# Joint Controllers — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/joint-controllers
> Sources are cited per item. Verify against the official texts before relying on them.

Multiple controllers jointly determining purposes and means

## Overview

## Legal Framework

Article 26 GDPR governs joint controllership, applying when two or more entities jointly determine the purposes and means of processing. The rationale is to ensure that data subjects have clear avenues to exercise their rights when multiple parties collaborate. Joint controllers must establish their respective responsibilities via an arrangement, unless the processing is mandated by law. This arrangement must designate which controller responds to data subjects' requests, and the essence of the arrangement must be made available to data subjects. The concept is broad, encompassing situations where parties are involved in different stages of the processing but jointly determine its purposes and means.

## Key Developments

The CJEU ruling in Fashion ID GmbH & Co. KG v. Verbraucherzentrale NRW eV established that a website operator embedding a social plugin can be a joint controller, even if it does not receive the collected data. However, liability is limited to the specific processing operations for which the operator jointly determines purposes and means. The court also clarified that the operator triggering the processing must obtain user consent prior to data collection, as relying on the plugin provider for consent would not ensure efficient protection of data subject rights. In Jehovah's Witnesses, the CJEU emphasized that joint controllers cannot systematically deny access rights without analyzing specific circumstances, reinforcing that joint controllership arrangements cannot impede data subject rights. Enforcement actions highlight the necessity of formalizing these relationships. The DPA of Niedersachsen fined a real estate company for failing to conclude a joint controllership agreement. Similarly, the CNIL's EUR 40 million fine against CRITEO demonstrates the severe financial consequences of mismanaging data subject rights in complex retargeting advertising ecosystems.

## Practical Guidance

- Execute a formal Article 26 arrangement whenever your organization collaborates with another entity to determine processing purposes and means. The Niedersachsen enforcement action confirms that the absence of this agreement constitutes a standalone violation.
- Clearly allocate responsibility for obtaining consent. Under Fashion ID, the party triggering the processing—such as a website operator embedding a third-party tool—must secure consent prior to data collection, rather than deferring to the other controller.
- Limit liability by defining the scope of each party's involvement. The Fashion ID ruling dictates that joint controller liability does not extend to processing operations where a party lacks determining influence.
- Ensure the essence of the joint controllership arrangement is transparent and accessible to data subjects. The arrangement must designate a contact point for data subjects to exercise their rights effectively.
- Avoid blanket denials of data subject requests. As affirmed in Jehovah's Witnesses, requests must be assessed on their individual merits, and joint controllers cannot use internal arrangements to systematically deny access.

## Case law

### Amsterdam District Court: consumers seek access to ING–Google Pay data agreements

*Source: District Court Amsterdam, 2026-07-16 — https://overview.legal/posts/144027 — original: https://gdprhub.eu/index.php?title=Rb._Amsterdam_-_781904*

Facts — ING Bank (the controller) is a bank. One of the services the controller offers is to make contactless payments using an Android phone. This was initially done through its own app, however, the controller later discontinued this and offered the contactless payment through Google Pay. To activate Google Pay, data subjects have to create an account with Google. When making a payment, the controller shares data related to the payment and store to Google. Two Dutch consumer’s organisations (the “Benadeelden in Actie” Foundation, or SBIA and Consumer Union) demanded that the controller discontinue Google Pay, and requested it to share its data. The controller stated that it had reached agreements with Google regarding data processing for contactless payments, but it refused to disclose those agreements. The consumer organisations therefore filed a case with the court, requesting it to order the controller to provide access to the agreements. The organisations also requested access to additional documentation, such as (draft) decisions and research data. They argued that they questioned the lawfulness of the processing of personal data in relation to contactless payments, and needed access in order to verify whether this processing was lawful. The controller, on the other hand, argued that the argument was unsubstantiated because the processing was lawful. The organisations argued that ING and Google acted as joint controllers in accordance with Article 26 GDPR. ING disputed this, and argued that it was only a joint controller with Google for the activation of tokens when making a payment. Holding — The court also clarified that ING Bank and Google were joint controllers, in accordance with Article 26 GDPR. The court dismissed the argument that ING and Google were joint controllers only in a specific instance (activating tokens). The court stated that both companies aimed at enabling data subjects to make contact payments with their phones using Google Pay. The court considered this a jointly defined purpose. Furthermore, the companies do not limit their data exchange to tokens; for example, Google stored the payment data to generate payment summaries. In terms of further processing of the personal data by Google (e.g. for advertising purposes), the court held that the ING may have a certain duty of care. This means that ING may have the obligation to implement safeguards to prevent the processing of data for contactless payments for any other purpose. The court also stated that the data subjects can hold ING liable for a breach of this duty of care. In terms of access, the court assessed whether the organisations had this right under the code of civil procedure rather than the GDPR. The court first stated that the request for access applied to ING Bank and not ING Group (the entity the organisations had initially brought the case against). This is because the parent group ING Group did not have a banking license. The court stated that the organisations have a legitimate interest in reviewing the agreements to assess whether they are sufficient and whether the companies are processing the data lawfully. Finally, the court noted that the organisations may determine the relationship (i.e. whether a joint controllership existed) between the companies based on this access request. The court ordered the controller to provide the organisations with access to the agreements between ING and Google. This includes how data subjects’ data will be processed (business sensitive information could be redacted. However, the controller did not have to grant access to the other requested data (e.g. research data or internal correspondence).

### Judgment of the Court (Fifth Chamber) of 4 May 2023.#UZ v Bundesrepublik Deutschland.#Request for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 5 – Principles relating to processing – Controllership – Article 6 – Lawfulness of processing – Electronic file compiled by an administrative authority relating to an asylum application – Tra

*Source: Court of Justice of the European Union, C-60/22, 2023-05-04 — https://overview.legal/posts/132289 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0060*

In Case C-60/22, the CJEU (Fifth Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden concerning UZ, a third-country national, and the Bundesrepublik Deutschland regarding the processing of personal data in an asylum application file. The Court held that an administrative authority transmitting an electronic asylum file to a competent national court via an electronic mailbox constitutes processing under the GDPR, and that where both the authority and the court determine the purposes and means of processing, they are joint controllers under Article 26, requiring an arrangement allocating responsibility and maintaining records of processing activities under Article 30. The Court further clarified that transmission of personal data without the data subject's consent constitutes unlawful processing, triggering the right to erasure under Article 17(1)(d) and the right to restriction under Article 18(1)(b), and that national courts must disregard such unlawfully processed data. No fine was imposed.

