# Marketing — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/marketing
> Sources are cited per item. Verify against the official texts before relying on them.

Use of personal data for marketing and advertising purposes

## Overview

## Legal Framework

Marketing under the GDPR is governed primarily by Article 6(1) (lawfulness of processing), [Article 13](/laws/gdpr/art-13) and [Article 14](/laws/gdpr/art-14) (transparency obligations), and Article 21 (right to object). The definitional scope of marketing-related processing — particularly profiling — is set out in [Article 4](/laws/gdpr/art-4):

Controllers relying on legitimate interests under Article 6(1)(f) must disclose those interests to data subjects under [Article 13(1)(d)](/laws/gdpr/art-13) (data collected from the subject) or [Article 14(2)(b)](/laws/gdpr/art-14) (data obtained indirectly). Where personal data are not collected from the data subject, Article 14 imposes additional information duties, including the source of the data. The right of access under [Article 15(1)(h)](/laws/gdpr/art-15#par-1-pnt-h) requires controllers to inform data subjects about automated decision-making, including profiling, and to provide meaningful information about the logic involved.

## Key Developments

The CJEU's January 2025 judgment in *Mousse* (C-394/23) confirms that direct marketing can rest on legitimate interests under Article 6(1)(f), but sets a contextual boundary grounded in data minimisation and reasonable expectations:

> "the processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest. In particular, personalised advertising may be equated with direct commercial marketing in such a context"
> — [CJEU, Mousse, ¶54](/posts/50377#seg-54)

The Court further narrowed the scope by holding that collecting data fields unnecessary for the transaction — such as title or gender identity when purchasing a travel document — falls outside what a consumer reasonably expects, particularly where the data serve only marketing goals. The right to object under Article 21(1) provides a backstop: once invoked, the controller must cease processing unless it demonstrates compelling legitimate grounds.

On the consent side, the EDPB's Guidelines 05/2020 establish that bundling marketing consent with service delivery is impermissible:

> "If the customer's refusal to consent to this processing purpose would lead to the denial of banking services, closure of the bank account, or, depending on the case, an increase of the fee, consent cannot be freely given."
> — [EDPB Guidelines 05/2020, §33](/posts/38053#seg-33)

## Status of the Debate

This topic is actively contested in court. The boundaries of legitimate interests for marketing are not fully settled: *Mousse* clarifies that reasonable expectation and data minimisation constrain Article 6(1)(f), but national courts continue to grapple with where personalised advertising crosses into profiling requiring consent under Article 22, and how Article 21 objections interact with lookalike-audience and inferred-interest models. No definitive court split is on record yet regarding the threshold at which behavioural advertising becomes profiling with legal or similarly significant effects. A future CJEU reference on that specific question would resolve the open issue.

## Practical Guidance

- **Conduct a legitimate-interest assessment for each marketing purpose.** Document the interest pursued, the necessity test, and the balance against data subject rights — *Mousse* confirms this is not optional for Article 6(1)(f) marketing.
- **Collect only data fields necessary for the transaction.** Gathering supplementary personal data (e.g., gender, title) solely for marketing at the point of sale violates the data minimisation principle and exceeds reasonable consumer expectations.
- **Do not bundle consent with service delivery.** If refusing marketing consent results in denial of service or price penalties, the consent is invalidly obtained.
- **Provide layered transparency.** When data are collected directly, disclose the marketing purpose, the legitimate interest relied upon, and the right to object under Article 21 — all at the point of collection per Article 13.
- **Honour Article 21 objections promptly.** Establish an automated opt-out mechanism that ceases processing without requiring the data subject to justify the objection; the burden of demonstrating compelling grounds shifts to the controller.

## Legislation (full text of key provisions)

### Automated individual decision-making, including profiling

*Source: GDPR, gdpr-art-22-en, 2016-04-27 — https://overview.legal/posts/90485*

### Recommender systems

*Source: DSA, dsa-art-38-en, 2022-10-19 — https://overview.legal/posts/94670*

In addition to the requirements set out in Article 27, providers of very large online platforms and of very large online search engines that use recommender systems shall provide at least one option for each of their recommender systems which is not based on profiling as defined in Article 4, point (4), of Regulation (EU) 2016/679.

### Recital 70 — right to object to direct marketing

*Source: GDPR, gdpr-rec-70-en, 2016-04-27 — https://overview.legal/posts/91655*

Where personal data are processed for the purposes of direct marketing, the data subject should have the right to object to such processing, including profiling to the extent that it is related to such direct marketing, whether with regard to initial or further processing, at any time and free of charge. That right should be explicitly brought to the attention of the data subject and presented clearly and separately from any other information.

### Recital 71 — automated decision making and profiling rights

*Source: GDPR, gdpr-rec-71-en, 2016-04-27 — https://overview.legal/posts/91657*

The data subject should have the right not to be subject to a decision, which may include a measure, evaluating personal aspects relating to him or her which is based solely on automated processing and which produces legal effects concerning him or her or similarly significantly affects him or her, such as automatic refusal of an online credit application or e-recruiting practices without any human intervention. Such processing includes ‘profiling’ that consists of any form of automated processing of personal data evaluating the personal aspects relating to a natural person, in particular to analyse or predict aspects concerning the data subject's performance at work, economic situation, health, personal preferences or interests, reliability or behaviour, location or movements, where it produces legal effects concerning him or her or similarly significantly affects him or her. However, decision-making based on such processing, including profiling, should be allowed where expressly authorised by Union or Member State law to which the controller is subject, including for fraud and tax-evasion monitoring and prevention purposes conducted in accordance with the regulations, standards and recommendations of Union institutions or national oversight bodies and to ensure the security and reliability of a service provided by the controller, or necessary for the entering or performance of a contract between the data subject and a controller, or when the data subject has given his or her explicit consent. In any case, such processing should be subject to suitable safeguards, which should include specific information to the data subject and the right to obtain human intervention, to express his or her point of view, to obtain an explanation of the decision reached after such assessment and to challenge the decision. Such measure should not concern a child. In order to ensure fair and transparent processing in respect of the data subject, taking into account the specific circumstances and context in which the personal data are processed, the controller should use appropriate mathematical or statistical procedures for the profiling, implement technical and organisational measures appropriate to ensure, in particular, that factors which result in inaccuracies in personal data are corrected and the risk of errors is minimised, secure personal data in a manner that takes account of the potential risks involved for the interests and rights of the data subject and that prevents, inter alia, discriminatory effects on natural persons on the basis of racial or ethnic origin, political opinion, religion or beliefs, trade union membership, genetic or health status or sexual orientation, or that result in measures having such an effect. Automated decision-making and profiling based on special categories of personal data should be allowed only under specific conditions.

### Recital 72 — profiling subject to regulation rules

*Source: GDPR, gdpr-rec-72-en, 2016-04-27 — https://overview.legal/posts/91659*

Profiling is subject to the rules of this Regulation governing the processing of personal data, such as the legal grounds for processing or data protection principles. The European Data Protection Board established by this Regulation (the ‘Board’) should be able to issue guidance in that context.

### Recital 30 — online identifiers enabling personal profiling

*Source: GDPR, gdpr-rec-30-en, 2016-04-27 — https://overview.legal/posts/91575*

Natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols, such as internet protocol addresses, cookie identifiers or other identifiers such as radio frequency identification tags. This may leave traces which, in particular when combined with unique identifiers and other information received by the servers, may be used to create profiles of the natural persons and identify them.

### Recital 69 — prohibition of targeted ads using sensitive data

*Source: DSA, dsa-rec-69-en, 2022-10-19 — https://overview.legal/posts/95535*

When recipients of the service are presented with advertisements based on targeting techniques optimised to match their interests and potentially appeal to their vulnerabilities, this can have particularly serious negative effects. In certain cases, manipulative techniques can negatively impact entire groups and amplify societal harms, for example by contributing to disinformation campaigns or by discriminating against certain groups. Online platforms are particularly sensitive environments for such practices and they present a higher societal risk. Consequently, providers of online platforms should not present advertisements based on profiling as defined in Article 4, point (4), of Regulation (EU) 2016/679, using special categories of personal data referred to in Article 9(1) of that Regulation, including by using profiling categories based on those special categories. This prohibition is without prejudice to the obligations applicable to providers of online platforms or any other service provider or advertiser involved in the dissemination of the advertisements under Union law on protection of personal data.

