# Political Opinions — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/political-opinions
> Sources are cited per item. Verify against the official texts before relying on them.

Processing of political views and affiliations

## Overview

## Legal Framework

Article 9(1) GDPR establishes a general prohibition on processing personal data revealing political opinions. This is one of the special categories of personal data that receive heightened protection due to the fundamental rights and freedoms at stake, particularly because such data could expose individuals to discrimination or other harm. The prohibition covers not only data that directly states a person's political views but also data from which political opinions can be inferred or revealed.

The prohibition is not absolute. Article 9(2) GDPR provides several derogations. Article 9(2)(g) permits processing when it is necessary for reasons of substantial public interest, subject to Union or Member State law and with appropriate safeguards. At the national level, Article 26 of the Dutch UAVG implements this derogation specifically for processing that occurs in connection with reasonable requirements related to political opinions in the context of fulfilling functions in administrative bodies and advisory councils.

The AI Act adds another layer: Recital 30 prohibits biometric categorisation systems that use biometric data—such as facial features or fingerprints—to deduce or infer an individual's political opinions. This prohibition does not extend to lawful labelling or filtering of biometric data sets acquired in accordance with Union or national law.

## Key Developments

The CJEU has consistently affirmed the special-category status of political opinions. In *GC and Others v CNIL*, the Court confirmed that Article 9(1) GDPR carries forward and strengthens the prohibition previously established under Article 8(1) of Directive 95/46, treating political opinions alongside racial origin, religious beliefs, and trade union membership as data requiring enhanced protection. In *Meta Platforms v noyb*, the Court reaffirmed the same framework in the context of targeted advertising, underscoring that inferred political opinions fall squarely within the Article 9 prohibition.

In *Dennekamp v European Parliament*, the General Court addressed whether disclosure of names of former MEP assistants could indirectly reveal political opinions. The Court found that the mere argument that disclosure might reveal political affiliations was insufficiently substantiated and could not substitute for a concrete showing that disclosure would specifically and effectively undermine privacy rights under Article 4(1)(b) of Regulation 45/2001. This establishes that a claim of political-opinion sensitivity requires demonstrable, specific harm—not a theoretical possibility.

Dutch enforcement has been active. The AP fined ten municipalities, including Delft and Ede, each €25,000 for unlawful processing of data revealing political opinions. These cases involved municipalities processing information about individuals' political or religious affiliations without a valid Article 9(2) derogation, demonstrating that public-sector controllers face scrutiny even when processing appears administratively routine.

## Practical Guidance

- **Establish a valid derogation before processing.** Identify the specific Article 9(2) ground relied upon—most commonly 9(2)(g) substantial public interest—and ensure it is backed by Union or Member State law, as required by the GDPR and illustrated by Article 26 UAVG.

- **Distinguish direct revelation from inference.** Data need not explicitly state political views to trigger Article 9. If processing combinations of data points would reveal political opinions, the prohibition applies. The *Dennekamp* ruling shows that a mere theoretical possibility is insufficient, but controllers should assess whether inference is reasonably likely.

- **Do not use biometric systems to infer political opinions.** Recital 30 of the AI Act prohibits biometric categorisation systems that deduce political opinions from biometric data. Ensure any biometric processing is limited to lawful, non-sensitive categorisation purposes.

- **Conduct a DPIA for any processing involving political opinions.** Given the high risk to fundamental rights, a Data Protection Impact Assessment under Article 35 GDPR is mandatory, documenting the necessity, proportionality, and safeguards applied.

- **Apply data minimisation strictly.** The Dutch municipality fines demonstrate that collecting or retaining political-opinion data without a clear legal basis invites enforcement. Limit collection to what is strictly necessary for the identified derogation and delete when no longer needed.

## Legislation (full text of key provisions)

### Recital 30 — prohibited biometric categorisation systems

*Source: AI Act, aiact-rec-30-en, 2024-06-12 — https://overview.legal/posts/93742*

Biometric categorisation systems that are based on natural persons’ biometric data, such as an individual person’s face or fingerprint, to deduce or infer an individuals’ political opinions, trade union membership, religious or philosophical beliefs, race, sex life or sexual orientation should be prohibited. That prohibition should not cover the lawful labelling, filtering or categorisation of biometric data sets acquired in line with Union or national law according to biometric data, such as the sorting of images according to hair colour or eye colour, which can for example be used in the area of law enforcement.

### Recital 75 — personal data processing risks to individuals

*Source: GDPR, gdpr-rec-75-en, 2016-04-27 — https://overview.legal/posts/91665*

The risk to the rights and freedoms of natural persons, of varying likelihood and severity, may result from personal data processing which could lead to physical, material or non-material damage, in particular: where the processing may give rise to discrimination, identity theft or fraud, financial loss, damage to the reputation, loss of confidentiality of personal data protected by professional secrecy, unauthorised reversal of pseudonymisation, or any other significant economic or social disadvantage; where data subjects might be deprived of their rights and freedoms or prevented from exercising control over their personal data; where personal data are processed which reveal racial or ethnic origin, political opinions, religion or philosophical beliefs, trade union membership, and the processing of genetic data, data concerning health or data concerning sex life or criminal convictions and offences or related security measures; where personal aspects are evaluated, in particular analysing or predicting aspects concerning performance at work, economic situation, health, personal preferences or interests, reliability or behaviour, location or movements, in order to create or use personal profiles; where personal data of vulnerable natural persons, in particular of children, are processed; or where processing involves a large amount of personal data and affects a large number of data subjects.

