# Public Authority — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/overheid
> Sources are cited per item. Verify against the official texts before relying on them.

Government bodies and their data processing activities

## Overview

## Legal Framework

Under Article 4(7) GDPR, a public authority, agency, or other body qualifies as a controller when it determines the purposes and means of processing personal data. Public authorities must identify a valid legal basis under Article 6(1). Unlike private entities, public bodies typically rely on Article 6(1)(c) (compliance with a legal obligation) or Article 6(1)(e) (performance of a task carried out in the public interest or in the exercise of official authority). Recital 154 permits public authorities to reconcile public access to official documents with data protection rights, provided disclosure is mandated by Union or Member State law. Furthermore, Article 10 restricts the processing of criminal conviction data, permitting it only under official government supervision or where authorized by national law with appropriate safeguards.

## Key Developments

The Court of Justice of the European Union has established critical boundaries for public authority data processing. In *Valsts policijas Rīgas reģiona pārvaldes Kārtības policijas pārvalde v. Rīgas pašvaldības SIA ‘Rīgas satiksme’*, the Court ruled that while a public authority might have a legitimate interest in processing data, it must also have a specific legal obligation or statutory basis to do so lawfully. This significantly narrows the ability of public bodies to rely on Article 6(1)(f). Regarding data subject access rights, the *X* decision established that when a public authority levies a fee for providing access to personal data, that fee cannot exceed the actual cost of communicating the data. Transparency obligations also feature prominently: *Client Earth v. EFSA* underscored that transparency in administrative processes enhances the legitimacy and democratic accountability of public authorities. Enforcement actions reflect these strict standards. The Polish Data Protection Authority fined the Minister of Justice €23,540 for insufficient technical and organizational measures, while the Belgian DPA fined the public water utility Société Wallonne des Eaux €86,000 for lacking a valid legal basis for its processing activities.

## Practical Guidance

- Ground all processing activities in explicit national legislation authorizing the public task or legal obligation, avoiding reliance on the legitimate interest basis under Article 6(1)(f) as established by the *Valsts policijas* ruling.
- Ensure that any fees charged to data subjects exercising their right of access are strictly limited to the administrative cost of communication, as mandated by the *X* decision.
- Implement specific safeguards and ensure official oversight when processing criminal conviction data, as required by Article 10 GDPR.
- Establish internal protocols to balance the public's right to access official documents (per Recital 154) with the data protection rights of individuals, ensuring any disclosure is backed by specific national access laws.
- Conduct regular reviews of technical and organizational security measures to prevent enforcement actions, as demonstrated by the €23,540 fine levied against the Polish Minister of Justice.

## Legislation (full text of key provisions)

### Processing and public access to official documents

*Source: GDPR, gdpr-art-86-en, 2016-04-27 — https://overview.legal/posts/91431*

Personal data in official documents held by a public authority or a public body or a private body for the performance of a task carried out in the public interest may be disclosed by the authority or body in accordance with Union or Member State law to which the public authority or body is subject in order to reconcile public access to official documents with the right to the protection of personal data pursuant to this Regulation.

### Right to lodge a complaint

*Source: DSA, dsa-art-53-en, 2022-10-19 — https://overview.legal/posts/94952*

Recipients of the service and any body, organisation or association mandated to exercise the rights conferred by this Regulation on their behalf shall have the right to lodge a complaint against providers of intermediary services alleging an infringement of this Regulation with the Digital Services Coordinator of the Member State where the recipient of the service is located or established. The Digital Services Coordinator shall assess the complaint and, where appropriate, transmit it to the Digital Services Coordinator of establishment, accompanied, where considered appropriate, by an opinion. Where the complaint falls under the responsibility of another competent authority in its Member State, the Digital Services Coordinator receiving the complaint shall transmit it to that authority. During these proceedings, both parties shall have the right to be heard and receive appropriate information about the status of the complaint, in accordance with national law.

### Recital 129 — competent authority power administrative fines

*Source: NIS2, nis2-rec-129-en, 2022-12-14 — https://overview.legal/posts/96786*

In order to ensure effective enforcement of the obligations laid down in this Directive, each competent authority should have the power to impose or request the imposition of administrative fines.

### Recital 8 — public administration exclusion scope

*Source: NIS2, nis2-rec-8-en, 2022-12-14 — https://overview.legal/posts/96544*

The exclusion of public administration entities from the scope of this Directive should apply to entities whose activities are predominantly carried out in the areas of national security, public security, defence or law enforcement, including the prevention, investigation, detection and prosecution of criminal offences. However, public administration entities whose activities are only marginally related to those areas should not be excluded from the scope of this Directive. For the purposes of this Directive, entities with regulatory competences are not considered to be carrying out activities in the area of law enforcement and are therefore not excluded on that ground from the scope of this Directive. Public administration entities that are jointly established with a third country in accordance with an international agreement are excluded from the scope of this Directive. This Directive does not apply to Member States’ diplomatic and consular missions in third countries or to their network and information systems, insofar as such systems are located in the premises of the mission or are operated for users in a third country.

### Recital 154 — public access to official documents

*Source: GDPR, gdpr-rec-154-en, 2016-04-27 — https://overview.legal/posts/91823*

This Regulation allows the principle of public access to official documents to be taken into account when applying this Regulation. Public access to official documents may be considered to be in the public interest. Personal data in documents held by a public authority or a public body should be able to be publicly disclosed by that authority or body if the disclosure is provided for by Union or Member State law to which the public authority or public body is subject. Such laws should reconcile public access to official documents and the reuse of public sector information with the right to the protection of personal data and may therefore provide for the necessary reconciliation with the right to the protection of personal data pursuant to this Regulation. The reference to public authorities and bodies should in that context include all authorities or other bodies covered by Member State law on public access to documents. Directive 2003/98/EC of the European Parliament and of the Council (14) leaves intact and in no way affects the level of protection of natural persons with regard to the processing of personal data under the provisions of Union and Member State law, and in particular does not alter the obligations and rights set out in this Regulation. In particular, that Directive should not apply to documents to which access is excluded or restricted by virtue of the access regimes on the grounds of protection of personal data, and parts of documents accessible by virtue of those regimes which contain personal data the re-use of which has been provided for by law as being incompatible with the law concerning the protection of natural persons with regard to the processing of personal data.

### Recital 93 — member state data protection impact assessment

*Source: GDPR, gdpr-rec-93-en, 2016-04-27 — https://overview.legal/posts/91701*

In the context of the adoption of the Member State law on which the performance of the tasks of the public authority or public body is based and which regulates the specific processing operation or set of operations in question, Member States may deem it necessary to carry out such assessment prior to the processing activities.

### Recital 94 — competent authorities trust services cooperation

*Source: NIS2, nis2-rec-94-en, 2022-12-14 — https://overview.legal/posts/96716*

Member States can assign the role of the competent authorities for trust services to the supervisory bodies under Regulation (EU) No 910/2014 in order to ensure the continuation of current practices and to build on the knowledge and experience gained in the application of that Regulation. In such a case, the competent authorities under this Directive should cooperate closely and in a timely manner with those supervisory bodies by exchanging relevant information in order to ensure effective supervision and compliance of trust service providers with the requirements laid down in this Directive and in Regulation (EU) No 910/2014. Where applicable, the CSIRT or the competent authority under this Directive should immediately inform the supervisory body under Regulation (EU) No 910/2014 about any notified significant cyber threat or incident affecting trust services as well as about any infringements by a trust service provider of this Directive. For the purpose of reporting, Member States can, where applicable, use the single entry point established to achieve a common and automatic incident reporting to both the supervisory body under Regulation (EU) No 910/2014 and the CSIRT or the competent authority under this Directive.

### Recital 134 — mutual assistance supervisory enforcement cooperation

*Source: NIS2, nis2-rec-134-en, 2022-12-14 — https://overview.legal/posts/96796*

For the purpose of ensuring entities’ compliance with their obligations laid down in this Directive, Member States should cooperate with and assist each other with regard to supervisory and enforcement measures, in particular where an entity provides services in more than one Member State or where its network and information systems are located in a Member State other than that where it provides services. When providing assistance, the requested competent authority should take supervisory or enforcement measures in accordance with national law. In order to ensure the smooth functioning of mutual assistance under this Directive, the competent authorities should use the Cooperation Group as a forum to discuss cases and particular requests for assistance.

### Recital 9 — national security public security exemptions

*Source: NIS2, nis2-rec-9-en, 2022-12-14 — https://overview.legal/posts/96546*

Member States should be able to take the necessary measures to ensure the protection of the essential interests of national security, to safeguard public policy and public security, and to allow for the prevention, investigation, detection and prosecution of criminal offences. To that end, Member States should be able to exempt specific entities which carry out activities in the areas of national security, public security, defence or law enforcement, including the prevention, investigation, detection and prosecution of criminal offences, from certain obligations laid down in this Directive with regard to those activities. Where an entity provides services exclusively to a public administration entity that is excluded from the scope of this Directive, Member States should be able to exempt that entity from certain obligations laid down in this Directive with regard to those services. Furthermore, no Member State should be required to supply information the disclosure of which would be contrary to the essential interests of its national security, public security or defence. Union or national rules for the protection of classified information, non-disclosure agreements, and informal non-disclosure agreements such as the traffic light protocol should be taken into account in that context. The traffic light protocol is to be understood as a means to provide information about any limitations with regard to the further spreading of information. It is used in almost all computer security incident response teams (CSIRTs) and in some information analysis and sharing centres.

