Skip to content
Topic Contested in court

Public Authority

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Government bodies and their data processing activities

962 linked items 40 Laws138 Case Law57 Guidance465 Enforcement229 News

Overview

21 sources · Jul 15, 2026

Legal Framework

Under Article 4(7) GDPR, a public authority, agency, or other body qualifies as a controller when it determines the purposes and means of processing personal data. Public authorities must identify a valid legal basis under Article 6(1). Unlike private entities, public bodies typically rely on Article 6(1)(c) (compliance with a legal obligation) or Article 6(1)(e) (performance of a task carried out in the public interest or in the exercise of official authority). Recital 154 permits public authorities to reconcile public access to official documents with data protection rights, provided disclosure is mandated by Union or Member State law. Furthermore, Article 10 restricts the processing of criminal conviction data, permitting it only under official government supervision or where authorized by national law with appropriate safeguards.

Key Developments

The Court of Justice of the European Union has established critical boundaries for public authority data processing. In Valsts policijas Rīgas reģiona pārvaldes Kārtības policijas pārvalde v. Rīgas pašvaldības SIA ‘Rīgas satiksme’, the Court ruled that while a public authority might have a legitimate interest in processing data, it must also have a specific legal obligation or statutory basis to do so lawfully. This significantly narrows the ability of public bodies to rely on Article 6(1)(f). Regarding data subject access rights, the X decision established that when a public authority levies a fee for providing access to personal data, that fee cannot exceed the actual cost of communicating the data. Transparency obligations also feature prominently: Client Earth v. EFSA underscored that transparency in administrative processes enhances the legitimacy and democratic accountability of public authorities. Enforcement actions reflect these strict standards. The Polish Data Protection Authority fined the Minister of Justice €23,540 for insufficient technical and organizational measures, while the Belgian DPA fined the public water utility Société Wallonne des Eaux €86,000 for lacking a valid legal basis for its processing activities.

