# Monitoring — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/monitoring
> Sources are cited per item. Verify against the official texts before relying on them.

Systematic observation and tracking of individuals

## Overview

## Legal Framework

Monitoring of individuals triggers several GDPR provisions. [Article 3(2)(b)](/laws/gdpr/art-3#par-2-pnt-b) extends the Regulation's territorial reach to controllers outside the EU that monitor the behaviour of data subjects within the Union — a provision that anchors the GDPR's extraterritorial grip on cross-border tracking and surveillance.

> "the monitoring of their behaviour as far as their behaviour takes place within the Union."
> — [GDPR Art. 3(2)(b)](/laws/gdpr/art-3#par-2-pnt-b)

Where monitoring is systematic and large-scale, it also drives mandatory organisational obligations. [Article 37(1)(b)](/laws/gdpr/art-37#par-1-pnt-b) requires designation of a Data Protection Officer when the controller's core activities consist of "regular and systematic monitoring of data subjects on a large scale." Similarly, [Article 35(3)(c)](/laws/gdpr/art-35#par-3-pnt-c) mandates a Data Protection Impact Assessment for "a systematic monitoring of a publicly accessible area on a large scale." [Article 23(1)(h)](/laws/gdpr/art-23#par-1-pnt-h) permits Member States to restrict GDPR rights for monitoring functions connected to the exercise of official authority, but only where proportionate and necessary in a democratic society.

## Key Developments

The CJEU's ruling in *WORTEN* clarifies that monitoring by public authorities — in that case, inspection of working-time records — must be narrowly tailored to the legal obligation being enforced. The Court held that access to personal data by a national monitoring authority is permissible only where the authority genuinely holds powers in that specific field.

> "only the grant of access to authorities having powers in that field could be considered to be necessary within the meaning of Article 7(e) of Directive 95/46"
> — [WORTEN ¶36](/posts/5968#seg-36)

The Court also acknowledged that employer surveillance measures may be justified as "measures necessary" to ensure compliance with working-time directives, but the employer in *WORTEN* argued the interference was excessive — illustrating that even lawful monitoring must survive a proportionality test. Enforcement actions reinforce this: the Spanish DPA sanctioned a controller for surveillance cameras facing public highways without authorisation, and the Italian Garante fined an agency €50,000 for remote-work monitoring that lacked adequate safeguards.

## Status of the Debate

This topic is actively contested in court. The boundaries of lawful monitoring are not settled: courts diverge on what constitutes "systematic" and "large-scale" monitoring under [Article 35(3)(c)](/laws/gdpr/art-35#par-3-pnt-c), and on how proportionality should be calibrated when monitoring serves a legitimate regulatory or employer interest. The *WORTEN* line of authority provides a necessity-and-proportionality framework, but later enforcement decisions — particularly on workplace surveillance and CCTV — apply it inconsistently. What would resolve the open question is further CJEU guidance on the threshold for "regular and systematic" monitoring under [Article 37(1)(b)](/laws/gdpr/art-37#par-1-pnt-b) and on the proportionality limits of employee monitoring under legitimate-interest grounds.

## Practical Guidance

- **Assess scale and systematicity early.** Determine whether your monitoring qualifies as "regular and systematic" and "large scale" under [Article 37(1)(b)](/laws/gdpr/art-37#par-1-pnt-b); if so, appoint a DPO before processing begins.
- **Conduct a DPIA for large-scale public-area monitoring.** [Article 35(3)(c)](/laws/gdpr/art-35#par-3-pnt-c) makes this mandatory; document the necessity and proportionality analysis in writing.
- **Limit access to data collected through monitoring.** Following *WORTEN*, ensure that only authorities or personnel with a genuine remit in the relevant field can access monitoring data — broad access undermines the necessity justification.
- **Check extraterritorial exposure.** If your organisation is outside the EU but monitors behaviour of individuals in the Union, [Article 3(2)(b)](/laws/gdpr/art-3#par-2-pnt-b) applies; designate an EU representative under Article 27.
- **Document proportionality for workplace monitoring.** Employer surveillance must be the least intrusive means of achieving the stated objective; the Italian Garante's €50,000 fine demonstrates that blanket remote-work monitoring without targeted safeguards will not withstand scrutiny.

## Legislation (full text of key provisions)

### Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems

*Source: AI Act, aiact-art-72-en, 2024-06-12 — https://overview.legal/posts/93175*

### Market surveillance and control of AI systems in the Union market

*Source: AI Act, aiact-art-74-en, 2024-06-12 — https://overview.legal/posts/93215*

### Mutual assistance, market surveillance and control of general-purpose AI systems

*Source: AI Act, aiact-art-75-en, 2024-06-12 — https://overview.legal/posts/93253*

### No general monitoring or active fact-finding obligations

*Source: DSA, dsa-art-8-en, 2022-10-19 — https://overview.legal/posts/94138*

No general obligation to monitor the information which providers of intermediary services transmit or store, nor actively to seek facts or circumstances indicating illegal activity shall be imposed on those providers.

### Monitoring of approved codes of conduct

*Source: GDPR, gdpr-art-41-en, 2016-04-27 — https://overview.legal/posts/90790*

### Supervision of testing in real world conditions by market surveillance authorities

*Source: AI Act, aiact-art-76-en, 2024-06-12 — https://overview.legal/posts/93261*

### Right to lodge a complaint with a market surveillance authority

*Source: AI Act, aiact-art-85-en, 2024-06-12 — https://overview.legal/posts/93389*

Without prejudice to other administrative or judicial remedies, any natural or legal person having grounds to consider that there has been an infringement of the provisions of this Regulation may submit complaints to the relevant market surveillance authority.In accordance with Regulation (EU) 2019/1020, such complaints shall be taken into account for the purpose of conducting market surveillance activities, and shall be handled in line with the dedicated procedures established therefor by the market surveillance authorities.

### Monitoring actions

*Source: AI Act, aiact-art-89-en, 2024-06-12 — https://overview.legal/posts/93407*

### Monitoring actions

*Source: DSA, dsa-art-72-en, 2022-10-19 — https://overview.legal/posts/95178*

### Recital 159 — biometric AI surveillance authority powers

*Source: AI Act, aiact-rec-159-en, 2024-06-12 — https://overview.legal/posts/94000*

Each market surveillance authority for high-risk AI systems in the area of biometrics, as listed in an annex to this Regulation insofar as those systems are used for the purposes of law enforcement, migration, asylum and border control management, or the administration of justice and democratic processes, should have effective investigative and corrective powers, including at least the power to obtain access to all personal data that are being processed and to all information necessary for the performance of its tasks. The market surveillance authorities should be able to exercise their powers by acting with complete independence. Any limitations of their access to sensitive operational data under this Regulation should be without prejudice to the powers conferred to them by Directive (EU) 2016/680. No exclusion on disclosing data to national data protection authorities under this Regulation should affect the current or future powers of those authorities beyond the scope of this Regulation.

## Case law

### Judgment of the General Court (Sixth Chamber, Extended Composition) of 8 January 2025.#Thomas Bindl v European Commission.#Processing of personal data – Protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies – Regulation (EU) 2018/1725 – Concept of ‘transfer of personal data to a third country’ – Transfer of data when visiting a website – EU Login – Action for annulment – Act not open to challenge – Inadmissibility – A

*Source: General Court, T-354/22, 2025-01-08 — https://overview.legal/posts/132155 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022TJ0354*

In Case T-354/22, Thomas Bindl sought annulment of alleged personal data transfers to third countries by the European Commission when visiting the Conference on the Future of Europe website, a declaration of failure to act on his information request, and EUR 1,200 in damages for non-material harm under Regulation (EU) 2018/1725. The General Court found the annulment action inadmissible as the alleged transfers did not constitute a challengeable act, declared there was no need to adjudicate the failure-to-act claim since the Commission had subsequently responded, and dismissed the damages claim for lack of a sufficiently serious breach and causal link. No fine was imposed.

### Judgment of the Court (Third Chamber) of 16 January 2019.#Deutsche Post AG v Hauptzollamt Köln.#Request for a preliminary ruling from the Finanzgericht Düsseldorf.#Reference for a preliminary ruling — Customs union — The Union Customs Code — Article 39 — Status of authorised economic operator — Implementing Regulation (EU) 2015/2447 — The second subparagraph of Article 24(1) — Applicant not a natural person — Questionnaire — Collection of personal data — Directive 95/46/EC — Articles 6 and 7 — R

*Source: Court of Justice of the European Union, C-496/17, 2019-01-16 — https://overview.legal/posts/132339 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62017CJ0496*

In a preliminary ruling arising from proceedings between Deutsche Post AG and the Hauptzollamt Köln, the Court of Justice of the European Union interpreted the second subparagraph of Article 24(1) of Implementing Regulation (EU) 2015/2447 regarding the scope of personal data that must be disclosed when a legal entity applies for authorised economic operator (AEO) status under the Union Customs Code. The Court held that customs authorities may require applicants that are not natural persons to submit personal data concerning individuals linked to the applicant—specifically those in charge of management or customs matters—to the extent such collection complies with the data minimisation principles of Directive 95/46/EC and Regulation 2016/679 (GDPR), meaning the requirement must be limited to what is necessary and proportionate for assessing the absence of serious customs or criminal infringements. No fine was imposed.

