while prohibiting retention of personal data solely to respond to potential access requests.

The legal threshold for identifiability turns on whether the controller has the legal means to link the IP address to an individual. Article 2(a) of Directive 95/46—the predecessor provision substantively carried forward into Article 4(1) GDPR—establishes that a dynamic IP address constitutes personal data where the holder possesses legal means enabling identification through additional data held by an internet service provider.

## Key Developments

The CJEU's ruling in *Breyer v. Bundesrepublik Deutschland* established the controlling standard. The Court held that a dynamic IP address registered by an online media services provider constitutes personal data where that provider has the legal means to identify the data subject by combining the IP address with additional data held by the internet service provider. Critically, the Court rejected the argument that only the ISP could make the connection; what matters is whether the website operator possesses a legal right to obtain the identifying data from the ISP, not whether it has already done so.

The *Planet49* decision extended the transparency framework to IP addresses collected through cookies, requiring service providers to inform users about cookie duration and third-party access. The *Fashion ID* ruling clarified that the duty to inform attaches only to processing operations where the operator actually determines purposes and means, and that information must be provided at the point of collection.

Dutch enforcement, including the *Microsoft Ireland Operations / Xandr* decision, confirmed that cookie IDs and the IP addresses transmitted alongside them are online identifiers constituting personal data under the GDPR. The Dutch DPA has treated the combination of cookie identifiers and IP addresses as personal data without requiring further analysis.

Enforcement actions demonstrate financial exposure: CNIL's €5,000,000 fine against IQVIA Operations France addressed non-compliance with general processing principles, while the Spanish AEPD fined SIPHONE 2020 €4,000 for insufficient legal basis—both contexts involving online identifier processing.

## Practical Guidance

- **Conduct a legal means analysis**: For each IP address processing operation, document whether your organization has the legal ability to obtain subscriber-identifying data from the relevant ISP. If such legal means exist—through court orders, police requests, or contractual arrangements—the IP address is personal data and full GDPR obligations apply, per *Breyer*.

- **Provide Article 13 transparency at collection point**: When IP addresses are collected through website access or cookies, deliver privacy information immediately at the point of collection, including details on cookie duration and third-party access, as required under *Planet49* and *Fashion ID*.

- **Establish a valid Article 6 legal basis**: Relying on legitimate interests under Article 6(1)(f) requires a documented balancing test. The AEPD's action against SIPHONE demonstrates that insufficient legal basis for IP address processing triggers enforcement even at modest processing volumes.

- **Minimize retention of dynamic IP addresses**: Since Recital 64 prohibits retaining personal data solely for potential access request responses, implement technical measures such as truncation or pseudonymization of IP address logs where full retention is not justified by a separate legal basis.

- **Treat IP addresses combined with cookie IDs as personal data by default**: Following the *Microsoft/Xandr* Dutch decision, do not attempt to argue that cookie IDs or transmitted IP addresses fall outside GDPR scope. Build compliance architecture on the assumption that these identifiers are personal data.

## Legislation (full text of key provisions)

### Recital 30 — online identifiers enabling personal profiling

*Source: GDPR, gdpr-rec-30-en, 2016-04-27 — https://overview.legal/posts/91575*

Natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols, such as internet protocol addresses, cookie identifiers or other identifiers such as radio frequency identification tags. This may leave traces which, in particular when combined with unique identifiers and other information received by the servers, may be used to create profiles of the natural persons and identify them.

### Recital 64 — data subject identity verification for access

*Source: GDPR, gdpr-rec-64-en, 2016-04-27 — https://overview.legal/posts/91643*

The controller should use all reasonable measures to verify the identity of a data subject who requests access, in particular in the context of online services and online identifiers. A controller should not retain personal data for the sole purpose of being able to react to potential requests.

## Case law

### BVerwG - 6 C 13.18

*Source: GDPRhub, 2026-07-24 — https://overview.legal/posts/158441 — original: https://gdprhub.eu/index.php?title=BVerwG_-_6_C_13.18*

Facts — Since 2016, SpaceNet AG, an ISP, has been challenging a German law which provides for an obligation to store traffic and location data of all users without any reason and across the board, arguing it is incompatible with the EU Charter of Fundamental Rights. Holding — Question referred "In the light of Articles 7, 8 and 11 and Article 52(1) of the Charter of Fundamental Rights of the European Union, on the one hand, and of Article 6 of the Charter of Fundamental Rights of the European Union and Article 4 of the Treaty on European Union, on the other hand, is Article 15 of Directive 2002/58/EC to be interpreted as precluding national legislation which obliges providers of publicly available electronic communications services to retain traffic and location data of end users of those services where that obligation does not require a specific reason in terms of location, time or region, the following data are the subject of the storage obligation in the provision of publicly available telephone services — including the transmission of short messages, multimedia messages or similar messages and unanswered or unsuccessful calls: the telephone number or other identifier of the calling and called parties as well as, in the case of call switching or forwarding, of every other line involved, the date and time of the start and end of the call or — in the case of the transmission of a short message, multimedia message or similar message — the times of dispatch and receipt of the message, and an indication of the relevant time zone, information regarding the service used, if different services can be used in the context of the telephone service, and also, in the case of mobile telephone services the International Mobile Subscriber Identity of the calling and called parties, the international identifier of the calling and called terminal equipment, in the case of pre-paid services, the date and time of the initial activation of the service, and an indication of the relevant time zone, the designations of the cells that were used by the calling and called parties at the beginning of the call, in the case of internet telephone services, the Internet Protocol addresses of the calling and the called parties and allocated user IDs, the following data are the subject of the storage obligation in the provision of publicly available internet access services: the Internet Protocol address allocated to the subscriber for internet use, a unique identifier of the connection via which the internet use takes place, as well as an allocated user ID, the date and time of the start and end of the internet use at the allocated Internet Protocol address, and an indication of the relevant time zone, in the case of mobile use, the designation of the cell used at the start of the internet connection, the following data must not be stored: the content of the communication, data regarding the internet pages accessed, data from electronic mail services, data underlying links to or from specific connections of persons, authorities and organisations in social or ecclesiastical spheres, the retention period is four weeks for location data, that is to say, the designation of the cell used, and ten weeks for the other data, effective protection of retained data against risks of misuse and against any unlawful access to that data is ensured, and the retained data may be used only to prosecute particularly serious criminal offences and to prevent a specific threat to life and limb or a person’s freedom or to the continued existence of the Federal Republic or of a Federal Land, with the exception of the Internet Protocol address allocated to a subscriber for internet use, the use of which data is permissible in the context of the provision of inventory data information for the prosecution of any criminal offence, maintaining public order and security and carrying out the tasks of the intelligence services?"