### Recital 47 — legitimate interests as processing legal basis

*Source: GDPR, gdpr-rec-47-en, 2016-04-27 — https://overview.legal/posts/91609*

The legitimate interests of a controller, including those of a controller to which the personal data may be disclosed, or of a third party, may provide a legal basis for processing, provided that the interests or the fundamental rights and freedoms of the data subject are not overriding, taking into consideration the reasonable expectations of data subjects based on their relationship with the controller. Such legitimate interest could exist for example where there is a relevant and appropriate relationship between the data subject and the controller in situations such as where the data subject is a client or in the service of the controller. At any rate the existence of a legitimate interest would need careful assessment including whether a data subject can reasonably expect at the time and in the context of the collection of the personal data that processing for that purpose may take place. The interests and fundamental rights of the data subject could in particular override the interest of the data controller where personal data are processed in circumstances where data subjects do not reasonably expect further processing. Given that it is for the legislator to provide by law for the legal basis for public authorities to process personal data, that legal basis should not apply to the processing by public authorities in the performance of their tasks. The processing of personal data strictly necessary for the purposes of preventing fraud also constitutes a legitimate interest of the data controller concerned. The processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest.

### Recital 95 — very large online platforms advertisement repositories

*Source: DSA, dsa-rec-95-en, 2022-10-19 — https://overview.legal/posts/95587*

Advertising systems used by very large online platforms and very large online search engines pose particular risks and require further public and regulatory supervision on account of their scale and ability to target and reach recipients of the service based on their behaviour within and outside that platform’s or search engine's online interface. Very large online platforms or very large online search engines should ensure public access to repositories of advertisements presented on their online interfaces to facilitate supervision and research into emerging risks brought about by the distribution of advertising online, for example in relation to illegal advertisements or manipulative techniques and disinformation with a real and foreseeable negative impact on public health, public security, civil discourse, political participation and equality. Repositories should include the content of advertisements, including the name of the product, service or brand and the subject matter of the advertisement, and related data on the advertiser, and, if different, the natural or legal person who paid for the advertisement, and the delivery of the advertisement, in particular where targeted advertising is concerned. This information should include both information about targeting criteria and delivery criteria, in particular when advertisements are delivered to persons in vulnerable situations, such as minors.

### Recital 10 — personal data protection safeguarding

*Source: AI Act, aiact-rec-10-en, 2024-06-12 — https://overview.legal/posts/93702*

The fundamental right to the protection of personal data is safeguarded in particular by Regulations (EU) 2016/679 (11) and (EU) 2018/1725 (12) of the European Parliament and of the Council and Directive (EU) 2016/680 of the European Parliament and of the Council (13). Directive 2002/58/EC of the European Parliament and of the Council (14) additionally protects private life and the confidentiality of communications, including by way of providing conditions for any storing of personal and non-personal data in, and access from, terminal equipment. Those Union legal acts provide the basis for sustainable and responsible data processing, including where data sets include a mix of personal and non-personal data. This Regulation does not seek to affect the application of existing Union law governing the processing of personal data, including the tasks and powers of the independent supervisory authorities competent to monitor compliance with those instruments. It also does not affect the obligations of providers and deployers of AI systems in their role as data controllers or processors stemming from Union or national law on the protection of personal data in so far as the design, the development or the use of AI systems involves the processing of personal data. It is also appropriate to clarify that data subjects continue to enjoy all the rights and guarantees awarded to them by such Union law, including the rights related to solely automated individual decision-making, including profiling. Harmonised rules for the placing on the market, the putting into service and the use of AI systems established under this Regulation should facilitate the effective implementation and enable the exercise of the data subjects’ rights and other remedies guaranteed under Union law on the protection of personal data and of other fundamental rights.

## Case law

### VG München - M 26a K 25.5210

*Source: Administrative Court Munich, 2026-05-18 — https://overview.legal/posts/108991 — original: https://gdprhub.eu/index.php?title=VG_München_-_M_26a_K_25.5210*

Facts — The data subject had been liable to pay broadcasting contributions to the Controller, a German regional public broadcasting authority, since 2007. Following objections to several contribution assessment notices, the data subject submitted a request under Article 15 GDPR seeking a copy of all personal data processed about him by the Controller. The Controller responded by providing the categories of personal data and related information specified under § 11(8) of the German Broadcasting Contribution Treaty (RBStV), which governs data subject access requests relating to broadcasting contribution records, together with general privacy information. The data subject argued that the response was incomplete because it did not include copies of all documents containing his personal data, including correspondence with him and third parties. The Controller maintained that it had fully complied with its obligations under the RBStV. After the Controller declined to provide additional information, the data subject brought proceedings seeking disclosure of all personal data concerning him processed by the Controller. Holding — The Court held that § 11(8) of the German Broadcasting Contribution Treaty (RBStV) constituted a lawful restriction of the broader right of access under Article 15 GDPR pursuant to Article 23(1)(e) GDPR. It found that the national provision was a valid legislative measure, respected the essence of the fundamental right to data protection, and pursued an important public interest by ensuring the effective financing and administration of the public broadcasting system. The Court further held that the restriction was necessary and proportionate, noting that requiring the Controller to comply with the full scope of Article 15 GDPR across more than 44 million broadcasting contribution accounts would impose a disproportionate administrative and financial burden capable of undermining that public interest. The Court also held that § 11(8) RBStV satisfied the safeguards required under Article 23(2) GDPR by specifying the purposes of processing, categories of personal data, scope of the restriction, safeguards against misuse and unlawful access, the identity of the Controller, applicable storage periods and other statutory protections. Accordingly, while the Controller was required to disclose the categories of information specified under § 11(8) RBStV, it was not required to provide a copy of all personal data processed under Article 15(3) GDPR. As the Controller had already provided all information required under the national provision, the court dismissed the action.

### French Supreme Court upholds €8M CNIL fine against Apple for App Store ad tracking

*Source: Supreme Administrative Court, 2025-10-10 — https://overview.legal/posts/122852 — original: https://gdprhub.eu/index.php?title=CE_-_473833*

Facts — The DPA imposed an €8 million administrative fine on Apple (the controller) in 2022 (CNIL - SAN-2022-025). The DPA found that Apple used identifiers stored on users’ devices to enable personalized advertising in the App Store without first obtaining valid user consent, as required by Article 82 of the French Data Protection Act, which implements Article 5(3) of the ePrivacy Directive. Apple challenged the sanction before the Supreme Administrative Court (Conseil d’État), arguing that the DPA lacked jurisdiction, that the investigation violated Apple’s procedural rights, that the advertising-related processing did not fall within the scope of Article 82, and that the case should be referred to the Court of Justice of the EU. Apple also claimed that the fine was disproportionate. Holding — The court held that reading identifiers stored on user devices for the purpose of delivering personalised advertising constitutes access to information under Article 5(3) of the ePrivacy Directive, requiring the controller to obtain the user’s prior consent. It reasoned that since this operation was to implement personalized advertising it could not fall within the exemptions to the consent requirement. The court found that the national authority was competent because the controller’s establishment within the country contributed to the advertising operations in question. It did so by marketing devices pre-equipped with the App Store where personalized advertising appears and by providing Search Ads Specialists who helped monetize and optimize that advertising space. It also rejected the controller’s claim that the authority had violated its procedural rights, finding that the right to remain silent did not apply during CNIL investigations and that the authority had lawfully carried out the investigation providing sufficient opportunity for the controller to respond. Additionally, the court rejected Apple's request to reference the case to the Court of Justice of the EU stating that there wasn't any reasonable doubt Finally, it held that the €8 million fine was proportionate, noting the scale of the processing, the number of affected users, and the economic significance of the advertising activity.

### Judgment of the Court (First Chamber) of 27 February 2025.#CK v Magistrat der Stadt Wien.#Request for a preliminary ruling from the Verwaltungsgericht Wien.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 15(1)(h) – Automated decision-making, including profiling – Scoring – Assessment of the creditworthiness of a natural person – Access to meaningful information about the logic involved in profiling – Verification of the accuracy of the infor

*Source: Court of Justice of the European Union, C-203/22, 2025-02-27 — https://overview.legal/posts/132146 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0203*

In Case C-203/22, the Court of Justice of the European Union interpreted Article 15(1)(h) of the GDPR in response to a preliminary ruling from the Verwaltungsgericht Wien concerning an individual's request for meaningful information about the logic of creditworthiness scoring conducted by Dun & Bradstreet Austria GmbH. The Court held that data subjects must receive sufficiently detailed explanations of the logic involved in automated profiling to understand how the decision was reached, while controllers may withhold information protected by trade secrets under Directive (EU) 2016/943 only insofar as such withholding does not render the information provided meaningless. The Court further clarified that data subjects may not use access rights to obtain personal data of third parties or to verify the absolute accuracy of the underlying information processed.

### Judgment of the Court (First Chamber) of 7 December 2023.#OQ v Land Hessen.#Request for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 22 – Automated individual decision-making – Credit information agencies – Automated establishment of a probability value concerning the ability of a person to meet payment commitments in the future (‘s

*Source: Court of Justice of the European Union, C-634/21, 2023-12-07 — https://overview.legal/posts/132279 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0634*

In Case C-634/21, the CJEU addressed a preliminary ruling from the Verwaltungsgericht Wiesbaden concerning OQ's challenge against Land Hessen's refusal to order SCHUFA Holding AG to grant access to and erase personal data, including a credit score. The core issue was whether the automated calculation of a probability value ("scoring") by a credit information agency regarding a person's future ability to meet payment commitments constitutes an automated individual decision-making under Article 22(1) of the GDPR when third parties use that score for their own decisions. The Court held that such scoring does not itself amount to a decision producing legal effects under Article 22(1), as it is the third party, not the credit agency, that makes the decision based on the score.

