# Notified Body Independence — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/notified-body-independence-impartiality
> Sources are cited per item. Verify against the official texts before relying on them.

Notified bodies must maintain strict independence and impartiality standards, which are critical operational obligations that warrant a dedicated topic for detailed coverage.

## Overview

## Legal Framework

Notified body independence is grounded in several overlapping EU and national provisions. DSA Recital 112 establishes that competent authorities designated under the regulation must act fully independently from both private and public bodies, without the obligation or possibility to seek or receive instructions — even from government. This independence is balanced against constitutional requirements and the obligation to cooperate with other competent authorities, Digital Services Coordinators, the Digital Services Board, and the Commission. DSA Recital 59 extends independence requirements to out-of-court dispute settlement bodies, requiring that independence be ensured not only at the institutional level but also at the level of the natural persons charged with resolving disputes, through explicit conflict-of-interest rules. At the national level, procurement law provisions such as Article 2.87(1)(e) in conjunction with Article 1.10b of the Dutch Public Procurement Act 2012 mandate exclusion of contractors where a conflict of interest compromises impartial performance. Article 3:40 of the Dutch Civil Code provides the broader nullity framework for acts conflicting with public policy, which encompasses violations of independence principles.

## Key Developments

The Gerechtshof Den Haag ruling of 30 June 2026 (cases 200.361.266/01, 200.361.440/01, and 200.361.896/01) clarifies the threshold for establishing that a conflict of interest undermines procurement integrity. The court examined whether a share transaction between municipal entities and a private party constituted prohibited state aid that should have triggered exclusion under Article 2.87(1)(e) jo. 1.10b Aw 2012. The court held that the claimant failed to sufficiently demonstrate that the transaction involved unlawful state aid influencing the procurement procedure's pricing, and consequently could not establish that the contracting authority should have excluded the bidder on conflict-of-interest grounds. The ruling reinforces the Xafax jurisprudence, under which a contract between a contracting authority and a contractor can only be set aside in appeal proceedings where nullity under Article 3:40 BW applies — specifically, conflict with public policy other than procurement law itself. The court's reasoning establishes that mere allegations of financial entanglement or below-market transactions are insufficient; parties must demonstrate a concrete causal link between the alleged conflict and the procurement outcome. Separately, the exhibitie procedure under Article 843a Rv confirms that a mediator's disclosure obligation regarding direct or indirect interests constitutes a statutory legal relationship, giving clients a right to inspect documents relevant to assessing whether a conflict of interest compromises representation.

## Practical Guidance

- **Structural separation**: Implement organizational firewalls ensuring that personnel involved in conformity assessment or dispute resolution cannot receive instructions from any government body, market participant, or affiliated entity, consistent with the independence standard articulated in DSA Recital 112.

- **Individual-level conflict protocols**: Maintain written conflict-of-interest declarations for every natural person involved in assessment or dispute resolution activities, requiring recusal where any direct or indirect financial or personal interest exists — the standard demanded by DSA Recital 59.

- **Transaction vetting**: Before engaging contractors or transferring ownership interests involving notified body functions, conduct documented market-conformity pricing analyses to pre-empt state aid and conflict-of-interest challenges under Article 2.87(1)(e) Aw 2012.

- **Evidentiary readiness**: Preserve records demonstrating the absence of any causal link between alleged financial entanglements and assessment or procurement outcomes, as the Gerechtshof Den Haag ruling places the burden squarely on the challenging party to prove such a nexus.

- **Disclosure as legal obligation**: Treat conflict-of-interest disclosure not merely as best practice but as a statutory obligation creating enforceable legal relationships, giving affected parties potential inspection rights under Article 843a Rv.

## Legislation (full text of key provisions)

### Recital 59 — certified out-of-court dispute settlement

*Source: DSA, dsa-rec-59-en, 2022-10-19 — https://overview.legal/posts/95515*

In addition, provision should be made for the possibility of engaging, in good faith, in the out-of-court dispute settlement of such disputes, including those that could not be resolved in a satisfactory manner through the internal complaint-handling systems, by certified bodies that have the requisite independence, means and expertise to carry out their activities in a fair, swift and cost-effective manner. The independence of the out-of-court dispute settlement bodies should be ensured also at the level of the natural persons in charge of resolving disputes, including through rules on conflict of interest. The fees charged by the out-of-court dispute settlement bodies should be reasonable, accessible, attractive, inexpensive for consumers and proportionate, and assessed on a case-by-case basis. Where an out-of-court dispute settlement body is certified by the competent Digital Services Coordinator, that certification should be valid in all Member States. Providers of online platforms should be able to refuse to engage in out-of-court dispute settlement procedures under this Regulation when the same dispute, in particular as regards the information concerned and the grounds for taking the contested decision, the effects of the decision and the grounds raised for contesting the decision, has already been resolved by or is already subject to an ongoing procedure before the competent court or before another competent out-of-court dispute settlement body. Recipients of the service should be able to choose between the internal complaint mechanism, an out-of-court dispute settlement and the possibility to initiate, at any stage, judicial proceedings. Since the outcome of the out-of-court dispute settlement procedure is not binding, the parties should not be prevented from initiating judicial proceedings in relation to the same dispute. The possibilities to contest decisions of providers of online platforms thus created should leave unaffected in all respects the possibility to seek judicial redress in accordance with the laws of the Member State concerned, and therefore should not affect the exercise of the right to an effective judicial remedy under Article 47 of the Charter. The provisions in this Regulation on out-of-court dispute settlement should not require Member States to establish such out-of-court settlement bodies.

## Case law

### Judgment of the Court (Fifth Chamber) of 9 July 2020.#European Commission v Ireland.#Failure of a Member State to fulfil obligations — Principles governing the investigation of accidents in the maritime transport sector — Directive 2009/18/EC — Article 8(1) — Parties whose interests could conflict with the task entrusted to the investigative body — Members of the investigative body simultaneously performing other functions — Failure to provide for an independent investigative body.#Case C-257/19

*Source: Court of Justice of the European Union, C-257/19, 2020-07-09 — https://overview.legal/posts/132332 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62019CJ0257*

The European Commission brought infringement proceedings against Ireland under Article 258 TFEU, alleging that Ireland failed to establish a maritime accident investigative body independent in its organization, legal structure, and decision-making from any party whose interests could conflict with its investigative task, as required by Article 8(1) of Directive 2009/18/EC. The Court of Justice (Fifth Chamber) found that Ireland had breached its obligations under the Directive by permitting members of its investigative body to simultaneously perform functions that could create conflicts of interest, thereby compromising the body's independence.

