# Privacy by Default — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/privacy-by-default
> Sources are cited per item. Verify against the official texts before relying on them.

Ensuring highest privacy settings apply by default

## Overview

## Legal Framework

The governing provision is [Article 25 GDPR](/laws/gdpr/art-25), which consolidates two related but distinct obligations: data protection by design (paragraph 1) and data protection by default (paragraph 2). Article 25(2) imposes a specific, operational duty on controllers to configure their systems so that the most privacy-protective settings apply automatically — without requiring the data subject to take affirmative steps.

> "The controller shall implement appropriate technical and organisational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed."
> — GDPR Art. 25(2)

The scope of this obligation is deliberately broad. It extends across four dimensions of the processing lifecycle:

> "That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility."
> — GDPR Art. 25(2)

Recital 78 reinforces this framework by situating the default-setting obligation within the broader accountability principle, listing concrete measures such as data minimisation, pseudonymisation, and transparency as means of demonstrating compliance. Article 47(d) also references data protection by design and by default as a required element of binding corporate rules, meaning the obligation extends into intra-group transfer governance.

## Key Developments

The Court of Justice of the European Union has begun to articulate the practical boundaries of Article 25 in preliminary rulings. In *X v Russmedia Digital SRL* (2 December 2025), the Grand Chamber examined the responsibility of an online marketplace operator for personal data published in user advertisements and linked that analysis directly to the default-setting obligation:

This framing confirms that the accessibility dimension of Article 25(2) is not merely aspirational: controllers must configure platforms so that personal data is not publicly exposed by default. The same judgment references Article 25(1) and (2) in full at paragraph 22, anchoring the default-setting analysis in the text of both paragraphs rather than treating them as separable obligations.

At the enforcement level, the Italian Garante fined the Calabrian Regional Agency for Agricultural Development €50,000 for a remote work policy that failed to embed privacy-protective defaults, and the EDPB's Guidelines 4/2019 on Article 25 remain the principal regulatory interpretive instrument, emphasising that default settings must be configured at the point of system design, not retrofitted.

## Status of the Debate

This topic is contested in court. The CJEU's *Russmedia* ruling represents an early judicial articulation of how Article 25(2) applies to platform operators, but the boundaries — particularly what constitutes "necessary" data for a "specific purpose" when multiple processing objectives coexist within a single service — remain actively litigated. The WAMCA proceedings against Google in the Netherlands, which challenge excessive data collection and cross-service bundling, will test whether Article 25(2) imposes categorical limits on data combination by default. What would resolve the open question is a CJEU ruling addressing whether the default-setting obligation operates as an independent prohibition on over-collection or merely as a procedural safeguard to be assessed alongside Article 5(1)(c) data minimisation.

## Practical Guidance

- **Map defaults to each processing purpose individually.** Article 25(2) requires that necessity is assessed per specific purpose, not globally. Configure separate default settings for each identified purpose so that no purpose inherits data collected for another.
- **Restrict default accessibility.** Ensure that personal data is not publicly visible by default; require affirmative user action before data becomes accessible to an indefinite number of persons, as confirmed in *Russmedia* ¶89.
- **Apply the four-dimensional test.** Audit the amount of data collected, the extent of processing, the storage period, and accessibility — each must be set to the minimum necessary by default.
- **Document design decisions contemporaneously.** Recital 78 links compliance demonstration to internal policies and measures; maintain records showing why specific default settings were chosen, including state-of-the-art and cost-of-implementation considerations.
- **Use certification as evidence.** Article 25(3) permits approved certification mechanisms under Article 42 as an element demonstrating compliance — pursue certification where available for your sector to substantiate the adequacy of your default configurations.

