# Personal Data — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/persoonsgegevens
> Sources are cited per item. Verify against the official texts before relying on them.

Information relating to identified or identifiable natural persons

## Overview

## Legal Framework

Personal data under the GDPR encompasses any information relating to an identified or identifiable natural person, as defined in Article 4(1). The Regulation's material scope, governed by Article 2, extends to the wholly or partly automated processing of such data, as well as non-automated processing within structured filing systems. Article 3 establishes territorial scope: the GDPR applies to controllers established in the Union processing data in the context of that establishment's activities, regardless of whether processing occurs within the EU. An "establishment" requires effective and actual activity through stable arrangements—even minimal activity suffices, including through a commercial agent collecting payments for an internet service. The Regulation also reaches non-EU controllers offering goods or services to, or monitoring, data subjects within the Union.

Article 6 provides the six lawful bases for processing, with consent under Article 6(1)(a) requiring that the data subject exercise genuine, free will—consent is invalid where the subject lacks a real choice or cannot refuse or withdraw without detriment (Recital 42). Separate consent must be obtainable for distinct processing operations. Article 10 imposes stricter conditions for data relating to criminal convictions, permitting processing only under official authority control or via Union/Member State law with appropriate safeguards. Articles 13 and 14 specify transparency obligations when collecting personal data, while Article 34 mandates notifying data subjects of breaches likely to result in high risk.

## Key Developments

The CJEU's judgment in *Data Protection Commissioner v. Facebook Ireland Ltd and Maximillian Schrems* (Schrems II) confirmed that national supervisory authorities bear independent responsibility for verifying whether transfers to third countries comply with GDPR requirements, even where an adequacy decision exists. The Court invalidated the Privacy Shield, emphasizing that protections must be assessed against the reality of third-country government surveillance practices.

In *Google LLC v. CNIL*, the CJEU addressed the territorial reach of de-referencing obligations, holding that while EU law does not currently require global de-referencing, it does not prohibit it either. National authorities retain competence to weigh privacy rights against freedom of information under national fundamental rights standards.

Enforcement actions confirm regulators' focus on security obligations. The Romanian DPA fined SSG SELECT SOLUTIONS €2,000 under Articles 29 and 32 for insufficient technical and organizational measures, and imposed a €5,000 fine on Poșta Română for comparable security deficiencies.

## Practical Guidance

- **Verify establishment nexus carefully**: Assess whether any EU-based activity—even through agents or subsidiaries—constitutes a stable arrangement triggering Article 3 territorial scope, particularly where advertising or payment collection occurs within the Union.

- **Audit consent mechanisms against the freedom requirement**: Ensure consent is granular, separately obtainable for distinct purposes, and revocable without penalty, per Recital 42 and the doctrinal interpretation of Articles 3:33 and 3:35 of the Dutch Civil Code applied by analogy.

- **Apply Article 10 restrictions to criminal records data**: Confirm that any processing of conviction data occurs exclusively under official authority control or pursuant to Member State law providing explicit safeguards; comprehensive conviction registers require official authority oversight.

- **Implement breach notification readiness**: Establish protocols to assess whether a breach is likely to result in high risk to data subjects, triggering Article 34 notification obligations, and prepare communication templates in advance.

- **Monitor emerging regulatory guidance on AI**: The Dutch DPA's July 2026 guidance on generative AI under the GDPR signals increased scrutiny of how AI systems process personal data—assess training data and output generation against Article 6 lawful bases and Article 13 transparency requirements.

## Legislation (full text of key provisions)

### Information to be provided where personal data are collected from the data subject

*Source: GDPR, gdpr-art-13-en, 2016-04-27 — https://overview.legal/posts/90352*

### Processing of personal data relating to criminal convictions and offences

*Source: GDPR, gdpr-art-10-en, 2016-04-27 — https://overview.legal/posts/90322*

Processing of personal data relating to criminal convictions and offences or related security measures based on Article 6(1) shall be carried out only under the control of official authority or when the processing is authorised by Union or Member State law providing for appropriate safeguards for the rights and freedoms of data subjects. Any comprehensive register of criminal convictions shall be kept only under the control of official authority.

### Right of access by the data subject

*Source: GDPR, gdpr-art-15-en, 2016-04-27 — https://overview.legal/posts/90406*

### Processing under the authority of the controller or processor

*Source: GDPR, gdpr-art-29-en, 2016-04-27 — https://overview.legal/posts/90592*

The processor and any person acting under the authority of the controller or of the processor, who has access to personal data, shall not process those data except on instructions from the controller, unless required to do so by Union or Member State law.

### Communication of a personal data breach to the data subject

*Source: GDPR, gdpr-art-34-en, 2016-04-27 — https://overview.legal/posts/90649*

### General principle for transfers

*Source: GDPR, gdpr-art-44-en, 2016-04-27 — https://overview.legal/posts/90853*

Any transfer of personal data which are undergoing processing or are intended for processing after transfer to a third country or to an international organisation shall take place only if, subject to the other provisions of this Regulation, the conditions laid down in this Chapter are complied with by the controller and processor, including for onward transfers of personal data from the third country or an international organisation to another third country or to another international organisation. All provisions in this Chapter shall be applied in order to ensure that the level of protection of natural persons guaranteed by this Regulation is not undermined.

### Right to rectification

*Source: GDPR, gdpr-art-16-en, 2016-04-27 — https://overview.legal/posts/90424*

The data subject shall have the right to obtain from the controller without undue delay the rectification of inaccurate personal data concerning him or her. Taking into account the purposes of the processing, the data subject shall have the right to have incomplete personal data completed, including by means of providing a supplementary statement.

### Principles relating to processing of personal data

*Source: GDPR, gdpr-art-5-en, 2016-04-27 — https://overview.legal/posts/90243*

### Notification obligation regarding rectification or erasure of personal data or restriction of processing

*Source: GDPR, gdpr-art-19-en, 2016-04-27 — https://overview.legal/posts/90457*

The controller shall communicate any rectification or erasure of personal data or restriction of processing carried out in accordance with Article 16, Article 17(1) and Article 18 to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort. The controller shall inform the data subject about those recipients if the data subject requests it.

### Transparent information, communication and modalities for the exercise of the rights of the data subject

*Source: GDPR, gdpr-art-12-en, 2016-04-27 — https://overview.legal/posts/90330*

## Case law

### Council of State: Tax Authority satisfied GDPR access request on FSV fraud registration

*Source: Council of State, 2026-08-05 — https://overview.legal/posts/187482 — original: https://gdprhub.eu/index.php?title=RVS_-_202307578/1/A3*

Facts — The personal data of an individual was stored in the Fraud Detection System (FSV), an application used by the Dutch Tax Authority between 2012 and 2020 to record potential indicators of tax fraud. The Minister of Finance was the controller. The data subject submitted an access request under Article 15 GDPR. In particular, she requested information about the personal data processed, the purposes of the processing, the recipients of the data, its source and retention period, and any automated decision-making concerning her. The controller provided an overview of the personal data stored in the FSV and answered the data subject’s questions. The data subject objected to the decision, claiming that the controller had not disclosed all information relating to her registration. The controller rejected the objection. It explained that the data subject had been selected for a manual review of her tax return under Project 1043, an anti-fraud initiative launched by the Dutch Tax, and was consequently registered in the FSV. It also stated that the data was accessible only to employees of the Tax Authority and had not been disclosed to other organisations. The District Court of Amsterdam dismissed the data subject’s appeal. It held that the proceedings concerned compliance with the GDPR access request and not the lawfulness of her inclusion in the FSV or any alleged resulting damage. The data subject appealed this judgment before the Council of State. Holding — The Council of State dismissed the appeal and upheld the judgment of the District Court. The Court held that there was no evidence that the controller had incorrectly applied Article 15 GDPR. The controller had provided an overview of all personal data concerning the data subject processed in the FSV, explained the purposes of the processing and clarified the circumstances of her registration under Project 1043. Although the data subject suspected that the controller held additional information, she did not provide concrete evidence supporting this claim. The Court also found no indication that she had been classified as a fraudster or that her personal data had been disclosed to other organisations. The Court further clarified that the lawfulness of the data subject’s registration in the FSV, the deletion of her data and any claim for compensation fell outside the scope of the access proceedings. Consequently, the Court confirmed the contested judgment and did not award litigation costs.

### NSS - 1 As 183/2023-62

*Source: Supreme Administrative Court, 2026-08-04 — https://overview.legal/posts/184683 — original: https://gdprhub.eu/index.php?title=NSS_-_1_As_183/2023-62*

Facts — OAKS Consulting s.r.o. (the company) provided consulting services concerning market access conditions for medicinal products and medical devices. Pursuant to the Czech Act on Free Access to Information, it requested information from the General Health Insurance Company of the Czech Republic concerning the treatment of patients with iron deficiency and related conditions for the period from 1 January 2010 to 31 October 2017. The request covered 183 types of diagnoses, 18 types of medical procedures, 96 DRG codes and 13 types of medications. The company stated that it wished to analyse how specific diagnoses were treated, the number of patients treated, and the frequency of related medical procedures, in order to compare clinical practice against the relevant theoretical background. The public health insurer rejected the request on the grounds that granting it would require the creation of new information. Following an appeal by the company, the Prague Municipal Court overturned the decision. The public health insurer provided then the company with five separate tables regarding the diagnoses, diagnoses in conjunction with medical procedures, the DRG codes and prescribed medications. It aggregated the parameters of the provided data as follows: five-year age groups, dates were given only at the monthly level, and healthcare providers were classified into broad geographic regions. However, it refused to add a unique random identifier which would allow linking the individual records and tables pertaining to the same patient. The public health insurer considered that providing the code would result in the disclosure of special categories of personal data. The company lodged a complaint with the Czech DPA (UOOU), which rejected it. The company filed another appeal with the Municipal Court of Prague, which dismissed the appeal. It ruled that the combination of factors such as gender, year of birth, the time and place of care, diagnoses, medications, and medical procedures could, with the addition of other information, lead to the identification of specific patients. According to the court, the random identifier would result in pseudonymisation rather than anonymisation, so the information would remain personal data pursuant to Article 4(1) GDPR. The Municipal Court also relied on modern technical capabilities for linking different sources and on the availability of a large volume of information in the media and on social media. It cited the CJEU’s decision in the Breyer case (C-582/14), according to which in order to determine whether a person is identifiable, account must be taken of all the means that could reasonably be used, both by the controller and by any other person, to identify that person. It did not follow the approach taken by the General Court in Case T-557/20 (SRB v. EDPS), which the company had cited. It ruled that the data were pseudonymised and that the requested information could not be disclosed in its entirety. The company filed a cassation appeal with the Supreme Administrative Court, arguing that the information had been anonymised. It alleged that the addition of a random code with no independent meaning would not alter their anonymous nature. It claimed that the Municipal Court had not explained what specific additional information could be used to identify the patients and had relied on hypothetical scenarios. The company stated that it was objectively impossible to obtain such data through other requests in a detailed and non-aggregated form. It also argued that iron deficiency was not a rare disease, but was associated with a large number of patients and various conditions and that the data had undergone both randomisation and generalisation so the risk of identification was therefore low. Finally, the company emphasized that the tables without the random identifier could not be used effectively for the intended analysis. It further argued that the DPA and the Municipal Court had not adequately balanced the right of access to information against the right to the protection of personal data. The DPA argued that the random identifier constituted personal data when considered in conjunction with the health data to which it would be linked. It stated that the concept of personal data was not limited to information that directly identifies an individual nor did it require that all necessary additional information be held by the same entity. Replacing direct identifiers with a code did not anonymise the data, but made it pseudonymised. Moreover, it argued that certain categories contained a relatively small number of records and that combining them with other data could make it possible to select and identify a specific insured person and their treatment history. It further argued that, even if identifiability was relative, it should be assessed in relation to all potential information applicants and their ability to obtain contextual information. The Supreme Administrative Court stayed the proceedings in the case pending the CJEU’s decision in Case C-413/23 P (EDPS v. SRB). After the judgment was issued, the company argued that whether the data were pseudonymised or anonymised should be assessed in relation to the specific recipient of the data and the means that it could reasonably use. It stated that it did not have any means of re-identification and that only specific and practically available cross-referencing possibilities should be taken into account. Holding — The court relied on Case C-413/23 and noted that pseudonymised data under Article 4(5) GDPR does not automatically constitute personal data in relation to every person. Therefore, it examined whether the company had lawful means that could reasonably be expected to be used to identify the patients directly or indirectly. The court found that the tables, without the random identifier, did not allow for the identification of specific insured individuals. It held that the requested random identifier would link the records from the different tables and allow for the aggregation of information on the diagnoses, medical procedures, hospitalizations, and medications for the same patient during the eight-year period. Certain combinations of these data, along with age group, gender, and region, could be unique and allow for the identification of patients using information from public sources. It pointed out that although iron deficiency was a very common diagnosis and some tables contained a very large number of entries, other categories were not sufficiently generalised. According to the court, in certain cases, such as rare diseases, unusual treatment combinations, or particularly young or old age, knowing even a few details about a person could make it possible to identify the corresponding record. The risk was not negligible, given that information about a person’s age, gender, hospitalization, diagnosis, or treatment could be available in the media or on social media. Consequently, the court held that adding the random identifier, in conjunction with the data already provided, would make the dataset personal data in relation to the company under Article 4(1) GDPR, including health data falling under Article 9 GDPR. The court clarified that classifying the information as personal data was not sufficient in itself to reject the request. It noted that the right of access to the information must also be balanced against patients’ right to privacy through an assessment of suitability, necessity and proportionality. It determined that the decision not to provide the random identifier was appropriate for the protection of privacy, because without it, it was impossible to link the tables and identify individual patients. It was also deemed necessary because the company insisted on receiving that specific code along with the existing tables and there was no other procedure that would constitute a lesser infringement of its right to information. The court also recognized the public interest in accessing information related to the operation of the healthcare system, but ruled that this did not outweigh the need to protect the detailed health data of potentially hundreds of thousands of insured individuals. It concluded that the refusal to provide the code was therefore proportionate. The Supreme Administrative Court therefore upheld the Municipal Court’s ruling, but partially corrected its reasoning regarding the relative nature of identifiability and the need to conduct a proportionality review. It dismissed the appeal.