### CJEU - C-614/10 - Commission v. Austria

*Source: GDPRhub, 2012-10-16 — https://overview.legal/posts/125643 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-614/10_-_Commission_v._Austria*

Facts — On 5 July 2005 the European Commission sent a letter of formal notice to the Republic of Austria in which it claimed that the organisation of the Austrian Data Protection Commission (Datenschutzkommission – DSK) failed to satisfy the criterion of independence set out in the second subparagraph of Article 28(1) Directive 95/46/EC. The Commission did not consider the observations of the Republic of Austria satisfactory and, therefore, issued a reasoned opinion pursuant to Article 258(1) TFEU. On 9 December 2009, the European Commission brought the matter in front of the Court of Justice of the European Union. The Commission and the EDPS noted that, according to the then-current national law, the managing member of DSK needed to be a member of the Federal Chancellery (Bundeskanzleramt). More in general, they pointed out that the office of DSK was structurally integrated with the departments of the Chancellery. They argued that this was contrary to the criterion of independence set out in the second subparagraph of Article 28(1) Directive 95/46/EC, as staff members were subject to the supervision of the Chancellery. The Republic of Austria argued that the requirement of set by the second subparagraph of Article 28(1) Directive 95/46/EC relates to “functional independence” and that the DSK had such independence, since § 37(1) of the then-in force Austrian Data Protection Code (Datenschutzgesetz - DSG 2000) provided for its members to be independent and not to be bound by instructions given by the government. It pointed out that the managing member did not necessarily need to be a member of the Chancellery and could be chosen among lawyers working in the federal public administration. Holding — Firstly, the court noted that Article 8(3) CFR, Article 16(2) TFEU and Article 28(1) Directive 95/46/EC require Member States to have a supervisory authority which have complete independence. The court found that the independence of the supervisory authority is an essential component of the protection of individuals with regard to the processing of personal data. Secondly, the court set aside the argument of the Republic of Austria that the DSK has a sufficient degree of independence since it satisfied the condition of independence inherent in Article 267 TFEU for it to qualify as a court or tribunal of a Member State. The court held that the notion of “complete independence” under data protection law is autonomous and independent from the one under Article 267 TFEU. Thirdly, the court gave its interpretation of the concept of “complete independence” set by Article 28(1) Directive 95/46/EC. To do that, the court referred to its previous judgement C-518/07, Commission v. Germany. In this judgement, it had held that this concept should be interpreted as meaning that the supervisory authorities must enjoy an independence which allows them to perform their duties free from any external influence, direct or indirect, which is liable to have an effect on their decisions. Applying this principle to the case at hand, the court found that the requisite of functional independence, like the one accorded to the DSK, is a condition which is essential to have a “complete independence”. However, this condition by itself is not sufficient to protect that supervisory authority from all external influence. On the contrary, according to the court, some pieces of Austrian legislation did not allow the DSK to be completely free from any indirect influence. For example, according to § 36(3) and § 38(1) DSG 2000 the managing member of the DSK is a federal official. Moreover, § 45(1) of the 1979 Law on the conditions of service of officials (Beamten-Dienstrechtsgesetz 1979 - BDG 1979) grants the hierarchical superior an extensive power of supervision over their officials and to encourage the promotion of their staff. Furthermore, the court held that the fact that the staff of the DSK was composed by federal officials was not compliant with the independence requirement, given that these officials are subject to supervision by the Federal Chancellery within the terms of § 45(1) BDG 1979. Finally, the court noted that the Federal Chancellor has the right to be informed at all times by the chairman and the managing member of all aspects of the work of the DSK, according to Article 20(2) of the Federal Constitutional Law (Bundes Verfassungsgesetz – BVG) and § 38(2) DSG 2000. On this matter, the court ruled that such a right to information is also liable to subject the DSK to indirect influence, given that it is far-reaching as it covers “all aspects of the work of the DSK” and that it is unconditional. On these grounds, the CJEU held that, by failing to take all of the measures necessary to ensure that the legislation in force in Austria meets the requirement of independence, the Republic of Austria has failed to fulfil its obligations under Article 28(1) Directive 95/46/EC.

### Judgment of the Court (Grand Chamber), 16 October 2012.#European Commission v Republic of Austria.#Failure of a Member State to fulfil obligations – Directive 95/46/EC – Processing of personal data and free movement of such data – Protection of natural persons – Article 28(1) – National supervisory authority – Independence – Supervisory authority and the Federal Chancellery – Personal and organisational links.#Case C‑614/10.

*Source: Court of Justice of the European Union, C-614/10, 2012-10-16 — https://overview.legal/posts/132377 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62010CJ0614*

The European Commission brought an infringement action against the Republic of Austria under Article 258 TFEU, alleging that Austria failed to ensure the independence of its Data Protection Commission (DSK) as required by the second subparagraph of Article 28(1) of Directive 95/46/EC. The Commission challenged the personal and organisational links between the DSK and the Federal Chancellery, including the Federal Chancellor's authority to establish the DSK's office, provide staff, and be informed of all aspects of the DSK's work. The Court ruled that Austria had failed to fulfil its obligations under the Directive by not guaranteeing the DSK's complete independence in exercising its functions.

### Judgment of the Court (Sixth Chamber) of 9 February 2023.#X-FAB Dresden GmbH & Co. KG v FC.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 38(3) – Data protection officer – Prohibition on dismissing data protection officer for performing his or her tasks – Requirement for functional independence – National legislation prohibiting

*Source: Court of Justice of the European Union, C-453/21, 2023-02-09 — https://overview.legal/posts/132296 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0453*

In Case C-453/21, the CJEU addressed a preliminary reference from the Bundesarbeitsgericht concerning X-FAB Dresden GmbH & Co. KG's dismissal of its employee FC from the position of data protection officer. The Court interpreted Article 38(3) and (6) GDPR, ruling that the second sentence of Article 38(3) is valid and that the prohibition on dismissing a DPO for performing their tasks implies DPOs must enjoy enhanced protection against dismissal beyond the general protections afforded to ordinary employees, while also clarifying that conflicts of interest under Article 38(6) must be assessed based on whether a DPO's additional duties could lead them to determine the purposes and means of processing personal data. No fine was imposed as the proceedings involved interpretation of EU law rather than an enforcement action.

### CJEU - C-288/12 - European Commission v Hungary

*Source: GDPRhub, 2014-04-08 — https://overview.legal/posts/158449 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-288/12_-_European_Commission_v_Hungary*

