# Minors — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/minderjarigen
> Sources are cited per item. Verify against the official texts before relying on them.

Special protections for children under GDPR

## Overview

## Legal Framework

Article 8 GDPR establishes the conditions for a child's consent in the context of information society services offered directly to children. Where a controller relies on consent as the lawful basis under Article 6(1)(a), the child must be at least 16 years old to provide valid consent independently. Member States may legislate a lower threshold, but not below 13 years of age. Below the applicable national age, consent must be given or authorized by the holder of parental responsibility. Controllers must make reasonable efforts to verify that parental consent has been obtained, using means appropriate to the available technology and the level of risk involved. Article 8 does not displace national contract law, meaning Member States may permit certain contracts with minors without requiring parental authorization.

Article 35 GDPR adds a further layer: where processing is likely to result in a high risk to the rights and freedoms of natural persons—and processing children's personal data is expressly identified as a factor contributing to high risk—a Data Protection Impact Assessment is mandatory. Recital 38 reinforces the rationale: children merit specific protection because they may be less aware of risks and their rights in relation to data processing.

The Digital Services Act, through Article 28 DSA, complements these protections by imposing additional obligations on online platforms regarding the protection of minors, including restrictions on targeted advertising directed at children based on profiling.

## Key Developments

The ICO's enforcement action against MediaLab.AI, Inc.—controller of the image-sharing platform Imgur—resulted in a fine of approximately EUR 284,450 and illustrates a concrete enforcement posture toward platforms accessible to minors. The Swedish DPA's fine of EUR 565,000 against Sportadmin i Skandinavien AB, arising from a cyberattack exposing personal data, underscores that inadequate security measures affecting minors' data carry significant financial consequences.

The Article 29 Working Party's transparency guidelines (WP260 rev.01) establish that privacy notices directed at children must use clear, age-appropriate language. Controllers cannot satisfy transparency obligations under Articles 12 and 13 GDPR by providing notices comprehensible only to adults when the service targets children.

CJEU jurisprudence, including the Schrems decision, confirms that supervisory authorities bear an active duty to monitor compliance with data protection rules—including transfers and processing affecting minors—reinforcing that protections for children's data are not merely aspirational but actively policed.

## Practical Guidance

- **Determine the applicable age threshold**: Identify the Member State-specific digital age of consent (ranging from 13 to 16) for each jurisdiction where your information society service is offered, as this directly governs whether a child can consent independently or requires parental authorization under Article 8(1) GDPR.

- **Implement age verification and parental consent mechanisms**: Deploy age-assessment tools proportionate to the risk of processing. For low-risk services, self-declaration may suffice; for higher-risk processing, more robust verification methods are required. Document the technical measures chosen and the rationale for their adequacy.

- **Conduct a Data Protection Impact Assessment**: Article 35(3)(b) GDPR mandates a DPIA where processing involves systematic monitoring of a large scale of data, and the involvement of minors is an explicit risk factor. The DPIA must specifically address vulnerabilities of child users and mitigation measures.

- **Draft child-appropriate privacy notices**: Transparency information provided to children must be concise, intelligible, and in language suited to the child's age, consistent with Article 12(1) GDPR and the WP260 guidelines. Layered notices—summary for children, full text for parents—are a recognized approach.

- **Restrict profiling and targeted advertising**: Article 22 GDPR and Article 28 DSA constrain automated decision-making and targeted advertising directed at minors. Controllers should disable behavioral profiling for child users unless strictly necessary and legally justified.

## Legislation (full text of key provisions)

### Conditions applicable to child's consent in relation to information society services

*Source: GDPR, gdpr-art-8-en, 2016-04-27 — https://overview.legal/posts/90292*

### Online protection of minors

*Source: DSA, dsa-art-28-en, 2022-10-19 — https://overview.legal/posts/94461*

### Recital 71 — protection of minors online

*Source: DSA, dsa-rec-71-en, 2022-10-19 — https://overview.legal/posts/95539*

The protection of minors is an important policy objective of the Union. An online platform can be considered to be accessible to minors when its terms and conditions permit minors to use the service, when its service is directed at or predominantly used by minors, or where the provider is otherwise aware that some of the recipients of its service are minors, for example because it already processes personal data of the recipients of its service revealing their age for other purposes. Providers of online platforms used by minors should take appropriate and proportionate measures to protect minors, for example by designing their online interfaces or parts thereof with the highest level of privacy, safety and security for minors by default where appropriate or adopting standards for protection of minors, or participating in codes of conduct for protecting minors. They should consider best practices and available guidance, such as that provided by the communication of the Commission on A Digital Decade for children and youth: the new European strategy for a better internet for kids (BIK+). Providers of online platforms should not present advertisements based on profiling using personal data of the recipient of the service when they are aware with reasonable certainty that the recipient of the service is a minor. In accordance with Regulation (EU) 2016/679, notably the principle of data minimisation as provided for in Article 5(1), point (c), thereof, this prohibition should not lead the provider of the online platform to maintain, acquire or process more personal data than it already has in order to assess if the recipient of the service is a minor. Thus, this obligation should not incentivize providers of online platforms to collect the age of the recipient of the service prior to their use. It should be without prejudice to Union law on protection of personal data.

### Recital 89 — protection of minors on large platforms

*Source: DSA, dsa-rec-89-en, 2022-10-19 — https://overview.legal/posts/95575*

Providers of very large online platforms and of very large online search engines should take into account the best interests of minors in taking measures such as adapting the design of their service and their online interface, especially when their services are aimed at minors or predominantly used by them. They should ensure that their services are organised in a way that allows minors to access easily mechanisms provided for in this Regulation, where applicable, including notice and action and complaint mechanisms. They should also take measures to protect minors from content that may impair their physical, mental or moral development and provide tools that enable conditional access to such information. In selecting the appropriate mitigation measures, providers can consider, where appropriate, industry best practices, including as established through self-regulatory cooperation, such as codes of conduct, and should take into account the guidelines from the Commission.

### Recital 46 — child-friendly terms explanation for minors

*Source: DSA, dsa-rec-46-en, 2022-10-19 — https://overview.legal/posts/95489*

Providers of intermediary services that are primarily directed at minors, for example through the design or marketing of the service, or which are used predominantly by minors, should make particular efforts to render the explanation of their terms and conditions easily understandable to minors.

### Recital 38 — special protection for children's personal data

*Source: GDPR, gdpr-rec-38-en, 2016-04-27 — https://overview.legal/posts/91591*

Children merit specific protection with regard to their personal data, as they may be less aware of the risks, consequences and safeguards concerned and their rights in relation to the processing of personal data. Such specific protection should, in particular, apply to the use of personal data of children for the purposes of marketing or creating personality or user profiles and the collection of personal data with regard to children when using services offered directly to a child. The consent of the holder of parental responsibility should not be necessary in the context of preventive or counselling services offered directly to a child.

### Recital 102 — voluntary technical standards for compliance

*Source: DSA, dsa-rec-102-en, 2022-10-19 — https://overview.legal/posts/95601*

To facilitate the effective and consistent application of the obligations in this Regulation that may require implementation through technological means, it is important to promote voluntary standards covering certain technical procedures, where the industry can help develop standardised means to support providers of intermediary services in complying with this Regulation, such as allowing the submission of notices, including through application programming interfaces, or standards related to terms and conditions or standards relating to audits, or standards related to the interoperability of advertisement repositories. In addition, such standards could include standards related to online advertising, recommender systems, accessibility and the protection of minors online. Providers of intermediary services are free to adopt the standards, but their adoption does not presume compliance with this Regulation. At the same time, by providing best practices, such standards could in particular be useful for relatively small providers of intermediary services. The standards could distinguish between different types of illegal content or different types of intermediary services, as appropriate.