### OLG München - 36 U 1054/25 e

*Source: Higher Regional Court Munich, 2026-06-26 — https://overview.legal/posts/184545 — original: https://gdprhub.eu/index.php?title=OLG_München_-_36_U_1054/25_e*

Facts — The data subject had used a social media platform operated by the controller, an Irish company, since 2013. The controller provided “Business Tools” to third-party website operators and app providers. These tools enabled the controller to obtain data concerning how users interacted with third-party websites and apps, including information about page visits, purchases and advertisements clicked. In November 2023, the data subject requested that the controller recognize that the processing of his personal data was contrary to the parties’ contract, erase or anonymize the personal data, provide access to the personal data and pay compensation. The data subject subsequently brought an action before the Regional Court of Munich II, seeking a declaration that the parties’ user contract did not permit the processing, cessation of the processing of personal data collected through the Business Tools on third-party websites and apps, restriction of further processing, erasure or anonymization of previously collected data and at least €5,000 in non-material damages. The relevant data included direct and indirect identifiers, such as his name, contact details, IP address and internal identifiers, as well as website URLs, visit times, app names and information about his interactions with websites and apps. The Regional Court of Munich II dismissed the action, holding that the declaratory and erasure or anonymization claims were inadmissible, the cessation claims were legally unavailable and the damages claim had not been sufficiently substantiated. In relation to the damages claim, it found that the data subject had not identified specific third-party websites or apps through which his personal data had been processed. The data subject accordingly appealed to the Higher Regional Court of Munich. Holding — The Higher Regional Court of Munich partially upheld the appeal. First, the court held that the Controller processed the data subject’s personal data under Articles 4(1) and 4(2) GDPR by receiving data transmitted through its Business Tools, associating it with a user account and storing it. The data subject was not required to identify every website, app or individual transmission because the relevant information was principally within the controller’s knowledge and it was sufficiently probable that he had been affected. Second, referring to CJEU C‑40/17 concerning the broad interpretation of “controller”, the court held that the controller was a joint controller under Articles 4(7) and 26 GDPR for the collection and transmission of the personal data. It controlled the programming of the Business Tools and participated in determining the purposes and means of processing. Allocating certain obligations to third-party website and app operators did not remove its responsibility. Third, referring to CJEU C‑252/21, the court held that the controller had not established a lawful basis for the processing of the personal data. The processing was not justified by consent under Article 6(1)(a), contractual necessity under Article 6(1)(b), a legal obligation under Article 6(1)(c), a public-interest task under Article 6(1)(e), or legitimate interests under Article 6(1)(f) GDPR. Accordingly, the court held that the controller's processing infringed Articles 5(1)(a), 5(1)(b), 5(1)(c) and 6 GDPR. Relying on CJEU C‑655/23, the court granted an injunction against future unlawful processing under German law. It also ordered restriction pending erasure under Article 18(1)(b) and erasure under Article 17(1)(d) GDPR. The court upheld the dismissal of the separate declaratory claim and also rejected anonymization of the website and app interaction data. Finally, relying on BGH VI ZR 10/24, the court awarded €1,500 in non-material damages under Article 82(1) GDPR for the data subject’s loss of control over his personal data.

### French Supreme Admin Court partly upholds challenge to graduated response IP data decree

*Source: Supreme Administrative Court, 2026-04-30 — https://overview.legal/posts/122869 — original: https://gdprhub.eu/index.php?title=CE_-_N._433539*

Facts — Several digital rights organisations asked the Prime Minister to repeal Decree No. 2010-236 of 5 March 2010. The decree regulated an automated personal data processing system used by the French authority for freedom of communications (ARCOM, hereinafter the French authority) for France’s online copyright enforcement mechanism, known as the graduated response procedure. Under this system, the French authority could receive IP addresses linked to alleged copyright infringements and request the corresponding subscriber identity data from electronic communications operators. This data could then be used to send warnings to subscribers and, in repeated cases, refer the matter to the public prosecutor. The applicants argued that the decree allowed the French authority to access personal data linked to IP addresses without sufficient safeguards under EU law. The court had previously referred questions to the CJEU, which ruled in Case C-470/21 that such access may be allowed, but only under strict conditions. Following the CJEU judgment, the court reviewed whether the French decree complied with EU law. Holding — The court partly upheld the action. First, the court held that EU law allows the general and indiscriminate retention of IP addresses for combating criminal offences in general only where serious interference with private life is effectively excluded. This requires strict separation between different categories of retained data, secure technical safeguards and regular monitoring by an independent public authority. The court found that French law did not require electronic communications operators to retain subscriber identity data and IP-related data under these conditions. Therefore, the decree was unlawful insofar as it allowed the French authority to process data that had not necessarily been retained in compliance with EU-law safeguards. Second, the court held that the French authority may access subscriber identity data linked to IP addresses in order to identify persons suspected of online copyright infringements and send the first two warnings under the graduated response procedure. However, the court distinguished the third access to such data. At that stage, the authority is no longer dealing with an isolated identification request: it has already linked the same person’s identity twice with alleged unlawful online activity and with the protected works concerned. A third access therefore allows the authority to build a more detailed picture of the person’s conduct and may reveal sensitive aspects of their private life. It also marks a more serious procedural stage, since it may lead to a registered letter and ultimately to referral to the public prosecutor. For that reason, EU law requires prior authorisation by a court or an independent administrative body before this third access takes place. The decree did not provide for such prior review, so the court held that it was unlawful to that extent. For this third access, EU law requires prior authorisation by a court or an independent administrative body. The decree did not provide for such prior review. The court therefore held that the decree was unlawful to that extent. The court annulled the Prime Minister’s refusal to repeal the unlawful parts of the decree and ordered their repeal. It also held that the French authority must stop applying the unlawful provisions. However, the French authority may still access identity data for the first and second warnings, and may request access in serious copyright offence cases under the conditions set out in the judgment.

### CJEU - C-582/14 - Breyer

*Source: GDPRhub, 2016-10-19 — https://overview.legal/posts/125655 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-582/14_-_Breyer*

Facts — Mr. Breyer accessed several websites, which provided topical information, operated by German Federal Institutions which were accessible to the public. To prevent attacks, the sites stored information on all access operations in log files. Information stored include name of the web page, terms entered in the search fields, time of access, quantity of data transferred, an indication of whether the access was successful and the IP address of the computer that accessed the website. Mr. Breyer brought an action before the German Administrative Court seeking an order to restrain the Federal Republic of Germany from storing his access information of his visit to the website. This first action was dismissed. He appealed to the Court of Appeal. The court granted the injunction but only in part. The court ordered the Federal Republic of Germany to refrain from storing or arranging with third parties to store, at the end of each consultation period, information relating to Mr. Breyer's access including his IP address and any information that could result in revealing his identity. The court further stated that a dynamic IP address together with the date on which the website was accessed, where the user had revealed his identity during that consultation period, amounts to personal data since the user’s identity is tied to that particular dynamic IP address. On the other hand, the court observed stated that where Mr Breyer did not reveal his identity and only the internet service provider knew his identity the dynamic IP address doesn’t amount to personal data. Mr Breyer and the Federal Republic of Germany each brought an appeal on a point of law before the Federal Court of Justice, Germany (Bundesgerichtshof). Mr Breyer sought to have his application for an injunction upheld in its entirety while the Federal Republic of Germany sought to have it dismissed. The Federal court stayed the proceedings and referred the following issues to the CJEU. Dispute — The CJEU answered the following questions: a) Whether a dynamic IP address constitutes personal data as defined under Article 2(1)(a) Directive 95/46 where a third party has additional knowledge required to identify a data subject. b) Whether Article 7(1)(f) prevents a provision in national law that allows a service provider to collect and use personal data without the data subject’s consent for purposes of ensuring general operability of the tele-medium. Holding — On the first question, the court reiterated personal data under Article 2(1)(a) Directive 95/46 is defined as information relating to an identified or an identifiable natural person. Also, an identifiable person is one who can be identified directly or indirectly by reference to an identification number or to one or more factors that are specific to the person’s physical, physiological, mental, economic, cultural or social identity. The court also noted that it was held in Scarlet Extended (C‑70/10), IP addresses of internet users were protected as personal data because they allowed users to be identified even though this case was concerning collection and identification of IP addresses by internet service providers. In answering this question, the court observed that a dynamic IP address alone doesn’t amount to information of an identified person but for it to fall under the definition in Article 2(1)(a) Directive 95/46 there must be additional data that can lead to the identification of a natural person. The court referred to Recital 26 Directive 95/46 which states that to determine whether a person is identifiable, account should be taken of all the means likely reasonably to be used either by the controller or by any other person to identify the said person. The referring court highlighted that German law doesn’t allow internet service providers to transmit data necessary for the identification of a data subject directly to online media services providers except in the event of cyber attacks when the online media services provider can contact a competent authority who can contact the internet service provider for such information that may help bring criminal proceedings. In light of this, the court held that an IP dynamic address is personal data where an online media services provider has legal means that enable them to identify natural persons. On the second question, the court first examined whether the processing activities if the General Federal Institute fall under the exception under Article 3(2) Directive 95/46 of processing activities of the state in criminal law. On this, the court referred to the decisions in Lindqvist, C‑101/01 and Satakunnan Markkinapörssi and Satamedia, C‑73/07 where it was stated that activities of the state or state authorities fall under the exception in Article 3(2) Directive 95/46. In the present case, the court observed that despite the status of the German Federal Institutions as public authorities, their activities fall outside the area of state criminal law activities. On to the main question of consent, the court referred to the wording under Article 7(1)(f) Directive 95/46 that provides that personal data may be processed based on a legitimate interest of a controller or a third party, without the consent of the data subject, except where such interests are overridden by the interests, fundamental rights and freedoms of the data subject. Besides, the court referred to the judgement in ASNEF and FECEMD, C‑468/10 and C‑469/10 at paragraphs 30 and 32 where the court held that Article 7 Directive 95/46 provides an exhaustive and restrictive list of cases in which the processing of personal data can be regarded as being lawful. Also, member states cannot add new principles relating to the lawfulness of processing personal data or impose additional requirements that have the effect of amending the scope of one of the six principles provided for in that article. This position is clearly stipulated under Article 5 Directive 95/46 which provides the margin of discretion that member states have according to Article 7 Directive 95/46. In light of this, the court observed that Paragraph 15 of TMG, if interpreted strictly, has a more restrictive scope than that stipulated under Article 7 Directive 95/46. The court held that the provision under Paragraph 15 reduces the scope of the principle laid down under Article 7 Directive 95/46 by excluding the balance of the controller’s interest and the fundamental rights and freedoms of users which call for protection under Article 1(1) Directive 95/46.