### BVwG - W256 2227693-1

*Source: Federal Administrative Court, 2023-09-28 — https://overview.legal/posts/125664 — original: https://gdprhub.eu/index.php?title=BVwG_-_W256_2227693-1*

Facts — On 05.09.2019, the Austrian DPA (DSB) notified the controller of a customer loyalty program that they were initiating an ex officio investigation. The controller responded by answering the provided questionnaire and submitting further documents. On 23.10.2019, the DPA ruled that the investigation was justified and that the declaration of consent for profiling using certain registration methods (website, app, partner company store, flyer) did not comply with the requirements of Article 4(11) GDPR and Article 7 GDPR, nor were they provided in an intelligible way. If a contract covers several aspects, the declaration of consent must be clearly distinguishable. Regarding the website and flyer, the following was found: The website says 'Enjoy your personal benefits' without providing clear information that 'personal benefits' involves profiling. In an embedded box, the relevant points were merely referred to. Information regarding profiling was only accessible by scrolling down further. Concerning the flyer, the following information was provided under the signature field: 'This signature only applies to the declaration of consent and is voluntary. Your registration [...] is also valid without a signature.' Thus, it conveyed the impression that a signature was required to confirm the registration. Consequently, the controller was required to amend the declaration and to cease using any obtained consents for the purpose of profiling prior to 01.05.2020. The controller lodged a complaint. In addition to other information, the controller stated that the data processing was in accordance with Article 6(1)(a) GDPR, and that they had a legitimate interest under Article 6(1)(f) GDPR. The DPA ruled a preliminary decision on the complaint, thereby changing the ruling that the website and flyer did not meet the requirements under Article 6(1)(a) GDPR, and thus, the processing of personal data, collected in that cases, was forbidden. The other methods ensured that the consent was clearly separated from the rest of the registration process. The controller then filed a request for referral to the court, arguing that the DPA had exceeded their corrective powers by prohibiting the processing of the data. Furthermore, the data processing for profiling would be used to manage customer memberships under Article 6(1)(b) GDPR. Following their view, processing under Article 6(4) GDPR was applicable. Additionally, the controller denied the DPA's view that a violation of the principle of good faith would foreclose a weighing of interests under Article 6(1)(f) GDPR. The court quashed the preliminary decision as the DPA had not examined the other grounds of justification for data processing under Article 6(1) GDPR in their initial decision. The DPA then lodged an appeal to the Austrian Supreme Administrative Court (Verwaltungsgerichtshof), which overturned the court's ruling (VwGH 08.02.2022, Ro 2021/04/0033). It was the court's responsibility to examine the potential legal bases, rather than overturning the DPA's decision. Therefore, the case was returned to the court. In the meantime, the controller complied with the preliminary decision by deleting the affected personal data in 2021 and changing their registration process in 2020. Holding — First, the court found that they had to formally rule on whether the DPA's decision was lawful at the time it was ruled. It is not to be considered that the controller complied with the administrative decision and fulfilled the required steps (VwGH 28.04.2022, Ra 2022/06/0056). Second, the court held that the controller did not comply with the transparency requirements regarding the layout of their declaration of consent under Article 7(2) GDPR in both cases (website, flyer). Third, the court ruled that they could not agree with DPA's view, that an invalid declaration of consent always constitutes unlawful data processing and that a review of other grounds of justification would not be necessary (CLEU in 'Meta Platforms and Others' (C-252/21) ECLI:EU:C:2023:537). Further on, the Supreme Administrative Court ruled that both, the DPA and the court are required to examine the presence of other grounds (VwGH 08.02.2022, Ro 2021/04/0033). Fourth, the court held that the controller could not base their appeal on Article 6(4) GDPR as the data processing did not satisfy the grounds of justification, nor were other grounds apparent. Inter alia, following the CLEU's preliminary ruling in 'Meta Platforms and Others' (C-252/21) ECLI:EU:C:2023:537, three cumulative requirements must be met for data processing under Article 6(1)(f) GDPR: (1) The controller or a third party must have a legitimate interest, (2) which requires the processing of that personal data, (3) and 'the fundamental rights and freedoms of the data subject' must not outweigh those interests. There were no doubts about the controller's legitimate interest in processing the personal data in question for targeted marketing purposes, as this was both necessary and reasonable. However, the data subject should have been notified about profiling. The wording 'only if the member consents' did not constitute such a notification, and therefore the data subjects were not to be expected that their personal data was used for profiling purposes. Furthermore, the controller explicitly excluded it in their general terms and conditions. Hence, the data subject's right to secrecy overrode the controller's legitimate interest. In summary, the court dismissed the controller's complaint. Last, the court held that an appeal to the Supreme Administrative Court was admissible under Article 133(4) B-VG, as no prevailing case law concerning the implementation of a declaration of consent existed. Hence, the decision relied on a legal question of fundamental importance.

### BVwG - W258 2227269-1/39E

*Source: Federal Administrative Court, 2024-12-27 — https://overview.legal/posts/184564 — original: https://gdprhub.eu/index.php?title=BVwG_-_W258_2227269-1/39E*

Facts — On the 8 January 2019, the Austrian DPA (Datenschutzbehörde – DSB) launched an investigation into the actions of the Austrian postal service as it also had a business license for address publishing and direct marketing. Media reports had claimed that the postal service (the controller) sold data concerning the political affinities of data subjects to third parties. The controller ran a platform entitled “Adress Shop” on which it sold personal data to legal entities. The datasets included names and addresses but more importantly it included data subjects’ affinities to certain things such as an affinity to moving house, an affinity to organic products or how frequently a data subject receives packages. The purpose of the data processing was to sell this data to third parties who would use it for marketing purposes and therefore could avoid scattering losses. In order to create this database, the controller abused its position as postal service provider. In the postal service contract provided to data subjects the controller had included a notice stating that data subject are agreeing to their personal data being processed for marketing purposes. The contract however also included a box which could be ticked in order to refuse the data processing for marketing purposes. One of these affinities was concluded through an affinity score concerning the main political parties in Austria. For example, data subjects would be assessed with either a “very low”, “low”, “high” or “very high” affinity towards the SPÖ (the Socialist Party of Austria), the ÖVP (the Conservative Party of Austria) or any other major political party. The controller calculated this score through combing anonymous survey results, socio-demographic data (e.g., age or level of income and education) and voting results of particular region. On the 20 Febuary 2019, the DSB alleged that the controller had unlawfully processed sensitive data under Article 9 GDPR. The DSB found that the controller could not rely on a legal basis for the processing of this data and that the controller had sold the data to third parties. The DSB issued a fine of fine of €18,000,000 for the processing of sensitive data and other violations. The full details can be found here. On the 25 November 2019, the controller appealed the decision of the DSB to the Austrian Federal Administrative Court (Bundesverwaltungsgericht – BVwG) and alleged that the DSB had inadequately assessed the situation. On the 26 November, the BVwG annulled the decision of the DSB stating that the DSB had failed to name a natural person to whom the actions of the controller could be attributed to. Based on an Austrian provision, namely paragraph 45(1)(3) of the Administrative Penal Code (Verwaltungsstrafgesetz - VStG), in order to fine a legal person for a violation of the GDPR all necessary requirements for the penalization of a natural person must be fulfilled. This finding was however annulled by the Supreme Administrative Court (Verwaltungsgerichtshof – VwGH) on the 1 February 2024. The VwGH explained that although the BVwG correctly applied the national provision, the CJEU case C-807/21 Deutsche Wohnen showed that Article 58(2)(i) GDPR and Article 83 GDPR are excluded from national derogations. Therefore, the BVwG should not have applied the national provision. The case was therefore reverted back to the BVwG. Holding — The BVwG reassessed the case and partly upheld the DSB decision but made the following alterations. Article 9 GDPR data related to political affinities The BVwG confirmed that the controller had at no point in time obtained the consent of the data subject and therefore was processing data in violation of Article 9(1) GDPR since the 25 May 2018. The BVwG held that the controller's conduct had proved negligent. The BVwG noted that the controller had made efforts to apply the GDPR correctly but criticized for example that the DPO had to monitor all processing activities which did not prove an effective monitoring and controlling system as it would require too much time for just one person. The BVwG held that it was clearly unacceptable that the DPO thought that the data processed did not constitute personal data, especially when it was explicitly connected to an individual person. Further, The BVwG found that the controller never conducted an assessment on whether certain affinities could constitute sensitive data under Article 9 GDPR. The BVwG classified this as grossly negligent behaviour on the part of the controller. The BVwG concluded that the controller should have consulted an external expert around the uncertainties it had concerning the correct application of the GDPR. Affinity towards receiving packages In relation to the data processed to assess their affinity for receiving packages, the controller was in a privileged position to have access to the relevant data. However, it then further processed this data contrary to their legal mandate for creating projection models for marketing purposes in violation of Article 6(4) GDPR. The court also held that this violated the principles of fairness and transparency under Article 5(1)(a) GDPR. The BVwG highlighted that the controller knew that its positions as postal service provider and data broker is likely to cause issues, therefore its behaviour was classified as negligent. Affinity towards moving house Assessing whether data subjects were likely to move house differed to the assessment of an affinity towards receiving packages as there was a contractual relationship between the data subject and the controller due to contractual redirection orders. The BVwG assessed that the minimal information provided to data subjects on the processing for marketing purposes, proved to be just about enough as the personal data was made up of a calculation of averages which was then anonymized. The court found that this could be classified as processing which, based on the controllers description, could be expected from the notice included in the contract. In addition, data subjects could easily refuse the data processing. Data Protection Impact Assessment The controller had processed an extensive amount of sensitive data which requires a data protection impact assessment. The controller’s assessment that this data processing was of low risk was therefore faulty. The controller had therefore violated Article 35(3)(b) GDPR and Article 35(7) GDPR. The BVwG held that as the controller had negligently categorized its processing as not concerning any sensitive data, it consequently also proves to have acted negligently in assessing the risks under Article 35 GDPR. The BVwG rejected the controller’s argument that penalization under Article 35 GDPR would result in a double punishment for the same offence. It explained that the general obligations under the GDPR pursue a different aim to the provisions governing lawfulness of the processing. Further, the DPIA is to be conducted prior to processing. Records of processing The faulty and therefore inadequate DPIA resulted in a violation of Article 30(1)(c) GDPR, which requires the records of data processing to include the categories of data processed. The BVwG again assessed that the controller had acted negligently in relation to this aftereffect of its faulty categorization of the processed data. The controller had merely stated that the data would be processed for marketing purposes and this was held to have been inadequate as the controller processed data such as the political affinities. The BVwG held that the controller had failed to provide a full description of all the processed categories. Fine The BVwG reduced the fine to €16 million mainly based on the controller's low annual turnover. Further, the BVwG noted that the political data had only been sold to two political parties which resulted in a limited amount of data subjects being affected.