### Recital 56 — electoral processing of political opinion data

*Source: GDPR, gdpr-rec-56-en, 2016-04-27 — https://overview.legal/posts/91627*

Where in the course of electoral activities, the operation of the democratic system in a Member State requires that political parties compile personal data on people's political opinions, the processing of such data may be permitted for reasons of public interest, provided that appropriate safeguards are established.

## Case law

### VwGH - VwGH Ro 2025/04/0007-7

*Source: Austrian Administrative Supreme Court, 2026-06-24 — https://overview.legal/posts/184547 — original: https://gdprhub.eu/index.php?title=VwGH_-_VwGH_Ro_2025/04/0007-7*

Facts — The controller was an address publisher and direct advertising company that operated a data application to provide advertisers with personal data for targeted marketing measures. In 2019, following media reports concerning the alleged sale of personal data, particularly information about natural persons’ political party affinity, the Austrian DPA (DSB) initiated an ex officio investigation against the controller. Based on its investigation, the DPA found that the controller had unlawfully processed political party affinity data and unlawfully further processed parcel-frequency data, and had infringed its obligations concerning the DPIA and record of processing activities. It consequently imposed a fine of €18,000,000. The controller appealed to the Federal Administrative Court (BVwG), arguing that the commission of an infringement by a legal person was not, in itself, sufficient for a fine to be imposed under the GDPR. It claimed that since a legal person could not act on its own, the culpable conduct of a natural person had to be identified and attributed to it. The controller argued that the DPA had failed to establish such attribution. The court agreed and, on 26 November 2020, annulled the fine. It found that the DPA had failed to establish that natural persons acting on behalf of the controller had engaged in culpable conduct. The DPA filed an extraordinary official appeal against this judgment with the Austrian Supreme Administrative Court (VwGH). The court stayed the proceedings pending the CJEU’s preliminary ruling in Case C-807/21 (Deutsche Wohnen SE), as the questions referred in that case were also relevant to the appeal proceedings. The CJEU published its judgement on this matter on 5 December 2023. The CJEU held that a fine under Article 83(4) GDPR, Article 83(5) GDPR and Article 83(6) GDPR may be imposed on anyone who qualifies as a controller where it is established that the controller committed the relevant infringement intentionally or negligently. A controller may be sanctioned where it could not have been unaware of the infringing nature of its conduct, regardless of whether it knew that its conduct infringed the GDPR. The CJEU further clarified that, where the controller is a legal person, the application of Article 83 GDPR does not require any action or knowledge on the part of its governing body. Member States may not impose additional substantive requirements for the imposition of fines beyond those laid down in Article 83 GDPR. For the determination of the fine, the controller may also constitute an undertaking within the meaning of EU competition law, with the turnover of the relevant economic unit being taken into account. Following the CJEU judgment, the Supreme Administrative Court annulled the Federal Administrative Court’s judgment on 1 February 2024. The Federal Administrative Court issued a new judgment on 27 December 2024, largely upholding the infringements but reducing the fine to €16,000,000. The controller appealed this decision before the Supreme Administrative Court. Holding — The court found that the controller gathered information concerning the political party affinity of the Austrian population based on anonymous surveys conducted by commissioned polling institutes. These surveys included specific questions concerning interest in election advertising, together with sociodemographic information such as age, level of education and income, place of residence and interest in advertising from political parties. Marketing groups were subsequently formed based on the sociodemographic data and place of residence. For each group, calculations were made to determine the likelihood that an individual with particular sociodemographic characteristics and religious affiliation would be interested in advertising from the political parties concerned. By assigning an identifiable individual to a particular marketing group, the controller linked that person to the probability values calculated for the group and the resulting political party affinity. The court held that the controller did not obtain consent from the data subjects to whom these probability scores were assigned. In total, political party affinity was attributed to approximately 2,200,000 individuals. The court reiterated that political party affinity scores attributed to identifiable individuals constituted personal data revealing political opinions within the meaning of Article 9(1) GDPR. It therefore upheld the finding that the controller had infringed Article 5(1)(a) GDPR in conjunction with Article 9(1) GDPR. In assessing the controller’s culpability, the court relied heavily on the CJEU’s judgment in Deutsche Wohnen SE. It held that the fact that the controller believed it had complied with the GDPR because it had established a quality-assured organisation was not decisive. It pointed out that under GDPR, a legal person’s fault does not require knowledge or awareness on the part of the management body. The establishment of a data protection compliance system, like the obtaining of legal advice, did not in itself exculpate the controller. It stated that the decisive question was whether the controller could have been aware of the unlawfulness of the processing of political party affinity data during the relevant period. The court ruled that the controller had incorrectly assessed that political party affinity scores did not constitute personal data and that it had consequently failed to examine whether they constituted special categories of personal data under Article 9 GDPR. The court rejected the controller’s argument that political party affinity was processed only in relation to groups rather than in relation to specific identifiable individuals. It also rejected the argument that marketing classifications used for political advertising posed no risk to data subjects. The court concluded that given the controller’s resources and its ability to examine the applicable legal position, that legal assessment amounted to gross negligence concerning the infringement of Article 5(1)(a) GDPR in conjunction with Article 9(1) GDPR. Furthermore, the court ruled that the controller’s incorrect assessment that political party affinity scores did not constitute personal data or special categories of personal data also led it to conclude in its Data Protection Impact Assessment (DPIA) that the processing did not pose a high risk and that the scope of Article 35(3)(a) GDPR was therefore not applicable. The court held that the DPIA-related infringement was therefore absorbed from the infringement of Article 5(1)(a) GDPR in conjunction with Article 9(1) GDPR. It found no separate element of wrongdoing. The court additionally ruled that the same incorrect legal assessment resulted in the controller’s failure to include political party affinity as a separate category of personal data in its record of processing activities under Article 30(1)(c) GDPR. The court similarly found that these documentation failures did not contain a separate element of wrongdoing beyond that already covered by the infringement of Article 5(1)(a) GDPR and Article 9(1) GDPR. The court therefore discontinued the proceedings concerning the separate DPIA and record-of-processing infringements. It further held that, where a controller commits multiple GDPR infringements, a single aggregate fine must be imposed under Article 83(3) GDPR, the total amount of which may not exceed the amount applicable to the most serious infringement. The court reassessed the penalty and reduced it to €13,000,000, because the DPIA and record of processing infringements were no longer to be taken into account in determining the fine.