### Recital 40 — cross border cooperation single points contact

*Source: NIS2, nis2-rec-40-en, 2022-12-14 — https://overview.legal/posts/96608*

The single points of contact should ensure effective cross-border cooperation with relevant authorities of other Member States and, where appropriate, with the Commission and ENISA. The single points of contact should therefore be tasked with forwarding notifications of significant incidents with cross-border impact to the single points of contact of other affected Member States upon the request of the CSIRT or the competent authority. At national level, the single points of contact should enable smooth cross-sectoral cooperation with other competent authorities. The single points of contact could also be the addressees of relevant information about incidents concerning financial entities from the competent authorities under Regulation (EU) 2022/2554 which they should be able to forward, as appropriate, to the CSIRTs or the competent authorities under this Directive.

## Case law

### USR - Us I-755/2025-8

*Source: Administrative Court in Rijeka, 2025-11-11 — https://overview.legal/posts/49225 — original: https://gdprhub.eu/index.php?title=USR_-_Us_I-755/2025-8*

Facts — The data subject was a member of the management board of Zagrebački holding, a company owned by the City of Zagreb, from 3 September 2021 until 31 March 2023. A television broadcaster published several pieces, including a video on its YouTube channel, reporting on the data subject’s resignation. The publications mentioned his name, role, employer, salary, and information on the brand of his private car. The data subject filed a complaint with the Croatian Personal Data Protection Agency (AZOP), claiming that the publication constituted unlawful processing under the GDPR because the media lacked a valid legal basis under Article 6, the reporting was inaccurate and excessive, and it did not serve any genuine public interest. He latter further claimed during the lawsuit against AZOP's decision that the authority had incorrectly and incompletely established the facts, misapplied substantive law, and breached procedural rules. He emphasized that the published personal data was unrelated to transparency in public administration, that he was neither a public figure nor a political actor, and that any public interest ended once he left office on 31 March 2023. He invoked his right to erasure under Article 17 GDPR and sought removal of the content, annulment of AZOP’s decision, or alternatively, a remittal for a new procedure. AZOP contested the lawsuit in full, maintaining that it had acted in accordance with Article 34 of the Croatian GDPR Implementation Act and Article 77 GDPR. It argued that the publication fell within a justified public interest under Article 8 of the Croatian Media Act and that it had properly carried out a balancing test between privacy (Article 8 ECHR) and freedom of expression (Article 10 ECHR). According to AZOP, the reporting was necessary, proportionate, and not sensationalistic, and did not excessively intrude on the data subject’s privacy. It added that consent was not required because the processing relied on legitimate interest under Article 6(1)(f) GDPR. Holding — The Administrative Court dismissed the action and upheld AZOP’s decision. Because Zagrebački holding is a city-owned and publicly funded company, the court considered information about the data subject’s salary, compensation for using his private vehicle in official duties, and his managerial role to be directly connected to the use of public resources. This placed the publication within the legitimate public interest in transparency recognised by Article 8 of the Media Act. In its proportionality assessment, the court accepted AZOP's application of Article 5 and 6 GDPR, emphasizing that the published data did not touch upon the data subject’s family or intimate life but related solely to his public functions. Publication was therefore limited to what was necessary to inform the public about the management of a publicly owned company. The data subject’s claims that the publication was false or harmful to his reputation did not alter the outcome, as AZOP is not empowered to determine the truthfulness or tone of journalistic content, particularly under the journalistic exemption in Article 85 GDPR. Issues of accuracy or reputational harm must instead be pursued through media-law mechanisms such as requests for correction or civil actions. On the erasure request, the court held that the right to be forgotten under Article 17 GDPR cannot override freedom of expression and information where media reporting is involved. Although the data subject no longer served on the board, the publication continued to contribute to public understanding of how a major public entity was run during his tenure, thus the public interest persisted and erasure was not justified. Finally, the court reiterated that consent was not required because Article 6 GDPR offers alternative lawful bases for processing. Since Article 6(1)(f) was satisfied, the absence of consent was irrelevant. Concluding that AZOP had properly applied the law and that the interference with the data subject’s privacy was proportionate, the court upheld the decision and denied the data subject’s claim and costs.

### Judgment of the Court (First Chamber) of 3 April 2025.#L. H. v Ministerstvo zdravotnictví.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 4 – Definitions – Article 6 – Lawfulness of processing – Article 86 – Public access to official documents – Data concerning the representative of a legal person – Case-law of a national court imposing an obligation to inform and consult the data subject prio

*Source: Court of Justice of the European Union, C-710/23, 2025-04-03 — https://overview.legal/posts/132145 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0710*

In Case C-710/23, the Court of Justice of the European Union (First Chamber) addressed a preliminary reference from the Czech Supreme Administrative Court concerning whether personal data of individuals acting as representatives of legal persons, contained in official documents related to COVID-19 screening test contracts, may be disclosed under GDPR Article 86 and the lawfulness of processing under Article 6. The case arose from a dispute between L.H. and the Czech Minister of Health, who had refused to disclose certain information about representatives of legal persons named in those contracts and related certificates. The Court held that data concerning a representative of a legal person constitutes personal data within the meaning of the GDPR when it allows the natural person to be identified, and that Member States may provide for public access to official documents containing such personal data, provided that the disclosure is reconciled with the right to data protection; however, a national court cannot impose a general obligation to inform and consult the data subject prior to every disclosure of official documents, as this would undermine the public's right of access to official documents.

### Judgment of the Court (Sixth Chamber) of 7 March 2024.#Endemol Shine Finland Oy.#Request for a preliminary ruling from the Itä-Suomen hovioikeus.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Articles 2, 4, 6, 10 and 86 – Data held by a court relating to the criminal convictions of a natural person – Oral disclosure of such data to a commercial company on account of a competition organised by that company – Concept of ‘processing of personal data’

*Source: Court of Justice of the European Union, C-740/22, 2024-03-07 — https://overview.legal/posts/132269 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0740*

In Case C-740/22, the Court of Justice of the European Union (Sixth Chamber) ruled on a preliminary reference from the Itä-Suomen hovioikeus (Court of Appeal, Eastern Finland) concerning whether the oral disclosure by a court of data relating to a natural person's criminal convictions to Endemol Shine Finland Oy, a commercial company organizing a competition, constitutes "processing of personal data" under the GDPR. The Court held that such oral disclosure falls within the scope of GDPR Article 2(1), as the concept of processing is not limited by the means or format of transmission, and that national legislation governing public access to official documents must reconcile the right of access with the GDPR's data protection requirements, particularly given the sensitive nature of criminal conviction data under Article 10. No fine was imposed, as the ruling solely addressed the interpretation of EU law.

### CJEU - Case C 312/24 - Darashev

*Source: GDPRhub, 2025-09-04 — https://overview.legal/posts/158443 — original: https://gdprhub.eu/index.php?title=CJEU_-_Case_C_312/24_-_Darashev*

Facts — The data subject is a police officer, holding various positions at the Internal Security directorate-general of the Bulgarian Ministry of the Interior (controller). In March 2016, investigative proceedings were commenced concerning an unknown offender in connection with an offence of theft. A few days later, the data subject was arrested and after being detained in police custody for 24 hours, he was released. Subsequently, he was neither placed under formal investigation nor charged, but he was the subject of several investigative measures, which in the course of 2016, were suspended without the offender having been identified. The controller stored the data about the criminal investigation on his personnel file, as provided by the ministerial instruction relating to personnel files, issued as a regulatory act pursuant to the statutory authorisation provided for in the Law on the Ministry of the Interior (ZMVR). The data subject continued his duties as a police officer and took part in selection procedures for promotion to other posts within the Ministry but he was rejected. The data subject brought an action before the Sofia District Court (Sofiyski rayonen sad) seeking compensation for non-material damage for the fact that he has not been promoted or transferred to other duties on account of his having been a suspect in the investigation. In addition, he asked that his name be erased from the database kept by the controller, in which he is mentioned as a suspect. In this context the court decided to stay the proceedings and to refer some questions to the CJEU for a preliminary ruling, regarding the interplay of the GDPR with the Law Enforcement Directive (LED), and more specifically regarding the storage of data concerning the official in his personnel file. The questions were combined and reformulated by the AG as follows: whether Article 2(1) GDPR and Article 9(1) LED are to be interpreted as meaning that the GDPR applies to the storing, by a public authority in the personnel file of one of its officials, of data regarding that official’s status as a suspect in a criminal investigation, where the data have been collected by an organisational unit within that public authority in the performance of its duties as a competent authority within the meaning of LED. whether Article 17(3) GDPR, read in conjunction with Article 6(1)(c) and Article 6(3) thereof, is to be interpreted as meaning that the storage, in a police officer’s personnel file, of personal data relating to a criminal investigation in which that officer was the subject of investigative measures, as a suspect, and which was discontinued, may be considered lawful for the purposes of compliance with a legal obligation to which the public authority that is his employer is subject under national law, as controller, merely on account of the nature of the duties which that officer is required to perform. Holding — Regarding the first question about the scope of the GDPR, the AG responded positively, that the GDPR does apply in this case, provided that the storage of that data pursues purposes other than those set out in Article 1(1) LED, purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties. Regarding the second question, the AG responded negatively, that the storage of the data subject’s data in this case was not lawful. First, he clarified that within the meaning of Article 6(3) GDPR, the storage of personal data could be based on a legal obligation being defined in a national law other that a law stricto sensu, though in accordance with national constitutional law. Therefore, in this case, the ministerial instruction was considered an appropriate legal basis. Nevertheless, the AG expressed doubts as to the foreseeability of the purposes of the processing, which, in accordance with Article 6(3) GDPR must be determined by the legal basis of the processing. As laid down in the ministerial instruction, the purpose of the storage was for reasons of ‘change of duties’. The AG considered that this, did not appear to meet an objective of public interest, for the purposes of Article 6(3) GDPR. Furthermore, he failed to see how the nature of the duties of maintaining public order, which fall to the data subject, could justify the storage of the data at issue in his personnel file. In conclusion, the AG opined that the storage of the data at issue was not lawful and that the data subject had the right to have them erased, pursuant to Article 17(1)(d) GDPR.