Practical Guidance

  • Ground all processing activities in explicit national legislation authorizing the public task or legal obligation, avoiding reliance on the legitimate interest basis under Article 6(1)(f) as established by the Valsts policijas ruling.
  • Ensure that any fees charged to data subjects exercising their right of access are strictly limited to the administrative cost of communication, as mandated by the X decision.
  • Implement specific safeguards and ensure official oversight when processing criminal conviction data, as required by Article 10 GDPR.
  • Establish internal protocols to balance the public's right to access official documents (per Recital 154) with the data protection rights of individuals, ensuring any disclosure is backed by specific national access laws.
  • Conduct regular reviews of technical and organizational security measures to prevent enforcement actions, as demonstrated by the €23,540 fine levied against the Polish Minister of Justice.
Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 40
rec 8 Recital 8 — public administration exclusion scope NIS2 Dec 2022 rec 129 Recital 129 — competent authority power administrative fines NIS2 Dec 2022 art 86 Processing and public access to official documents GDPR Apr 2016 rec 154 Recital 154 — public access to official documents GDPR Apr 2016 rec 93 Recital 93 — member state data protection impact assessment GDPR Apr 2016 rec 113 Recital 113 — member state jurisdiction over entities NIS2 Dec 2022 rec 94 Recital 94 — competent authorities trust services cooperation NIS2 Dec 2022 rec 134 Recital 134 — mutual assistance supervisory enforcement cooperation NIS2 Dec 2022 rec 24 Recital 24 — sector-specific reporting consistency NIS2 Dec 2022 rec 40 Recital 40 — cross border cooperation single points contact NIS2 Dec 2022 rec 9 Recital 9 — national security public security exemptions NIS2 Dec 2022 rec 127 Recital 127 — cross-border digital services cooperation DSA Oct 2022 rec 110 Recital 110 — national Digital Services Coordinator designation DSA Oct 2022 rec 123 Recital 123 — supervision by member state of establishment DSA Oct 2022 rec 114 Recital 114 — competent authorities enforcement powers and means DSA Oct 2022 rec 109 Recital 109 — Member States competent authorities designation DSA Oct 2022 rec 141 Recital 141 — Commission information gathering and investigation powers DSA Oct 2022 rec 149 Recital 149 — service recipients right to mandate representatives DSA Oct 2022 rec 80 Recital 80 — non-EU controller processor representative requirement GDPR Apr 2016 rec 43 Recital 43 — freely given consent validity conditions GDPR Apr 2016 Show 20 more →
Case Law 138
¶6 Article 2 of that directive provides: ‘For the purposes of this Directive: (a) “personal data” shall mean any information relating to an identified or… Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV ¶65 In this regard, it should be noted that, in accordance with the aim pursued by Directive 95/46, namely to ensure a high level of protection of the fun… Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV ¶75 However, the Court specified that Article 15(1) of Directive 2002/58, read in the light of Articles 7, 8 and 11 and Article 52(1) of the Charter, does… Judgment of the Court (Grand Chamber) of 20 September 2022.#Bundesrepublik Deutschland v SpaceNet AG and Telekom Deutschland GmbH.#Requests for a preliminary ruling from the Bundesverwaltungsgericht.#Reference for a preliminary ruling – Processing of personal data in the electronic communications sector – Confidentiality of communications – Providers of electronic communications services – General and indiscriminate retention of traffic and location data – Directive 2002/58/EC – Article 15(1) – ¶115 In such a situation, in the light of the balance that must be struck between the rights and interests at issue referred to in paragraphs 65 to 68 abov… Judgment of the Court (Grand Chamber) of 20 September 2022.#Bundesrepublik Deutschland v SpaceNet AG and Telekom Deutschland GmbH.#Requests for a preliminary ruling from the Bundesverwaltungsgericht.#Reference for a preliminary ruling – Processing of personal data in the electronic communications sector – Confidentiality of communications – Providers of electronic communications services – General and indiscriminate retention of traffic and location data – Directive 2002/58/EC – Article 15(1) – 740/22 Judgment of the Court (Sixth Chamber) of 7 March 2024.#Endemol Shine Finland Oy.#Request for a preliminary ruling from the Itä-Suomen hovioikeus.