### Recital 104 — code of conduct consideration areas

*Source: DSA, dsa-rec-104-en, 2022-10-19 — https://overview.legal/posts/95605*

It is appropriate that this Regulation identify certain areas of consideration for such codes of conduct. In particular, risk mitigation measures concerning specific types of illegal content should be explored via self- and co-regulatory agreements. Another area for consideration is the possible negative impacts of systemic risks on society and democracy, such as disinformation or manipulative and abusive activities or any adverse effects on minors. This includes coordinated operations aimed at amplifying information, including disinformation, such as the use of bots or fake accounts for the creation of intentionally inaccurate or misleading information, sometimes with a purpose of obtaining economic gain, which are particularly harmful for vulnerable recipients of the service, such as minors. In relation to such areas, adherence to and compliance with a given code of conduct by a very large online platform or a very large online search engine may be considered as an appropriate risk mitigating measure. The refusal without proper explanations by a provider of an online platform or of an online search engine of the Commission’s invitation to participate in the application of such a code of conduct could be taken into account, where relevant, when determining whether the online platform or the online search engine has infringed the obligations laid down by this Regulation. The mere fact of participating in and implementing a given code of conduct should not in itself presume compliance with this Regulation.

### Recital 40 — harmonised due diligence obligations intermediary services

*Source: DSA, dsa-rec-40-en, 2022-10-19 — https://overview.legal/posts/95477*

In order to achieve the objectives of this Regulation, and in particular to improve the functioning of the internal market and ensure a safe and transparent online environment, it is necessary to establish a clear, effective, predictable and balanced set of harmonised due diligence obligations for providers of intermediary services. Those obligations should aim in particular to guarantee different public policy objectives such as the safety and trust of the recipients of the service, including consumers, minors and users at particular risk of being subject to hate speech, sexual harassment or other discriminatory actions, the protection of relevant fundamental rights enshrined in the Charter, the meaningful accountability of those providers and the empowerment of recipients and other affected parties, whilst facilitating the necessary oversight by competent authorities.

### Recital 81 — fundamental rights risks of services

*Source: DSA, dsa-rec-81-en, 2022-10-19 — https://overview.legal/posts/95559*

A second category concerns the actual or foreseeable impact of the service on the exercise of fundamental rights, as protected by the Charter, including but not limited to human dignity, freedom of expression and of information, including media freedom and pluralism, the right to private life, data protection, the right to non-discrimination, the rights of the child and consumer protection. Such risks may arise, for example, in relation to the design of the algorithmic systems used by the very large online platform or by the very large online search engine or the misuse of their service through the submission of abusive notices or other methods for silencing speech or hampering competition. When assessing risks to the rights of the child, providers of very large online platforms and of very large online search engines should consider for example how easy it is for minors to understand the design and functioning of the service, as well as how minors can be exposed through their service to content that may impair minors’ health, physical, mental and moral development. Such risks may arise, for example, in relation to the design of online interfaces which intentionally or unintentionally exploit the weaknesses and inexperience of minors or which may cause addictive behaviour.

## Case law

### Judgment of the General Court (Seventh Chamber, Extended Composition) of 19 November 2025.#Amazon EU Sàrl, venant aux droits de Amazon Services Europe Sàrl v European Commission.#Digital services – Regulation (EU) 2022/2065 – Designation as a very large online platform – Plea of illegality – Admissibility – Article 33(1) and (4) of Regulation 2022/2065 – Right to respect for private and family life – Freedom to conduct a business – Right to property – Equal treatment – Freedom of expression – Da

*Source: General Court, T-367/23, 2025-11-19 — https://overview.legal/posts/132131 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023TJ0367*

Amazon EU Sàrl challenged the European Commission's decision designating Amazon Store as a very large online platform under Article 33(4) of the Digital Services Act (Regulation 2022/2065), raising pleas alleging the illegality of Articles 33(1), 38, and 39 of the regulation on grounds including violations of fundamental rights to privacy, freedom to conduct a business, property, equal treatment, and freedom of expression. The General Court (Seventh Chamber, Extended Composition) ruled on the admissibility of the plea challenging Article 33(1), finding that the application's scope was sufficiently clear and precise to permit assessment of its merits, thereby rejecting the Council's argument that the plea was inadmissible for lack of clarity.

### HvJ EU 9 januari 2025, C‑394/23 (Mousse).

*Source: CJEU, 2025-01-09 — https://overview.legal/posts/50377 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0394*

HvJ EU 9 januari 2025, C‑394/23 (Mousse). Artikelen: 5(1)(c), 6(1), en 21 AVG Onderwerp : Beginsel van minimale gegevensverwerking Gek genoeg verwijst het HvJ EU zelf niet naar HvJ EU 1 augustus 2022, C‑184/20 (Vyriausioji tarnybinės etikos komisija), maar dat had hier ook heel logisch geweest.

### CE - 439360

*Source: CE, 2021-04-13 — https://overview.legal/posts/125663 — original: https://gdprhub.eu/index.php?title=CE_-_439360*

Facts — In February 2020 the French minister of the interior enacted the Decree No. 2020-151 of 20 February 2020 authorising the automated processing of personal data known as "mobile note-taking application" (Décret n° 2020-151 du 20 février 2020 portant autorisation d'un traitement automatisé de données à caractère personnel dénommé «application mobile de prise de notes» (GendNotes)). The app should be used on the occasion of preventive actions, investigations or interventions necessary for the exercise of judicial or administrative police missions. Among the data that can be collected is information relating to alleged racial or ethnic origin, political, philosophical or religious opinions, trade union membership, health or sexual activities or orientation. A group of human rights organisations filed a complaint with the French Constitutional Court. Dispute — Is the "GendNotes" App of the French national police force (Gendarmerie nationale) unlawfully processing special category personal data? Holding — The French Highest Administrative Court held that the decree infringed Article 4 of the Law of 6 January 1978, implementing GDPR in France, the Council of Europe Convention No. 108 for the Protection of Individuals with regard to Automatic Processing of Personal Data and Article 8 CFR, as it excessively infringed upon the right to respect for private life and the correlative right to protection of personal data, without providing appropriate safeguards for their protection in terms of the purpose of the processing and the nature of the data collected, as well as excessive data retention period, data sharing and data security. The Court discussed whether the decree violated Article 4 (a) GDPR, Article 4 (b) GDPR, Article 4 (c) GDPR, and Article 4 (e) GDPR and Article 9 GDPR. According to the Court, the processing of data did not comply with the principle of purpose limitation, as data is collected for future investigations or proceedings. However, the Court did not find a violation on the collect of special category data, given the fact that the decree establishes that this data can only be processed in case of "absolute necessity". Additionally, the Court noted that, even if the decree provides a limitation for the storage of the data, in practice this can be ignored, as the data may be used in different or further investigations, that would impede its erasure. However, they found that the decree was lawful in this regard, given that it clearly stated a retention period of 3 months to 1 year. Taken the above-mentioned into account, the French Highest Administrative Court decided that the data processed by the French national police force can no longer be used "in other data processing, in particular by means of a pre-information system". Therefore, the Court held: In Article 1° of the decree, the words "in other data processing, in particular by means of a pre-information system," are cancelled out. The State will pay €3,000 to every claimant. The rest of the application is rejected. The allowance to collect special category data is not overruled, as the Court argues that the decree only allows it when it is "absolutely necessary". This decision will be notified to the claimants: the Ligue des droits de l'homme, the associations Homosexualités et socialismes and Internet Society France, the associations Mousse, Stop Homophobie, Adheos and Familles A, the association AIDES, the Syndicat de la magistrature, the Syndicat des avocats de France, the Conseil national des barreaux, the Quadrature du Net and the International League against Racism and Anti-Semitism, the Prime Minister and the Minister of the Interior.