### CJEU - C‑769/22 - European Commission v Hungary

*Source: GDPRhub, 2026-07-24 — https://overview.legal/posts/158432 — original: https://gdprhub.eu/index.php?title=CJEU_-_C‑769/22_-_European_Commission_v_Hungary*

Facts — The background In 2021 Hungary adopted "Law LXXIX of 2021 adopting stricter measures against persons convicted of paedophilia and amending certain laws for the protection of children" ("the amending law"). The law introduced a number of rules to restrict the access of minors to content portraying or promoting gender identities that do not correspond to the sex assigned at birth, sex reassignment or homosexuality. The law also introduced new rules for access to public documents, requiring public bodies to allow broad access to information about individuals convicted of sexual offences against children. The alleged purpose of the law was to protect minors. In 2021 the Commission sent a formal letter to Hungary contesting the amending law's compliance with EU law. After some unproductive back-and-forth, the Commission escalated the case to the CJEU, requesting the CJEU to declare the amending law incompatible with EU law. The European Commission filed four pleas, claiming that Hungary violated of a long list of provisions from primary and secondary EU law . Only the Commission's fourth plea invokes data protection law- specifically, Article 8(2) of the EU Charter of Fundamental Rights (CFR) ("Protection of personal data") and Article 10 GDPR ("Processing of personal data relating to criminal convictions and offences"). The fourth plea: Article 10 GDPR The alleged violation of the GDPR relates to the amended law's rules on access to information about individuals convicted of sexual offences against children. The law amended the "Law on the criminal record system" and made documents about sexual offences accessible to a broad audience. Under the new rules, any adult who is either a relative or a guardian of a minor ("authorised person"), has the right to access and share information about individuals convicted of sexual offences against children (the data subjects) from bodies with access to registered data. The Commission claimed that the amended law failed to specify with sufficient clarity who is authorised to submit a data request and, therefore, did not provide sufficient guarantees for the rights and freedoms of data subjects regarding the conditions of access to their personal data. On these grounds, the Commission claimed that the amended law infringed Article 10 of the GDPR (as well as Art. 8(2) CFR). In its defense, Hungary argued that the law accurately identified "authorised persons" when read in light of the definition of "relatives" in the Hungarian civil code. Additionally, Hungary claimed that there were two additional criteria access to personal data under Hungarian law: the authorised person must consider the relevant data to be probably necessary, and it must be disproportionately difficult for them to access the subjects' data if they are not disclosed. In other words, Hungary argued that when interpreted correctly, Hungarian law provided for three cumulative criteria for the disclosure of data about convictions for sex offences against children: (i) the disclosure was requested by an authorized person (i.e. "any adult who is either a relative of, or educates, supervises or cares for, a person who has not attained 18 years of age"- where "relative" was to be understood in the well-defined sense of Hungarian civil law); (ii) the disclosure was probably necessary to keep the minor safe; (iii) it was disproportionately difficult for the authorized person to access the data otherwise. Hungary claimed that these criteria were clearly defined and provided sufficient safeguards for data subjects. On this basis, Hungary argued that the amended law complied with Article 10 GDPR and 8(2) CFR. Advocate General Opinion — AG Cápeta clarified that, according to CJEU case law, the GDPR did not impose an absolute ban on the disclosure of personal data from public authorities. The GDPR did, however, require a balancing between the purpose of such disclosures, and the rights and freedoms of data subjects. In particular, the disclosure of personal data regarding criminal convictions, required strict justification and clear legal safeguards, because of the sensitive nature of such data. In the case at hand, the AG conceded that the data disclosure pursued an important public interest (the protection of minors). So, the question was whether the amending law correctly balanced this interest against the right to data protection. The AG opined that the amending law failed to do so and exceeded what was strictly necessary to protect minors, for two reasons. First, the AG agreed with the Commission that the notion of "authorised persons" was too broad and unclearly defined under the amending law, even when the amending law was interpreted in light of domestic civil law. In this regard, the AG pointed to the CJEU case law on the access to personal data from national authorities: in order to satisfy the requirement of proportionality, national law that allowed for such access "must lay down clear and precise rules governing the scope and application of the measure in question and imposing minimum safeguards". The AG further opined that such criteria would also apply to access from private citizens, as in the case at hand. Second, the AG considered that requirements (ii) and (iii) (i.e.: the probable necessity of the disclosure, and the difficulty of otherwise accessing the data) were overly generic and were to be assessed by the authorized person themselves. The AG argued that such a self-declaratoty regime lent itself to abuse and deprived the disclosing body of any control over the necessity and proportionality of the disclosure. For this reason, the AG opined that the amending law failed to provide the required safeguards for data subjects. On these grounds, the AG opined that the amended law was disproportionate and violated Article 10 GDPR as well as Article 8(2) CFR. Holding — The court first noted that one of the objectives of the GDPR is to ensure a high level of protection of data subjects’ fundamental rights and freedoms, in accordance with Article 1 GDPR and Article 8(1) CFR. Therefore, any processing of personal data must be lawful, in accordance with Articles 5(1)(a) and 6(1) GDPR. In addition, any legal basis other than consent (Article 6(1)(a) GDPR) must be interpreted restrictively. The court then assessed whether the processing was lawful under Article 6(1)(e) and 86 GDPR. Article 6(1)(e) GDPR provides for a legal basis based on public interest or in the exercise of official authority vested in the controller. In the case of disclosing this data, Article 86 GDPR states that this may be done to reconcile public access to official documents with the right to the protection of personal data. The court stated that, in principle, the processing of data related to criminal convictions (including its disclosure) could be lawful under Article 6(1)(e) and 10 GDPR. However, Article 10 GDPR makes the processing subject to additional restrictions (for example, the processing must provide for appropriate safeguards). In addition, limits to the fundamental rights to privacy and data protection must respect the essence of the fundamental right and be proportionate, in accordance with Article 52(1) CFR. This is especially relevant in this case, as data related to criminal convictions is particularly sensitive and its processing can be a particularly serious interference with data subjects’ fundamental rights. The court followed the reasoning of the AG in stating that the protection of minors was an important public interest. However, the court considered the amending law incompatible with Article 10 GDPR. The law was not sufficiently precise, particularly in defining the concept of “authorised person”. The court considered that the processing was not limited to what is strictly necessary, as the circle of persons potentially entitled to submit a request was too broad. Finally, the court concurred with the AG, and stated that the amending law was not proportionate. This is because it relied on the person requesting the data to justify the need to access it. Therefore, the amending law did not provide for appropriate safeguards by relying on the self-declaration regarding the necessity and proportionality of accessing the data. The court concluded that the amending law did not meet the requirements under Article 10 GDPR, meaning it could not justify its processing under Article 6(1)(e) GDPR. With this, Hungary had failed to fulfil its obligations under Article 10 GDPR and Article 8(2) CFR.

### Rb. Overijssel: Police access request wrongly assessed under GDPR instead of Wpg

*Source: District Court Overijssel, 2026-07-24 — https://overview.legal/posts/187481 — original: https://gdprhub.eu/index.php?title=Rb._Overijssel_-_ZWO_25/2142*

Facts — On 5 January 2025, the data subject submitted an access request to the Chief of Police, the controller, concerning her personal data for the period between 1 January 2016 and 31 December 2017. In particular, she requested information about searches carried out using her Citizen Service Number in a Basic Register of Persons. On 10 February 2025, the controller extended the deadline for deciding on the request by eight weeks. Since the controller considered it unclear whether the request had been submitted under Article 15 GDPR or Article 25 of the Police Data Act (Wet politiegegevens (Wpg)), it contacted the data subject by telephone. On 14 April 2025, the controller assessed the request under Article 15 GDPR and rejected it on the ground that it had not processed the data subject’s personal data during the relevant period. The data subject lodged an objection against this decision. On 13 June 2025, the controller rejected the objection and upheld its initial decision. Since the decision did not contain information on the available legal remedies, the controller sent it again on 18 June 2025 with the relevant appeal clause. On 29 July 2025, the data subject appealed to the District Court of Overijssel. She argued that the controller should have understood from the content and context of her request that it had been submitted under Article 25 Wpg rather than Article 15 GDPR. In particular, the request referred to an earlier access request that the controller had processed under the Wpg. Holding — The Court held that the controller should have assessed the access request under Article 25 Wpg rather than Article 15 GDPR. The content and context of a request determine its legal classification, irrespective of the legal basis identified by the applicant. The request referred to an earlier request processed under the Wpg and sought a similar overview for a different period. Moreover, the Wpg constitutes the specific legal framework applicable to personal data processed by the police for public-security purposes and therefore takes precedence over the GDPR. The Court declared the appeal well-founded and annulled the contested decision. Since decisions under Article 25 Wpg are not subject to an administrative objection procedure, it ordered the controller to issue a new primary decision under the Wpg. No fine was imposed.

