# Law Enforcement — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/law-enforcement
> Sources are cited per item. Verify against the official texts before relying on them.

Processing for law enforcement purposes

## Overview

## Legal Framework

Processing of personal data for law enforcement purposes falls primarily under Directive (EU) 2016/680 (the Law Enforcement Directive, or LED), which governs processing by competent authorities for the prevention, investigation, detection, or prosecution of criminal offences. The GDPR expressly excludes such processing under Article 2(2)(a). The LED requires a legal basis under national law for each processing operation, along with necessity and proportionality safeguards. Article 7 CFR (respect for private and family life) and Article 8 CFR (protection of personal data) operate as overarching constitutional constraints, as confirmed in *Digital Rights Ireland v. Ireland*, where the CJEU held that mandatory data retention in itself constitutes an interference with Article 7 CFR, and that subsequent access by national authorities constitutes a further, separate interference requiring its own justification.

The AI Act imposes additional obligations where law enforcement authorities deploy high-risk AI systems. Article 16 AI Act requires providers to ensure conformity with Section 2 requirements, maintain quality management systems under Article 17, and retain technical documentation and automated logs under Articles 18 and 19. The DSA complements this framework by providing recipients of services a right to lodge complaints with Digital Services Coordinators under Article 53, with each Member State designating a single coordinating authority per Recital 110.

## Key Developments

The CJEU has established critical thresholds for lawful enforcement-related processing. In *Digital Rights Ireland*, the Court invalidated blanket data retention obligations, requiring targeted retention with clear scope limitations and prior judicial or independent administrative review before access. In *Ryneš v. Úřad pro ochranu osobních údajů*, the Court accepted that domestic video surveillance capturing public spaces for the purpose of protecting property could fall within the household exemption, but recordings handed to police for criminal proceedings were deemed processing subject to data protection law. In *Breyer v. Bundesrepublik Deutschland*, the Court held that IP addresses constitute personal data where the online service provider has legal channels to obtain identifying information through competent authorities and ISPs, even where direct identification is not possible (paragraphs 47–48). In *Minister voor Immigratie v. M*, the Court clarified that legal analysis applied to an applicant's situation constitutes personal data when grounded in that individual's circumstances (paragraph 40).

The EDPB has been actively evaluating the LED under Article 62, assessing Member State implementation gaps and harmonization needs. Recent enforcement signals include the Slovenian DPA fining a utility company €6,600 for insufficient legal basis and the Romanian DPA imposing €20,000 on Tensa Art Design S.A. for processing deficiencies during investigation. License plate reader deployments for purposes beyond their original scope—such as school residency verification and noise complaints—continue to attract scrutiny as function creep.

## Practical Guidance

- **Establish a specific national law basis** for each processing activity. The LED requires that every law enforcement processing operation be grounded in a precise, accessible national legal provision—not merely internal policy or general police powers.

- **Apply necessity and proportionality at the access stage**, not merely at collection. *Digital Rights Ireland* requires that access to retained data by competent authorities undergo independent review and be limited to what is strictly necessary for the specific investigation.

- **Treat IP addresses and surveillance footage as personal data** regardless of whether direct identification is immediately possible. *Breyer* confirms that the existence of legal channels to obtain identifying information through authorities suffices to trigger data protection obligations.

- **Implement purpose limitation controls to prevent function creep** when deploying surveillance technologies such as license plate readers. Expanding use beyond the original law enforcement purpose—e.g., to administrative verification—requires a separate legal basis and impact assessment.

- **Where AI systems are deployed for law enforcement, ensure Article 16 AI Act compliance** by maintaining quality management documentation, retaining automated logs, and verifying conformity with high-risk system requirements before deployment.

## Legislation (full text of key provisions)

### Right to lodge a complaint

*Source: DSA, dsa-art-53-en, 2022-10-19 — https://overview.legal/posts/94952*

Recipients of the service and any body, organisation or association mandated to exercise the rights conferred by this Regulation on their behalf shall have the right to lodge a complaint against providers of intermediary services alleging an infringement of this Regulation with the Digital Services Coordinator of the Member State where the recipient of the service is located or established. The Digital Services Coordinator shall assess the complaint and, where appropriate, transmit it to the Digital Services Coordinator of establishment, accompanied, where considered appropriate, by an opinion. Where the complaint falls under the responsibility of another competent authority in its Member State, the Digital Services Coordinator receiving the complaint shall transmit it to that authority. During these proceedings, both parties shall have the right to be heard and receive appropriate information about the status of the complaint, in accordance with national law.

### Recital 129 — competent authority power administrative fines

*Source: NIS2, nis2-rec-129-en, 2022-12-14 — https://overview.legal/posts/96786*

In order to ensure effective enforcement of the obligations laid down in this Directive, each competent authority should have the power to impose or request the imposition of administrative fines.

### Recital 133 — temporary suspensions and prohibitions as enforcement

*Source: NIS2, nis2-rec-133-en, 2022-12-14 — https://overview.legal/posts/96794*

In order to further strengthen the effectiveness and dissuasiveness of the enforcement measures applicable to infringements of this Directive, the competent authorities should be empowered to suspend temporarily or to request the temporary suspension of a certification or authorisation concerning part or all of the relevant services provided or activities carried out by an essential entity and request the imposition of a temporary prohibition of the exercise of managerial functions by any natural person discharging managerial responsibilities at chief executive officer or legal representative level. Given their severity and impact on the entities’ activities and ultimately on users, such temporary suspensions or prohibitions should only be applied proportionally to the severity of the infringement and taking account of the circumstances of each individual case, including whether the infringement was intentional or negligent, and any actions taken to prevent or mitigate the material or non-material damage. Such temporary suspensions or prohibitions should only be applied as a last resort, namely only after the other relevant enforcement measures laid down in this Directive have been exhausted, and only until the entity concerned takes the necessary action to remedy the deficiencies or comply with the requirements of the competent authority for which such temporary suspensions or prohibitions were applied. The imposition of such temporary suspensions or prohibitions should be subject to appropriate procedural safeguards in accordance with the general principles of Union law and the Charter, including the right to an effective remedy and to a fair trial, the presumption of innocence and the rights of the defence.

### Recital 24 — sector-specific reporting consistency

*Source: NIS2, nis2-rec-24-en, 2022-12-14 — https://overview.legal/posts/96576*

Where provisions of a sector-specific Union legal act require essential or important entities to comply with reporting obligations that are at least equivalent in effect to the reporting obligations laid down in this Directive, the consistency and effectiveness of the handling of incident notifications should be ensured. To that end, the provisions relating to incident notifications of the sector-specific Union legal act should provide the CSIRTs, the competent authorities or the single points of contact on cybersecurity (single points of contact) under this Directive with an immediate access to the incident notifications submitted in accordance with the sector-specific Union legal act. In particular, such immediate access can be ensured if incident notifications are being forwarded without undue delay to the CSIRT, the competent authority or the single point of contact under this Directive. Where appropriate, Member States should put in place an automatic and direct reporting mechanism that ensures systematic and immediate sharing of information with the CSIRTs, the competent authorities or the single points of contact concerning the handling of such incident notifications. For the purpose of simplifying reporting and of implementing the automatic and direct reporting mechanism, Member States could, in accordance with the sector-specific Union legal act, use a single entry point.

### Recital 40 — cross border cooperation single points contact

*Source: NIS2, nis2-rec-40-en, 2022-12-14 — https://overview.legal/posts/96608*

The single points of contact should ensure effective cross-border cooperation with relevant authorities of other Member States and, where appropriate, with the Commission and ENISA. The single points of contact should therefore be tasked with forwarding notifications of significant incidents with cross-border impact to the single points of contact of other affected Member States upon the request of the CSIRT or the competent authority. At national level, the single points of contact should enable smooth cross-sectoral cooperation with other competent authorities. The single points of contact could also be the addressees of relevant information about incidents concerning financial entities from the competent authorities under Regulation (EU) 2022/2554 which they should be able to forward, as appropriate, to the CSIRTs or the competent authorities under this Directive.