Facts — On 29 September 2008, Mr Jori was appointed Data Protection Supervisor for a 6 year term, which would terminate around the end of September 2014. However, Mr Jori was asked to vacate the office on 31 December 2011. Upon proposal by the Hungarian Prime Minister, Mr Peterfalvi was appointed as Head Authority for a term of nine years. Advocate General Opinion — The AG considers that the European Commission does not dispute in any way the right of Hungary to modify its institutional set up for its data protection authority. The issue disputed is that, in changing the institutional set up, Hungary failed to fulfil its obligation to respect the independence of their supervisor by terminating its employment before the beginning of their term. Article 28(1) Dir.95/46 puts forward the need for supervision of the personal data protection by an independent authority as an essential component of the protection of individual in personal data processing. As found by the CJEU in C-518/07, the term “with complete independence” is interpreted broadly and autonomously in light of the objective to ensure the effectiveness and reliability of the supervision of data protection compliance. Moreover, the guarantee of independence is established not to grant a special status to those authorities themselves as well as their agents but rather to strengthen the protection of individuals and bodies affected by their decisions. Still from CJEU in C-518/07, the CJEU held that actions that may lead to “prior compliance” would not be consistent with the requirement of “complete independence” which Member States must guarantee their supervisory authority. The AG shares the European Commission’s view that independence of an authority must involve a term of office of predetermined duration and that his tenure must be assured until that term of office expires, unless this is precluded for overriding reasons, pre-determined by law and objectively verifiable. Such an intrinsic link between security of tenure throughout the term of office and the “complete independence” requirement is indisputable. Similarly, the independence of a judge cannot be said to be respected if their duties are prematurely terminated under cover of the dismantling of the court in which he sits and its replacement by another court, even if such court is accorded independence. The mere risk that an authority may be compelled to vacate office may expose the authority to which Article 28(1) Dir.95/46 refers to “undue intervention or pressure” and led to a form of “prior compliance” on its part. So, even if Member States have a measure of discretion to establish their institutional structure, it cannot be denied that “complete independence” as required under EU law is predicated under the existence and observance of specific and detailed rules which dispel any reasonable doubt as to the imperviousness of that authority to external factors that, directly or indirectly, may influence the authority’s decisions. Even if the Authority has a different legal status from the Supervisor and operates in accordance with different rules, it has succeeded the Supervisor in the exercise of the tasks attributed to the supervisory authority under Article 28 Dir.95/46. In relation to the claim that institutional change was decided by the constitutional authority, it is clear from the documents before the court that the Authority itself was created by “organic law”. Moreover, institutional changes cannot compromise the effectiveness of the higher obligations imposed by EU law as regards the guarantee of “complete independence”, since the primacy of EU law applied whatever the nature of the national rule at stake. Such changes cannot justify compelling the data protection Supervisor to vacate office before serving his full term. The AG thus concludes its analysis, by claiming that, by prematurely bringing to an end the term to be served by the data protection supervisory authority, Hungary failed to fulfil the obligations of Article 28 Dir.95/46. Holding — The CJEU started its analysis by stating that Article 28(1) Dir.95/46 requires Member States to set up one or more supervisory authorities with complete independence in the exercise of the duties entrusted to them. The obligation to have an independent Supervisory Authority to ensure compliance with data protection law stems directly from primary law of the EU, i.e. Article 8(3) CFR and Article 16(2) TFEU. Having an independent supervisory authority is thus an essential protection of individuals, as confirmed in C-518/07 Commission v Germany. The CJEU decided that the relevant aspect to be examined whether the requirements of Article 28(1) Dir.95/46 to ensure that each supervisory authority is able to carry out the tasks entrusted to it in complete independence entails an obligation for the Member States concerned to allow that authority to serve its full term in office. This provision shall be interpreted as meaning that supervisory authority responsible for supervising the processing of personal data must enjoy an independence allowing them to perform their duties free from external influence. The CJEU previously held that the risk that a Member States’ scrutinizing authorities could exercise a political influence over the decisions of the supervisory authorities is enough to hinder the latter in the independent performance of their tasks due to the following. First, those authorities could exercise “prior compliance”. Second, Article 28(1) Dir.95/46 requires that the supervisory authority’s decisions remain above each suspicion of partiality. In fact, if it was permitted for all Member States to compel a supervisory authority to vacate office before serving its full term, the threat of such premature termination to which that authority would be exposed throughout its term of office could lead it to enter into a form of prior compliance with the political authority, which would completely undermine the requirement of independence. In such a situation, the supervisory authority cannot be regarded as being able to operate impartially. In fact, Article 28(1) Dir.95/46 entails that the independence requirement shall be construed so that the supervisory authority can operate above all suspicions of partiality. Thus, the CJEU highlighted that the independence requirement shall cover the obligation to allow the supervisory authority to serve their full time in office and to have them vacate the office before expiry of the full term only in accordance with the rules and safeguards established by the applicable legislation. As per Article 15(1) Law of 1993, the Supervisor can be called to resign from office only if their term expire, upon death, resignation, declaration of a conflict of interest, compulsory retirement or resignation. These last grounds require a Parliament decision adopted by a two-thirds majority. The CJEU clearly stated that none of these grounds apply to the disputed dismissal and that Hungary obliged the Supervisor to vacate office in contravention of the safeguards established to protect his term of office, consequently compromising their independence as per Article 28(1) Dir.95/46. The claim advanced by Hungary that this dismissal related to an institutional change is also not applicable to the case at hand, according to the CJEU. More specifically, the CJEU considered that, when Member States implement institutional changes, they must ensure that the independence of the supervisory authority under Article 28(1) GDPR is not compromised. This holds particularly true due to the fact that the Supervisor and the subsequently-established Authority are entrusted with identical tasks. Thus, by prematurely ending to end the term served by the supervisory authority for the protection of personal data, Hungary failed to fulfil its obligations under Dir.95/46/EC on the protection of individuals with regards to the processing of personal data on the free movement of such data.

### Judgment of the Court (Second Chamber) of 19 October 2016.#Xabier Ormaetxea Garai and Bernardo Lorenzo Almendros v Administración del Estado.#Request for a preliminary ruling from the Tribunal Supremo.#Reference for a preliminary ruling — Electronic communications networks and services — Directive 2002/21/EC — Article 3 — Impartiality and independence of national regulatory authorities — Institutional reform — Merger of national regulatory authority with other regulatory authorities — Dismissal

*Source: Court of Justice of the European Union, C-424/15, 2016-10-19 — https://overview.legal/posts/132352 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62015CJ0424*

The CJEU ruled on a preliminary reference from the Spanish Tribunal Supremo concerning Xabier Ormaetxea Garai and Bernardo Lorenzo Almendros, who challenged their dismissal as President and board member of the Comisión del Mercado de las Telecomunicaciones following an institutional merger, against the Administración del Estado. The core issue was whether Article 3 of the Framework Directive (Directive 2002/21/EC), as amended, precludes the dismissal of the head or board members of a national regulatory authority before the expiry of their terms of office on grounds not provided for in national law at the time of their appointment. The Court held that EU law requires that grounds for dismissal be laid down in advance in national law, ensuring the independence and impartiality of national regulatory authorities.

### Judgment of the Court (Grand Chamber), 8 April 2014.#European Commission v Hungary.#Failure of a Member State to fulfil obligations — Directive 95/46/EC — Protection of individuals with regard to the processing of personal data and the free movement of such data — Article 28(1) — National supervisory authorities — Independence — National legislation prematurely bringing to an end the term served by the supervisory authority — Creation of a new supervisory authority and appointment of another per

*Source: Court of Justice of the European Union, C-288/12, 2014-04-08 — https://overview.legal/posts/132371 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62012CJ0288*

The European Commission brought an infringement action against Hungary before the Court of Justice (Grand Chamber) under Article 258 TFEU, alleging that Hungary violated Article 28(1) of Directive 95/46/EC by adopting national legislation that prematurely terminated the term of its existing data protection supervisory authority and appointed a new head. The Court ruled that Hungary had failed to fulfil its obligations, holding that the independence of supervisory authorities under Article 28(1) requires that their term of office cannot be brought to an end without legitimate justification, and that a Member State may not reduce the originally established term of office through general legislation without respecting the conditions previously governing the termination of that term. No fine was imposed in this judgment.