### Judgment of the Court (First Chamber) of 13 November 2025.#Inteligo Media SA v Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP).#Request for a preliminary ruling from the Curtea de Apel Bucureşti.#Reference for a preliminary ruling – Processing of personal data and the protection of privacy in the electronic communications sector – Directive 2002/58/EC – Article 13(1) and (2) – Unsolicited communications – Concept of communication ‘for the purposes of di

*Source: Court of Justice of the European Union, C-654/23, 2025-11-13 — https://overview.legal/posts/132132 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0654*

The Court of Justice of the European Union ruled on a preliminary reference from the Romanian Curtea de Apel Bucureşti in proceedings between Inteligo Media SA and the Romanian DPA (ANSPDCP) concerning the scope of "direct marketing" and the customer-relationship exception under Article 13 of the ePrivacy Directive (Directive 2002/58/EC) in relation to GDPR Article 6. The case addressed whether a daily newsletter sent to users who registered on an online platform to access additional content qualifies as a communication "for the purposes of direct marketing" and whether the platform registration constitutes obtaining contact details "in the context of the sale of a product or a service" under Article 13(2). The Court's ruling clarifies the interplay between the ePrivacy Directive's specific consent regime for unsolicited communications and the GDPR's general lawfulness requirements, with the underlying national proceedings involving an administrative penalty imposed by ANSPDCP for processing customers' personal data without consent.

### HvJ EU 9 januari 2025, C‑394/23 (Mousse).

*Source: CJEU, 2025-01-09 — https://overview.legal/posts/50377 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0394*

HvJ EU 9 januari 2025, C‑394/23 (Mousse). Artikelen: 5(1)(c), 6(1), en 21 AVG Onderwerp : Beginsel van minimale gegevensverwerking Gek genoeg verwijst het HvJ EU zelf niet naar HvJ EU 1 augustus 2022, C‑184/20 (Vyriausioji tarnybinės etikos komisija), maar dat had hier ook heel logisch geweest.

### Judgment of the Court (Fourth Chamber) of 4 October 2024.#Maximilian Schrems v Meta Platforms Ireland Limited.#Request for a preliminary ruling from the Oberster Gerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Online social networks – General terms of use relating to contracts concluded between a digital platform and a user – Personalised advertising – Article 5(1)(b) – Principle of purpos

*Source: Court of Justice of the European Union, C-446/21, 2024-10-04 — https://overview.legal/posts/132159 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0446*

In a preliminary ruling arising from proceedings between Maximilian Schrems and Meta Platforms Ireland Limited, the Court of Justice of the European Union interpreted GDPR Articles 5(1)(b), 5(1)(c), 6(1), and 9 concerning the lawfulness of processing user personal data for personalised advertising on online social networks. The Court addressed whether such processing can be deemed compatible with the original purpose of data collection under a platform's terms of use, the applicability of the data minimisation principle, and the conditions under which special categories of personal data, including data concerning sexual orientation made public by the data subject, may be processed. No fine was imposed, as the ruling provides interpretative guidance to the Austrian Supreme Court for resolution of the underlying dispute.

### BVwG - W211 2230221-1

*Source: BVwG, 2021-09-03 — https://overview.legal/posts/158457 — original: https://gdprhub.eu/index.php?title=BVwG_-_W211_2230221-1*

Facts — The data subject filed a complaint with the Austrian Data Protection Authority (DSB) against the controller, requesting to be provided with recipients to whom the personal data had been shared under Article 15(1)(c) GDPR, rather than mere categories of recipients. The controller refused, arguing that a controller has a right to choose whether to provide a data subject with information on actual data recipients or rather just categories thereof. Further, the controller argued that the disclosure of actual data recipients would reveal its trade secrets. The DSB upheld the data subject's complaint and ordered the controller to provide the data subject with information on the actual data recipients. The controller filed an appeal against that decision with the Austrian Federal Administrative Court (BVwG), repeating its arguments brought forward before the DSB. Holding — The BVwG did not (yet) take a decision on the merit of the case but stalled the procedure because the Austrian Supreme Court (OGH) had already filed a request for preliminary ruling on the question the interpretation of Article 15(1)(c) GDPR in February 2021. Once the CJEU has passed its judgment on the matter, the BVwG will reopen the case.

### Meta Platforms v noyb

*Source: CJEU, C-252/21, 2023-01-12 — https://overview.legal/posts/51484 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0252*

GDPR consent requirements and lead supervisory authority mechanism.

### Trib. of Bologna - RG 12124/2020

*Source: Tribunal of Bologna, 2022-07-30 — https://overview.legal/posts/125653 — original: https://gdprhub.eu/index.php?title=Trib._of_Bologna_-_RG_12124/2020*

Facts — A data subject made an access request to Comet s.p.a., the controller, to verify the lawfulness of the processing of her personal data for marketing purposes. In particular, she requested the information provided for in Article 15(1)(a) and (h) GDPR, and a copy of the personal data in possession of the controller. The controller did not respond to the request. Therefore, the data subject appealed to the Tribunal of Bologna, requesting an order for the fulfilment of her right under Article 15 GDPR. She stated that the controller must (have) processed her personal data, since she had a 'loyalty card' from the controller and documentation relating to the purchase of a smart TV (receipt and financing contract). Holding — The Court held that it was becoming increasingly crucial to protect people's rights when it comes to the processing of their personal data, especially from an economic standpoint. In doing so, it is necessary to remember that protecting people's fundamental rights cannot be sacrificed in favour of the interests of the market alone. The Court recalled that the GDPR, although known as the Privacy Regulation, actually has a far wider scope of application that extends beyond and individual's right to privacy, which is historically linked to their most private sphere. While the liberal concept of privacy requires essentially refraining from something for its protection, the current conception of privacy has an interactive and dynamic nature. It particularly concerns personal data and their circulation. The right to data protection is the cornerstone of the (positive) freedom to fully control the flow of an individual's own data. It is distinct from the (negative) freedom not to be interfered with in an individual's own private sphere. This is also, and above all, in the logic of market regulation covered by the GDPR. The Court added that it was sufficient to say that the Economist ' described personal data as the new 'most valuable resource', i.e. the new oil. The Court considered that the controller failed to act within the time limit, whereas the applicant had exercised her right correctly. Therefore, the Court held that, with reference to Article 12(1), (2), (3) and (4), and Article 15 GDPR, the data subject's right to access must be fulfilled by the controller. Consequently, the Court ordered the controller to provide the data subject with all the personal data, and documents relating to the data subject in possession.