## Legislation (full text of key provisions)

### Data protection by design and by default

*Source: GDPR, gdpr-art-25-en, 2016-04-27 — https://overview.legal/posts/90530*

### Recital 78 — data protection by design and default

*Source: GDPR, gdpr-rec-78-en, 2016-04-27 — https://overview.legal/posts/91671*

The protection of the rights and freedoms of natural persons with regard to the processing of personal data require that appropriate technical and organisational measures be taken to ensure that the requirements of this Regulation are met. In order to be able to demonstrate compliance with this Regulation, the controller should adopt internal policies and implement measures which meet in particular the principles of data protection by design and data protection by default. Such measures could consist, inter alia, of minimising the processing of personal data, pseudonymising personal data as soon as possible, transparency with regard to the functions and processing of personal data, enabling the data subject to monitor the data processing, enabling the controller to create and improve security features. When developing, designing, selecting and using applications, services and products that are based on the processing of personal data or process personal data to fulfil their task, producers of the products, services and applications should be encouraged to take into account the right to data protection when developing and designing such products, services and applications and, with due regard to the state of the art, to make sure that controllers and processors are able to fulfil their data protection obligations. The principles of data protection by design and by default should also be taken into consideration in the context of public tenders.

### Recital 69 — privacy and data protection lifecycle

*Source: AI Act, aiact-rec-69-en, 2024-06-12 — https://overview.legal/posts/93820*

The right to privacy and to protection of personal data must be guaranteed throughout the entire lifecycle of the AI system. In this regard, the principles of data minimisation and data protection by design and by default, as set out in Union data protection law, are applicable when personal data are processed. Measures taken by providers to ensure compliance with those principles may include not only anonymisation and encryption, but also the use of technology that permits algorithms to be brought to the data and allows training of AI systems without the transmission between parties or copying of the raw or structured data themselves, without prejudice to the requirements on data governance provided for in this Regulation.

### Recital 98 — Promoting encryption for electronic communications security

*Source: NIS2, nis2-rec-98-en, 2022-12-14 — https://overview.legal/posts/96724*

In order to safeguard the security of public electronic communications networks and publicly available electronic communications services, the use of encryption technologies, in particular end-to-end encryption as well as data-centric security concepts, such as cartography, segmentation, tagging, access policy and access management, and automated access decisions, should be promoted. Where necessary, the use of encryption, in particular end-to-end encryption should be mandatory for providers of public electronic communications networks or of publicly available electronic communications services in accordance with the principles of security and privacy by default and by design for the purposes of this Directive. The use of end-to-end encryption should be reconciled with the Member States’ powers to ensure the protection of their essential security interests and public security, and to allow for the prevention, investigation, detection and prosecution of criminal offences in accordance with Union law. However, this should not weaken end-to-end encryption, which is a critical technology for the effective protection of data and privacy and the security of communications.

### Recital 51 — Innovative technology for cybersecurity

*Source: NIS2, nis2-rec-51-en, 2022-12-14 — https://overview.legal/posts/96630*

Member States should encourage the use of any innovative technology, including artificial intelligence, the use of which could improve the detection and prevention of cyberattacks, enabling resources to be diverted towards cyberattacks more effectively. Member States should therefore encourage in their national cybersecurity strategy activities in research and development to facilitate the use of such technologies, in particular those relating to automated or semi-automated tools in cybersecurity, and, where relevant, the sharing of data needed for training users of such technology and for improving it. The use of any innovative technology, including artificial intelligence, should comply with Union data protection law, including the data protection principles of data accuracy, data minimisation, fairness and transparency, and data security, such as state-of-the-art encryption. The requirements of data protection by design and by default laid down in Regulation (EU) 2016/679 should be fully exploited.