### VG Düsseldorf - 29 K 3490/24

*Source: Administrative Court Düsseldorf, 2026-06-22 — https://overview.legal/posts/108992 — original: https://gdprhub.eu/index.php?title=VG_Düsseldorf_-_29_K_3490/24*

Facts — A district (the controller), acting as the lower water authority, initiated administrative proceedings after identifying unauthorised riverbank works and a private jetty on two riverside properties. One property belonged to a water utility company, while the other belonged to a municipality and was leased to the data subjects. During those proceedings, the controller shared the data subjects' personal data with various participants, including the owners of the affected properties, other public authorities and a lawyer who claimed to represent the data subjects. The data subjects lodged a complaint with the competent supervisory authority (LDI NRW), alleging that the controller had unlawfully processed and disclosed their personal data. They argued that their personal data had been shared with uninvolved third parties, that the controller had communicated with a lawyer whom they had not authorised, recorded a telephone conversation with an unknown person, and transmitted personal data by unencrypted email. The controller's data protection officer addressed each allegation and provided additional factual information concerning the disputed processing operations. The DPA initially informed the data subjects that no GDPR infringement was apparent, invited them to provide any additional factual information, and explained that it would obtain extracts from the controller's administrative file if there were concrete indications that it contained relevant facts not already available. The data subjects did not identify any additional facts and instead reiterated their legal position that the controller had breached its GDPR accountability obligations. The DPA rejected the complaint, concluding that no GDPR infringement could be established. The data subjects then brought an action before the Verwaltungsgericht Düsseldorf (Administrative Court Düsseldorf), seeking a fresh decision on their complaint on the basis that the DPA had failed to adequately investigate the complaint because it had not obtained the controller's administrative file before reaching its decision. Holding — The court held that Articles 57(1)(f) and 77(1) GDPR give rise to an enforceable right requiring a supervisory authority to investigate a complaint to the extent appropriate in the circumstances before determining whether a GDPR infringement has occurred. Recital 141 GDPR requires the investigation to extend as far as is appropriate in light of the circumstances of the individual case, including the significance of the complaint and the seriousness of the alleged infringement. Applying these principles, the court held that the DPA had adequately investigated the complaint. It had considered each allegation together with the detailed response provided by the controller's data protection officer, invited the data subjects to provide any additional factual information, and explained that it would obtain extracts from the administrative file if concrete indications emerged that further relevant facts required clarification. As the data subjects did not provide any additional facts and there were no objective indications that the information already available was inaccurate or incomplete, the court held that the DPA was not required to obtain the controller's administrative file or undertake further investigations in the absence of concrete indications that additional factual clarification was necessary. The court further held that the DPA had correctly concluded that no GDPR infringement had occurred. The court held that the disputed processing was lawful under Article 6(1)(e) GDPR, read together with Article 6(3) GDPR and § 88 of the German Water Resources Act (WHG), which provided the legal basis for the processing. The court also held that the transmission of personal data by email did not infringe Article 5(1)(f) GDPR because, in the circumstances of the case, transport encryption provided an appropriate level of security.

### Judgment of the Court (Full Court) of 30 April 2024.#La Quadrature du Net and Others v Premier ministre and Ministère de la Culture.#Request for a preliminary ruling from the Conseil d'État (France).#Reference for a preliminary ruling – Processing of personal data and the protection of privacy in the electronic communications sector – Directive 2002/58/EC – Confidentiality of electronic communications – Protection – Article 5 and Article 15(1) – Charter of Fundamental Rights of the European Unio

*Source: Court of Justice of the European Union, C-470/21, 2024-04-30 — https://overview.legal/posts/132259 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0470*

In Case C-470/21, the CJEU addressed a preliminary reference from the French Conseil d'État concerning La Quadrature du Net and others v. Premier ministre and Ministre de la Culture, which challenged France's "graduated response" system allowing public authorities to access civil identity data associated with IP addresses retained by ISPs for the purpose of combating online copyright infringement. The Court ruled that while such access may be justified under Article 15(1) of Directive 2002/58/EC (the ePrivacy Directive) for intellectual property protection, it requires strict safeguards including prior review by a court or independent administrative body, and must be limited to what is strictly necessary, proportional, and subject to substantive and procedural protections against abuse. No fine was imposed as this was a preliminary ruling.

### Judgment of the Court (Fifth Chamber) of 14 March 2024.#Budapest Főváros IV. Kerület Újpest Önkormányzat Polgármesteri Hivatala v Nemzeti Adatvédelmi és Információszabadság Hatóság.#Request for a preliminary ruling from the Fővárosi Törvényszék.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 58(2)(d) and (g) – Powers of the supervisory authority of a Member State – Paragraph 17(1) – Right to e

*Source: Court of Justice of the European Union, C-46/23, 2024-03-14 — https://overview.legal/posts/132267 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0046*

In a preliminary ruling requested by the Budapest High Court, the Court of Justice interpreted whether Article 58(2)(d) and (g) of the GDPR permits a national supervisory authority to order a controller to erase unlawfully processed personal data without a prior request from the data subject. The case arose from a dispute between the Budapest District IV (Újpest) municipal administration and the Hungarian National Data Protection and Freedom of Information Authority (NAIH), which had ordered the municipality to erase unlawfully processed data. The Court held that GDPR provisions do not require a prior data subject request for a supervisory authority to exercise its corrective power to order erasure of unlawfully processed personal data, as such a requirement would undermine the consistent and effective protection of fundamental rights under the GDPR.

### CE - 449212

*Source: CE, 2021-03-04 — https://overview.legal/posts/125660 — original: https://gdprhub.eu/index.php?title=CE_-_449212*

Facts — On December, 7 2020, the French DPA imposed a financial penalty of 60 Million euros fine against Google LLC and a 40 million euros against Google Ireland Limited in accordance with the General Data Protection Regulation (GDPR) and ePrivacy Directive 2002/58/EC, for lack of transparency, inadequate information and lack of valid consent regarding for violating the regulation on cookies while operating the website google.fr. The sanction was accompanied by an order to comply with article 82 of the French Law on data protection (Law Informatique et Libertés), under three months on penalty of a €100,000 fine per day of delay. The companies appealed to the Conseil d’État in interim procedure against the CNIL's decision, arguing that the French DPA was not the competent authority because it was not the lead supervisory authority for Google LLC or Google Ireland Limited. Dispute — Is the CNIL territorially competent to investigate and sanction a company for violating the information principle when depositing cookies if it is not the lead supervisory authority of the company? The CNIL considered that Google does have EU headquarters in Ireland, but that this Irish entity ‘did not have a decision making power’ in relation to the relevant cross-border data processing activities to which the complaints related. For that reason the CNIL decided that the One Stop Shop mechanism did not apply and that the CNIL, like any other European supervisory authority, was therefore competent to make a decision. Holding — The Conseil d’État rejected the request made by Google and ruled that the French DPA was territorially competent on this matter even though it is not the lead supervisory authority. The court stated that Article 82 of the Law Informatique et Libertés was a transposition of Article 5(3) ePrivacy Directive 2002/58/EC into French Law when dealing with cookies and that the CNIL is charged with enforcing this Directive. As such, the one-stop shop mechanism provided for in Article 56 GDPR does not apply in the present case.