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Articles 2, 4, 6, 10 and 86 – Data held by a court relating to the criminal convictions of a natural person – Oral disclosure of such data to a commercial company on account of a competition organised by that company – Concept of ‘processing of personal data’ Court of Justice of the European Union Mar 2024 40/17 Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV CJEU Jul 2019 245/19 Judgment of the Court (Grand Chamber) of 6 October 2020.#État luxembourgeois v B and Others.#Requests for a preliminary ruling from the Cour administrative (Luxembourg).#References for a preliminary ruling – Directive 2011/16/EU – Administrative cooperation in the field of taxation – Articles 1 and 5 – Decision ordering that information be provided to the competent authority of a Member State, acting in response to a request for exchange of information from the competent authority of another Mem Court of Justice of the European Union Oct 2020 33/22 Judgment of the Court (Grand Chamber) of 16 January 2024.#Österreichische Datenschutzbehörde v WK.#Request for a preliminary ruling from the Verwaltungsgerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Article 16 TFEU – Regulation (EU) 2016/679 – Article 2(2)(a) – Scope – Exclusions – Activities which fall outside the scope of Union law – Article 4(2) TEU – Activities concerning national security – Committee of inquir Court of Justice of the European Union Jan 2024 746/18 Judgment of the Court (Grand Chamber) of 2 March 2021.#Criminal proceedings against H. K.#Request for a preliminary ruling from the Riigikohus.#Reference for a preliminary ruling – Processing of personal data in the electronic communications sector – Directive 2002/58/EC – Providers of electronic communications services – Confidentiality of the communications – Limitations – Article 15(1) – Articles 7, 8 and 11 and Article 52(1) of the Charter of Fundamental Rights of the European Union – Legisl Court of Justice of the European Union Mar 2021 582/14 Patrick Breyer v Bundesrepublik Deutschland CJEU Oct 2016 210/16 Unabhängiges Landeszentrum für Datenschutz v Wirtschaftsakademie Schleswig-Holstein CJEU Jun 2018 CJEU HvJ EU 9 januari 2025, C‑394/23 (Mousse). CJEU Jan 2025 65/23 Judgment of the Court (Eighth Chamber) of 19 December 2024.#MK v K GmbH.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 88(1) and (2) – Processing in the context of employment – Employees’ personal data – More specific rules provided for by a Member State pursuant to that Article 88 – Obligation to comply with Article 5, Article 6 Court of Justice of the European Union Dec 2024 73/16 Judgment of the Court (Second Chamber) of 27 September 2017.#Peter Puškár v Finančné riaditeľstvo Slovenskej republiky and Kriminálny úrad finančnej správy.#Request for a preliminary ruling from the Najvyšší súd Slovenskej republiky.#Reference for a preliminary ruling — Charter of Fundamental Rights of the European Union — Articles 7, 8 and 47 — Directive 95/46/EC — Articles 1, 7 and 13 — Processing of personal data — Article 4(3) TEU — Drawing up of a list of personal data — Subject matter — Ta Court of Justice of the European Union Sep 2017 204/21 Judgment of the Court (Grand Chamber) of 5 June 2023.#European Commission v Republic of Poland.#Failure of a Member State to fulfil obligations – Second subparagraph of Article 19(1) TEU – Article 47 of the Charter of Fundamental Rights of the European Union ‐ Rule of law – Effective legal protection in the fields covered by EU law – Independence of judges – Article 267 TFEU – Possibility of making a reference to the Court for a preliminary ruling – Primacy of EU law – Jurisdiction in relation t Court of Justice of the European Union Jun 2023 340/21 VB v Natsionalna agentsia za prihodite CJEU Dec 2023 473/12 Judgment of the Court (Third Chamber), 7 November 2013.#Institut professionnel des agents immobiliers (IPI) v Geoffrey Englebert and Others.#Request for a preliminary ruling from the Cour constitutionnelle (Belgium).#Processing of personal data — Directive 95/46/EC — Articles 10 and 11 — Obligation to inform — Article 13(1)(d) and (g) — Exceptions — Scope of exceptions — Private detectives acting for the supervisory body of a regulated profession — Directive 2002/58/EC — Article 15(1).#Case C‑47 Court of Justice of the European Union Nov 2013 638/23 Judgment of the Court (Eighth Chamber) of 27 February 2025.#Amt der Tiroler Landesregierung v Datenschutzbehörde.#Request for a preliminary ruling from the Verwaltungsgerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 4(7) – Concept of ‘controller’ – Direct designation of the controller by national law – Auxiliary administrative entity in the service of a regional government – Lack of Court of Justice of the European Union Feb 2025 557/20 Judgment of the General Court (Eighth Chamber, Extended Composition) of 26 April 2023.