### TSJ PV: Accidental Teams recordings after meetings ended cannot justify trust-based

*Source: High Court of Justice of the Basque Country, 2026-07-17 — https://overview.legal/posts/53074 — original: https://gdprhub.eu/index.php?title=TSJ_PV_-_1713/2026*

Facts — The data subject had worked for Fineco Sociedad de Valores, SA and GIIC Fineco Sociedad Gestora de Instituciones de Inversión Colectiva, SAU, the controller, since 2004. The data subject held a senior position and was presented externally as responsible for fixed income management. In May and June 2024, several work meetings took place via Microsoft Teams. After some of these meetings had ended, one participant failed to deactivate Teams correctly. As a result, the system continued recording for several hours conversations which no longer formed part of any professional meeting. The conversations involved the data subject, the former CEO and another board member. The participants were unaware that they were still being recorded. During the conversations, they discussed, among other matters, possible strategies connected to substantial changes in working conditions and compensation. The recordings were automatically stored in the company’s Teams environment. Months later, the new management accessed the recordings. In January 2025, the controller held a meeting with the data subject and referred to extracts of the recordings, stating that their content had affected the trust placed in her. The data subject questioned the legality of the recordings. The data subject brought a labour claim seeking judicial termination of her employment contract for serious breach by the controller. She argued that the controller had accessed and used private conversations obtained without her knowledge or consent, thereby infringing her rights to privacy, secrecy of communications and personal data protection. The Social Court No. 9 of Bilbao dismissed the claim. It considered the recordings admissible as evidence, rejected the alleged violation of fundamental rights and imposed a €4,500 penalty on the data subject for bad faith and procedural recklessness. The data subject appealed before the Court. Holding — The Court partially upheld the appeal. The Court departed from the first instance court’s reasoning on the key issue of admissibility. The first instance court had held that the recordings were admissible because they had been generated after another participant failed to deactivate Teams. By contrast, the Court held that this mistake could not remove the data subject’s reasonable expectation of privacy. The Court found that the data subject had not been informed that Teams continued recording after the meetings had ended, had not consented to it and had not caused the technical error. The conversations took place after the professional meetings had ended and the participants believed that they were speaking privately. The controller had not shown any prior policy or information allowing it to access and use such recordings for employment purposes. The Court therefore held that the controller infringed the data subject’s rights to privacy and secrecy of communications under Articles 18.1 and 18.3 of the Spanish Constitution, read together with Article 18.4 of the Spanish Constitution, Article 8 ECHR and Article 7 CFR and Article 8 CFR . It also relied on Articles 87, 88 and 89 LOPDGDD and the Workers’ Statute rules on digital rights at work, which require prior information, proportionality and respect for workers’ privacy. The Court clarified that the relevant breach was not merely the accidental creation of the recordings, but the controller’s subsequent access to and use of them in the employment relationship. The recordings could not be used as evidence against the data subject because they had been obtained and used in breach of fundamental rights. However, this did not prevent the Court from assessing the controller’s own conduct, namely that it had accessed the recordings and relied on them in the meeting with the data subject. On that basis, the Court found a serious breach by the controller and granted the data subject’s request to terminate the employment contract for cause under Article 50.1(c) of the Spanish Workers’ Statute. It ordered the controller to pay €328,491.62 as statutory compensation for the termination of the employment relationship. The Court also awarded €7,501 as compensation for moral damages caused by the violation of the data subject’s fundamental rights. It did not award the €100,000 requested by the data subject, considering that the initial recording was accidental and that the controller had not installed a deliberate surveillance system. No administrative fine or GDPR corrective measure was imposed, as this was a labour court case rather than a DPA enforcement procedure.

### Digital Rights Ireland Ltd v Minister for Communications

*Source: CJEU, C-293/12, 2014-04-08 — https://overview.legal/posts/51474 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62012CJ0293&ref=51474*

Invalidated Data Retention Directive as incompatible with fundamental rights.

### PHR - 22/01253

*Source: Supreme Court of the Netherlands, 2022-08-26 — https://overview.legal/posts/125598 — original: https://gdprhub.eu/index.php?title=PHR_-_22/01253*

Facts — A patient (the data subject) was treated in a hospital. Because she believed that an error had been made, she held the hospital liable. The hospital involved its liability insurer. On behalf of this liability insurer, a doctor from another hospital assessed the data subject's medical file. He checked whether the treatment had been carried out correctly. This doctor did not see the data subject nor was she involved in the investigation in any other way. The data subject found out that this other doctor had made an assessment of the treatment and tried to get access to the findings. The doctor who made the assessment refused her access. The data subject then filed a disciplinary complaint against this doctor with the Regional Medical Disciplinary Tribunal. The Regional Tribunal declared the complaint unfounded. The data subject appealed against this decision to the Central Medical Disciplinary Tribunal. The data subject argued that she should get access to the medical assessment based on the inspection rights from the Medical Treatment Contracts Act (MTCA) laid down in the Dutch Civil Code (article 7:456 BW). However, the Central Tribunal held that the data subject could not appeal to these rights, as an exception in the MTCA was applicable (article 7:464 BW). According to the Central Tribunal, the nature of the legal relationship (the trial) between the data subject and the hospital opposed this. It explained that the hospital had the right to prepare their defence against the data subject's liability claim 'in freedom and seclusion'. In that context, they must also be able to call in another doctor to assess the course of treatment, without the data subject being able to inspect the findings. The Central Tribunal therefore held that there was no obligation to make the medical assessment available to the data subject and declared the complaint unfounded. As a rule, decisions of the Central Tribunal cannot be appealed. However, cassation is possible if it is in the interests of the law at the Procurator General (PG) of the Supreme Court. This is what happened in the present case. Holding — The PG of the Supreme Court agreed with the Central Tribunal that the patient had no right of access. However, it held that the legal grounds used to substitute the decision were incorrect. According to the PG, the Central Tribunal misapplied various provisions of the MTCA. The PG noted that for the MTCA to be applicable, there must be an 'act in the field of medicine'. An assessment by a doctor solely based on a medical file, as in this case, did not involve such an act. To this end, the PG considered it important that the doctor did not treat, assess or examine the data subject, but only carried out a 'paper exercise' on her medical data. The PG thus held that the MTCA was, contrary to what the Central Tribunal had assumed, not applicable. Consequently, the data subject could not derive a right to inspect from the MTCA (and the hospital could not have appealed to the exception). Next, the PG examined whether the data subject may be entitled to access the medical assessment on the basis of a different regulation. In doing so, the PR looked at the GDPR. It held that a medical assessment qualifies as personal data and is thus subject to the GDPR. In principle, the data subject had a right to access her personal data in that assessment pursuant to Article 15(1) GDPR. However, Article 23(1)(i) GDPR and Article 41 UAVG provide the possibility of a restriction to protect the rights and freedoms of others. In the present case, this is the right to prepare for the defence against a legal claim in freedom and seclusion. The PG argued that such a right exists based on Article 6(1) ECHR. The PG followed that the corresponding interest can be found in the GDPR. Notably, the PG referenced Recital 52 and Article 9 GDPR. Recital 52 GDPR states that a derogation from the prohibition on processing special categories of personal data should be provided for the defence of legal claims. Article 9(1) GDPR and Article (2)(f) GDPR contain an exception to the prohibition of processing special categories of personal data when processing is necessary for the establishment, exercise or defence of legal claims. While this concerned the prohibition of processing personal data and not the exercise of the right of access, the PG argued it was still meaningful for the case at hand. It showed that while the drafting the GDPR, the need to process personal data for the defence against a legal claim was taken into consideration. Last, the PG stated that the data subject's interest (keeping track of the processing of her personal data) was only affected to a limited extent. The data subject could (1) still access her medical file pursuant to the MTCA and her personal data pursuant to Article 15(1) GDPR, insofar it did not restrict the hospital's interest to prepare its defence in freedom and privacy. In addition, (2) making the medical assessment involved no collection of any new personal data. The restriction was therefore proportionate. The PG therefore concluded that in a situation like the present case, a patient will usually not be able to demand access to the medical assessment based on Article 15 GDPR. Such an assessment qualifies as personal data, but that the hospital can object based on Article 23 GDPR to prepare its defence in freedom and privacy.

### Data Protection Commissioner v. Facebook Ireland Ltd, and Maximillian Schrems

*Source: CJEU, 2020-07-16 — https://overview.legal/posts/5945 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0311*

“the national supervisory authorities are responsible for monitoring compliance with the EU rules concerning the protection of natural persons with regard to the processing of personal data. Each of those authorities is therefore vested with the power to check whether a transfer of personal data from its own Member State to a third country complies with the requirements laid down in that regulation” / “The exercise of that responsibility is of particular importance where personal data is tra

### CJEU - C-311/18 - Facebook Ireland and Schrems

*Source: GDPRhub, 2026-07-17 — https://overview.legal/posts/125639 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-311/18_-_Facebook_Ireland_and_Schrems*