### LG Rostock - 3 O 762/19

*Source: LG Rostock, 2020-09-15 — https://overview.legal/posts/122848 — original: https://gdprhub.eu/index.php?title=LG_Rostock_-_3_O_762/19*

Facts — The German consumer organisation Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband e.V. (vzbv, the claimant) filed a lawsuit against advocado GmbH (advocado, the defendant), a German-based company that runs an online platform where attorneys can offer their services. The defendant's website had used a cookie banner with pre-ticked boxes for the use of marketing and analytics cookies. This included the use of tools such as Google Analytics that entail a data transfer to third countries. The claimant argued that the data processing in connection with the placed cookies was unlawful under Article 6(1) GDPR: A user's consent under Article 6(1)(a) GDPR could not be considered valid under Articles 4(11) and 7 GDPR, especially since the boxes were pre-ticked. Moreover, the claimant claimed that the defendant had violated Articles 5(1)(a), 13/14, 26 and 44 et seqq. GDPR as it had failed to properly inform users of the scope of intended processing activities, joint controllers and international data transfers in connection with the use of cookies. The defendant stated that it had based the use of cookies on legitimate interests under Article 6(1)(f) GDPR until the CJEU issued its decision C-673/17 on 01.10.2019 ("Planet 49"). Afterwards, the defandent argued that they changed the legal basis for processing to consent under Article 6(1)(a) GDPR, which it considered valid under Articles 4(11) and 7 GDPR. The defendant also stated that it was the sole controller for the processing activities - there were no joint controllers involved, only processors. (Furthermore, the claimant had also argued that some provisions in the defendant's general terms and conditions were unlawful from a civil law / consumer protection law perspective. This will not be discussed further in this summary.) Dispute — Was it necessary to ask for the users' consent under Article 6(1)(a) GDPR or could the processing activities in connection with the use of marketing and analytics cookies be based on legitimate interest under Artilce 6(1)(f)? Was the consent given by users' when interacting with the defendant's cookie banner valid under Articles 6(1)(a), 4(11) and 7 GDPR? Did the defendant violate GDPR provisions on transparency? Was the defendant the sole controller regarding the processing activities in connection with the use of marketing and analytics cookies or were there any joint controllers? Holding — Legal basis and validity of consent — The court held that the marketing and analytics cookies used by the defendant c an only be placed with the users' consent under Article 6(1)(a) GDPR : § 15(3) Telemediengesetz that deals with such cookies must be interpreted in light of Article 5(3) e-Privacy Directive, which requires consent for cookies not strictly necessary for technical reasons. Taking into consideration the design of the cookie banner and the lack of information provided to a website user, the court held that consent given could not be considered valid under Articles 6(1)(a), 4(11) and 7 GDPR. The banner featured pre-ticked boxes and a big "OK" button. The option "use only necessary cookies" was designed to not look like an interactive button but rather a link. Consent could therefore not be considered "freely given" and was invalid. Transparency — The court further held that the defendant violated Article 13 GDPR by mentioning an incorrect transfer mechanism under Articles 44 et seqq. GDPR for data transfers in connection with the use of cookies. Sole or joint controllership when using Google Analytics? — Lastly, the court held that the use of Google Analytics results in joint controllership of the website provider using this tool and Google . Google does not qualify as the website provider's processor under Article 4(7). This is because Google does not process the data solely for the purpose of use by the website provider. Rather, Google, like other third-party providers, expressly reserves the right to process the data for its own purposes as well. The fact that the defendant and Google entered into a data processing agreement under Article 28 GDPR does not change this assessment. The court's legal view is in line with the official opinion of the "Datenschutzkonferenz", a gathering of all German DPAs.

### CJEU - C-40/17 - Fashion ID

*Source: GDPRhub, 2019-07-29 — https://overview.legal/posts/125654 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-40/17_-_Fashion_ID*

Facts — Fashion ID, an online retailer clothing company, embedded the ‘Like’ social plug-in from Facebook on its website. When a visitor visited the website, whether they clicked on the plug-in or not, their personal data was transmitted to Facebook Ireland without the user’s knowledge or consent of this whether or not they had user accounts with Facebook. Verbraucherzentrale NRW, a public service association brought legal proceedings against Fashion ID for transmitting personal data to Facebook Ireland without consent and in breach of their obligation to inform users of this activity. The Regional Court upheld the request made by NRW but Fashion ID appealed the decision to the Higher Regional Court arguing that it wasn’t a controller within the definition set out under Article 2(d) Directive 95/46 and that NRW did not have legal standing to bring a class action suit under Directive 95/46. The Higher Regional Court stayed the proceedings and sought clarifications on these questions from the CJEU. Dispute — Whether Fashion ID is a controller within the definition under Article 2(d) and whether NRW has legal standing to bring a class action suit under Directive 95/46. Holding — On the first question, the court held that the Fashion ID was a joint controller with Facebook Ireland. The reasoning behind this: Fashion ID embedded the plug-in to optimize the publicity of its goods and make them more visible to a visitor. As such, it consented to the terms of using the plug-in to benefit from the commercial advantage of increased publicity of its goods, well aware that the plug-in enabled transmission of personal data to Facebook Ireland. Facebook Ireland also had a commercial benefit of processing such personal data. Thus, the fact that Fashion ID did not have access to the personal data collected doesn’t preclude it from being a controller within the definition of Article 2(d). Its liability was limited to the purpose and means of processing on its part which was the transmission of personal data and failure to disclose this to the visitors of its website. On the whether NRW had legal standing to bring a claim on behalf of consumers, the court held that Articles 22 and 24 Directive 95/46 allow consumer protection associations to bring and defend legal proceedings against a person in breach of protection of personal data.

### CJEU - C-210/16 - Wirtschaftsakademie Schleswig-Holstein

*Source: GDPRhub, 2018-06-05 — https://overview.legal/posts/125658 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-210/16_-_Wirtschaftsakademie_Schleswig-Holstein*

Facts — The company offered educational services through a fan page hosted by Facebook. As administrators, they obtained statistical information on visitors to the fan page via Facebook Insights offered by Facebook free of charge under non-negotiable conditions of use. The information was obtained using cookies, each containing a unique user code, stored by Facebook in the devices of visitors and were active for two years. The unique code could be matched with users registered on Facebook and their personal data was collected when the fan page was opened. Neither the company nor Facebook notified users/visitors of the fan page of the storing of cookies or processing of their personal data. Dispute — The Independent Data Protection Centre Germany, (ULD) made a decision on 3rd November 2011 against the company ordering them to deactivate the fan page within the prescribed period or pay a penalty fine on grounds that: 1. Neither Facebook nor the company notified the users that Facebook collected Personal data of the users; 2. Facebook processed personal data of the users. The company brought a dispute against that decision arguing that it was not responsible for the processing of personal data under the data protection law. This dispute went back and forth from the Administrative Court to the Federal Court who referred the matter to the CJEU seeking clarifications on whether an administrator of a fan page hosted by a social network is a controller within the definition under Article 2 (d)of Directive 95/46. Holding — The CJEU held that the mere fact of using a social network doesn’t make the user a controller responsible for processing personal data. However, an administrator who creates a fan page, consents to the use policy, cookies policy, defines the objectives and promotes its activities has an influence on the processing of personal data for the purpose of producing a statistical report, by Facebook, on the fan page, whether anonymized or not. Thus, the administrator is a joint controller with Facebook under Article 2(d) Directive 95/46. It also held that, as a joint controller with Facebook, the administrator’s responsibility is not equal to that of Facebook because they may be involved at different stages of that processing of personal data and to different degrees.