### Recital 108 — appropriate safeguards for international data transfers

*Source: GDPR, gdpr-rec-108-en, 2016-04-27 — https://overview.legal/posts/91731*

In the absence of an adequacy decision, the controller or processor should take measures to compensate for the lack of data protection in a third country by way of appropriate safeguards for the data subject. Such appropriate safeguards may consist of making use of binding corporate rules, standard data protection clauses adopted by the Commission, standard data protection clauses adopted by a supervisory authority or contractual clauses authorised by a supervisory authority. Those safeguards should ensure compliance with data protection requirements and the rights of the data subjects appropriate to processing within the Union, including the availability of enforceable data subject rights and of effective legal remedies, including to obtain effective administrative or judicial redress and to claim compensation, in the Union or in a third country. They should relate in particular to compliance with the general principles relating to personal data processing, the principles of data protection by design and by default. Transfers may also be carried out by public authorities or bodies with public authorities or bodies in third countries or with international organisations with corresponding duties or functions, including on the basis of provisions to be inserted into administrative arrangements, such as a memorandum of understanding, providing for enforceable and effective rights for data subjects. Authorisation by the competent supervisory authority should be obtained when the safeguards are provided for in administrative arrangements that are not legally binding.

## Case law

### Supreme Court upholds €300,000 fine against INPS for GDPR violations in COVID bonus data

*Source: Supreme Court, 2026-05-21 — https://overview.legal/posts/53097 — original: https://gdprhub.eu/index.php?title=Cass.Civ._-_15625/2026*

Facts — Istituto nazionale della previdenza sociale (INPS, the controller) is the Italian National Institute for Social Security. In 2021, the DPA fined the controller €300,000 for its data processing activities linked to a subsidy given during the pandemic (also called “the COVID bonus”). The DPA found that the controller had postponed its second screening of verifying the eligibility of data subjects to a later stage, on the grounds that there was a need to immediately pay the subsidy. The controller considered that politicians did not fall under the scope of eligible data subjects, as they were already enrolled in a mandatory social security scheme. The controller processed their personal data from databases to cross reference them with data subjects who had applied for the subsidy. The DPA found a violation of several GDPR principles: the principle of lawfulness (Article 5(1)(a) GDPR), data minimisation (Article 5(1)(c) GDPR), accuracy (Article 5(1)(d) GDPR) and accountability (Articles 5(2) and 24 GDPR). According to the DPA, the controller had not limited the cross referencing to data subjects that had received the allowance, but to those whose applications had already been rejected. In addition, the DPA found a violation of Articles 25 and 35 GDPR, as the controller failed to conduct a data protection impact assessment (DPIA). The DPA ordered the controller to erase all personal data that had been processed unlawfully and to carry out a DPIA before resuming its processing activities. The controller appealed the decision to the Court of Rome, and argued that the DPA’s decision was unfounded. The court upheld the appeal and dismissed the DPA’s decision. The court considered that the controller had processed data subjects’ data lawfully, as it had limited the amount of data to what was necessary to verify data subjects’ eligibility. The court also considered that the processing posed a low risk for data subjects’ rights, as the data subjects’ names were not disclosed. The DPA appealed this decision to the court. Holding — The court dismissed the appeal. The court first stated that the controller processed the data lawfully under Article 6(1)(e) GDPR (public interest) and Article 6(3)(b) GDPR. While the controller processed data of specific data subjects (politicians), the court stated that national law allowed the controller to check the eligibility of all data subjects applying for the subsidy. The controller had also obtained the personal data through public databases provided by the Chambers of Parliament and Ministry of the Interior. The court also dismissed the DPA’s arguments on data minimisation (Article 5(1)(c) GDPR). The court stated that the principle of data minimisation is not absolute, and must be balanced with other interests at stake. The court took into consideration the fact that the data was publicly available and the need to quickly verify a high number of applications during a state of emergency. According to the court, there was also no other way to check applications still under review, and concluded that there was an overriding public interest in carrying out the verification process quickly. Finally, the court considered that the controller complied with Article 25 GDPR, as it processed data lawfully and in compliance with Article 5(1)(c) GDPR. In terms of data accuracy (Article 5(1)(d) GDPR), the court dismissed the DPA’s argument that the controller’s system did not eliminate the risk of “homocodes” (identical tax numbers between two or more people). The court considered that the data collected by the Chambers of Parliament and Ministry of Interior were presumed to be accurate. The court also noted that national law foresees the risk of “homocodes” and sets specific procedures in such cases, and that no actual inaccuracies were found in the controller’s verification process. Finally, the court did not find a violation of Article 35 GDPR. The court stated that the controller did not have the obligation to conduct a DPIA, as it did not meet all the necessary criteria. According to the court, the DPA failed to explain the potential high risks of large scale processing that would have justified the need for a DPIA. Given the previous dismissed arguments, the court considered that the controller had also complied with the principle of accountability (Articles 5(2) and 24 GDPR).