### GC and Others v CNIL

*Source: CJEU, C-136/17, 2019-09-24 — https://overview.legal/posts/51475 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62017CJ0136*

Conditions for delisting sensitive data from search results.

### Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV

*Source: CJEU, C-40/17, 2019-07-29 — https://overview.legal/posts/51478 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62017CJ0040*

Website operators using Facebook Like button are joint controllers for data collection.

### Unabhängiges Landeszentrum für Datenschutz v Wirtschaftsakademie Schleswig-Holstein

*Source: CJEU, C-210/16, 2018-06-05 — https://overview.legal/posts/51477 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62016CJ0210&ref=51477*

Facebook fan page administrators are joint controllers with Facebook.

### Google Spain SL and Google Inc. v AEPD and Mario Costeja González

*Source: CJEU, C-131/12, 2014-05-13 — https://overview.legal/posts/51472 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62012CJ0131&ref=51472*

Established the right to be forgotten (delisting). Search engines are data controllers.

### CJEU C-473/12 IPI: Member States need not transpose all Directive 95/46 Article 13

*Source: GDPRhub, 2013-11-07 — https://overview.legal/posts/158436 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-473/12_-_IPI*

Facts — The Belgian Professional Institute of Real Estate Agents (IPI) had used private detectives to collect information on a real estate company that allegedly breached regulatory rules. The admissibility of the private detectives’ evidence in court was questioned on the grounds that the company’s agents had not been informed that their personal data would be processed by third parties in accordance with Article 11(1) of the Data Protection Directive 95/46. IPI argued that the use of private detectives fell within the exception under Article 13(1)(d) of Directive 95/46, which permits the collection of data without consent for the prevention, investigation, detection and prosecution of breaches for regulated professions. Belgian law had specified exceptions for journalistic purposes, artistic or literary expression, public authorities exercising judicial police duties, police services and the European Centre for Missing and Sexually Abused Children. The Belgian Constitutional Court considered that the Belgian law did not strictly transpose exceptions comparable to Article 13 of Directive 95/46/EC. It referred three questions to the ECJ for clarification on the obligations for Member States to implement Article 13 in national law: Does Article 13(1)(d) of Directive 95/46 leave Member States free to choose whether or not to provide for an exception to the immediate obligation to inform under Article 11(1) to protect others’ rights and freedoms? Do professional activities of private detectives (governed by national law) come within an exception referred to in Article 13(1)(d) and (g) of Directive 95/46? If they do not, is Article 13(1)(d) and (g) of Directive 95/46 compatible with Article 6(3) TEU – specifically, with the principle of equality and non-discrimination? Holding — With regard to the first question, the Court ruled that Member States have the option, but not an obligation, to transpose the list of exceptions provided under Article 13 of the Data Protection Directive 95/46/EC. Article 13 permits Member States to adopt exemptions allowing the collection and processing of personal data without notifying the data subject in seven circumstances: To safeguard national security. For defence. For public security. For the prevention, investigation, detection and prosecution of criminal offenses or breaches of ethics for regulated professions. For an important economic or financial interests of a Member State. For monitoring, inspection or regulatory functions. For the protection of the data subject or the rights and freedoms of others. The CJEU based its interpretation on the emphasis on a high level of protection found in recitals 3, 8 and 10 of Directive 95/46. In provisions such as these, Directive 95/46's aim of harmonisation must be balanced against the applicability of the Directive's general language in specific situations and the need to afford Member States some flexibility in this regard. With regard to the second question, the CJEU considered that the activity of a private investigator on behalf of a regulated body – in this case, the IPI – falls within the scope of Article 13(1)(d) of Directive 95/46. Thus, if a Member State has chosen to implement an exception pursuant to Article 13(1)(d) of Directive 95/46, the professional body concerned and the private detectives acting on its behalf may rely on it. Accordingly, they need not inform the data subject pursuant to Article 10 and 11 of Directive 95/46.

### Norges Høyesterett - 2021-2403-A

*Source: Norges Høyesterett, 2021-12-07 — https://overview.legal/posts/125647 — original: https://gdprhub.eu/index.php?title=Norges_Høyesterett_-_2021-2403-A*

Facts — In 2012, a company "Legelisten.no AS" launched a website where people could submit anonymous reviews of healthcare personnel. From the same year, the Norwegian DPA Datatilsynet received multiple complaints from affected individuals. In one case in 2015, the DPA held that Legelisten did not have a legal basis for processing personal data related to the website reviews and, further, that Legelisten had to offer an opt-out arrangement for healthcare personnel not wanting their personal data published on the website. The decision was appealed to the Norwegian Privacy Appeals Board, who overturned parts of the DPA's decision, importantly relating to the (lack of) legal basis and the opt-out arrangement. Following this, the Norwegian Medical Association brought an action to the Norwegian courts, claiming that the website had no legal basis as per Article 6(1)(f) GDPR for registering and publishing subjective user reviews of healthcare personnel. Holding — After a balancing of the legitimate interests safeguarded by the website operator Legelisten against the interests of the healthcare personnel, the Supreme Court agreed with the Privacy Appeal Board's decision and found that Legelisten had a legal basis for the processing as per Article 6(1)(f) GDPR. The Court emphasised that Legelisten.no is an important source for the general public to acquire information about healthcare providers. The measures taken to limit privacy concerns also satisfied what could reasonably be expected. Thus, the DPA's initial decision was overturned and the appeal appeal against the Privacy Appeals Board's decision was rejected.

### Privacy International v Secretary of State

*Source: CJEU, C-623/17, 2020-10-06 — https://overview.legal/posts/51481 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62017CJ0623*

General and indiscriminate transmission of traffic data to security agencies incompatible with EU law.

### Maximillian Schrems v Data Protection Commissioner

*Source: CJEU, C-362/14, 2015-10-06 — https://overview.legal/posts/51471 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0362&ref=51471*

Invalidated Safe Harbor adequacy decision. National supervisory authorities can examine adequacy decisions.

### VOLKER UND MARKUS SCHECKE GBR V. LAND HESSEN, EIFERT V. LAND HESSEN AND BUNDESANSTALT FUR LANDWIRTSCHAFT UND ERNAHRUNG, 9.Nov.2010 (“SCHECKE”)

*Source: CJEU, 2010-11-09 — https://overview.legal/posts/6180 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62009CJ0092&ref=6180*

Purpose for processing: The legislation at issue does base the processing on consent. Rather, it provides that they are to be informed. Thus, processing is not based on their consent. (¶ 54)

## Guidance

### EDPB comments on European Commission's Guidelines on Art. 28 DSA

*Source: EDPB, edpb-comments-europeancommission-article-28-dsa-en, 2025-06-25 — https://overview.legal/posts/50981 — original: https://www.edpb.europa.eu/documents/other-policy-document/edpb-comments-on-european-commissions-guidelines-on-art-28-dsa_en*

EDPB, EDPB comments on European Commission's Guidelines on Art. 28 DSA, 2025.