Facts — Maximillian Schrems, an Austrian citizen, had been a Facebook user since 2008. As is the case with users residing in the European Union, some of the data belonging to Mr. Schrems had been transferred by Facebook Ireland to its servers belonging to Facebook Inc., located in the United States. In 2013, Mr. Schrems complained to the Irish Data Protection Commissioner (DPC) seeking to prohibit these transfers. When this complaint was rejected, he brought an action against the decision before the Irish High Court, which in turn referred a number of questions to the CJEU, the most prominent of which was whether the EU-US adequacy decision, the so-called “Safe Harbor", was valid. In its judgment on October 6th 2015 (Case C-362/14, “Schrems I”), the CJEU invalidated the Safe Harbor and stated that, in order to be "adequate", the level of data protection offered by the third country should be “essentially equivalent” to that being offered in the EU. As a result, the High Court annulled the decision rejecting Mr. Schrems’ complaint, and referred the case back to the DPC. In the remittal “judgment” before the DPC, Facebook Ireland explained that the invalidated adequacy decision was not relevant as a large part of personal data was transferred to Facebook Inc. pursuant to Standard Contractual Clauses (SCCs). On this basis, the DPC asked Mr. Schrems to reformulate his complaint. In his reformulated complaint lodged on December 1st 2015, Mr. Schrems alleged that US law required Facebook Inc. to disclose his personal data to certain United States authorities in the context of various monitoring programs (in particular, the FISA 702 and the Executive Order 12.333). In Mr Schrems’ view, these programs contravened different data protection principles as well as Article 7 CFR, Article 8 CFR, and Article 47 CFR. After investigating the allegations made by Mr. Schrems, the DPC argued that it could not adjudicate on them until the CJEU had examined the validity of the SCCs, and so it brought proceedings before the High Court. On May 4th 2018 the High Court made the reference for a (second) preliminary ruling to the CJEU. In its reference to the CJEU, the High Court specified that Section 702 of the FISA permitted the Attorney General and the Director of National Intelligence to authorize jointly, following FISA approval, the surveillance of individuals who are not US citizens and who are located outside of the US in order to obtain foreign intelligence information. It was also affirmed that Section 702 of the FISA provided the basis for the PRISM and UPSTREAM surveillance programs. PRISM in particular, requires Internet Service Providers (ISPs) to supply the NSA with all communications to and from a ‘selector’. UPSTREAM on the other hand, permitted the NSA to copy and filter Internet traffic flows from the ‘backbone’ of the internet, granting it access to both the content of communications and their metadata. Furthermore, the High Court had found that Executive Order 12.333 (E.O. 12333) allowed the NSA to access data in transit by accessing underwater cables on the floor of the Atlantic. The High Court stated that the only limit on US surveillance activities was found in the Presidential Policy Directive (PPD-28), and even this only stated that intelligence activities should be ‘tailored as feasible’. On the basis of these findings, the High Court considered that the US carried out mass processing of personal data without ensuring a level of protection that was essentially equivalent to that which was guaranteed by Article 7 CFR and Article 8 CFR. The High Court also highlighted that EU citizens did not have the same remedies available to them as US citizens with regards to the processing of their personal data, since the Fourth Amendment to the Constitution of the United States did not apply to non-US citizens. This meant that it was particularly difficult for EU citizens to establish standing before a US court. Moreover, activities based on E.O. 12333 were not subject to judicial oversight and were not justiciable. Given the considerable effects of US surveillance law on the rights of Europeans, the High Court raised the question of whether the SCCs are valid, given that they may not be binding on the State authority of the third country. If they did not bind the third country State authority, then they are not capable of remedying a possible lack of an adequate level of protection of personal data. Dispute — The request for a preliminary ruling referred eleven questions to the Court of Justice. The topics covered in these questions were as follows: the applicability of EU law to data transfers made for commercial purposes, but further processed for national security and law enforcement purposes the relevant legislation for determining whether there has been a violation of individual rights how to assess the level of protection in a third country whether data transfers to the US violate the Charter whether the level of protection offered in the US respects or limits an individual’s right to a judicial remedy what level of protection is required to be afforded to personal data that is transferred under SCCs whether the SCCs can even be adequate as safeguards given they do not bind national authorities whether there is an obligation to suspend data flows if a data importer is subject to surveillance law what the relevance of the Privacy Shield decision is with regards to assessing safeguards whether the presence of an ombudsperson can ensure that the US provides an effective remedy to data subjects whether the SCCs violate the Charter Holding — The Court began by clarifying that the GDPR applies to the transfer of personal data for commercial purposes by an economic operator established in a Member State, to another economic operator established in a third country, even if in that country the data would be processed by the national authorities for public security, defense, and state security purposes. In particular, the Court stressed that a transfer of data is not excluded from the scope of the GDPR for the reason that it may be processed by the national authorities of a third country. Regarding the level of protection required in such an instance, the Court held that the requirements presented by the GDPR regarding safeguards, enforceable rights, and legal remedies must continue to be applied. In other words, when their data is transferred abroad, a data subject must be afforded a level of protection essentially equivalent to that which they would receive in EU. In such circumstances, in order to assess the level of protection, both existing contractual clauses between the data importer and exporter, and the potential access by public authorities in a third country must be taken into account, along with the relevant aspects of the legal system in the third country. The Court then analyzed Decision 2016/1250 (the “Privacy Shield”), which was the self-certification scheme in place for controllers based in the US. Examining the decision in light of the provisions of the Charter, the Court held that the requirements of US national security, public interest, and law enforcement do in fact interfere with the fundamental rights of persons whose data is transferred there. These limitations on the protection of personal data were not circumscribed in a way that satisfied requirements that are essentially equivalent to those required under EU law. The principle of proportionality was also not satisfied, in so far as US surveillance programs are not limited to what is ‘strictly necessary’. It was noted that the provisions in the US surveillance programs neither limited the power they conferred onto national authorities, nor granted data subjects actionable rights before the courts against the US authorities. The Court proceeded to scrutinize the Ombudsperson mechanism that had been in place under the Privacy Shield, stating that it too did not provide data subjects with a cause of action before a body which was fully independent, and that this body was limited in so far as it could not impose rules that were binding on US intelligence services. Taking all of this into account, the Court declared the Privacy Shield Decision to therefore be invalid. The Court also clarified that in the absence of an adequacy decision, the competent supervisory authorities are required to suspend or prohibit a transfer of personal data to a third country where they consider that the standard data protection clauses are not or cannot be complied with in the third country, and that the protection of the data transferred cannot be ensured by other means. Following this, the Court then examined the validity of the SCCs (Decision 2010/87). First, the Court held that the validity of the Decision was not called into question by the mere fact that the SCCs do not bind national authorities in a third country. After establishing this, the Court emphasized that the validity of the SCCs, however, did depend on whether there were effective mechanisms in place that make it possible to ensure compliance with the level of protection required by EU law. Important to note is that here the Court held that the SCCs in themselves did provide for such mechanisms. However, it went on to stress that where these mechanisms cannot be complied with, the transfers of personal data pursuant to these clauses is to be suspended or prohibited. Furthermore, there is an obligation on the data exporter and the recipient of the data to verify prior to a transfer, what the level of protection in a third country is, and whether it will be possible to comply with the requirements of the SCCs.

### Bulgarian SAC upholds DPA finding on neighbour's CCTV covering adjacent property

*Source: Supreme Administrative Court of Bulgaria‎, 2026-07-13 — https://overview.legal/posts/184723 — original: https://gdprhub.eu/index.php?title=BAC_(Bulgaria)_-_7890/2026*

Facts — A data subject lodged a complaint with the Bulgarian DPA (CPDP), alleging that her neighbour (the controller) was unlawfully monitoring her property through CCTV. She claimed that a camera had been mounted on a metal structure on a third-floor terrace of the neighbouring building and installed in a manner that extended into the space above her property. According to the data subject, the camera had the technical capacity to identify individuals and objects throughout her property. The controller did not deny installing the camera but argued that it was directed towards the fence and an outbuilding on his own property. He also stated that a second camera had been installed on the western façade of the building. The controller claimed that both cameras were used solely to monitor his own property and the processing was lawful under the GDPR. The DPA carried out an on-site investigation and found that the CCTV system consisted of two independent cameras operated through separate software applications. Both cameras could be rotated in all directions and could use an automatic tracking function. The recordings were stored on memory cards for approximately 15 days before being automatically deleted, and only the controller had access to the system. The DPA noted that Camera 1 recorded the northern part of the controller’s yard, his house and the fence bordering the data subject’s property and Camera 2 recorded the roof of the controller’s house and a small part of the data subject’s yard. The DPA reviewed the oldest available footage and noticed that Camera 2 had recorded the data subject’s house and yard. The inspection report stated that the system could process personal data relating to individuals on both properties, but did not allow the identification of individuals or facial recognition. The DPA pointed out that warning stickers informing individuals of the video surveillance were displayed at the property. It found the complaint well founded in relation to Camera 1 and established a violation of Article 5(1)(c) GDPR, for which it issued an official warning to the controller. However, it found the complaint unfounded in relation to Camera 2, considering that the surveillance was permissible on the basis of the controller’s legitimate interest in protecting his property. The data subject appealed the part of the decision concerning Camera 2. The court of first instance annulled that part of the DPA’s decision and remitted the case to the DPA for reconsideration. It found that the DPA had relied entirely on the findings of the inspection team without carrying out a thorough, objective and independent examination of the relevant facts. Both the DPA and the controller appealed that judgment before the Bulgarian Supreme Administrative Court. Holding — The Supreme Administrative Court rejected the appeals and upheld the judgment of the court of first instance. The court noted that Camera 2 recorded the roof of the controller’s building and part of the data subject’s yard. It further pointed out that the DPA had found that, due to their technical characteristics, both cameras could alter their surveillance coverage and process personal data relating to individuals on both properties, while the CCTV system allowed individuals to be identified. Moreover, the court agreed with the first-instance court that the DPA had failed to provide adequate reasons for treating the two cameras differently. In particular, the DPA had not explained how the partial recording of the data subject’s yard contributed to the protection of the controller’s legitimate interest in safeguarding his property. It determined that it had also failed to establish whether adjusting the field of view of Camera 2 could expand its recording perimeter and allow it to capture a larger part of the data subject’s property.

### French Supreme Admin Court partly upholds challenge to graduated response IP data decree

*Source: Supreme Administrative Court, 2026-04-30 — https://overview.legal/posts/122869 — original: https://gdprhub.eu/index.php?title=CE_-_N._433539*

Facts — Several digital rights organisations asked the Prime Minister to repeal Decree No. 2010-236 of 5 March 2010. The decree regulated an automated personal data processing system used by the French authority for freedom of communications (ARCOM, hereinafter the French authority) for France’s online copyright enforcement mechanism, known as the graduated response procedure. Under this system, the French authority could receive IP addresses linked to alleged copyright infringements and request the corresponding subscriber identity data from electronic communications operators. This data could then be used to send warnings to subscribers and, in repeated cases, refer the matter to the public prosecutor. The applicants argued that the decree allowed the French authority to access personal data linked to IP addresses without sufficient safeguards under EU law. The court had previously referred questions to the CJEU, which ruled in Case C-470/21 that such access may be allowed, but only under strict conditions. Following the CJEU judgment, the court reviewed whether the French decree complied with EU law. Holding — The court partly upheld the action. First, the court held that EU law allows the general and indiscriminate retention of IP addresses for combating criminal offences in general only where serious interference with private life is effectively excluded. This requires strict separation between different categories of retained data, secure technical safeguards and regular monitoring by an independent public authority. The court found that French law did not require electronic communications operators to retain subscriber identity data and IP-related data under these conditions. Therefore, the decree was unlawful insofar as it allowed the French authority to process data that had not necessarily been retained in compliance with EU-law safeguards. Second, the court held that the French authority may access subscriber identity data linked to IP addresses in order to identify persons suspected of online copyright infringements and send the first two warnings under the graduated response procedure. However, the court distinguished the third access to such data. At that stage, the authority is no longer dealing with an isolated identification request: it has already linked the same person’s identity twice with alleged unlawful online activity and with the protected works concerned. A third access therefore allows the authority to build a more detailed picture of the person’s conduct and may reveal sensitive aspects of their private life. It also marks a more serious procedural stage, since it may lead to a registered letter and ultimately to referral to the public prosecutor. For that reason, EU law requires prior authorisation by a court or an independent administrative body before this third access takes place. The decree did not provide for such prior review, so the court held that it was unlawful to that extent. For this third access, EU law requires prior authorisation by a court or an independent administrative body. The decree did not provide for such prior review. The court therefore held that the decree was unlawful to that extent. The court annulled the Prime Minister’s refusal to repeal the unlawful parts of the decree and ordered their repeal. It also held that the French authority must stop applying the unlawful provisions. However, the French authority may still access identity data for the first and second warnings, and may request access in serious copyright offence cases under the conditions set out in the judgment.