### CJEU - C‑474/24 - NADA Austria and Others

*Source: GDPRhub, 2026-07-24 — https://overview.legal/posts/108989 — original: https://gdprhub.eu/index.php?title=CJEU_-_C‑474/24_-_NADA_Austria_and_Others*

Facts — Several data subjects were subject to suspension proceedings by the Austrian Anti-Doping Legal Commission (ÖADR). Under Austrian law, the National Anti-Doping Agency (“NADA”) publishes the names of persons who have been suspended on its website. For the duration of the suspension, the website includes information such as the athlete’s name, sport practised, infringement of anti-doping rules, and the duration of the penalty. The ÖADR publishes the same information in a press release, with the addition of the prohibited substances involved. For this summary, both authorities are referred to as the controllers. The data subjects filed a complaint with the DPA on the grounds that the controllers refused their request to cease displaying their names and practised sports. They also argued that the controllers were processing sensitive data within the meaning of Article 9 and 10 GDPR, and that the undifferentiated publication system was incompatible with Article 6(3) GDPR. The DPA dismissed the complaint. In particular, one of the data subjects’ complaints was rejected on the grounds that the relevant data had not been published yet. The data subjects appealed the decision to the Federal Administrative Court (BVwG). The controllers argued that publishing the information in their website was lawful, as it was based on the legal bases of legal obligation (Article 6(1)(c) GDPR) and public interest (Article 6(1)(e) GDPR). The BVwG stayed proceedings and requested a preliminary ruling from the CJEU. The BVwG referred the following questions: Does the GDPR apply to the making information relating to athletes’ anti-doping violations publicly available through websites? If yes: Does information that an individual has committed a specific anti-doping violation fall under the scope of data relating to health within the meaning of Article 9 GDPR? Does the GDPR preclude national legislation from publishing the information mentioned above, if it does not make it possible to infer health data of the person concerned? Does the GDPR require a balancing test between the interests of the data subject and the interest of the general public of being informed of anti-doping violations every time anti-doping violations will be published? Does information that an individual has committed a specific anti-doping violation fall under the scope of data relating to criminal convictions within the meaning of Article 10 GDPR? If yes, must the decisions of the authority processing this data be subject to judicial review? Is filing a complaint before the processing takes place (but was processed during the proceedings) permissible? Or does it become permissible provided that at the time of the complaint there were specific indications that the processing was imminent or would take place in the near future? Advocate General Opinion — The AG gave his opinion on each question separately, with the exception of the third and fourth questions that were answered together. Question 1: Does the GDPR apply to the making information relating to athletes’ anti-doping violations publicly available through websites? — The AG first considered that the GDPR was applicable to this case. Under Article 2(2)(d) GDPR a situation falls outside of the scope of the GDPR when data is processed for the prevention, detection or prosecution of criminal offenses. This is because the Law Enforcement Directive (LED) applies. According to the AG, the GDPR may apply even if personal data relating to criminal convictions is processed if the controllers are not “competent authorities” within the meaning of Article 3(7) LED. If the controllers were competent authorities, the referring court would have to decide if the GDPR applies. The main question the AG addressed is whether the exception under Article 2(2)(a) GDPR applies, meaning the processing falls outside the scope of Union law; here, the AG noted that the exceptions are interpreted narrowly, and may only apply to activities intended to safeguard national security or activities classified in the same category. The AG concluded that the aim of combating anti-doping is not related to national security. The exception did not apply even if the activity fell under the competence of a Member State. Therefore, the GDPR was applicable. Question 2: Does information that an individual has committed a specific anti-doping violation fall under the scope of data relating to health within the meaning of Article 9 GDPR? — The AG first highlighted the sensitive nature of Article 9 GDPR data, which must be interpreted broadly. The AG also noted that the legal basis of the controller does not influence whether the data falls under the scope of health data. Beyond a medical context, the AG opined that the determining factor is whether it is possible to draw inferences about the health status of the data subject. In this case, the AG agreed with the reasoning of the DPA that only specific information relating to the infringements should be considered health data. This is because not all data revealed information related to the data subjects’ health. Specifically, the information regarding the anti-doping tests and its analysis should be considered health data. The AG noted that, while the name of the substance itself may not reveal information on health status, it may be possible to make indirect inferences. However, if the name is not included, the link to the health status of the data subject would be too indirect to fall under the scope of health data. Questions 5 and 6: Does information that an individual has committed a specific anti-doping violation fall under the scope of data relating to criminal convictions within the meaning of Article 10 GDPR, and must the decisions of the authority processing this data be subject to judicial review? — The AG first noted that the GDPR does not prohibit processing this data, but rather subjects it to enhanced scrutiny. The AG assessed whether the processing fell under the scope of Article 10 GDPR based on the three “Engel” criteria in ECtHR case Engel and Others v. the Netherlands. Anti-doping offenses under national law do not fall under the “criminal” classification according to Article 10 GDPR. However, the AG opined that article 10 GDPR applies if the convictions have a punitive purpose and have a degree of severity equivalent to a criminal penalty. This is a matter for the BVwG to decide. In terms of judicial review, the AG stated that the authority at issue is an “official authority” within the meaning of Article 10 GDPR. The wording itself of Article 10 GDPR does not provide for judicial review. However, the AG opined that it must be possible for an act following a decision by an official authority to be subject to judicial review. This is in light of Article 79(1) GDPR and a contextual interpretation of Article 10 GDPR. Questions 3 and 4: Does the GDPR preclude national legislation from publishing the information mentioned in the facts, and does it require a balancing test every time anti-doping violations will be published? — The AG considered, in essence, whether Articles 5(1)(a) and (c), and Article 6(3) GDPR precluded the controllers to publish the data concerned under legal obligation. The AG also considered whether the GDPR requires a case-by-case balancing of interests, or whether the proportionality test provided by the legislator is sufficient. The AG noted that the aim to deter athletes and prevent circumventing of anti-doping rules are legitimate public interest objectives in the context of combating doping in sport. Making this information public online is appropriate in order to achieve the public interest aims, with the exception of referring to the prohibited substance in question. According to the AG, this was not expressly provided for by national law, and is not required to achieve the public interests involved. However, the AG considered the publication of the personal data involved a serious interference with the fundamental rights of the data subjects. While national law provided exceptions on the publication of data (e.g. amateur athletes or vulnerable persons), the AG opined that the publication of personal data for an unlimited amount of time could be considered excessive. Therefore, the AG concluded that making this information publicly accessible is only permitted as long as it is proportionate. Finally, the AG opined that a case-by-case analysis is necessary, as the controllers must comply with data minimisation and accountability principles under the GDPR even if they are designated by national law. Question 7: Is filing a complaint before the processing takes place permissible? — Here, the AG stated that the wording of the GDPR does not seem to preclude a priori a precautionary or preventative approach by the supervisory authorities in handling complaints. Restricting the powers of a DPA to decide on cases involving processing that has already taken place would go against the objectives of the GDPR. Nonetheless, the alleged infringement of the GDPR must be appropriate, and the processing in question cannot be purely hypothetical. In this case, it would be impossible for a controller to erase data that has not been disclosed yet, unless the complaint is interpreted as seeking to prevent the data from being published. The AG stated that it is a matter for the BVwG to decide. The AG noted that the complaint would be inadmissible if it was based on Article 17 GDPR even if the processing is imminent. However, the AG opined that a complaint requesting injunctive relief is potentially admissible under the GDPR and Austrian law in the event of a threat of imminent unlawful interference with data subjects’ rights under the GDPR. This includes requesting the DPA to review a restriction of processing based on Article 18 GDPR before the start of the processing or if the processing has started, as long as the processing is not purely hypothetical. Finally, the AG considered whether a complaint could become admissible a posteriori. Here, the AG opined that it is a matter of the national law system to settle the question, while complying with the principles of effectiveness and equivalence. Holding — The Court held that the GDPR applied to the publication of information concerning anti-doping infringements. Such processing did not fall within the exception under Article 2(2)(a) GDPR, even if anti-doping policy primarily falls within Member State competence. Information that a data subject infringed anti-doping rules and was banned from competitions does not, in principle, constitute health data under Article 9 GDPR. However, it may do so where the publication identifies a prohibited substance or method and, together with other information, allows conclusions to be drawn about the data subject’s health. The Court accepted that combating doping and protecting the fairness and integrity of sport constitute objectives of general interest. Nevertheless, publishing athletes’ identities and sanctions online constitutes a serious interference with their rights. National legislation may therefore require such publication only where the controller can assess, in each case, whether the content and duration of the publication are necessary and proportionate. Publication should not continue longer than strictly necessary and may be disproportionate where a sanction is lengthy or lifelong. The Court also held that Article 10 GDPR did not apply, as the anti-doping infringements formed part of a disciplinary regime and were not criminal in nature. Finally, Article 77 GDPR allows a data subject to lodge a complaint before processing takes place where there are specific indications that the processing is imminent and not merely hypothetical. The DPA must assess the substance of such a preventive complaint.

### EWCA - Dawson-Damer v Taylor Wessing LLP

*Source: EWCA, 2026-07-17 — https://overview.legal/posts/125652 — original: https://gdprhub.eu/index.php?title=EWCA_-_Dawson-Damer_v_Taylor_Wessing_LLP*

Facts — This case concerns a data subject access request (SAR) under the Data Protection Act (DPA) 1998. The data subjects were beneficiaries under a trust. The data controller was a firm of solicitors, holding trust money as trustees. Following the appointment of further trustees and transfer of trust money into a new trust for other discretionary beneficiaries, the data subjects challenged the validity of these appointments and served the data controller with a SAR under section 7(2) DPA 1998. The data controller refused to make the disclosure, stating that the personal data was covered by Legal Professional Privilege (LPP), and therefore exempted from disclosure under Schedule 7 para. 10 DPA 1998. Furthermore, the data controller asserted that the supply of information required a disproportionate effort. The data subjects contended that many categories of personal data held by the data controller were not privileged and that, if any, the only privilege on which the data controller could rely was litigation privilege. The data subjects applied to the court for a declaration under section 7(9) DPA 1998 that the data controller had not complied with the request and to oblige the data controller to comply with the SAR. At trial, the court agreed with the data controller and refused to make such an order. The appellate court had to determine: whether, taking a narrow view, the LLP exception is limited to documents subject only to legal professional privilege under English law; whether, if the narrow view is correct, any further search would involve "disproportionate effort" for the purposes of section 8(2) DPA 1998 so that the data controller is excused from doing so; whether the exercise of the court’s discretion under section 7(9) DPA 1998 can be refused because the data subject's real motive was to use the information in legal proceedings against the data controller. Holding — The Court of Appeal held that 'privilege' in the LLP exception is limited to legal professional privilege. It falls to the data controller to show that the supply of a copy of the information in permanent form would involve disproportionate effort. The High Court judge was wrong not to exercise its discretion under section 7(9) DPA 1998 to order the data controller to comply with the request. On Issue 1 - Extent of the Legal Professional Privilege Exception: The purpose of Directive 95/46/EC (the Directive) was to regulate the activities of data controllers on a territorial basis. Therefore, the words "legal proceedings" in sched. 7 para. 10 DPA 1998 refer to legal proceedings in any part of the UK. If Parliament had intended to legislate for events which occur outside the territory of the UK, it would have introduced provisions specifying which parts of the world were relevant for this purpose and under which conditions the privilege applied. The LPP exception is expressly limited to legal professional privilege. Documents not disclosable to a beneficiary of a trust under trust law principles are not within the LPP exception. Insofar as the exception was interpreted purposively as also including documents covered by the trustees' right of non-disclosure, the Directive would have to name appropriate objectives which could support an interpretation along these lines. However, the DPA does not contain such exceptions. The court concluded at para. 45 that the LPP exception “relieves the data controller from complying with a SAR only if there is relevant privilege according to the law of any part of the UK.” Since the data in question is not covered by the LPP under English law and no other exemption under the DPA 1998 applies, the SAR must be granted. On Issue 2 - Whether compliance with the request would involve disproportionate effort: The public interest reasons set out in the Directive for giving people control over the data held about them require that SARs should be enforced so far as possible. Under section 8(2) DPA 1998 the data controller is obliged to supply copies of information constituting personal information to the data subject, "unless …the supply of such a copy is not possible or would involve disproportionate effort." The effort, the data controller undertakes must be weighed in a proportionality exercise against the potential benefits that the provision of the information could bring to the data subject. That includes the possibility that there may be limits to a search in certain circumstances, see Ezsias v Welsh Ministers [2007] EWHC B15 (QB). The court held at para. 75 ff, that “It falls to the data controller to show that the supply of a copy of the information in permanent form would involve disproportionate effort”. However, “disproportionate effort must involve more than an assertion that it is too difficult to search through voluminous papers”. The data controller “must produce evidence to show what it has done to identify the material and to work out a plan of action.” On Issue 3 - Whether the request can be declined because the data subject intended to use the information against the data controller: The purpose of the Directive is to protect fundamental rights conferred by EU law. The court found that nothing in Directive or the DPA 1998 limits the purpose for which data subjects may request their data or allows data controllers not to provide data based solely on the on the basis of the purpose of the data subject. Also, Parliament has not expressly required data subjects to show that they have no other purpose. The court distinguished Dunn v Durham County Council [2003] 1 WLR 2305, Lin & Anor v Commissioner of Police of the Metropolis [2015] EWHC 2484 and Kololo v Metropolitan Police Commissioner [2015] 1 WLR 3702. Durant v Financial Services Authority [2004] FSR 573 at para. 27 also does not establish a “no other purpose rule” and should only be interpreted to mean that “a person could not claim that something was personal data because it would assist him in obtaining discovery or in litigation or complaints against third parties.” (para. 111) The court found that the trial judge had wrongly refused to enforce the request just because the appellants intended to use the information obtained in other proceedings. The section 7(9) DPA 1998 discretion must be applied with a view to fulfilling the purposes of the DPA.