### Judgment of the Court (Grand Chamber) of 2 December 2025.#X v Russmedia Digital SRL and Inform Media Press SRL.#Request for a preliminary ruling from the Curtea de Apel Cluj.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 4(7) – Concept of ‘controller’ – Responsibility of the operator of an online marketplace for the publication of personal data contained in advertisements placed on its online marketplace by user advertisers – Article 5(2) –

*Source: Court of Justice of the European Union, C-492/23, 2025-12-02 — https://overview.legal/posts/132130 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0492*

In Case C-492/23, the Court of Justice of the European Union (Grand Chamber) addressed a preliminary reference from the Curtea de Apel Cluj concerning whether an online marketplace operator (Russmedia Digital SRL and Inform Media Press SRL) qualifies as a data "controller" under Article 4(7) GDPR for personal data contained in advertisements published by user advertisers. The Court examined the allocation of controller responsibility, including potential joint control with user advertisers, and analyzed whether the operator's obligations under Articles 5(2), 9, 24, 25, and 32 GDPR—including prior identification of sensitive data and advertisers, refusal of unlawful advertisements, and implementation of security measures—preclude reliance on the intermediary liability exemptions under Articles 12 to 15 of Directive 2000/31/EC (E-Commerce Directive). No fine was imposed, as the ruling is an interpretive preliminary reference rather than an enforcement action.

### French Supreme Court upholds €8M CNIL fine against Apple for App Store ad tracking

*Source: Supreme Administrative Court, 2025-10-10 — https://overview.legal/posts/122852 — original: https://gdprhub.eu/index.php?title=CE_-_473833*

Facts — The DPA imposed an €8 million administrative fine on Apple (the controller) in 2022 (CNIL - SAN-2022-025). The DPA found that Apple used identifiers stored on users’ devices to enable personalized advertising in the App Store without first obtaining valid user consent, as required by Article 82 of the French Data Protection Act, which implements Article 5(3) of the ePrivacy Directive. Apple challenged the sanction before the Supreme Administrative Court (Conseil d’État), arguing that the DPA lacked jurisdiction, that the investigation violated Apple’s procedural rights, that the advertising-related processing did not fall within the scope of Article 82, and that the case should be referred to the Court of Justice of the EU. Apple also claimed that the fine was disproportionate. Holding — The court held that reading identifiers stored on user devices for the purpose of delivering personalised advertising constitutes access to information under Article 5(3) of the ePrivacy Directive, requiring the controller to obtain the user’s prior consent. It reasoned that since this operation was to implement personalized advertising it could not fall within the exemptions to the consent requirement. The court found that the national authority was competent because the controller’s establishment within the country contributed to the advertising operations in question. It did so by marketing devices pre-equipped with the App Store where personalized advertising appears and by providing Search Ads Specialists who helped monetize and optimize that advertising space. It also rejected the controller’s claim that the authority had violated its procedural rights, finding that the right to remain silent did not apply during CNIL investigations and that the authority had lawfully carried out the investigation providing sufficient opportunity for the controller to respond. Additionally, the court rejected Apple's request to reference the case to the Court of Justice of the EU stating that there wasn't any reasonable doubt Finally, it held that the €8 million fine was proportionate, noting the scale of the processing, the number of affected users, and the economic significance of the advertising activity.