## Guidance

### Report on stakeholder event on processing of personal data to target or deliver political advertisements

*Source: EDPB, report-on-stakeholder-event-on-processing-of-personal-data-en, 2026-03-27 — https://overview.legal/posts/125684 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/report-on-stakeholder-event-on-processing-of-personal-data_en*

Report on stakeholder event on processing of personal data to target or deliver political advertisements 27 March 2026 1. Background The EDPB organised an online stakeholder event on 27 March 2026 to collect stakeholders’ input on processing of personal data to target or deliver political advertisements. The objective was to engage with stakeholders at an early stage of drafting the EDPB Guidelines on the processing of personal data to target or deliver political advertisements (Chapter III of…

### Guidelines 8/2020 on the targeting of social media users

*Source: EDPB, edpb-guidelines-on-the-targeting-of-social-media-users, 2021-04-13 — https://overview.legal/posts/38073 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-82020-on-the-targeting-of-social-media-users_en*

The EDPB adopted Guidelines 8/2020 on the targeting of social media users to clarify the roles, responsibilities, and legal obligations of the various actors involved in social media targeting, including social media providers, targeters, and users. The guidelines analyze different targeting mechanisms—based on provided, observed, and inferred data—and address controller determinations, legal bases, transparency requirements, DPIAs, and the processing of special categories of data. No fines are imposed, as this is interpretive guidance intended to assist stakeholders in achieving GDPR compliance.

### Statement 2/2019 on the use of personal data in the course of political campaigns

*Source: EDPB, statement-22019-on-the-use-of-personal-data-in-the-course-of-political-en, 2019-03-13 — https://overview.legal/posts/126230 — original: https://www.edpb.europa.eu/documents/statement/statement-22019-on-the-use-of-personal-data-in-the-course-of-political_en*

1 Statement 2 / 2019 on the use of personal data in the course of political campaigns Adopted on 13 March 2019 The European Data Protection Board has adopted the following statement: Engaging with voters is inherent to the democratic process. It allow s the preparation of political program me s , enable s citizens to influence politics and the develop ment of campaign s in line with citizens expectation s. Political parties , political coalitions and candidates increasingly rely on personal…

### Automated decision-making and profiling

*Source: EDPB, automated-decision-making-and-profiling-en, 2018-05-25 — https://overview.legal/posts/126332 — original: https://www.edpb.europa.eu/documents/guideline/automated-decision-making-and-profiling_en*

### Art. 29 WP Guidelines on GDPR transparency requirements (WP260 rev.01)

*Source: EDPB, edpb-guidelines-on-transparency, 2025-11-21 — https://overview.legal/posts/38076 — original: https://www.edpb.europa.eu/system/files/2023-09/wp260rev01_en.pdf*

The Article 29 Data Protection Working Party issued these guidelines (WP260 rev.01), adopted on 29 November 2017 and last revised on 11 April 2018, to provide interpretive and practical guidance on the transparency requirements under the GDPR (Articles 12–14). The document addresses the form, timing, content, and modalities of information provided to data subjects, including issues such as plain language, layered privacy notices, information for children, and exceptions to the obligation to provide information. No fines or enforcement actions are imposed, as this is a guidance document rather than an enforcement decision.

### EDPB-EDPS Joint Opinion 2/2022 on the Proposal of the European Parliament and of the Council on harmonised rules on fair access to and use of data (Data Act)

*Source: EDPB, edpb-edps-joint-opinion-22022-on-the-proposal-of-the-european-en, 2022-05-04 — https://overview.legal/posts/125945 — original: https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-22022-on-the-proposal-of-the-european_en*

1 Adopted EDPB - EDP S Joint Opinion 2/2022 on the Proposal of the European Parliament and of the Council on harmonised rules on fair access to and use of data (Data Act) Adopted on 4 May 2022 2 Adopted Executive s ummary With this Joint Opinion, the EDPB and the EDPS aim to draw attention to a number of overarching concerns on the Proposal on Data Act and urge the co - legislature to take decisive action. The EDPB and EDPS note that the Proposal would apply to a broad range of products and…

### Guidelines 2/2019 on the processing of personal data under Article 6(1)(b) GDPR in the context of the provision of online services to data subjects

*Source: EDPB, guidelines-22019-on-the-processing-of-personal-data-under-article-61b-gdpr-in-en, 2019-10-16 — https://overview.legal/posts/126202 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-22019-on-the-processing-of-personal-data-under-article-61b-gdpr-in_en*

1 Adopted Guidelines 2/2019 on the processing of personal data under Article 6(1)(b) GDPR in the context of the provision of online services to data subjects Version 2.0 8 October 2019 2 Adopted Version history Version 2.0 8 October 2019 Adoption of the Guidelines after public consultation Version 1.0 9 April 2019 Adoption of the Guidelines for publication consultation 3 Adopted 1 Part 1 – Introduction ................................ ................................…

### Opinion 01/2019 on the draft list of the competent supervisory authority of the Principality of Liechtenstein regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-012019-on-the-draft-list-of-the-competent-supervisory-en, 2019-01-23 — https://overview.legal/posts/126254 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-012019-on-the-draft-list-of-the-competent-supervisory_en*

Adopted 1 EDPB Plenary Meeting, 22 - 23 January 2019 Opinion 01 /201 9 on the draft list of the competent supervisory authority of the Principality of Liechtenstein regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 23 January 201 9 Adopted 2 Table of c ontents 1 Summary of the Facts ................................ ................................ ................................ ..................... 4 2…

## Enforcement decisions

### AEPD (Spain) - PS/00259/2020

*Source: AEPD (Spain), 2021-07-06 — https://overview.legal/posts/184544 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS/00259/2020*

Facts — A data subject exercised their right to object to receiving commercial communications against a bank (Bankia/Caixabank), after what whose DPO confirmed that the right had been correctly exercised. However, two years after that, the data subject received a letter from the bank which envelope contained a commercial communication, promoting and informing about the bank's services. The data subject lodged a complaint with the Spanish DPA (AEPD). The bank alleged that it was not a commercial communication but a mere standard envelope like the banners and signs that they display at their offices, that include information about the bank's services, and that the letter inside was just information sent to the client regarding the services that they had contracted. The bank also stated that it was not a direct marketing action, as it did not include any profiling or made use of individual preferences, but was general information sent to their clients. They alleged that they were relying on a legitimate interest for this. The bank also alleged that they had not processed their client's data for marketing purposes, since the processing was done to send the letter, and the envelope containing the commercial message was just accidental to it, but the data was not processed for that purpose. Holding — The Spanish DPA determined that the actions performed by the bank were nevertheless commercial communications with a marketing purpose, and that the controller did not have a legal basis for doing so, as the bank could not rely on a legitimate interest since the data subject had exercised their right to object, in accordance to Article 21 GDPR. The Spanish DPA also made reference to Recitals 69 and 70. The AEPD also noted that the privacy policy of the bank declared that commercial communications were based on consent, contrary to what the controller alleged during the procedure. Therefore, the AEPD concluded that there had been a violation of Article 6(1)(f) and fined the controller €50,000, compelling it to implement the necessary measures to prevent the sending of commercial communications to data subjects that have objected to them. The Spanish DPA took into account the lack of diligence, the scope of the infringing behaviour (even if in this case there was an only claimant, the lack of measures to prevent it may make it happen regarding other clients), the link between the controller's activity and the infringement, and the recidivism of the controller; and the fact that the entity was assimilated by another entity, so the infringement could be attributed to the latter entity, as a mitigating factor.