### AG - C-78/18 - Commission v Hungary (Transparency of associations)

*Source: GDPRhub, C-78/18, 2026-07-17 — https://overview.legal/posts/125593 — original: https://gdprhub.eu/index.php?title=AG_-_C-78/18_-_Commission_v_Hungary_(Transparency_of_associations)*

In Commission v. Hungary (C-78/18), the European Commission challenged Hungary's 2017 transparency law requiring civil society organizations receiving foreign donations above a threshold to register, label their publications, and publicly disclose donor identities and amounts. The Court of Justice ruled that Hungary breached Articles 63 TFEU and 7, 8, and 12 of the Charter by imposing discriminatory and unjustified restrictions on free movement of capital and unjustified interferences with the rights to private life, personal data protection, and freedom of association. No fine was imposed as this was a failure-to-fulfil-obligations ruling.

### TSJ PV: Accidental Teams recordings after meetings ended cannot justify trust-based

*Source: High Court of Justice of the Basque Country, 2026-07-17 — https://overview.legal/posts/53074 — original: https://gdprhub.eu/index.php?title=TSJ_PV_-_1713/2026*

Facts — The data subject had worked for Fineco Sociedad de Valores, SA and GIIC Fineco Sociedad Gestora de Instituciones de Inversión Colectiva, SAU, the controller, since 2004. The data subject held a senior position and was presented externally as responsible for fixed income management. In May and June 2024, several work meetings took place via Microsoft Teams. After some of these meetings had ended, one participant failed to deactivate Teams correctly. As a result, the system continued recording for several hours conversations which no longer formed part of any professional meeting. The conversations involved the data subject, the former CEO and another board member. The participants were unaware that they were still being recorded. During the conversations, they discussed, among other matters, possible strategies connected to substantial changes in working conditions and compensation. The recordings were automatically stored in the company’s Teams environment. Months later, the new management accessed the recordings. In January 2025, the controller held a meeting with the data subject and referred to extracts of the recordings, stating that their content had affected the trust placed in her. The data subject questioned the legality of the recordings. The data subject brought a labour claim seeking judicial termination of her employment contract for serious breach by the controller. She argued that the controller had accessed and used private conversations obtained without her knowledge or consent, thereby infringing her rights to privacy, secrecy of communications and personal data protection. The Social Court No. 9 of Bilbao dismissed the claim. It considered the recordings admissible as evidence, rejected the alleged violation of fundamental rights and imposed a €4,500 penalty on the data subject for bad faith and procedural recklessness. The data subject appealed before the Court. Holding — The Court partially upheld the appeal. The Court departed from the first instance court’s reasoning on the key issue of admissibility. The first instance court had held that the recordings were admissible because they had been generated after another participant failed to deactivate Teams. By contrast, the Court held that this mistake could not remove the data subject’s reasonable expectation of privacy. The Court found that the data subject had not been informed that Teams continued recording after the meetings had ended, had not consented to it and had not caused the technical error. The conversations took place after the professional meetings had ended and the participants believed that they were speaking privately. The controller had not shown any prior policy or information allowing it to access and use such recordings for employment purposes. The Court therefore held that the controller infringed the data subject’s rights to privacy and secrecy of communications under Articles 18.1 and 18.3 of the Spanish Constitution, read together with Article 18.4 of the Spanish Constitution, Article 8 ECHR and Article 7 CFR and Article 8 CFR . It also relied on Articles 87, 88 and 89 LOPDGDD and the Workers’ Statute rules on digital rights at work, which require prior information, proportionality and respect for workers’ privacy. The Court clarified that the relevant breach was not merely the accidental creation of the recordings, but the controller’s subsequent access to and use of them in the employment relationship. The recordings could not be used as evidence against the data subject because they had been obtained and used in breach of fundamental rights. However, this did not prevent the Court from assessing the controller’s own conduct, namely that it had accessed the recordings and relied on them in the meeting with the data subject. On that basis, the Court found a serious breach by the controller and granted the data subject’s request to terminate the employment contract for cause under Article 50.1(c) of the Spanish Workers’ Statute. It ordered the controller to pay €328,491.62 as statutory compensation for the termination of the employment relationship. The Court also awarded €7,501 as compensation for moral damages caused by the violation of the data subject’s fundamental rights. It did not award the €100,000 requested by the data subject, considering that the initial recording was accidental and that the controller had not installed a deliberate surveillance system. No administrative fine or GDPR corrective measure was imposed, as this was a labour court case rather than a DPA enforcement procedure.

### Spanish court reviews DPA decision on KFC Spain website privacy information and DPO

*Source: National Court, 2026-07-16 — https://overview.legal/posts/184690 — original: https://gdprhub.eu/index.php?title=AN_-_SAN_3154/2026*

Facts — In May 2021, a data subject lodged a complaint with the DPA against KFC Restaurants Spain, S.L.U., the controller, concerning the processing of personal data through its website. The data subject claimed that the privacy information applicable to users in the EEA was not easily accessible, as the main privacy link led to a global policy. The data subject also alleged that users could not create an account without apparently accepting promotional communications, that the registration form did not correctly link to the privacy policy and that the controller had not appointed a data protection officer. The complaint further identified deficiencies in the privacy information, including insufficient details about the identity of the controller, recipients, international transfers and retention periods. During the investigation, the controller acknowledged that certain links and checkbox descriptions had been incorrectly configured and undertook to correct them. It maintained, however, that its privacy information was provided through several interconnected documents and that it was not required to appoint a DPO. According to the controller, it did not engage in profiling, its marketing communications were based on opt-in consent and the processing of personal data was ancillary to its restaurant business. The DPA found that the information provided on the website was excessively generic and did not comply with Article 13 GDPR. It imposed a €5,000 fine and ordered the controller to bring its website into compliance. The DPA also concluded that the controller’s processing activities required the appointment of a DPO under Article 37(1)(b) GDPR. It imposed a further €20,000 fine and ordered the controller to appoint a DPO. The controller appealed both the sanctioning decision and a subsequent resolution requiring it to demonstrate that it had implemented corrective measures. Holding — The Court dismissed the appeal and upheld the total fine of €25,000. Regarding Article 13 GDPR, the Court found that the controller’s privacy information was excessively generic and did not clearly explain the purposes, legal bases and relevant circumstances of the processing. It also held that the DPA was not limited to investigating only the exact issues identified in the initial complaint. The €5,000 fine was proportionate despite the controller’s subsequent corrective action. Regarding Article 37(1)(b) GDPR, the Court held that the controller was required to appoint a DPO. Although its primary business was the provision of restaurant services, the processing of customer data was inseparable from its online ordering, marketing, loyalty and customer-management activities. The processing also involved regular and systematic monitoring, as the controller continuously collected data such as customer preferences, browsing history, IP addresses, cookies and geolocation for commercial and operational purposes. Considering the number of data subjects, the volume and variety of data, the duration of the processing and its nationwide scope, the Court concluded that the processing was carried out on a large scale.

### CJEU - C‑209/23 - RRC Sports

*Source: GDPRhub, 2026-07-16 — https://overview.legal/posts/144028 — original: https://gdprhub.eu/index.php?title=CJEU_-_C‑209/23_-_RRC_Sports*

Facts — Fédération internationale de football association (FIFA) is a Switzerland-based non-profit that acts as the global governing body for football. A large number of football clubs and national football associations are member of FIFA and bound by its regulations. In January FIFA published the FIFA Football Agent Regulations (FFAR). FFAR regulated the conduct of player’s agents. In particular, FFAR provided maximum limits to agents’ remuneration and prohibited specific types of contractual arrangements between clubs, agents, and agencies. In order to ensure compliance with these rules, Article 12 FFAR required agents to disclose certain information to FIFA. In particular, agents had to disclose: Information about any agreement with a client, other than a representation agreement; Information on any arrangement between agents to cooperate in the provision of their services, or to share the revenue or profits of their services; Information about their relationship with agencies, including the names of all of the agency’s employees. Additionally, FIFA would make the information available to a number of stakeholders including agents, players, and football clubs. Three applicants (an agent, a company acting as a players’ agent, and the Vice-President of a players’ agents’ associations) challenged FFAR in the Regional Court of Mainz (Germany). The Court referred four questions to the CJEU for a preliminary ruling. In essence, the Court asked the CJEU whether the FFAR was compatible with Articles 101 TFEU (prohibition on cartels), 102 TFEU (prohibition on abuse of a dominant position), 56 TFEU (freedom to provide services), and 6 GDPR (legal bases for processing personal data). With regards to Article 6 GDPR specifically, the referring court essentially asked whether there was a lawful basis under the GDPR for a collection of personal data, such as required under the FFAR’s mandatory disclosure rules. Advocate General Opinion — The referring question did not specify what legal basis had to be examined in order to assess the compatibility of FFAR disclosures with the GDPR. However, the AG opined that interest under Article 6(1)(f) was the relevant legal basis, based on the nature of the FFAR rules and on other information on the order for reference. Therefore, the AG focused on the legal basis of legitimate interest exclusively. The AG recalled that the mandatory disclosure under FFAR were compatible with the GDPR if they met three cumulative requirements: They genuinely pursued an interest worthy of protection; They were limited to what was strictly necessary to that end; They did not place an intolerable burden on the data subjects as regards their right to privacy and their financial interests. The AG opined that in the case at hand, the processing of personal data pursued an interest worthy of protection (that is, FIFA’s interest in ensuring that the conduct of agents was consistent with the core objective of the football transfer systems, and other objectives related to the good functioning of the player market). However, the AG was more cautious about the other two requirements. With regards to the requirement of necessity, the AG noted that FFAR required the collection of a substantial amount of personal data, including delicate data about agents’ remuneration and contractual agreements. Additionally, FIFA would not only receive the data but also make it available to stakeholders such as clubs, players, and player’s agents. The AG opined that such a broad collection and disclosure of personal data could, to some extent, exceed what was strictly necessary to pursue FIFA’s legitimate interest. In that regard, the AG stressed that FIFA should explain to the referring court why the collection and disclosure of the data were necessary, in relation to each type of information. With regards to the balancing of interests, the AG opined that agents operate within a regulatory framework and, therefore, have a reasonable expectation that FIFA would process their data as a regulatory body. In the AG’s view, this expectation could weight favorably on the balancing of legitimate interest. At the same time, the AG opined that the availability of agents’ personal data to both competitors and potential clients, could financially harm agents and erode trust in agent-client relationships. Holding — The CJEU held that processing based on Article 6(1)(f) GDPR is lawful only where three cumulative conditions are met. First, the controller or a third party must pursue a legitimate interest. Second, the processing must be necessary for that interest. Third, the interests or fundamental rights and freedoms of the data subject must not override the legitimate interest pursued. Regarding the information agents were required to submit through the controller’s digital platform under Article 16 FFAR, the Court considered that ensuring compliance with the regulatory framework governing football agents could constitute a legitimate interest. This was conditional on the underlying obligations being compatible with EU and national law. The Court found that the information required under Article 16 FFAR appeared capable of identifying attempts to circumvent rules on representation, remuneration and conflicts of interest. The processing could therefore be adequate, relevant and limited to what was necessary. However, the referring court had to determine whether equally effective but less intrusive measures were available and assess any additional information requested through the platform whose precise scope was not defined in the regulations. The processing under Article 16 FFAR could therefore be compatible with Article 6(1)(f) GDPR, subject to verification by the referring court. Regarding Article 19 FFAR, the Court distinguished between the different categories of information disclosed by the controller. The publication of agents’ names and contact details, the identity of their clients, the duration and exclusivity of representation agreements and the services provided could pursue legitimate interests such as establishing professional and ethical standards, protecting clients from unethical conduct and improving transparency. Since the information concerned professional activities within a regulatory framework known to the persons involved, this processing could satisfy the balancing test under Article 6(1)(f) GDPR. By contrast, publishing detailed information about every transaction involving an agent, including the service fees paid, was not limited sufficiently. The Court held that agents and clients did not need access to detailed information about all transactions involving their competitors to comply with the regulations. The indiscriminate disclosure of this information therefore infringed the data minimisation principle under Article 5(1)(c) GDPR and was not necessary under Article 6(1)(f) GDPR. The Court also examined the publication of sanctions imposed on agents and clients. It accepted that publication could, in certain circumstances, deter misconduct, restore confidence in the market and allow persons harmed by an infringement to become aware of it. Nevertheless, Article 19 FFAR required the publication of every sanction without considering its seriousness, the harm caused, its relevance to market confidence or the time elapsed since the infringement. The regulation also did not provide for the information to cease being available after a defined period. The blanket publication obligation therefore did not appropriately balance the controller’s interests against the data subjects’ rights under Articles 7 and 8 CFR. Moreover, where a sanction contained personal data relating to criminal convictions or offences, Article 10 GDPR applied. In the absence of authorisation under EU or Member State law and supervision by a public authority, the controller could not process such data. The Court consequently held that Article 6(1)(f) GDPR precluded regulations adopted by an international sports federation insofar as they required the disclosure and publication of: every sanction imposed on agents or their clients; and detailed information concerning all transactions involving agents. The Court did not impose a fine or order any specific corrective measure. It provided an interpretation of EU law for the referring court, which remained responsible for resolving the underlying dispute and verifying the relevant factual and legal conditions.