### Judgment of the Court (First Chamber) of 3 April 2025.#L. H. v Ministerstvo zdravotnictví.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 4 – Definitions – Article 6 – Lawfulness of processing – Article 86 – Public access to official documents – Data concerning the representative of a legal person – Case-law of a national court imposing an obligation to inform and consult the data subject prio

*Source: Court of Justice of the European Union, C-710/23, 2025-04-03 — https://overview.legal/posts/132145 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0710*

In Case C-710/23, the Court of Justice of the European Union (First Chamber) addressed a preliminary reference from the Czech Supreme Administrative Court concerning whether personal data of individuals acting as representatives of legal persons, contained in official documents related to COVID-19 screening test contracts, may be disclosed under GDPR Article 86 and the lawfulness of processing under Article 6. The case arose from a dispute between L.H. and the Czech Minister of Health, who had refused to disclose certain information about representatives of legal persons named in those contracts and related certificates. The Court held that data concerning a representative of a legal person constitutes personal data within the meaning of the GDPR when it allows the natural person to be identified, and that Member States may provide for public access to official documents containing such personal data, provided that the disclosure is reconciled with the right to data protection; however, a national court cannot impose a general obligation to inform and consult the data subject prior to every disclosure of official documents, as this would undermine the public's right of access to official documents.

### HvJ EU 9 januari 2025, C‑394/23 (Mousse).

*Source: CJEU, 2025-01-09 — https://overview.legal/posts/50377 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0394*

HvJ EU 9 januari 2025, C‑394/23 (Mousse). Artikelen: 5(1)(c), 6(1), en 21 AVG Onderwerp : Beginsel van minimale gegevensverwerking Gek genoeg verwijst het HvJ EU zelf niet naar HvJ EU 1 augustus 2022, C‑184/20 (Vyriausioji tarnybinės etikos komisija), maar dat had hier ook heel logisch geweest.

### Judgment of the Court (Fourth Chamber) of 12 September 2024.#HTB Neunte Immobilien Portfolio geschlossene Investment UG & Co. KG and Ökorenta Neue Energien Ökostabil IV geschlossene Investment GmbH & Co. KG v Müller Rechtsanwaltsgesellschaft mbH and Others.#Requests for a preliminary ruling from the Amtsgericht München.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Points (b), (c) and (f) of the firs

*Source: Court of Justice of the European Union, C-17/22, 2024-09-12 — https://overview.legal/posts/132246 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0017*

The Court of Justice of the European Union (Fourth Chamber) issued a preliminary ruling in joined cases C-17/22 and C-18/22, originating from the Amtsgericht München, concerning the interpretation of Article 6(1)(b) and (f) GDPR in the context of investment fund partners seeking contact details of other partners with indirect shareholdings. The core issue was whether an investment fund controller could lawfully process and disclose personal data of indirectly participating partners to a direct partner based on contractual necessity, legal obligation, or legitimate interests. No fine was imposed, as the Court's ruling addressed the legal interpretation of the GDPR's lawful bases for processing in the investment fund context.

### BVwG - W 108 2284491-1

*Source: Federal Administrative Court, 2024-07-31 — https://overview.legal/posts/122850 — original: https://gdprhub.eu/index.php?title=BVwG_-_W_108_2284491-1*

Facts — The data subject visited a website operated by a media company (the controller). Upon opening the website a cookie banner showed up. This cookie banner was designed in such a way that a reject button was “hidden” in a second layer. The cookie banner’s first layer presented only an option to accept the cookies or to manage the options. The cookie manage option was presented as a link. When the data subject clicked on the accept button, they also agreed to pre-ticked options, visible only within the cookie management link. The reject button was a part of the second layer of the cookie banner (within the cookie management link). The data subject lodged a complaint with the Austrian DPA (DSB), claiming the controller violated, inter alia, Article 5(1)(a) GDPR and Article 6(1)(a) GDPR. The data subject was represented by noyb. The controller argued to the DPA that the website provided access to online newspaper articles. Because of that, the processing activities were carried for journalistic purposes and the DPA was not competent to hear the case. In the meantime the controller updated the settings of the cookie banner and introduced a reject button on its first layer, next to the accept button. Also, the link to manage the cookie settings was redesigned as a button. Moreover, the controller added a floating icon, allowing the website users to withdraw the consent given at any time. If a website user rejected the cookies or withdrew the consent via the floating icon, the controller would interpret such a conduct to be an objection under Article 21 GDPR. Additionally, the controller informed they deleted the data concerning the data subject. In response, the data subject emphasized that due to new settings of the website, the controller wrongly qualified certain cookies to be strictly necessary. In consequence, the controller installed the cookies before the website’s user interacted with the cookie banner, violating Article 5(3) ePrivacy Directive. Although the controller announced that it would implement a completely new cookie banner, they later retracted from that plan. The controller changed the cookie banner and – after improving it initially – removed the reject button again. Eventually, updated cookie banner didn’t include a reject button on the first layer any longer. The DPA issued a decision, ordering the controller to modify the cookie banner so that its first layer offered an option to close the cookie banner without giving consent. This option had to be visually equivalent to the accept button. The DPA rejected the applications of the data subject regarding the deletion of its data, an order to stop unlawful processing and establishing the violation of data confidentiality (“Recht auf Geheimhaltung”). The controller appealed the DPA’s order to introduce an equivalent reject option in the first layer of its cookie banner to the Federal Administrative Court (Bundesverwaltungsgericht – BVwG). After hearing the parties and visiting the website itself the court issued its decision. Holding — The court dismissed the appeal of the controller as unfounded. No exemption from the GDPR through media privilege (“Medienprivileg”) — The controller’s processing activities didn’t fall within the scope of journalistic purposes. The court emphasised that the controller placed the cookies and processed the collected data for analytical and advertising purposes. Need for an equivalent reject option in cookie banners — The court also upheld the interpretation of the DPA that the first layer of the cookie banner needs to contain a visually equivalent option to reject cookies. According to the court Article 7(3) GDPR implies that refusing consent shall be as easy as giving consent. In particular, refusing consent shall not require more interactions than giving consent. In the case at hand consenting required only one click, whereas rejecting consent required two clicks. Therefore no equivalence between the options was given. Furthermore, the different design of the options in the first layer – a button for consent on one hand and a link to access the second layer on the other – equally lead to the conclusion that the options cannot be considered equivalent. A mere explanation in the first layer of the cookie banner on how to reject cookies does not change this assessment. Additionally, the cookie manage link at the bottom of the website is not an equivalent option either, since it is only available after an interaction with the cookie banner. Hence, the DPA order was found to be correct. The court did not find that the controller had complied with this order in the meantime.