### Belgian DPA: Political campaign email without consent violates GDPR and ePrivacy

*Source: APD/GBA (Belgium), 2024-05-16 — https://overview.legal/posts/158448 — original: https://gdprhub.eu/index.php?title=APD/GBA_(Belgium)_-_74/2024*

Facts — On 30 January 2024, the data subject received an email from a candidate in the June 2024 regional elections (‘controller’), promoting their programme. On 3 January 2024, the data subject responded to the email indicating that Belgian law prohibits political spamming practices. He also indicated that he no longer wished for the controller to use his data, and made an access request, in particular to understand where the controller collected his personal data. On 5 February 2024, the controller responded to the access request by explaining that the data subject’s personal data was probably already in his address book, although it was possible that friends had given it to him. On 5 April 2024, the data subject lodged a complaint with the Belgian DPA (‘APD’). Holding — First, regarding the use of the data subject’s email address for electoral propaganda purposes, Article 6(1)(a) GDPR establishes that the processing of personal data is lawful if the data subject has consented to the processing. Article 13(1) ePrivacy directive states that the use of an email for the purposes of direct marketing may be authorised only if the targeted subscribers have given consent. Furthermore, the APD published a note on the processing of personal data in the context of elections in which it established that the targeting people with political propaganda on the basis of voters’ personal data must be considered direct marketing within the meaning of the GDPR and ePrivacy Directive. In the present case, the APD noted that the data subject did not give consent to the processing of his email address for direct marketing purposes. Therefore, the DPA held that the controller may have breached Article 6(1)(a) GDPR as well as Article 13(1) ePrivacy directive. The DPA examined the possibility of invoking legitimate interest under Article 6(1)(f) GDPR as a legal basis. This article establishes that the processing of personal data is lawful if it is necessary for the purposes of the legitimate interests pursued by the controller, unless the interests or fundamental rights and freedoms of the data subject prevail. Recital 47 GDPR states that the processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest. In CJEU, 4 May 2017, Rigas, C-13/16, the Court of Justice held that Article 6(1)(f) GDPR lays down three cumulative conditions. (i) the pursuit of a legitimate interest by the controller, (ii) the necessity of the processing in order to achieve the legitimate interest pursued and (iii) the fundamental rights and freedoms of the data subject must not prevail. Regarding the pursuit of a legitimate interest, Belgian law provides that candidates in elections may promote their programme through communications. Moreover, the APD described the controller’s interest as ‘sending direct marketing communications to promote the electoral programme for the regional elections in June 2024’. Thus, the controller’s interest is sufficiently specific that it represents a real and present interest. The APD considered that the controller is pursuing a legitimate interest. Regarding the necessity of the processing in order to achieve the legitimate interest, the APD took into account the existence of less intrusive means to attain the objective. The DPA considered that an election programme can be promoted by means of flyers placed in people’s mailboxes for example, which is far less intrusive, even if It may require some extra effort. Therefore, the APD held that the direct marketing was not strictly necessary to the legitimate interest pursued, namely the promotion of its electoral programme. Thus, the APD concluded that the controller may have committed a potential breach of Article 6 GDPR. Second, regarding the access request in order to discover the source of the data used, the APD considered that the controller sent vague and imprecise information about the source of the data subject’s personal data. Therefore, the APD concluded that there may have been a breach of Articles 5(1)(a) and 12(1) GDPR. Hence, the APD issued a prima facie warning to the controller.

### Italian DPA sanctions Lusha Systems for processing contact data without consent in B2B

*Source: Garante per la protezione dei dati personali (Italy), 2026-07-14 — https://overview.legal/posts/184678 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_542/2026*

Facts — Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database. It was an US company wholly owned by Lusha Systems Ltd. In April 2025, the Italian DPA (Garante) initiated an investigation after media reports revealed that telephone numbers of senior Italian officials were available on the platform. The DPA later received one complaint and one report from data subjects who had received unsolicited advertising communications. The data subjects further stated that after requesting information about the source of their contact details, they discovered that their data were available on the controller’s platform without their consent. The controller explained that, for a subscription fee, it provided its Clients with a Business Contact Card for each Contact. The controller further distinguished between “Clients”, namely customers who used the platform and accessed its B2B database, and “Contacts”, namely the individuals whose personal data were included in that database, regardless of whether they used or were aware of the platform. Clients received Contact Cards containing information such as names, professional email addresses, telephone numbers, job titles, roles and locations, which could be used for sales, marketing, recruitment, business intelligence and fraud prevention. The DPA limited its investigation to the processing of Contacts’ personal data. The controller stated that it collected and combined data from publicly available sources, specialised providers, affiliated companies and commercial partners. It also inferred missing professional email addresses through algorithms that identified standard company email patterns. Through its Community Program and integrations with email, calendar and CRM services, it could also obtain information from Clients’ professional networks and communications. The data were cross-referenced, enriched and regularly updated to reflect changes in Contacts’ professional circumstances. The controller argued that the GDPR did not apply because it was established outside the EU and provided services only to businesses. It additionally claimed that the weekly updating of Contact Cards ensured accuracy rather than constituting monitoring or profiling. The controller maintained that the collection and disclosure of the data were necessary for its own economic interest in providing accurate professional contact information and for its Clients’ interests, including fraud prevention. According to the controller, it processed only a limited range of information concerning the Contacts’ professional lives. It further claimed that individuals who made professional information publicly available, particularly through services such as LinkedIn, could reasonably expect that the information might be reused and that they could be contacted regarding professional opportunities. Regarding transparency, the controller stated that its Personal Information Notice was sent to each Contact before their information became available in the database. It explained that it notified Contacts that they had a seven-day period during which they could opt out before their information became available to Clients. The controller also maintained that excluding public officials and public figures from the database was not a requirement under the GDPR. It attributed the presence of certain public officials to technical limitations in its filtering system. It also argued that public figures had a lower expectation of privacy. After the proceedings began, the controller removed profiles connected with Italian public bodies and officials, strengthened its filters and customer-verification measures, discontinued the Community Program in Italy and extended the opt-out period to fourteen days. Holding — Regarding the territorial scope of the GDPR, the DPA acknowledged that Article 3(2)(a) GDPR could apply to the processing of Clients’ data, but not to Contacts, since they were not recipients of the service. However, it held that Article 3(2)(b) GDPR applied because the controller systematically combined, enriched and updated Contacts’ professional information in order to assess their circumstances and determine whether and how they would appear in the database. Referring to Recital 24 and Recital 30, the DPA held that monitoring did not require profiling. It noted that the systematic observation of online traces and changes in a person’s professional situation was sufficient. The fact that the processing also served data accuracy did not alter that conclusion. It emphasised that the fact that the controller also updated the information to ensure its accuracy did not prevent the processing from constituting monitoring. Regarding transparency, the DPA found that the information concerning the collection of the Contacts’ data, the purposes of the processing and the legal basis relied upon was scattered across several documents. Also, the relevant information was not easily accessible from the controller’s homepage, while the Personal Information Notice could not be located directly through the website without prior knowledge of its existence. It further pointed out that the documents were provided in English rather than in the language of the affected data subjects. The DPA held that presenting the information in this manner did not satisfy the requirement that information be concise, transparent, intelligible and easily accessible. It therefore found an infringement of Article 5(1)(a) GDPR and Article 12 GDPR. Moreover, the DPA assessed whether Article 6(1)(f) GDPR provided a valid legal basis for the processing. It examined the controller’s Legitimate Interest Assessment and considered it essentially non-existent, as it contained only generic statements on necessity and proportionality and no genuine balancing assessment. The DPA then applied the three-part test under Article 6(1)(f) GDPR. It held that making the Contacts’ data available to Clients for their own marketing and sales activities could not constitute a legitimate interest, since the disclosure of contact information to third parties for their independent advertising purposes required prior consent under the applicable national and ePrivacy framework . However, it acknowledged that the controller’s interest in fraud prevention could be considered legitimate. The DPA nevertheless found that the processing was not necessary for the purposes pursued. It held that the controller collected information extending beyond ordinary professional contact details, including third-party data contained in CRM databases, email headers and subject lines, information about calendar meetings, and browsing data collected through browser extensions or other software integrations used by Clients. It pointed out that much of this information was not publicly available but was extracted from private interpersonal communications, disclosed by Clients, obtained through integrations with information systems or acquired from third-party providers. The DPA held that the collection and combination of such extensive information was neither strictly necessary nor proportionate for creating professional Contact Cards. Furthermore, it stressed that fraud prevention could also have been achieved through less intrusive means. The DPA therefore concluded that the necessity requirement and the principle of data minimisation were not met. Regarding the balancing test, the DPA emphasised that there was no prior relationship between the controller and the Contacts. Creating a professional profile on LinkedIn or another professional platform did not create a reasonable expectation that unpublished contact details would be collected from multiple sources, continuously updated and disclosed to an unspecified number of paying customers. It further noted that the processing could expose Contacts to communications from unknown third parties for purposes they could not reasonably anticipate. The DPA concluded that the Contacts’ interests, rights and freedoms prevailed over the controller’s economic interests and that the safeguards adopted by the controller could not change this outcome. Therefore, the DPA held that Article 6(1)(f) GDPR did not provide an appropriate legal basis and found that the controller infringed Article 5(1)(a) GDPR, Article 5(1)(c) GDPR, and Article 6 GDPR. Regarding public officials, the DPA held that their status did not reduce their entitlement to data protection and that no public interest justified disclosing their direct contact details for commercial purposes. The DPA further found that the controller had been aware of the risk that public officials could be included in its database but had failed to implement sufficiently effective technical and organisational measures. Its filters recognised general titles such as “President” but failed to exclude more specific titles such as “President of the Italian Republic” and “Vice Prime Minister”. The DPA therefore found an infringement of the principle of data minimisation under Article 5(1)(c) GDPR and the obligation of data protection by design and by default under Article 25 GDPR. The DPA imposed a fine of €2,000,000. Furthermore, it prohibited any further processing of personal data of data subjects located in Italy that had been collected without an adequate legal basis and ordered their deletion.