### CJEU - C-673/17 - Planet49

*Source: GDPRhub, 2026-07-16 — https://overview.legal/posts/122861 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-673/17_-_Planet49*

Facts — A German company called Planet49 organized an online lottery hosted on their webpage. In order to participate in the lottery the participant had to enter a name and an address. Underneath the input field there were two checkboxes. The first checkbox required the user to accept being contacted by firms for promotional offers. The second checkbox required the user to consent to cookies being installed on the participants computer. The first checkbox was not pre-ticked, while the second checkbox was. To participate in the lottery the user had to tick, at least, the first checkbox. The Federation of German Consumer Organisations (the “Bundesverband”) initated court proceedings against Planet49, claiming that the declaration of consent did not meet the requirements for a freely given and informed consent. The case reached the Federal Court of Justice (“Bundesgerichtshof”), which referred questions regarding the scope of consent under provisions of the Data Protection Directive 95/46/EC, the ePrivacy Directive 2002/58/EC, and the GDPR to the CJEU. The case was referred to the Court of Justice on 5 October 2017 - before the GDPR became applicable on 25 May 2018. As the Bundesverband sought an injunction to prevent Planet49 from continuing its practices in the future, the Court’s decision takes into account the requirements for consent on the basis of both the Directive 95/46/EC and the GDPR. The decision of the Court — The Court assessed the requirements for a valid consent under both Directive 95/46/EC and the GDPR and found that there were no substantial differences between them, noting however that the GDPR explicitly states requirements that need to be inferred under Directive 95/46/EC. As the Court notes, the notion of consent under the ePrivacy directive should have the same meaning as consent under Directive 95/46/EC and the GDPR. Consent — A key question posed by the referring court in relation to the consent requirement was whether consent could be “passive” or if it had to be “active”. The Court concluded that a key component of a valid consent is that the consent is given by a clear affirmative act. Requiring the user to untick a box to “opt-out” is not sufficient. The Court emphasized that inaction is insufficient to establish whether the consent is a “freely given and informed decision”. The Court concludes on this basis that Planet 49’s consent model was inadequate with regards to securing a compliant consent to place cookies on the user’s device. The Court’s conclusion follows from reading Article 5(3) of the ePrivacy directive in conjunction with Article 2(h) of Directive 95/46/EC, and noting that active consent is now regulated under GDPR. For the consent to be valid, it must be “given” on the basis of “clear and comprehensive information” communicated to the user. The requirement for the information to be “clear and comprehensive” implies that in cases where the cookie aim to collect information for advertising purposes, there should be information about “the duration of the operation of cookies and whether or not third parties may have access to those cookies”. Worth noting here is that the Court explicitly referred to Article 13 GDPR and Article 10 Directive 95/46/EC as the relevant framework for determining which information should be provided to the user. The ePrivacy directive and GDPR — The German law transposing the ePrivacy directive establishes a difference between the collection of “personal data” and other data. The Court referenced the earlier opinion of the AG, noting that the AG correctly interpreted the provision to protect the user from any privacy interference, irrespective of whether that interference concerns personal data or other data. The obligation to secure a valid consent for the placement of cookies is therefore applicable regardless of the legal status of that information. A consequence of this view is that the German incorporation of directive 2002/58 is not fully in line with the directive. It is worth highlighting that Article 5(3) of the ePrivacy directive carves out an exception for the consent requirement for cookies that are “strictly necessary” to provide the service as requested by the user. In broad strokes, this means that so-called “functional cookies” that are essential for browsing and using the website, typically for holding items in the cart while browsing a web shop, are exempt for the consent requirement (most often first-party session cookies).

### CA - EWCA Civ 899 Vince v. Associated Newspapers Limited

*Source: Court of Appeal, 2026-07-15 — https://overview.legal/posts/144030 — original: https://gdprhub.eu/index.php?title=CA_-_EWCA_Civ_899_Vince_v._Associated_Newspapers_Limited*

Facts — Associated Newspapers Limited, the controller, published print and online articles in the Daily Mail and Mail+ on 8 and 9 June 2023 concerning a data subject. The articles were published under the headline "Labour repays £100,000 to 'sex harassment' donor" and featured two photographs of the data subject immediately beneath the headline. The article explained that the Labour donor accused of sexual harassment was another person, not the data subject. However, the data subject argued that the juxtaposition of the headline and his photographs created the misleading impression that he was the person referred to in the headline. The photographs were later removed from the online version of the article, but remained in the print edition. The data subject first brought defamation proceedings against the controller. The High Court struck out the claim, holding that a libel claim must be assessed by reference to the publication as a whole and that the article made clear that the allegations concerned another person. The data subject also complained to the Independent Press Standards Organisation, which rejected the complaint. The data subject subsequently brought a claim under Article 5(1)(a) and Article 82 UK GDPR, alleging that the controller had processed his personal data unfairly by juxtaposing his photographs with the headline. The High Court struck out the claim as an abuse of process and, in any event, granted summary judgement in favour of the controller, holding that the personal data had been processed fairly when the publication was considered as a whole. The data subject appealed both findings. Holding — The Court allowed the appeal. It held that the High Court had erred in striking out the claim as an abuse of process and in granting summary judgement in favour of the controller. Instead, it dismissed the application to strike out the claim and granted summary judgement to the data subject on liability, with damages to be assessed. The Court held that the controller had processed the data subject's personal data unfairly in breach of Article 5(1)(a) UK GDPR. It found that the juxtaposition of the headline referring to a "sex harassment donor" with photographs of the data subject was misleading and likely to lead readers to believe that the headline referred to him. Although the body of the article clarified that another individual was the subject of the allegations, many readers would only see the headline and photographs. The Court rejected the controller's argument that the fairness of the processing should be assessed by applying the common law principle that publications must be read as a whole. It held that this principle did not determine whether processing was fair under Article 5(1)(a) UK GDPR. Instead, fairness had to be assessed in light of the context of the processing. In reaching its conclusion, the Court relied on the Editors' Code of Practice, which requires newspapers to take care not to publish misleading information or images, including headlines not supported by the text. It found that the controller had failed to take adequate care to avoid publishing misleading information and could not rely on the journalism exemption under the Data Protection Act 2018. Finally, the Court held that, as the controller had accepted that the data subject had suffered material damage, the data subject was entitled to summary judgement under Article 82 UK GDPR, with damages to be assessed.

## Guidance

### EDPB-EDPS Joint Opinion 2/2022 on the Proposal of the European Parliament and of the Council on harmonised rules on fair access to and use of data (Data Act)

*Source: EDPB, edpb-edps-joint-opinion-22022-on-the-proposal-of-the-european-en, 2022-05-04 — https://overview.legal/posts/125945 — original: https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-22022-on-the-proposal-of-the-european_en*

1 Adopted EDPB - EDP S Joint Opinion 2/2022 on the Proposal of the European Parliament and of the Council on harmonised rules on fair access to and use of data (Data Act) Adopted on 4 May 2022 2 Adopted Executive s ummary With this Joint Opinion, the EDPB and the EDPS aim to draw attention to a number of overarching concerns on the Proposal on Data Act and urge the co - legislature to take decisive action. The EDPB and EDPS note that the Proposal would apply to a broad range of products and…

### Guidelines 03/2020 on the processing of data concerning health for the purpose of scientific research in the context of the COVID-19 outbreak

*Source: EDPB, guidelines-032020-on-the-processing-of-data-concerning-health-for-the-purpose-en, 2020-04-21 — https://overview.legal/posts/126170 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-032020-on-the-processing-of-data-concerning-health-for-the-purpose_en*

Adopted 1 Guidelines 03 /2020 on the processing of data concerning health for the purpose of scientific research in the context of the COVID - 19 outbreak Adopted on 21 April 2020 Adopted 2 Version history Version 1.1 30 April 2020 Minor corrections Version 1. 0 21 April 2020 Adoption of the Guidelines Adopted 3 Adopted 4 The European Data Protection Board Having regard to Article 70 (1) (e) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the…

### Guidelines 2/2019 on the processing of personal data under Article 6(1)(b) GDPR in the context of the provision of online services to data subjects

*Source: EDPB, guidelines-22019-on-the-processing-of-personal-data-under-article-61b-gdpr-in-en, 2019-10-16 — https://overview.legal/posts/126202 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-22019-on-the-processing-of-personal-data-under-article-61b-gdpr-in_en*

1 Adopted Guidelines 2/2019 on the processing of personal data under Article 6(1)(b) GDPR in the context of the provision of online services to data subjects Version 2.0 8 October 2019 2 Adopted Version history Version 2.0 8 October 2019 Adoption of the Guidelines after public consultation Version 1.0 9 April 2019 Adoption of the Guidelines for publication consultation 3 Adopted 1 Part 1 – Introduction ................................ ................................…

### Opinion 25/2018 on the draft list of the competent supervisory authority of Croatia regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-252018-on-the-draft-list-of-the-competent-supervisory-en, 2018-12-04 — https://overview.legal/posts/126268 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-252018-on-the-draft-list-of-the-competent-supervisory_en*

1 Adopted EDPB Plenary meeting, 04/05.12.2018 Opinion 25 /2018 on the draft list of the competent supervisory authority of Croatia regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 4 December 2018 2 Adopted TABLE OF C ONTENTS 1 Summary of the Facts ................................ ................................ ................................ ..................... 4 2 Assessment…

### Opinion 16/2018 on the draft list of the competent supervisory authority of the Netherlands regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-162018-on-the-draft-list-of-the-competent-supervisory-en, 2018-10-03 — https://overview.legal/posts/126303 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-162018-on-the-draft-list-of-the-competent-supervisory_en*

Opinion 16 /2018 on the draft list of the competent supervisory authority of the Netherlands regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 25th September 2018 2 Contents 1. Summary of the Facts ................................ ................................ ................................ ........ 4 2. Assessment ................................ ................................…

### Opinion 3/2018 on the draft list of the competent supervisory authority of Bulgaria regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-32018-on-the-draft-list-of-the-competent-supervisory-en, 2018-10-03 — https://overview.legal/posts/126291 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-32018-on-the-draft-list-of-the-competent-supervisory_en*

Opinion 3 /2018 on the draft list of the competent supervisory authority of Bulgaria regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 25th September 2018 2 Contents 1. Summary of the Facts ................................ ................................ ................................ ........ 4 2. Assessment ................................ ................................ ................................…

### Opinion 8/2018 on the draft list of the competent supervisory authority of Finland regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-82018-on-the-draft-list-of-the-competent-supervisory-en, 2018-10-03 — https://overview.legal/posts/126284 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-82018-on-the-draft-list-of-the-competent-supervisory_en*

Opinion 8 /2018 on the draft list of the competent supervisory authority of Finland regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 25th September 2018 2 Contents 1. Summary of the Facts ................................ ................................ ................................ ........ 4 2. Assessment ................................ ................................ ................................…