### Judgment of the Court (Fourth Chamber) of 11 July 2024.#Meta Platforms Ireland Limited v Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband e.V.#Request for a preliminary ruling from the Bundesgerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – First sentence of Article 12(1) – Transparency of information – Article 13(1)(c) and (e) – Obligation o

*Source: Court of Justice of the European Union, C-757/22, 2024-07-11 — https://overview.legal/posts/132250 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0757*

In a preliminary ruling requested by the German Federal Court of Justice (Bundesgerichtshof), the Court of Justice of the European Union interpreted Article 80(2) GDPR in the context of proceedings between Meta Platforms Ireland Ltd and the Bundesverband der Verbraucherzentralen und Verbraucherverbände (Consumer Association). The core issue is whether a consumer protection association may bring a representative action under Article 80(2) GDPR without a mandate from specific data subjects and independently of an actual infringement of a data subject's rights, based on a controller's alleged violation of its transparency obligations under Articles 12(1) and 13(1)(c) and (e). The Court held that such an action is permissible, finding that an infringement of the controller's information obligations constitutes an "infringement of the rights of data subjects as a result of the processing" within the meaning of Article 80(2), and that Member States may allow representative actions without requiring a specific data subject's mandate or an actual infringement of individual rights.

### Judgment of the Court (Fourth Chamber) of 7 March 2024.#IAB Europe v Gegevensbeschermingsautoriteit.#Request for a preliminary ruling from the Hof van beroep te Brussel.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Standard-setting sectoral organisation proposing to its members rules on the processing of users’ consent – Article 4(1) – Concept of ‘personal data’ – String of letters and characters ca

*Source: Court of Justice of the European Union, C-604/22, 2024-03-07 — https://overview.legal/posts/132270 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0604*

In Case C-604/22, the Court of Justice of the European Union ruled on a preliminary reference from the Brussels Court of Appeal in proceedings between IAB Europe and the Belgian Data Protection Authority (Gegevensbeschervingsautoriteit) concerning whether IAB Europe's "Transparency and Consent String" (TC String)—a coded string capturing users' consent preferences—constitutes personal data under GDPR Article 4(1) and whether IAB Europe qualifies as a (joint) controller under Article 4(7). The Court held that the TC String constitutes personal data because it can be linked to an identifiable natural person through reasonably likely means, and that IAB Europe, as a standard-setting sectoral organization determining purposes and means of processing through its framework, acts as a controller even without direct access to the data, with its responsibility extending to subsequent processing by third parties that it does not mandate but facilitates through its rules. No fine was imposed in this preliminary ruling, as the underlying Belgian DPA decision and any sanctions remain before the national court.

### Judgment of the Court (Sixth Chamber) of 7 March 2024.#Endemol Shine Finland Oy.#Request for a preliminary ruling from the Itä-Suomen hovioikeus.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Articles 2, 4, 6, 10 and 86 – Data held by a court relating to the criminal convictions of a natural person – Oral disclosure of such data to a commercial company on account of a competition organised by that company – Concept of ‘processing of personal data’

*Source: Court of Justice of the European Union, C-740/22, 2024-03-07 — https://overview.legal/posts/132269 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0740*

In Case C-740/22, the Court of Justice of the European Union (Sixth Chamber) ruled on a preliminary reference from the Itä-Suomen hovioikeus (Court of Appeal, Eastern Finland) concerning whether the oral disclosure by a court of data relating to a natural person's criminal convictions to Endemol Shine Finland Oy, a commercial company organizing a competition, constitutes "processing of personal data" under the GDPR. The Court held that such oral disclosure falls within the scope of GDPR Article 2(1), as the concept of processing is not limited by the means or format of transmission, and that national legislation governing public access to official documents must reconcile the right of access with the GDPR's data protection requirements, particularly given the sensitive nature of criminal conviction data under Article 10. No fine was imposed, as the ruling solely addressed the interpretation of EU law.

### VB v Natsionalna agentsia za prihodite

*Source: CJEU, C-340/21, 2023-12-14 — https://overview.legal/posts/51485 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0340*

Data breach alone does not establish inadequate security measures. Burden on controller to prove adequacy.

## Guidance

### EDPS Opinion 4/2026 on the Proposal for a Regulation establishing a framework of measures to facilitate the transport of military equipment, goods and personnel across the Union

*Source: EDPS, 2026-01-12-opinion-42026-regulation-framework-measures-facilitate-transport-military-equipment-goods, 2026-03-19 — https://overview.legal/posts/51417 — original: https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-42026-on-the-proposal-for-a-cybersecurity-act_en*

Opinion 4 / 2026 on the draft decision of the Dutch Supervisory Authority regarding the Controller Binding Corporate Rules of the ABB Group Adopted on 15 January 2026 1 | 2 | The European Data Protection Board Having regard to Article 63, Article 64(1)(f) and Article 47 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and…

### Report on stakeholder event on anonymisation and pseudonymisation of 12 December 2025

*Source: EDPB, report-on-stakeholder-event-on-anonymisation-and-en, 2026-02-18 — https://overview.legal/posts/125688 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/report-on-stakeholder-event-on-anonymisation-and_en*

Report on stakeholder event on anonymisation and pseudonymisation of 12 December 2025 1. Background The EDPB organise d a remote stakeholder event on 12 December 2025 to collect stakeholders’ input on anonymisation and pseudonymisation , following the Court of Justice of the European Union ( “ CJEU ” ) judgment in case EDPS v SRB 1 . The objective was to engage with stakeholders to inform the EDPB’s ongoing work on its guidelines 01/2025 on pseudonymisation and f orthcoming guidelines on…

### Art. 29 WP Guidelines on GDPR transparency requirements (WP260 rev.01)

*Source: EDPB, edpb-guidelines-on-transparency, 2025-11-21 — https://overview.legal/posts/38076 — original: https://www.edpb.europa.eu/system/files/2023-09/wp260rev01_en.pdf*

The Article 29 Data Protection Working Party issued these guidelines (WP260 rev.01), adopted on 29 November 2017 and last revised on 11 April 2018, to provide interpretive and practical guidance on the transparency requirements under the GDPR (Articles 12–14). The document addresses the form, timing, content, and modalities of information provided to data subjects, including issues such as plain language, layered privacy notices, information for children, and exceptions to the obligation to provide information. No fines or enforcement actions are imposed, as this is a guidance document rather than an enforcement decision.