### AEPD sanctions Tiger Media Inc. for installing advertising cookies without user consent

*Source: AEPD (Spain), 2025-11-14 — https://overview.legal/posts/158452 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS-00480-2025*

Facts — Tiger Media Inc., the controller, operated an advertising platform for publishers and advertisers of adult products and services. The platform acted as an ad network, connecting publishers offering advertising space with advertisers seeking to display ads on those websites. Through this platform, the controller processed personal data of users visiting publishers’ websites where its ads were displayed. This included IP addresses, device and browser information, website URLs, referral URLs, clicks, impressions and cookie identifiers. According to the controller, the data were processed for ad delivery, fraud prevention, frequency capping, performance measurement and service improvement. The controller argued that it did not carry out behavioural advertising or profiling. It claimed that any targeting was limited to contextual factors, such as country and language. The controller relied mainly on legitimate interest as a legal basis and argued that publishers, as independent controllers of their own websites, were responsible for obtaining any consent required for cookies. The DPA investigated the controller’s platform and several Spanish websites using it. It found that cookies linked to the controller’s platform were installed on users’ devices without prior consent. These cookies were used for advertising-related purposes, including measuring ad performance, improving ad relevance, limiting frequency and detecting fraud. The AEPD also noted that the controller was not established in the EU. Although the controller stated that it had appointed a representative in Northern Ireland and was in the process of changing representative, the DPA considered that it did not have a valid representative established in the Union. Holding — The AEPD held that the controller violated Article 6 GDPR by processing personal data without a valid legal basis. The DPA emphasised that the LSSI, the Spanish law implementing the ePrivacy Directive require prior consent for storing or accessing information on a user’s device through cookies, unless an exemption applies. The DPA distinguished between the placement or reading of cookies, which is governed by the cookie rules, and the subsequent processing of personal data obtained through those cookies, which must comply with the GDPR. Since the cookies were installed without consent, the subsequent processing of the data collected through them could not be considered lawful. The AEPD rejected the controller’s reliance on legitimate interest under Article 6(1)(f) GDPR. It found that users had not received clear information and had not consented to the use of cookies. Moreover, users of the affected websites did not have a reasonable expectation that their browsing-related data would be processed by a third-party advertising network for advertising purposes. Therefore, the processing did not pass the balancing test required under Article 6(1)(f) GDPR. The DPA also held that the controller violated Article 27 GDPR. Since the controller was not established in the EU but processed personal data of users in Spain in connection with its advertising services, it was required to appoint a representative established in an EU Member State. A representative in Northern Ireland did not meet this requirement. The AEPD fined the controller €120,000 in total: €70,000 for the violation of Article 6 GDPR and €50,000 for the violation of Article 27 GDPR. Pursuant to Article 85 of the Spanish administrative Law 39/2015, the notice of initiation informed the controller of the possibility of acknowledging liability and making a voluntary payment of the proposed penalty, which would entail two cumulative reductions of 20% each. With the application of these two reductions, the final penalty was set at €72,000, and its payment resulted in the termination of the proceedings. The AEPD also ordered the controller to adopt corrective measures within three months. In particular, the controller had to ensure compliance with Article 6 GDPR, ensure compliance with the Spanish cookie rules by the service providers using its cookies, appoint an EU representative and notify the AEPD of the measures adopted.

### GOOGLE IRELAND LIMITED: Onvoldoende juridische basis voor de verwerking van gegevens.

*Source: French Data Protection Authority (CNIL), 2025-09-01 — https://overview.legal/posts/52129*

De Franse autoriteit voor gegevensbescherming heeft GOOGLE IRELAND LIMITED een boete van 125.000.000 euro opgelegd. Bij het aanmaken van een account voor de diensten van de verantwoordelijke, heeft deze de procedure voor toestemming voor cookies zodanig ontworpen dat een vrije, geïnformeerde toestemming niet mogelijk was. De betrokkene kon alleen kiezen tussen de gratis dienst met gepersonaliseerde marketing of een betaalde versie zonder dit. De verantwoordelijke heeft ook haar e-maildienst zo ontworpen dat advertenties getoond konden worden in gebieden waar betrokkene normaal gesproken...

### LfD (Lower Saxony) - Fine EUR 900,000 against bank

*Source: LfD (Lower Saxony), 2022-09-28 — https://overview.legal/posts/6319 — original: https://gdprhub.eu/index.php?title=LfD_(Lower_Saxony)_-_Fine_EUR_900,000_against_bank*

Facts — A commercial bank (controller) used personal data of current and former customers (data subjects) to identify customers with an affinity for digital media usage, in order to address them more intensely through electronic communication channels for further commercial communication (advertisement). A service provider analyzed digital usage behavior on behalf of the controller, including the total amount of app-store purchases, the usage frequency of bank statement printers as well as the total amount of transfers in online banking system (in comparison to the offline usage in their local branch offices). The results were compared and further enriched with data from a commercial credit reporting agency. Most customers were informed in advance, but no consent under Article 6(1)(a) GDPR was obtained. The controller based the data analysis, data enrichment and the subsequent creation of customer profiles on legitimate interest as per Article 6(1)(f) GDPR. Holding — The DPA found that the analysis of large amounts of data to create customer profiles could not be based on Article 6(1)(f). It followed that processing based on a legitimate interest requires a balancing act between the interest of the controller and the fundamental rights and freedoms if the data subject. The controller had to consider the reasonable expectations of the data subjects. The DPA argued that a data subject could not reasonably expect large amounts of its personal data to be analyzed by the controller to better target its advertising. Third-party data enrichment, like the use of commercial credit reporting agency data, further overrides the interest of the controller and tips the balancing test in favor of the data subject. The DPA held that in addition, data enrichment from a third-party source and linking it to profiles could also not be based on legitimate interest. This could potentially link data from all areas of life to an accurate customer profile, which could also not be reasonably expected by a customer. Customer consent (see Article 6(1)(a)) is required. The controller cooperated with the DPA throughout the process. For the violation, the DPA fined the controller €900,000.

### Garante per la protezione dei dati personali (Italy) - 9788429

*Source: Garante per la protezione dei dati personali (Italy), 2022-07-07 — https://overview.legal/posts/122853 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_9788429*

Facts — Social media platform TikTok (the controller) provided personalized advertising to its users (the data subjects) on the legal basis of consent (Article 6(1)(a) GDPR). In June 2022, the controller announced that a new privacy policy would come into effect on 13 July 2022. Under the new policy, the controller would only serve personalize advertising to users over 18 years of age and on the legal basis of the legitimate interest of the controller (Article 6(1)(f) GDPR). The Italian DPA started an investigation and found that personalized advertisement would likely involve the use of cookies or other tracking mechanisms. Holding — Regarding the competence of the Italian DPA, it should be noted that the Irish DPA is the lead supervisory authority for the controller’s data processing activities under the GDPR's "one-stop-shop" mechanism. The Italian DPA acknowledged the Irish DPA’s position in its decision. However, the Italian DPA held the ePrivacy Directive to be applicable to the processing of cookies by the controller and held itself competent to enforce the Directive. The DPA referenced Recital 173 GDPR and EDPB Opinion 05/2020 on this point. The DPA held that the controller’s new privacy policy violated Article 5(3) ePrivacy Directive 2002/58/EC. The Article only allows the controller to process cookies and use similar tracking mechanisms with the user’s consent . For this reason, legitimate interest under Article 6(1)(f) GDPR is not a valid legal basis for the processing of cookies. The Italian DPA also held that the controller violated Article 122 of the Italian Privacy Code (d. lgs. 30 giugno 2003, n. 196). Article 122 is a direct transposition of Article 5(3) ePrivacy Directive. The violation of the Code constitutes a direct consequence of the violation of the Directive. The DPA issued a warning against the controller.