### Opinion 39/2021 on whether Article 58(2)(g) GDPR could serve as a legal basis for a supervisory authority to order ex officio the erasure of personal data, in a situation where such request was not submitted by the data subject

*Source: EDPB, opinion-392021-on-whether-article-582g-gdpr-could-serve-as-a-en, 2021-12-14 — https://overview.legal/posts/125971 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-392021-on-whether-article-582g-gdpr-could-serve-as-a_en*

Adopted 1 Opinion 39 /2021 on whether Article 58(2) ( g) GDPR coul d serve as a legal basis for a s upervisory a uthority to order ex officio the erasure of personal data, in a situation where such request was not submitted by the data subject Adopted on 14 December 2021 Adopted 2 Adopted 3 The European Data Protection Board Having regard to Article 63 and Article 64 (2) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural…

## Enforcement decisions

### Italian DPA: Justice Ministry unlawful disclosure of employee health data in service order

*Source: Garante per la protezione dei dati personali (Italy), 2026-07-20 — https://overview.legal/posts/144019 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_10254256*

Facts — The data subject was an employee at a detention facility run by the Italian Ministry of Justice (the controller). Following an assessment by the occupational health physician, who certified that the data subject was fit for service but had to be exempted from wearing a duty belt and could not hold fixed postures for long periods, the facility issued a service order assigning him to a specific operational unit. The service order referred to the data subject's "physical conditions", his "health needs" and the need for an "alternation of posture". The service order itself provided that a copy would be posted on the institute's noticeboard for publicity purposes. Copies were displayed on the noticeboard located in the bar/canteen area and in the TV/relax area, both accessible to all staff on duty but not to outsiders. Further copies were sent to the head of department, the services office, the coordinator of the records office and the penitentiary police secretariat, as well as to the trade unions, and the document was filed in the official collection of service orders. The data subject filed a complaint with the DPA. During the investigation, the controller argued that the reference to the alternation of posture did not disclose any sensitive data and merely justified the assignment decision to other staff. It also argued that, as an administrative act, the service order had to state the reasons of fact and law behind it under Article 3 of Law 241/1990, that its display and communication to the trade unions followed from transparency rules on administrative acts and from the National Framework Agreement for Penitentiary Police Personnel, and that the data subject had been notified of the order and had not objected at the time. The controller added that the order was replaced on the noticeboard after a short period and that all internal recipients were instructed and authorised to process personal data. Holding — First, the DPA held that the information in the service order constituted health data under Article 4(15) GDPR. The references to the data subject's physical conditions, health needs and the need to alternate his posture related unequivocally to his overall psychophysical state, even without any express diagnosis, and the order had been issued precisely to implement the measures prescribed by the occupational health physician under Article 42 of Legislative Decree 81/2008. The DPA also noted that the reference to the alternation of posture allowed anyone to infer the nature of the data subject's condition. Second, the DPA recalled that an employer may access the fitness-for-duty assessment and the working conditions prescribed by the occupational health physician, but only through staff specifically appointed and authorised to process such data. Making data available to persons who are not authorised to process it, even where they belong to the controller's own organisation, amounts to a communication of personal data that requires a legal basis under Article 2-ter of the Italian Data Protection Code and, for health data, under Article 9 GDPR. The DPA found that the display of the order on a noticeboard accessible to all staff, and its transmission to the trade unions, made the data available to colleagues and third parties who had no need to know it. Access should have been restricted, on strict proportionality grounds, to the staff responsible for actually implementing the measures in the exercise of managerial and organisational functions. Therefore, the DPA found a violation of Articles 5(1)(a), 6 and 9 GDPR and Article 2-ter of the Italian Data Protection Code. Third, the DPA rejected the controller's justification based on the duty to give reasons for an administrative act. The document remained in full in the administration's files and was accessible to anyone demonstrating a direct, concrete and current interest under Articles 22 of Law 241/1990 and Articles 59 and 60 of the Italian Data Protection Code. A generic reference to transparency rules on administrative acts was not sufficient either, since those rules do not provide for disclosure by way of noticeboard display. Fourth, the DPA held that collective agreements cannot constitute an appropriate legal basis for a communication of personal data. Collective agreements may only specify, in favour of employees, a framework already laid down by national legislation and cannot introduce a new processing operation not provided for by law. The DPA added that, even where union prerogatives do entail communications to trade unions, these must comply with the necessity principle and be accompanied by specific safeguards, all the more so where the data concern the most intimate sphere of the person. Finally, the DPA classified the gravity of the violation as medium. It considered that the case concerned a single data subject and that the order remained on the noticeboard for a very short time, but also that the conduct reflected an ordinary practice based on collective agreements. The violation was negligent, as the controller had acted in the mistaken belief that it was complying with the applicable rules. As mitigating factors, the DPA took into account the controller's full cooperation during the investigation and the absence of relevant previous violations at the facility concerned. On these grounds, the DPA fined the controller €12,000.

### Italian Garante: OPI of Pisa must remove residential addresses from public register

*Source: Garante per la protezione dei dati personali (Italy), 2026-07-16 — https://overview.legal/posts/122839 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_10192784*

Facts — The data subject, a professional registered with the OPI of Pisa, discovered while consulting the Public Register of Professionals online that the database included the residential address, information not necessary for the purposes of the Register [Note: the OPI is a governance body for registered nurses]. The OPI (the controller), when asked by the DPA to provide further clarification, initially stated that, in accordance with the applicable local regulation (DPR 221/1950), the public register included residential addresses to provide employers with accurate information and to avoid identity confusion in cases of identical names. During the investigation, the National Federation of Nursing Professional Orders (the “Federation”), the representative body entrusted with functions of guidance, coordination and administrative support to the territorial Orders, indicated that the residential address was not required for the functioning or the purpose of the register, expressly referring to Article 6(3) GDPR to confirm that no legal provision required the publication of such data. The controller subsequently revised its position, explaining that it routinely maintained two databases: a complete version and a reduced one containing only minimal information. The publication in which the residential address of a single data subject appeared resulted from an employee’s mistake during the update following a meeting of the Directive Council. Holding — The DPA upheld the complaint and found violations of Article 5(1)(a) GDPR, Article 6(1)(e) GDPR, Article 6(2) GDPR and Article 6(3) GDPR. The publication, through the internet, of personal data that exceeds the main purpose of the professional public registry, without a proper legal basis, breached the Article 6(1). The DPA rejected the controller’s argument that the disclosure resulted merely from an employee’s mistake, noting that the controller did not act promptly to prevent continued access through search engine caching and that such circumstances could not justify the unlawful disclosure. It also clarified that the version of the Register published online contained the residential addresses of all registered professionals, not only that of the complainant, as later confirmed by the DPA. It was mandatory for the the controller to comply with the principles governing data protection, including the principles of lawfulness, fairness and transparency, as well as data minimisation. In accordance with this principles, the data processing should had been processed lawfully, fairly and in a transparent manner in relation to the data subject, and adequate, relevant and limited to what was strictly necessary in relation to the purposes. Following this, the DPA imposed a €16,000 fine. In defining the amount, the DPA took into account that the violation was produced due to the negligence of the Controller (art. 83, par. 2, lett. b.) and its lack of cooperation.

### IMY reprimands Swedish Police for inadequate GDPR Article 13 info at Arlanda border

*Source: IMY (Sweden), 2026-07-03 — https://overview.legal/posts/57263 — original: https://gdprhub.eu/index.php?title=IMY_(Sweden)_-_IMY-2024-2904*

Facts — The supervisory authority launched an investigation into the border control unit of the national police authority (the controller) at Arlanda Airport concerning the processing of the personal data of travellers arriving from third countries (the data subjects). During border control, the controller scanned the data subjects’ passports, and some travellers were required to provide fingerprints. The data collected was then possibly checked against various border control systems, such as the Schengen Information System (SIS) and the Visa Information System (VIS). There were no signs, brochures, or other written information on the processing of personal data available directly in the arrival hall. The only information available could be found on the controller’s website. Holding — The DPA issued the controller a reprimand for the infringement of Article 13 GDPR. It held that the controller had not provided the data subjects sufficient information about the processing of personal data during border controls. According to the DPA, the data subjects had not been able to easily access information regarding, among other things, what personal data is collected, how it is processed, and what rights data subjects have. The DPA took into account that not all travellers arriving from third countries could be expected to know which national authority is responsible for border controls, let alone be able to find and understand the information on the controller’s website without any guidance in the arrivals hall. It concluded that the lack of easily accessible information on this matter constituted a significant shortcoming: the border control operations included the processing of sensitive data, including biometric data, of a large number of travellers on a daily basis. On the other hand, the investigation was limited to one arrivals hall. The controller had also obtained signs with tailored information regarding the processing of personal data during border control since the beginning of the investigation. Based on an overall assessment, the DPA held that the lack of information required by Article 13 in the arrivals hall constituted a minor GDPR violation.

### HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens

*Source: HDPA (Greece), 2026-05-13 — https://overview.legal/posts/144044 — original: https://gdprhub.eu/index.php?title=HDPA_(Greece)_-_12/2026*

Facts — The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of Undesirable Aliens. In response to the Authority's request for clarifications, the competent Directorate of the Ministry of Citizen Protection informed the DPA that: • By a decision dated 27-07-2017, an entry ban and registration in the National Registry of Undesirable Aliens were imposed on the complainant for reasons of national security. • Following temporary 48-hour lifts of the measure for humanitarian reasons in 2019, the entry ban was re-imposed. • Subsequent decisions in 2020, 2023, and 2025 maintained the entry ban and renewed his registration in the National Registry of Undesirable Aliens for successive three-year periods, as the grounds for registration remained active. • The explicit grounds and documentation behind the registration were not disclosed to the complainant because the competent Directorate classified the file as restricted/classified service material. The complainant and his attorney attended a DPA hearing on 22-04-2026, arguing that the registration lacked specific, adequate, or definitive justification regarding any threat to public order or national security. They noted that the complainant has no criminal convictions, poses no threat, and possesses strong ties, residency, and business operations in the region of Northern Epirus and Greece, meaning the entry ban severely disrupts his professional and family life. Holding — According to the provisions of Article 82(1) of Law 3386/2005, foreign nationals whose presence in Greek territory constitutes a threat to national security, public safety, or public order can be registered in the National Registry of Undesirable Aliens, with registrations subject to an ex officio review every three years. Furthermore, pursuant to the provisions of Article 54(2) and Article 55(4) of Law 4624/2019 (the Greek law implementing the GDPR), the data controller is legally empowered to restrict or omit the provision of information and to deny a data subject access to their personal data when dictated by reasons of national security or public order. These national provisions are explicitly anchored in Article 23 GDPR (specifically Article 23(1)(a)GDPR and Article 23(1)(c) GDPR), which permits Member State law to restrict the scope of the obligations and data subject rights (such as the right to be informed under Article 13 GDPR - Article 14 GDPR and the right of access under Article 15 GDPR) to safeguard national security and public security. In the present case, the evidence demonstrated that the complainant's initial registration and subsequent renewals in the National Registry of Undesirable Aliens were executed lawfully for reasons of national security. The Ministry of Citizen Protection, acting as the data controller, exercised its legal discretion under these frameworks to weigh these interests and correctly determined that the underlying operational decision constitutes classified material that cannot be disclosed to the data subject. Consequently, the fundamental principles of data protection law were not breached, and the Hellenic DPA rejected the complaint as unfounded.