### Joint Guidelines on the Interplay between the Digital Markets Act and the General Data Protection Regulation

*Source: EDPB, joint-guidelines-interplay-between-digital-en, 2025-10-13 — https://overview.legal/posts/51268 — original: https://www.edpb.europa.eu/our-work-tools/documents/public-consultations/2025/joint-guidelines-interplay-between-digital_en*

Executive summary The Digital Markets Act (DMA) and the General Data Protection Regulation (GDPR) pursue different purposes and objectives and have different scopes. While the GDPR aims to protect natural persons with regard to the processing of personal data and ensure the free flow of personal data in the U nion covering all data controllers and processors, the DMA aims to tackle unfair prac tices, and their potential harmful effects for business users, by laying down harmonised rules…

### Guidelines 02/2024 on Article 48 GDPR

*Source: EDPB, edpb-guidelines-022024-on-article-48-gdpr, 2025-06-05 — https://overview.legal/posts/38045 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-022024-on-article-48-gdpr_en*

Article  48  GDPR  provides  that:  ' Any  judgment  of  a  court  or  tribunal  and  any  decision  of  an administrative authority of a third country requiring a controller or processor to transfer or disclose personal data  may  only  be  recognised  or  enforceable  in  any  manner  if  based  on  an  international agreement, such as a mutual legal assistance treaty, in force between the requesting third country and the Union or a Member State, without prejudice to other grounds for transfer...

### Guidelines 2/2023 on Technical Scope of Art. 5(3) of ePrivacy Directive

*Source: EDPB, edpb-guidelines-on-technical-scope-of-art-53-of-eprivacy-directive, 2024-10-16 — https://overview.legal/posts/38063 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-22023-on-technical-scope-of-art-53-of-eprivacy-directive_en*

The European Data Protection Board (EDPB) issued Guidelines 2/2023 to clarify the technical scope of Article 5(3) of the ePrivacy Directive, focusing on its application to emerging tracking technologies that operate as alternatives to cookies. The guidelines establish three key elements—information, terminal equipment, and gaining access/storage—to determine whether specific technical operations require user consent. The document applies this framework to common use cases such as URL and pixel tracking, local processing, IP-based tracking, intermittent IoT reporting, and the use of unique identifiers.

### Guidelines 04/2022 on the calculation of administrative fines under the GDPR

*Source: EDPB, edpb-guidelines-on-the-calculation-of-administrative-fines-under-the-gdpr, 2023-05-24 — https://overview.legal/posts/38068 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-042022-on-the-calculation-of-administrative-fines-under-the-gdpr_en*

The European Data Protection Board (EDPB) has adopted these guidelines to harmonise the methodology supervisory  authorities use  when calculating of the amount of the fine. These Guidelines complement the previously  adopted Guidelines on the application and setting of administrative fines  for the purpose  of the Regulation 2016/679 (WP253), which focus on the circumstances in which to impose a fine. The calculation of the amount of the fine is at the discretion of the supervisory  authority, ...

### Guidelines 03/2021 on the application of Article 65(1)(a) GDPR

*Source: EDPB, edpb-guidelines-on-the-application-of-article-651a-gdpr, 2023-05-24 — https://overview.legal/posts/38137 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-032021-on-the-application-of-article-651a-gdpr_en*

The European Data Protection Board (EDPB) adopted Guidelines 03/2021 to clarify the dispute resolution mechanism under Article 65(1)(a) GDPR, which governs the EDPB's authority to issue binding decisions when a Lead Supervisory Authority receives relevant and reasoned objections from Concerned Supervisory Authorities that it does not follow. The Guidelines address the procedural framework, the threshold for "relevant and reasoned" objections, the scope of the EDPB's substantive competence, and applicable procedural safeguards including the right to be heard, access to the file, and available judicial remedies.

## Enforcement decisions

### DSB Austria: No fine imposed on COVID mask shop for cookie consent failure

*Source: DSB (Austria), 2026-01-16 — https://overview.legal/posts/144040 — original: https://gdprhub.eu/index.php?title=DSB_(Austria)_-_2026-0.043.390*

Facts — Following the first COVID-19 outbreak in March 2020, a limited liability company (the controller) decided to offer protective masks to the general public. It set up an online shop within a few days and made it publicly accessible to its customers on 28 March 2020. On 1 April 2020, a customer (the data subject) visited the controller’s online shop. They discovered that it had placed 14 cookies on their device without displaying any cookie consent banner. The customer lodged a complaint with the North Rhine-Westphalian DPA, arguing that the cookies had been stored on their device without prior opportunity for refusal. The German authority transmitted the complaint to the Austrian DPA (DSB). The controller acknowledged that, because the online shop had been set-up rapidly, it did not yet meet all technical requirements at the time of the customer’s visit, including the absence of a cookie consent pop-up. It further admitted that although a privacy policy had already been drafted, it was not publicly accessible to the users when the data subject visited the site. The controller explained that the online shop had been established as a matter of urgency due to the shortage of protective masks. It claimed it had not previously offered any business-to-consumer sales, and given the closure of physical stores and the absence of other direct sales channels, online sales were the best option under the circumstances. The controller stated during proceedings that the deficiencies had subsequently been remedied. The website was no longer accessible on 24 November 2025. Holding — The DPA found that, when the data subject accessed the online shop, the controller processed the data subject’s IP address in connection with the 14 cookies placed on their device. The cookies contained a unique user identifier and were processed for purposes including user recognition, advertising, marketing and the creation of a digital shopping cart. It acknowledged that the website had been created at short notice, that the deficiencies existed only for a brief period and that the controller had subsequently implemented a cookie banner and made a privacy policy available. The DPA held that the controller failed to transparently inform any user about the cookies that were placed, whether the cookies were technically necessary or not, since neither a cookie banner nor a publicly accessible privacy policy was available at the relevant time. The DPA emphasised that the principle of transparency requires data subjects to be able to understand which personal data concerning them are processed, for which purposes and to what extent, as well as the associated risks, rights and safeguards. This enables data subjects to exercise their rights against the controller and to demand processing that is fair and consistent with their reasonable expectations. Moreover, the DPA noted that the principle of transparency constitutes an integral part of numerous GDPR provisions, including the controller's obligation to inform data subjects about the processing of their personal data where personal data are collected directly from the data subjects pursuant to Article 13 GDPR as well as the communications standards under Article 12 GDPR. It concluded that the controller had therefore infringed Article 13 GDPR by failing to provide the required information in a concise, transparent, intelligible and easily accessible form, as required by Article 12 GDPR. The DPA considered unnecessary to further examine whether the processing was based on a valid legal basis under Article 6 GDPR, as the processing already infringed the principles laid down in Article 5 GDPR. The DPA upheld the complaint and found that the controller had infringed the principle of transparency under Article 5(1)(a) GDPR and the data subject’s right to information under Article 13 GDPR. However, it did not issue an order under Article 58(2) GDPR as it took into account that the controller had remedied the deficiencies shortly after the incident and that the website was no longer accessible.