### Judgment of the Court (First Chamber) of 22 June 2022.#Leistritz AG v LH.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Second sentence of Article 38(3) – Data protection officer – Prohibition of the dismissal, by a controller or processor, of a data protection officer or of the imposition, by a controller or processor, of a penalty on h

*Source: Court of Justice of the European Union, C-534/20, 2022-06-22 — https://overview.legal/posts/132310 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62020CJ0534*

The Court of Justice of the European Union (First Chamber) ruled on a preliminary reference from the German Bundesarbeitsgericht in a dispute between Leistritz AG and its former data protection officer LH concerning the termination of LH's employment contract following a departmental reorganization. The Court held that the second sentence of Article 38(3) GDPR, which prohibits controllers or processors from dismissing or penalizing data protection officers for performing their tasks, is validly based on Article 16 TFEU and requires Member States to ensure the functional independence of data protection officers, including by maintaining national protections that prevent their dismissal without just cause. No fine was imposed, as the ruling was limited to interpreting and validating the GDPR provision.

### Korkein hallinto-oikeus (Finland) - KHO:2021:125

*Source: Supreme Administrative Court of Finland, 2021-09-10 — https://overview.legal/posts/122863 — original: https://gdprhub.eu/index.php?title=Korkein_hallinto-oikeus_(Finland)_-_KHO:2021:125*

Facts — The Regional Government of Åland had appointed Mr A as head of the regional Ålandic DPA for a probationary period of one year. Pursuant to section 10(2) of the Act on Public Officials in the Region of Åland, the Government of Åland stated that they would not propose the appointment of A to a permanent post and that A's term of office would therefore automatically come to and end after the one-year probationary period. At the end of the probationary period, the Government of Åland issued a notice confirming that Mr A's term of office had ended. Mr A however applied to the Supreme Administrative Court of Finland for the annulment of this decision, which he considered contrary to the GDPR. Holding — The Supreme Administrative Court considered that the notice issued by the Government of Åland constituted an administrative decision terminating Mr A's mandate. The Supreme Administrative Court found that, in addition to national legislation, A's role as head of the data protection authority is also regulated by EU law, and in particular by the GDPR. Although the GDPR does not contain explicit provisions regarding probationary period, the minimum length of the term of any member of any data protection authority is "no less than four years", as set in Article 54(1)(d) GDPR. As a consequence, the termination of A's mandate at the end of the probationary period could not be considered in line with the GDPR. The Supreme Administrative Court further noted that leaving Mr A without any possibility of appeal against that decision would be contrary to the right to a fair trial as protected under the Finnish Constitution, Article 19 TFEU and Article 47 CFR. As Mr A's mandate and termination had not been assessed in the light of the provisions of the GDPR, the Supreme Administrative Court concluded that the decision to terminate Mr A's mandate had to be annulled and the matter referred back to the Government of Åland for reconsideration.

### BVerwG - 6 C 1.24

*Source: German Federal Administrative Court, 2025-11-05 — https://overview.legal/posts/125606 — original: https://gdprhub.eu/index.php?title=BVerwG_-_6_C_1.24*

Facts — The data subject was employed by the German Federal Financial Supervisory Authority (BaFin), the public authority responsible for supervising banks, financial service providers, and insurance companies. He worked as a case officer in a specialised unit dealing with serious financial misconduct, including organised crime and terrorism financing. Due to their work, employees in this unit regularly issue binding decisions, conduct on-site inspections, and may appear as witnesses in criminal proceedings, which makes them identifiable to affected persons. Because several employees in this unit had been threatened in the past, the data subject’s home address had been blocked from disclosure in the population register for many years. When the blocking period expired, he applied for a renewal. The local registration authority refused the request on the ground that no individual threat against the claimant had been demonstrated. The lower administrative court dismissed the data subject’s appeal against the authority’s decision, while the Higher Administrative Court ordered the renewal after the data subject also appealed the first instance court’s decision. The registration authority appealed to the Federal Administrative Court. Holding — The Court dismissed the appeal and confirmed that the blocking of the address had to be granted. The Court held that an address may be blocked where there are objectively verifiable facts showing that disclosure could endanger a person’s life, health, personal freedom, or similarly protected interests. This requires an individualised risk assessment, but it does not require that the applicant has already been personally threatened. Risks arising from a specific professional activity may suffice, particularly where other persons performing essentially the same tasks have been subjected to threats or attacks. In this case, the Court had to find a balance between the public’s right to transparency of information, and the employee’s right to privacy and protection of personal data, under the GDPR and Articles 7 and 8 of the Charter of Fundamental Rights. Applying these principles, the Court found that the claimant’s work in a unit dealing with organised crime and terrorism financing, together with documented threats against colleagues in the same unit, justified the conclusion that disclosure of his address could expose him to serious risks. Where these conditions are met, the registration authority has no discretion and must block the address for the statutory period.

### Judgment of the Court (Third Chamber) of 9 July 2020.#VQ v Land Hessen.#Request for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling — Article 267 TFEU — Concept of ‘court or tribunal’ — Protection of natural persons with regard to the processing of personal data — Regulation (EU) 2016/679 — Scope — Article 2(2)(a) — Meaning of ‘activity which falls outside the scope of Union law’ — Article 4(7) — Concept of ‘controller’ — Petitions Committee of the

*Source: Court of Justice of the European Union, C-272/19, 2020-07-09 — https://overview.legal/posts/132331 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62019CJ0272*

In a preliminary ruling requested by the Verwaltungsgericht Wiesbaden in proceedings between VQ and Land Hessen, the CJEU addressed whether the GDPR applies to the processing of personal data by the Petitions Committee of a German federated state's parliament. The Court held that the activities of such a parliamentary body fall within the scope of Union law and thus within the GDPR's material scope, meaning the parliament's President qualifies as a "controller" under Article 4(7) and is subject to the data subject's right of access under Article 15. No fine was imposed, as the ruling solely provides interpretive guidance on the GDPR's scope and the controller concept.