### Recital 41 — national CSIRT capabilities and resources

*Source: NIS2, nis2-rec-41-en, 2022-12-14 — https://overview.legal/posts/96610*

Member States should be adequately equipped, in terms of both technical and organisational capabilities, to prevent, detect, respond to and mitigate incidents and risks. Member States should therefore establish or designate one or more CSIRTs under this Directive and ensure that they have adequate resources and technical capabilities. The CSIRTs should comply with the requirements laid down in this Directive in order to guarantee effective and compatible capabilities to deal with incidents and risks and to ensure efficient cooperation at Union level. Member States should be able to designate existing computer emergency response teams (CERTs) as CSIRTs. In order to enhance the trust relationship between the entities and the CSIRTs, where a CSIRT is part of a competent authority, Member States should be able to consider functional separation between the operational tasks provided by the CSIRTs, in particular in relation to information sharing and assistance provided to the entities, and the supervisory activities of the competent authorities.

### Recital 127 — minimum enforcement powers and proportionate penalties

*Source: NIS2, nis2-rec-127-en, 2022-12-14 — https://overview.legal/posts/96782*

In order to make enforcement effective, a minimum list of enforcement powers that can be exercised for breach of the cybersecurity risk-management measures and reporting obligations provided for in this Directive should be laid down, setting up a clear and consistent framework for such enforcement across the Union. Due regard should be given to the nature, gravity and duration of the infringement of this Directive, the material or non-material damage caused, whether the infringement was intentional or negligent, actions taken to prevent or mitigate the material or non-material damage, the degree of responsibility or any relevant previous infringements, the degree of cooperation with the competent authority and any other aggravating or mitigating factor. The enforcement measures, including administrative fines, should be proportionate and their imposition should be subject to appropriate procedural safeguards in accordance with the general principles of Union law and the Charter of Fundamental Rights of the European Union (the ‘Charter’), including the right to an effective remedy and to a fair trial, the presumption of innocence and the rights of the defence.

### Recital 126 — immediate enforcement decisions for cyber threats

*Source: NIS2, nis2-rec-126-en, 2022-12-14 — https://overview.legal/posts/96780*

In duly substantiated cases where it is aware of a significant cyber threat or an imminent risk, the competent authority should be able to take immediate enforcement decisions with the aim of preventing or responding to an incident.

### Recital 107 — reporting suspected serious criminal incidents

*Source: NIS2, nis2-rec-107-en, 2022-12-14 — https://overview.legal/posts/96742*

Where it is suspected that an incident is related to serious criminal activities under Union or national law, Member States should encourage essential and important entities, on the basis of applicable criminal proceedings rules in accordance with Union law, to report incidents of a suspected serious criminal nature to the relevant law enforcement authorities. Where appropriate, and without prejudice to the personal data protection rules applying to Europol, it is desirable that coordination between the competent authorities and the law enforcement authorities of different Member States be facilitated by the European Cybercrime Centre (EC3) and ENISA.

### Recital 94 — competent authorities trust services cooperation

*Source: NIS2, nis2-rec-94-en, 2022-12-14 — https://overview.legal/posts/96716*

Member States can assign the role of the competent authorities for trust services to the supervisory bodies under Regulation (EU) No 910/2014 in order to ensure the continuation of current practices and to build on the knowledge and experience gained in the application of that Regulation. In such a case, the competent authorities under this Directive should cooperate closely and in a timely manner with those supervisory bodies by exchanging relevant information in order to ensure effective supervision and compliance of trust service providers with the requirements laid down in this Directive and in Regulation (EU) No 910/2014. Where applicable, the CSIRT or the competent authority under this Directive should immediately inform the supervisory body under Regulation (EU) No 910/2014 about any notified significant cyber threat or incident affecting trust services as well as about any infringements by a trust service provider of this Directive. For the purpose of reporting, Member States can, where applicable, use the single entry point established to achieve a common and automatic incident reporting to both the supervisory body under Regulation (EU) No 910/2014 and the CSIRT or the competent authority under this Directive.

## Case law

### CE - 449212

*Source: CE, 2021-03-04 — https://overview.legal/posts/125660 — original: https://gdprhub.eu/index.php?title=CE_-_449212*

Facts — On December, 7 2020, the French DPA imposed a financial penalty of 60 Million euros fine against Google LLC and a 40 million euros against Google Ireland Limited in accordance with the General Data Protection Regulation (GDPR) and ePrivacy Directive 2002/58/EC, for lack of transparency, inadequate information and lack of valid consent regarding for violating the regulation on cookies while operating the website google.fr. The sanction was accompanied by an order to comply with article 82 of the French Law on data protection (Law Informatique et Libertés), under three months on penalty of a €100,000 fine per day of delay. The companies appealed to the Conseil d’État in interim procedure against the CNIL's decision, arguing that the French DPA was not the competent authority because it was not the lead supervisory authority for Google LLC or Google Ireland Limited. Dispute — Is the CNIL territorially competent to investigate and sanction a company for violating the information principle when depositing cookies if it is not the lead supervisory authority of the company? The CNIL considered that Google does have EU headquarters in Ireland, but that this Irish entity ‘did not have a decision making power’ in relation to the relevant cross-border data processing activities to which the complaints related. For that reason the CNIL decided that the One Stop Shop mechanism did not apply and that the CNIL, like any other European supervisory authority, was therefore competent to make a decision. Holding — The Conseil d’État rejected the request made by Google and ruled that the French DPA was territorially competent on this matter even though it is not the lead supervisory authority. The court stated that Article 82 of the Law Informatique et Libertés was a transposition of Article 5(3) ePrivacy Directive 2002/58/EC into French Law when dealing with cookies and that the CNIL is charged with enforcing this Directive. As such, the one-stop shop mechanism provided for in Article 56 GDPR does not apply in the present case.

### Judgment of the Court (Grand Chamber) of 30 April 2024.#Criminal proceedings against Unknown individuals.#Request for a preliminary ruling from the Giudice delle indagini preliminari presso il Tribunale di Bolzano.#Reference for a preliminary ruling – Processing of personal data in the electronic communications sector – Confidentiality of communications – Providers of electronic communications services – Directive 2002/58/EC – Article 15(1) – Articles 7, 8, 11 and Article 52(1) of the Charter of

*Source: Court of Justice of the European Union, C-178/22, 2024-04-30 — https://overview.legal/posts/132260 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0178*

The Court of Justice of the European Union, ruling in Case C-178/22 on a preliminary reference from the Giudice delle indagini preliminari presso il Tribunale di Bolzano, addressed whether national authorities may compel providers of electronic communications services to disclose retained personal data for the prosecution of aggravated theft under Article 15(1) of Directive 2002/58/EC and the Charter of Fundamental Rights. The Court held that Member States retain competence to define what constitutes a "serious offence" justifying such interference, but that data access for non-serious offences is impermissible and all access requests must be subject to prior independent review—whether by a court or an independent administrative body—to ensure strict proportionality and necessity. No fine was imposed.

### Judgment of the Court (Grand Chamber) of 5 March 2024.#Marián Kočner v European Union Agency for Law Enforcement Cooperation (Europol).#Appeal – Law enforcement cooperation – Regulation (EU) 2016/794 – Article 49(3) and Article 50 – Protection of personal data – Unlawful data processing – Criminal proceedings brought in Slovakia against the appellant – Expert’s report drawn up by the European Union Agency for Law Enforcement Cooperation (Europol) for the purposes of the investigation – Retrieval

*Source: Court of Justice of the European Union, C-755/21, 2024-03-05 — https://overview.legal/posts/132271 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0755*

In Case C-755/21 P, Marián Kočner appealed a General Court judgment dismissing his claim for compensation against Europol for alleged damage arising from Europol's disclosure of his personal data and inclusion of his name on so-called "mafia lists." The Grand Chamber of the Court of Justice of the European Union examined the scope of non-contractual liability under Articles 49(3) and 50 of Regulation (EU) 2016/794, addressing whether Europol could be held liable for non-material damage resulting from unlawful data processing. The full outcome of the appeal is not reflected in the provided excerpt, which does not include the operative part of the judgment.