### Statement 1/2025 on Age Assurance

*Source: EDPB, statement-12025-on-age-assurance-en, 2025-02-12 — https://overview.legal/posts/125696 — original: https://www.edpb.europa.eu/documents/statement/statement-12025-on-age-assurance_en*

1 Statement 1/2025 on Age Assurance Adopted on 11 February 2025 1 The European Data Protection Board has adopted the following statement: 1. BACKGROUND AND PURPOSE OF THIS STATEMENT 1. The European regulatory framework calls for the increased protection of children in the digital environment. For example, the Audiovisual Media Services Directive 2 , which Member States have transposed into their national laws, highlights the possibility to implement age verification measures (Articles 6a and…

### EDPB-EDPS Joint Opinion 04/2022 on the Proposal for a Regulation of the European Parliament and of the Council laying down rules to prevent and combat child sexual abuse

*Source: EDPB, edpb-edps-joint-opinion-042022-on-the-proposal-for-a-regulation-of-en, 2022-07-28 — https://overview.legal/posts/125917 — original: https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-042022-on-the-proposal-for-a-regulation-of_en*

Adopted 2 EDPB-EDPS Joint Opinion 0 4/2022 on the Proposal for a Regulation of the European Parliament and of the Council laying down rules to prevent and combat child sexual abuse Adopted on 28 July 2022 Adopted 3 Adopted 5 Executive Summary On 11 May 2022, the European Commission published a Proposal for a Regulation of the European Parliament and of the Council laying down rules to prevent and combat child sexual abuse. The Proposal would impose qualified obligations on providers of hosting…

### Art. 29 WP Guidelines on GDPR transparency requirements (WP260 rev.01)

*Source: EDPB, edpb-guidelines-on-transparency, 2025-11-21 — https://overview.legal/posts/38076 — original: https://www.edpb.europa.eu/system/files/2023-09/wp260rev01_en.pdf*

The Article 29 Data Protection Working Party issued these guidelines (WP260 rev.01), adopted on 29 November 2017 and last revised on 11 April 2018, to provide interpretive and practical guidance on the transparency requirements under the GDPR (Articles 12–14). The document addresses the form, timing, content, and modalities of information provided to data subjects, including issues such as plain language, layered privacy notices, information for children, and exceptions to the obligation to provide information. No fines or enforcement actions are imposed, as this is a guidance document rather than an enforcement decision.

### Statement 1/2024 on legislative developments regarding the Proposal for a Regulation laying down rules to prevent and combat child sexual abuse

*Source: EDPB, statement-12024-on-legislative-developments-regarding-the-en, 2024-02-14 — https://overview.legal/posts/125769 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-12024-on-legislative-developments-regarding-the_en*

1 Statement 1/2024 on legislative developments regarding the Proposal for a Regulation laying down rules to prevent and combat child sexual abuse Adopted on 13 February 2024 The European Data Protection Board has adopted the following statement: The European Data Protection Board (‘EDPB’) acknowledges the importance of the fight against child sexual abuse online 1 . While it welcomes the recent improvements proposed by the European Parliament 2 that remedy some of the main issues of the…

### Guidelines 03/2022 on Deceptive design patterns in social media platform interfaces: how to recognise and avoid them

*Source: EDPB, edpb-guidelines-on-deceptive-design-patterns-in-social-media-platform-interfaces-how-to-recognise, 2023-02-24 — https://overview.legal/posts/38056 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-032022-on-deceptive-design-patterns-in-social-media-platform_en*

These Guidelines offer practical recommendations to social media providers as controllers of social media, designers and users of social media platforms on how to assess and avoid so-called 'deceptive design patterns' in social media interfaces that infringe on GDPR requirements. To this end, the EDPB recommends  that  controllers  make  use  of  interdisciplinary  teams,  consisting,  among  others,  of designers,  data  protection  officers  and  decision-makers.  It  is  important  to  note  ...

### Guidelines 2/2019 on the processing of personal data under Article 6(1)(b) GDPR in the context of the provision of online services to data subjects

*Source: EDPB, guidelines-22019-on-the-processing-of-personal-data-under-article-61b-gdpr-in-en, 2019-10-16 — https://overview.legal/posts/126202 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-22019-on-the-processing-of-personal-data-under-article-61b-gdpr-in_en*

1 Adopted Guidelines 2/2019 on the processing of personal data under Article 6(1)(b) GDPR in the context of the provision of online services to data subjects Version 2.0 8 October 2019 2 Adopted Version history Version 2.0 8 October 2019 Adoption of the Guidelines after public consultation Version 1.0 9 April 2019 Adoption of the Guidelines for publication consultation 3 Adopted 1 Part 1 – Introduction ................................ ................................…

### Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models

*Source: EDPB, opinion-282024-on-certain-data-protection-aspects-related-to-en, 2024-12-18 — https://overview.legal/posts/125697 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-282024-on-certain-data-protection-aspects-related-to_en*

Adopted 1 Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models Adopted on 17 December 2024 Adopted 2 Executive summary AI technologies create many opportunities and benefits across a wide range of sectors and social activities. By protecting the fundamental right to data protection, GDPR supports these opportunities and promotes other EU fundamental rights, including the right to freedom of thought, expression and information,…

## Enforcement decisions

### AEPD fines El Español for disclosing minor's identity in assault video

*Source: AEPD (Spain), 2026-07-27 — https://overview.legal/posts/184546 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS-00304-2024*

Facts — El León de El Español Publicaciones, S.A., the controller, operates the Spanish digital newspaper „El Español“. It published an article concerning an assault and embedded a video showing both the victim and the assailant, who was a minor. Their image and voice were disclosed without applying techniques to prevent their direct or indirect identification. The controller also published the video through its accounts on two social media platforms. The DPA initiated preliminary investigations ex officio after becoming aware of the dissemination of the video. It ordered the controller, as a precautionary measure, to immediately remove the content from the relevant URLs. The controller subsequently informed the DPA that it had removed the article and prevented access through both external links and its internal search engine. The DPA verified that the video was no longer available through the identified web addresses. The DPA subsequently initiated disciplinary proceedings for a potential infringement of Article 5(1)(c) GDPR. The controller argued that the incident was newsworthy, the video had already gone viral and the publication was protected by freedom of information. It also claimed that the video was necessary to understand the news and that the assailant’s status as a minor should be assessed in light of his apparent maturity and awareness that he was being recorded. Holding — The DPA found that the controller violated the data minimisation principle under Article 5(1)(c) GDPR. The DPA clarified that the proceedings did not concern whether the incident was newsworthy or whether the controller could report on it. Instead, the relevant question was whether publishing the identifiable image and voice of the individuals was necessary and proportionate for that purpose. According to the DPA, freedom of information and the right to data protection are not absolute. Under Article 85 GDPR, they must be reconciled on a case-by-case basis. In this case, the controller could have informed the public about the incident while using technical measures, such as blurring the individuals’ faces or altering the audio, to prevent their identification. Showing the individuals in an identifiable manner was therefore not necessary to achieve the journalistic purpose. The DPA also rejected the argument that the previous virality of the video justified its republication. Each additional publication contributed to the further dissemination of the personal data and amplified the risks and adverse effects for the data subjects. Similarly, the fact that the affected individuals had not submitted a complaint did not prevent the DPA from exercising its supervisory powers ex officio. The DPA gave particular weight to the vulnerability of the victim and to the fact that the assailant was a minor. It held that the best interests and enhanced protection of minors had to be taken into account irrespective of the minor’s alleged maturity or awareness of being recorded. The age at which a minor may consent under Article 7 LOPDGDD did not reduce the controller’s obligation to assess whether the disclosure was necessary. The DPA further noted that, pursuant to Articles 5(2) and 25 GDPR, the controller was required to assess and document the risks of the processing and implement data protection by design and by default. As a professional media organisation regularly processing personal data, the controller was expected to apply a particularly high standard of diligence and to consider less intrusive methods of publication. When determining the sanction, the DPA considered the unrestricted online dissemination of the data, the potentially unlimited audience, the controller’s negligence, the sensitive circumstances surrounding the victim and the minor, and the impact of the infringement on the rights of a minor. It therefore imposed a €20,000 fine. Under Article 58(2)(d) GDPR, the DPA also ordered the controller to demonstrate, within three months after the decision became enforceable, that it had adopted measures to prevent the excessive publication or dissemination of personal data, particularly data concerning minors. It made the earlier precautionary measure definitive and required the permanent removal of the content, while allowing its restricted preservation where necessary as evidence for administrative, police or judicial proceedings.