### Supreme Court upholds €300,000 fine against INPS for GDPR violations in COVID bonus data

*Source: Supreme Court, 2026-05-21 — https://overview.legal/posts/53097 — original: https://gdprhub.eu/index.php?title=Cass.Civ._-_15625/2026*

Facts — Istituto nazionale della previdenza sociale (INPS, the controller) is the Italian National Institute for Social Security. In 2021, the DPA fined the controller €300,000 for its data processing activities linked to a subsidy given during the pandemic (also called “the COVID bonus”). The DPA found that the controller had postponed its second screening of verifying the eligibility of data subjects to a later stage, on the grounds that there was a need to immediately pay the subsidy. The controller considered that politicians did not fall under the scope of eligible data subjects, as they were already enrolled in a mandatory social security scheme. The controller processed their personal data from databases to cross reference them with data subjects who had applied for the subsidy. The DPA found a violation of several GDPR principles: the principle of lawfulness (Article 5(1)(a) GDPR), data minimisation (Article 5(1)(c) GDPR), accuracy (Article 5(1)(d) GDPR) and accountability (Articles 5(2) and 24 GDPR). According to the DPA, the controller had not limited the cross referencing to data subjects that had received the allowance, but to those whose applications had already been rejected. In addition, the DPA found a violation of Articles 25 and 35 GDPR, as the controller failed to conduct a data protection impact assessment (DPIA). The DPA ordered the controller to erase all personal data that had been processed unlawfully and to carry out a DPIA before resuming its processing activities. The controller appealed the decision to the Court of Rome, and argued that the DPA’s decision was unfounded. The court upheld the appeal and dismissed the DPA’s decision. The court considered that the controller had processed data subjects’ data lawfully, as it had limited the amount of data to what was necessary to verify data subjects’ eligibility. The court also considered that the processing posed a low risk for data subjects’ rights, as the data subjects’ names were not disclosed. The DPA appealed this decision to the court. Holding — The court dismissed the appeal. The court first stated that the controller processed the data lawfully under Article 6(1)(e) GDPR (public interest) and Article 6(3)(b) GDPR. While the controller processed data of specific data subjects (politicians), the court stated that national law allowed the controller to check the eligibility of all data subjects applying for the subsidy. The controller had also obtained the personal data through public databases provided by the Chambers of Parliament and Ministry of the Interior. The court also dismissed the DPA’s arguments on data minimisation (Article 5(1)(c) GDPR). The court stated that the principle of data minimisation is not absolute, and must be balanced with other interests at stake. The court took into consideration the fact that the data was publicly available and the need to quickly verify a high number of applications during a state of emergency. According to the court, there was also no other way to check applications still under review, and concluded that there was an overriding public interest in carrying out the verification process quickly. Finally, the court considered that the controller complied with Article 25 GDPR, as it processed data lawfully and in compliance with Article 5(1)(c) GDPR. In terms of data accuracy (Article 5(1)(d) GDPR), the court dismissed the DPA’s argument that the controller’s system did not eliminate the risk of “homocodes” (identical tax numbers between two or more people). The court considered that the data collected by the Chambers of Parliament and Ministry of Interior were presumed to be accurate. The court also noted that national law foresees the risk of “homocodes” and sets specific procedures in such cases, and that no actual inaccuracies were found in the controller’s verification process. Finally, the court did not find a violation of Article 35 GDPR. The court stated that the controller did not have the obligation to conduct a DPIA, as it did not meet all the necessary criteria. According to the court, the DPA failed to explain the potential high risks of large scale processing that would have justified the need for a DPIA. Given the previous dismissed arguments, the court considered that the controller had also complied with the principle of accountability (Articles 5(2) and 24 GDPR).

### NSA - III OSK 5037/21

*Source: Supreme Administrative Court, 2025-04-29 — https://overview.legal/posts/125644 — original: https://gdprhub.eu/index.php?title=NSA_-_III_OSK_5037/21*