### Valsts policijas Rīgas reģiona pārvaldes Kārtības policijas pārvalde  v  Rīgas pašvaldības SIA ‘Rīgas satiksme’

*Source: CJEU, 2017-05-04 — https://overview.legal/posts/5953 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62015CJ0013*

setting out a test based on three criteria to decide whether a processing operation can rely on this ground. The Court reached a surprising conclusion, stating that while there is legitimate interest to process (disclose) data in the case at hand, the controller (a public authority) would also need a legal obligation to lawfully disclose the data.

### CJEU - C-614/10 - Commission v. Austria

*Source: GDPRhub, 2012-10-16 — https://overview.legal/posts/125643 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-614/10_-_Commission_v._Austria*

Facts — On 5 July 2005 the European Commission sent a letter of formal notice to the Republic of Austria in which it claimed that the organisation of the Austrian Data Protection Commission (Datenschutzkommission – DSK) failed to satisfy the criterion of independence set out in the second subparagraph of Article 28(1) Directive 95/46/EC. The Commission did not consider the observations of the Republic of Austria satisfactory and, therefore, issued a reasoned opinion pursuant to Article 258(1) TFEU. On 9 December 2009, the European Commission brought the matter in front of the Court of Justice of the European Union. The Commission and the EDPS noted that, according to the then-current national law, the managing member of DSK needed to be a member of the Federal Chancellery (Bundeskanzleramt). More in general, they pointed out that the office of DSK was structurally integrated with the departments of the Chancellery. They argued that this was contrary to the criterion of independence set out in the second subparagraph of Article 28(1) Directive 95/46/EC, as staff members were subject to the supervision of the Chancellery. The Republic of Austria argued that the requirement of set by the second subparagraph of Article 28(1) Directive 95/46/EC relates to “functional independence” and that the DSK had such independence, since § 37(1) of the then-in force Austrian Data Protection Code (Datenschutzgesetz - DSG 2000) provided for its members to be independent and not to be bound by instructions given by the government. It pointed out that the managing member did not necessarily need to be a member of the Chancellery and could be chosen among lawyers working in the federal public administration. Holding — Firstly, the court noted that Article 8(3) CFR, Article 16(2) TFEU and Article 28(1) Directive 95/46/EC require Member States to have a supervisory authority which have complete independence. The court found that the independence of the supervisory authority is an essential component of the protection of individuals with regard to the processing of personal data. Secondly, the court set aside the argument of the Republic of Austria that the DSK has a sufficient degree of independence since it satisfied the condition of independence inherent in Article 267 TFEU for it to qualify as a court or tribunal of a Member State. The court held that the notion of “complete independence” under data protection law is autonomous and independent from the one under Article 267 TFEU. Thirdly, the court gave its interpretation of the concept of “complete independence” set by Article 28(1) Directive 95/46/EC. To do that, the court referred to its previous judgement C-518/07, Commission v. Germany. In this judgement, it had held that this concept should be interpreted as meaning that the supervisory authorities must enjoy an independence which allows them to perform their duties free from any external influence, direct or indirect, which is liable to have an effect on their decisions. Applying this principle to the case at hand, the court found that the requisite of functional independence, like the one accorded to the DSK, is a condition which is essential to have a “complete independence”. However, this condition by itself is not sufficient to protect that supervisory authority from all external influence. On the contrary, according to the court, some pieces of Austrian legislation did not allow the DSK to be completely free from any indirect influence. For example, according to § 36(3) and § 38(1) DSG 2000 the managing member of the DSK is a federal official. Moreover, § 45(1) of the 1979 Law on the conditions of service of officials (Beamten-Dienstrechtsgesetz 1979 - BDG 1979) grants the hierarchical superior an extensive power of supervision over their officials and to encourage the promotion of their staff. Furthermore, the court held that the fact that the staff of the DSK was composed by federal officials was not compliant with the independence requirement, given that these officials are subject to supervision by the Federal Chancellery within the terms of § 45(1) BDG 1979. Finally, the court noted that the Federal Chancellor has the right to be informed at all times by the chairman and the managing member of all aspects of the work of the DSK, according to Article 20(2) of the Federal Constitutional Law (Bundes Verfassungsgesetz – BVG) and § 38(2) DSG 2000. On this matter, the court ruled that such a right to information is also liable to subject the DSK to indirect influence, given that it is far-reaching as it covers “all aspects of the work of the DSK” and that it is unconditional. On these grounds, the CJEU held that, by failing to take all of the measures necessary to ensure that the legislation in force in Austria meets the requirement of independence, the Republic of Austria has failed to fulfil its obligations under Article 28(1) Directive 95/46/EC.

### French Supreme Admin Court partly upholds challenge to graduated response IP data decree

*Source: Supreme Administrative Court, 2026-04-30 — https://overview.legal/posts/122869 — original: https://gdprhub.eu/index.php?title=CE_-_N._433539*

Facts — Several digital rights organisations asked the Prime Minister to repeal Decree No. 2010-236 of 5 March 2010. The decree regulated an automated personal data processing system used by the French authority for freedom of communications (ARCOM, hereinafter the French authority) for France’s online copyright enforcement mechanism, known as the graduated response procedure. Under this system, the French authority could receive IP addresses linked to alleged copyright infringements and request the corresponding subscriber identity data from electronic communications operators. This data could then be used to send warnings to subscribers and, in repeated cases, refer the matter to the public prosecutor. The applicants argued that the decree allowed the French authority to access personal data linked to IP addresses without sufficient safeguards under EU law. The court had previously referred questions to the CJEU, which ruled in Case C-470/21 that such access may be allowed, but only under strict conditions. Following the CJEU judgment, the court reviewed whether the French decree complied with EU law. Holding — The court partly upheld the action. First, the court held that EU law allows the general and indiscriminate retention of IP addresses for combating criminal offences in general only where serious interference with private life is effectively excluded. This requires strict separation between different categories of retained data, secure technical safeguards and regular monitoring by an independent public authority. The court found that French law did not require electronic communications operators to retain subscriber identity data and IP-related data under these conditions. Therefore, the decree was unlawful insofar as it allowed the French authority to process data that had not necessarily been retained in compliance with EU-law safeguards. Second, the court held that the French authority may access subscriber identity data linked to IP addresses in order to identify persons suspected of online copyright infringements and send the first two warnings under the graduated response procedure. However, the court distinguished the third access to such data. At that stage, the authority is no longer dealing with an isolated identification request: it has already linked the same person’s identity twice with alleged unlawful online activity and with the protected works concerned. A third access therefore allows the authority to build a more detailed picture of the person’s conduct and may reveal sensitive aspects of their private life. It also marks a more serious procedural stage, since it may lead to a registered letter and ultimately to referral to the public prosecutor. For that reason, EU law requires prior authorisation by a court or an independent administrative body before this third access takes place. The decree did not provide for such prior review, so the court held that it was unlawful to that extent. For this third access, EU law requires prior authorisation by a court or an independent administrative body. The decree did not provide for such prior review. The court therefore held that the decree was unlawful to that extent. The court annulled the Prime Minister’s refusal to repeal the unlawful parts of the decree and ordered their repeal. It also held that the French authority must stop applying the unlawful provisions. However, the French authority may still access identity data for the first and second warnings, and may request access in serious copyright offence cases under the conditions set out in the judgment.

### Judgment of the Court (Eighth Chamber) of 27 February 2025.#Amt der Tiroler Landesregierung v Datenschutzbehörde.#Request for a preliminary ruling from the Verwaltungsgerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 4(7) – Concept of ‘controller’ – Direct designation of the controller by national law – Auxiliary administrative entity in the service of a regional government – Lack of

*Source: Court of Justice of the European Union, C-638/23, 2025-02-27 — https://overview.legal/posts/132147 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0638*

In Case C-638/23, the Court of Justice interpreted Article 4(7) GDPR in response to a preliminary reference from the Austrian Verwaltungsgerichtshof in proceedings between the Amt der Tiroler Landesregierung (Office of the Provincial Government of Tyrol) and the Datenschutzbehörde (Austrian Data Protection Authority). The core issue was whether an auxiliary administrative entity lacking legal personality and legal capacity, operating in the service of a regional government, qualifies as a "controller" under the GDPR when national law directly designates it to determine the purposes and means of personal data processing. The Court held that such an entity may be designated as a controller by Member State law provided it in fact determines the purposes and means of the processing, with the concept of "other body" in Article 4(7) not requiring the entity to possess legal personality or its own legal capacity.

## Guidance

### Opinion 07/2025 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data by the European Patent Organisation

*Source: EDPB, edpb-opinion-202507-epo-adequacydecision-en, 2025-05-06 — https://overview.legal/posts/50823 — original: https://www.edpb.europa.eu/documents/adequacy/opinion-072025-regarding-the-european-commission-draft-implementing-decision_en*

EDPB, Opinion 07/2025 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data by the European Patent Organisation, 2025.