### CE - 451423

*Source: Supreme Administrative Court, 2022-06-27 — https://overview.legal/posts/108993 — original: https://gdprhub.eu/index.php?title=CE_-_451423*

Facts — The French DPA had received a complaint on 28 May 2018 regarding the lawfulness of processing by Amazon Europe Core ('Provider' or 'The company'). The French DPA had forwarded this complaint to the Luxembourg DPA under the 'one stop shop' mechanism of Article 56 GDPR. The luxembourg DPA started an investigation regarding Amazon's use of cookies and its compliance with the GDPR and the ePrivacy directive. However, the French DPA started its own investigation into Amazon's compliance with Article 82 of the French Data protection act, a national implementation of Article 5(3) of the ePrivacy directive. (directive 2002/58/EC). This investigation regarding Article 82 had resulted in decision SAN-2020-013. In this decision, the French DPA fined Amazon €35,000,000 for the failure to obtain prior consent and the failure to inform users of their rights with regards to the processing of their data, which was mandatory under Article 82 of the Data Protection Act. The DPA found that when a user visited the "Amazon.fr" site, a large number of cookies with advertising purposes were automatically placed on the data subjects computer. Because this type of cookie was not essential to the service provided by the controller, the DPA considered that the controller had not complied with the obligation to obtain the consent of Internet users before depositing the cookies. Amazon appealed this decision at the Conseil d'Etat, the French Supreme Administrative Court, and requested its annulment. Amazon also asked the Conseil to refer several questions to the CJEU for a preliminary ruling. Among other arguments, Amazon claimed that the French DPA had made an incorrect interpretation of the law regarding its competence and had disregarded its competence by imposing the contested sanction. The controller also stated that the involvement of the French DPA, when the Luxembourg DPA was already involved, constituted a violation of Article 50 of the Charter of Fundamental Rights. According to this article, the same person may not be prosecuted more than once for the same acts. Holding — With regard to the application of the "one-stop shop" mechanism and the CNIL's jurisdiction: The Conseil ruled that the application and enforcement of the ePrivacy directive was the responsibility of national DPAs according to Article 15a of the directive. The "one-stop shop" mechanism did not apply in this case, even when there was a form of a cross-border processing. The Conseil also stated that the absence of a 'one-stop shop' mechanism did not imply any infringement of Article 50 of the Charter of Fundamental Rights, because the DPA only ruled on breaches of national law transposing EU law in the contested decision, and not on GDPR related violations. The Conseil also assessed the compatibility of Article 3 of the French Data protection Act with the ePrivacy Directive. The Conseil determined that Directive 2002/58/EC did not prevent the French DPA to apply the French data protection Act (including Article 82). The Directive would therefore also not prevent the French DPA from penalising the controller for supposed violations of Article 82 of the French data protection Act. Therefore, the Conseil established that the French DPA could enforce the French data protection act against any person or legal entity responsible for the processing of data who had an establishment in France, irrespective of the location of the principal establishment of the responsible entity. This enforcement by the DPA would also not constitute violations of articles 49 (Freedom of establishment) or 56 (Freedom to provide services) of the TFEU. With regard to the sanction imposed by the CNIL: The Conseil deemed that the applicant was sufficiently informed regarding the scope of the DPA's investigations, the facts and the legal grounds on which the sanction was based. Moreover, the Conseil considered that the applicant was given sufficient time to present its defence. The Conseil also ruled that the involvement of the French DPA, while the Luxembourg DPA was the lead supervisory authority, was not enough to constitute a breach of the equality of arms principle. Amazon had argued that the involvement of the French DPA in the procedure had enabled the French DPA to gain access to privileged and confidential information and had used this information as a basis for its own decision. The Conseil determined that Amazon did not provide enough proof for this argument and stated that Amazon was not able to prove that was the procedure contrary to Article 15a(4) of Directive 2002/58/EC. On a possible violation of Article 50 of the Charter of Fundamental Rights: The Conseil explained, based on the CJEU's case law (Aklagaren v Akerberg Fransson C-617/10, Powszechny Zaklad Ubezpieczen na Zycie SA of C-617/17 and bpost SA v Belgian Competition Authority C-117/20), that the principle invoked by the applicant, that the same person may not be the subject of several proceeding in respect of the same facts, was not violated by the French DPA. The Conseil stated that the principle could only be enforced when criminal proceedings had been definitively terminated. This was in particular the case when a criminal penalty had become final. The Conseil held that Amazon was not found to be the subject of a final sanction issued by the Luxembourg DPA for the facts that had resulted in the €35,000,000 fine in the contested decision. The Conseil rejected the applicant's claim for a reference for a preliminary ruling on the matter. Regarding the application of French Data Protection Act by the French DPA, Amazon had argued that the legal framework regarding cookies was not stable and unclear at the time when proceedings against Amazon were started. The Conseil concluded that it had published guidelines detailing obligations for entities under the applicable law, and considered that the fact that other national supervisory authorities had taken divergent positions in interpreting the conditions and procedures applicable to the collection of user consent had no bearing on the application of the French Data Protection Act by the French DPA. On the proportionality of the sanction imposed: Taking into account the elements assessed by the French DPA to calculate the imposed fine, the Conseil ruled that the DPA had not imposed a disproportionate penalty on the controller. Consequently, the Conseil rejected the entirety of controller's claims.

### CE - 449209

*Source: CE, 2022-01-28 — https://overview.legal/posts/122847 — original: https://gdprhub.eu/index.php?title=CE_-_449209*

Facts — On 7 December 2020, the French DPA (CNIL) imposed two fines totaling € 100 million on Google LLC and Google Ireland Ltd for violating Article 82 of the French Data Protection Act (which transposes the ePrivacy Directive). Google (1) had not obtained the user’s consent before depositing advertising cookies in the user’s terminal equipment, (2) had lacked to provide information, and (3) had not implemented a mechanism to refuse the cookies. Google did not agree with the CNIL’s decision and brought the issue before court. First, it claimed that, since there is cross-border processing, the Irish DPA (DPC) is the lead supervisory authority since Google’s main establishment in the EU is in Ireland, and the CNIL therefore did not have competence to rule on this matter according to the one-stop-shop mechanism. Second, it found the fine to be disproportionate. Hence, it requested the Council of State to annul the decision, and to refer two preliminary questions to the CJEU, asking: (1) whether the one-stop-shop mechanism provided for in Article 56 GDPR is excluded in the context of cross-border processing that falls within the scope of both the ePrivacy Directive and the GDPR, and (2) whether Article 15a ePrivacy Directive violates the right to data protection because does not provide an obligation, but rather an option, “for the competent national regulatory authorities to adopt measures to ensure effective cross-border cooperation in the enforcement of national laws adopted pursuant to the directive and to create harmonised conditions for the provision of services involving cross-border data flows”. Holding — The Council of State rejected Google’s appeal. First, according to the Council, the ePrivacy Directive, implemented in the French Data Protection Act, does not provide for the application of the one-stop-shop mechanism as mentioned in Article 56 GDPR. Although the requirements for consent are regulated by the GDPR the deposit of cookies is regulated by the ePrivacy Directive. Hence, even if cross-border processing takes place, the CNIL is competent to monitor compliance with the objectives of such Directive. The Council then notes that “it follows that, as regards the control of the operations of access and recording of information in the terminals of users in France of an electronic communications service, even if they are the result of cross-border processing, the measures to monitor the application of the provisions transposing the objectives of Directive 2002/58/EC fall within the competence conferred on the CNIL by the Law of 6 January 1978.” The Council stipulated that there is no need to refer preliminary questions to the CJEU, because it had no doubt as to whether the one-stop-shop mechanism should be excluded in the context of cookies. Second, the Council rejected Google’s argument that their right of defense had been infringed by the CNIL because they did not provide a prior formal notice, since it is not required to provide such a formal notice before imposing a sanction. Third, on the substance of the matter, the Council confirmed the three violations of Article 82 of the Data Protection Act: (1) not obtaining the user’s consent before depositing advertising cookies in the user’s terminal equipment, (2) not providing clear information on the deposit of cookies, and (3) not implementing a mechanism to refuse the cookies. Lastly, the Council stated that the fines were not disproportionate in light of the financial capacities of the “two” companies. It considered Google’s market share of more than 90% with (an estimated) 47 million users in France and the large profits that follow from the targeted online advertisement. Moreover, it stated that Google did not genuinely cooperated with the CNIL since it did not provide advertising revenues, and the breaches were serious.