#Single Resolution Board v European Data Protection Supervisor.#Protection of personal data – Procedure for granting compensation to shareholders and creditors following the resolution of a bank – Decision of the EDPS in which it found that the SRB failed to fulfil its obligations concerning the processing of personal data – Article 15(1)(d) of Regulation (EU) 2018/1725 – Concept of personal data – Article 3(1) General Court Apr 2023 231/22 Judgment of the Court (Third Chamber) of 11 January 2024.#État belge v Autorité de protection des données.#Request for a preliminary ruling from the cour d'appel de Bruxelles.#Reference for a preliminary ruling – Approximation of laws – Protection of natural persons with regard to the processing of personal data and free movement of such data (General Data Protection Regulation) – Regulation (EU) 2016/679 – Point 7 of Article 4 – Concept of ‘controller’ – Official journal of a Member State – Obl Court of Justice of the European Union Jan 2024 245/20 Judgment of the Court (First Chamber) of 24 March 2022.#X and Z v Autoriteit Persoonsgegevens.#Request for a preliminary ruling from the Rechtbank Midden-Nederland.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Competence of the supervisory authority – Article 55(3) – Processing operations of courts acting in their judicial capacity – Concept – Making available to a journalist of documents arising fr Court of Justice of the European Union Mar 2022 413/23 Judgment of the Court (First Chamber) of 4 September 2025.#European Data Protection Supervisor v Single Resolution Board.#Appeal – Protection of natural persons with regard to the processing of personal data – Procedure for granting compensation to shareholders and creditors of a banking institution following the resolution of that institution – Decision of the European Data Protection Supervisor finding that the Single Resolution Board failed to fulfil its obligations relating to the processing Court of Justice of the European Union Sep 2025 293/12 Digital Rights Ireland Ltd v Minister for Communications CJEU Apr 2014 252/21 Meta Platforms v noyb CJEU Jan 2023 Show 118 more →
Guidance 57
statement 20250313 implementation of the pnr directive in light of the cjeu judgment Statement 2/2025 on the implementation of the PNR Directive in light of CJEU Judgment C-817/19 CJEU Mar 2025 22020 on articles 46 2 a and 46 3 b of regulation 2016679 for Guidelines 2/2020 on articles 46 (2) (a) and 46 (3) (b) of Regulation 2016/679 for transfers of personal data between EEA and non-EEA public authorities and bodies EDPB Dec 2020 012023 on article 37 law enforcement directive Guidelines 01/2023 on Article 37 Law Enforcement Directive EDPB Jun 2024 guidelines on the concepts of controller and processor in the gdpr Guidelines 07/2020 on the concepts of controller and processor in the GDPR EDPB Jul 2021 guidelines 022024 on article 48 gdpr Guidelines 02/2024 on Article 48 GDPR EDPB Jun 2025 guidelines on restrictions under article 23 gdpr Guidelines 10/2020 on restrictions under Article 23 GDPR EDPB Oct 2021 guidelines on derogations of article 49 Guidelines 2/2018 on derogations of Article 49 under Regulation 2016/679 EDPB May 2018 guidelines 202402 article48 v2 Guidelines 02/2024 on Article 48 GDPR EDPB Jun 2025 guidelines on the calculation of administrative fines under the gdpr Guidelines 04/2022 on the calculation of administrative fines under the GDPR EDPB May 2023 guidelines on the criteria of the right to be forgotten in the search engines cases under th Guidelines 5/2019 on the criteria of the Right to be Forgotten in the search engines cases under the GDPR (part 1) EDPB Jul 2020 guidelines on consent Guidelines 05/2020 on consent under Regulation 2016/679 EDPB May 2020 012021 on the adequacy referential under the law Recommendations 01/2021 on the adequacy referential under the Law Enforcement Directive EDPB Feb 2021 052021 on the interplay between the application of article 3 and the Guidelines 05/2021 on the Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR EDPB Feb 2023 guidelines on codes of conduct as tools for transfers Guidelines 04/2021 on Codes of Conduct as tools for transfers EDPB Feb 2022 022020 on the european essential guarantees for Recommendations 02/2020 on the European Essential Guarantees for surveillance measures EDPB Nov 2020 opinion 202507 epo adequacydecision Opinion 07/2025 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data