### APD/GBA (Belgium) - 115/2022

*Source: APD/GBA (Belgium), 2022-07-19 — https://overview.legal/posts/6317 — original: https://gdprhub.eu/index.php?title=APD/GBA_(Belgium)_-_115/2022*

Facts — During a meeting where the data subject was not present, the data subject's manager (controller) announced her departure and read out a document issued by the company doctor, stating that she was unfit to work and would leave the company. This statement was also included in the minutes of that meeting. When the data subject discovered this, she filed a complaint against the controller with the Belgian DPA for unlawfully disclosing health related personal data to third parties. She added that the minutes were then saved on the controller´s server, freely accessible to all its staff, including from other departments. Holding — The DPA noted that the data subject did not dispute the lawfulness of processing of the information that she was unfit to work, but the subsequent communication about her health to her colleagues and other staff members. The DPA noted that it was not able to verify whether the minutes were actually made available on the controller's server. However if that were the case, this would amount to an additional processing activity and the following findings of the infringement also apply. The DPA first assessed whether the further processing was compatible with the purpose of the original processing (Article 5(1)(b) GDPR). It found that the purpose of the original processing was personnel management. The DPA held that the data subject could not reasonably expect that the same data would be communicated widely beyond the persons authorised for personnel management. Especially considering the sensitive nature of the data. Therefore the DPA held that the further processing was incompatible with the purpose of the original processing. As the further processing was incompatible with the purpose of the original processing, the DPA noted that it could only be lawful if it had its own legal basis pursuant to Article 9(2) juncto Article 6(1). However the DPA found that this was also not present. Therefore, the DPA held that the controller did not have a proper legal basis for processing the data subject's health related data and thereby violated Article 5(1)(b) juncto Article 6(4) and Article 9(2). The DPA issued a reprimand against the controller. The DPA noted that it was not competent to issue a fine as the controller was a public authority.

### CNPD (Portugal) - Deliberação 2019/494

*Source: CNPD (Portugal), 2019-09-03 — https://overview.legal/posts/122872 — original: https://gdprhub.eu/index.php?title=CNPD_(Portugal)_-_Deliberação_2019/494*

Facts — In its Opinion 20/2018 concerning the draft of Law 58/2019 which ensures the implementation of the GDPR in the portuguese national legal framework, the DPA drew the attention of the national legislator to a set of provisions that could potentially violate EU law, particularly the GDPR. The DPA emphasized the primacy of EU law as outlined in the EU treaties, particularly reflecting on Article 288 of the Treaty on the Functioning of the European Union (TFEU) and reinforced by the jurisprudence of the CJEU, which has consistently stated that national laws cannot obstruct the direct applicability of EU regulations and must comply with EU law to ensure uniform implementation across the Member States. However, Law 58/2019 came into force without incorporating all of the DPA's recommendations. The DPA explains that the decision to not apply some of its provisions aims to ensure legal certainty, reinforcing the importance of consistent GDPR application without being hindered by conflicting national rules. Holding — The DPA has decided to disapply the following provisions of Law 58/2019, in cases of personal data processing under its review due to their conflict with the GDPR: Article 2(1)(2): This article broadens the territorial scope of the GDPR to encompass all personal data processing within national territory and processing linked to national establishments outside the territory. The DPA believes this contradicts Article 3 and Article 56 of the GDPR, which outlines the applicable law in cross-border situations. Additionally, it undermines the one-stop-shop mechanism and fails to address instances where the GDPR applies, such as in Portuguese embassies, consulates, ships, and aircraft. Article 20(1): This article states that the right to be informed and the right of access cannot be exercised when a duty of secrecy is imposed on the data controller/processor. In the view of the DPA, this article lacks legal relevance in relation to the GDPR, as it merely repeats provisions already present in the GDPR, particularly concerning the possibility of restricting the data subject's right to information in cases where data collection is indirect and a legal duty of confidentiality exists. Regarding the possibility of restricting the right to information when collecting data directly from the data subject, this right can only be restricted under the provisions of Article 23 GDPR, and Law58/2019 does not meet the requirements therein, thus contradicting the norms of the GDPR and the Charter of Fundamental Rights. Article 23: This article allows public authorities to reuse personal data for any public interest without ensuring compliance with principles of purpose limitation and data minimization (Article 5 GDPR) and could lead to potential misuse of personal data and a violation of individuals’ rights, as it does not ensure that the reuse of data serves the original purpose for which it was collected nor respecting the requirements imposed in Article 23 GDPR. Article 28(3)(a): The employee's consent cannot be the legal basis if the processing results in a legal or economic advantage for the employee. The Portuguese DPA considers it to be a contraction of the doctrine established by European institutions, which accepts employee consent in situations where the act of giving or refusing consent does not, in itself, have negative consequences for the employee. The DPA therefore believes that this provision does not protect the dignity, fundamental rights, and legitimate interests of employees, and thus fails to meet the requirements set forth in Article 9 (2) (b) and Article 88 GDPR. Regime of Administrative Offenses – Articles 37, 38, and 39: The DPA notes that some of the violations outlined in the law contradict the exhaustive list provided in the GDPR (Article 83). The DPA also criticizes the distinction in sanctioning frameworks based on the size of companies and the collective or individual nature of the entities conducting data processing, as the impact on personal data does not depend on those characteristics but rather on the nature of the activity being carried out. Article 61(2) states that "if the expiration of consent is the reason for terminating a contract in which the data subject is a party, the processing of data is lawful until this occurs." The DPA notes that this provision is incongruent, conflating two types of legal basis: consent and contract execution. The contract in which the data subject is a party is sufficient to justify the processing of the data necessary for its execution. Regarding the reasons that led to publish this decision, the Portuguese DPA clarifies that it did so in order to ensure the transparency of its future decision-making processes and, in this regard, contribute to legal certainty and security. It also clarifies that the non-application, in future specific cases, of the legal provisions listed above results in the direct application of the GDPR provisions that were manifestly restricted, contradicted, or compromised in their useful effect.

### HDPA (Greece) 33/2020 — Employee's access and erasure claims against the American College

*Source: HDPA (Greece), 2026-07-24 — https://overview.legal/posts/158444 — original: https://gdprhub.eu/index.php?title=HDPA_(Greece)_-_33/2020*

Facts — The data subject was under the employment of the College for a certain period of time, during which two female students of the College filed a complaint against the complainant regarding the latter's posts on social media that violated the College's Code of Conduct due to their homophobic and racist content. After this event, the College decided to move the complainant to a different position, while reacting to this situation the complainant argued that he had suffered a defamation by the College and requested the altering of the situation. The College asked the complainant to appear to the new position, something the complainant never did, but, nevertheless, the College continued paying the complainant's salary up to the ending point of their contract. Then, the data subject/complainant filed a request to the American College of Greece, asking for access to and copies of their personal data the latter is keeping in its records given the employment relationship between the two, while they specifically requested access to the two complaints made by the two students. With the same request, the data subject asked for the erasure of their personal data from the College's records, since the reason for which the data had been collected and were being kept was no longer valid, since the employment relationship between the complainant and the College had expired. In addition, with the same request, the complainant revoked their - possibly given silently - consent for the keeping and processing of their personal data by the College. The complainant claimed that there was no response from the College to their request. The HDPA requested the College's response to the situation. The latter claimed that the request under question only came into its attention via the HDPA's request for response to the claims. It justified this situation by mentioning that the employee who received the request was not in a good state of health, while the period when the request was filed was a period of heavy workload at the College. The College further underlined that, as soon as the request came to its attention, it contacted the complainant and: i) fulfilled their right to access their data by informing them for all data currently kept by the College and for providing information on how to get copies of all personal data, but not for the data referring to the personal information of one female student of the College who had filed a complaint against the data subject/complainant regarding the latter's behaviour, since the student expressed her not willingness for her name and complained to be known. The College also sent a question to the HDPA regarding the existence or not of their legal responsibility to provide access to the details of the complaint made by the student who expressed her not willingness to be known, as well as regarding the conditions under which such an access should be provided. This question, as the HDPA found, was never answered. ii) informed the complainant that the right to erasure could only be partly fulfilled, since some of the personal data being kept by the College must continue being kept due to the existence of the legal necessity for their existence, in order for the College to be able to fulfil some of its legal responsibilities, according to the provisions of Article 17(3)f GDPR, 250-253 Civil Law Code, and 95 Law 4387/2016. Moreover, the College claimed that it had the right to deny the fulfilment of the complainant's right to access and erasure, according to article 12(5)b GDPR, since the respective request has been made in a manifestly unfounded or excessive and repetitive manner. Answering to the College's claims, the complainant argued that the College is not fulfilling their rights to access and erasure, as well as that the College is not properly justifying the excessive or unfounded manner of the complainant's requests based on the said GDPR article. Additionally, the complainant argued that their right to access had never been fulfilled as their relevant request to the College was only answered by the latter with the explanation that the College had sent a question to the HDPA regarding the legality of fulfilling such a request, but with no information being provided later on by the College. Thus, the complainant underlined that, under Article 55 of Law 4629/2019, the College had the legal responsibility, as a data processor, to inform the data subject for all the data being kept and processed and to fulfil the data subject's right to access before fulfilling their right to erasure. Dispute — Whether the American College of Greece violated the complainant's right to access and erasure of their personal data? Holding — The HDPA confirmed its jurisdiction to rule on the complaint regarding a possible violation of the rights to access to and erasure of personal data, according to Articles 51,55,57,58 GDPR and Articles 9,13,15 of Law 4624/2019. On the contrary, it underlined its lack of jurisdiction to rule on the dispute of the complainant and the American College of Greece as regards the conditions of the employment relationship between them. The HDPA, after presenting the principles of data processing of Article 5(1) GDPR, underlined that, based on Article 5(2) GDPR, it is the data processor's responsibility to conform and to be able to prove their conformity with these principles at all times and by themselves (principle of accountability). Additionally, the HDPA stated that, in accordance with Article 8(1) of the Charter of Fundamental Rights of the EU, Article 9A of the Greek Constitution, and the Recital 4 of GDPR, the right to protection of personal data is not an absolute right, but a right that should be perceived always in connection to its function within society and a right that should be weighted in connection to other fundamental rights, always according to the principle of proportionality. Furthermore, the HDPA referred to Articles 12 and 15 GDPR regarding the right to access personal data, while it also underlined the restrictions to this right that Articles 23 GDPR and 33 Law 4624/2019 provide. More specifically, Article 33 mentions that the right to access cannot be fulfilled when: "1) [...] b) the data i) were recorded just because they could not have been erased due to legal provisions for the necessity of their keeping or ii) exclusively serve purposes of protection or control of data, and the provision of information would require a disproportional effort and the necessary technical and organisational measures render the processing of the data impossible for other purposes. 2) The reasons for the denial of provision of information to the data subject should be justified. The denial must be justified to the data subject, unless the provision of the real and legal reasons on which the denial is based would put the purpose of the denial into danger. [...] 4) The right to information on their data according to Article 15 GDPR does not apply, to the degree that through the provision of information other information, that according to a legal provision or to their nature, especially due to a third party's interest, must remain confidential, would be revealed. " Adding to this, the HDPA noted its past Decision 73/2010, where it judged that "the information of who is complaining against the accused constitutes an information that refers to the latter and is included in the right to access [...] . More specifically, the right to know the source of the data means that the data processor must inform the data subject of the source of the data (HDPA Decisions 4/2005, 39/2005). The HDPA has ruled that the "source" can also be a third party (natural person) (HDPA Decisions 4/2003 & 43/2003, where it is underlined that the accused has the right to access the text of the complaint and to know - when the complaint is eponymous - the name of the complainant, without the matter of whether the complainant is a third party or not being examined). After all, the knowledge of the source of the data is necessary for the data subject to be able to exercise their further rights [...]. Therefore, the HDPA underlined that the name of the female student in included in the content of the term personal data for which the data subject has the right to access, according to Article 15(1)g GDPR. Thus, the HDPA held that the College as a data controller, according to Article 4(7) GDPR, fulfilled the right to access of the complainant via the provision of copies of the data being kept. But, as concerns the non provision of the information for the complaint made by the second female student, the College violated Article 15 GDPR regarding the right to access, since it connected the provision of access to those with the consent of the female student, without examining Article 15 GDPR or Article 33 Law 2462/2019. In addition, from the merits of the case, there is no evidence for the existence of any danger faced by the female student nor is there any claim by the College or the female student for such a danger, given as well that the College did not pursue a disciplinary process against the complainant, while it also continued their salary payments even though the complainant denied to work in the new position where they were transferred. {Here there was a separate opinion of one member of the HDPA, highlighting that the text of the female student's complaint should have been provided to the complainant but with the covering of all relevant data pointing to the female student's identity.}. Additionally, the College's claim for the sickness of their employee and the work overload have no effect over the responsibility of the College to respond to the complainant's request, while there is also no effect on this responsibility from the fact that the HDPA did not answer to the College's request for its Opinion, since the HDPA did not have jurisdiction to impose to the data processor the provision to a third person of data nor had a complained been filed to the HDPA by th data subject (the female student) so as to open up the HDPA's jurisdiction (Article 5 Law 2472/1997, HDPA Opinions 4/2009, 6/2013, HDPA Decision 8/2019). Furthermore, the HDPA held that the complainant's claim that the College did not prove the unfounded or excessive character of their request is of no meaning, since the College responded to their request, even though with delay. The HDPA also held that the complainant's claim for the implementation of Article 55(5) Law 4624/2019 is unfounded, as its provisions cannot be implemented in this case. Lastly, the HDPA referred to Article 17 GDPR on the right to erasure and the restrictions of this non-absolute right provided in par.3 of the said Article and in Article 34 Law 4624/2019. Thus, the HDPA underlined that in the case under question the College as a data processor fulfilled the complainant's right to erasure. The HDPA held that there is, in this case, a legal case of exception from the right to erasure concerning the data referring to the complainant's employment relationship with the College that the latter is required to be keeping based on Article 17(3)b & e GDPR. Additionally, the HDPA held that the College has the legal right to keep the data referring to the two complaints made by the students according to Articles 17(3)e GDPR and 34(1) Law 4624/2019. Therefore, the HDPA held that the College partly fulfilled the data subject's right to access, since it did not provide information on the second female student's complaint, including her name, in violation of Articles 5,15 GDPR, 33 Law 4624/2019. Thus, the HDPA, making use of its corrective powers of Article 58(2)c GDPR, ordered the College to provide the complainant with the relevant information. Additionally, the HDPA held that the College fulfilled the right to access but in violation of the deadlines for such a fulfilment provided by Article 12(3) & (4) GDPR. For this reason, an administrative fine of 1000 EUR was imposed (83(5)b GDPR). Lastly, the HDPA held that the College fulfilled the complainant's right to erasure but in violation of the deadlines provided for such a fulfilment by Article 12(3) & (4) GDPR. For this reason, an administrative fine of 1000 EUR was imposed (Article 83(5)b GDPR).