### Rb. Den Haag - C/09/689833

*Source: District Court Den Haag, 2026-05-27 — https://overview.legal/posts/53095 — original: https://gdprhub.eu/index.php?title=Rb._Den_Haag_-_C/09/689833*

Facts — Kindred Group PLC and Risepoint Limited (the controllers) are companies that provide online gambling products. Several companies within Kindred Group PLC (Risepoint was initially in this group) offered online gambling products before a national law requiring a license entered into force. In response, several lawsuits were filed before courts regarding the validity of the gambling agreements between players and unlicensed online gambling providers. Several data subjects later requested access (Article 15 GDPR, or in the alternative, the right to portability under Article 20 GDPR) to the controller to receive information on specific transaction data and the types of games they participated in. The data subjects did not receive access and brought a claim to the court. The data subjects requested the court to hold both companies liable (jointly or separately) The court initially dismissed the claim based on the code of civil procedure, but allowed the data subjects to amend their arguments regarding the GDPR. Both companies argued that they were not controllers, and that the requests made by the data subjects were abusive. According to the companies, the data subjects requested access for the sole purpose of bringing legal actions against them. Finally, the companies argued that they did not have the obligation to comply with the requests under Article 15(4) GDPR. Holding — The court first clarified that both Kindred Group PLC and Risepoint Limited were controllers. Kindred Group PLC argued that it did not exercise any decisive influence over the purpose and means of processing. The court took into consideration the functional definition of “controller” under Article 4(7) GDPR and CJEU case law, rather than a formal definition. The court found that Kindred Group PLC was a controller for access made between May and October 2024, but not for requests made after October 2024. This is because Kindred had a unified privacy policy for companies under its group, and answered the access request from an email address containing its name. However, after October 2024, Risepoint was no longer a part of the group, and the data from Kindred had been transferred to Risepoint. The court then dismissed the controllers’ arguments, and stated that the access requests were not abusive under Article 12(5) GDPR. Under Article 12(5) GDPR, a controller may refuse a request for access if it is manifestly unfounded or excessive. However, the CJEU has clarified that a data subject does not need to justify an access request, and a controller cannot refuse a request for access on the sole ground that it serves a purpose other than obtaining information about the processing of personal data and verifying its lawfulness. In any case, the court stated that the controller bears the burden in proving that a request is manifestly unfounded or excessive. Similarly, the controllers could not rely on Article 15(4) GDPR to refuse the data subjects’ requests. The court stated that the controllers’ interest in not granting information that data subjects could use against them in court is not recognised under EU law as a basis to refuse access. While the GDPR allows for national law to restrict specific rights under Article 23 GDPR, the court stated that the restriction must be necessary and proportionate. This, however, does not apply for hypothetical situations. The court upheld the data subjects’ claim, and ordered the controllers to provide them with a copy of their transaction data. The court specified that the controllers had the obligation to provide a complete copy, in accordance with CJEU case law.

### HvJ EU 9 januari 2025, C‑394/23 (Mousse).

*Source: CJEU, 2025-01-09 — https://overview.legal/posts/50377 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0394*

HvJ EU 9 januari 2025, C‑394/23 (Mousse). Artikelen: 5(1)(c), 6(1), en 21 AVG Onderwerp : Beginsel van minimale gegevensverwerking Gek genoeg verwijst het HvJ EU zelf niet naar HvJ EU 1 augustus 2022, C‑184/20 (Vyriausioji tarnybinės etikos komisija), maar dat had hier ook heel logisch geweest.

### Judgment of the Court (Fourth Chamber) of 7 March 2024.#IAB Europe v Gegevensbeschermingsautoriteit.#Request for a preliminary ruling from the Hof van beroep te Brussel.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Standard-setting sectoral organisation proposing to its members rules on the processing of users’ consent – Article 4(1) – Concept of ‘personal data’ – String of letters and characters ca

*Source: Court of Justice of the European Union, C-604/22, 2024-03-07 — https://overview.legal/posts/132270 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0604*

In Case C-604/22, the Court of Justice of the European Union ruled on a preliminary reference from the Brussels Court of Appeal in proceedings between IAB Europe and the Belgian Data Protection Authority (Gegevensbeschervingsautoriteit) concerning whether IAB Europe's "Transparency and Consent String" (TC String)—a coded string capturing users' consent preferences—constitutes personal data under GDPR Article 4(1) and whether IAB Europe qualifies as a (joint) controller under Article 4(7). The Court held that the TC String constitutes personal data because it can be linked to an identifiable natural person through reasonably likely means, and that IAB Europe, as a standard-setting sectoral organization determining purposes and means of processing through its framework, acts as a controller even without direct access to the data, with its responsibility extending to subsequent processing by third parties that it does not mandate but facilitates through its rules. No fine was imposed in this preliminary ruling, as the underlying Belgian DPA decision and any sanctions remain before the national court.

### Judgment of the Court (Third Chamber) of 11 January 2024.#État belge v Autorité de protection des données.#Request for a preliminary ruling from the cour d'appel de Bruxelles.#Reference for a preliminary ruling – Approximation of laws – Protection of natural persons with regard to the processing of personal data and free movement of such data (General Data Protection Regulation) – Regulation (EU) 2016/679 – Point 7 of Article 4 – Concept of ‘controller’ – Official journal of a Member State – Obl

*Source: Court of Justice of the European Union, C-231/22, 2024-01-11 — https://overview.legal/posts/132274 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0231*

In Case C-231/22, the Court of Justice of the European Union interpreted Article 4(7) and Article 5(2) of the GDPR in response to a preliminary reference from the Brussels Court of Appeal in proceedings between the Belgian State and the Belgian Data Protection Authority concerning whether the managing authority of the Moniteur belge (Belgium's official journal) constitutes a "controller" under the GDPR. The central issue was whether a Member State authority that is legally obligated to publish company documents containing personal data, as prepared and submitted by third parties, determines the purposes and means of processing within the meaning of Article 4(7). The Court held that such an authority does qualify as a controller because, by disseminating the personal data to the public, it determines the means of making the data accessible and exercises autonomous control over that processing operation, even though it does not determine the content of the published documents; no fine was at issue in this preliminary ruling.