by the European Patent Organisation EDPB May 2025 82019 on the competence of a supervisory authority in Opinion 8/2019 on the competence of a supervisory authority in case of a change in circumstances relating to the main or single establishment EDPB Jul 2019 edps joint opinion 032021 on the proposal for a regulation of EDPB-EDPS Joint Opinion 03/2021 on the Proposal for a regulation of the European Parliament and of the Council on European data governance (Data Governance Act) EDPB Mar 2021 guidelines on the use of facial recognition technology in the area of law enforcement Guidelines 05/2022 on the use of facial recognition technology in the area of law enforcement EDPB May 2023 guidelines on deceptive design patterns in social media platform interfaces how to recognise Guidelines 03/2022 on Deceptive design patterns in social media platform interfaces: how to recognise and avoid them EDPB Feb 2023 Show 37 more →
Enforcement 465
NAIH (Hungary) NAIH fines online store HUF 15M for transparency and Article 12(1) GDPR violations NAIH (Hungary) May 2026 Garante per la protezione dei dati personali (Italy) Italian DPA sanctions Lusha Systems for processing contact data without consent in B2B Garante per la protezione dei dati personali (Italy) Jul 2026 UODO (Poland) UODO (Poland) - DKN.5131.27.2023 UODO (Poland) May 2026 HDPA (Greece) HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens HDPA (Greece) May 2026 Garante per la protezione dei dati personali (Italy) Italian DPA: AgID's automatic transfer of PEC addresses to INAD index unlawful Garante per la protezione dei dati personali (Italy) May 2026 APDCAT (Catalonia) APDCAT sanctions Madremanya City Council for exposing applicants' sensitive data in tender APDCAT (Catalonia) Jul 2026 AKI (Estonia) AKI (Estonia) - No. 2.1-1/24/397-890-38 AKI (Estonia) Apr 2026 Garante per la protezione dei dati personali (Italy) Italian DPA: Justice Ministry unlawful disclosure of employee health data in service order Garante per la protezione dei dati personali (Italy) Jul 2026 Garante per la protezione dei dati personali (Italy) Italian DPA: Vasto municipality breached transparency duties over traffic cameras Garante per la protezione dei dati personali (Italy) Jun 2026 AEPD (Spain) AEPD: Digi Telecom violated Art 6(1) GDPR by issuing duplicate SIM to impersonator AEPD (Spain) Jul 2026 Polish National Personal Data Protection Office (UODO) Minister of Justice: Insufficient technical and organisational measures to ensure information security Polish National Personal Data Protection Office (UODO) Jun 2026 AEPD (Spain) AEPD fines El Español for disclosing minor's identity in assault video AEPD (Spain) Jul 2026 UODO (Poland) UODO (Poland) - DKN.5131.5.2025 UODO (Poland) May 2026 Garante per la protezione dei dati personali (Italy) Italian DPA: Enna Health Authority violated GDPR by publishing judicial data Garante per la protezione dei dati personali (Italy) Jul 2026 UODO (Poland) UODO (Poland) - DKN.5131.34.2023 UODO (Poland) Jun 2026 Belgian Data Protection Authority (APD) Société Wallonne des Eaux: Insufficient legal basis for data processing Belgian Data Protection Authority (APD) May 2026 Dutch Supervisory Authority for Data Protection (AP) Municipality of Hilversum: Insufficient legal basis for data processing Dutch Supervisory Authority for Data Protection (AP) Feb 2026 Dutch Supervisory Authority for Data Protection (AP) Municipality of Gooise Meren: Insufficient legal basis for data processing Dutch Supervisory Authority for Data Protection (AP) Feb 2026 Dutch Supervisory Authority for Data Protection (AP) Municipality of Zoetermeer: Insufficient legal basis for data processing Dutch Supervisory Authority for Data Protection (AP) Feb 2026 Dutch Supervisory Authority for Data Protection (AP) Municipality of Eindhoven: Insufficient legal basis for data processing Dutch Supervisory Authority for Data Protection (AP) Feb 2026 Show 445 more →
News 229