### Overview on resources made available by Member States to the Data Protection Authorities and on enforcement actions by the Data Protection Authorities

*Source: EDPB, overview-on-resources-made-available-by-member-states-to-en, 2021-08-11 — https://overview.legal/posts/125988 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/overview-on-resources-made-available-by-member-states-to_en*

1 Overview on resources made available by Member States to the Data Protection Authorities and on enforcement actions by the Data Protection Authorities 05 August 2021 2 Table of co n tent Background ................................ ................................ ................................ ................................ ......... 3 Introduction ................................ ................................ ................................ ................................ ........ 3…

### Guidelines 2/2020 on articles 46 (2) (a) and 46 (3) (b) of Regulation 2016/679 for transfers of personal data between EEA and non-EEA public authorities and bodies

*Source: EDPB, guidelines-22020-on-articles-46-2-a-and-46-3-b-of-regulation-2016679-for-en, 2020-12-15 — https://overview.legal/posts/126098 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-22020-on-articles-46-2-a-and-46-3-b-of-regulation-2016679-for_en*

Adopted 1 Guidelines 2/2020 on a rticles 46 (2) (a) and 46 (3) (b) of Regulation 2016/679 for transfers of personal data between EEA and non - EEA public authorities and bodies Version 2 .0 Adopted on 1 5 December 2020 Adopted 2 Version history Version 2.0 15 December 2020 Adoption of the Guidelines after public consultation Version 1.0 18 February 2020 Adoption of the Guidelines for public consulation Adopted 3 Adopted 4 The European Data Protection Board Having regard to Article 70 (1e) of…

### Opinion 8/2019 on the competence of a supervisory authority in case of a change in circumstances relating to the main or single establishment

*Source: EDPB, opinion-82019-on-the-competence-of-a-supervisory-authority-in-en, 2019-07-12 — https://overview.legal/posts/126208 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-82019-on-the-competence-of-a-supervisory-authority-in_en*

Adopted 1 Opinion 8 /2019 on the competence of a supervisory authority in case of a change in circumstances relating to the main or single establishment Adopted on 9 July 2019 Adopted 2 Table of c ontents 1 SUMMARY OF THE FACTS ................................ ................................ ................................ ................ 3 2 ON THE COMPETENCE OF THE BOARD TO ADOPT AN OPINION UNDER ARTICLE 64.2 ON THIS TOPIC ................................ ................................…

### EDPB Annual Report 2025

*Source: EDPB, edpb-annual-report-2025-en, 2026-04-09 — https://overview.legal/posts/125683 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-annual-report-2025_en*

Clarity in action: Supporting stakeholders through guidance and dialogue Annual Report 2025 Foreword 3 Highlights 4 1. The EDPB Secretariat 6 1.1 Mission And Activities 8 2. European Data Protection Board – Activities in 2025 12 2.1 Bridging Fundamental Rights and Digital Innovation Through GDPR Compliance 12 2.1.1 Helsinki high-level meeting: enhanced clarity, support and engagement 12 2.1.2 Regulation on procedural rules and Omnibus regulation on the record of processing 14 2.1.3 Cross…

### Statement 3/2024 on data protection authorities’ role in the Artificial Intelligence Act framework

*Source: EDPB, statement-32024-on-data-protection-authorities-role-in-the-en, 2024-07-16 — https://overview.legal/posts/125732 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-32024-on-data-protection-authorities-role-in-the_en*

Final 1 Statement 3/2024 on data protection authorities’ role in the Artificial Intelligence Act framework Adopted on 16 July 2024 The European Data Protection Board has adopted the following statement: 1 BACKGROUND AND PURPO SE OF THIS STATEMENT 1. On 12 July 2024, Regulation (EU) 2024/1689 laying down harmonised rules on a rtificial i ntelligence (Artificial Intelligence Act, hereinafter the “ AI Act ”) and amending certain Union Legislative Acts was published in the Official Journal 1 . 2.…

### Toolbox on essential data protection safeguards for enforcement cooperation between EEA data protection authorities and competent data protection authorities of third countries

*Source: EDPB, toolbox-on-essential-data-protection-safeguards-for-enforcement-en, 2022-03-14 — https://overview.legal/posts/125962 — original: https://www.edpb.europa.eu/documents/other-guidance/toolbox-on-essential-data-protection-safeguards-for-enforcement_en*

Adopted Toolbox on essential data protection safeguards for enforcement cooperation between EEA data protection authorities and competent data protection authorities of third countries Adopted on 14 Mar c h 2022 2 Adopted The European Data Protection Board Having regard to Article 70 (1)(u) and Article 50(a) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the…

### Statement 05/2021 on the Data Governance Act in light of the legislative developments

*Source: EDPB, statement-052021-on-the-data-governance-act-in-light-of-en, 2021-05-20 — https://overview.legal/posts/126024 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-052021-on-the-data-governance-act-in-light-of_en*

1 Statement 05/2021 on the Data Governance Act in light of the legislative developments Adopted on 19 May 2021 The European Data Protection Board has adopted the following statement: On 9 March 2021 the EDPS and the EDPB adopted the Joint Opinion on the Proposal for a Data Governance Act (DGA) 1 , which has also been presented at the European Parliament at the hearing of the LIBE Committee of 16 March 2021 2 . The EDPB is closely followin g the work of the co - legislators on this important…

## Enforcement decisions

### Datatilsynet (Denmark) - 2020-431-0061 (Helsingor decision no. 4)

*Source: Datatilsynet (Denmark), 2022-09-28 — https://overview.legal/posts/6313 — original: https://gdprhub.eu/index.php?title=Datatilsynet_(Denmark)_-_2020-431-0061_(Helsingor_decision_no._4)*

Facts — This is the Danish DPA's fourth decision in the case relating to Helsingor municipality's processing of personal data in primary and lower secondary school. Helsingor municipality, the controller, has been using Google Chromebooks and Workspace for Education in violation of several GDPR requirements, as detailed in the first decision of September 2021, the second decision of 14 July 2022 and the third decision of 18 August 2022. Following the third decision, the municipality submitted more documentation and also requested a consultation with the DPA as per Article 36 GDPR. Holding — The DPA temporarily suspended its processing ban against Helsingor municipality until 5 November 2022, and also ordered the municipality to: Change the data processing agreement with Google so that the DPA's remarks in their 14 July and 18 August decisions, are implemented. This includes, at a minimum, a clarification of where and if Google acts as a sole controller and any uncertainties that may entail that Google acts beyond their role as a processor, see Article 28(3)(a) GDPR. Document that all transfers of personal data to insecure third countries, are in line with the GDPR. Describe all data flows and identify the personal data that are shared with the vendor, and clarify when the vendor acts as a sole or joint controller. This documentation must include the whole technology stack used by the municipality (for this processing activity). Update their data protection impact assessment based on all identified risks. Consult the DPA if the DPIA shows any high risks the municipality is not able to mitigate. If any processing activities are still not in line with the GDPR before the DPA's deadline 3 November 2022, present a final plan for bringing them in line with the GDPR.

### Privacy Appeals Board: Datatilsynet may demand information from OpenX under GDPR Art.

*Source: Datatilsynet (Norway), 2020-09-07 — https://overview.legal/posts/122844 — original: https://gdprhub.eu/index.php?title=Datatilsynet_(Norway)-_20/02254*

Facts — The Norwegian Consumer Council (Forbrukerrådet) filed three complaints against the gay/bi dating app Grindr and five adtech companies that received personal data through the app. Subsequently, Datatilsynet sent a request for more information from one of the adtech companies; OpenX. OpenX refused to respond on the basis that Datatilsynet does not have legal grounds to impose such a request on them, because, in their opinion, the issue relates to the Electronic Communications Act § 2(7)(b) (cf. Article 5(3) ePrivacy Directive 2002/58/EC), where the Norwegian Communications Authority is the right supervisory authority (and not Datatilsynet), and filed a complaint to the Privacy Appeals Board. Dispute — Does the Datatilsynet have the legal grounds (as a supervisory authority) to impose a request for information on OpenX? Holding — The Privacy Appeals Board rejected OpenX's complaint as they concluded that Datatilsynet has legal grounds to impose such requests for information as per Article 58(1) GDPR.

### UODO (Poland) - DKN.5131.27.2023

*Source: UODO (Poland), 2026-05-19 — https://overview.legal/posts/83471 — original: https://gdprhub.eu/index.php?title=UODO_(Poland)_-_DKN.5131.27.2023*

Facts — A municipal social welfare unit (the controller) processed the personal data of the residents of the municipality (the data subjects), including names, addresses, and information regarding whether certain individuals were subject to mandatory quarantine to prevent and combat the SARS-COV-2 virus. An employee of the controller posted a file containing this information on a private server in November 2020. An automated search engine indexing bot subsequently accessed the file and made its full contents available in search results to any Internet user. The supervisory authority received an electronic report concerning a potential data breach in February 2021. The controller had not notified the DPA or the data subjects of this incident, as it concluded it had not acted as a controller in the context of the processing operations at issue. The DPA launched an investigation into the unauthorised disclosure of personal data and initiated administrative proceedings against the controller in August 2023. Holding — The DPA issued the controller three separate fines amounting to PLN 33,700 (€7,800) in total, as it considered its GDPR violations were the result of three separate courses of conduct. It held that the social welfare unit had clearly determined the means and purposes of processing and acted as controller within the meaning of Article 4(7) GDPR – the employee responsible for the processing operations had acted with the unit’s authorisation, at its instruction, and on its behalf. First, the DPA held the controller had violated Articles 24(1), 25(1), 32(1), and 32(2) GDPR by failing to implement appropriate technical and organisational measures and imposed a fine of PLN 15,000 (€3,460) on the controller. This resulted in violations of the principles of integrity, confidentiality and accountability set out in Articles 5(1)(f) and 5(2) GDPR. There was an internal document in effect during the data breach that identified the risk level of processing as high. However, the DPA pointed out this document did not include, among other things, the number of data subjects, the periods for data storage, and the duration of the processing. The measures implemented were not reviewed or updated and also proved to be ineffective. Second, the DPA issued the controller a fine of PLN 5,500 (€1,270) for an infringement of Article 33(1) GDPR due to a failure to report the data breach to the supervisory authority. Finally, the DPA held that the controller had violated Article 34(1) GDPR by failing to notify the data subjects of the data breach and imposed a fine of PLN 13,200 (€3,060) on the controller. In addition, it ordered the controller to notify the data subjects of the breach in question.

### HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens

*Source: HDPA (Greece), 2026-05-13 — https://overview.legal/posts/144044 — original: https://gdprhub.eu/index.php?title=HDPA_(Greece)_-_12/2026*

Facts — The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of Undesirable Aliens. In response to the Authority's request for clarifications, the competent Directorate of the Ministry of Citizen Protection informed the DPA that: • By a decision dated 27-07-2017, an entry ban and registration in the National Registry of Undesirable Aliens were imposed on the complainant for reasons of national security. • Following temporary 48-hour lifts of the measure for humanitarian reasons in 2019, the entry ban was re-imposed. • Subsequent decisions in 2020, 2023, and 2025 maintained the entry ban and renewed his registration in the National Registry of Undesirable Aliens for successive three-year periods, as the grounds for registration remained active. • The explicit grounds and documentation behind the registration were not disclosed to the complainant because the competent Directorate classified the file as restricted/classified service material. The complainant and his attorney attended a DPA hearing on 22-04-2026, arguing that the registration lacked specific, adequate, or definitive justification regarding any threat to public order or national security. They noted that the complainant has no criminal convictions, poses no threat, and possesses strong ties, residency, and business operations in the region of Northern Epirus and Greece, meaning the entry ban severely disrupts his professional and family life. Holding — According to the provisions of Article 82(1) of Law 3386/2005, foreign nationals whose presence in Greek territory constitutes a threat to national security, public safety, or public order can be registered in the National Registry of Undesirable Aliens, with registrations subject to an ex officio review every three years. Furthermore, pursuant to the provisions of Article 54(2) and Article 55(4) of Law 4624/2019 (the Greek law implementing the GDPR), the data controller is legally empowered to restrict or omit the provision of information and to deny a data subject access to their personal data when dictated by reasons of national security or public order. These national provisions are explicitly anchored in Article 23 GDPR (specifically Article 23(1)(a)GDPR and Article 23(1)(c) GDPR), which permits Member State law to restrict the scope of the obligations and data subject rights (such as the right to be informed under Article 13 GDPR - Article 14 GDPR and the right of access under Article 15 GDPR) to safeguard national security and public security. In the present case, the evidence demonstrated that the complainant's initial registration and subsequent renewals in the National Registry of Undesirable Aliens were executed lawfully for reasons of national security. The Ministry of Citizen Protection, acting as the data controller, exercised its legal discretion under these frameworks to weigh these interests and correctly determined that the underlying operational decision constitutes classified material that cannot be disclosed to the data subject. Consequently, the fundamental principles of data protection law were not breached, and the Hellenic DPA rejected the complaint as unfounded.

### AKI (Estonia) - No. 2.1-1/24/397-890-38

*Source: AKI (Estonia), 2026-04-16 — https://overview.legal/posts/53882 — original: https://gdprhub.eu/index.php?title=AKI_(Estonia)_-_No._2.1-1/24/397-890-38*

Facts — OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic. On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had failed to provide all personal data requested. The controller only partially complied after several requests from the DPA. Although the DPA closed the part of the case concerning the access request, it continued investigating the controller’s processing of patients’ personal data when providing Invisalign treatment. The service required the controller to collect and transfer patients’ health data to Align Technology, Inc. However, the contractual documents did not clearly establish whether Align Technology acted as a processor, an independent controller or a joint controller. The controller stated that Align Technology largely determined the conditions of the service, including the consent form and the processing arrangements, and that individual clinics could not unilaterally amend these conditions. The DPA also found that the information provided to patients was incomplete and fragmented. The consent form and privacy information did not clearly explain the legal basis and purposes of processing, the parties involved, data recipients, retention periods, transfers outside the European Union or the safeguards applied to such transfers. Parts of the information were only available in English on external websites. Holding — The DPA held that the controller had failed to demonstrate that the processing carried out in connection with the Invisalign service was lawful and transparent under Articles 5(1)(a) and 5(2) GDPR. First, the DPA found that the parties’ roles had not been properly determined. Under Article 4(7) GDPR, the assessment had to be based on which party actually determined the purposes and means of processing, rather than solely on the contractual description of the relationship. The controller decided whether Invisalign treatment was suitable for a patient and collected the relevant health data. It therefore acted as a controller in relation to the treatment. However, Align Technology exercised significant control over the subsequent processing, including the data collected, the recipients, retention arrangements, the use of other service providers and transfers outside the European Union. The DPA therefore considered that Align Technology could not simply be regarded as a processor acting only on documented instructions under Article 28(3)(a) GDPR. On the available evidence, it was at least a joint controller under Article 26 GDPR. The DPA ordered the controller to review the contractual relationship. If Align Technology acted as a processor, the agreement had to comply with Article 28 GDPR, including the requirements concerning subprocessors under Article 28(2). If the parties were joint controllers, they had to allocate their respective responsibilities under Article 26 GDPR. Second, the DPA found that the consent obtained from patients was invalid. The consent form did not provide sufficient information for patients to understand the processing and therefore did not meet Articles 4(11), 6(1)(a), 7 and 9(2)(a) GDPR. The DPA also noted that healthcare processing may, depending on the operation concerned, rely on Article 6(1)(b) GDPR together with Article 9(2)(h) GDPR. However, the controller had not clearly identified the applicable legal bases for the different processing activities. The privacy information also failed to comply with Articles 12, 13 and 14 GDPR. Patients were required to consult several documents and external websites, some of which contained incomplete or inconsistent information. The controller had therefore not ensured that the information was easily accessible, understandable and available in Estonian. The DPA further referred to Article 25 GDPR when emphasising that the controller had to ensure that the processing arrangements and safeguards complied with the GDPR. Under Article 58(2)(d) GDPR and § 56(1) of the Estonian Personal Data Protection Act, the DPA ordered the controller to clarify the parties’ roles, conclude an Article 26 arrangement or Article 28 agreement, amend the consent form and privacy policy, and publish the required information in Estonian. No administrative fine was imposed. However, failure to comply could result in a penalty payment of €1,000 for each unfulfilled point or subpoint of the order, imposed repeatedly until compliance.

### Garante per la protezione dei dati personali (Italy) - 9794895

*Source: Garante per la protezione dei dati personali (Italy), 2022-06-09 — https://overview.legal/posts/6314 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_9794895*