### CJEU - C‑313/23, C‑316/23 and C‑332/23 - Inspektorat kam Visshia sadeben savet

*Source: GDPRhub, 2025-04-30 — https://overview.legal/posts/158459 — original: https://gdprhub.eu/index.php?title=CJEU_-_C‑313/23,_C‑316/23_and_C‑332/23_-_Inspektorat_kam_Visshia_sadeben_savet*

Facts — Following the expiration of the prescribed time limit for submission of annual declarations of assets of judges, public prosecutors and investigating magistrates and their families, the Inspectorate at the Bulgarian Supreme Judicial Council requested the Sofia District Court to lift the banking secrecy of several judges and public prosecutors, as well as their families. The Inspectorate is comprised of an Inspector General and a panel of ten Inspectors. At the time, the terms of office of the Inspectorate members had been expired for two years and there was no provision in national law limiting the permissible extent of the extention of their duties . The referring Court was unsure as to whether the continuation of the performance of their duties by the Inspectorate past the expiry of their term undermines the independence of the Office under EU law and unsure as to the interplay between the provisions in the Bulgarian Constitution and the GDPR, and referred the following questions: (1) Must the second subparagraph of Article 19(1) TEU, read in conjunction with the second paragraph of Article 47 of [the Charter], be interpreted as meaning that it is per se or under certain conditions an infringement of the obligation incumbent on Member States to provide effective remedies sufficient to ensure independent judicial review for the functions of an authority which can impose disciplinary penalties on judges and has powers to collect data relating to their assets and liabilities to be indefinitely extended after the constitutionally stipulated term of office of that body comes to an end? If such an extension is permissible, under what conditions is that the case? (2) Must Article 2(2)(a) of [the GDPR] be interpreted as meaning that the disclosure of data covered by banking secrecy for the purposes of verifying assets and liabilities of judges and public prosecutors which are subsequently made public constitutes an activity which falls outside the scope of [EU] law? Is the answer different where that activity also includes the disclosure of data relating to family members of those judges and public prosecutors who are not judges or public prosecutors themselves? (3) If the answer to the second question is that [EU] law is applicable, must Article 4(7) of [the GDPR] be interpreted as meaning that a judicial authority which allows another State authority to access data concerning the account balances of judges and public prosecutors and their family members determines the purposes or means of the processing of personal data and is therefore a “controller” for the purposes of the processing of personal data? (4) If the answer to the second question is that [EU] law is applicable and the third question is answered in the negative, must Article 51 of [the GDPR] be interpreted as meaning that a judicial authority which allows another State authority to access data concerning the account balances of judges and public prosecutors and their family members is responsible for monitoring the application of that regulation and must therefore be classified as a “supervisory authority” in relation to those data? (5) If the answer to the second question is that [EU] law is applicable and either the third or the fourth questions are answered in the affirmative, must Article 32(1)(b) of [the GDPR] and Article 57(1)(a) of that regulation be interpreted as meaning that a judicial authority which allows another State authority to access data concerning the account balances of judges and public prosecutors and their families, is obliged, in the presence of [information] concerning a personal data breach committed in the past by the authority to which such access is to be granted, to obtain information on the data protection measures taken and to take into account the appropriateness of those measures in its decision to permit access? (6) If the answer to the second question is that [EU] law is applicable, and irrespective of the answers to the third and fourth questions, must Article 79(1) of [the GDPR], read in conjunction with Article 47 of [the Charter], be interpreted as meaning that, where the national law of a Member State provides that certain categories of data may be disclosed only after permission to do so has been granted by a court, the court so competent must of its own motion grant legal protection to the persons whose data are to be disclosed, by requiring the authority which has applied for access to the data in question and which is known to have committed a personal data breach in the past to provide information on the measures taken pursuant to Article 33(3)(d) of [the GDPR] and their effective application? Holding — Question 1: The Court ruled that that Article 19(1) TEU, read in light of Article 47 of the Charter must be interpreted as meaning that the principle of judicial independence precludes a Member State’s allowing the office holders of judicial body authorised to scrutinize the activities of judges, magistrates and public prosecutors to continue to perform their functions beyond their term where such extension does not have an explicit basis in national law which governs the exercise of such authority and where the extension is not limited in time. Question 2: The Court held that Article 2 of the GDPR must be interpreted as meaning that disclosures to judicial bodies of personal data concerning judges, public prosecutors and investigating magistrates, as well as their family members, with the view of verifying submitted declarations and are published constitutes processing within the material scope of the GDPR. The Court noted that it had previously found (Commission v Poland C-204/21) that neither the fact that information which is the subject of national provisions relates to judges nor the fact that information might have certain links with the performance of their duties is, in itself, sufficient to remove those national provisions from the scope of the GDPR. Although the proper administration of justice and rules relating to the performance and conduct of judges come within the competence of Member States, the processing in question does not fall within that category, nor is it an activity intended to safeguard national security, the Court found. Accordingly, the Court held that the processing in question comes under the material scope of the GDPR. Question 3: The Court held that Article 4(7) of the GDPR must be interpreted as meaning that a court competent to authorise disclosure by a bank to a judicial authority data relating to the bank accounts of judges, public prosecutors and magistrates, and their family members, cannot be classified as a controller under that provision. The Court reasoned that the national legislation determines the scope of such processing, the purpose of the processing and designates the body which is competent to carry it out. The national court, the Court found, confines itself to considering whether the conditions laid down in the national law are met. As such, the Court concluded that the national court determines neither the purposes nor the means and thus cannot be regarded as the controller under the GDPR. It is the designated body, in this case the Inspectorate, which is the controller. Question 4 The Court held that Article 51 of the GDPR must be interpreted as meaning that a court competent to authorise disclosure of personal data to another judicial body does not constitute a supervisory authority in the meaning of that provision. The Court reasoned that the national court has not been designated under Bulgarian law as a supervisory authority, as envisaged in Article 51(1) GDPR. Member States are also obliged to notify the Commission of such provisions adopted or amended pursuant to Chapter VI GDPR. No such notification had been made as to the designation of the national court as supervisory authority. Question 5: As the Court answered both questions 2 & 3 in the negative, no response to question 5 was necessary. Question 6: The Court held that Article 79(1) GDPR, read in light of Article 47 of the Charter, must be interpreted as meaning that a court competent to authorise disclosure of personal data to another judicial body is not required to ensure, of its own volition, the security of the personal data to be disclosed in accordance with the GDPR. This is the case even where the receiving body has, in the past, infringed those provisions of the GDPR. In reaching this conclusion, the Court highlighted the difference between supervisory authorities and their powers under the GDPR and the position of national courts. The Court also highlighted that it is the obligation of the Member State to ensure that practical arrangements have been made for the exercise of the remedies in Articles 77(1), 78(1) & 79(1).

### CE - 451423

*Source: Supreme Administrative Court, 2022-06-27 — https://overview.legal/posts/108993 — original: https://gdprhub.eu/index.php?title=CE_-_451423*

Facts — The French DPA had received a complaint on 28 May 2018 regarding the lawfulness of processing by Amazon Europe Core ('Provider' or 'The company'). The French DPA had forwarded this complaint to the Luxembourg DPA under the 'one stop shop' mechanism of Article 56 GDPR. The luxembourg DPA started an investigation regarding Amazon's use of cookies and its compliance with the GDPR and the ePrivacy directive. However, the French DPA started its own investigation into Amazon's compliance with Article 82 of the French Data protection act, a national implementation of Article 5(3) of the ePrivacy directive. (directive 2002/58/EC). This investigation regarding Article 82 had resulted in decision SAN-2020-013. In this decision, the French DPA fined Amazon €35,000,000 for the failure to obtain prior consent and the failure to inform users of their rights with regards to the processing of their data, which was mandatory under Article 82 of the Data Protection Act. The DPA found that when a user visited the "Amazon.fr" site, a large number of cookies with advertising purposes were automatically placed on the data subjects computer. Because this type of cookie was not essential to the service provided by the controller, the DPA considered that the controller had not complied with the obligation to obtain the consent of Internet users before depositing the cookies. Amazon appealed this decision at the Conseil d'Etat, the French Supreme Administrative Court, and requested its annulment. Amazon also asked the Conseil to refer several questions to the CJEU for a preliminary ruling. Among other arguments, Amazon claimed that the French DPA had made an incorrect interpretation of the law regarding its competence and had disregarded its competence by imposing the contested sanction. The controller also stated that the involvement of the French DPA, when the Luxembourg DPA was already involved, constituted a violation of Article 50 of the Charter of Fundamental Rights. According to this article, the same person may not be prosecuted more than once for the same acts. Holding — With regard to the application of the "one-stop shop" mechanism and the CNIL's jurisdiction: The Conseil ruled that the application and enforcement of the ePrivacy directive was the responsibility of national DPAs according to Article 15a of the directive. The "one-stop shop" mechanism did not apply in this case, even when there was a form of a cross-border processing. The Conseil also stated that the absence of a 'one-stop shop' mechanism did not imply any infringement of Article 50 of the Charter of Fundamental Rights, because the DPA only ruled on breaches of national law transposing EU law in the contested decision, and not on GDPR related violations. The Conseil also assessed the compatibility of Article 3 of the French Data protection Act with the ePrivacy Directive. The Conseil determined that Directive 2002/58/EC did not prevent the French DPA to apply the French data protection Act (including Article 82). The Directive would therefore also not prevent the French DPA from penalising the controller for supposed violations of Article 82 of the French data protection Act. Therefore, the Conseil established that the French DPA could enforce the French data protection act against any person or legal entity responsible for the processing of data who had an establishment in France, irrespective of the location of the principal establishment of the responsible entity. This enforcement by the DPA would also not constitute violations of articles 49 (Freedom of establishment) or 56 (Freedom to provide services) of the TFEU. With regard to the sanction imposed by the CNIL: The Conseil deemed that the applicant was sufficiently informed regarding the scope of the DPA's investigations, the facts and the legal grounds on which the sanction was based. Moreover, the Conseil considered that the applicant was given sufficient time to present its defence. The Conseil also ruled that the involvement of the French DPA, while the Luxembourg DPA was the lead supervisory authority, was not enough to constitute a breach of the equality of arms principle. Amazon had argued that the involvement of the French DPA in the procedure had enabled the French DPA to gain access to privileged and confidential information and had used this information as a basis for its own decision. The Conseil determined that Amazon did not provide enough proof for this argument and stated that Amazon was not able to prove that was the procedure contrary to Article 15a(4) of Directive 2002/58/EC. On a possible violation of Article 50 of the Charter of Fundamental Rights: The Conseil explained, based on the CJEU's case law (Aklagaren v Akerberg Fransson C-617/10, Powszechny Zaklad Ubezpieczen na Zycie SA of C-617/17 and bpost SA v Belgian Competition Authority C-117/20), that the principle invoked by the applicant, that the same person may not be the subject of several proceeding in respect of the same facts, was not violated by the French DPA. The Conseil stated that the principle could only be enforced when criminal proceedings had been definitively terminated. This was in particular the case when a criminal penalty had become final. The Conseil held that Amazon was not found to be the subject of a final sanction issued by the Luxembourg DPA for the facts that had resulted in the €35,000,000 fine in the contested decision. The Conseil rejected the applicant's claim for a reference for a preliminary ruling on the matter. Regarding the application of French Data Protection Act by the French DPA, Amazon had argued that the legal framework regarding cookies was not stable and unclear at the time when proceedings against Amazon were started. The Conseil concluded that it had published guidelines detailing obligations for entities under the applicable law, and considered that the fact that other national supervisory authorities had taken divergent positions in interpreting the conditions and procedures applicable to the collection of user consent had no bearing on the application of the French Data Protection Act by the French DPA. On the proportionality of the sanction imposed: Taking into account the elements assessed by the French DPA to calculate the imposed fine, the Conseil ruled that the DPA had not imposed a disproportionate penalty on the controller. Consequently, the Conseil rejected the entirety of controller's claims.