### Meta Platforms v noyb

*Source: CJEU, C-252/21, 2023-01-12 — https://overview.legal/posts/51484 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0252*

GDPR consent requirements and lead supervisory authority mechanism.

### HvJ EU: Privacy Shield ongeldig verklaard (Schrems II)

*Source: Hof van Justitie EU, 2020-07-16 — https://overview.legal/posts/1 — original: https://eur-lex.europa.eu/legal-content/NL/TXT/?uri=CELEX:62018CJ0311*

Het Hof van Justitie verklaart het Privacy Shield-akkoord ongeldig wegens onvoldoende waarborgen voor Europese burgers tegen toegang door Amerikaanse inlichtingendiensten.

### Data Protection Commissioner v Facebook Ireland and Maximillian Schrems

*Source: CJEU, C-311/18, 2020-07-16 — https://overview.legal/posts/51470 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0311&ref=51470*

Invalidated Privacy Shield adequacy decision and upheld validity of Standard Contractual Clauses with additional safeguards required.

## Guidance

### Guidelines 05/2021 on the Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR

*Source: EDPB, guidelines-052021-on-the-interplay-between-the-application-of-article-3-and-the-en, 2023-02-24 — https://overview.legal/posts/125866 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-052021-on-the-interplay-between-the-application-of-article-3-and-the_en*

Adopted 1 Guidelines 05/2021 on the Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR Version 2.0 Adopted on 14 February 2023 Adopted 2 Version history Version 2.0 14 02 2023 Adoption of the Guidelines after public consultation Version 1.0 18 11 2021 Adoption of the Guidelines for public consultation Adopted 3 EXECUTIVE SUMMARY The GDPR does not provide for a legal definition of the notion “transfer of personal data to a…

### Guidelines 07/2020 on the concepts of controller and processor in the GDPR

*Source: EDPB, edpb-guidelines-on-the-concepts-of-controller-and-processor-in-the-gdpr, 2021-07-07 — https://overview.legal/posts/38069 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-072020-on-the-concepts-of-controller-and-processor-in-the-gdpr_en*

The concepts of controller, joint controller and processor play a crucial role in the application of the General Data Protection Regulation 2016/679 (GDPR), since they determine who shall be responsible for compliance with different data protection rules, and how data subjects can exercise their rights in practice. The precise meaning of these concepts and the criteria for their correct interpretation must be sufficiently clear and consistent throughout the European Economic Area (EEA). The conc...

### Opinion 1/2018 on the draft list of the competent supervisory authority of Austria regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-12018-on-the-draft-list-of-the-competent-supervisory-en, 2018-10-03 — https://overview.legal/posts/126293 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-12018-on-the-draft-list-of-the-competent-supervisory_en*

Opinion 1/2018 on the draft list of the competent supervisory authority of Austria regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 25th September 2018 2 Contents 1. Summary of the Facts ................................ ................................ ................................ ........ 4 2. Assessment ................................ ................................ ................................…

### Opinion 14/2026 on the Europrivacy certification criteria regarding their approval by the Board as European Data Protection Seal pursuant to Article 42.5 GDPR

*Source: EDPB, opinion-142026-on-the-europrivacy-certification-criteria-en, 2026-04-16 — https://overview.legal/posts/125682 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-142026-on-the-europrivacy-certification-criteria_en*

Opinion 14 / 2026 on the Europrivacy certification criteria regarding their approval by the Board as European Data Protection Seal pursuant to Article 42.5 GDPR Adopted on 15 April 2026 1 | Adopted 2 | Adopted The European Data Protection Board Having regard to Article 63, Article 64 (2) and Article 42 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free…

### Opinion 15/2026 on the Europrivacy certification criteria regarding their approval by the Board as European Data Protection Seal to be used as tool for transfers pursuant to Articles 42 and 46 GDPR

*Source: EDPB, opinion-152026-on-the-europrivacy-certification-criteria-en, 2026-04-16 — https://overview.legal/posts/125681 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-152026-on-the-europrivacy-certification-criteria_en*

Opinion 15 / 2026 on the Europrivacy certification criteria regarding their approval by the Board as European Data Protection Seal to be used as tool for transfers pursuant to Articles 42 and 46 GDPR Adopted on 15 April 2026 1 | Adopted 2 | Adopted The European Data Protection Board Having regard to Article 63, Article 64(2), Article 42 and Article 46 of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to…

### Report on stakeholder event on processing of personal data to target or deliver political advertisements

*Source: EDPB, report-on-stakeholder-event-on-processing-of-personal-data-en, 2026-03-27 — https://overview.legal/posts/125684 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/report-on-stakeholder-event-on-processing-of-personal-data_en*

Report on stakeholder event on processing of personal data to target or deliver political advertisements 27 March 2026 1. Background The EDPB organised an online stakeholder event on 27 March 2026 to collect stakeholders’ input on processing of personal data to target or deliver political advertisements. The objective was to engage with stakeholders at an early stage of drafting the EDPB Guidelines on the processing of personal data to target or deliver political advertisements (Chapter III of…

### Report on stakeholder event on anonymisation and pseudonymisation of 12 December 2025

*Source: EDPB, report-on-stakeholder-event-on-anonymisation-and-en, 2026-02-18 — https://overview.legal/posts/125688 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/report-on-stakeholder-event-on-anonymisation-and_en*

Report on stakeholder event on anonymisation and pseudonymisation of 12 December 2025 1. Background The EDPB organise d a remote stakeholder event on 12 December 2025 to collect stakeholders’ input on anonymisation and pseudonymisation , following the Court of Justice of the European Union ( “ CJEU ” ) judgment in case EDPS v SRB 1 . The objective was to engage with stakeholders to inform the EDPB’s ongoing work on its guidelines 01/2025 on pseudonymisation and f orthcoming guidelines on…

### Opinion 27/2025 regarding the European Commission Draft Implementing Decision pursuant to Directive (EU) 2016/680 on the adequate protection of personal data by the United Kingdom

*Source: EDPB, edpb-opinion-202527-united-kingdom-adequacy-led-en, 2025-10-16 — https://overview.legal/posts/51407 — original: https://www.edpb.europa.eu/documents/adequacy/opinion-272025-regarding-the-european-commission-draft-implementing-decision_en*