Facts — The Municipality of Policoro (Basilicata), implemented the use of CCTV cameras to monitor and fight waste abandonment within its territory. A data subject complained the Municipality had breached their data protection right of fair, transparent and lawful processing under art. 5(1)(a) as the sign signaling the CCTV monitoring referred to an outdated legislative decree. They also alleged a breach of art. 5(1)(e) and art. 13 GDPR, in so far the municipality never defined a data retention period for each processing purpose pursued. The last complaint moved forward by the data subject was that by being legally represented in Court by the same lawyer, who also acted as DPO of Policoro, the Municipality gave rise to a conflict of interest situation and breached art. 38(6) GDPR. The Municipality argued that the claim had been done in front of the Justice of Peace, who had no competency to decide on issues of privacy. It was also alleged the judgement only pertained an administrative matter, without rising any data protection concerns or a situation of conflict of interest with the Municipality's DPO. The last argument alleged the processing and retention of the CCTV footage was related to illegal dumps within the municipal territory, meaning the filming had been carried out in the course of judicial police investigations and the data retention periods of the GDPR did not apply in this case. Holding — The Italian DPA held that in this case the Municipality was carrying activities of data processing, by surveilling public entities by means of surveillance cameras. It also noted, that in par. 41 of the Guidelines 3/2019 on the Processing of Personal Data by Video Devices, waste management is "among the institutional activities entrusted to local authorities". This means the surveillance done by the Municipality of Policoro, a task carried out in the public interest in connection with the exercise of official authority as per art.6(1)(e) GDPR, was unrelated to public security and/or judicial police and obliging the controller to comply with data protection principles. The DPA found that the information provided in regards to the processing of personal data by means of surveillance cameras, did not meet the requirements of conciseness, transparency, intelligibility and easy readability contained in art. 5(1)(a) GDPR. The Municipality of Policoro had failed to provide suitable first-level information to the data subject, in so far the sign signaling the CCTV surveillance made reference to an outdated legislative decree (d.lgs 196/03) instead of the one currently in force (d.lgs 101/18). Furthermore, the data controller failed to provide the data subject with an adequate notice on second-level processing of their data. The signage did not include information on the most suitable impacts of the processing or an indication of a website, where to consult an extended version of the explanation. The DPA also found a violation of art. 13 GDPR as well as the principles of storage limitation and accountability in art. 5(1)(e) and art. 5(2). It stated that "the longer the intended storage period (especially if longer than 72 hours), the more reasoned the analysis referring to the legitimacy of the purpose and necessity of storage must be". In this case, the data controller not only failed to set a maximum retention period for the images taken for the purpose of combating illegal littering, but also established the administrative fines for the violation two months after the images were recorded. This did not allow for the data controller to respect the principle of accountability. Lastly, the DPA addressed the alleged conflict of interest raised by the involvement of the Policoro's DPO in the legal proceedings brought against the data subject. The DPA ruled DPOs "may perform other duties and functions," with the understanding that "the controller must ensure that such duties and functions do not give rise to a conflict of interest." The DPA also made reference to the Article 29 WP's Guidelines on Data Protection Officers, in which it is urged to not designate DPOs already acting as defense counsel for the same court. In the case at hand, it resulted that the DPO shared with the Municipality an interest in obtaining a rejection of the appeal. Consequently, the Italian Garante held this to be in violation of art. 38(6) GDPR, as well the fact that it undermined the DPO's independence. The Italian DPA held a cumulative breach of art. 5(1)(a) and (e) and (2) (in conjunction with article 24), 12, 13 and 38(6) GDPR. It balanced the fact that the personal data processing affected all other citizens, who passed through the areas under surveillance, against the lack of previous violations committed by the data controller. The DPA issued a fine of €26,000 EUR to the Municipality of Policoro.

### EDPS - 2020-1013

*Source: EDPS, 2022-01-05 — https://overview.legal/posts/122849 — original: https://gdprhub.eu/index.php?title=EDPS_-_2020-1013*

Facts — In January 2021, noyb filed a complaint against the European Parliament on behalf of six Members of the European Parliament over an internal coronavirus testing website. The issues raised were: confusing and unclear cookie banners, vague and unclear data protection notices, and the illegal transfer of data to the US. Holding — On data controllership — According to the EDPS, the processor may enjoy a considerable degree of autonomy in providing its services and may identify the ‘non-essential’ elements of the processing operation. Furthermore, the processor may advise or propose certain measures in this respect, but it is up to the controller to decide whether to accept such advice or proposals. The analysis of the EDPS shows that the European Parliament (EP) delegated some aspects on the setting up and functioning of the website to Ecolog. The EDPS considers the EP acts as the sole data controller for the processing in question (i.e. the operation of the Parliament’s dedicated website) whereas Ecolog acts as a processor. After having assessed the instructions given by the EP to the processor, the EDPS concluded that the EP did not show the necessary diligence required from a data controller and, ultimately, failed to comply with the Regulation on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data 2018/1725 (hereafter Regulation 2018/1725), in particular with Articles 26(1) and 29(1). Moreover, the EDPS considered that the EP failed to provide the necessary detailed instructions to Ecolog for the setting up of the website, including the drafting of the data protection notice. The absence of documented instructions is therefore in violation of Article 29(3) Regulation 2018/1725. Transparency and information requirements — The EDPS confirmed that the data protection notice published at the time of the complaint did not reflect the processing done by the EP, since it merely consisted of a copy of the testing center of Zaventem's airport. Moreover, the reference made in the document to Article 6(1)(f) GDPR was wrong since it stems from the same error. The EDPS confirmed that the EP did not meet its transparency requirements. The EDPS also analysed the updated version of the data protection notice during the procedure and raised several remaining -and even new- inconsistencies and issues. Among other things, the following problems persisted after the data protection notice was updated: a mere reference to Article 15 and 16 Regulation 2018/1725 is misleading as it should apply in its entirety; the reference to the processing of health data is not correct since no such data are processed in the case at hand; the retention period mentioned is not precise enough; the sections of the data protection notices relating to the recipients of the personal data fail to make any reference to the processor; inconsistencies between the different linguistic versions of the data protection notices were still observed: The English and German versions refer to Ecolog and the Laboratory van Poucke as processors under Article 29 Regulation 2018/1725, whereas the French version refers to them as controllers (‘responsables du traitement’). Moreover, the DPO’s contact details on the website refer to Ecolog in all three linguistic versions of the website, when they should be referring to the Parliament Cookies and transfers of personal data to the US — The EDPS confirmed that tracking cookies, such as the Stripe and the Google analytics cookies, are considered personal data, even if the traditional identity parameters of the tracked users are unknown or have been deleted by the tracker after collection. In the same vein, the EDPS rejected the EP's argument and confirmed that upon installation on a device, a cookie cannot be considered ‘inactive’. Every time a user visited Ecolog’s website, personal data was transferred to Stripe through the Stripe cookie, which contained an identifier. The EDPS reached the conclusion that a transfer of data was taking place to the US, via the use of Google and Stripe cookies, since Google Analytics is hosted in the US and the data protection notice referred to a Standard Contractual Clause (SCC) for the transfer of data outside of the EU. However, the Parliament provided no documentation, evidence or other information regarding the contractual, technical or organisational measures in place to ensure an essentially equivalent level of protection to the personal data transferred to the US in the context of the use of cookies on the website. Cookie banner on the Parliament’s dedicated website — The EDPS reminded that: before setting cookies or any other technology falling within the scope of Article 5(3) ePrivacy Directive 2002/58/EC (hereafter ePrivacy Directive), the EU institution must provide the user with adequate information on what is accessed or stored on the user’s terminal equipment, on the purposes of this action and the means for expressing their consent; no action may be performed before the consent is collected. In addition, users must be enabled to withdraw their consent at any time; ‘cookie walls’ are not in line with Regulation 2018/1725, meaning that for consent to be freely given, access to the website’s service and functionalities should not depend on the users’ consent for cookies that are not strictly necessary in the sense described above; in case personal data collected through the cookies are shared with third parties such as analytics partners, the cookie banner should draw the user's attention to it. The EDPS reached the conclusion that the cookie banners in all three languages were not in line with the definition of consent under Article 3(15) Regulation 2018/1725, nor did they meet the requirements of Article 37 Regulation 2018/1725 and Article 5(3) ePrivacy Directive. The cookie banner further failed to provide transparent information regarding the processing of personal data in relation to the cookies on the website. Request for access to personal data — The Parliament was aware that the complainants’ personal data had been processed through the cookies, which were present on the website for the period between 30 September to 4 November 2020, since transfers of personal data had taken place. Consequently, and especially following the EDPS’ inquiry on the matter, the Parliament should have replied to the complainants’ access to personal data request. The Parliament should have provided the relevant information even if it was aware that the processing of the personal data in question was unlawful, as the main purpose of the right of access under Article 15 GDPR is precisely to enable data subjects to become aware of the processing and verify the lawfulness thereof, or exercise other data subject rights. Conclusion — The EDPS concludes that the Parliament has infringed the following articles of Regulation 2018/1725: Articles 26(1) and 29(1) due to its failure to fulfil its responsibilities as controller and use a processor providing sufficient guarantees to implement appropriate technical and organisational measures; Article 29(3) due to its failure to provide documentation relating to the detailed instructions given to the processor for the setting up and functioning of the website; Articles 4(1)(a) and 14, 4(2), and 15 due to its failure to respect the principle of transparency, accountability and the data subjects’ right to information because of the inaccurate data protection notice and cookie banner on the dedicated website; Article 46 and Article 48(2)(b) of the Regulation, due to its reliance on the Standard Contractual Clauses in the absence of a demonstration that data subjects’ personal data transferred to the US were provided an essential equivalent level of protection; Article 37 read in the light of Article 5(3) of the ePrivacy Directive, due to its failure to protect information (the cookies) transmitted to, stored in, related to, processed by and collected from the users’ terminal equipment; Articles 17 and 14(4) due to its failure to reply to the data subjects’ request for access to their personal data. On the basis of the above, the EDPS decides: to issue a reprimand to the Parliament in accordance with Article 58(2)(b) Regulation 2018/1725 for the above infringements; to order the Parliament, pursuant to Article 58(2)(b) Regulation 2018/1725:, to update its data protection notices in the dedicated website in order to provide all relevant information relating to the processing of personal data. The Parliament should address this order within one month from the date of the decision.