### CJEU C-473/12 IPI: Member States need not transpose all Directive 95/46 Article 13

*Source: GDPRhub, 2013-11-07 — https://overview.legal/posts/158436 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-473/12_-_IPI*

Facts — The Belgian Professional Institute of Real Estate Agents (IPI) had used private detectives to collect information on a real estate company that allegedly breached regulatory rules. The admissibility of the private detectives’ evidence in court was questioned on the grounds that the company’s agents had not been informed that their personal data would be processed by third parties in accordance with Article 11(1) of the Data Protection Directive 95/46. IPI argued that the use of private detectives fell within the exception under Article 13(1)(d) of Directive 95/46, which permits the collection of data without consent for the prevention, investigation, detection and prosecution of breaches for regulated professions. Belgian law had specified exceptions for journalistic purposes, artistic or literary expression, public authorities exercising judicial police duties, police services and the European Centre for Missing and Sexually Abused Children. The Belgian Constitutional Court considered that the Belgian law did not strictly transpose exceptions comparable to Article 13 of Directive 95/46/EC. It referred three questions to the ECJ for clarification on the obligations for Member States to implement Article 13 in national law: Does Article 13(1)(d) of Directive 95/46 leave Member States free to choose whether or not to provide for an exception to the immediate obligation to inform under Article 11(1) to protect others’ rights and freedoms? Do professional activities of private detectives (governed by national law) come within an exception referred to in Article 13(1)(d) and (g) of Directive 95/46? If they do not, is Article 13(1)(d) and (g) of Directive 95/46 compatible with Article 6(3) TEU – specifically, with the principle of equality and non-discrimination? Holding — With regard to the first question, the Court ruled that Member States have the option, but not an obligation, to transpose the list of exceptions provided under Article 13 of the Data Protection Directive 95/46/EC. Article 13 permits Member States to adopt exemptions allowing the collection and processing of personal data without notifying the data subject in seven circumstances: To safeguard national security. For defence. For public security. For the prevention, investigation, detection and prosecution of criminal offenses or breaches of ethics for regulated professions. For an important economic or financial interests of a Member State. For monitoring, inspection or regulatory functions. For the protection of the data subject or the rights and freedoms of others. The CJEU based its interpretation on the emphasis on a high level of protection found in recitals 3, 8 and 10 of Directive 95/46. In provisions such as these, Directive 95/46's aim of harmonisation must be balanced against the applicability of the Directive's general language in specific situations and the need to afford Member States some flexibility in this regard. With regard to the second question, the CJEU considered that the activity of a private investigator on behalf of a regulated body – in this case, the IPI – falls within the scope of Article 13(1)(d) of Directive 95/46. Thus, if a Member State has chosen to implement an exception pursuant to Article 13(1)(d) of Directive 95/46, the professional body concerned and the private detectives acting on its behalf may rely on it. Accordingly, they need not inform the data subject pursuant to Article 10 and 11 of Directive 95/46.

## Guidance

### Opinion 01/2019 on the draft list of the competent supervisory authority of the Principality of Liechtenstein regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-012019-on-the-draft-list-of-the-competent-supervisory-en, 2019-01-23 — https://overview.legal/posts/126254 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-012019-on-the-draft-list-of-the-competent-supervisory_en*

Adopted 1 EDPB Plenary Meeting, 22 - 23 January 2019 Opinion 01 /201 9 on the draft list of the competent supervisory authority of the Principality of Liechtenstein regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 23 January 201 9 Adopted 2 Table of c ontents 1 Summary of the Facts ................................ ................................ ................................ ..................... 4 2…

### Opinion 27/2025 regarding the European Commission Draft Implementing Decision pursuant to Directive (EU) 2016/680 on the adequate protection of personal data by the United Kingdom

*Source: EDPB, edpb-opinion-202527-united-kingdom-adequacy-led-en, 2025-10-16 — https://overview.legal/posts/51407 — original: https://www.edpb.europa.eu/documents/adequacy/opinion-272025-regarding-the-european-commission-draft-implementing-decision_en*

Adopted 1 Opinion 27/2025 regarding the European Commission Draft Implementing Decision pursuant to Directive (EU) 2016/680 on the adequate protection of personal data by the United Kingdom Adopted 16 October 2025 Adopted 2 Executive summary The European Commission endorsed its draft implementing decision on the adequate protection of personal data by the United Kingdom pursuant to the Law Enforcement Directive on 22 July 2025. On the same date, as part of the procedure towards the formal…

### Opinion 11/2018 on the draft list of the competent supervisory authority of Ireland regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-112018-on-the-draft-list-of-the-competent-supervisory-en, 2018-10-03 — https://overview.legal/posts/126301 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-112018-on-the-draft-list-of-the-competent-supervisory_en*

Opinion 11 /2018 on the draft list of the competent supervisory authority of Ireland regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 25th September 2018 2 Contents 1. Summary of the Facts ................................ ................................ ................................ ........ 4 2. Assessment ................................ ................................ ................................…

### Opinion 20/2018 on the draft list of the competent supervisory authority of Sweden regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-202018-on-the-draft-list-of-the-competent-supervisory-en, 2018-10-03 — https://overview.legal/posts/126286 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-202018-on-the-draft-list-of-the-competent-supervisory_en*

Opinion 20 /2018 on the draft list of the competent supervisory authority of Sweden regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 25th September 2018 2 Contents 1. Summary of the Facts ................................ ................................ ................................ ........ 4 2. Assessment ................................ ................................ ................................…

### Opinion 17/2018 on the draft list of the competent supervisory authority of Poland regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-172018-on-the-draft-list-of-the-competent-supervisory-en, 2018-10-03 — https://overview.legal/posts/126299 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-172018-on-the-draft-list-of-the-competent-supervisory_en*

Opinion 17 /2018 on the draft list of the competent supervisory authority of Poland regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 25th September 2018 2 Contents 1. Summary of the Facts ................................ ................................ ................................ ........ 4 2. Assessment ................................ ................................ ................................…

### Opinion 16/2018 on the draft list of the competent supervisory authority of the Netherlands regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-162018-on-the-draft-list-of-the-competent-supervisory-en, 2018-10-03 — https://overview.legal/posts/126303 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-162018-on-the-draft-list-of-the-competent-supervisory_en*

Opinion 16 /2018 on the draft list of the competent supervisory authority of the Netherlands regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 25th September 2018 2 Contents 1. Summary of the Facts ................................ ................................ ................................ ........ 4 2. Assessment ................................ ................................…

### Opinion 13/2018 on the draft list of the competent supervisory authority of Lithuania regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-132018-on-the-draft-list-of-the-competent-supervisory-en, 2018-10-03 — https://overview.legal/posts/126307 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-132018-on-the-draft-list-of-the-competent-supervisory_en*

Opinion 13 /2018 on the draft list of the competent supervisory authority of Lithuania regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 25th September 2018 2 Contents 1. Summary of the Facts ................................ ................................ ................................ ........ 4 2. Assessment ................................ ................................ ................................…

### Opinion 10/2018 on the draft list of the competent supervisory authority of Hungary regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-102018-on-the-draft-list-of-the-competent-supervisory-en, 2018-10-03 — https://overview.legal/posts/126282 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-102018-on-the-draft-list-of-the-competent-supervisory_en*

Opinion 10 /2018 on the draft list of the competent supervisory authority of Hungary regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 25th September 2018 2 Contents 1. Summary of the Facts ................................ ................................ ................................ ........ 4 2. Assessment ................................ ................................ ................................…

## Enforcement decisions

### DPC (Ireland) - 06/SIU/2018

*Source: DPC (Ireland), 2023-08-22 — https://overview.legal/posts/125614 — original: https://gdprhub.eu/index.php?title=DPC_(Ireland)_-_06/SIU/2018*

Facts — The Irish DPC started an own volition inquiry into processing operations carried out by the Galway County Council (the controller), focusing mainly into the surveillance technologies deployed by state authorities, including the Galway County Council and by the An Garda Síochána (the Irish police). More specifically, the Galway County Council Officials make use of CCTV systems, body-worn cameras and automated number plate recognition (ANPR) technologies for various purposes including law enforcement purposes. The DPC carried out its assessment both on the basis of the GDPR and of the Law Enforcement Directive (LED) for activities meant to prevent, investigate, detect and prosecute crime or for the execution of criminal penalties. Holding — In its inquiry, the DPC assessed the legitimacy of processing activities by the controller in light of both the GDPR and the Irish Data Protection Act and the LED, as different processing activities pursued different purposes. The DPC held with respect to body-worn cameras and ANPR systems that the GDPR applies to these processing activities as they mainly serve health and safety and traffic management purposes respectively, thus no law enforcement purposes. Making reference to the strict interpretation in CJEU jurisprudence, the DPC held that in order for a processing activity to fall under the scope of the LED, it must be specifically and concretely used for law enforcement purposes and it does not suffice that the data could potentially (emphasis added) be processed for law enforcement purposes. Firstly, as regards ANPR cameras used for traffic management, the DPC held that the latter enable identification of data subjects within the vehicle and thus constitutes processing of personal data. The legal basis referred to by the Council is Article 6(1)(e) GDPR. The DPC held that processing ex Article 6(1)(e) GDPR, read in light of Article 6(3) GDPR and Recital 41 GDPR requires a legal basis to set out the conditions for processing clearly, precisely and in a foreseeable way. In this case, the DPC held that the use of ANPR cameras does aid to the traffic management function of officials but it may also have significant impacts on the rights and freedoms of data subjects. The DPC concluded that the national provisions relied on by the controller to make use of such cameras are too broad and cannot constitute a legal basis for the Council to deploy APNR cameras for traffic management purposes. Hence, the DPC found the Council had acted in violation of Article 5(1)(a) GDPR. In addition to this, the DPC considered whether the controller complied with its Article 24(1) GDPR obligation to adopt appropriate technical and organizational measures to ensure and demonstrate GDPR-compliant processing activities, also by means of a data protection policy as per Article 24(2) GDPR. The DPC held that the controller failed to comply with its obligation under Article 24(1) GDPR with respect to the use of ANPR cameras for traffic management purposes as it failed to demonstrate compliance with the GDPR. Further, the DPC also found the controller had failed to comply with its obligation to carry out a Data Protection Impact Assessment by virtue of Article 35(1) GDPR for the use of APNR cameras for the systematic monitoring, tracking and observing of individuals. Secondly, the DPC considered the use of a body-worn camera by a Housing Tenacy Officer who had been threatened while conducting official activities. The legal basis relied upon by the Council in this case was Article 6(1)(d) GDPR, which allows for processing activities that are necessary to protect the vital interest of an individual. Further the Council also relied on Article 6(1)(e) GDPR as it is required to comply with health and safety obligations towards its employees set out in two specific Acts. As regards the use of body-worn cameras on the basis of Article 6(1)(d) GDPR, the DPC held that the controller failed to carry out a test for proving the necessity of the use of such cameras before their actual use. Hence, the controller failed to prove that such measure was necessary to protect the vital interest of the officer or to perform a task in the public interest. As for the use of such cameras on the basis of Article 6(1)(e) GDPR, the DPC held that again the controller did not rely on a clear, precise and foreseeable provision in the law allowing specifically for the body-worn cameras to be used. In this case too, the DPC held that the Council had infringed Article 5(1)(a) GDPR. Lastly, the DPC held that the controller infringed Article 24(1) GDPR to the extent that it failed to raise staff awareness on the principles of data processing, which counts as an organizational measure to be adopted by the controller under Article 24(1) GDPR. With respect to all the above mentioned violations, the DPC decided to adopt the following corrective powers: it provisionally banned the use of body-worn cameras and APNR cameras until a valid legal basis is identified and issued a reprimand concerning the violation of Article 24 GDPR. The rest of the activities carried out by the Galway County Council were assessed in light of the provisions of the LED, and the DPC found several violations in that respect too.