Facts — In March 2020, the Ombudsman requested the DPA to initiate proceedings regarding several laws that introduced an obligation for judges and prosecutors to declare their membership in an association, which would then be included in a Public Information Bulletin. The declarations of membership included associations to churches, religions, political parties, and functions similar to trade unions. The Ombudsman argued that the law was unconstitutional. In addition, the Ombudsman requested that the DPA issue an order restricting the processing of this data, specifically to prohibit the publication in the bulletin until proceedings were complete. The DPA dismissed the case in April 2020. The DPA stated that Article 6(1) GDPR provided a legal basis for the processing based on a legal obligation (Article 6(1)(c) GDPR) and necessity for the public interest (Article 6(1)(e) GDPR). Finally, the DPA stated that it did not have the competence under Article 57 GDPR to decide on the issue of constitutionality; this was a matter the Ombudsman should have taken to the Constitutional Court. The Ombudsman appealed the decision to the Court of First Instance, arguing that the DPA should have also considered whether the law fulfilled the requirements of public interest and proportionality under Article 6(3) GDPR. The Court upheld the reasoning of the DPA, stating that law has a legal basis in accordance with the GDPR. According to the Court, GDPR does not give the DPA broader powers, since the this was not foreseen by the EU legislator or provided by national law. The Ombudsman appealed the case to the Provincial Administrative Court, who dismissed the case. The Ombudsman requested the Court to reconsider, or alternatively, the Supreme Administrative Court. In addition, the Ombudsman requested the Supreme Administrative Court to refer a preliminary question to the EU Court of Justice (CJEU). The Provincial Administrative Court referred the case to the Supreme Administrative Court. In its complaint, the Ombudsman argued there was a violation of EU and national law due to the DPA’s and Court’s failure to act, as well as the law restricting the judges and prosecutor’s freedom of religion and assembly. The Ombudsman cited CJEU Case C-204/21 (European Commission v. Republic of Poland). In this case, the CJEU found that national legislation requiring judges to submit written declarations of membership in a political party violated Article 7 CFR and Article 8 CFR, as well as Article 6(1)(c) GDPR and Article 6(3) GDPR. In addition, the CJEU stated that it was insufficient for a national law to meet the formal criteria (e.g. by specifying the data processed and the storage period), it also needed to meet the qualitative criteria (public interest purpose and proportionality). Holding — The Supreme Administrative Court first dismissed the request of the Ombudsman to refer a preliminary question to the CJEU, on the basis that the case C-204/21 made the question irrelevant. Nonetheless, the Court stated that it had the obligation to take the CJEU case into account in assessing whether a national law is compatible with EU law, regardless of the issues raised in the appeal. Article 260(1) TFEU obliges the Court to take measures to ensure the implementation of a CJEU judgment stating that a Member State has not complied with its obligations under the Treaties. The Court considered that the Court of First Instance had misinterpreted Article 6(1)(c) GDPR and Article 6(1)(e) GDPR by limiting its interpretation to national laws. According to the Court, the decision did not consider the Constitution or the CFREU (Article 8 CFR and Article 10(1) CFR) and the European Convention of Human Rights (ECHR) (Article 8 ECHR and Article 9(1) ECHR and Article 9(2) ECHR ). The Court followed the reasoning of the CJEU in Case C-204/21 and concluded that the Polish law requiring judges and prosecutors to disclose their affiliation with religious, trade union and political organisations was a serious interference of their rights under the CFREU. The Polish law also violated Article 6(1)(c) GDPR and Article 6(1)(e) GDPR and Article 6(3) GDPR. The Court referred to the CJEU's reasoning in stating that the processing and publishing of judges' and prosecutors' personal data is likely to reveal their worldview and religious beliefs. This data belongs to the special category of personal data that has additional protections in accordance with Article 9(1) GDPR. The Court overturned the decision by the lower courts and the DPA.

### Judgment of the Court (Eighth Chamber) of 19 December 2024.#MK v K GmbH.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 88(1) and (2) – Processing in the context of employment – Employees’ personal data – More specific rules provided for by a Member State pursuant to that Article 88 – Obligation to comply with Article 5, Article 6

*Source: Court of Justice of the European Union, C-65/23, 2024-12-19 — https://overview.legal/posts/132156 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0065*

In a preliminary ruling requested by the German Federal Labour Court (Bundesarbeitsgericht), the Court of Justice of the European Union interpreted Article 88 of the GDPR regarding Member States' ability to adopt more specific rules for processing employee data in the employment context. The case arose from a dispute between an employee (MK) and his employer (K GmbH) over compensation for non-material damage allegedly caused by the processing of personal data based on a works agreement. The Court held that Article 88 does not grant Member States or social partners a margin of discretion to deviate from the core GDPR requirements of Article 5, Article 6(1), and Article 9, meaning national courts must conduct full judicial review of whether such data processing complies with these fundamental GDPR provisions.

### Judgment of the Court (Third Chamber) of 28 November 2024.#Nemzeti Adatvédelmi és Információszabadság Hatóság v UC.#Request for a preliminary ruling from the Kúria.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data and the free movement of such data – Regulation (EU) 2016/679 – Data processed when drawing up a COVID-19 certificate – Data not collected from the data subject – Information to be provided – Exception to the obligation t

*Source: Court of Justice of the European Union, C-169/23, 2024-11-28 — https://overview.legal/posts/132158 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0169*

In Case C-169/23, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Kúria (Hungary) concerning whether the Budapest Metropolitan Government Office, as controller issuing COVID-19 immunity certificates, was required to provide information to data subjects under Article 14 GDPR where the personal data was not collected directly from them. The Court held that data generated by the controller in the context of its own processes falls within the Article 14(5)(c) exemption from the obligation to provide information, provided that Member State law ensures appropriate measures to protect the data subject's legitimate interests, including data security measures under Article 32. The Court also confirmed that supervisory authorities retain competence to handle complaints under Article 77(1) even where the Article 14(5)(c) exemption applies.