### Datatilsynet (Denmark) - 2020-431-0061 (Helsingor decision no. 4)

*Source: Datatilsynet (Denmark), 2022-09-28 — https://overview.legal/posts/6313 — original: https://gdprhub.eu/index.php?title=Datatilsynet_(Denmark)_-_2020-431-0061_(Helsingor_decision_no._4)*

Facts — This is the Danish DPA's fourth decision in the case relating to Helsingor municipality's processing of personal data in primary and lower secondary school. Helsingor municipality, the controller, has been using Google Chromebooks and Workspace for Education in violation of several GDPR requirements, as detailed in the first decision of September 2021, the second decision of 14 July 2022 and the third decision of 18 August 2022. Following the third decision, the municipality submitted more documentation and also requested a consultation with the DPA as per Article 36 GDPR. Holding — The DPA temporarily suspended its processing ban against Helsingor municipality until 5 November 2022, and also ordered the municipality to: Change the data processing agreement with Google so that the DPA's remarks in their 14 July and 18 August decisions, are implemented. This includes, at a minimum, a clarification of where and if Google acts as a sole controller and any uncertainties that may entail that Google acts beyond their role as a processor, see Article 28(3)(a) GDPR. Document that all transfers of personal data to insecure third countries, are in line with the GDPR. Describe all data flows and identify the personal data that are shared with the vendor, and clarify when the vendor acts as a sole or joint controller. This documentation must include the whole technology stack used by the municipality (for this processing activity). Update their data protection impact assessment based on all identified risks. Consult the DPA if the DPIA shows any high risks the municipality is not able to mitigate. If any processing activities are still not in line with the GDPR before the DPA's deadline 3 November 2022, present a final plan for bringing them in line with the GDPR.

### Garante per la protezione dei dati personali (Italy) - 9788429

*Source: Garante per la protezione dei dati personali (Italy), 2022-07-07 — https://overview.legal/posts/122853 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_9788429*

Facts — Social media platform TikTok (the controller) provided personalized advertising to its users (the data subjects) on the legal basis of consent (Article 6(1)(a) GDPR). In June 2022, the controller announced that a new privacy policy would come into effect on 13 July 2022. Under the new policy, the controller would only serve personalize advertising to users over 18 years of age and on the legal basis of the legitimate interest of the controller (Article 6(1)(f) GDPR). The Italian DPA started an investigation and found that personalized advertisement would likely involve the use of cookies or other tracking mechanisms. Holding — Regarding the competence of the Italian DPA, it should be noted that the Irish DPA is the lead supervisory authority for the controller’s data processing activities under the GDPR's "one-stop-shop" mechanism. The Italian DPA acknowledged the Irish DPA’s position in its decision. However, the Italian DPA held the ePrivacy Directive to be applicable to the processing of cookies by the controller and held itself competent to enforce the Directive. The DPA referenced Recital 173 GDPR and EDPB Opinion 05/2020 on this point. The DPA held that the controller’s new privacy policy violated Article 5(3) ePrivacy Directive 2002/58/EC. The Article only allows the controller to process cookies and use similar tracking mechanisms with the user’s consent . For this reason, legitimate interest under Article 6(1)(f) GDPR is not a valid legal basis for the processing of cookies. The Italian DPA also held that the controller violated Article 122 of the Italian Privacy Code (d. lgs. 30 giugno 2003, n. 196). Article 122 is a direct transposition of Article 5(3) ePrivacy Directive. The violation of the Code constitutes a direct consequence of the violation of the Directive. The DPA issued a warning against the controller.

### Luka Inc.: Niet-naleving van de algemene principes voor gegevensverwerking.

*Source: Italian Data Protection Authority (Garante), 2025-04-10 — https://overview.legal/posts/52327*

De Italiaanse gegevensbeschermingsautoriteit heeft Luka Inc. een boete van 5.000.000 euro opgelegd. Het bedrijf heeft een chatbot genaamd Replika ontwikkeld, met een tekst- en spraakinterface. Deze chatbot is gebaseerd op een generatief AI-systeem, specifiek een LLM-model, dat voortdurend wordt aangevuld en verbeterd door interacties met gebruikers. Replika is bedoeld als een "virtuele metgezel" die de stemming en het emotionele welzijn van gebruikers verbetert door hen te helpen hun eigen psyche te begrijpen. Replika kan worden ingesteld als een vriend, therapeut, romantische partner of mentor. De controle...

### Italian DPA finds GDPR applies to US-based Character.AI service

*Source: Garante per la protezione dei dati personali (Italy), 2026-07-03 — https://overview.legal/posts/108999 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_487/2026*