### BVwG - W 108 2284491-1

*Source: Federal Administrative Court, 2024-07-31 — https://overview.legal/posts/122850 — original: https://gdprhub.eu/index.php?title=BVwG_-_W_108_2284491-1*

Facts — The data subject visited a website operated by a media company (the controller). Upon opening the website a cookie banner showed up. This cookie banner was designed in such a way that a reject button was “hidden” in a second layer. The cookie banner’s first layer presented only an option to accept the cookies or to manage the options. The cookie manage option was presented as a link. When the data subject clicked on the accept button, they also agreed to pre-ticked options, visible only within the cookie management link. The reject button was a part of the second layer of the cookie banner (within the cookie management link). The data subject lodged a complaint with the Austrian DPA (DSB), claiming the controller violated, inter alia, Article 5(1)(a) GDPR and Article 6(1)(a) GDPR. The data subject was represented by noyb. The controller argued to the DPA that the website provided access to online newspaper articles. Because of that, the processing activities were carried for journalistic purposes and the DPA was not competent to hear the case. In the meantime the controller updated the settings of the cookie banner and introduced a reject button on its first layer, next to the accept button. Also, the link to manage the cookie settings was redesigned as a button. Moreover, the controller added a floating icon, allowing the website users to withdraw the consent given at any time. If a website user rejected the cookies or withdrew the consent via the floating icon, the controller would interpret such a conduct to be an objection under Article 21 GDPR. Additionally, the controller informed they deleted the data concerning the data subject. In response, the data subject emphasized that due to new settings of the website, the controller wrongly qualified certain cookies to be strictly necessary. In consequence, the controller installed the cookies before the website’s user interacted with the cookie banner, violating Article 5(3) ePrivacy Directive. Although the controller announced that it would implement a completely new cookie banner, they later retracted from that plan. The controller changed the cookie banner and – after improving it initially – removed the reject button again. Eventually, updated cookie banner didn’t include a reject button on the first layer any longer. The DPA issued a decision, ordering the controller to modify the cookie banner so that its first layer offered an option to close the cookie banner without giving consent. This option had to be visually equivalent to the accept button. The DPA rejected the applications of the data subject regarding the deletion of its data, an order to stop unlawful processing and establishing the violation of data confidentiality (“Recht auf Geheimhaltung”). The controller appealed the DPA’s order to introduce an equivalent reject option in the first layer of its cookie banner to the Federal Administrative Court (Bundesverwaltungsgericht – BVwG). After hearing the parties and visiting the website itself the court issued its decision. Holding — The court dismissed the appeal of the controller as unfounded. No exemption from the GDPR through media privilege (“Medienprivileg”) — The controller’s processing activities didn’t fall within the scope of journalistic purposes. The court emphasised that the controller placed the cookies and processed the collected data for analytical and advertising purposes. Need for an equivalent reject option in cookie banners — The court also upheld the interpretation of the DPA that the first layer of the cookie banner needs to contain a visually equivalent option to reject cookies. According to the court Article 7(3) GDPR implies that refusing consent shall be as easy as giving consent. In particular, refusing consent shall not require more interactions than giving consent. In the case at hand consenting required only one click, whereas rejecting consent required two clicks. Therefore no equivalence between the options was given. Furthermore, the different design of the options in the first layer – a button for consent on one hand and a link to access the second layer on the other – equally lead to the conclusion that the options cannot be considered equivalent. A mere explanation in the first layer of the cookie banner on how to reject cookies does not change this assessment. Additionally, the cookie manage link at the bottom of the website is not an equivalent option either, since it is only available after an interaction with the cookie banner. Hence, the DPA order was found to be correct. The court did not find that the controller had complied with this order in the meantime.