Autoriteit Persoonsgegevens Privacy regulators ask European Commission to review Israeli registration requirement for aid workers Autoriteit Persoonsgegevens Apr 2026 Government Short: “ Government Mar 2026 Government Short : Government Jan 2026 Government In short: Government Jan 2026 Government Fact Sheet Government Jan 2026 Government Fiche. Government Jan 2026 Government The "policy situation" surrounding Transaction Monitoring Netherlands. Government Jan 2026 Autoriteit Persoonsgegevens Ten municipalities fined for illegal processing of information regarding Islamic persons Autoriteit Persoonsgegevens Feb 2026 Government Short: Government Mar 2026 Government Short: Government Mar 2026 Autoriteit Persoonsgegevens Dutch DPA: no clear necessity for public transport BOAs to have access to passport photos in the driving license register Autoriteit Persoonsgegevens Jan 2026 Government Planning for the SUWI work agenda. Government Jan 2026 Government Short: Government Mar 2026 Politico Europe Public sector AI readiness: closing the gap between ambition and execution in Europe Politico Europe Feb 2026 European Digital Rights Fighting for algorithmic justice: lessons learned in working closely with affected people European Digital Rights Jan 2026 Autoriteit Persoonsgegevens DPD: data breaches caused by misuse of personal data at municipalities often fly under the radar Autoriteit Persoonsgegevens Jan 2026 Privacy Laws & Business More ICO/Government cooperation: Less ICO focus on rights? Privacy Laws & Business Jan 2026 Electronic Frontier Foundation Open Letter to Tech Companies: Protect Your Users From Lawless DHS Subpoenas Electronic Frontier Foundation Feb 2026 Electronic Frontier Foundation EFF in the news: 2025 Review. Electronic Frontier Foundation Dec 2025 GDPRhub CNIL (France) - SAN-2025-015 GDPRhub Jan 2026 Show 209 more →
Literature 33
SSRN Electronic Journal Grounds for Lawful Processing of Personal Data in GDPR and Personal Data Protection Bill 2018, India (PDPB): Section – V: Public Interests amp; Exercise of Official Authority. SSRN Electronic Journal Jan 2019 European Data Protection Law Review GDPR Implementation Series ∙ Malta: An Overview of the GDPR Implementation European Data Protection Law Review Jan 2020 European Data Protection Law Review GDPR Implementation Series ∙ Netherlands: The GDPR Implementation Act European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Croatia: Minimum Service for the Implementation, Big Service to the Public Sector European Data Protection Law Review Jan 2020 European Data Protection Law Review GDPR Implementation Series ∙ Portugal: A Brief Overview of the GDPR Implementation European Data Protection Law Review Jan 2019 European Data Protection Law Review GDPR Implementation Series ∙ Romania: Overview of the GDPR Implementation European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Belgium: Substantial Reform of Supervisory Authority and Framework Implementing Act Finally Adopted European Data Protection Law Review Jan 2018 European Data Protection Law Review Two Worlds Colliding – The GDPR In Between Public and Private Law European Data Protection Law Review Jan 2022 European Data Protection Law Review Belgium ∙ Data Protection Authority Provides New Policies on GDPR Infringements and Litigation Proceedings Aspects European Data Protection Law Review Jan 2021 European Data Protection Law Review GDPR Implementation Series ∙ Slovenia: Introduction to the Most Recent Public Draft of the GDPR Implementing Law European Data Protection Law Review Jan 2020 European Data Protection Law Review GDPR Implementation Series ∙ Hungary: Introduction to the GDPR Application and a Brief History of Data Protection European Data Protection Law Review Jan 2019 European Data Protection Law Review GDPR Implementation Series ∙ Italy: The Legislative Procedure for National Harmonisation with the GDPR European Data Protection Law Review Jan 2018 Computer law & security review If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation Computer law & security review Jan 2026 Athens Journal of Law Artificial Intelligence in Decision-making: A Test of Consistency between the “EU AI Act” and the “General Data Protection Regulation” Athens Journal of Law Jan 2025 Journal of Data Protection Privacy General Data Protection Regulation (GDPR) ambiguity, national diversity and data protection officer certification: Implementing Art. 39(1) GDPR in France, Italy, Luxembourg and Spain Journal of Data Protection Privacy Sep 2021 European Data Protection Law Review GDPR Implementation Series ∙ Finland: A Brief Overview of the GDPR Implementation European Data Protection Law Review Jan 2019 European Data Protection Law Review GDPR Implementation Series ∙ France: The French Approach to the GDPR Implementation European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Germany: Starting Implementation of the GDPR - Brief Overview of the Government Bill for a New Federal Data Protection Act European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ United Kingdom: Heading Towards Brexit but with a Data Protection Bill Implementing GDPR European Data Protection Law Review Jan 2017 Journal Scientific and Applied Research HOW GDPR TREATS AUTOMATED DECISION-MAKING Journal Scientific and Applied Research Nov 2025 Show 13 more →