Adopted 1 Opinion 27/2025 regarding the European Commission Draft Implementing Decision pursuant to Directive (EU) 2016/680 on the adequate protection of personal data by the United Kingdom Adopted 16 October 2025 Adopted 2 Executive summary The European Commission endorsed its draft implementing decision on the adequate protection of personal data by the United Kingdom pursuant to the Law Enforcement Directive on 22 July 2025. On the same date, as part of the procedure towards the formal…

## Enforcement decisions

### AKI (Estonia) - No. 2.1-1/24/397-890-38

*Source: AKI (Estonia), 2026-04-16 — https://overview.legal/posts/53882 — original: https://gdprhub.eu/index.php?title=AKI_(Estonia)_-_No._2.1-1/24/397-890-38*

Facts — OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic. On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had failed to provide all personal data requested. The controller only partially complied after several requests from the DPA. Although the DPA closed the part of the case concerning the access request, it continued investigating the controller’s processing of patients’ personal data when providing Invisalign treatment. The service required the controller to collect and transfer patients’ health data to Align Technology, Inc. However, the contractual documents did not clearly establish whether Align Technology acted as a processor, an independent controller or a joint controller. The controller stated that Align Technology largely determined the conditions of the service, including the consent form and the processing arrangements, and that individual clinics could not unilaterally amend these conditions. The DPA also found that the information provided to patients was incomplete and fragmented. The consent form and privacy information did not clearly explain the legal basis and purposes of processing, the parties involved, data recipients, retention periods, transfers outside the European Union or the safeguards applied to such transfers. Parts of the information were only available in English on external websites. Holding — The DPA held that the controller had failed to demonstrate that the processing carried out in connection with the Invisalign service was lawful and transparent under Articles 5(1)(a) and 5(2) GDPR. First, the DPA found that the parties’ roles had not been properly determined. Under Article 4(7) GDPR, the assessment had to be based on which party actually determined the purposes and means of processing, rather than solely on the contractual description of the relationship. The controller decided whether Invisalign treatment was suitable for a patient and collected the relevant health data. It therefore acted as a controller in relation to the treatment. However, Align Technology exercised significant control over the subsequent processing, including the data collected, the recipients, retention arrangements, the use of other service providers and transfers outside the European Union. The DPA therefore considered that Align Technology could not simply be regarded as a processor acting only on documented instructions under Article 28(3)(a) GDPR. On the available evidence, it was at least a joint controller under Article 26 GDPR. The DPA ordered the controller to review the contractual relationship. If Align Technology acted as a processor, the agreement had to comply with Article 28 GDPR, including the requirements concerning subprocessors under Article 28(2). If the parties were joint controllers, they had to allocate their respective responsibilities under Article 26 GDPR. Second, the DPA found that the consent obtained from patients was invalid. The consent form did not provide sufficient information for patients to understand the processing and therefore did not meet Articles 4(11), 6(1)(a), 7 and 9(2)(a) GDPR. The DPA also noted that healthcare processing may, depending on the operation concerned, rely on Article 6(1)(b) GDPR together with Article 9(2)(h) GDPR. However, the controller had not clearly identified the applicable legal bases for the different processing activities. The privacy information also failed to comply with Articles 12, 13 and 14 GDPR. Patients were required to consult several documents and external websites, some of which contained incomplete or inconsistent information. The controller had therefore not ensured that the information was easily accessible, understandable and available in Estonian. The DPA further referred to Article 25 GDPR when emphasising that the controller had to ensure that the processing arrangements and safeguards complied with the GDPR. Under Article 58(2)(d) GDPR and § 56(1) of the Estonian Personal Data Protection Act, the DPA ordered the controller to clarify the parties’ roles, conclude an Article 26 arrangement or Article 28 agreement, amend the consent form and privacy policy, and publish the required information in Estonian. No administrative fine was imposed. However, failure to comply could result in a penalty payment of €1,000 for each unfulfilled point or subpoint of the order, imposed repeatedly until compliance.

### Datatilsynet (Denmark) - 2020-431-0061 (Helsingor decision no. 4)

*Source: Datatilsynet (Denmark), 2022-09-28 — https://overview.legal/posts/6313 — original: https://gdprhub.eu/index.php?title=Datatilsynet_(Denmark)_-_2020-431-0061_(Helsingor_decision_no._4)*

Facts — This is the Danish DPA's fourth decision in the case relating to Helsingor municipality's processing of personal data in primary and lower secondary school. Helsingor municipality, the controller, has been using Google Chromebooks and Workspace for Education in violation of several GDPR requirements, as detailed in the first decision of September 2021, the second decision of 14 July 2022 and the third decision of 18 August 2022. Following the third decision, the municipality submitted more documentation and also requested a consultation with the DPA as per Article 36 GDPR. Holding — The DPA temporarily suspended its processing ban against Helsingor municipality until 5 November 2022, and also ordered the municipality to: Change the data processing agreement with Google so that the DPA's remarks in their 14 July and 18 August decisions, are implemented. This includes, at a minimum, a clarification of where and if Google acts as a sole controller and any uncertainties that may entail that Google acts beyond their role as a processor, see Article 28(3)(a) GDPR. Document that all transfers of personal data to insecure third countries, are in line with the GDPR. Describe all data flows and identify the personal data that are shared with the vendor, and clarify when the vendor acts as a sole or joint controller. This documentation must include the whole technology stack used by the municipality (for this processing activity). Update their data protection impact assessment based on all identified risks. Consult the DPA if the DPIA shows any high risks the municipality is not able to mitigate. If any processing activities are still not in line with the GDPR before the DPA's deadline 3 November 2022, present a final plan for bringing them in line with the GDPR.

### DPC (Ireland) - 05/SIU/2018

*Source: DPC (Ireland), 2023-01-16 — https://overview.legal/posts/125613 — original: https://gdprhub.eu/index.php?title=DPC_(Ireland)_-_05/SIU/2018*