Facts — Character Technologies, Inc (the controller) is a company established in the US that operates the site Character.AI. Character.AI is a generative AI service that allows users to create and interact through chat with virtual characters that already exist or are created at the moment. The controller made this available to data subjects in Italian, and had a specific version for children. The DPA initiated an ex-officio investigation in 2024. The DPA requested information related to the LLM models used by the controller, the provision of the service, and data transfers. The controller provided a DPIA, and stated that it introduced an age verification system that required data subjects to register their date of birth. In 2025, the controller announced it would prevent underage data subjects from accessing open chat rooms, and would begin processing personal data of data subjects in the EEA to post-train its generative AI systems. Holding — The DPA first clarified that the GDPR is applicable even if the controller was established outside of the EU, in accordance with Article 3(2) GDPR. The DPA took into account the fact that the service was available in Italy and in Italian, as well as the privacy policy also applying to EEA residents. Given that the controller did not have an establishment in the EU, the one-stop-shop mechanism did not apply and the DPA was competent. The DPA found a violation of Articles 12(1), 13(1) and (2), and 14(1) and (2) GDPR. The DPA considered that the controller had failed to meet its information obligations. In terms of the controller’s privacy policy, the DPA considered that the controller had not provided data subjects’ with clear information regarding its processing activities, data transfers, or data subjects’ right to object and opt out. In addition, the controller failed to designate a representative in the EU, and included misleading and inaccurate statements on the processing of personal data for purposes of post-training LLMs for the service. However, the DPA also took into consideration that the controller had updated its privacy policy to make its language clearer. In terms of its pre-training activities, the DPA stated that the controller had failed to provide adequate information and therefore violated Articles 14(1) and (2) GDPR. The DPA dismissed the controller’s argument that it did not have the obligation to provide this information due to the data being collected by third parties from open sources. The DPA stated that the controller had the obligation to verify whether personal data was present. In addition, the exemption under Article 14(5)(b) GDPR does not exempt the controller from having the obligation to implement appropriate measures to protect data subjects’ rights. However, the DPA did not find a violation of Articles 21(1) and (4). The DPA referred to the EDPB opinion on processing personal data in relation to AI systems. The EDPB recommended controllers to adopt measures for data subjects to exercise their rights, including providing the option to provide data subjects with the option to object unconditionally before the processing takes place. The DPA considered that this opinion went beyond the literal wording of Articles 14 and 21 GDPR. This interpretation could not, in the DPA’s view, be interpreted retroactively to the controller’s processing activities. The DPA found a violation of Articles 24(1) and 25(2) GDPR. The DPA considered that the controller had failed to implement adequate technical and organisational measures to verify data subjects’ age. During its investigations, the DPA found that the controller’s age verification systems were not effective, as they allowed data subjects’ to access the service even after self declaring to be younger than the minimum age limit set by the controller. The DPA also found that the accounts were set to public by default. Therefore, the controller had failed to implement appropriate measures to protect underage data subjects, even if the GDPR does not set a harmonised and binding standard in relation to age verification. The DPA also found a violation of Articles 5(2) and 35 GDPR. Under Article 5(2) GDPR, the controller has the obligation to proactively demonstrate compliance with the GDPR. The DPA stated that a key tool to do this is through data protection impact assessments (DPIAs). Controllers are obliged to carry out a DPIA under Article 35 GDPR if the processing is likely to result in a high to the rights and freedoms of data subjects. The controller failed to do a DPIA on time in relation to providing the service to underage data subjects, as well as in relation to its processing activities for the purpose of pre-training its LLM. The DPA stated that the controller should have done this before launching the service in 2022, as the processing activities had a presumed high risk to freedoms and rights of data subjects (e.g. the use of large scale processing or processing data of vulnerable data subjects). However, the DPA acknowledged that the controller progressively improved its compliance by doing a (late) DPIA and updating it. Finally, the DPA found a violation of Article 27(1) GDPR, as the controller belatedly designated a representative in the EU. The DPA stated that the exemption under Article 27(2) GDPR did not apply. The DPA fined the controller €158,000. The DPA also ordered the controller to bring its privacy policy and storage of personal data for purposes of pre-training its LLM into compliance with the GDPR. The DPA also ordered the controller to implement effective age verification mechanisms.

### AEPD fines Alkora, S.A. for ransomware breach exposing 40,000 individuals' data

*Source: AEPD (Spain), 2026-07-16 — https://overview.legal/posts/53655 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS-00020-2025*

Facts — Alkora, S.A., the controller, is an insurance broker that was victim of a ransomware attack. The controller notified the DPA of a personal data breach after a ransomware attack affected its servers, databases, email systems and employee devices. The controller first estimated that 25,000 persons were affected. It later stated that the incident had affected around 40,000 persons, including 75 minors. The incident affected confidentiality, availability and integrity. The attacker encrypted systems and exfiltrated between 3.5 and 4 TB of information from the document management server. The affected data included identification and contact data, ID numbers, dates of birth, financial and insurance data, bank account numbers, health data, employee data and access credentials. The controller also processed data relating to minors in accident claims. A data subject complained to the DPA after being informed that their personal data had been exposed. The data subject was concerned about identity theft and requested additional information from the controller. During the investigation, the DPA found that the controller had known that its IT systems faced an extreme cybercrime risk before the breach. The forensic report could not determine the initial entry point because the servers had been encrypted, but it showed that attackers could move laterally through the infrastructure, obtain privileged access, install tools, exfiltrate data and encrypt systems. The controller had carried out a risk analysis in 2019, but this document concluded that no DPIA was necessary. After the breach, a later analysis found that a DPIA was necessary for treatments involving health data and minors. The controller did not prove that it had carried out the required DPIA. Holding — The DPA held that the controller violated Article 5(1)(f) GDPR. It considered that the controller had failed to ensure the integrity and confidentiality of the personal data under its responsibility. The DPA emphasised that the principle in Article 5(1)(f) GDPR is not limited to the existence of isolated security measures. Rather, the controller must implement adequate technical and organisational measures capable of ensuring that personal data is protected against unauthorised or unlawful processing, loss, destruction or damage. The DPA rejected the controller’s argument that the attack was an external criminal act that could not be attributed to it. The DPA found that the controller was aware of an extreme cyber risk and that its internal vulnerabilities and security posture allowed the attackers to move through the systems, access personal data and encrypt files. The DPA therefore considered that the controller’s measures were clearly insufficient. The DPA also held that the controller violated Article 35 GDPR. The controller processed high-risk categories of data, including health data and data concerning minors. In these circumstances, it should have carried out a DPIA before the processing. The DPA found that the controller’s 2019 risk analysis wrongly concluded that no high risk existed, while its later documentation acknowledged that a DPIA was necessary. The DPA proposed a fine of €150,000 for the infringement of Article 5(1)(f) GDPR and €100,000 for the infringement of Article 35 GDPR, totalling €250,000. The controller paid voluntarily without acknowledging liability, obtaining a 20% reduction under Spanish Administrative Law (39/2015). The final payable amount was therefore €200,000. The DPA also ordered the controller, under Article 58(2)(d) GDPR, to prove within three months from the enforceability of the decision that it had carried out the mandatory DPIA required under Article 35 GDPR.

### Luka Inc.: Non-compliance with general data processing principles

*Source: Italian Data Protection Authority (Garante), 2025-04-10 — https://overview.legal/posts/48726 — original: https://www.enforcementtracker.com/ETid-2611*

The Italian DPA imposed a fine of EUR 5,000,000 on Luka Inc. The developer created a chatbot called Replika with a written and voice interface. It is based on a generative AI system, specifically an LLM model, that is constantly fed and improved by user interactions. Replika is intended to be a 'virtual companion' that improves users' moods and emotional well-being by helping them understand their own psyche. Replika can be set up as a friend, therapist, romantic partner, or mentor. The controll

### CNIL rejects Google's stay request and ne bis in idem challenge in cookie consent case

*Source: CNIL (France), 2021-12-31 — https://overview.legal/posts/125662 — original: https://gdprhub.eu/index.php?title=CNIL_(France)_-_SAN-2021-023*