### AEPD (Spain) - PS/00249/2025

*Source: AEPD (Spain), 2026-08-12 — https://overview.legal/posts/187487 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS/00249/2025*

Facts — MÁS SOL ENERGÍA 15, S.L., the controller, is a company that carries out customer acquisition through telephone calls to offer solar panel installation services. On 18 November 2024, the data subject received a marketing call from an agent acting on behalf of the controller. The agent addressed the data subject by name and asked questions about the type of residence in which he lived. When the data subject asked whether the controller had checked the Robinson List, the agent stated that this was unnecessary because the call was based on a “database”. When the data subject subsequently asked about the source of his personal data, the call ended. The data subject later contacted the controller’s customer service to enquire about the source of his data and was told that the data had been obtained by its sales department and might originate from his acceptance of cookies. The data subject disputed this, stating that he had never visited the controller’s website. At the time of the call, his telephone number had been registered with the Robinson List since March 2024. The controller explained that it obtained databases from external marketing providers which guaranteed that the personal data had been lawfully collected. It claimed that the data subject had consented in June 2020 through an online form to the processing of his data, the receipt of marketing communications and the disclosure of his data to third parties. As evidence, the controller provided a record containing the data subject’s details, an IP address, a timestamp and consent indicators, as well as a generic version of the relevant online form. However, the form was blank and did not contain any information specifically identifying the data subject. The controller also acknowledged that it did not independently verify the validity of the consent provided by its external supplier. Holding — The DPA held that the controller violated Article 66(1)(b) LGTel and Article 14 GDPR. First, regarding the commercial call, the DPA considered that the controller had not demonstrated that the data subject had given valid consent within the meaning of Article 4(11) GDPR. The documentation provided did not establish that the data subject personally completed the registration, entered the telephone number or could be linked to the IP address contained in the record. Moreover, the controller did not provide the privacy policy applicable when the alleged consent was obtained, meaning that it could not establish the purposes or third parties covered by that consent. The DPA recalled that, pursuant to Articles 5(2) and 7 GDPR, it is for the controller to demonstrate that valid consent was obtained. This responsibility could not be transferred to the external data provider through contractual guarantees. The controller remained responsible for establishing a valid legal basis for using the purchased data for its own marketing campaign. This was particularly relevant because the data subject's telephone number was registered with the Robinson List. Although the registration, and as specific consent was not sufficiently demonstrated, the controller could not rely on the exception under Article 23(4) LOPDGDD. Consequently, the DPA found that the unsolicited call lacked a valid legal basis and violated Article 66(1)(b) LGTel. Second, the DPA found a violation of Article 14 GDPR. Since the controller had obtained the personal data from a third party, it was required to provide the information listed in Article 14 GDPR. During the call, the agent merely referred to an unspecified “database” and did not adequately inform the data subject about the source of the data, the controller's identity, the legal basis for the processing or his data protection rights. The duration or termination of the call did not relieve the controller of this obligation, and the controller had not demonstrated that the required information was provided through another channel. The DPA imposed a fine of €5,000 for the violation of Article 66(1)(b) LGTel and a further €5,000 for the violation of Article 14 GDPR, resulting in a total fine of €10,000.

### NAIH fines online store HUF 2M for unclear and incomplete privacy notice

*Source: NAIH (Hungary), 2026-07-22 — https://overview.legal/posts/156361 — original: https://gdprhub.eu/index.php?title=NAIH_(Hungary)_-_NAIH-11443-3/2026*

Facts — The DPA initiated an investigation into the GDPR compliance of an online store (the controller) processing the data of its customers (the data subjects) in April 2025. The processing activities in question included, inter alia, cookies, registration, billing, shipping, consumer complaint, and processing of orders. The privacy notice of the company operating the online store had been in force unchanged from May 2018 to May 2025, and the period under investigation extended from 1 January 2020 to 27 June 2025. Holding — The DPA held that the controller had violated Articles 12(1), 13(1)(c), (d) and (f), and 13(2)(a) GDPR and issued the controller a fine of HUF 2,000,000 (€5,500). In addition, the DPA ordered the controller to bring its data processing operations into compliance with the GDPR and to amend the content of its privacy notice. First, the DPA found an infringement of Article 12(1) GDPR: the structure of the privacy notice was confusing and difficult to follow. The privacy notice also contained incomplete, incorrect, and unnecessary information as well as repetitive details. Based on this, the DPA concluded that the controller had failed to provide data subjects with information regarding the processing of personal data that was sufficiently concise, transparent, intelligible and easily accessible. Second, the DPA held that the controller had also violated Articles 13(1)(c), (d) and (f) GDPR by failing to specify a legal basis for certain processing operations such as the use of cookies, not specifying its legitimate interests when relying on Article 6(1)(f) GDPR as a legal basis, and not providing detailed information regarding the safeguards ensuring the lawfulness of data transfers to the United States. Finally, the DPA found a violation of Article 13(2)(a) GDPR as the controller had also failed to provide the data subjects information on the period for which the personal data processed would be stored.

### Italian DPA sanctions Lusha Systems for processing contact data without consent in B2B

*Source: Garante per la protezione dei dati personali (Italy), 2026-07-14 — https://overview.legal/posts/184678 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_542/2026*