Facts — This case involves an own-volition investigation conducted by the Irish DPA (DPC) into Kildare County Council, the controller. In June 2018, Officers from the Special Investigations Unit of the DPC were authorised to conduct a range of inquiries pertaining to surveillance technologies deployed by state authorities, including An Garda Síochána (the national police) and various local authorities, including Kildare County Council. These inquiries sought to determine whether the data processing was lawful, and also to ensure that full accountability measures for the collection and processing of personal data were in place, in advance of further investment in and deployment of newer surveillance technology. The investigation into Kildare County Council focused on the following: the legal basis for surveillance technology employed for the purposes of preventing, investigating, detecting or prosecuting crime; the legal basis for surveillance tech deployed for purposes other than preventing, investigating, detecting, or prosecuting crime; appropriate signage and general transparency; and the question of a joint controller agreement between the council and the national police. Furthermore, the authority sought to examine the security measures for traffic management CCTV; housing department CCTV; and the transmission of CCTV footage to An Garda Síochána. Holding — Issuing its final decision, the DPC began by establishing that not all of the processing of personal data in question is regulated by the GDPR. Any processing of personal data for the purposes of prevention, investigation, detection, or prosecution of criminal offences is regulated by the Law Enforcement Directive (LED) supplemented into Irish law by the Irish Data Protection Act 2018 (“the 2018 Act”). The other personal data processing at issue here is covered by the GDPR. For further information and relevant legal provisions, please see Article 2(2)(d) GDPR, Articles 1 and 2 LED, and Part 5 and 6 of the 2018 Act. The first issue addressed in the DPC’s decision was the legal basis for the surveillance technologies employed for the purposes of preventing, investigating, detecting or prosecuting crime. In particular, this concerned CCTV systems deployed in a number of housing estates and Traveller caravan parks in the area. While the County Council initially submitted that the lawful basis for this processing was Article 6(1)(c) and 6(1)(d) GDPR, after clarifying that the relevant regime is the LED, the DPC sought to examine the justification for processing in light of this Directive and the 2018 Act. The controller sought to rely on its ‘estate management functions’ as set out in domestic housing legislation, and the powers to combat anti-social behaviour afforded therein. In accordance with the 2018 Act, personal data must be processed lawfully and fairly (Section 71(1)(a)) and the processing will only be lawful where the subject has given their consent, or where the processing is necessary for the performance of a function of the controller for a purpose specified in Section 70(1)(a) and the function has a legal basis in the law of the EU or Ireland (Section 71(2)). Furthermore, for special category data, one of the additional nine conditions in Article 73(1)(b) must be met. After examining the case, the DPC found no requirement to support the development of CCTV cameras in the estates as described above. The cited Irish legislation places no requirement upon the local authority to monitor in this way, and makes no reference to CCTV cameras. Furthermore, given that Irish Travellers are an ethnic group, and their accommodation has a distinct design and layout, the activities also represented the illegal processing of special category data. The DPC found an infringement of Sections 71(1)(a) and 73 of the 2018 Act. With regards to CCTV cameras located on the grounds of 2 supermarkets for the purpose of detecting illegal dumping. The investigation found that these cameras had not been operational before, during or after the investigation, and accordingly the DPC found no violation of the 2018 Act. Thereafter the DPC decision addressed the second issue: the legal basis for the surveillance technologies employed for purposes other than for preventing, investigating, detecting or prosecuting crime. In particular, the authority investigated CCTV used for: traffic management; the sharing of live feed traffic with An Garda Síochána; and the use of ANPR cameras, which recognise and digitise number plates. With regard to processing for traffic management, the Council sought to rely on the Irish Roads Act 1993, which places obligations upon public authorities to, among other things, provide for the safety or convenience of road users. Accordingly, the council argued they had a lawful basis for processing was in the public interest (Article 6(1)(e) GDPR). The DPC held that, given the significant potential impact to fundamental rights of a widespread video surveillance system, the Roads Act is not sufficiently clear, precise or foreseeable to constitute a valid legal basis for the processing of personal data in accordance with Article 6(1)(e) GDPR. There was also a complete lack of legal basis for the sharing of a live traffic feed with An Garda Síochána. Furthermore, for the use of ANPR cameras to be lawful under Article 6(1)(e) GDPR, it would be necessary for the legislature to specifically grant power to the local authority to carry out such processing in a manner which is clear, precise and foreseeable for the data subjects. As the Roads Act does not explicitly permit such processing, the Council does not have a lawful basis to operate ANPR cameras. In light of the above, the DPC found that the Council had violated Article 5(1)(a) GDPR in all 3 respects. The third question investigated was the presence of appropriate signage and general transparency. The investigation found that no appropriate signage had been installed to inform data subjects of the use of CCTV for traffic management purposes. Accordingly, the DPC held there had been a violation of Article 13 GDPR. Regarding the fourth issue, the DPC investigated the question of whether the Kildare County Council could be considered “joint controllers” with respect to Article 26 GDPR. The Decision finds that while An Garda Síochána used the CCTV footage for the prevention of crime, there is no evidence that the two entities “jointly” determined the purposes of processing. In other words, there is no connection between the Council’s decision to use the cameras for traffic management purposes and An Garda Síochána’s decision to then use the live feed for monitoring and preventing crime. Accordingly, the Council has not violated Article 26 GDPR. The DPC also made a number of findings regarding the security measures implemented by the Council. The Council failed to maintain a data log that recorded which users had accessed the CCTV cameras, thereby infringing Article 32(1) GDPR. The Council also violated Sections 71(1)(f), 72(1) and 78 of the 2018 Act by failing to implement appropriate technical or organisational security measures when installing the CCTV cameras. Furthermore, by failing to keep a data log, the Council also violated Section 82(2) of the 2018 Act. The Council also infringed Section 71(1)(c) and Section 76(2) of the 2018 Act by recording CCTV of private properties, in the absence of any privacy masking technology. Additionally, the Council infringed Section 71(10) of the 2018 Act by failing to be in a position to demonstrate that its processing of personal data via CCTV cameras at one location was not excessive to its purpose of preventing anti-social behaviour. Finally, The Council infringed its obligations under Sections 71(1)(f), 72(1) and 78 of the 2018 Act in connection with arrangements surrounding the transfer of personal data to An Garda Síochána using unencrypted USB sticks. Exercising its corrective powers, the DPC imposed a temporary ban on the processing of personal data with CCTV for the purposes of criminal law enforcement and traffic management, until a legal basis can be identified. Furthermore, they imposed an order for Kildare County Council to bring its processing into compliance with the legislation, and imposed an administrative fine of €50,000.