### Judgment of the Court (Third Chamber) of 11 April 2024.#GP v juris GmbH.#Request for a preliminary ruling from the Landgericht Saarbrücken.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 82 – Right to compensation for damage caused by data processing that infringes that regulation – Concept of ‘non-material damage’ – Impact of the seriousness of the damage suffered – Liability of the controlle

*Source: Court of Justice of the European Union, C-741/21, 2024-04-11 — https://overview.legal/posts/132262 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0741*

In Case C-741/21, the Court of Justice of the European Union (Third Chamber) addressed a preliminary reference from the Landgericht Saarbrücken in proceedings between data subject GP and juris GmbH concerning GP's claim for compensation under Article 82 GDPR after the company processed his personal data for marketing purposes despite his objections. The Court held that "non-material damage" under Article 82(1) GDPR must be interpreted broadly and is not subject to a seriousness threshold, that a controller may be exempt from liability under Article 82(3) if it proves it was not in any way responsible for the infringement (including where a person acting under its authority under Article 29 was at fault), and that the criteria for administrative fines under Article 83 GDPR do not apply to the assessment of compensation amounts.

### Data Protection Commissioner v Facebook Ireland and Maximillian Schrems

*Source: CJEU, C-311/18, 2020-07-16 — https://overview.legal/posts/51470 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0311&ref=51470*

Invalidated Privacy Shield adequacy decision and upheld validity of Standard Contractual Clauses with additional safeguards required.

### Data Protection Commissioner v. Facebook Ireland Ltd, and Maximillian Schrems

*Source: CJEU, 2020-07-16 — https://overview.legal/posts/6121 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0311&ref=6121*

“although not requiring a third country to ensure a level of protection identical to that guaranteed in the EU legal order, the term ‘adequate level of protection’ must […] be understood as requiring the third country in fact to ensure, by reason of its domestic law or its international commitments, a level of protection of fundamental rights and freedoms that is essentially equivalent to that guaranteed within the European Union by virtue of the regulation, read in the light of the Charter.

### Maximillian Schrems v Data Protection Commissioner

*Source: CJEU, C-362/14, 2015-10-06 — https://overview.legal/posts/51471 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0362&ref=51471*

Invalidated Safe Harbor adequacy decision. National supervisory authorities can examine adequacy decisions.

### Data Protection Commissioner v. Schrems and Facebook

*Source: CJEU, 2015-10-06 — https://overview.legal/posts/6146 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0362&ref=6146*

Safe harbour: US public authorities are not required to comply with safe harbor principles. Decision 2000/520 specifies that safe harbor principles may be limited to the extent necessary to meet national security, public interest or law enforcement requirements, or statute, regulation or caselaw. Self-certified US organizations receiving personal data from the EU are thus bound to disregard safe harbor principles when they conflict with US legal requirements. Decision 2000/520 does not contain s

### Judgment of the Court (Grand Chamber) of 22 November 2022.#WM and Sovim SA v Luxembourg Business Registers.#Requests for a preliminary ruling from the Tribunal d'arrondissement de Luxembourg.#Reference for a preliminary ruling – Prevention of the use of the financial system for the purposes of money laundering or terrorist financing – Directive (EU) 2018/843 amending Directive (EU) 2015/849 – Amendment to Article 30(5), first subparagraph, point (c), of Directive 2015/849 – Access for any member

*Source: Court of Justice of the European Union, C-37/20, 2022-11-22 — https://overview.legal/posts/132303 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62020CJ0037*

In Joined Cases C-37/20 and C-601/20, the Court of Justice of the European Union (Grand Chamber) addressed preliminary references from a Luxembourg court concerning WM and Sovim SA's challenge to Luxembourg Business Registers' refusal to restrict public access to their beneficial ownership information. The core issue was the validity of Article 1(15)(c) of Directive (EU) 2018/843, which amended Directive (EU) 2015/849 to require Member States to ensure public access to beneficial ownership registers, in light of Articles 7 and 8 of the EU Charter of Fundamental Rights. The Court ruled the provision invalid, holding that unconditional public access to beneficial ownership data constitutes a disproportionate interference with the fundamental rights to private life and personal data protection.