Facts — Google LLC is a subsidiary owned wholly by Alphabet Inc. Google Ireland Limited ('GIL') "presents itself" as the headquarters for the Google group's operations in the EEA and Switzerland. In March 2020 the French DPA (CNIL) carried out an online inspection of the website "google.fr" in the context of a previous procedure against Google LLC and GIL. The purpose of this inspection was to verify their compliance with the Loi 'Informatique et Libertés', and in particular with Article 82 thereof. This resulted in this decision, that Google appealed. Following this decision, the CNIL received more complaints about the methods of refusing cookies from the website "google.fr". It therefore reopened the case and launched a new investigation. Holding — On the request for a stay of proceedings — First, the companies requested that per Article 66 of the CNIL's rules of procedure, the CNIL stay these proceedings pending the decision to be handed down by the Council of State in the appeal against its first decision against Google and pending the conclusions of the new EDPB working group on cookies. The CNIL rejected this request, as it considered that there were no acceptable grounds for staying the proceedings. On the complaint alleging breach of the ne bis in idem principle — Second, the companies argued that the restricted formation cannot rule again on the same facts as those concerned by deliberations No. SAN-2020-012 and No. SAN-2021-004, without violating the ne bis in idem principle, as it considered the parties and material facts in those case to be identical. The CNIL responded that the two procedures do not concern the same facts, as these cases included an injunction relating to the information of users on the purposes of cookies subject to consent and on the means available to refuse cookies, whereas the one at hand concerned the refusal methods themselves, and not only the information. It also highlighted that this procedure concerned both the websites "google.fr" and "youtube.com", whereas the previous procedure concerned only the website "google.fr". As such, the CNIL rejected the complaint based on the violation of the ne bis in idem principle. On the competence of the CNIL — The material competence of the CNIL and the non-application of the "one-stop shop" mechanism provided for by the GDPR — The processing operations investigated by the CNIL in this case were carried out in the context of the provision of publicly available electronic communications services via a public electronic communications network offered within the European Union. As such, it considered they fell within the material scope of the ePrivacy Directive. Article 5(3) of that directive was transposed into domestic law through Article 82 of the French Data Protection Act. The CNIL therefore considered itself materially competent under these provisions to monitor and sanction the access or registration of information by companies in the terminals of users of the "google.fr" and "youtube.com" websites in France. The companies contested the jurisdiction of the CNIL. They argued they should be subject to the procedural framework provided for by the GDPR, or the 'one-stop shop' mechanism, under which the Irish DPA (DPC) would be the lead supervisory authority (LSA). They considered that the absence of specific rules on determining the competence of the supervisory authority in the case of cross-border processing operations falling within the scope of the ePrivacy Directive should be replaced by the application of the procedural framework provided for by the GDPR. Interestingly, the companies further argued that the EDPB's announcement regarding the creation of a working group on cookie banners in response to the significant number of complaints recently filed with supervisory authorities by noyb was evidence that the EDPB considers that cookie-related breaches fall directly within the scope of the GDPR and, therefore, the 'one-stop shop' mechanism. First, the CNIL responded that a distinction should be made between, on the one hand, the operations consisting in depositing and reading a cookie on a user's terminal and, on the other hand, the subsequent use that is made of the data generated by these cookies ("subsequent/further processing"). The former are governed by special rules, set by the ePrivacy Directive - in this case, by its Article 5(3) - and transposed into national law, the latter is governed by the GDPR and, as such, may be subject to the "one-stop-shop" mechanism in the event that they are cross-border. This case only concerned the read and write operations carried out on the terminal of the user located in France visiting the Google Search and YouTube search engines. Second, it held that where a processing operation may fall within both the material scope of the ePrivacy Directive and the material scope of the GDPR, reference should be made to the relevant provisions of the two texts which provide for their articulation. The rule laid down in Article 5(3) of the ePrivacy Directive, according to which reading and/or writing operations must systematically be subject to the prior consent of the user, after having been informed, constitutes a special rule with regard to the GDPR, since it prohibits the legal bases mentioned in Article 6 GDPR from being invoked in order to be able to lawfully carry them out. The control of this rule is therefore a matter for the special control and sanction mechanism provided for by the ePrivacy Directive, and not for the data protection authorities and the EDPB under the GDPR. It stated that the French legislator entrusted this task to the CNIL. Thus, the "one-stop shop" mechanism provided for by the GDPR could not be applied to the processing operations covered by the Directive, as the companies claimed. Third, the CNIL confirmed that the 'one-stop-shop' mechanism is not applicable to facts that are materially covered by the ePrivacy Directive, by referring to the Opinion No 5/2019 of the EDPB and the CJEU decision C-645/19 (Facebook Belgium) upholding this opinion. Finally, the CNIL stated that the creation of a working group on cookies in response to the large number of complaints filed by noyb did not mean that the EDPB considered that all violations related to cookies necessarily fall within the scope of the GDPR. Furthermore, pursuant to Article 70(1)(u) GDPR, one of the EDPS's tasks is to promote cooperation and the effective bilateral and multilateral exchange of information and best practices between supervisory authorities. The purpose of the working party was thus only to exchange views on the analysis of the numerous complaints lodged by noyb . Thus, the CNIL held that the "one-stop shop" mechanism provided for by the GDPR was not applicable to the present procedure and that it was competent to control and sanction processing operations consisting of reading and/or writing information in the terminal of users located in France implemented by companies falling within the scope of the "ePrivacy" Directive, provided that they fall within its territorial jurisdiction. On the territorial jurisdiction of the CNIL — The CNIL considered it was territorially competent under Article 3 GDPR since the processing that was the subject of the present procedure, namely consisting of accessing or recording information on the terminals of users residing in France when using the Google Search engine and YouTube, in particular for advertising purposes, was carried out within the "framework of the activities" of the company Google France, which constituted the "establishment" of the Google group in France. In response, Google argued that its establishment in the EU was located in Ireland. The CNIL considered a range of CJEU case law (included but not limited to Google Spain C-131/12, Weltimmo C-230/14) and its findings in the previous decision SAN-2020-012, which pointed towards a broad interpretation of 'establishment' and 'in the context of the activities' and rejected this argument. As such, it held that French law was applicable and that it was materially and territorially competent to exercise its powers, including the power to impose sanctions on processing operations falling within the scope of the ePrivacy Directive. The determination of the controller — The CNIL held that Google LLC and Google Ireland Limited jointly determined the purposes and means of the processing consisting of accessing or recording information in the terminal of users residing in France when using the Google Search engine and YouTube. On the failure to comply with the obligations relating to cookies — The CNIL finally assessed whether the companies had complied with Article 82 of the French Data Protection Act. It noted that, in order to give consent to the reading and/or writing of information on their terminal, users visiting the home page of the sites "google.fr" and "youtube.com" only had to click on the "I accept" button on the pop-up window, which made the window disappear and allowed them to continue browsing. On the other hand, the users going to these same home pages and wishing to refuse cookies had to click on the "Personalise" button of this first window, which took them to an interface on both the "google.fr" and "youtube.com" sites, offering them the choice of activating or deactivating cookies, on which they had the possibility of carrying out various actions. The investigator for the CNIL considered that making the mechanism for refusing cookies more complex than the one for accepting them amounted to discouraging users from refusing cookies and encouraging them to opt for the "I accept" button. This led to their conclusion that the methods of refusing cookies implemented by the companies on the sites "google.fr" and "youtube.com" did not comply with the provisions of Article 82 of the French Data Protection Act, as clarified by the enhanced consent requirements set out in the GDPR. In response, the companies argued that neither the ePrivacy Directive, nor the RGPD, nor Article 82 of the Data Protection Act provided that the action of refusing cookies should be as simple as accepting them. "They [also added] that, for many years, the CNIL itself had not deduced this principle even though the regulations in question had remained unchanged since the RGPD came into force. They point out that the CNIL cannot, through its guidelines and recommendations, introduce new requirements relating to the refusal of consent and consider that it is up to each data controller to choose the most appropriate method of obtaining consent." The CNIL rejected this, restating its powers, which include drawing up and publishing guidelines, recommendations or benchmarks intended to facilitate the compliance of personal data processing with the texts relating to the protection of personal data. It was in this context the DPA had issued its previous deliberations which provided guidance to stakeholders on the implementation of concrete measures to ensure compliance with these provisions, so that they implemented these measures or measures of equivalent effect. Indeed, the guidelines' main purpose "is to recall and clarify the law applicable to the reading and/or writing of information [...] in the subscriber's or user's electronic communications terminal equipment, and in particular to the use of cookies". It thus considered that it had not created any new obligations for the actors in its recommendation, but has limited itself to illustrating in concrete terms how Article 82 of the law should be applied. The position according to which it must be as simple for users to refuse cookies as to consent to them was even endorsed by the French Council of State in CE, 19 June 2020, No. 434684, pt 15. Further, the CNIL highlighted that users residing in France who visit the Google Search engine and/or YouTube had to perform a single action to accept cookies, whereas they had to perform five to refuse them. It was therefore not as simple to refuse cookies as to accept them. It referred to studies that showed that having a "refuse all" button on the first-level consent interface led to a decrease in the rate of consent to accept cookies. It therefore considered that making the mechanism for refusing cookies more complex than the one for accepting them actually discourages users from refusing cookies and encourages them to prefer the ease of the "accept all" button. "In view of the above, the [CNIL held] that there [had] been a breach of the provisions of Article 82 of the [French] Data Protection Act, interpreted in the light of the GDPR, insofar as the companies [did] not provide users located in France, on the websites "google.fr" and "youtube.com", with a means of refusing to read and/or write information to their terminal that is as simple as the one provided for accepting its use. Thus, the CNIL: imposed a fine of €90,000,000 on Google LLC for failing to comply with Article 82 of the French Data Protection Act, imposed a fine of €60,000,000 on Google Ireland Limited for failing to comply with Article 82 of the French Data Protection Act, ordered Google LLC and Google Ireland Limited to modify, on the websites "google.fr" and "youtube.com", the methods for obtaining the consent of users located in France to the reading and/or writing of information in their terminal, by offering them a means of refusing these operations that is as simple as the mechanism provided for their acceptance, in order to guarantee the freedom of their consent; attached to the injunction a penalty of 100,000 euros (one hundred thousand euros) per day of delay at the end of a period of three months following notification of this decision, with proof of compliance to be sent to the restricted panel within this period; made its decision public on the CNIL website and on the Légifrance website, which will no longer identify the companies by name at the end of a two-year period from the date of its publication.