Facts — Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database. It was an US company wholly owned by Lusha Systems Ltd. In April 2025, the Italian DPA (Garante) initiated an investigation after media reports revealed that telephone numbers of senior Italian officials were available on the platform. The DPA later received one complaint and one report from data subjects who had received unsolicited advertising communications. The data subjects further stated that after requesting information about the source of their contact details, they discovered that their data were available on the controller’s platform without their consent. The controller explained that, for a subscription fee, it provided its Clients with a Business Contact Card for each Contact. The controller further distinguished between “Clients”, namely customers who used the platform and accessed its B2B database, and “Contacts”, namely the individuals whose personal data were included in that database, regardless of whether they used or were aware of the platform. Clients received Contact Cards containing information such as names, professional email addresses, telephone numbers, job titles, roles and locations, which could be used for sales, marketing, recruitment, business intelligence and fraud prevention. The DPA limited its investigation to the processing of Contacts’ personal data. The controller stated that it collected and combined data from publicly available sources, specialised providers, affiliated companies and commercial partners. It also inferred missing professional email addresses through algorithms that identified standard company email patterns. Through its Community Program and integrations with email, calendar and CRM services, it could also obtain information from Clients’ professional networks and communications. The data were cross-referenced, enriched and regularly updated to reflect changes in Contacts’ professional circumstances. The controller argued that the GDPR did not apply because it was established outside the EU and provided services only to businesses. It additionally claimed that the weekly updating of Contact Cards ensured accuracy rather than constituting monitoring or profiling. The controller maintained that the collection and disclosure of the data were necessary for its own economic interest in providing accurate professional contact information and for its Clients’ interests, including fraud prevention. According to the controller, it processed only a limited range of information concerning the Contacts’ professional lives. It further claimed that individuals who made professional information publicly available, particularly through services such as LinkedIn, could reasonably expect that the information might be reused and that they could be contacted regarding professional opportunities. Regarding transparency, the controller stated that its Personal Information Notice was sent to each Contact before their information became available in the database. It explained that it notified Contacts that they had a seven-day period during which they could opt out before their information became available to Clients. The controller also maintained that excluding public officials and public figures from the database was not a requirement under the GDPR. It attributed the presence of certain public officials to technical limitations in its filtering system. It also argued that public figures had a lower expectation of privacy. After the proceedings began, the controller removed profiles connected with Italian public bodies and officials, strengthened its filters and customer-verification measures, discontinued the Community Program in Italy and extended the opt-out period to fourteen days. Holding — Regarding the territorial scope of the GDPR, the DPA acknowledged that Article 3(2)(a) GDPR could apply to the processing of Clients’ data, but not to Contacts, since they were not recipients of the service. However, it held that Article 3(2)(b) GDPR applied because the controller systematically combined, enriched and updated Contacts’ professional information in order to assess their circumstances and determine whether and how they would appear in the database. Referring to Recital 24 and Recital 30, the DPA held that monitoring did not require profiling. It noted that the systematic observation of online traces and changes in a person’s professional situation was sufficient. The fact that the processing also served data accuracy did not alter that conclusion. It emphasised that the fact that the controller also updated the information to ensure its accuracy did not prevent the processing from constituting monitoring. Regarding transparency, the DPA found that the information concerning the collection of the Contacts’ data, the purposes of the processing and the legal basis relied upon was scattered across several documents. Also, the relevant information was not easily accessible from the controller’s homepage, while the Personal Information Notice could not be located directly through the website without prior knowledge of its existence. It further pointed out that the documents were provided in English rather than in the language of the affected data subjects. The DPA held that presenting the information in this manner did not satisfy the requirement that information be concise, transparent, intelligible and easily accessible. It therefore found an infringement of Article 5(1)(a) GDPR and Article 12 GDPR. Moreover, the DPA assessed whether Article 6(1)(f) GDPR provided a valid legal basis for the processing. It examined the controller’s Legitimate Interest Assessment and considered it essentially non-existent, as it contained only generic statements on necessity and proportionality and no genuine balancing assessment. The DPA then applied the three-part test under Article 6(1)(f) GDPR. It held that making the Contacts’ data available to Clients for their own marketing and sales activities could not constitute a legitimate interest, since the disclosure of contact information to third parties for their independent advertising purposes required prior consent under the applicable national and ePrivacy framework . However, it acknowledged that the controller’s interest in fraud prevention could be considered legitimate. The DPA nevertheless found that the processing was not necessary for the purposes pursued. It held that the controller collected information extending beyond ordinary professional contact details, including third-party data contained in CRM databases, email headers and subject lines, information about calendar meetings, and browsing data collected through browser extensions or other software integrations used by Clients. It pointed out that much of this information was not publicly available but was extracted from private interpersonal communications, disclosed by Clients, obtained through integrations with information systems or acquired from third-party providers. The DPA held that the collection and combination of such extensive information was neither strictly necessary nor proportionate for creating professional Contact Cards. Furthermore, it stressed that fraud prevention could also have been achieved through less intrusive means. The DPA therefore concluded that the necessity requirement and the principle of data minimisation were not met. Regarding the balancing test, the DPA emphasised that there was no prior relationship between the controller and the Contacts. Creating a professional profile on LinkedIn or another professional platform did not create a reasonable expectation that unpublished contact details would be collected from multiple sources, continuously updated and disclosed to an unspecified number of paying customers. It further noted that the processing could expose Contacts to communications from unknown third parties for purposes they could not reasonably anticipate. The DPA concluded that the Contacts’ interests, rights and freedoms prevailed over the controller’s economic interests and that the safeguards adopted by the controller could not change this outcome. Therefore, the DPA held that Article 6(1)(f) GDPR did not provide an appropriate legal basis and found that the controller infringed Article 5(1)(a) GDPR, Article 5(1)(c) GDPR, and Article 6 GDPR. Regarding public officials, the DPA held that their status did not reduce their entitlement to data protection and that no public interest justified disclosing their direct contact details for commercial purposes. The DPA further found that the controller had been aware of the risk that public officials could be included in its database but had failed to implement sufficiently effective technical and organisational measures. Its filters recognised general titles such as “President” but failed to exclude more specific titles such as “President of the Italian Republic” and “Vice Prime Minister”. The DPA therefore found an infringement of the principle of data minimisation under Article 5(1)(c) GDPR and the obligation of data protection by design and by default under Article 25 GDPR. The DPA imposed a fine of €2,000,000. Furthermore, it prohibited any further processing of personal data of data subjects located in Italy that had been collected without an adequate legal basis and ordered their deletion.

### NAIH fines online store HUF 15M for transparency and Article 12(1) GDPR violations

*Source: NAIH (Hungary), 2026-05-12 — https://overview.legal/posts/184727 — original: https://gdprhub.eu/index.php?title=NAIH_(Hungary)_-_NAIH-450-7-2026*

Facts — The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The period under review extended from January 2020 to November 2025. During this time, the company had multiple privacy notices in force, as well as other documents that contained relevant information on the processing of personal data. Holding — The DPA found the controller guilty of multiple GDPR violations and issued it a fine of HUF 15,000,000 (€41,500). In addition, it ordered the controller to bring its processing operations in compliance with the GDPR by amending the information system used on its website, in particular the data processing provisions of the general terms and conditions and the data processing notices related to prize contests. First, the DPA held that the controller had violated the principle of transparency laid down in Article 5(1)(a) GDPR: several separate documents contained partially conflicting, irrelevant, and incomplete information regarding the processing of personal data. The information was not organised within a uniform, transparent system. Second, the DPA determined that the controller had failed to provide concise, transparent, and intelligible information regarding the purposes and the legal basis for each processing activity and therefore infringed Article 12(1) GDPR. Finally, the DPA found infringements of Articles 13(1) and 13(2) GDPR – the controller had not provided the data subjects all information necessary when personal data is collected from data subjects. In particular, the controller had failed to adequately distinguish the purposes and the legal bases for each processing operation, recipients of personal data, and retention periods. The controller’s website also contained contradictory information on whether or not personal data was transferred to the United States.

### DSB Austria: Online shop violated GDPR by ignoring request to stop gender-specific

*Source: DSB (Austria), 2025-11-24 — https://overview.legal/posts/158460 — original: https://gdprhub.eu/index.php?title=DSB_(Austria)_-_2025-0.950.759*

Facts — On 18 September 2023, a data subject created a customer account with a public limited company operating an online shop (the controller). It allowed customers to place orders either as guests or through an optional customer account. During the registration process, the data subject's personal data was collected, including a gender-specific title. The only options provided for the title were "Mr." and "Ms.", with no option to select no title. The data subject selected “Ms.” during the registration process. The data subject then informed the controller about this situation and requested that it should refrain from using gender-specific forms of address regarding them. The controller initially assured the data subject that it would inform the relevant department. Later, the controller communicated that implementing the requested adjustment was currently not technically feasible, but that a solution was being worked on. On 14 May 2025, the data subject received a newsletter from the controller in which a gender specific salutation (specifically "Ms.") was used. On 16 May 2025, the data subject lodged a complaint with the Austrian DPA against the controller. The data subject argued that the controller had infringed their rights regarding the principles of data processing under Article 5 GDPR, the rights to rectification under Article 16 GDPR, to erasure under Article 17 GDPR and to data protection by design and by default under Article 25 GDPR. Τhe controller stated in its privacy notice that it was necessary to process customers’ personal data for registration purposes under Article 6(1)(b) GDPR. Moreover, the controller also claimed reliance on Article 6(1)(f) GDPR. During the proceedings before the DPA, the controller restructured its IT system. On 8 September 2025, the controller announced that it had implemented gender-neutral forms of address in its online shop and requested for the complaint to be dismissed. Holding — The DPA first noted that, during the proceedings, the controller had implemented the requested changes by removing gender-specific forms of address from the registration process. Since the data subject did not contest this, the DPA considered the alleged infringements of the rights to rectification and erasure to have been remedied and ended that part of the proceedings. However, it continued to examine whether the past processing had violated Article 5 GDPR and Article 25 GDPR. Regarding the processing of salutation data for the personalisation of business communications, the DPA relied on the CJEU judgment in Case C-394/23 (Mousse). In this case, the CJEU had ruled that the processing of salutation data for the personalization of business communications is neither necessary for the performance of a contract pursuant to Article 6(1)(b) GDPR nor consistent with the principle of data minimization pursuant to Article 5(1)(c) GDPR, because such processing is not required for the stated purposes. The DPA concluded that using gender-specific salutations for contract fulfilment, order processing, internal correspondence, contests, newsletters, user account registration, and delivery of goods was not strictly necessary, even under a broad interpretation. It backed this conclusion by the fact that the controller had already stopped using gender-specific salutations in direct communications, newsletters, contests, contact forms, delivery notifications, invoices, and order confirmations. The DPA therefore held that neither Article 6(1)(b) GDPR nor Article 6(1)(f) GDPR could serve as a legal basis for processing gender-specific salutations during the registration process, since the processing was not necessary. In relation to Article 6(1)(f) GDPR , the DPA accepted that the controller could in principle have a legitimate economic interest in personally addressing customers, but found that the necessity requirement was not met. The DPA found that the processing operation violated the principles of purpose limitation and data minimisation under Article 5(1)(b) GDPR and Article 5(1)(c) GDPR due to the lack of necessity of the gender-specific salutation and the availability of less intrusive alternatives. The DPA also referred to the Austrian Constitutional Court’s (Verfassungsgerichtshof) decision GZ G 77/2018, according to which a restriction to only two gender categories is incompatible with Article 8 ECHR. Regarding data protection by design and by default, the DPA held that Article 25 GDPR imposes obligations on the controller, but does not grant the data subject a subjective right to demand a specific privacy-friendly technical setting. It pointed out that while privacy-unfriendly default settings might lead to a violation of confidentiality or of the data protection principles, the data subject could not require the controller to implement specific privacy-friendly settings.