### EDPS - 2020-1013

*Source: EDPS, 2022-01-05 — https://overview.legal/posts/122849 — original: https://gdprhub.eu/index.php?title=EDPS_-_2020-1013*

Facts — In January 2021, noyb filed a complaint against the European Parliament on behalf of six Members of the European Parliament over an internal coronavirus testing website. The issues raised were: confusing and unclear cookie banners, vague and unclear data protection notices, and the illegal transfer of data to the US. Holding — On data controllership — According to the EDPS, the processor may enjoy a considerable degree of autonomy in providing its services and may identify the ‘non-essential’ elements of the processing operation. Furthermore, the processor may advise or propose certain measures in this respect, but it is up to the controller to decide whether to accept such advice or proposals. The analysis of the EDPS shows that the European Parliament (EP) delegated some aspects on the setting up and functioning of the website to Ecolog. The EDPS considers the EP acts as the sole data controller for the processing in question (i.e. the operation of the Parliament’s dedicated website) whereas Ecolog acts as a processor. After having assessed the instructions given by the EP to the processor, the EDPS concluded that the EP did not show the necessary diligence required from a data controller and, ultimately, failed to comply with the Regulation on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data 2018/1725 (hereafter Regulation 2018/1725), in particular with Articles 26(1) and 29(1). Moreover, the EDPS considered that the EP failed to provide the necessary detailed instructions to Ecolog for the setting up of the website, including the drafting of the data protection notice. The absence of documented instructions is therefore in violation of Article 29(3) Regulation 2018/1725. Transparency and information requirements — The EDPS confirmed that the data protection notice published at the time of the complaint did not reflect the processing done by the EP, since it merely consisted of a copy of the testing center of Zaventem's airport. Moreover, the reference made in the document to Article 6(1)(f) GDPR was wrong since it stems from the same error. The EDPS confirmed that the EP did not meet its transparency requirements. The EDPS also analysed the updated version of the data protection notice during the procedure and raised several remaining -and even new- inconsistencies and issues. Among other things, the following problems persisted after the data protection notice was updated: a mere reference to Article 15 and 16 Regulation 2018/1725 is misleading as it should apply in its entirety; the reference to the processing of health data is not correct since no such data are processed in the case at hand; the retention period mentioned is not precise enough; the sections of the data protection notices relating to the recipients of the personal data fail to make any reference to the processor; inconsistencies between the different linguistic versions of the data protection notices were still observed: The English and German versions refer to Ecolog and the Laboratory van Poucke as processors under Article 29 Regulation 2018/1725, whereas the French version refers to them as controllers (‘responsables du traitement’). Moreover, the DPO’s contact details on the website refer to Ecolog in all three linguistic versions of the website, when they should be referring to the Parliament Cookies and transfers of personal data to the US — The EDPS confirmed that tracking cookies, such as the Stripe and the Google analytics cookies, are considered personal data, even if the traditional identity parameters of the tracked users are unknown or have been deleted by the tracker after collection. In the same vein, the EDPS rejected the EP's argument and confirmed that upon installation on a device, a cookie cannot be considered ‘inactive’. Every time a user visited Ecolog’s website, personal data was transferred to Stripe through the Stripe cookie, which contained an identifier. The EDPS reached the conclusion that a transfer of data was taking place to the US, via the use of Google and Stripe cookies, since Google Analytics is hosted in the US and the data protection notice referred to a Standard Contractual Clause (SCC) for the transfer of data outside of the EU. However, the Parliament provided no documentation, evidence or other information regarding the contractual, technical or organisational measures in place to ensure an essentially equivalent level of protection to the personal data transferred to the US in the context of the use of cookies on the website. Cookie banner on the Parliament’s dedicated website — The EDPS reminded that: before setting cookies or any other technology falling within the scope of Article 5(3) ePrivacy Directive 2002/58/EC (hereafter ePrivacy Directive), the EU institution must provide the user with adequate information on what is accessed or stored on the user’s terminal equipment, on the purposes of this action and the means for expressing their consent; no action may be performed before the consent is collected. In addition, users must be enabled to withdraw their consent at any time; ‘cookie walls’ are not in line with Regulation 2018/1725, meaning that for consent to be freely given, access to the website’s service and functionalities should not depend on the users’ consent for cookies that are not strictly necessary in the sense described above; in case personal data collected through the cookies are shared with third parties such as analytics partners, the cookie banner should draw the user's attention to it. The EDPS reached the conclusion that the cookie banners in all three languages were not in line with the definition of consent under Article 3(15) Regulation 2018/1725, nor did they meet the requirements of Article 37 Regulation 2018/1725 and Article 5(3) ePrivacy Directive. The cookie banner further failed to provide transparent information regarding the processing of personal data in relation to the cookies on the website. Request for access to personal data — The Parliament was aware that the complainants’ personal data had been processed through the cookies, which were present on the website for the period between 30 September to 4 November 2020, since transfers of personal data had taken place. Consequently, and especially following the EDPS’ inquiry on the matter, the Parliament should have replied to the complainants’ access to personal data request. The Parliament should have provided the relevant information even if it was aware that the processing of the personal data in question was unlawful, as the main purpose of the right of access under Article 15 GDPR is precisely to enable data subjects to become aware of the processing and verify the lawfulness thereof, or exercise other data subject rights. Conclusion — The EDPS concludes that the Parliament has infringed the following articles of Regulation 2018/1725: Articles 26(1) and 29(1) due to its failure to fulfil its responsibilities as controller and use a processor providing sufficient guarantees to implement appropriate technical and organisational measures; Article 29(3) due to its failure to provide documentation relating to the detailed instructions given to the processor for the setting up and functioning of the website; Articles 4(1)(a) and 14, 4(2), and 15 due to its failure to respect the principle of transparency, accountability and the data subjects’ right to information because of the inaccurate data protection notice and cookie banner on the dedicated website; Article 46 and Article 48(2)(b) of the Regulation, due to its reliance on the Standard Contractual Clauses in the absence of a demonstration that data subjects’ personal data transferred to the US were provided an essential equivalent level of protection; Article 37 read in the light of Article 5(3) of the ePrivacy Directive, due to its failure to protect information (the cookies) transmitted to, stored in, related to, processed by and collected from the users’ terminal equipment; Articles 17 and 14(4) due to its failure to reply to the data subjects’ request for access to their personal data. On the basis of the above, the EDPS decides: to issue a reprimand to the Parliament in accordance with Article 58(2)(b) Regulation 2018/1725 for the above infringements; to order the Parliament, pursuant to Article 58(2)(b) Regulation 2018/1725:, to update its data protection notices in the dedicated website in order to provide all relevant information relating to the processing of personal data. The Parliament should address this order within one month from the date of the decision.

### Company: €16,600  fine

*Source: Data Protection Authority of Niedersachsen, 2023-01-01 — https://overview.legal/posts/48548 — original: https://www.enforcementtracker.com/ETid-2433*

The DPA of Niedersachsen has imposed a fine of EUR 16,600 on a company in the real estate industry for failing to conclude a joint controllership agreement. In addition, the controller had collected personal data without a legal basis and had not complied with a deletion request in good time.