### Judgment of the Court (Fourth Chamber) of 4 October 2024.#Maximilian Schrems v Meta Platforms Ireland Limited.#Request for a preliminary ruling from the Oberster Gerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Online social networks – General terms of use relating to contracts concluded between a digital platform and a user – Personalised advertising – Article 5(1)(b) – Principle of purpos

*Source: Court of Justice of the European Union, C-446/21, 2024-10-04 — https://overview.legal/posts/132159 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0446*

In a preliminary ruling arising from proceedings between Maximilian Schrems and Meta Platforms Ireland Limited, the Court of Justice of the European Union interpreted GDPR Articles 5(1)(b), 5(1)(c), 6(1), and 9 concerning the lawfulness of processing user personal data for personalised advertising on online social networks. The Court addressed whether such processing can be deemed compatible with the original purpose of data collection under a platform's terms of use, the applicability of the data minimisation principle, and the conditions under which special categories of personal data, including data concerning sexual orientation made public by the data subject, may be processed. No fine was imposed, as the ruling provides interpretative guidance to the Austrian Supreme Court for resolution of the underlying dispute.

### Judgment of the Court (Fifth Chamber) of 4 May 2023.#UZ v Bundesrepublik Deutschland.#Request for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 5 – Principles relating to processing – Controllership – Article 6 – Lawfulness of processing – Electronic file compiled by an administrative authority relating to an asylum application – Tra

*Source: Court of Justice of the European Union, C-60/22, 2023-05-04 — https://overview.legal/posts/132289 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0060*

In Case C-60/22, the CJEU (Fifth Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden concerning UZ, a third-country national, and the Bundesrepublik Deutschland regarding the processing of personal data in an asylum application file. The Court held that an administrative authority transmitting an electronic asylum file to a competent national court via an electronic mailbox constitutes processing under the GDPR, and that where both the authority and the court determine the purposes and means of processing, they are joint controllers under Article 26, requiring an arrangement allocating responsibility and maintaining records of processing activities under Article 30. The Court further clarified that transmission of personal data without the data subject's consent constitutes unlawful processing, triggering the right to erasure under Article 17(1)(d) and the right to restriction under Article 18(1)(b), and that national courts must disregard such unlawfully processed data. No fine was imposed.

### Meta Platforms v noyb

*Source: CJEU, C-252/21, 2023-01-12 — https://overview.legal/posts/51484 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0252*

GDPR consent requirements and lead supervisory authority mechanism.

### Judgment of the Court (Grand Chamber) of 1 August 2022.#OT v Vyriausioji tarnybinės etikos komisija.#Request for a preliminary ruling from the Vilniaus apygardos administracinis teismas.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Charter of Fundamental Rights of the European Union – Articles 7, 8 and 52(1) – Directive 95/46/EC – Article 7(c) – Article 8(1) – Regulation (EU) 2016/679 – Point (c) of the first subparagraph of

*Source: Court of Justice of the European Union, C-184/20, 2022-08-01 — https://overview.legal/posts/132309 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62020CJ0184*

In Case C-184/20, the CJEU Grand Chamber addressed a preliminary reference from a Lithuanian administrative court concerning OT's challenge to a decision by the Vyriausioji tarnybinės etikos komisija (Chief Official Ethics Commission) finding that OT failed to file a declaration of private interests. The core issue was whether national legislation requiring internet publication of personal data—including potentially special category data—from private interest declarations of public servants and heads of publicly funded associations is compatible with GDPR Articles 6(1)(c) and 9(1), read alongside Articles 7, 8, and 52(1) of the EU Charter of Fundamental Rights. The Court held that such processing may be justified under the legal obligation and public interest lawful bases, but Member States must ensure the publication framework is proportionate, particularly by limiting the scope of published data and the duration of its online availability, and that indiscriminate publication of all declared data without individualized assessment would violate the proportionality principle.

### GC and Others v CNIL

*Source: CJEU, C-136/17, 2019-09-24 — https://overview.legal/posts/51475 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62017CJ0136*

Conditions for delisting sensitive data from search results.

### Judgment of the Court (Second Chamber) of 4 May 2017.#Valsts policijas Rīgas reģiona pārvaldes Kārtības policijas pārvalde v Rīgas pašvaldības SIA "Rīgas satiksme".#Request for a preliminary ruling from the Augstākās tiesas Administratīvo lietu departaments.#Reference for a preliminary ruling — Directive 95/46/EC — Article 7(f) — Personal data — Conditions for the lawful processing of personal data — Concept of ‘necessity for the realisation of the legitimate interests of a third party’ — Reques

*Source: Court of Justice of the European Union, C-13/16, 2017-05-04 — https://overview.legal/posts/132348 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62016CJ0013*

In Case C-13/16, the Court of Justice of the European Union (Second Chamber) addressed a preliminary ruling from the Latvian Supreme Court in proceedings between the Riga Regional Police Board and the municipal transit company SIA "Rīgas satiksme" concerning whether the police could compel disclosure of personal data identifying the perpetrator of a road accident. The Court interpreted Article 7(f) of Directive 95/46/EC, holding that while a third party's request to process personal data for the purpose of pursuing a legal claim may fall within the scope of legitimate interests, the directive does not impose an obligation on the data controller to grant such a disclosure request, as the controller must balance the legitimate interests against the data subject's fundamental rights and freedoms. No fine was imposed, as the ruling solely provided interpretative guidance on the conditions for lawful processing under the directive.