### PARLIAMENT V. COUNCIL (PNR)

*Source: CJEU, 2006-05-30 — https://overview.legal/posts/5985 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62004CJ0317*

Transfers: Where the transfers of personal data are authorized under an agreement that was adopted ultra vires, the authorization is void.

### LINDQUIST, 6.11.2003 (“LINDQUIST”)

*Source: CJEU, 2003-11-06 — https://overview.legal/posts/6197 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62007CJ0557&ref=6197*

Transfers to third countries: The publication on the internet does not constitute a transfer, as an internet user would have to connect to the internet and personally carry out the necessary actions to consult those pages where: (i) the internet pages did not contain the technical means to send that information automatically to people who did not intentionally seek access; and, (ii) the internet page is stored with his/her hosting provider in that or another Member State.  (¶¶ 60–61, 68, 70)

## Guidance

### Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020

*Source: EDPB, edpb-guidelines-on-data-protection-by-design-and-by-default, 2020-10-20 — https://overview.legal/posts/38054 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-42019-on-article-25-data-protection-by-design-and-by-default_en*

The European Data Protection Board (EDPB) adopted these guidelines (Version 2.0) to provide interpretive guidance on Article 25 of the GDPR, which mandates data protection by design and by default. The guidelines address controllers' obligations to implement appropriate technical and organizational measures and necessary safeguards into processing operations, including the dimensions of data minimization required by default. No fines or enforcement actions are at issue, as this is a guidance document intended to assist controllers in complying with their Article 25 obligations.

### EDPB Annual Report 2019

*Source: EDPB, edpb-annual-report-2019-en, 2020-05-18 — https://overview.legal/posts/126163 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-annual-report-2019_en*

EDPB Annual Report 2019 1 EDPB Annual Report 2019 1 European Data Protection Board 2019 Annual Report WORKING TOGETHER FOR STRONGER RIGHTS An Executive Summary of this report, which provides an overview of key EDPB activities in 2019, is also available. Further details about the EDPB can be found on our website at edpb.europa.eu. EDPB Annual Report 2019 EDPB Annual Report 2019 2 3 FOREWORD 1 4 MISSION STATEMENT, TASKS AND PRINCIPLES 2 5 Tasks and duties Guiding principles 5 6 2.1. 2.2 . ABOUT…

### Guidelines 1/2020 on processing personal data in the context of connected vehicles and mobility related applications

*Source: EDPB, edpb-guidelines-on-processing-personal-data-in-the-context-of-connected-vehicles-and-mobility-rel, 2020-01-01 — https://overview.legal/posts/38135*

The EDPB adopted Guidelines 1/2020 to provide guidance on the application of the GDPR to the processing of personal data in connected vehicles and mobility-related applications. The guidelines address key issues including data minimisation, data protection by design and by default, transparency obligations, data subjects' rights, security, third-party data sharing, and international transfers, with practical case studies covering services provided by third parties, eCall, accidentology, anti-theft measures, and rental car information. The document does not impose fines but offers recommendations to help controllers and processors in the automotive ecosystem comply with their GDPR obligations.

### EDPB comments on European Commission's Guidelines on Art. 28 DSA

*Source: EDPB, edpb-comments-europeancommission-article-28-dsa-en, 2025-06-25 — https://overview.legal/posts/50981 — original: https://www.edpb.europa.eu/documents/other-policy-document/edpb-comments-on-european-commissions-guidelines-on-art-28-dsa_en*

EDPB, EDPB comments on European Commission's Guidelines on Art. 28 DSA, 2025.