### CJEU - C-350/21 - Spetsializirana prokuratura (Retention of traffic and location data)

*Source: GDPRhub, C-350/21, 2026-07-16 — https://overview.legal/posts/122856 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-350/21_-_Spetsializirana_prokuratura_(Retention_of_traffic_and_location_data)*

Facts — In the context of criminal proceedings in Bulgaria, the prosecutor requested the Spetsializiran nakazatelen sad (Bulgarian Criminal Court) to give him access to data, including location data, concerning the telephone calls of five persons involved in a serious crime case. The case file showed that the telephone numbers were potentially used to commit the crime. Under Bulgarian national law, the retention of traffic and location data is limited to six months. Access to these data is only allowed for investigative purposes in serious offences, but the national law does not include a provision that restricts access to what is strictly necessary for the purpose. The Criminal Court therefore referred the following question to the CJEU. (1) Is national legislation (Article 251b(1) of the Zakon za elektronnite saobshtenia (Law on electronic communications)) providing for the general and indiscriminate retention of all traffic data (traffic data and location data of users of electronic means of communication) for a period of 6 months in order to fight serious crime compatible with Article 15(1) of Directive 2002/58, read in combination with Article 5(1) and recital 11 thereof, provided that the national legislation contains certain safeguards? (2) Is national legislation (Article 159a of the Nakazatelno-protsesualen kodeks (Code of Criminal Procedure)) which does not limit access to traffic data to what is strictly necessary and does not grant the persons whose traffic data are accessed by the law enforcement authorities the right to be notified thereof, provided that that does not impede criminal proceedings, or the right to a legal remedy against unlawful access compatible with Article 15(1) of Directive 2002/58, read in combination with Article 5(1) and recital 11 thereof? Holding — (1) The Court considered that Article 15(1) of Directive 2002/58 does not allow Member States to derogate from Articles 4(1) and 4(1)bis, which require providers of electronic communications services to take appropriate technical and organisational measures to ensure effective data protection. It answered the first question by stating that Article 15(1) of the Directive must be interpreted as precluding national legislation which provides for general and undifferentiated data retention as a preventive measure in the context of criminal investigations. (2) As to the second question, concerning the failure of national legislation to provide for access to data to be limited to what is strictly necessary, the Court held that national legislation must satisfy the requirement of proportionality. In particular, the legislation cannot be limited to requiring that the authorities' access to the data be in accordance with the purpose of the legislation, but must also provide for the material and procedural conditions governing that use. The Court therefore considered that national legislation which does not provide that access to stored data is limited to what is strictly necessary to achieve the purpose of that storage does not comply with the mentioned provisions. As regards information and the right of appeal for data subjects, the Court considered that the articles in question preclude national legislation which does not guarantee that data subjects are informed of the processing to the extent provided for by EU law and which does not allow any means of appeal in the event of unlawful access to such data.

### CJEU - Case C‑5/25 - Pilev

*Source: GDPRhub, 2026-03-05 — https://overview.legal/posts/125592 — original: https://gdprhub.eu/index.php?title=CJEU_-_Case_C‑5/25_-_Pilev*

Facts — In September 2023, the Bulgarian Public Prosecutor’s Office brought a criminal case against a data subject to the Sofia City Court. According to the Prosecutor’s Office, the data subject bribed police officers, and worked as a taxi driver without the necessary license. During the proceedings, the court requested personal data from the data subject in order to verify their identity. While a data subject can be identified with their identity card, national law requires national courts to ask further questions to further verify the data subject’s identity. The court had doubts on the compatibility of said national law provisions with the Bulgarian Constitution, and stayed proceedings. In addition, the court had doubts on whether requesting additional information (e.g. place of birth, ethnicity, or marital status) is necessary, and whether the national provisions are consistent with Article 10 Law Enforcement Directive 2016/680. The court referred the matter to the Constitutional Court. The Constitutional Court refused to give a substantive ruling, and the court therefore requested a preliminary ruling from the CJEU. Advocate General Opinion — The AG first stated that the data processing fell in the scope of the LED in accordance with Article 2(1) Law Enforcement Directive 2016/680. The LED is applicable if the data processing is carried out by a competent authority (Article 3(7) Law Enforcement Directive 2016/680) and for the purposes listed in Article 1(1) Law Enforcement Directive 2016/680. The LED is the lex specialis of the GDPR, which excludes from its scope processing of personal data that falls within the scope of the LED. In the AG’s view, the court falls within the definition of a competent authority; while it may not expressly follow the definition of competent authority, it can be inferred from the provisions’ context. The AG also considered that the definition of “prosecution of criminal offenses” can be interpreted broadly, and therefore the court’s processing activities fell under the scope of the LED. This does not contradict the principle that exceptions to the GDPR (as lex generalis) should be interpreted strictly, as criminal court proceedings would not be exempt from data protection regulations. The AG also highlighted that having two different data protection laws apply at different stages of the court proceedings and by different law enforcement actors would lead to a fragmented legal regime, in contradiction to the principle of legal certainty and consistent protection of personal data. Finally, the AG noted that the LED grants law enforcement authorities more flexibility in processing data, particularly in the case of processing sensitive personal data prohibited under Article 9(1) GDPR. In terms of national law provisions, the AG opined that national law requiring the systematic processing of data subjects’ personal data when verifying their identity was not compatible with the LED, when this data is not necessary for that purpose. The purpose of verifying that a data subject is the person being indicted is a legitimate purpose. However, the AG opined that requiring courts to systematically process data such as ethnicity, marital status or previous convictions were not compatible with the principle of data minimisation (Article 4(1)(c) Law Enforcement Directive 2016/680) or lawfulness (Article 8(1) Law Enforcement Directive 2016/680). This is because this information is not necessary at the stage of proceedings of verifying the data subject’s identity. Even in cases where this information was needed, the AG noted that the systematic nature of this data processing was disproportionate. Finally, the AG highlighted that the court would systematically process special categories of personal data, which Article 10 Law Enforcement Directive 2016/680 allows only where strictly necessary. Holding — TBD.

### CJEU - Case C 312/24 - Darashev

*Source: GDPRhub, 2025-09-04 — https://overview.legal/posts/158443 — original: https://gdprhub.eu/index.php?title=CJEU_-_Case_C_312/24_-_Darashev*