### Judgment of the Court (First Chamber) of 7 December 2023.#OQ v Land Hessen.#Request for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 22 – Automated individual decision-making – Credit information agencies – Automated establishment of a probability value concerning the ability of a person to meet payment commitments in the future (‘s

*Source: Court of Justice of the European Union, C-634/21, 2023-12-07 — https://overview.legal/posts/132279 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0634*

In Case C-634/21, the CJEU addressed a preliminary ruling from the Verwaltungsgericht Wiesbaden concerning OQ's challenge against Land Hessen's refusal to order SCHUFA Holding AG to grant access to and erase personal data, including a credit score. The core issue was whether the automated calculation of a probability value ("scoring") by a credit information agency regarding a person's future ability to meet payment commitments constitutes an automated individual decision-making under Article 22(1) of the GDPR when third parties use that score for their own decisions. The Court held that such scoring does not itself amount to a decision producing legal effects under Article 22(1), as it is the third party, not the credit agency, that makes the decision based on the score.

## Guidance

### Statement 2/2019 on the use of personal data in the course of political campaigns

*Source: EDPB, statement-22019-on-the-use-of-personal-data-in-the-course-of-political-en, 2019-03-13 — https://overview.legal/posts/126230 — original: https://www.edpb.europa.eu/documents/statement/statement-22019-on-the-use-of-personal-data-in-the-course-of-political_en*

1 Statement 2 / 2019 on the use of personal data in the course of political campaigns Adopted on 13 March 2019 The European Data Protection Board has adopted the following statement: Engaging with voters is inherent to the democratic process. It allow s the preparation of political program me s , enable s citizens to influence politics and the develop ment of campaign s in line with citizens expectation s. Political parties , political coalitions and candidates increasingly rely on personal…

### Toolbox on essential data protection safeguards for enforcement cooperation between EEA data protection authorities and competent data protection authorities of third countries

*Source: EDPB, toolbox-on-essential-data-protection-safeguards-for-enforcement-en, 2022-03-14 — https://overview.legal/posts/125962 — original: https://www.edpb.europa.eu/documents/other-guidance/toolbox-on-essential-data-protection-safeguards-for-enforcement_en*

Adopted Toolbox on essential data protection safeguards for enforcement cooperation between EEA data protection authorities and competent data protection authorities of third countries Adopted on 14 Mar c h 2022 2 Adopted The European Data Protection Board Having regard to Article 70 (1)(u) and Article 50(a) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the…

### Guidelines 8/2020 on the targeting of social media users

*Source: EDPB, edpb-guidelines-on-the-targeting-of-social-media-users, 2021-04-13 — https://overview.legal/posts/38073 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-82020-on-the-targeting-of-social-media-users_en*

The EDPB adopted Guidelines 8/2020 on the targeting of social media users to clarify the roles, responsibilities, and legal obligations of the various actors involved in social media targeting, including social media providers, targeters, and users. The guidelines analyze different targeting mechanisms—based on provided, observed, and inferred data—and address controller determinations, legal bases, transparency requirements, DPIAs, and the processing of special categories of data. No fines are imposed, as this is interpretive guidance intended to assist stakeholders in achieving GDPR compliance.

### Recommendation 01/2019 on the draft list of the European Data Protection Supervisor regarding the processing operations subject to the requirement of a data protection impact assessment (Article 39.4 of Regulation (EU) 2018/1725)

*Source: EDPB, recommendation-012019-on-the-draft-list-of-the-european-data-protection-en, 2019-07-12 — https://overview.legal/posts/126224 — original: https://www.edpb.europa.eu/documents/recommendation/recommendation-012019-on-the-draft-list-of-the-european-data-protection_en*

Adopted 1 Recommendation 01/ 2019 on the draft list of the European Data Protection Supervisor regarding the processing operations subject to the requirement of a data protection impact assessment (Article 3 9 .4 of Regulation (EU) 2018/1725) Adopted on 10 July 2019 Adopted 2 3 CONCLUSION ................................ ................................ ................................ ................................ ... 7 Adopted 3 The European Data Protection Board Having regard to Article…

### EDPB Annual Report 2022

*Source: EDPB, edpb-annual-report-2022-en, 2023-04-17 — https://overview.legal/posts/125861 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-annual-report-2022_en*

EDPB Annual Report 2022 1 2022 ANNUAL REPORT STREAMLINING ENFORCEMENT THROUGH COOPERATION An Executive Summary of this report, which provides an overview of key EDPB activities in 2022, is also available. Further details about the EDPB can be found on our website at edpb.europa.eu. 1 GLOSSARY 4 2 FOREWORD 7 3 2022 – HIGHLIGHTS 9 3.1. ENFORCEMENT COOPERATION 9 3.1.1. Vienna statement on enforcement cooperation 10 3.1.2. Guidelines 02/2022 on the application of Art. 60 GDPR 10 3.1.3. Guidelines…

## Enforcement decisions

### Municipality of Eindhoven: Insufficient legal basis for data processing

*Source: Dutch Supervisory Authority for Data Protection (AP), 2026-02-03 — https://overview.legal/posts/52388 — original: https://www.enforcementtracker.com/ETid-3034*

The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Eindhoven. The controller, one of ten municipalities that were fined, processed data regarding the Islamic community in its municipality using a force field analysis, for which it employed an external processor. This processing took place at a time of heightened societal concern about Islamic extremism and terrorism. During this period, the Dutch government and the National Coordinator for Security and Counterterrorism stepped

### Municipality of Ede: Insufficient legal basis for data processing

*Source: Dutch Supervisory Authority for Data Protection (AP), 2026-02-03 — https://overview.legal/posts/52387 — original: https://www.enforcementtracker.com/ETid-3033*