### EDPS - 2019-0878

*Source: EDPS, 2021-05-03 — https://overview.legal/posts/122870 — original: https://gdprhub.eu/index.php?title=EDPS_-_2019-0878*

Facts — A data subject complained around cookies and similar technologies used in connection to audiovisual material on the website of the Court of Justice of the European Union (CJEU), as well as websites displaying the Court's branding that the Court linked to (two firms, Companywebcast and Connectedviews, to host a conference recording), claiming that they did not correctly inform the user or obtain required consent before data processing or storage of information on a terminal device. Dispute — The complaint was decided under the data protection regime applying to EU institutions, rather than the GDPR (Regulation (EU) 2018/1725). The dispute concerned: - did the laying of cookies by the CJEU violate Article 37 of the Regulation, implementing the requirements of the e-Privacy Directive? - did the laying of cookies and the lack of transparent information on a third party website, with CJEU branding, linked to by the CJEU to provide it with services, breach the transparency (art 14) and consent (art 7) requirements of Regulation (EU) 2018/1725? - were the conditions for consent met by the CJEU? Holding — The EDPS held that there had been violations by the CJEU, on its own webpages of several provisions of Regulation (EU) 2018/1725. - Article 37 (accessing and storage of information on a terminal device), on the basis that the CJEU did not inform the user about the potential for YouTube cookies to be set if they accepted, nor did they provide a mechanism to refuse all cookies on the website. - Article 7 (conditions for consent), "as the CJEU did not provide its website users with a way to withdraw their consent regarding the use of cookies as easily as giving it - such as a ‘reject’ button displayed in the same place and in the same manner as the ‘accept’ button. Instead, in order to reject cookies, users had to click on the button ‘more information’ and go almost to the bottom of the page to withdraw their consent." It held that there were partial violations of - Article 14 (transparency), in relation to the CJEU's website's own YouTube cookies. In relation to the third party websites, Fashion ID applied, as the CJEU had no obligation to inform users of cookies laid by a website linked to by that website, regardless of whether it was a service the CJEU were using to deliver material or the branding on the site. The CJEU rectified all breaches following the complaint, in co-operation with the EDPS. As a result, the EDPS did not use any of its corrective powers. The EDPS also used the complaint to deploy its Website Evidence Collector (WEC). In relation to linked pages of third party services that the CJEU used to host branded conference videos, which laid Google and DoubleClick cookies without information or a possibility to reject, these were in breach of the law but did not fall within EDPS jurisdiction, and the CJEU had no obligation to provide information on cookies on pages it linked to (Fashion ID applied). This case clarified and confirmed that a withdraw button is needed to be placed as clearly as an accept button in order for consent to be valid to cookies and similar technologies. The EDPS took no formal action as the CJEU engaged rapidly with the organisation and rectified all breaches following the complaint.

### CRITEO: Insufficient fulfilment of data subjects rights

*Source: French Data Protection Authority (CNIL), 2023-06-15 — https://overview.legal/posts/48027 — original: https://www.enforcementtracker.com/ETid-1912*

The French DPA has imposed a fine of EUR 40 million on CRITEO. The controller is specialized in 'retargeting advertising'. This involves the company tracking the surfing behavior of Internet users via so-called Criteo trackers (cookies) in order to show them personalized advertising. In the course of its investigation, the DPA found numerous deficiencies in data processing. First, the DPA found that the controller failed to prove that Internet users had given their consent to be tracked using th

## Recent developments

### What Happened to the Risk-Based Approach to Data Transfers?

*Source: Future of Privacy Forum, 2022-09-27 — https://overview.legal/posts/6271 — original: https://fpf.org/blog/what-happened-to-the-risk-based-approach-to-data-transfers/#entry-912*

The GDPR incorporates the RBA for all obligations of the controller in the GDPR. Where the transfer rules are stated as obligations of the controller (rather than as absolute principles), the RBA of Article 24 therefore applies. Other than the DPAs assume, this is not contradicted by the ECJ in Schrems II nor by the EDPB recommendations on additional measures following the Schrems II judgment, according to Lokke Moerel, Professor of Global ICT Law at Tilburg University and a Dutch Cyber Security

### Health data and use of cookies: DOCTISSIMO fined €380,000

*Source: CNIL, 2023-05-17 — https://overview.legal/posts/6202 — original: https://www.cnil.fr/en/health-data-and-use-cookies-doctissimo-fined-eu380000#entry-5237*

Background information
Following a complaint by the PRIVACY INTERNATIONAL association, the CNIL carried out four investigations into DOCTISSIMO. The doctissimo.fr website mainly offers articles, tests, quizzes and discussion forums related to health and well-being for the general public.
During its investigations, the CNIL noted several infringements, in particular concerning the duration of data retention, the collection of health data via online tests, the security of data as well as the wayco

### DeFine is a calculator for GDPR fines based on method of the EDPB

*Source: Kromann Reumert, 2022-02-01 — https://overview.legal/posts/6310 — original: https://www.khlaw.com/define#entry-14*

> DeFine is a translation into a calculator of part of the methodology proposed by the European Data Protection Board to calculate GDPR fines (see EDPB, Guidelines 04/2022 on the calculation of administrative fines under the GDPR, 12 May 2022, available online; it was subject to a public consultation until 27 June 2022).

## Literature

### Data Controller, Processor or a Joint Controller: Towards Reaching GDPR Compliance in the Data and Technology Driven World

*Source: SSRN Electronic Journal, 2020-01-01 — https://overview.legal/posts/132509 — original: https://doi.org/10.2139/ssrn.3584207*

### The Wirtschaftsakademie Fan Page Decision: A Landmark on Joint Controllership – A Challenge for Supervisory Authorities Competences

*Source: European Data Protection Law Review, 2018-01-01 — https://overview.legal/posts/132499 — original: https://doi.org/10.21552/edpl/2018/4/21*

### ‘Leading by Science’ through Covid-19: the GDPR Automated Decision-Making

*Source: International Journal of Population Data Science, 2021-02-24 — https://overview.legal/posts/132597 — original: https://doi.org/10.23889/ijpds.v5i4.1402*

The UK government announced in March 2020 that it would create an NHS Covid-19 ‘Data Store’ from information routinely collected as part of the health service. This ‘Store’ would use a number of sources of population data to provide a ‘single source of truth’ about the spread of the coronavirus in England. The initiative illustrates the difficulty of relying on automated processing when making healthcare decisions under the General Data Protection Regulation (GDPR). The end-product of the store,

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Data Controller** — https://overview.legal/topics/verwerkingsverantwoordelijke
  The entity that determines purposes and means of processing personal data
- **Consent** — https://overview.legal/topics/toestemming
  Freely given, specific, informed indication of data subject wishes
- **IP Address** — https://overview.legal/topics/ip-adres
  Internet protocol addresses as personal data

---
Generated by overview.legal · https://overview.legal/topics/joint-controllers · 2026-08-22