Facts — The data subject is a police officer, holding various positions at the Internal Security directorate-general of the Bulgarian Ministry of the Interior (controller). In March 2016, investigative proceedings were commenced concerning an unknown offender in connection with an offence of theft. A few days later, the data subject was arrested and after being detained in police custody for 24 hours, he was released. Subsequently, he was neither placed under formal investigation nor charged, but he was the subject of several investigative measures, which in the course of 2016, were suspended without the offender having been identified. The controller stored the data about the criminal investigation on his personnel file, as provided by the ministerial instruction relating to personnel files, issued as a regulatory act pursuant to the statutory authorisation provided for in the Law on the Ministry of the Interior (ZMVR). The data subject continued his duties as a police officer and took part in selection procedures for promotion to other posts within the Ministry but he was rejected. The data subject brought an action before the Sofia District Court (Sofiyski rayonen sad) seeking compensation for non-material damage for the fact that he has not been promoted or transferred to other duties on account of his having been a suspect in the investigation. In addition, he asked that his name be erased from the database kept by the controller, in which he is mentioned as a suspect. In this context the court decided to stay the proceedings and to refer some questions to the CJEU for a preliminary ruling, regarding the interplay of the GDPR with the Law Enforcement Directive (LED), and more specifically regarding the storage of data concerning the official in his personnel file. The questions were combined and reformulated by the AG as follows: whether Article 2(1) GDPR and Article 9(1) LED are to be interpreted as meaning that the GDPR applies to the storing, by a public authority in the personnel file of one of its officials, of data regarding that official’s status as a suspect in a criminal investigation, where the data have been collected by an organisational unit within that public authority in the performance of its duties as a competent authority within the meaning of LED. whether Article 17(3) GDPR, read in conjunction with Article 6(1)(c) and Article 6(3) thereof, is to be interpreted as meaning that the storage, in a police officer’s personnel file, of personal data relating to a criminal investigation in which that officer was the subject of investigative measures, as a suspect, and which was discontinued, may be considered lawful for the purposes of compliance with a legal obligation to which the public authority that is his employer is subject under national law, as controller, merely on account of the nature of the duties which that officer is required to perform. Holding — Regarding the first question about the scope of the GDPR, the AG responded positively, that the GDPR does apply in this case, provided that the storage of that data pursues purposes other than those set out in Article 1(1) LED, purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties. Regarding the second question, the AG responded negatively, that the storage of the data subject’s data in this case was not lawful. First, he clarified that within the meaning of Article 6(3) GDPR, the storage of personal data could be based on a legal obligation being defined in a national law other that a law stricto sensu, though in accordance with national constitutional law. Therefore, in this case, the ministerial instruction was considered an appropriate legal basis. Nevertheless, the AG expressed doubts as to the foreseeability of the purposes of the processing, which, in accordance with Article 6(3) GDPR must be determined by the legal basis of the processing. As laid down in the ministerial instruction, the purpose of the storage was for reasons of ‘change of duties’. The AG considered that this, did not appear to meet an objective of public interest, for the purposes of Article 6(3) GDPR. Furthermore, he failed to see how the nature of the duties of maintaining public order, which fall to the data subject, could justify the storage of the data at issue in his personnel file. In conclusion, the AG opined that the storage of the data at issue was not lawful and that the data subject had the right to have them erased, pursuant to Article 17(1)(d) GDPR.

### Judgment of the General Court (Tenth Chamber, Extended Composition) of 29 January 2025 (Extracts).#Data Protection Commission v European Data Protection Board.#Protection of personal data – Article 65(1)(a) of Regulation (EU) 2016/679 – Binding decision instructing a lead supervisory authority to broaden the scope of its investigation and issue a new draft decision – Competence of the European Data Protection Board.#Joined Cases T-70/23, T-84/23 and T-111/23.

*Source: General Court, T-70/23, 2025-01-29 — https://overview.legal/posts/132152 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023TJ0070*

The Irish Data Protection Commission (DPC) challenged provisions of EDPB Binding Decisions 3/2022, 4/2022, and 5/2022, arguing the EDPB exceeded its competence under Article 65(1)(a) GDPR by requiring the DPC to broaden its investigation into Facebook, Instagram, and WhatsApp and issue new draft decisions. The core legal issue was whether the EDPB, in the consistency mechanism context, can compel a lead supervisory authority to conduct additional investigations and produce new draft decisions beyond addressing the specific relevant and reasoned objections raised by concerned supervisory authorities. The General Court dismissed the DPC's actions, upholding the EDPB's authority to issue binding decisions instructing the lead supervisory authority to carry out further investigation and issue new draft decisions.

### Judgment of the Court (Grand Chamber) of 30 April 2024.#Criminal proceedings against M.N.#Request for a preliminary ruling from the Landgericht Berlin.#Reference for a preliminary ruling – Judicial cooperation in criminal matters – Directive 2014/41/EU – European Investigation Order (EIO) in criminal matters – Obtaining of evidence already in the possession of the competent authorities of the executing State – Conditions for issuing an EIO – Encrypted telecommunications service – EncroChat – Nee

*Source: Court of Justice of the European Union, C-670/22, 2024-04-30 — https://overview.legal/posts/132261 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0670*

The Court of Justice of the European Union (Grand Chamber), in response to a preliminary ruling from the Landgericht Berlin, examined the interpretation of Directive 2014/41/EU (the European Investigation Order Directive) in the context of criminal proceedings against M.N. The case addressed the lawfulness of EIOs issued by German authorities to obtain evidence already in the possession of the executing State, specifically data derived from the EncroChat encrypted telecommunications service, and clarified the conditions for issuing an EIO and the impact of evidence obtained in potential breach of EU law on fundamental rights and data protection. The Court's ruling provides guidance on the principles of equivalence and effectiveness, the necessity of judicial authorization, and the admissibility of evidence gathered through cross-border investigative measures under the EIO framework.

### Judgment of the Court (Grand Chamber) of 20 September 2022.#Criminal proceedings against VD bd]&#xd; &#xd; Criminal proceedings against VD and SR.#Requests for a preliminary ruling from the Cour de cassation.#References for a preliminary ruling – Single market for financial services – Market abuse – Insider dealing – Directive 2003/6/EC – Article 12(2)(a) and (d) – Regulation (EU) No 596/2014 – Article 23(2)(g) and (h) – Supervisory and investigatory powers of the Autorité des marchés financiers

*Source: Court of Justice of the European Union, C-339/20, 2022-09-20 — https://overview.legal/posts/132308 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62020CJ0339*

In Joined Cases C-339/20 and C-397/20, the Court of Justice of the European Union (Grand Chamber) addressed preliminary ruling requests from the French Cour de cassation in criminal proceedings against VD and SR, concerning whether the French financial markets authority (AMF) could require electronic communications service providers to retain and disclose traffic data for insider dealing investigations. The Court examined the interplay between the market abuse regulatory framework and the ePrivacy Directive (2002/58/EC), assessing whether national legislation authorizing general and indiscriminate retention of traffic data complies with Articles 7, 8, and 11 of the EU Charter of Fundamental Rights. The Court held that such general and indiscriminate retention is precluded and that national courts may not restrict the temporal effects of a declaration of invalidity with respect to incompatible national provisions.

### Judgment of the Court (Fourth Chamber) of 16 December 2021.#Criminal proceedings against HP.#Request for a preliminary ruling from the Spetsializiran nakazatelen sad.#Reference for a preliminary ruling – Judicial cooperation in criminal matters – European Investigation Order (EIO) – Directive 2014/41/EU – Article 2(c)(i) – Concept of ‘issuing authority’ – Article 6 – Conditions for issuing an EIO – Article 9(1) and (3) – Recognition of an EIO – EIO seeking to obtain traffic and location data ass

*Source: Court of Justice of the European Union, C-724/19, 2021-12-16 — https://overview.legal/posts/132318 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62019CJ0724*

In Case C-724/19, the Court of Justice of the European Union interpreted Directive 2014/41/EU (the European Investigation Order Directive) in response to a preliminary reference from the Bulgarian Specialised Criminal Court in criminal proceedings against HP, where four EIOs issued by a Bulgarian public prosecutor sought traffic and location data from other Member States. The Court held that a public prosecutor designated as an "issuing authority" under national transposition law qualifies as such under Article 2(c)(i) of the Directive, even where domestic law reserves the exclusive competence to order the same investigative measure to a judge in analogous domestic cases. The Court further ruled that the executing State must recognize and execute such an EIO, as differences in national rules governing the designation of competent authorities cannot justify refusal of recognition under the Directive's mutual recognition framework.