### Italian Garante sanctions EstEnergy for automated creditworthiness scoring in energy

*Source: Garante per la protezione dei dati personali (Italy), 2026-07-03 — https://overview.legal/posts/184565 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_484/2026*

Facts — EstEnergy S.p.A. (hereinafter, the controller) is an Italian energy company supplying natural gas, electricity and related services. Before entering into contracts, the controller assessed the creditworthiness of potential customers through an internal and an external credit check. The internal assessment involved verifying whether potential customers had outstanding debts not only with the controller but also with Hera Comm S.p.A (hereinafter, the corporate group). The assessment was conducted on behalf of the controller by Hera S.p.A. (hereinafter, the processor), which returned an “OK” or “KO” result. Where the internal assessment returned an “OK”, the controller conducted an external assessment using credit information supplied by Experian Italia S.p.A. and commercial information provided by Cerved Group S.p.A. This information was combined using the “CGS-X” software provided by Major 1 S.r.l. (hereinafter, the software provider and processor). The software generated an integrated creditworthiness score and several underlying sub-scores. On the basis of the result, the controller could refuse to enter into an energy supply contract. The DPA received several complaints from data subjects whose requests for energy supply had been rejected on the basis of their risk profiles. However, when the data subjects contacted the credit and commercial information providers, they were informed that the relevant databases did not contain negative information or adverse events concerning them. The data subjects also submitted access requests under Article 15 GDPR. Although the controller responded within the applicable time limits, it did not provide the CGS-X score, the underlying sub-scores or meaningful information about the logic and criteria used to calculate the profiles. Instead, the controller referred the data subjects to the credit and commercial information providers. Following the complaints, the DPA consolidated the proceedings and initiated an ex officio investigation. It conducted inspections at the premises of the processor, the software provider and processor, and the credit and commercial information providers. The investigation also established that the controller retained the information obtained through the credit checks. Through the processor, the controller subsequently analysed this information to potentially refine the corporate group’s customer rating system. Between 2022 and March 2024, this processing concerned more than one million data subjects. Holding — The DPA held that the controller’s creditworthiness assessment infringed Articles 5(1)(a), (b), (d) and (e), 12, 13, 14, 15 and 28 GDPR. First, the controller failed to provide transparent information about the internal assessment of customers’ previous debts and the sharing of such information within the corporate group. The instructions given to the processor also did not adequately cover these processing operations. The DPA therefore found violations of Articles 5(1)(a), 13, 14 and 28 GDPR. Second, the controller provided incomplete responses to access requests. It did not disclose the CGS-X score, the underlying sub-scores or meaningful information on the logic and criteria used to generate the creditworthiness profile. Referring the data subjects to the credit and commercial information providers did not discharge the controller’s obligations under Articles 12 and 15 GDPR. Third, the controller had not established a justified retention period for the data collected during the external assessment. Applying a general ten-year retention period for accounting records was not shown to be necessary for the creditworthiness assessment, in violation of Article 5(1)(e) GDPR. The DPA also found that reusing credit and commercial information to refine the corporate group’s rating system was incompatible with the original purpose for which the data had been collected. Since the retained information could become outdated, this processing also violated the purpose limitation and accuracy principles under Articles 5(1)(b) and (d) GDPR. The DPA ordered the controller to adopt a compliant access-response template, provide the relevant information to the data subjects involved and establish procedures enabling rectification, human intervention and the possibility to challenge decisions. The controller had six months to demonstrate compliance. Finally, the DPA imposed a €1,400,000 fine, taking into account the seriousness and scale of the infringements, the impact on approximately one million data subjects and the risk of refusal of essential energy services. It also considered the controller’s cooperation, lack of previous relevant infringements and remedial measures as mitigating factors.

## Recent developments

### noyb WIN: French DPA fines Google €325 million for “Spam Emails” in Gmail

*Source: noyb - European Center for Digital Rights, 2025-09-04 — https://overview.legal/posts/53140 — original: https://noyb.eu/en/noyb-win-french-dpa-fines-google-eu325-million-spam-emails-gmail*

Forced Consent & Consent Bypass More than three years ago, noyb had filed a complaint against Google for sending unsolicited advertising emails directly to the inboxes of Gmail users. Contrary to EU law, the company never asked the people concerned for their consent. That's how the competent data protection authority sees it, too: Today, the CNIL has issued a decision siding with noyb – and fined Google €325 million. Press release by the CNILOriginal complaints from 2022Ads disguised as emails.

### Political Microtargeting by EU Commission illegal

*Source: noyb - European Center for Digital Rights, 2024-12-13 — https://overview.legal/posts/53170 — original: https://noyb.eu/en/political-microtargeting-eu-commission-illegal*

Political Microtargeting, Manipulation & Tracking noyb win against the European Commission: The EDPS (European Data Protection Supervisor) has issued a decision finding that the European Commission has illegally targeted advertising at citizens using "sensitive" personal data on their political views. Decision by the EDPSComplaint filed with the EDPS in 2023Related noyb complaints in Germany ("Target Leaks")EU Commission tried to influence political views in the Netherlands. In the contentious f

### AEPD publishes GDPR Risk Assessment

*Source: AEPD, 2022-10-11 — https://overview.legal/posts/6259 — original: https://evalua-riesgo.aepd.es/index_en.html#entry-1032*

> GDPR RISK ASSESSMENT is intended to assist controllers and processors to identify the risk factors for the rights and freedoms of data subjects whose data are present in the processing, to make an initial assessment of the intrinsic risk, including the need to perform a DPIA, and to estimate the residual risk if measures and safeguards are used to mitigate the specific risk factors.

### Garante onderzoekt het gebruik van "cookie walls".

*Source: Garante Privacy, 2022-10-25 — https://overview.legal/posts/51828*

De Garante (de Italiaanse Autoriteit voor de bescherming van persoonsgegevens) merkt op dat de Europese wetgeving inzake de bescherming van persoonsgegevens in principe niet verhindert dat de eigenaar van een website de toegang tot content voor gebruikers afhankelijk maakt van hun toestemming voor het verzamelen van gegevens voor profilering (via cookies of andere trackingtools), of, als alternatief, van het betalen van een bedrag. Dit verwijst naar de initiatieven die de afgelopen dagen zijn genomen door verschillende online kranten, websites en bedrijven die actief zijn op internet.

### Court rules on Experian appeal of ICO enforcement notice

*Source: IAPP, 2023-02-21 — https://overview.legal/posts/6241 — original: https://iapp.org/news/a/court-rules-on-experian-appeal-of-ico-enforcement-notice#entry-3894*

> 
																						The First-Tier Tribunal overturned portions of a 2020 enforcement notice by the U.K. Information Commissioner's Office against Experian, confirming the company's reliance on legitimate interests as a legal basis for processing credit reference agency information for direct marketing purposes. Deputy Commissioner Stephen Bonner, CIPP/E, CIPM, said marketing processes "must happen in line with the law and in an open and honest way" and the ICO noted it will consider an app

## Literature

### HOW GDPR TREATS AUTOMATED DECISION-MAKING

*Source: Journal Scientific and Applied Research, 2025-11-14 — https://overview.legal/posts/132599 — original: https://doi.org/10.46687/jsar.v28i1.435*

This article examines how the General Data Protection Regulation (GDPR) regulates automated decision-making, including profiling, in the context of personal data processing. It analyzes the main provisions of Article 22 of the Regulation, as well as the conditions under which fully automated decisions that produce legal effects or significantly affect data subjects are permitted. The article highlights the rights of data subjects – the right to human intervention, the right to express their poin

### CJEU: The Rating of a Natural Person’s Creditworthiness by a Credit Rating Agency Constitutes Profiling and Can Be an Automated Decision under Article 22 GDPR

*Source: European Data Protection Law Review, 2024-01-01 — https://overview.legal/posts/132601 — original: https://doi.org/10.21552/edpl/2024/1/17*

### Implications of GDPR and EU Adequacy Decision for Regulation of Profiling and Automated Decision-making in Korea

*Source: Chungnam Law Review, 2022-11-30 — https://overview.legal/posts/132602 — original: https://doi.org/10.33982/clr.2022.11.30.4.189*

### Data is power: Towards additional guidance on profiling and automated decision-making in the GDPR

*Source: Journal of Information Rights, Policy and Practice, 2018-03-14 — https://overview.legal/posts/132598 — original: https://doi.org/10.21039/irpandp.v2i2.45*

### Perlindungan Hukum terhadap Inferred data dalam Automated Decision-Making: Studi Perbandingan GDPR dan UU PDP

*Source: Jurnal Ilmu Hukum, Humaniora dan Politik, 2026-05-25 — https://overview.legal/posts/132606 — original: https://doi.org/10.38035/jihhp.v6i4.8347*

Perkembangan kecerdasan buatan dan sistem automated decision-making (ADM) mendorong penggunaan inferred data yang memungkinkan pembentukan profil individu tanpa keterlibatan langsung subjek data. Praktik ini menimbulkan risiko terhadap hak individu, termasuk diskriminasi algoritmik dan kurangnya transparansi. Namun, belum ada kajian yang secara spesifik membandingkan perlindungan inferred data dalam kedua rezim ini. Penelitian ini bertujuan menganalisis klasifikasi inferred data dalam kerangka G

## Tools

### ICO data protection self-assessment checklists

*Source: ICO, 2026-07-17 — https://overview.legal/posts/125624 — original: https://ico.org.uk/for-organisations/advice-for-small-organisations/checklists/*

Self-assessment checklists by the UK regulator for small organisations: controllers, processors, information security, direct marketing, records management and CCTV — each producing a rating with suggested actions.

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Profiling** — https://overview.legal/topics/profiling
  Automated processing to evaluate personal aspects
- **Automated Decision-Making** — https://overview.legal/topics/geautomatiseerde-besluitvorming
  Processing involving automated decisions without human involvement
- **Direct Marketing** — https://overview.legal/topics/direct-marketing
  Processing for marketing and advertising purposes

---
Generated by overview.legal · https://overview.legal/topics/marketing · 2026-08-22