### OGS Zagreb - Pn-877/2023-29

*Source: Municipal Civil Court in Zagreb, 2026-01-16 — https://overview.legal/posts/52429 — original: https://gdprhub.eu/index.php?title=OGS_Zagreb_-_Pn-877/2023-29*

Facts — A data subject filed a lawsuit against Propuls d.o.o., the controller and publisher of the news portal direktno.hr, claiming that two articles published on 11 January 2023 and 31 January 2023 disclosed her personal data without her consent: The first article reported on payments related to the football club Dinamo Zagreb and included the data subject’s full name, bank account number, and payment amounts. The second article referred to the first article via a hyperlink but did not mention the data subject directly. The data subject argued that the disclosure violated her right to privacy and the protection of personal and family life under Croatian law and the GDPR. She claimed non-material damage and sought compensation as well as publication of the court decision in the controller's news portal. The controller admitted publishing the articles but argued that the information was accurate and that publishing the data served the public interest. The controller also stated that it had issued a correction upon the data subject request and argued that journalistic activity may be exempt from certain obligations under GDPR and it's exempt from liability if the facts concerned are true according to the Croatian Media Law. The evidence included the published articles, the correction request, witness testimony from journalists and the data subject, and financial records. Holding — The court held that the controller violated the data subject’s right to privacy and the protection of personal and family life. It reasoned that publishing her full name, bank account number, and payment amounts was disproportionate because the details were not necessary to inform the public about the football club payments. Following the ECHR jurisprudence, the court applied a proportionality test, balancing the controller’s freedom of expression against data subject's privacy rights under the Croatian Constitution and civil law. The court emphasised that the data subject was not a public figure, had not voluntarily exposed her private life to the media, and did not participate in public debate in a way that could justify disclosing her sensitive data. The court also addressed the controller’s argument regarding journalistic freedom. It recognised that journalists may publish personal data when there is an overriding public interest, such as exposing wrongdoing or contributing to an important debate. However, in this case, the disclosure of the data subject’s bank account and payment amounts was unnecessary for the story’s public interest. The court noted that general information about club payments could have been reported without identifying her. Regarding the harm suffered, the court found that the data subject experienced non-material damage, including emotional stress and intrusion into her private and family life. It awarded €3,000 in damages with statutory interest, while rejecting the additional claim of €3,636.14 as excessive. The court also denied the data subject’s request to publish the decision, explaining that publishing it could further disclose her personal data and undermine her privacy rights.

## Guidance

### Opinion 1/2023 on the draft decision of the competent supervisory authority of Croatia regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to Article 41 GDPR

*Source: EDPB, opinion-12023-on-the-draft-decision-of-the-competent-en, 2023-02-17 — https://overview.legal/posts/125874 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-12023-on-the-draft-decision-of-the-competent_en*

Adopted 1 Opinion 1/2023 on the draft decision of the competent supervisory authority of Croatia regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to Article 41 GDPR Adopted on 3 February 2023 Adopted 2 Table of c ontents 1 Summary of the Facts................................................................................................................... 4 2 Assessment…

### Opinion 9/2019 on the Austrian data protection supervisory authority draft accreditation requirements for a code of conduct monitoring body pursuant to article 41 GDPR

*Source: EDPB, opinion-92019-on-the-austrian-data-protection-supervisory-en, 2019-07-12 — https://overview.legal/posts/126220 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-92019-on-the-austrian-data-protection-supervisory_en*

adopted Opinion 9 /201 9 on the Austrian d ata protection supervisory authority draft accreditation requirements for a code of conduct monitoring body pursuant to a rticle 41 GDPR Adopted on 9 Jul y 201 9 2 adopted Contents 1 Summary of the Facts ................................ ................................ ................................ ..................... 4 2 Assessment ................................ ................................ ................................…

### Opinion 03/2023 on the draft decision of the competent supervisory authority of Romania regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR

*Source: EDPB, opinion-032023-on-the-draft-decision-of-the-competent-en, 2023-02-17 — https://overview.legal/posts/125871 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-032023-on-the-draft-decision-of-the-competent_en*

1 Adopted Opinion 03/2023 on the draft decision of the competent supervisory authority of Romania regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR Adopted on 3 February 2023 2 Adopted 3 Adopted The European Data Protection Board Having regard to Article 63, Article 64 (1)(c), (3)-(8) and Article 41 (3) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of…

### Opinion 16/2022 on the draft decision of the competent supervisory authority of Slovenia regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR

*Source: EDPB, opinion-162022-on-the-draft-decision-of-the-competent-en, 2022-07-04 — https://overview.legal/posts/125924 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-162022-on-the-draft-decision-of-the-competent_en*

1 Adopted Opinion 16 / 20 22 on the draft decision of the competent supervisory authority of Slovenia regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR Adopted on 4 July 2022 2 Adopted 3 Adopted The European Data Protection Board Having regard to Article 63, Article 64 (1)(c), (3) - (8) and Article 41 (3) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of…

### Opinion 14/2022 on the draft decision of the competent supervisory authority of Bulgaria regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR

*Source: EDPB, opinion-142022-on-the-draft-decision-of-the-competent-en, 2022-07-04 — https://overview.legal/posts/125933 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-142022-on-the-draft-decision-of-the-competent_en*

1 Adopted Opinion 14 / 20 22 on the draft decision of the competent supervisory authority of Bulgaria regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR Adopted on 4 July 2022 2 Adopted 3 Adopted The European Data Protection Board Having regard to Article 63, Article 64 (1)(c), (3) - (8) and Article 41 (3) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of…

### Opinion 15/2022 on the draft decision of the competent supervisory authority of Luxembourg regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR

*Source: EDPB, opinion-152022-on-the-draft-decision-of-the-competent-en, 2022-07-04 — https://overview.legal/posts/125926 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-152022-on-the-draft-decision-of-the-competent_en*

Adopted Opinion 15 / 20 22 on the draft decision of the competent supervisory authority of Luxembourg regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR Adopted on 4 July 2022 Adopted Adopted The European Data Protection Board Having regard to Article 63, Article 64 (1)(c), (3) - (8) and Article 41 (3) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of…

### Opinion 37/2021 on the draft decision of the competent supervisory authority of Malta regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR

*Source: EDPB, opinion-372021-on-the-draft-decision-of-the-competent-en, 2021-11-30 — https://overview.legal/posts/125977 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-372021-on-the-draft-decision-of-the-competent_en*

Adopted Opinion 37 / 202 1 on the draft decision of the competent supervisory authority of Malta regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR Adopted on 30 November 2021 Adopted Adopted The European Data Protection Board Having regard to Article 63, Article 64 (1)(c), (3) - (8) and Article 41 (3) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of…

### Opinion 23/2021 on the draft decision of the competent supervisory authority of Czech Republic regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR

*Source: EDPB, opinion-232021-on-the-draft-decision-of-the-competent-en, 2021-07-20 — https://overview.legal/posts/126006 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-232021-on-the-draft-decision-of-the-competent_en*

1 Adopted Opinion 23 / 20 21 on the draft decision of the competent supervisory authority of Czech Republic regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR Adopted on 20 July 2021 2 Adopted 3 Adopted The European Data Protection Board Having regard to Article 63, Article 64 (1)(c), (3) - (8) and Article 41 (3) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the…

## Enforcement decisions

### Persónuvernd (Iceland) - 2020061979

*Source: Persónuvernd (Iceland), 2022-06-29 — https://overview.legal/posts/6316 — original: https://gdprhub.eu/index.php?title=Persónuvernd_(Iceland)_-_2020061979*