## Guidance

### Guidelines 01/2023 on Article 37 Law Enforcement Directive

*Source: EDPB, guidelines-012023-on-article-37-law-enforcement-directive-en, 2024-06-19 — https://overview.legal/posts/125738 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-012023-on-article-37-law-enforcement-directive_en*

Adopted 1 Guidelines 0 1 / 2023 on Article 37 Law Enforcement Directive V ersion 2 . 1 Adopted on 19 June 2024 Adopted 2 Version history Version 1.0 27 September 2023 Adoption of the Guidelines for public consultation Version 2.0 19 June 2024 Adoption of the Guidelines after public consultation Version 2.1 30 September 2024 Minor corrections in footnotes 10 and 57 Adopted 3 Executive summary These guidelines provide guidance on the application of Article 37 LED, in particular on the legal…

### EDPB Strategy 2021-2023

*Source: EDPB, edpb-strategy-2021-2023-en, 2020-12-15 — https://overview.legal/posts/126089 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-strategy-2021-2023_en*

Adopted EDPB Strategy 2021 - 2023 Adopted on 15 December 2020 Adopted Adopted 1 INTRODUCTION 1. The mission of the European Data Protection Board (EDPB) is to ensure the consistent application of European data protection rules and to promote effective cooperation among supervisory authorities throughout the European Economic Area (EEA). 2. On 25 May 2018, the EDPB began putting into practice a new institutiona l and legal framework. This framework comprises both the General Data Protection…

### EDPB Strategy 2024-2027

*Source: EDPB, edpb-strategy-2024-2027-en, 2024-04-18 — https://overview.legal/posts/125760 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-strategy-2024-2027_en*

The mission and legal task of the European Data Protection Board (EDPB) is to ensure the consistent application of EU data protection rules and to promote effective cooperation among data protection authorities throughout the European Economic Area (EEA). Since their entries into application in 2018, the General Data Protection Regulation (GDPR) and the Law Enforcement Directive (LED) have strengthened, modernised and harmonised data protection across the European Economic Area (EEA). Awareness…

### Opinion 27/2025 regarding the European Commission Draft Implementing Decision pursuant to Directive (EU) 2016/680 on the adequate protection of personal data by the United Kingdom

*Source: EDPB, edpb-opinion-202527-united-kingdom-adequacy-led-en, 2025-10-16 — https://overview.legal/posts/51407 — original: https://www.edpb.europa.eu/documents/adequacy/opinion-272025-regarding-the-european-commission-draft-implementing-decision_en*

Adopted 1 Opinion 27/2025 regarding the European Commission Draft Implementing Decision pursuant to Directive (EU) 2016/680 on the adequate protection of personal data by the United Kingdom Adopted 16 October 2025 Adopted 2 Executive summary The European Commission endorsed its draft implementing decision on the adequate protection of personal data by the United Kingdom pursuant to the Law Enforcement Directive on 22 July 2025. On the same date, as part of the procedure towards the formal…

### Report of the work undertaken by the Cookie Banner Taskforce

*Source: EDPB, report-of-the-work-undertaken-by-the-cookie-banner-taskforce-en, 2023-01-18 — https://overview.legal/posts/125875 — original: https://www.edpb.europa.eu/documents/task-force-report/report-of-the-work-undertaken-by-the-cookie-banner-taskforce_en*

Adopted 1 Report of the work undertaken by the Cookie Banner Taskforce Adopted on 17 January 2023 Adopted 2 Adopted 3 DISCLAIMER The positions presented in this document result from the coordination of the members of the TF with a view to handling the “cookies banner” complaints received from NOYB. They reflect the common denominator agreed by the SAs in their interpretation of the applicable provisions of the ePrivacy Directive, and of the applicable provisions of the GDPR, for the analysis to…

### Contribution of the EDPB to the European Commission’s evaluation of the Data Protection Law Enforcement Directive (LED) under Article 62

*Source: EDPB, contribution-of-the-edpb-to-the-european-commissions-en, 2021-12-14 — https://overview.legal/posts/125973 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/contribution-of-the-edpb-to-the-european-commissions_en*

Adopted Contribution of the EDPB to the European Commission’s evaluation of the Data Protection Law Enforcement Directive ( LED ) under Article 62 Adopted on 14 December 2021 2 3 The European Data Protection Board Having regard to Articles 51(1)(a)(b) and (h) of the Directive ( EU ) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal da ta by competent authorities for the purposes of the…

### Statement 04/2021 on international agreements including transfers

*Source: EDPB, statement-042021-on-international-agreements-including-transfers-en, 2021-04-13 — https://overview.legal/posts/126036 — original: https://www.edpb.europa.eu/documents/statement/statement-042021-on-international-agreements-including-transfers_en*

1 Adopted Statement 04/2021 on i nternational agreements including transfers Adopted on 13 April 2021 The European Data Protection Board has adopted the following statement: As the EDPB/national Supervisory Authorities have been receiving questions about the exchange of personal data between public authorities under existing international agreements in different areas, the EDPB wishes to recall the requirements of Article 96 G DPR and Article 61 Law Enforcement Directive (LED). According to…

### Recommendations 01/2021 on the adequacy referential under the Law Enforcement Directive

*Source: EDPB, recommendations-012021-on-the-adequacy-referential-under-the-law-en, 2021-02-02 — https://overview.legal/posts/126065 — original: https://www.edpb.europa.eu/documents/recommendation/recommendations-012021-on-the-adequacy-referential-under-the-law_en*

1 vo.1 Adopted Recommendations 01/2021 on the adequacy referential under the Law Enforcement Directive Adopted on 2 February 2021 2 vo.1 Adopted Version history Version 1.1 6 July 2021 Formatting change Version 1.0 2 February 2021 Adoption of the Recommendations 3 vo.1 Adopted 4 vo.1 Adopted The European Data Protection Board Having regard to Article 51 (1) (b) of Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with…

## Enforcement decisions

### EDPB - Binding Decision 1/2026

*Source: EDPB, 2026-05-28 — https://overview.legal/posts/144037 — original: https://gdprhub.eu/index.php?title=EDPB_-_Binding_Decision_1/2026*

Facts — On 10 August 2021, a data subject represented by noyb lodged a complaint with the Austrian DPA against Vlaamse Radio- en Televisieomroeporganisatie (VRT), the controller. The complaint concerned the controller’s cookie banner and alleged infringements of Articles 5(1)(a), 6(1)(a), 12(1), 12(2) and 13(1)(c) GDPR, as well as Article 5(3) ePrivacy Directive. It formed part of a wider project involving similar cookie banner complaints submitted by noyb across the EEA. The Austrian DPA transferred the complaint to the Belgian DPA, which acted as the lead supervisory authority. In its draft decision, the DPA proposed dismissing the complaint without examining its merits. It considered that the data subject and noyb had abused the rights provided under Articles 77 and 80(1) GDPR. The DPA relied on factors including the standardised and partly automated preparation of the complaints, noyb’s role in selecting the targeted controllers, the relationship between the data subject and noyb, and the broader strategic objectives pursued by the organisation. It considered that both the objective and subjective elements required to establish an abuse of rights were present. The Austrian DPA raised a relevant and reasoned objection under Article 60(4) GDPR. It argued that the circumstances did not demonstrate an abuse of rights and requested that the complaint be examined on its merits in accordance with Article 57(1)(f) GDPR. As the DPA did not follow the objection, it referred the dispute to the EDPB under Article 65(1)(a) GDPR. Holding — The EDPB first held that it was competent to decide the dispute. Its powers under Article 65(1)(a) GDPR are not limited to determining whether a controller infringed the GDPR. They also cover disputes concerning whether an action envisaged by a supervisory authority, including the dismissal of a complaint, complies with the GDPR. The EDPB found that the Austrian DPA’s objection met the requirements of Article 4(24) GDPR. The objection was directly connected to the draft decision, proposed a different outcome and sufficiently demonstrated the risks that the dismissal would create for data subjects’ rights and the consistent application of the GDPR. On the merits, the EDPB recalled that the prohibition of abuse of rights must be interpreted strictly, particularly where its application may restrict the fundamental right to data protection and the rights provided by Articles 77 and 80(1) GDPR. The supervisory authority alleging abuse bears the burden of establishing both its objective and subjective elements on the basis of sufficient evidence. Regarding the objective element, the EDPB acknowledged that noyb had organised a project involving predefined selection criteria, standardised complaints and automated tools. However, the data subject had validly mandated noyb under Article 80(1) GDPR and had lodged a complaint concerning an alleged infringement of their own data protection rights. Consequently, the objectives of Articles 77 and 80(1) GDPR had been fulfilled rather than circumvented. Regarding the subjective element, the EDPB found no evidence that the complaint had been submitted to obtain an undue advantage unrelated to the purposes of the GDPR. The objectives pursued by noyb could not be separated from those of the data subject merely because the organisation had played a leading role in preparing the complaint. Nor was there evidence that the data subject or noyb had sought compensation or another financial benefit. The EDPB therefore concluded that the data subject had not abused the right to lodge a complaint under Article 77 GDPR or the right to be represented under Article 80(1) GDPR. It instructed the DPA not to dismiss the complaint on that basis, to assess it on its merits and to submit a new draft decision to the supervisory authorities concerned under Article 60(3) GDPR.