The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Ede. The controller, one of ten municipalities that were fined, processed data regarding the Islamic community in its municipality using a force field analysis, for which it employed an external processor. This processing took place at a time of heightened societal concern about Islamic extremism and terrorism. During this period, the Dutch government and the National Coordinator for Security and Counterterrorism stepped up me

### Municipality of Gooise Meren: Insufficient legal basis for data processing

*Source: Dutch Supervisory Authority for Data Protection (AP), 2026-02-03 — https://overview.legal/posts/52389 — original: https://www.enforcementtracker.com/ETid-3035*

The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Gooise Meren. The controller, one of ten municipalities that were fined, processed data regarding the Islamic community in its municipality using a force field analysis, for which it employed an external processor. This processing took place at a time of heightened societal concern about Islamic extremism and terrorism. During this period, the Dutch government and the National Coordinator for Security and Counterterrorism step

### Municipality of Haarlemmermeer: Insufficient legal basis for data processing

*Source: Dutch Supervisory Authority for Data Protection (AP), 2026-02-03 — https://overview.legal/posts/52390 — original: https://www.enforcementtracker.com/ETid-3036*

The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Haarlemmermeer. The controller, one of ten municipalities that were fined, processed data regarding the Islamic community in its municipality using a force field analysis, for which it employed an external processor. This processing took place at a time of heightened societal concern about Islamic extremism and terrorism. During this period, the Dutch government and the National Coordinator for Security and Counterterrorism st

### Municipality of Hilversum: Insufficient legal basis for data processing

*Source: Dutch Supervisory Authority for Data Protection (AP), 2026-02-03 — https://overview.legal/posts/52391 — original: https://www.enforcementtracker.com/ETid-3037*

The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Hilversum. The controller, one of ten municipalities that were fined, processed data regarding the Islamic community in its municipality using a force field analysis, for which it employed an external processor. This processing took place at a time of heightened societal concern about Islamic extremism and terrorism. During this period, the Dutch government and the National Coordinator for Security and Counterterrorism stepped

### Municipality of Huizen: Insufficient legal basis for data processing

*Source: Dutch Supervisory Authority for Data Protection (AP), 2026-02-03 — https://overview.legal/posts/52392 — original: https://www.enforcementtracker.com/ETid-3038*

The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Huizen. The controller, one of ten municipalities that were fined, processed data regarding the Islamic community in its municipality using a force field analysis, for which it employed an external processor. This processing took place at a time of heightened societal concern about Islamic extremism and terrorism. During this period, the Dutch government and the National Coordinator for Security and Counterterrorism stepped up

### Municipality of Tilburg: Insufficient legal basis for data processing

*Source: Dutch Supervisory Authority for Data Protection (AP), 2026-02-03 — https://overview.legal/posts/52393 — original: https://www.enforcementtracker.com/ETid-3039*

The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Tilburg. The controller, one of ten municipalities that were fined, processed data regarding the Islamic community in its municipality using a force field analysis, for which it employed an external processor. This processing took place at a time of heightened societal concern about Islamic extremism and terrorism. During this period, the Dutch government and the National Coordinator for Security and Counterterrorism stepped u

### Municipality of Veenendaal: Insufficient legal basis for data processing

*Source: Dutch Supervisory Authority for Data Protection (AP), 2026-02-03 — https://overview.legal/posts/52394 — original: https://www.enforcementtracker.com/ETid-3040*

The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Veenendaal. The controller, one of ten municipalities that were fined, processed data regarding the Islamic community in its municipality using a force field analysis, for which it employed an external processor. This processing took place at a time of heightened societal concern about Islamic extremism and terrorism. During this period, the Dutch government and the National Coordinator for Security and Counterterrorism steppe

## Recent developments

### Austrian Supreme Court: Meta must give users full access to their data

*Source: noyb - European Center for Digital Rights, 2025-12-18 — https://overview.legal/posts/49120 — original: https://noyb.eu/en/austrian-supreme-court-meta-must-give-users-full-access-their-data*

Online & Mobile tracking Austrian Supreme Court (OGH): Meta must provide full access to all personal data of user within 14 days, including the sources, recipients and purposes for which each information was used. All of Meta's claims of trade secrets or other limitations were rejected, leading to unprecedented access to the inner workings of Meta. Meta was also illegally collecting data from third party apps and websites and may only provide personalised advertisement if a user provided “specif

### EU Commission internal draft would wreck core principles of the GDPR

*Source: noyb - European Center for Digital Rights, 2025-11-10 — https://overview.legal/posts/49184 — original: https://noyb.eu/en/eu-commission-about-wreck-core-principles-gdpr*

GDPR Policy As gradually leaked the last days by various news outlets, the EU Commission has secretly set in motion a potentially massive reform of the GDPR. If internal drafts become reality, this would have significant impact on people's fundamental right to privacy and data protection. The reform would be part of the so-called "Digital Omnibus" which was supposed to only bring targeted adjustments to simplify compliance for businesses. Now, the Commission proposes changes to core elements lik

### Snap Election faster than German DPAs: Microtargeting continues to influence voters

*Source: noyb - European Center for Digital Rights, 2025-02-21 — https://overview.legal/posts/53161 — original: https://noyb.eu/en/snap-election-faster-german-dpas-microtargeting-continues-influence-voters*