## Recent developments

### noyb win: Microsoft ordered to stop tracking school children

*Source: noyb - European Center for Digital Rights, 2026-01-27 — https://overview.legal/posts/52487 — original: https://noyb.eu/en/noyb-win-microsoft-ordered-stop-tracking-school-children*

Data Subject Rights noyb has scored another win in its proceedings against Microsoft 365 Education: The Austrian data protection authority (DSB) has decided that the company illegally installed cookies on the devices of a pupil without consent. According to Microsoft’s own documentation, these cookies analyse user behaviour, collect browser data and are used for advertising. Microsoft now has four weeks to comply and cease the use of tracking cookies. Decision by the Austrian DSB (DE)PR for prev

### noyb win: Microsoft 365 Education may not track school children

*Source: noyb - European Center for Digital Rights, 2025-10-09 — https://overview.legal/posts/53134 — original: https://noyb.eu/en/noyb-win-microsoft-365-education-tracks-school-children*

Data Subject Rights The Austrian Data Protection Authority ("DSB") issued a decision finding that Microsoft 365 Education illegally tracks students and uses student data for Microsoft's own purposes. The software giant also did not answer an access request related to Microsoft 365 Education, which is widely used in European schools. Instead, Microsoft tried to shift all responsibility to local schools. While the relevant schools also have to provide more detailed access data and additional priva

### Het EDPB en het EDPS: Het voorstel om online seksueel misbruik van kinderen te bestrijden, brengt serieuze risico's met zich mee voor fundamentele rechten.

*Source: EDPS, 2022-07-29 — https://overview.legal/posts/51845*

De Europese Autoriteit voor gegevensbescherming (EDPB) en de Europese Toezichthouder op het gebied van gegevensbescherming (EDPS) hebben een gezamenlijk advies aangenomen over het voorstel voor een verordening ter bestrijding van seksueel misbruik van kinderen.

### Europese Commissie presenteert nieuwe regels om seksueel misbruik van kinderen op internet te voorkomen en te bestrijden

*Source: NL EU Court Expert, 2022-05-13 — https://overview.legal/posts/6305 — original: https://ecer.minbuza.nl/-/europese-commissie-presenteert-nieuwe-regels-om-seksueel-misbruik-van-kinderen-op-internet-te-voorkomen-en-te-bestrijden?redirect=%2Fecer%2Fnieuws%3Fq%3Dprivacy%2520OR%2520avg%26f%3D%26t%3D#entry-304*

The proposed rules would require online service providers to detect, report and remove child sexual abuse material on their services. Those providers must also assess the risk of their services being used to distribute child sexual abuse material. A new European Center on Child Sexual Abuse will provide support to providers, law enforcement and victims.

### Initiatiefnota van de leden Ceder en Six Dijkstra over online kinderrechten.

*Source: Government, 2025-04-09 — https://overview.legal/posts/50732 — original: https://www.tweedekamer.nl/kamerstukken/kamervragen/detail?id=2025D14141&amp;did=2025D14141*

Kamerstukken II 2024–2025, 36 719, nr. 2 Initiatiefnota van de leden Ceder en Six Dijkstra over online kinderrechten. Drie specifieke voorstellen trekken de aandacht : (1) Kom met een proof of concept voor online leeftijdsverificatie, (2) Introduceer een «rode knop» voor gegevenswissing, (6) Betr...

## Literature

### Children and the Artificial Intelligence Act: Is the EU Legislator Doing Enough?

*Source: European Law Blog, 2023-09-12 — https://overview.legal/posts/132444 — original: https://doi.org/10.21428/9885764c.799b4d2d*

### Legal concerns regarding the protection of minors’ personal data in compliance with national legislation and GDPR requirements

*Source: ScienceRise: Juridical Science, 2023-09-13 — https://overview.legal/posts/132533 — original: https://doi.org/10.15587/2523-4153.2023.286647*

The article highlights the legal concerns surrounding the protection of minors' personal data. The writers have conducted an original study of the sources regulating civil and labor relations in the field of acquiring and using personal data. The expansion and use of information technology and online communications can potentially lead to the violation of personal rights by the owners of personal data, both in workplace settings and in the daily lives of ordinary residents. The purpose of this a

### Collective Damages for GDPR Breaches: A Feasible solution for the GDPR Enforcement Deficit?

*Source: European Data Protection Law Review, 2022-01-01 — https://overview.legal/posts/132504 — original: https://doi.org/10.21552/edpl/2022/4/8*

### GDPR ve KVKK Bakımından Çocukların Kişisel Verilerinin Korunması ve Konuya İlişkin Kurul Kararının Değerlendirilmesi (Protecting Personal Data Of Children From Point Of GDPR and Personal Data Protection Law and Review Of Assize)

*Source: SSRN Electronic Journal, 2021-01-01 — https://overview.legal/posts/132476 — original: https://doi.org/10.2139/ssrn.3792410*

### GDPR Implementation Series ∙ Netherlands: The GDPR Implementation Act

*Source: European Data Protection Law Review, 2018-01-01 — https://overview.legal/posts/132478 — original: https://doi.org/10.21552/edpl/2018/3/15*

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Law Enforcement** — https://overview.legal/topics/law-enforcement
  Processing for law enforcement purposes
- **Human Resources** — https://overview.legal/topics/human-resources
  Processing of employee and HR data
- **Public Authority** — https://overview.legal/topics/overheid
  Government bodies and their data processing activities
- **Consent** — https://overview.legal/topics/toestemming
  Freely given, specific, informed indication of data subject wishes
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data

---
Generated by overview.legal · https://overview.legal/topics/minderjarigen · 2026-08-22