### FUENSANTA S.L.: Insufficient cooperation with supervisory authority

*Source: Spanish Data Protection Authority (aepd), 2021-11-23 — https://overview.legal/posts/47028 — original: https://www.enforcementtracker.com/ETid-913*

The controller failed to provide information requested by the Spanish DPA (AEPD) for investigative purposes.

### Privacy Appeals Board: Datatilsynet may demand information from OpenX under GDPR Art.

*Source: Datatilsynet (Norway), 2020-09-07 — https://overview.legal/posts/122844 — original: https://gdprhub.eu/index.php?title=Datatilsynet_(Norway)-_20/02254*

Facts — The Norwegian Consumer Council (Forbrukerrådet) filed three complaints against the gay/bi dating app Grindr and five adtech companies that received personal data through the app. Subsequently, Datatilsynet sent a request for more information from one of the adtech companies; OpenX. OpenX refused to respond on the basis that Datatilsynet does not have legal grounds to impose such a request on them, because, in their opinion, the issue relates to the Electronic Communications Act § 2(7)(b) (cf. Article 5(3) ePrivacy Directive 2002/58/EC), where the Norwegian Communications Authority is the right supervisory authority (and not Datatilsynet), and filed a complaint to the Privacy Appeals Board. Dispute — Does the Datatilsynet have the legal grounds (as a supervisory authority) to impose a request for information on OpenX? Holding — The Privacy Appeals Board rejected OpenX's complaint as they concluded that Datatilsynet has legal grounds to impose such requests for information as per Article 58(1) GDPR.

### CNPD (Portugal) - Deliberação 2019/494

*Source: CNPD (Portugal), 2019-09-03 — https://overview.legal/posts/122872 — original: https://gdprhub.eu/index.php?title=CNPD_(Portugal)_-_Deliberação_2019/494*

Facts — In its Opinion 20/2018 concerning the draft of Law 58/2019 which ensures the implementation of the GDPR in the portuguese national legal framework, the DPA drew the attention of the national legislator to a set of provisions that could potentially violate EU law, particularly the GDPR. The DPA emphasized the primacy of EU law as outlined in the EU treaties, particularly reflecting on Article 288 of the Treaty on the Functioning of the European Union (TFEU) and reinforced by the jurisprudence of the CJEU, which has consistently stated that national laws cannot obstruct the direct applicability of EU regulations and must comply with EU law to ensure uniform implementation across the Member States. However, Law 58/2019 came into force without incorporating all of the DPA's recommendations. The DPA explains that the decision to not apply some of its provisions aims to ensure legal certainty, reinforcing the importance of consistent GDPR application without being hindered by conflicting national rules. Holding — The DPA has decided to disapply the following provisions of Law 58/2019, in cases of personal data processing under its review due to their conflict with the GDPR: Article 2(1)(2): This article broadens the territorial scope of the GDPR to encompass all personal data processing within national territory and processing linked to national establishments outside the territory. The DPA believes this contradicts Article 3 and Article 56 of the GDPR, which outlines the applicable law in cross-border situations. Additionally, it undermines the one-stop-shop mechanism and fails to address instances where the GDPR applies, such as in Portuguese embassies, consulates, ships, and aircraft. Article 20(1): This article states that the right to be informed and the right of access cannot be exercised when a duty of secrecy is imposed on the data controller/processor. In the view of the DPA, this article lacks legal relevance in relation to the GDPR, as it merely repeats provisions already present in the GDPR, particularly concerning the possibility of restricting the data subject's right to information in cases where data collection is indirect and a legal duty of confidentiality exists. Regarding the possibility of restricting the right to information when collecting data directly from the data subject, this right can only be restricted under the provisions of Article 23 GDPR, and Law58/2019 does not meet the requirements therein, thus contradicting the norms of the GDPR and the Charter of Fundamental Rights. Article 23: This article allows public authorities to reuse personal data for any public interest without ensuring compliance with principles of purpose limitation and data minimization (Article 5 GDPR) and could lead to potential misuse of personal data and a violation of individuals’ rights, as it does not ensure that the reuse of data serves the original purpose for which it was collected nor respecting the requirements imposed in Article 23 GDPR. Article 28(3)(a): The employee's consent cannot be the legal basis if the processing results in a legal or economic advantage for the employee. The Portuguese DPA considers it to be a contraction of the doctrine established by European institutions, which accepts employee consent in situations where the act of giving or refusing consent does not, in itself, have negative consequences for the employee. The DPA therefore believes that this provision does not protect the dignity, fundamental rights, and legitimate interests of employees, and thus fails to meet the requirements set forth in Article 9 (2) (b) and Article 88 GDPR. Regime of Administrative Offenses – Articles 37, 38, and 39: The DPA notes that some of the violations outlined in the law contradict the exhaustive list provided in the GDPR (Article 83). The DPA also criticizes the distinction in sanctioning frameworks based on the size of companies and the collective or individual nature of the entities conducting data processing, as the impact on personal data does not depend on those characteristics but rather on the nature of the activity being carried out. Article 61(2) states that "if the expiration of consent is the reason for terminating a contract in which the data subject is a party, the processing of data is lawful until this occurs." The DPA notes that this provision is incongruent, conflating two types of legal basis: consent and contract execution. The contract in which the data subject is a party is sufficient to justify the processing of the data necessary for its execution. Regarding the reasons that led to publish this decision, the Portuguese DPA clarifies that it did so in order to ensure the transparency of its future decision-making processes and, in this regard, contribute to legal certainty and security. It also clarifies that the non-application, in future specific cases, of the legal provisions listed above results in the direct application of the GDPR provisions that were manifestly restricted, contradicted, or compromised in their useful effect.

### Italian DPA: AgID's automatic transfer of PEC addresses to INAD index unlawful

*Source: Garante per la protezione dei dati personali (Italy), 2026-05-28 — https://overview.legal/posts/122875 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_419/2026*

Facts — The data controller for the case is a government body called the Agency for Digital Italy (AgID). AgID is tasked with driving the adoption of digital technologies in both government and the private sector. Additionally, AgID is Italy’s soon-to-be notification authority for the AI Act. The case revolves around two public online indexes of certified email addresses: the INI-PEC and the INAD. INI-PEC is the older of the two indexes and includes, among others, the email addressess of professionals (the data subjects). INAD was created by AgID in 2023 as provided by Italian law and functions as an index of “digital domiciles” (where data subjects are supposed to get certain important communications) for both professionals and other owners of a digital email address. Shortly after setting up the INAD index, AgID automatically included the addresses of professionals from the old INI-PEC index. As a result, the addresses automatically became the digital domicile for communications not related to the professional lives of the data subjects. Data subjects were given the option to opt-out of the inclusion in the INAD index. Some data subjects complained that this processing severely infringed on their privacy. As the DPA’s decision explains, it is not uncommon for professionals to give co-workers access to their professional email addresses, on the assumption that they will only be used for strictly professional communications. When the addressess became digital domiciles, third parties (such as public bodies) started using them for communications unrelated to the data subjects' personal lives - which occasionally led to unintended data disclosures. The data subjects also claimed that the controller had not informed them about the processing, which prevented them from opting out in a timely fashion. Holding — The investigation — On the duty of information — First of all, the DPA clarified that by including email addresses in the INAD index, the controller further processed personal data for a new purpose, incompatible with the original purpose of the processing (i.e.: the inclusion of email addresses in the older index). With regards to the duty of information, the controller pointed out that it contacted professional orders to inform them about the creation of the INAD index. In the context of these communications, the controller asked professional orders to inform the data subjects about this processing of personal data and about their right to opt out. The controller stated that it did not directly contact the data subjects via their email addresses, as it feared that its emails would have been mistaken as phishing or scams . The controller later launched a more effective information campaign with the help of other government bodies; however, this campaign only took place in 2025 - two years after addresses where included in the INAD index. On the controller’s identity — The DPA’s investigation also focused on a second issue, relative to the authentication procedure for digital domiciles: for a long time, a company (InfoCamere S.c.p.a.) was erroneously listed as a service provider for the INAD index. During the investigation, the controller confirmed that InfoCamere had no role in the processing of personal data. The controller also stated that it had contacted the actual service provider in order to correct the error and that the provider had done so with great delay. The DPA's conclusion — The DPA held that until 2025, the controller had failed to inform the data subjects about the inclusion of their email address in the INAD index, in violation of Articles 5(1)(a), 5(1)(b), 5(2), 12, 14 and 25 GDPR. On these grounds, the DPA fined the controller €55,000. With regards to the erroneous indication of the service provider in the authentication screen, the DPA found that the mistake was isolated and that overall, the information provided during the procedure was still sufficient to clarify that AgID was the controller. On these grounds, the DPA found that the mistake did not, in and of itself, constitute a violation of the GDPR.