Facts — The Icelandic DPA started an investigation into a genetic research company. More specifically, to assess the company's Data Protection Officer (DPO), as well as the performance of the DPO's tasks. The DPA requested information from the company to determine if and how the company's DPO was compatible with Article 38 GDPR. The DPA stated that the decision to investigate the DPO was made with the intention of ensuring compliance, not because it assumed the requirements of the GDPR were not being followed. The DPA wrote two letters, but the company did not respond to any of them within the prescribed deadlines. After a phone call, the DPA received a response almost two months after the first letter had been sent. Holding — After reviewing the responses from the controller, the Icelandic DPA concluded that there were no violations in relation to the obligations to appoint a DPO (Article 37), to involve the DPO in relevant matters (Article 38(1)), and to provide the DPO with the necessary resources (Article 38(2)). However, the DPA held that the controller violated the obligation to ensure the DPO's independence pursuant to Article 38(3). The acting DPO at the time of the investigation also held the position of deputy CEO, senior lawyer and board member. The DPA held that that could lead to a conflict of interest. The current DPO also held the position of senior lawyer. The DPA held that this also constituted a conflict of interest. The DPA instructed the controller to ensure that the acting DPO would not be responsible for other tasks and duties that may lead to a conflict of interest. The DPA further noted that the despite the delayed answers, it would not impose a fine, taking into account the fact that the information was eventually received as well as the COVID-19 outbreak.

### Company: Lack of appointment of data protection officer

*Source: Austrian Data Protection Authority (dsb), 2024-10-16 — https://overview.legal/posts/48888 — original: https://www.enforcementtracker.com/ETid-2773*

The Austrian DPA has imposed a fine on a company. The controller appointed a DPO who had a conflict of interest, meaning the person was not suitable for the role.

### Garante per la protezione dei dati personali (Italy) - 9794895

*Source: Garante per la protezione dei dati personali (Italy), 2022-06-09 — https://overview.legal/posts/6314 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_9794895*

Facts — The Municipality of Policoro (Basilicata), implemented the use of CCTV cameras to monitor and fight waste abandonment within its territory. A data subject complained the Municipality had breached their data protection right of fair, transparent and lawful processing under art. 5(1)(a) as the sign signaling the CCTV monitoring referred to an outdated legislative decree. They also alleged a breach of art. 5(1)(e) and art. 13 GDPR, in so far the municipality never defined a data retention period for each processing purpose pursued. The last complaint moved forward by the data subject was that by being legally represented in Court by the same lawyer, who also acted as DPO of Policoro, the Municipality gave rise to a conflict of interest situation and breached art. 38(6) GDPR. The Municipality argued that the claim had been done in front of the Justice of Peace, who had no competency to decide on issues of privacy. It was also alleged the judgement only pertained an administrative matter, without rising any data protection concerns or a situation of conflict of interest with the Municipality's DPO. The last argument alleged the processing and retention of the CCTV footage was related to illegal dumps within the municipal territory, meaning the filming had been carried out in the course of judicial police investigations and the data retention periods of the GDPR did not apply in this case. Holding — The Italian DPA held that in this case the Municipality was carrying activities of data processing, by surveilling public entities by means of surveillance cameras. It also noted, that in par. 41 of the Guidelines 3/2019 on the Processing of Personal Data by Video Devices, waste management is "among the institutional activities entrusted to local authorities". This means the surveillance done by the Municipality of Policoro, a task carried out in the public interest in connection with the exercise of official authority as per art.6(1)(e) GDPR, was unrelated to public security and/or judicial police and obliging the controller to comply with data protection principles. The DPA found that the information provided in regards to the processing of personal data by means of surveillance cameras, did not meet the requirements of conciseness, transparency, intelligibility and easy readability contained in art. 5(1)(a) GDPR. The Municipality of Policoro had failed to provide suitable first-level information to the data subject, in so far the sign signaling the CCTV surveillance made reference to an outdated legislative decree (d.lgs 196/03) instead of the one currently in force (d.lgs 101/18). Furthermore, the data controller failed to provide the data subject with an adequate notice on second-level processing of their data. The signage did not include information on the most suitable impacts of the processing or an indication of a website, where to consult an extended version of the explanation. The DPA also found a violation of art. 13 GDPR as well as the principles of storage limitation and accountability in art. 5(1)(e) and art. 5(2). It stated that "the longer the intended storage period (especially if longer than 72 hours), the more reasoned the analysis referring to the legitimacy of the purpose and necessity of storage must be". In this case, the data controller not only failed to set a maximum retention period for the images taken for the purpose of combating illegal littering, but also established the administrative fines for the violation two months after the images were recorded. This did not allow for the data controller to respect the principle of accountability. Lastly, the DPA addressed the alleged conflict of interest raised by the involvement of the Policoro's DPO in the legal proceedings brought against the data subject. The DPA ruled DPOs "may perform other duties and functions," with the understanding that "the controller must ensure that such duties and functions do not give rise to a conflict of interest." The DPA also made reference to the Article 29 WP's Guidelines on Data Protection Officers, in which it is urged to not designate DPOs already acting as defense counsel for the same court. In the case at hand, it resulted that the DPO shared with the Municipality an interest in obtaining a rejection of the appeal. Consequently, the Italian Garante held this to be in violation of art. 38(6) GDPR, as well the fact that it undermined the DPO's independence. The Italian DPA held a cumulative breach of art. 5(1)(a) and (e) and (2) (in conjunction with article 24), 12, 13 and 38(6) GDPR. It balanced the fact that the personal data processing affected all other citizens, who passed through the areas under surveillance, against the lack of previous violations committed by the data controller. The DPA issued a fine of €26,000 EUR to the Municipality of Policoro.

### Clinic: Insufficient involvement of data protection officer

*Source: Data Protection Authority of Berlin, 2021-01-01 — https://overview.legal/posts/47337 — original: https://www.enforcementtracker.com/ETid-1222*

The DPA from Berlin has imposed a fine on a clinic. The clinic had appointed the clinic manager, who was also a shareholder of the clinic, as the data protection officer. A data protection officer may perform other tasks and duties, but the company must ensure that other tasks and duties do not lead to a conflict of interest. In the present case, however, there was such a conflict of interest. On the one hand, the clinic manager had to make economic decisions in his executive position, and on th

### Proximus SA: Insufficient involvement of data protection officer

*Source: Belgian Data Protection Authority (APD), 2020-04-28 — https://overview.legal/posts/46387 — original: https://www.enforcementtracker.com/ETid-272*

According to the data protection authority, the company's data protection officer was not sufficiently involved in the processing of personal data breaches and the company did not have a system in place to prevent a conflict of interest of the DPO, who also held numerous other positions within the company (head of compliance and audit department), which led the DPA to the conclusion that the company's DPO was not able to work independently.