### AEPD (Spain) - E/03783/2020

*Source: AEPD (Spain), 2026-07-15 — https://overview.legal/posts/108996 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_E/03783/2020*

Facts — The Directorate for National Security of the Ministry of Interior issued guidelines for the police forces to monitor news and social networks to spot fake news and misinformation, to prevent some actors from causing social stress, in light of the covid-19 pandemic. This came to the Spanish DPA (AEPD) knowledge, that launched an investigation to verify that such behaviour complied with the personal data regulations. Such guidelines were issued to prevent and minimize the effects of misinformation, with extreme vigilance and monitoring of networks and websites where false messages and information aimed at increasing social stress are disseminated, and, where appropriate, calling for the intervention measures provided for in the applicable legislation". According to the guidelines, within the surveillance and monitoring of networks and web pages, intervention shall only be carried out in accordance with the aforementioned purposes and principles and always under the protection of the applicable legislation. Also, personal data will only be processed when there is sign of a criminal offence, in accordance with the Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data. If such activities were related to national security, then the processed would be carried out with basis on the national legislation regarding state secrets and classified matters. In their response to the DPA, the Directorate for National Security also stated that they do not collect personal data, but only carry out a daily observation of news or public information from social networks, where the information collected relates to data of a public nature, shared by its authors through social networks and public media, consisting primarily of the content of the communication and the medium of dissemination. For this, specialized officers from the Spanish Civil Guard ("Guardia Civil") browse the news and create anonymous users to monitor (read) social networks such as Twitter, Facebook, Instagram, Badoo and other websites. Afterwards, reports with reference to cybercrime, cyberterrorism, hacktivism, cyberattacks, misinformation and news summaries are issued. If there is a sign of a criminal offence, evidence is gathered. Such reports are stored for 5 years. Holding — The DPA concluded that there was no violation of the GDPR, that is not applicable in accordance with its Article 2, nor with the Directive (EU) 2016/680, as personal data were not processed, as the reports showed, and there was no evidence that there was any illegal additional processing. Therefore, the presumption of innocence principle applied. Hence, the AEPD archived the case.

### UODO (Poland) - DKE.561.4.2026

*Source: UODO (Poland), 2026-05-22 — https://overview.legal/posts/108997 — original: https://gdprhub.eu/index.php?title=UODO_(Poland)_-_DKE.561.4.2026*

Facts — The DPA initiated an ex officio investigation against an individual (the controller) after several data subjects complained about the controller’s video surveillance extending beyond the boundary of their property to include public roads and the data subjects’ properties. The DPA decided that the controller had unlawfully processed data subjects’ data. The DPA held that the controller had the obligation to erase the data, and prohibited the controller from future monitoring. The DPA later requested the controller to provide evidence of compliance with the decision, but did not receive a response from the controller. The DPA received a complaint from one of the data subjects, stating that the controller continued to violate the GDPR despite the DPA’s decision. The DPA found that the controller had reinstalled the cameras and continued to cover areas outside their property, even after the cameras were removed by police officers. Holding — The DPA found a violation of Article 5(2) GDPR, as the controller had failed to demonstrate compliance with the DPA’s decision. The DPA stated that the obligation to demonstrate compliance with the principle of lawfulness (Article 5(1)(a) GDPR) extended to complying with decisions from the DPA. The DPA reiterated that the controller processed data subjects’ personal data unlawfully through their surveillance camera. The DPA took into account the small size of the local community and the number of data subjects affected, and concluded that the controller’s continuous monitoring disrupted the community’s functioning by deeply interfering with data subjects’ lives. In addition, the DPA stated that the manner in which the controller used the surveillance footage suggested that the processing purpose was to harass data subjects. The DPA fined the controller PLN 26,711 (approximately €6,174).

### Garante per la protezione dei dati personali (Italy) - 9794895

*Source: Garante per la protezione dei dati personali (Italy), 2022-06-09 — https://overview.legal/posts/6314 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_9794895*

Facts — The Municipality of Policoro (Basilicata), implemented the use of CCTV cameras to monitor and fight waste abandonment within its territory. A data subject complained the Municipality had breached their data protection right of fair, transparent and lawful processing under art. 5(1)(a) as the sign signaling the CCTV monitoring referred to an outdated legislative decree. They also alleged a breach of art. 5(1)(e) and art. 13 GDPR, in so far the municipality never defined a data retention period for each processing purpose pursued. The last complaint moved forward by the data subject was that by being legally represented in Court by the same lawyer, who also acted as DPO of Policoro, the Municipality gave rise to a conflict of interest situation and breached art. 38(6) GDPR. The Municipality argued that the claim had been done in front of the Justice of Peace, who had no competency to decide on issues of privacy. It was also alleged the judgement only pertained an administrative matter, without rising any data protection concerns or a situation of conflict of interest with the Municipality's DPO. The last argument alleged the processing and retention of the CCTV footage was related to illegal dumps within the municipal territory, meaning the filming had been carried out in the course of judicial police investigations and the data retention periods of the GDPR did not apply in this case. Holding — The Italian DPA held that in this case the Municipality was carrying activities of data processing, by surveilling public entities by means of surveillance cameras. It also noted, that in par. 41 of the Guidelines 3/2019 on the Processing of Personal Data by Video Devices, waste management is "among the institutional activities entrusted to local authorities". This means the surveillance done by the Municipality of Policoro, a task carried out in the public interest in connection with the exercise of official authority as per art.6(1)(e) GDPR, was unrelated to public security and/or judicial police and obliging the controller to comply with data protection principles. The DPA found that the information provided in regards to the processing of personal data by means of surveillance cameras, did not meet the requirements of conciseness, transparency, intelligibility and easy readability contained in art. 5(1)(a) GDPR. The Municipality of Policoro had failed to provide suitable first-level information to the data subject, in so far the sign signaling the CCTV surveillance made reference to an outdated legislative decree (d.lgs 196/03) instead of the one currently in force (d.lgs 101/18). Furthermore, the data controller failed to provide the data subject with an adequate notice on second-level processing of their data. The signage did not include information on the most suitable impacts of the processing or an indication of a website, where to consult an extended version of the explanation. The DPA also found a violation of art. 13 GDPR as well as the principles of storage limitation and accountability in art. 5(1)(e) and art. 5(2). It stated that "the longer the intended storage period (especially if longer than 72 hours), the more reasoned the analysis referring to the legitimacy of the purpose and necessity of storage must be". In this case, the data controller not only failed to set a maximum retention period for the images taken for the purpose of combating illegal littering, but also established the administrative fines for the violation two months after the images were recorded. This did not allow for the data controller to respect the principle of accountability. Lastly, the DPA addressed the alleged conflict of interest raised by the involvement of the Policoro's DPO in the legal proceedings brought against the data subject. The DPA ruled DPOs "may perform other duties and functions," with the understanding that "the controller must ensure that such duties and functions do not give rise to a conflict of interest." The DPA also made reference to the Article 29 WP's Guidelines on Data Protection Officers, in which it is urged to not designate DPOs already acting as defense counsel for the same court. In the case at hand, it resulted that the DPO shared with the Municipality an interest in obtaining a rejection of the appeal. Consequently, the Italian Garante held this to be in violation of art. 38(6) GDPR, as well the fact that it undermined the DPO's independence. The Italian DPA held a cumulative breach of art. 5(1)(a) and (e) and (2) (in conjunction with article 24), 12, 13 and 38(6) GDPR. It balanced the fact that the personal data processing affected all other citizens, who passed through the areas under surveillance, against the lack of previous violations committed by the data controller. The DPA issued a fine of €26,000 EUR to the Municipality of Policoro.

### EDPS - 2020-1013

*Source: EDPS, 2022-01-05 — https://overview.legal/posts/122849 — original: https://gdprhub.eu/index.php?title=EDPS_-_2020-1013*