### BLUE TEAM FLIGHT SCHOOL, S.L.: Insufficient cooperation with supervisory authority

*Source: Spanish Data Protection Authority (aepd), 2025-12-20 — https://overview.legal/posts/51498 — original: https://www.enforcementtracker.com/ETid-2987*

The Spanish DPA has imposed a fine of EUR 6,000 on BLUE TEAM FLIGHT SCHOOL, S.L. The controller failed to react to requests made by the DPA.

### SPAIN DPA: Insufficient cooperation with supervisory authority

*Source: Spanish Data Protection Authority (aepd), 2025-12-20 — https://overview.legal/posts/51497 — original: https://www.enforcementtracker.com/ETid-2986*

The Spanish DPA has imposed a fine of EUR 300 on an unkonwn person/entity. The controller failed to react to requests made by the DPA.

### Entrepreneur: Insufficient cooperation with supervisory authority

*Source: Polish National Personal Data Protection Office (UODO), 2025-07-28 — https://overview.legal/posts/48879 — original: https://www.enforcementtracker.com/ETid-2764*

The Polish DPA has imposed a fine of EUR 4,400 on an Entrepreneur. The controller failed to adequatly react to a request from the DPA.

## Recent developments

### Data Protection Day: 5 misconceptions about data protection, debunked

*Source: noyb - European Center for Digital Rights, 2026-01-28 — https://overview.legal/posts/52486 — original: https://noyb.eu/en/data-protection-day-5-misconceptions-about-data-protection-debunked*

Ever since the GDPR (General Data Protection Regulation) came into force in 2018, people in the European Union have stronger privacy and data protection. However, the law is far from perfect – and big tech companies, industry lawyers and lobbyists made sure to use every tool in their arsenal to either circumvent GDPR provisions (by misinterpretation) or to influence the public opinion about the law so that consumer don’t blame them for violations, but the GDPR itself. Over the past few years, th

### ‘Pay or Okay’ study: Users prefer a tracking-free “third option”

*Source: noyb - European Center for Digital Rights, 2025-12-04 — https://overview.legal/posts/49178 — original: https://noyb.eu/en/pay-or-okay-study-users-prefer-tracking-free-third-option*

Cookie Banners So-called ‘Pay or Okay’ systems are on the rise in Europe. Instead of giving users a choice to either accept or reject ad tracking, Pay or Okay systems require a payment if you want to refuse to give your “consent”. This nudges 99.9% of users to consent, even if they actually don’t want to do so. Given the upcoming guidelines by the European Data Protection Board on this highly controversial approach, noyb has commissioned a study about user choices. Download the user study on Pay

### EU pledged to improve GDPR cooperation - and made it worse

*Source: noyb - European Center for Digital Rights, 2025-04-17 — https://overview.legal/posts/53157 — original: https://noyb.eu/en/eu-pledged-improve-gdpr-cooperation-and-made-it-worse*

National Administrative Procedures and DPA inactivity As of 2018, the GDPR is supposed to ensure that Europeans enjoy privacy rights throughout the entire EU. However, when people's rights are violated by companies based in another EU/EEA Member State, complaints are dealt with through a complex "cooperation mechanism" between the Data Protection Authority (DPA) in the users' Member State and the DPA in the company's Member State. This enforcement mechanism is at the core of the generally acknow

### Europese Commissie presenteert nieuwe regels om seksueel misbruik van kinderen op internet te voorkomen en te bestrijden

*Source: NL EU Court Expert, 2022-05-13 — https://overview.legal/posts/6305 — original: https://ecer.minbuza.nl/-/europese-commissie-presenteert-nieuwe-regels-om-seksueel-misbruik-van-kinderen-op-internet-te-voorkomen-en-te-bestrijden?redirect=%2Fecer%2Fnieuws%3Fq%3Dprivacy%2520OR%2520avg%26f%3D%26t%3D#entry-304*

The proposed rules would require online service providers to detect, report and remove child sexual abuse material on their services. Those providers must also assess the risk of their services being used to distribute child sexual abuse material. A new European Center on Child Sexual Abuse will provide support to providers, law enforcement and victims.

### Mensenrechtenorganisaties bekritiseren de geautomatiseerde gegevensuitwisseling voor de samenwerking tussen de politie (voorstel Prüm II).

*Source: eucrim, 2022-10-05 — https://overview.legal/posts/51798*

Het netwerk European Digital Rights (EDRi) heeft een position paper gepubliceerd over het voorgestelde Europees regelgevend kader voor geautomatiseerde gegevensuitwisseling ter bevordering van de samenwerking tussen politie, bekend als "Prüm II". Dit omvat momenteel voornamelijk een netwerk voor gegevensuitwisseling (waarbij nationale DNA-databases, vingerafdrukken en voertuigregistraties met elkaar worden verbonden). Het voorziet in een uitbreiding van dit netwerk, waarbij gezichtsherkenningstechnologie wordt toegevoegd en, op vrijwillige basis, "politiedossiers".

Het position paper werpt verschillende belangrijke vragen op over...

## Literature

### The EU Law Enforcement Directive (LED): A commentary

*Source: Journal of Data Protection Privacy, 2025-06-01 — https://overview.legal/posts/132428 — original: https://doi.org/10.69554/tnfi3768*

### European Union · Proceduralising GDPR Enforcement: How Complexity May Undermine Effective Cross-Border Data Protection

*Source: European Data Protection Law Review, 2026-01-01 — https://overview.legal/posts/132459 — original: https://doi.org/10.21552/edpl/2025/4/13*

### Collective Damages for GDPR Breaches: A Feasible solution for the GDPR Enforcement Deficit?

*Source: European Data Protection Law Review, 2022-01-01 — https://overview.legal/posts/132504 — original: https://doi.org/10.21552/edpl/2022/4/8*

### GDPR Implementation Series ∙ Malta: An Overview of the GDPR Implementation

*Source: European Data Protection Law Review, 2020-01-01 — https://overview.legal/posts/132480 — original: https://doi.org/10.21552/edpl/2020/4/15*

### European Union ∙ Article 29 Data Protection Working Party Opinion on the Law Enforcement Directive

*Source: European Data Protection Law Review, 2018-01-01 — https://overview.legal/posts/132458 — original: https://doi.org/10.21552/edpl/2018/1/15*

## Tools

### European Commission adequacy decisions

*Source: European Commission, 2026-07-17 — https://overview.legal/posts/125629 — original: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en*

The authoritative list of third countries the European Commission has recognised as providing adequate protection under Article 45 GDPR (and its LED equivalent), with links to each adequacy decision and its review status — the first stop for any transfer analysis.

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Processing Agreement** — https://overview.legal/topics/verwerkersovereenkomst
  Contract between controller and processor defining processing terms
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Data Controller** — https://overview.legal/topics/verwerkingsverantwoordelijke
  The entity that determines purposes and means of processing personal data

---
Generated by overview.legal · https://overview.legal/topics/law-enforcement · 2026-08-22