### Bank: Insufficient involvement of data protection officer

*Source: Belgian Data Protection Authority (APD), 2021-12-16 — https://overview.legal/posts/47109 — original: https://www.enforcementtracker.com/ETid-994*

The Belgian DPA has imposed a fine of EUR 75,000 on a bank. The DPA identified a conflict of interest regarding the data protection officer. In addition to his work as data protection officer, he was also head of a department to which he had to report in his capacity as data protection officer. The DPA considered this to be a violation of Art. 38 (6) GDPR.

### Austrian DSB rules 360-degree feedback unlawful without specific works agreement

*Source: DSB (Austria), 2026-03-20 — https://overview.legal/posts/187479 — original: https://gdprhub.eu/index.php?title=DSB_(Austria)_-_2025-0.960.016*

Facts — The data subject was employed by an Austrian stock corporation (the controller) from August 2018 to June 2025. They worked as a manager in the controller’s finance department, with technical and disciplinary responsibility for up to five employees. The controller operated a 360-degree feedback process under which the data subject completed a self-assessment and 17 other individuals, including their supervisor, three subordinates and other employees, evaluated their leadership behaviour across 27 categories. Both the data subject and their supervisor had access to the results. The process was also used for other managers within the company. On 1 August 2025, the data subject lodged a complaint with the Austrian DPA, alleging a violation of their right to confidentiality. They argued that the processing carried out as part of the 360-degree feedback process required a specific works agreement and was therefore unlawful in the absence of one. The controller had concluded a framework works agreement with the central works council on the processing of employee data, as well as a supplementary agreement concerning its HR system. However, there was no specific works agreement covering the 360-degree feedback process. The controller alleged that it relied on its legitimate interests under Article 6(1)(f) GDPR and on the performance of the employment contract under Article 6(1)(b) GDPR. It argued that a works agreement would merely specify its legitimate interests and that the absence of such an agreement did not render the processing unlawful. It further maintained that whether a works agreement was required was a labour-law issue that could not be determined in the proceedings before the DPA The data subject responded that the processing of personal data in a 360-degree feedback process served to evaluate employees and therefore constituted a measure within the meaning of § 96 of the Austrian Labour Constitution Act (ArbVG). Section 96 ArbVG lists certain workplace measures that can be introduced only with the works council’s consent through a works agreement. Holding — The DPA first found that the data subject was an employee covered by the Austrian Labour Constitution Act, rather than a senior executive excluded from its scope. It further held that the assessments of the data subject’s leadership behaviour constituted personal data. The DPA explained that Article 88 GDPR enables Member States to adopt, through legislation or collective agreements, more specific rules protecting the rights and freedoms of individuals in the context of employment-related processing. Such rules must include appropriate safeguards for, among other things, human dignity, legitimate interests and the fundamental rights of data subjects. Recital 155 GDPR expressly refers to works agreements as a possible instrument for implementing such rules. It further stated that Austria had made use of the opening clause in Article 88 GDPR and that § 96 ArbVG constituted one of the more specific national rules protecting employees in the context of personal data processing. It determined that the 360-degree feedback process constituted a systematic and standardised assessment of employees falling under both § 96(1)(2) ArbVG, concerning personnel questionnaires, and § 96(1)(3) ArbVG, concerning monitoring measures affecting human dignity. It held that under § 96 ArbVG, the processing therefore required the works council’s consent through a valid works agreement. It pointed out that the controller’s existing works agreements did not cover the 360-degree feedback process or the categories of personal data collected through it. It therefore held that the processing could not be based on a works agreement under Article 88(1) GDPR in conjunction with § 96 ArbVG. The DPA held that the controller could not rely on Article 6(1)(f) GDPR. It stated that although personnel management and improving employee performance might generally constitute legitimate interests, an interest pursued through processing contrary to national law could not be regarded as lawful. It concluded that since the mandatory works council consent had not been obtained, the interest could not be regarded as legitimate under Article 6(1)(f) GDPR. Moreover, it pointed out that Article 6(1)(b) GDPR was also inapplicable because the feedback process was not necessary for the performance of the employment contract. It reasoned that the employment relationship could be performed without it, and the process was not applied to all employees. The DPA therefore found that the processing was unlawful and violated the data subject’s right to confidentiality. It prohibited the controller from continuing the 360-degree feedback process for employees covered by the ArbVG until a valid works agreement was concluded.

### HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens

*Source: HDPA (Greece), 2026-05-13 — https://overview.legal/posts/144044 — original: https://gdprhub.eu/index.php?title=HDPA_(Greece)_-_12/2026*

Facts — The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of Undesirable Aliens. In response to the Authority's request for clarifications, the competent Directorate of the Ministry of Citizen Protection informed the DPA that: • By a decision dated 27-07-2017, an entry ban and registration in the National Registry of Undesirable Aliens were imposed on the complainant for reasons of national security. • Following temporary 48-hour lifts of the measure for humanitarian reasons in 2019, the entry ban was re-imposed. • Subsequent decisions in 2020, 2023, and 2025 maintained the entry ban and renewed his registration in the National Registry of Undesirable Aliens for successive three-year periods, as the grounds for registration remained active. • The explicit grounds and documentation behind the registration were not disclosed to the complainant because the competent Directorate classified the file as restricted/classified service material. The complainant and his attorney attended a DPA hearing on 22-04-2026, arguing that the registration lacked specific, adequate, or definitive justification regarding any threat to public order or national security. They noted that the complainant has no criminal convictions, poses no threat, and possesses strong ties, residency, and business operations in the region of Northern Epirus and Greece, meaning the entry ban severely disrupts his professional and family life. Holding — According to the provisions of Article 82(1) of Law 3386/2005, foreign nationals whose presence in Greek territory constitutes a threat to national security, public safety, or public order can be registered in the National Registry of Undesirable Aliens, with registrations subject to an ex officio review every three years. Furthermore, pursuant to the provisions of Article 54(2) and Article 55(4) of Law 4624/2019 (the Greek law implementing the GDPR), the data controller is legally empowered to restrict or omit the provision of information and to deny a data subject access to their personal data when dictated by reasons of national security or public order. These national provisions are explicitly anchored in Article 23 GDPR (specifically Article 23(1)(a)GDPR and Article 23(1)(c) GDPR), which permits Member State law to restrict the scope of the obligations and data subject rights (such as the right to be informed under Article 13 GDPR - Article 14 GDPR and the right of access under Article 15 GDPR) to safeguard national security and public security. In the present case, the evidence demonstrated that the complainant's initial registration and subsequent renewals in the National Registry of Undesirable Aliens were executed lawfully for reasons of national security. The Ministry of Citizen Protection, acting as the data controller, exercised its legal discretion under these frameworks to weigh these interests and correctly determined that the underlying operational decision constitutes classified material that cannot be disclosed to the data subject. Consequently, the fundamental principles of data protection law were not breached, and the Hellenic DPA rejected the complaint as unfounded.

## Recent developments

### De IJslandse toezichthouder heeft geoordeeld dat er sprake is van een belangenconflict wanneer een Functionaris Gegevensbescherming (FG) tegelijkertijd ook de hoofdjurist van een bedrijf is.