Facts — In January 2021, noyb filed a complaint against the European Parliament on behalf of six Members of the European Parliament over an internal coronavirus testing website. The issues raised were: confusing and unclear cookie banners, vague and unclear data protection notices, and the illegal transfer of data to the US. Holding — On data controllership — According to the EDPS, the processor may enjoy a considerable degree of autonomy in providing its services and may identify the ‘non-essential’ elements of the processing operation. Furthermore, the processor may advise or propose certain measures in this respect, but it is up to the controller to decide whether to accept such advice or proposals. The analysis of the EDPS shows that the European Parliament (EP) delegated some aspects on the setting up and functioning of the website to Ecolog. The EDPS considers the EP acts as the sole data controller for the processing in question (i.e. the operation of the Parliament’s dedicated website) whereas Ecolog acts as a processor. After having assessed the instructions given by the EP to the processor, the EDPS concluded that the EP did not show the necessary diligence required from a data controller and, ultimately, failed to comply with the Regulation on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data 2018/1725 (hereafter Regulation 2018/1725), in particular with Articles 26(1) and 29(1). Moreover, the EDPS considered that the EP failed to provide the necessary detailed instructions to Ecolog for the setting up of the website, including the drafting of the data protection notice. The absence of documented instructions is therefore in violation of Article 29(3) Regulation 2018/1725. Transparency and information requirements — The EDPS confirmed that the data protection notice published at the time of the complaint did not reflect the processing done by the EP, since it merely consisted of a copy of the testing center of Zaventem's airport. Moreover, the reference made in the document to Article 6(1)(f) GDPR was wrong since it stems from the same error. The EDPS confirmed that the EP did not meet its transparency requirements. The EDPS also analysed the updated version of the data protection notice during the procedure and raised several remaining -and even new- inconsistencies and issues. Among other things, the following problems persisted after the data protection notice was updated: a mere reference to Article 15 and 16 Regulation 2018/1725 is misleading as it should apply in its entirety; the reference to the processing of health data is not correct since no such data are processed in the case at hand; the retention period mentioned is not precise enough; the sections of the data protection notices relating to the recipients of the personal data fail to make any reference to the processor; inconsistencies between the different linguistic versions of the data protection notices were still observed: The English and German versions refer to Ecolog and the Laboratory van Poucke as processors under Article 29 Regulation 2018/1725, whereas the French version refers to them as controllers (‘responsables du traitement’). Moreover, the DPO’s contact details on the website refer to Ecolog in all three linguistic versions of the website, when they should be referring to the Parliament Cookies and transfers of personal data to the US — The EDPS confirmed that tracking cookies, such as the Stripe and the Google analytics cookies, are considered personal data, even if the traditional identity parameters of the tracked users are unknown or have been deleted by the tracker after collection. In the same vein, the EDPS rejected the EP's argument and confirmed that upon installation on a device, a cookie cannot be considered ‘inactive’. Every time a user visited Ecolog’s website, personal data was transferred to Stripe through the Stripe cookie, which contained an identifier. The EDPS reached the conclusion that a transfer of data was taking place to the US, via the use of Google and Stripe cookies, since Google Analytics is hosted in the US and the data protection notice referred to a Standard Contractual Clause (SCC) for the transfer of data outside of the EU. However, the Parliament provided no documentation, evidence or other information regarding the contractual, technical or organisational measures in place to ensure an essentially equivalent level of protection to the personal data transferred to the US in the context of the use of cookies on the website. Cookie banner on the Parliament’s dedicated website — The EDPS reminded that: before setting cookies or any other technology falling within the scope of Article 5(3) ePrivacy Directive 2002/58/EC (hereafter ePrivacy Directive), the EU institution must provide the user with adequate information on what is accessed or stored on the user’s terminal equipment, on the purposes of this action and the means for expressing their consent; no action may be performed before the consent is collected. In addition, users must be enabled to withdraw their consent at any time; ‘cookie walls’ are not in line with Regulation 2018/1725, meaning that for consent to be freely given, access to the website’s service and functionalities should not depend on the users’ consent for cookies that are not strictly necessary in the sense described above; in case personal data collected through the cookies are shared with third parties such as analytics partners, the cookie banner should draw the user's attention to it. The EDPS reached the conclusion that the cookie banners in all three languages were not in line with the definition of consent under Article 3(15) Regulation 2018/1725, nor did they meet the requirements of Article 37 Regulation 2018/1725 and Article 5(3) ePrivacy Directive. The cookie banner further failed to provide transparent information regarding the processing of personal data in relation to the cookies on the website. Request for access to personal data — The Parliament was aware that the complainants’ personal data had been processed through the cookies, which were present on the website for the period between 30 September to 4 November 2020, since transfers of personal data had taken place. Consequently, and especially following the EDPS’ inquiry on the matter, the Parliament should have replied to the complainants’ access to personal data request. The Parliament should have provided the relevant information even if it was aware that the processing of the personal data in question was unlawful, as the main purpose of the right of access under Article 15 GDPR is precisely to enable data subjects to become aware of the processing and verify the lawfulness thereof, or exercise other data subject rights. Conclusion — The EDPS concludes that the Parliament has infringed the following articles of Regulation 2018/1725: Articles 26(1) and 29(1) due to its failure to fulfil its responsibilities as controller and use a processor providing sufficient guarantees to implement appropriate technical and organisational measures; Article 29(3) due to its failure to provide documentation relating to the detailed instructions given to the processor for the setting up and functioning of the website; Articles 4(1)(a) and 14, 4(2), and 15 due to its failure to respect the principle of transparency, accountability and the data subjects’ right to information because of the inaccurate data protection notice and cookie banner on the dedicated website; Article 46 and Article 48(2)(b) of the Regulation, due to its reliance on the Standard Contractual Clauses in the absence of a demonstration that data subjects’ personal data transferred to the US were provided an essential equivalent level of protection; Article 37 read in the light of Article 5(3) of the ePrivacy Directive, due to its failure to protect information (the cookies) transmitted to, stored in, related to, processed by and collected from the users’ terminal equipment; Articles 17 and 14(4) due to its failure to reply to the data subjects’ request for access to their personal data. On the basis of the above, the EDPS decides: to issue a reprimand to the Parliament in accordance with Article 58(2)(b) Regulation 2018/1725 for the above infringements; to order the Parliament, pursuant to Article 58(2)(b) Regulation 2018/1725:, to update its data protection notices in the dedicated website in order to provide all relevant information relating to the processing of personal data. The Parliament should address this order within one month from the date of the decision.

### Persónuvernd examines BL ehf over alleged unlawful employee monitoring via shared OneDrive

*Source: Persónuvernd (Island), 2026-07-01 — https://overview.legal/posts/83499 — original: https://gdprhub.eu/index.php?title=Persónuvernd_(Island)_-_2025010358*

Facts — The data subject was an employee of the enterprise BL ehf (the controller). When she started working there, she was provided with a computer set up by the controller’s IT department. The controller had a Microsoft Office 365 subscription, which included OneDrive and Delve for each employee. OneDrive is a cloud storage service linked to a user account, where files may be stored online rather than only locally. The data subject lodged a complaint with the Icelandic DPA (Persónuvernd) against the controller. She argued that she had been subject to unlawful electronic surveillance during her employment and that colleagues had gained unauthorised access to her computer. According to the data subject, the controller had configured her work computer and the software installed on it in such a way that colleagues and supervisors could monitor her work and view personal data stored on her desktop. She claimed that all of her data was automatically saved to a shared OneDrive of the controller and integrated into Delve. According to the data subject, through Delve her personal data was accessible to her colleagues, including passwords, personal work documents, employee-related documents, payslips and a medical certificate. She also claimed that she had witnessed a colleague opening those documents on the colleague’s own work computer. The controller denied that it had subjected the data subject to electronic surveillance or that the access controls for her file storage areas were inadequate. It argued that OneDrive was a personal file storage area assigned to each employee, that employees could access other employees’ documents only if those documents had been shared with them, and that the data subject’s personal data had been adequately secured through access controls. Holding — The DPA found no evidence that a shared enterprise OneDrive existed to which the data subject’s personal data had been automatically copied or linked. Instead, it found that the relevant OneDrive was the data subject’s personal OneDrive, assigned to her as an employee under the controller’s corporate Microsoft 365 subscription. The DPA also discovered no indication that the data subject’s colleagues or supervisors had access to her OneDrive desktop folder through permissions in the folder’s security settings. Although the “Everyone” group appeared in the list of users or groups in the security settings, the evidence submitted with the complaint did not show that this group had any defined access rights. Nor did the fact that the data subject had access to a colleague’s file prove that the controller’s access controls were defective, since the evidence indicated that employees could grant each other access to files stored in their respective file storage areas. The DPA further held that Delve view counts could not, on their own, prove that unauthorised third parties had viewed the data subject’s documents. The view count was not broken down by user and could include views by the document owner herself. It could therefore only show that the relevant document had been opened a certain number of times by users who had access to it, not that unauthorised access had occurred. The DPA therefore concluded that it was unproven that the controller had carried out electronic monitoring of the data subject or that unauthorised colleagues had accessed personal data stored in her file storage areas. It also held that the controller had ensured appropriate security of the data subject’s personal data through access controls, in accordance with Article 5(1)(f) GDPR, Article 5(2) GDPR and Article 32(1) GDPR.

### AEPD sanctions ACVIL Aparcamientos for denying access to parking surveillance footage

*Source: AEPD (Spain), 2026-07-21 — https://overview.legal/posts/144029 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS-00159-2025*

Facts — On 13 December 2024, the DPA received a complaint against ACVIL Aparcamientos, S.L.U., the controller, concerning a request for video surveillance footage from a car park. The data subject’s vehicle had allegedly been damaged while parked in a facility operated by the controller. On 23 February 2024, the data subject’s legal representative requested access to the footage recorded between 12 and 19 February 2024. The request sought the images showing the collision or, alternatively, the licence plate of the vehicle responsible. The data subject also expressly requested that the controller preserve the relevant footage because it was required for the establishment, exercise or defence of legal claims. The controller acknowledged receipt of the request but did not provide a substantive response until 4 April 2024, after the one-month period under the GDPR had expired. It stated that the footage could only be disclosed to the police or a judge and instructed the data subject to file a police report. After the data subject challenged that requirement and reiterated both the access and preservation requests, the controller responded that it would not provide the recordings and that the footage had already been deleted. During the proceedings, the controller argued that the request was excessive because it covered footage from 16 cameras over several days, amounting to approximately 3,072 hours of recordings. It also maintained that the footage contained personal data relating to numerous third parties and that it was not established that the damage had occurred inside the car park. The controller acknowledged, however, that it had not explained these considerations to the data subject, asked the data subject to narrow the request or notified an extension of the response period. Holding — The DPA held that the controller infringed Articles 15 and 18 GDPR. Regarding Article 15 GDPR, the DPA found that the controller failed to respond to the access request within the one-month period required under Article 12(3) GDPR. Although the controller considered the request complex and excessive, it neither informed the data subject of an extension within the initial one-month period nor explained why it considered the request excessive. The DPA noted that the controller could have asked the data subject to provide additional information to narrow the search. It could also have reviewed the recordings and provided only the footage necessary for the specific incident, applying measures such as blurring or limiting the disclosed extract to protect third parties. The DPA rejected the controller’s position that the footage could only be provided following a request from the police or a court. The exercise of the right of access was not conditional on the prior filing of a police report. The controller was required to assess the request under the GDPR and provide a reasoned and timely response. The failure to respond in time resulted in the deletion of the requested footage. Consequently, the data subject was prevented from obtaining information that could have been relevant to identifying the person responsible for the damage and pursuing a legal claim. Regarding Article 18 GDPR, the DPA held that the data subject had expressly requested the preservation of the recordings for the establishment, exercise or defence of legal claims. Under Article 18(1)(c) GDPR, processing must be restricted where the controller no longer needs the data for its original purposes but the data subject requires it for legal claims. The controller did not address this request and deleted the footage under its ordinary retention schedule. The DPA considered that Article 22(3) Spanish Data Protection Act (LOPDGDD), which generally requires video surveillance images to be erased within one month, did not justify disregarding a valid restriction request. Once the data subject requested preservation for potential legal proceedings, the controller was required to retain the relevant images rather than erase them. The DPA also linked the preservation of the evidence to the data subject’s right to effective judicial protection under Article 24(1) of the Spanish Constitution. Deleting the footage made it more difficult for the data subject to identify the responsible party and exercise their rights before a court. The DPA initially imposed two fines of €75,000: one for the infringement of Article 15 GDPR and one for the infringement of Article 18 GDPR, amounting to €150,000 in total. The controller acknowledged liability and voluntarily paid the fine. Under Article 85 of Spanish Administrative (Law 39/2015), it received a 20% reduction for acknowledging liability and a further 20% reduction for voluntary payment. Consequently, the initial fine of €150,000 was reduced by 40% to a final amount of €90,000. The DPA also ordered the controller to adopt the compliance measures specified in the decision initiating the proceedings and to report their implementation to the DPA within three months after the decision became final and enforceable.