### CNPD (Portugal) - Deliberação 2019/494

*Source: CNPD (Portugal), 2019-09-03 — https://overview.legal/posts/122872 — original: https://gdprhub.eu/index.php?title=CNPD_(Portugal)_-_Deliberação_2019/494*

Facts — In its Opinion 20/2018 concerning the draft of Law 58/2019 which ensures the implementation of the GDPR in the portuguese national legal framework, the DPA drew the attention of the national legislator to a set of provisions that could potentially violate EU law, particularly the GDPR. The DPA emphasized the primacy of EU law as outlined in the EU treaties, particularly reflecting on Article 288 of the Treaty on the Functioning of the European Union (TFEU) and reinforced by the jurisprudence of the CJEU, which has consistently stated that national laws cannot obstruct the direct applicability of EU regulations and must comply with EU law to ensure uniform implementation across the Member States. However, Law 58/2019 came into force without incorporating all of the DPA's recommendations. The DPA explains that the decision to not apply some of its provisions aims to ensure legal certainty, reinforcing the importance of consistent GDPR application without being hindered by conflicting national rules. Holding — The DPA has decided to disapply the following provisions of Law 58/2019, in cases of personal data processing under its review due to their conflict with the GDPR: Article 2(1)(2): This article broadens the territorial scope of the GDPR to encompass all personal data processing within national territory and processing linked to national establishments outside the territory. The DPA believes this contradicts Article 3 and Article 56 of the GDPR, which outlines the applicable law in cross-border situations. Additionally, it undermines the one-stop-shop mechanism and fails to address instances where the GDPR applies, such as in Portuguese embassies, consulates, ships, and aircraft. Article 20(1): This article states that the right to be informed and the right of access cannot be exercised when a duty of secrecy is imposed on the data controller/processor. In the view of the DPA, this article lacks legal relevance in relation to the GDPR, as it merely repeats provisions already present in the GDPR, particularly concerning the possibility of restricting the data subject's right to information in cases where data collection is indirect and a legal duty of confidentiality exists. Regarding the possibility of restricting the right to information when collecting data directly from the data subject, this right can only be restricted under the provisions of Article 23 GDPR, and Law58/2019 does not meet the requirements therein, thus contradicting the norms of the GDPR and the Charter of Fundamental Rights. Article 23: This article allows public authorities to reuse personal data for any public interest without ensuring compliance with principles of purpose limitation and data minimization (Article 5 GDPR) and could lead to potential misuse of personal data and a violation of individuals’ rights, as it does not ensure that the reuse of data serves the original purpose for which it was collected nor respecting the requirements imposed in Article 23 GDPR. Article 28(3)(a): The employee's consent cannot be the legal basis if the processing results in a legal or economic advantage for the employee. The Portuguese DPA considers it to be a contraction of the doctrine established by European institutions, which accepts employee consent in situations where the act of giving or refusing consent does not, in itself, have negative consequences for the employee. The DPA therefore believes that this provision does not protect the dignity, fundamental rights, and legitimate interests of employees, and thus fails to meet the requirements set forth in Article 9 (2) (b) and Article 88 GDPR. Regime of Administrative Offenses – Articles 37, 38, and 39: The DPA notes that some of the violations outlined in the law contradict the exhaustive list provided in the GDPR (Article 83). The DPA also criticizes the distinction in sanctioning frameworks based on the size of companies and the collective or individual nature of the entities conducting data processing, as the impact on personal data does not depend on those characteristics but rather on the nature of the activity being carried out. Article 61(2) states that "if the expiration of consent is the reason for terminating a contract in which the data subject is a party, the processing of data is lawful until this occurs." The DPA notes that this provision is incongruent, conflating two types of legal basis: consent and contract execution. The contract in which the data subject is a party is sufficient to justify the processing of the data necessary for its execution. Regarding the reasons that led to publish this decision, the Portuguese DPA clarifies that it did so in order to ensure the transparency of its future decision-making processes and, in this regard, contribute to legal certainty and security. It also clarifies that the non-application, in future specific cases, of the legal provisions listed above results in the direct application of the GDPR provisions that were manifestly restricted, contradicted, or compromised in their useful effect.

## Recent developments

### In short:

*Source: Government, 2025-03-24 — https://overview.legal/posts/52206*

Regarding the Data Protection Regulation, it should be noted that: "The Data Protection Authority (AP) is designated as the supervisory body for the section concerning the collection of data by government agencies in situations of exceptional necessity, and for the specific provisions relating to the processing of personal data, as well as for the explanation of audiovisual materials..."

### Kort:

*Source: Government, 2025-03-24 — https://overview.legal/posts/50675 — original: https://www.tweedekamer.nl/kamerstukken/kamervragen/detail?id=2025D10009&amp;did=2025D10009*

inzake de Dataverordening wordt opgemerkt : "De AP wordt aangewezen als toezichthouder voor het onderdeel dat gaat over het opvragen van gegevens door overheidsinstanties in situaties van uitzonderlijke noodzaak en specifieke bepalingen die zien op verwerking van persoonsgegevens en uitleg van AV...

### EU-wetgeving inzake datagovernance definitief vastgesteld

*Source: NL EU Court Expert, 2022-06-08 — https://overview.legal/posts/6302 — original: https://ecer.minbuza.nl/-/eu-wetgeving-inzake-datagovernance-definitief-vastgesteld?redirect=%2Fecer%2Fnieuws%3Fq%3Dprivacy%2520OR%2520avg%26f%3D%26t%3D#entry-303*

The new data governance regulation sets out the conditions for the reuse of certain government data. In addition, the regulation provides a notification and oversight framework for the provision of data mediation services. Furthermore, the regulation contains a framework for the voluntary registration of entities that collect and process data made available for altruistic purposes. The rules will apply from September 2023.

### EU-Hof: een belastingautoriteit die bij een marktaanbieder van  internetdiensten gegevens opvraagt moet de AVG in acht nemen

*Source: NL EU Court Expert, 2022-03-02 — https://overview.legal/posts/6309 — original: https://ecer.minbuza.nl/-/eu-hof-een-belastingautoriteit-die-bij-een-marktaanbieder-van-internetdiensten-gegevens-opvraagt-moet-de-avg-in-acht-nemen?redirect=%2Fecer%2Fnieuws%3Fq%3Dprivacy%2520OR%2520avg%26f%3D%26t%3D#entry-308*

The collection by the tax authority of a Member State of personal data concerning the advertisements for the sale of vehicles placed on the website of an economic operator falls within the material scope of the General Data Protection Regulation (AVG). Thus, that authority will also have to comply with the principles on the processing of personal data laid down in the AVG. However, a tax authority can derogate from the AVG in certain cases, even if the right to derogate is not granted by nationa

### Dirkzwager: ABRvS geeft uitleg aan het AVG-begrip "de instelling, uitoefening of onderbouwing van een rechtsvordering"

*Source: Dirkzwager, 2022-10-05 — https://overview.legal/posts/6332 — original: https://www.dirkzwager.nl/kennis/artikelen/abrvs-geeft-uitleg-aan-het-avg-begrip-de-instelling-uitoefening-of-onderbouwing-van-een-rechtsvordering/#entry-968*

> Privacybescherming is niet absoluut. Dat staat zelfs letterlijk zo in de privacywetgeving. De AVG bevat daarom ook allerlei uitzonderingen. Een van de uitzonderingen die enkele keren terugkomt in de AVG ziet op de verwerking van persoonsgegevens in het kader van "de instelling, uitoefening of onderbouwing van een rechtsvordering". Tot op heden was echter niet heel erg duidelijk wat die woorden nu precies betekenen. Een recente uitspraak van de Afdeling bestuursrechtspraak van de Raad van State

## Literature

### Grounds for Lawful Processing of Personal Data in GDPR and Personal Data Protection Bill 2018, India (PDPB): Section – V: Public Interests amp; Exercise of Official Authority.

*Source: SSRN Electronic Journal, 2019-01-01 — https://overview.legal/posts/132516 — original: https://doi.org/10.2139/ssrn.3743566*

### GDPR Implementation Series ∙ Malta: An Overview of the GDPR Implementation

*Source: European Data Protection Law Review, 2020-01-01 — https://overview.legal/posts/132480 — original: https://doi.org/10.21552/edpl/2020/4/15*

### GDPR Implementation Series ∙ Netherlands: The GDPR Implementation Act

*Source: European Data Protection Law Review, 2018-01-01 — https://overview.legal/posts/132478 — original: https://doi.org/10.21552/edpl/2018/3/15*

### GDPR Implementation Series ∙ Croatia: Minimum Service for the Implementation, Big Service to the Public Sector

*Source: European Data Protection Law Review, 2020-01-01 — https://overview.legal/posts/132520 — original: https://doi.org/10.21552/edpl/2020/2/14*

### GDPR Implementation Series ∙ Portugal: A Brief Overview of the GDPR Implementation

*Source: European Data Protection Law Review, 2019-01-01 — https://overview.legal/posts/132482 — original: https://doi.org/10.21552/edpl/2019/4/12*

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Public Sector** — https://overview.legal/topics/public-sector
  Processing by public authorities
- **Law Enforcement** — https://overview.legal/topics/law-enforcement
  Processing for law enforcement purposes
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing

---
Generated by overview.legal · https://overview.legal/topics/overheid · 2026-08-22