### Tietosuojavaltuutetun toimisto (Finland) - TSV/4630/2023

*Source: Tietosuojavaltuutetun toimisto (Finland), 2026-07-22 — https://overview.legal/posts/184713 — original: https://gdprhub.eu/index.php?title=Tietosuojavaltuutetun_toimisto_(Finland)_-_TSV/4630/2023*

Facts — A company that provides comparison services for loans and financial products (the controller) received a loan application submitted on the data subject’s behalf in October 2022. The data subject made an access request in November 2022 – they suspected the misuse of their personal data as they had not submitted the loan application themselves. The data subject provided their name, phone number, and email address as identifying information in connection with the access request. The controller did not provide the requested information; instead, it asked the data subject to disclose their residential address and personal identification number as well as to sign the access request electronically using strong authentication in order to verify their identity. The data subject refused to comply with this request and filed a complaint with the DPA, stating that the controller’s procedure for verifying the identity of the data subject in connection with an access request violated Articles 5(1)(c), 12(2) and (6), and 25(2) GDPR. The controller considered the additional information necessary to identify the correct individual and avoid providing the data subject’s information to an unauthorised third party. Holding — The DPA found no GDPR violation and held that the controller was entitled to request the data subject to provide additional information necessary to verify their identity pursuant to Article 12(6) GDPR. The controller’s procedure was also in line with the principle of data minimisation laid down in Article 5(1)(c) GDPR. According to the DPA, the personal data originally provided by the data subject when making the access request could not be considered sufficient identifying information since several people might have the same name and the email address and the phone number of the data subject could also be known to third parties. The DPA considered that the controller had a legitimate reason to request that the data subject provide additional information to verify their identity, as the controller processes personal data concerning the financial status of its customers.

## Recent developments

### ANSPDCP (Romania) - ANSPDCP (Romania) - Fine against Poliserv JG (PJG) SRL

*Source: GDPRhub, 2026-08-21 — https://overview.legal/posts/291402 — original: https://gdprhub.eu/index.php?title=ANSPDCP_(Romania)_-_ANSPDCP_(Romania)_-_Fine_against_Poliserv_JG_(PJG)_SRL*

The Romanian DPA imposed a fine of RON 15,728 (€ 3,000) on a car dealer for failing to implement appropriate technical and organisational measures in order to guarantee the security of its processing, in breach of Article 32 GDPR. English Summary. Facts. A personal data breach occurred because of a cyberattack made possible through a phishing method that stole the credentials of a controller account with administrator privileges. Thus, the personal data of individual customers (at least their fi

### Uber krijgt boete van bijna 825 miljoen euro voor geautomatiseerd blokkeren van chauffeurs

*Source: Autoriteit Persoonsgegevens, 2026-08-21 — https://overview.legal/posts/291406 — original: https://autoriteitpersoonsgegevens.nl/actueel/uber-krijgt-boete-van-bijna-825-miljoen-euro-voor-geautomatiseerd-blokkeren-van-chauffeurs*

De Autoriteit Persoonsgegevens (AP) legt Uber een boete op van 824.990.000 euro. De reden hiervoor is dat de AP heeft geoordeeld dat Uber volledig geautomatiseerd besluiten nam over chauffeurs. Bij vermoedens van fraude of bij te lage klantbeoordelingen werden accounts van chauffeurs automatisch tijdelijk of, bij aanhoudend lage klantbeoordelingen, permanent gedeactiveerd. Hierdoor viel tijdens de deactivatie hun inkomen via Uber weg.

### Datatilsynet (Norway) - 23/00435-62

*Source: GDPRhub, 2026-08-21 — https://overview.legal/posts/291399 — original: https://gdprhub.eu/index.php?title=Datatilsynet_(Norway)_-_23/00435-62*

The DPA found that pharmaceutical company unlawfully continued using an influencer’s personal data after their contract expired and fined it NOK 205,000 for breaching its duty to cooperate under Article 31 GDPR. English Summary. Facts. Lab Pharma AS, the controller, is a Norwegian manufacturer of dietary supplements which markets and sells its products online. In 2016, an influencer, the data subject, entered into an agreement with the controller under which she would promote its products on her

### ICO (UK) - ACRO Criminal Records Office

*Source: GDPRhub, 2026-08-21 — https://overview.legal/posts/291401 — original: https://gdprhub.eu/index.php?title=ICO_(UK)_-_ACRO_Criminal_Records_Office*

The ICO reprimanded ACRO for failing to implement appropriate security measures, including effective patch management and security monitoring, resulting in prolonged unauthorised access to systems containing sensitive personal data. English Summary. Facts. ACRO Criminal Records Office, the processor, is a national police unit providing public services including Police Certificates, International Child Protection Certificates, Subject Access Requests and Record Deletion Requests. It processes per

### AP adviseert Twitch-gebruikers: zet instellingen uit voor delen van data met Amazon AI

*Source: Autoriteit Persoonsgegevens, 2026-08-20 — https://overview.legal/posts/291397 — original: https://autoriteitpersoonsgegevens.nl/actueel/ap-adviseert-twitch-gebruikers-zet-instellingen-uit-voor-delen-van-data-met-amazon-ai*

Streamingplatform Twitch heeft bekendgemaakt dat Amazon persoonsgegevens van Twitch-gebruikers gebruikt om AI-modellen mee te trainen. Gebruikers die niet willen dat Amazon hun streams, afbeeldingen en andere persoonsgegevens gebruikt, kunnen dit nu uitzetten. De Autoriteit Persoonsgegevens (AP) roept mensen op dat te doen.

## Literature

### Automating the Design and Development of Usable, GDPR-Aware Web Forms

*Source: SN Computer Science, 2026-07-14 — https://overview.legal/posts/132119 — original: https://doi.org/10.1007/s42979-026-05219-7*

Abstract Personal data collection in web applications should follow mandated legislative frameworks such as the EU General Data Protection Regulation (GDPR) principles. Among others, web data collection forms should provide clear and transparent explanations regarding the purposes of the collection. At the same time, for users’ ease, such forms should follow standard usability principles. There have been works studying the merging of usability principles and privacy standards. Building on this l

### HOW GDPR TREATS AUTOMATED DECISION-MAKING

*Source: Journal Scientific and Applied Research, 2025-11-14 — https://overview.legal/posts/132599 — original: https://doi.org/10.46687/jsar.v28i1.435*

This article examines how the General Data Protection Regulation (GDPR) regulates automated decision-making, including profiling, in the context of personal data processing. It analyzes the main provisions of Article 22 of the Regulation, as well as the conditions under which fully automated decisions that produce legal effects or significantly affect data subjects are permitted. The article highlights the rights of data subjects – the right to human intervention, the right to express their poin

### Privacy vs. business convenience: the Mousse judgment and the future of data protection in the EU

*Source: Unio - EU Law Journal, 2025-06-18 — https://overview.legal/posts/53865 — original: https://doi.org/10.21814/unio.11.1.6632*

The Mousse ruling represents a pivotal moment in EU data protection law, reinforcing strict limitations on personal data processing and clarifying the legal standards under the General Data Protection Regulation (GDPR). The Court of Justice of the European Union (CJEU) reaffirmed that data collection must be objectively indispensable for a specified legal basis, rejecting broad interpretations of contractual necessity and legitimate interest. Additionally, the ruling confirms that the right to o

### Personal data protection enforcement under GDPR—the Slovak experience

*Source: International Data Privacy Law, 2024-06-20 — https://overview.legal/posts/132513 — original: https://doi.org/10.1093/idpl/ipae008*

### Clarifying “personal data” and the role of anonymisation in data protection law: Including and excluding data from the scope of the GDPR (more clearly) through refining the concept of data protection

*Source: Computer Law Security Review, 2024-04-01 — https://overview.legal/posts/132527 — original: https://doi.org/10.1016/j.clsr.2023.105932*

## Tools

### Meldloket datalekken Autoriteit Persoonsgegevens

*Source: Autoriteit Persoonsgegevens, 2026-07-04 — https://overview.legal/posts/53807 — original: https://datalekken.autoriteitpersoonsgegevens.nl/*

Het officiële loket van de Autoriteit Persoonsgegevens voor het melden van datalekken op grond van artikel 33 AVG. Verwerkingsverantwoordelijken melden hier binnen 72 uur een inbreuk in verband met persoonsgegevens, en kunnen meldingen aanvullen of intrekken.

### CNIL GDPR guide for developers

*Source: CNIL, 2026-07-04 — https://overview.legal/posts/53810 — original: https://github.com/LINCnil/GDPR-Developer-Guide*

Open-source best-practice guide by the French DPA translating GDPR obligations into concrete development practice: data minimisation in code, managing consent, securing data flows, retention, and preparing for data subject rights — organised in 16 practical sheets.

### Standard Contractual Clauses (SCCs) for international transfers

*Source: European Commission, 2026-07-04 — https://overview.legal/posts/53805 — original: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en*

The European Commission's modernised standard contractual clauses (2021) for transfers of personal data to third countries under Article 46(2)(c) GDPR, plus the controller-processor SCCs under Article 28(7). Includes the official Word/PDF templates for all four transfer modules.

### GDPR.eu compliance checklist

*Source: GDPR.eu (Proton), 2026-07-17 — https://overview.legal/posts/125625 — original: https://gdpr.eu/checklist/*

Widely used plain-language GDPR compliance checklist covering lawful basis, data inventory, accountability documents, data subject rights, security and transfer requirements. Published by Proton as part of the GDPR.eu resource site (an unofficial but well-maintained companion to the Regulation).

### AVG-regelhulp voor bedrijven

*Source: RVO, 2026-07-04 — https://overview.legal/posts/53808 — original: https://regelhulpenvoorbedrijven.nl/avg/*

Interactieve regelhulp van de Rijksdienst voor Ondernemend Nederland, ontwikkeld met de Autoriteit Persoonsgegevens: in circa tien vragen een beeld van wat de AVG concreet voor een organisatie betekent, met een persoonlijk actieplan als resultaat.

## Related topics

- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Data Controller** — https://overview.legal/topics/verwerkingsverantwoordelijke
  The entity that determines purposes and means of processing personal data
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities
- **Law Enforcement** — https://overview.legal/topics/law-enforcement
  Processing for law enforcement purposes

---
Generated by overview.legal · https://overview.legal/topics/persoonsgegevens · 2026-08-22