### Italian DPA: vehicle tracking by Liguria Health Agency lawful, information duties met

*Source: Garante per la protezione dei dati personali (Italy), 2026-05-28 — https://overview.legal/posts/53883 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_382/2026*

Facts — A data subject filed a complaint before the DPA against the Liguria Health Protection Agency (the controller). The data subject was employed by the Ligurian Social and Health Care Agency, however, the organisation was later merged with the controller. According to the data subject, the controller initiated discliplinary proceedings and suspended them based on data collected unlawfully through a tracking system in the company vehicle. The data subject also argued that the controller did not sufficiently inform employees that their location was being tracked through the company vehicles. The DPA received several complaints from other data subjects, and joined the complaints. The controller argued that the geolocation system was a measure to protect its assets, to optimise the management of its vehicles, and to ensure worker safety (e.g. to ensure that an employee followed the route while carrying hazardous materials). The controller argued that it did not process employees’ personal data, as it tracked the vehicles themselves and did not link the vehicle with the employee. Finally, the controller argued that the tracking was in compliance with its workers’ statutes. Holding — The DPA first stated that the controller had complied with its information obligations. Following the collective bargaining agreement, the controller informed data subjects of how their data was going to be processed. In addition, the controller had included a notice on how their location data was processed. Therefore, the DPA did not find a violation of Article 13 GDPR. The DPA found a violation of Article 5(1)(c) GDPR. The DPA found that the controller systematically and continuously monitored employees assigned company vehicles, as they were tracked at very frequent intervals without allowing them to deactivate the tracking. The DPA found this frequent tracking particularly detrimental to data subjects’ rights and freedoms, because the controller was able to access real-time information on vehicle movements. The DPA considered that the controller processed more data than necessary for its purposes, and that it risked processing data related to data subjects’ personal lives. The controller’s need to ensure that hazardous materials are transported safely did not justify continuously monitoring employees, especially because the controller later increased the interval of monitoring to every 15 minutes. Finally, the DPA dismissed the argument that the controller only tracked vehicles and not data subjects. This is because the controller could identify the data subject at any time by checking the logbook inside the vehicles. The DPA also found a violation of Articles 5(1)(a), (b), 6 and 88 GDPR. The DPA stated that a collective bargaining agreement was a necessary but not always sufficient condition for the data processing activities to be lawful. This means that the controller must comply with both labour and data protection legislation. Given the excessive amount of data processed, the DPA found that the controller did not have a legal basis to process this data. The DPA found that the controller also unlawfully further processed the location data of data subjects for disciplinary proceedings, in violation of the principle of purpose limitation. This is because the disciplinary proceedings did not specifically concern the data subject’s movements detected by the tracking system, but rather the data subject’s failure to notify potentially dangerous situations that occurred during the performance of their duties. Finally, the DPA found a violation of Articles 25 and 35 GDPR. The DPA found that the controller failed to choose a less invasive solution during the design phase. Therefore, its processing activities did not meet the requirements of privacy by design and default (Article 25 GDPR). The controller violated Article 35 GDPR by not conducting a data protection impact assessment (DPIA) before processing data subjects’ location data. The controller’s awareness of data protection issues and evidence of introducing measures to protect data subjects was not sufficient to meet this requirement. The DPA fined the controller €6,000. The DPA took into consideration the changes the controller had made during its investigations, including adjusting the interval of tracking vehicles from every 60 seconds to every 15 minutes

## Recent developments

### ICO (UK) - ACRO Criminal Records Office

*Source: GDPRhub, 2026-08-21 — https://overview.legal/posts/291401 — original: https://gdprhub.eu/index.php?title=ICO_(UK)_-_ACRO_Criminal_Records_Office*

The ICO reprimanded ACRO for failing to implement appropriate security measures, including effective patch management and security monitoring, resulting in prolonged unauthorised access to systems containing sensitive personal data. English Summary. Facts. ACRO Criminal Records Office, the processor, is a national police unit providing public services including Police Certificates, International Child Protection Certificates, Subject Access Requests and Record Deletion Requests. It processes per

### VG Berlin - 42 K 73/25

*Source: GDPRhub, 2026-08-18 — https://overview.legal/posts/291280 — original: https://gdprhub.eu/index.php?title=VG_Berlin_-_42_K_73/25*

A court annulled a reprimand issued by the DPA and held that requiring a photo ID to access outdoor swimming pools and video surveillance in the entry and exit areas constituted necessary processing for a task carried out in the public interest.A court held that requiring a photo ID to access outdoor swimming pools and video surveillance in the entry and exit areas were necessary to prevent crimes and provide safety to swimmers and staff members. Therefore, the court considered the processing la

### VG Berlin - 42 K 51.25

*Source: GDPRhub, 2026-08-18 — https://overview.legal/posts/291291 — original: https://gdprhub.eu/index.php?title=VG_Berlin_-_42_K_51.25*

English Summary The data subject appealed the DPA decision in April 2025. He argued that there was no particular threat that would justify the installation of a video surveillance system. According to the data subject, an on-site investigation carried out by the Berlin police supported this view.The data subject appealed the DPA decision in April 2025. He argued that there was no particular threat that would justify the installation of a video surveillance system. According to the data subject,

### 1,741 “informed” consents with one click?! GDPR complaint against dict.cc filed

*Source: noyb - European Center for Digital Rights, 2026-07-30 — https://overview.legal/posts/184576 — original: https://noyb.eu/en/1741-informed-consents-one-click-gdpr-complaint-against-dictcc-filed*

Cookie Banners Today, noyb has filed a complaint against the popular online dictionary dict.cc. The GDPR requires that consent is freely given, informed, specific and unambiguous. However, when visiting dict.cc, users are nudged into consenting to online tracking by a staggering 1,741 (!) “partners” with a single click. This makes it impossible for users to know exactly who has access to their data and how it is actually used. While dict.cc is an extreme example, requests to blindly waive your r

### Nordic Media Giant Schibsted switches to “Pay or Okay” – complaint filed!

*Source: noyb - European Center for Digital Rights, 2026-06-03 — https://overview.legal/posts/53125 — original: https://noyb.eu/en/nordic-media-giant-schibsted-switches-pay-or-okay-complaint-filed*

Forced Consent & Consent Bypass Today, the Norwegian Consumer Council (Forbrukerrådet) and noyb have filed a complaint against the Norwegian news publisher Schibsted for implementing a “Pay or Okay” system across its products. Schibsted is one of the largest news publishers in the Nordics and owns well-known brands such as TV4, Aftenposten E24 and VG. The company’s introduction of “Pay or Okay” sets a dangerous precedent for free consent across the Nordic countries, which follows the wide-spread

## Literature

### General-Purpose AI under the EU AI Act: A Conceptual Allocation of Duties across the Value Chain

*Source: SCRIPTed A Journal of Law Technology & Society, 2026-06-30 — https://overview.legal/posts/132370 — original: https://doi.org/10.2218/scrip.12300*

This article examines how the final version of the EU Artificial Intelligence Act (“AI Act”, adopted 2024) allocates obligations across the AI value chain, with a focus on general-purpose AI (“GPAI”) or foundation models. It proposes a taxonomy of key actors – foundation model providers, fine-tuners, integrators, and deployers – and analyses the interfaces between them, including documentation tools (model cards, system cards) and logging requirements. Building on principles of control, foreseea

### Effective Regulation through Design – Aligning the ePrivacy Regulation with the EU General Data Protection Regulation (GDPR): Tracking Technologies in Personalised Internet Content and the Data Protection by Design Approach

*Source: SSRN Electronic Journal, 2021-01-01 — https://overview.legal/posts/132422 — original: https://doi.org/10.2139/ssrn.3945471*

### Artificial Intelligence in Decision-making: A Test of Consistency between the “EU AI Act” and the “General Data Protection Regulation”

*Source: Athens Journal of Law, 2025-01-02 — https://overview.legal/posts/132443 — original: https://doi.org/10.30958/ajl.11-1-3*

The recent Regulation that sets down harmonised rules on Artificial Intelligence in the European Union, known as the "AI Act," includes a significant requirement for human oversight in high-risk AI systems during their use (art. 14). This requirement embodies the "human-in-command" approach, ensuring both legal and ethical compliance. The AI Act is intended to complement the General Data Protection Regulation (hereinafter GDPR), thereby forming a consistent and comprehensive legal framework. Thi

### European Union ∙ New EDPB Guidance Expands the Technical Scope of Article 5(3) ePrivacy Directive to Many Standard Tracking Technologies

*Source: European Data Protection Law Review, 2025-01-01 — https://overview.legal/posts/132452 — original: https://doi.org/10.21552/edpl/2024/4/8*

### GDPR Enforcement Beyond EU-Borders — The Dutch Data Protection Authority’s Fine on Clearview AI and the Future of AI Regulation Enforcement

*Source: Computer Law Review International, 2025-03-01 — https://overview.legal/posts/132514 — original: https://doi.org/10.9785/cri-2025-260103*

Abstract After a brief introduction (I.), the article summarises the reasoning of the Dutch Data Protection Authority (II.) and examines the challenges of enforcing GDPR against companies outside the EU (III.) as well as the potential future impact of the upcoming European Union Artificial Intelligence (AI) Act on such cases (IV.). A particular emphasis is placed on how the AI Act’s provisions may influence future regulatory decisions and enforcement actions involving AI technologies such as fac

## Tools

### CookieViz — visualise web tracking (CNIL)

*Source: CNIL, 2026-07-17 — https://overview.legal/posts/125634 — original: https://github.com/LINCnil/CookieViz*

Open-source tool by the French DPA's innovation lab that visualises in real time which third parties are notified while you browse: cookies set, trackers loaded and the network of data flows between sites — useful for demonstrations and cookie audits.

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Law Enforcement** — https://overview.legal/topics/law-enforcement
  Processing for law enforcement purposes

---
Generated by overview.legal · https://overview.legal/topics/monitoring · 2026-08-22