*Source: GDPRhub, 2022-09-28 — https://overview.legal/posts/51805*

De IJslandse Autoriteit Persoonsgegevens (SA) heeft vastgesteld dat er sprake is van een belangenconflict wanneer een Functionaris Gegevensbescherming (FG) tegelijkertijd ook de senior jurist, plaatsvervangend CEO of bestuurslid van een bedrijf is. Een FG kan echter wel de functie van compliance officer bekleden.

### Can the roles of DPO and whistleblowing officer be merged?

*Source: IAPP, 2023-03-28 — https://overview.legal/posts/6228 — original: https://iapp.org/news/a/can-be-the-role-of-data-protection-officer-and-whistleblowing-officer-merged-in-one-person#entry-4228*

> 
																						Personal data protection and whistleblowing are two different topics — different regulations with different purposes, scope and requirements. But, in fact, they are closer than they seem, especially for practical reasons.
Both data protection governance and whistleblowing systems are often exercised by the same unit —  the compliance department — or even by the same person. This solution offers several advantages, but also some problematic points that need to be highligh

### Het Italiaanse bedrijf SA heeft juridische stappen ondernomen tegen een gemeente vanwege het gebruik van haar videosurveillance systeem en omdat het haar Functionaris Gegevensbescherming (FG) heeft aangesteld om de gemeente in een rechtszaak te vertegenwoordigen.

*Source: GDPRhub, 2022-09-28 — https://overview.legal/posts/51807*

Tenslotte oordeelde de gegevensbeschermingsautoriteit dat de verantwoordelijke, door de functionaris gegevensbescherming (FG) te betrekken bij de verdediging in rechtszaken, de FG in een positie van belangenconflict bracht, in strijd met artikel 38(6) van de AVG. Dit was met name omdat dit ertoe leidde dat de betrokkene het gevoel had niet in staat te zijn om contact op te nemen met de FG met betrekking tot kwesties die verband houden met de verwerking van hun persoonlijke gegevens en de uitoefening van hun rechten zoals uiteengezet in artikel 38(4) van de AVG.

### Berlin DPA imposes 525K euro fine over DPO violation

*Source: IAPP, 2022-09-22 — https://overview.legal/posts/6275 — original: https://iapp.org/news/a/berlin-dpa-imposes-525k-fine-over-dpo-violation#entry-482*

> The Berlin Commissioner for Data Protection and Freedom of Information issued a 525,000 euro fine to a Berlin-based retailer for violation of data protection officer requirements under the \[GDPR]. An investigation found an alleged conflict of interest concerning the DPO's employment status and decision-making responsibilities that violated Article 38(6) of the GDPR. The company received a warning from the regulator in 2021.

### EU-Hof: gegevens waaruit indirect de seksuele geaardheid van een persoon kan worden afgeleid vormen gevoelige gegevens in de zin van de AVG

*Source: NL EU Court Expert, 2022-08-17 — https://overview.legal/posts/6290 — original: https://ecer.minbuza.nl/-/eu-hof-gegevens-waaruit-indirect-de-seksuele-geaardheid-van-een-persoon-kan-worden-afgeleid-vormen-gevoelige-gegevens-in-de-zin-van-de-avg?redirect=%2Fecer%2Fnieuws%3Fq%3Dprivacy%2520OR%2520avg%26f%3D%26t%3D#entry-300*

The processing of personal data that may indirectly reveal sensitive information about an individual, such as information about their sexual orientation, may qualify as processing of "special categories of personal data" within the meaning of the AVG. The processing of such sensitive data is prohibited in principle. This is the EU Court's answer to questions from a Lithuanian judge.

## Literature

### The independence requirement for national data protection supervisory authorities.

*Source: PinG Privacy in Germany, 2019-04-26 — https://overview.legal/posts/132494 — original: https://doi.org/10.37307/j.2196-9817.2019.03.07*

### Event-Driven Compliance: Reconciling Privacy Regulation with Real-Time Advertising Infrastructure

*Source: Journal of Computer Science and Technology Studies, 2025-11-26 — https://overview.legal/posts/53852 — original: https://doi.org/10.32996/jcsts.2025.7.12.20*

Programmatic advertising ecosystem functions based on distributed, event-driven frameworks that handle user data across enterprise limits in milliseconds, with basic contradictions with the present-day privacy laws such as GDPR, ePrivacy Directive, and CCPA/CPRA. The system of real-time bidding projects the identifiers of users and the cues of their behavior to many prospective advertisers, creating compliance risks that are multiplicative beyond jurisdictional lines. This manuscript formalizes

### The AI Act and the future of STEM education in Europe: rethinking pedagogy, assessment, and teacher agency

*Source: Frontiers in Education, 2026-07-02 — https://overview.legal/posts/53829 — original: https://doi.org/10.3389/feduc.2026.1845045*

Generative artificial intelligence (AI) is swiftly transforming STEM education, presenting pedagogical, ethical, and regulatory challenges. The Artificial Intelligence Act, a comprehensive legislative framework emphasizing transparency, accountability, and human oversight, is implemented throughout Europe. This paper analyzes the necessity of re-evaluating STEM education in light of the convergence between generative AI and the AI Act. The paper posits that, grounded in pedagogy, evaluation, and

### Perlindungan Hukum Data Pribadi di Era Globalisasi Digital: Studi Perbandingan General Data Protection Regulation Uni Eropa dengan Undang-Undang Perlindungan Data Pribadi Indonesia

*Source: As-Syar i Jurnal Bimbingan & Konseling Keluarga, 2026-07-04 — https://overview.legal/posts/83517 — original: https://doi.org/10.47467/as.v8i3.12817*

Personal data protection has become an increasingly important legal issue due to the rapid development of digital technology and the growing volume of personal data processing activities. Indonesia has enacted Law Number 27 of 2022 concerning Personal Data Protection (PDP Law) as the primary legal framework for personal data protection. However, several limitations remain within its substantive and institutional aspects, requiring further improvement. This study aims to analyze the substantive a

### The Magician’s Eye

*Source: Journal of Ethics and Emerging Technologies, 2026-07-01 — https://overview.legal/posts/53832 — original: https://doi.org/10.55613/jeet.v36i2.239*

David Eliot trained as a card magician before turning to AI research. His Artificially Intelligent sets out to democratise AI for general readers, and on its own terms it succeeds: the history is rich, the writing is clear, and the central argument that AI is socially constructed and democratically redirectable is held with conviction. This review reads the book alongside the regulatory architecture being built on the same theory of agency: the EU AI Act, the harmonised standards beneath it, the

## Related topics

- **Scientific Panel Independence** — https://overview.legal/topics/scientific-panel-independence-impartiality
  A specific topic is needed to address the independence and impartiality requirements that are critical for scientific panels to maintain credibility and objecti
- **Monitoring** — https://overview.legal/topics/monitoring
  Systematic observation and tracking of individuals
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities

---
Generated by overview.legal · https://overview.legal/topics/notified-body-independence-impartiality · 2026-08-22