Political Microtargeting, Manipulation & Tracking In March 2023, noyb filed complaints against several German political parties: During the 2021 elections, CDU, AfD, SPD, Bündnis 90/Die Grünen, Die Linke and the Ecological Democratic Party illegally used political microtargeting to attract voters. Now, almost two years later, we are just one day away from the next federal election. However, the competent Data Protection Authorities still haven’t decided these cases – and political parties still

### Political Microtargeting by EU Commission illegal

*Source: noyb - European Center for Digital Rights, 2024-12-13 — https://overview.legal/posts/53170 — original: https://noyb.eu/en/political-microtargeting-eu-commission-illegal*

Political Microtargeting, Manipulation & Tracking noyb win against the European Commission: The EDPS (European Data Protection Supervisor) has issued a decision finding that the European Commission has illegally targeted advertising at citizens using "sensitive" personal data on their political views. Decision by the EDPSComplaint filed with the EDPS in 2023Related noyb complaints in Germany ("Target Leaks")EU Commission tried to influence political views in the Netherlands. In the contentious f

### Data breach in Malta: 65.000 € fine for C-Planet

*Source: noyb - European Center for Digital Rights, 2022-01-20 — https://overview.legal/posts/53287 — original: https://noyb.eu/en/data-breach-malta-65000-eu-fine-c-planet*

Following a complaint by noyb, the Information & Data Protection Commissioner (IDPC) imposed a fine of 65 000 € on the IT company C-Planet. The company had illegally collected data of 98% of Maltese voters, including political preferences and failed to take appropriate data-protection measures. C-Planet notified neither the users nor the data protection authority about the data breach. Download: Decision of the IDPC against C-PLANET Complaint filed in 2020. In November 2020, noyb filed a complai

## Literature

### Criminal Offence and Health Condition Information as Special Categories of Data, and the Legal Aspects of Processing in Labor Relations under GDPR and Georgian Law

*Source: ORBELIANI LAW REVIEW, 2025-03-11 — https://overview.legal/posts/132538 — original: https://doi.org/10.52340/olr.2024.03.01.05*

71 Orbeliani Law Review  Vol. 3, No. 1, 2024 Simoni Takashvili* ORCID: 0000-0001-8608-170X Criminal Offence and Health Condition Information as Special Categories of Data, and the Legal Aspects of Processing in Labor Relations under GDPR and Georgian Law ABSTRACT Criminal offence and health condition information as special categories of data present significant legal challenges in labor relations. The new Personal Data Protection Law outlines the general regulations regarding criminal offence and health condition information as special categories of personal data. The prin - ciples governing the processing of this personal information are very specific, and depend on several factors, especially in employment contexts. Employers have access to private data related to candidates during the pre-contractual phase, and to employees during the contractual relationship. This access car - ries a high risk of breaching the principles of processing special categories of personal data. This article provides a comprehensive analysis of the processing of criminal of - fence and health condition information as special categories of data by the em - ployer. This issue is analyzed within the cont

### GDPR - General Data Protection Regulation on Sites Requiring Accessibility

*Source: Innovative STEM Education, 2021-06-29 — https://overview.legal/posts/132420 — original: https://doi.org/10.55630/stem.2021.0305*

The paper describes what GDPR - General Data Protection Regulation is and why it matters for business, institutions and other legal entities, who need to collect personal data in order to provide and deliver services or products. They have to apply and describe to consumers’ principles and general rules to protect their data. Rules include reasons why personal data collection is necessary, transparency how and by who it will be used and stored and for how long, as well as safety measures to not

### Tracking Walls, Take-It-Or-Leave-It Choices, the GDPR, and the ePrivacy Regulation

*Source: European Data Protection Law Review, 2017-01-01 — https://overview.legal/posts/132455 — original: https://doi.org/10.21552/edpl/2017/3/9*

1 Tracking Walls, Take - It - Or - Leave - It Choices, the GDPR, and the ePrivacy Regulation F rederik J Zuiderveen Borgesius, S anne Kruikemeier, Sophie C Boerman and N atali Helberger * Pre - print. P ublished version : F. J. Zuiderveen Borgesius , S. Kruikemeier, S. C. Boerman, and N. Helberger, ‘ Tracking walls, take - it - or - leave - it choices, and EU data privacy law ’ , European Data Protection Law Review, Volume 3, 2017, Issue 3, p.353 - 368. * Dr Frederik J Zuiderveen Borgesius is a researcher at Research Group on Law Science Technology & Society (LSTS) of the Free University Brussels. His email address is: fzuiderv@vub.ac.be . Dr Sanne Kruikemeier is assistant professor Political Communication and Journalism at the Amsterdam School of Communication Research (ASCoR) of the University of Amsterdam. Dr Sophie C Boerman is assistant professor of Persuasive Communication at the Amsterdam Scho ol of Communication Research (ASCoR) of the University of Amsterdam. Prof D r Natatali Helberger is professor Information Law at the Institute for Information Law (IViR) of the University of Amsterdam. 1 1 All authors cooperate in the Personalised Communication Project <http://personal

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Special Categories of Data** — https://overview.legal/topics/bijzondere-persoonsgegevens
  Sensitive data requiring enhanced protection (health, biometric, etc.)
- **Types of Special Categories of Personal Data** — https://overview.legal/topics/special-categories-data-types
  A dedicated topic is needed to comprehensively cover the specific types and definitions of special categories of personal data, including racial/ethnic origin, 
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Religious Beliefs** — https://overview.legal/topics/religious-beliefs
  Processing of religious or philosophical beliefs
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing

---
Generated by overview.legal · https://overview.legal/topics/political-opinions · 2026-08-22