### Shop Owner: Insufficient legal basis for data processing

*Source: Austrian Data Protection Authority (dsb), 2025-10-27 — https://overview.legal/posts/53524 — original: https://www.enforcementtracker.com/ETid-3073*

Austrian Data Protection Authority (dsb) fined Shop Owner €1,500 on 2025-10-27 for: Insufficient legal basis for data processing.

### Telecommunications Operator: Non-compliance with general data processing principles

*Source: Bulgarian Commission for Personal Data Protection (KZLD), 2023-03-16 — https://overview.legal/posts/48999 — original: https://www.enforcementtracker.com/ETid-2884*

The Bulgarian DPA has imposed a fine of EUR 1,020 on a telecommunications operator. The controller did not implement sufficient identification methodes, resulting in a customer profile being created for an individual who neither knew nor wanted a profile to be made.

## Recent developments

### When the data relates to us.

*Source: European Digital Rights, 2025-12-04 — https://overview.legal/posts/52048*

The ruling concerning the relationship between the European Data Protection Supervisor (EDPS) and the Single Resolution Board (SRB) addresses the core of the fundamental right to data protection within the EU and determines how artificial intelligence, data spaces, and so-called privacy-enhancing technologies (PETs) will be regulated in practice. The judgment of the Court of Justice of the European Union (CJEU) comes at a crucial moment to reiterate what constitutes personal data and emphasizes the importance of the protection that the General Data Protection Regulation (GDPR) aims to guarantee. The post "When data relates to us..."

### Stakeholder event on anonymisation and pseudonymisation: express your interest

*Source: EDPB, 2025-11-17 — https://overview.legal/posts/49125 — original: https://www.edpb.europa.eu/news/news/2025/stakeholder-event-anonymisation-and-pseudonymisation-express-your-interest_en*

Brussels, 17 November - The EDPB organises a remote event to collect stakeholders’ input on anonymisation and pseudonymisation on implications of the judgement of the Court of Justice of the European Union (CJEU) in EDPS v Single Resolution Board (SRB). The event will take place on 12 December 2025 (time to be confirmed). This will be an opportunity to inform and support the EDPB’s ongoing work on these topics as per its work programme 2024-2025 and it reflects the EDPB’s commitment to stakehold

### Coordinated Enforcement Framework: EDPB selects topic for 2026

*Source: EDPB, 2025-10-14 — https://overview.legal/posts/49129 — original: https://www.edpb.europa.eu/news/news/2025/coordinated-enforcement-framework-edpb-selects-topic-2026_en*

Brussels, 14 October - During its October plenary, the European Data Protection Board (EDPB) picked the topic for its fifth coordinated enforcement action, which will concern compliance with the obligations of transparency and information under the General Data Protection Regulation (GDPR). The GDPR ensures that individuals are informed when their data is being processed (under Art. 12, 13 and 14). This right to be informed is a core element of transparency and ensures that individuals have more

### Greek SA fines Clearview AI for EUR 20M

*Source: IAPP, 2022-10-20 — https://overview.legal/posts/6252 — original: https://iapp.org/news/a/greek-dpa-imposes-20m-euro-fine-on-clearview-ai-for-unlawful-processing-of-personal-data#entry-1098*

A rundown of the fine on IAPP: https://iapp.org/news/a/a-rundown-of-the-greek-dpas-clearview-ai-fine-findings

### AEPD publishes GDPR Risk Assessment

*Source: AEPD, 2022-10-11 — https://overview.legal/posts/6259 — original: https://evalua-riesgo.aepd.es/index_en.html#entry-1032*

> GDPR RISK ASSESSMENT is intended to assist controllers and processors to identify the risk factors for the rights and freedoms of data subjects whose data are present in the processing, to make an initial assessment of the intrinsic risk, including the need to perform a DPIA, and to estimate the residual risk if measures and safeguards are used to mitigate the specific risk factors.

## Literature

### Building data management capabilities to address data protection regulations: Learnings from EU-GDPR

*Source: Journal of Information Technology, 2023-01-19 — https://overview.legal/posts/132524 — original: https://doi.org/10.1177/02683962221141456*

The European Union’s General Data Protection Regulation (EU-GDPR) has initiated a paradigm shift in data protection toward greater choice and sovereignty for individuals and more accountability for organizations. Its strict rules have inspired data protection regulations in other parts of the world. However, many organizations are facing difficulty complying with the EU-GDPR: these new types of data protection regulations cannot be addressed by an adaptation of contractual frameworks, but requir

### Collective Damages for GDPR Breaches: A Feasible solution for the GDPR Enforcement Deficit?

*Source: European Data Protection Law Review, 2022-01-01 — https://overview.legal/posts/132504 — original: https://doi.org/10.21552/edpl/2022/4/8*

### GDPR Implementation Series ∙ Malta: An Overview of the GDPR Implementation

*Source: European Data Protection Law Review, 2020-01-01 — https://overview.legal/posts/132480 — original: https://doi.org/10.21552/edpl/2020/4/15*

### GDPR Implementation Series ∙ Portugal: A Brief Overview of the GDPR Implementation

*Source: European Data Protection Law Review, 2019-01-01 — https://overview.legal/posts/132482 — original: https://doi.org/10.21552/edpl/2019/4/12*

### GDPR Implementation Series ∙ Cyprus: A Look into the Law for the Effective Application of the GDPR

*Source: European Data Protection Law Review, 2019-01-01 — https://overview.legal/posts/132507 — original: https://doi.org/10.21552/edpl/2019/3/13*

## Related topics

- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Processing Agreement** — https://overview.legal/topics/verwerkersovereenkomst
  Contract between controller and processor defining processing terms
- **Law Enforcement** — https://overview.legal/topics/law-enforcement
  Processing for law enforcement purposes
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing

---
Generated by overview.legal · https://overview.legal/topics/ip-adres · 2026-08-22