### EDPB-EDPS Joint Opinion 02/2023 on the Proposal for a Regulation of the European Parliament and of the Council on the establishment of the digital euro

*Source: EDPB, edpb-edps-joint-opinion-022023-on-the-proposal-for-a-regulation-of-en, 2023-10-17 — https://overview.legal/posts/125823 — original: https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-022023-on-the-proposal-for-a-regulation-of_en*

Adopted 2 Adopted 3 Executive summary Two years after the launch of the investigation phase on the issuance of a digital euro by the European Central Bank (ECB), the European Parliament and the Council of the European Union will, in the coming months, examine the Proposal for a Regulation establishing the digital euro as central bank digital currency. Having regard to the particular importance of the digital euro for the fundamental rights to privacy and to the protection of personal data, the…

### Statement 04/2022 on the design choices for a digital euro from the privacy and data protection perspective

*Source: EDPB, statement-042022-on-the-design-choices-for-a-digital-euro-en, 2022-10-10 — https://overview.legal/posts/125887 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-042022-on-the-design-choices-for-a-digital-euro_en*

1 Adopted Statement 04/2022 on the design choices for a digital euro from the privacy and data protection perspective Adopted on 10 October 2022 The European Data Protection Board has adopted the following statement: In July 2021, the European C entral B ank (ECB) decided to launch a 24 - month investigation phase for a possible digital euro, aiming at the issuance of the digital euro, if confirmed, two or three years after 1 . Given the possible h igh risks for fundamental rights and freedoms…

### Guidelines on processing of personal data through blockchain technologies

*Source: EDPB, guidelines-on-processing-of-personal-data-through-blockchain-technologies-en, 2026-07-07 — https://overview.legal/posts/125668 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-on-processing-of-personal-data-through-blockchain-technologies_en*

Guidelines 02/2025 on processing of personal data through blockchain technologies Version 2.0 Adopted on 07 July 2026 1 | Adopted Version history Version Date Adoption information version 1.1 08 April 2025 adoption of the guidelines before public consultation version 2.0 07 July 2026 adoption of the guidelines after public consultation 3 | Adopted 4 | Adopted The European Data Protection Board Having regard to Article 70 (1)(e) of the Regulation 2016/679/EU of the European Parliament and of the…

### EDPB Annual Report 2025

*Source: EDPB, edpb-annual-report-2025-en, 2026-04-09 — https://overview.legal/posts/125683 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-annual-report-2025_en*

Clarity in action: Supporting stakeholders through guidance and dialogue Annual Report 2025 Foreword 3 Highlights 4 1. The EDPB Secretariat 6 1.1 Mission And Activities 8 2. European Data Protection Board – Activities in 2025 12 2.1 Bridging Fundamental Rights and Digital Innovation Through GDPR Compliance 12 2.1.1 Helsinki high-level meeting: enhanced clarity, support and engagement 12 2.1.2 Regulation on procedural rules and Omnibus regulation on the record of processing 14 2.1.3 Cross…

## Enforcement decisions

### DSB Austria: Online shop violated GDPR by ignoring request to stop gender-specific

*Source: DSB (Austria), 2025-11-24 — https://overview.legal/posts/158460 — original: https://gdprhub.eu/index.php?title=DSB_(Austria)_-_2025-0.950.759*

Facts — On 18 September 2023, a data subject created a customer account with a public limited company operating an online shop (the controller). It allowed customers to place orders either as guests or through an optional customer account. During the registration process, the data subject's personal data was collected, including a gender-specific title. The only options provided for the title were "Mr." and "Ms.", with no option to select no title. The data subject selected “Ms.” during the registration process. The data subject then informed the controller about this situation and requested that it should refrain from using gender-specific forms of address regarding them. The controller initially assured the data subject that it would inform the relevant department. Later, the controller communicated that implementing the requested adjustment was currently not technically feasible, but that a solution was being worked on. On 14 May 2025, the data subject received a newsletter from the controller in which a gender specific salutation (specifically "Ms.") was used. On 16 May 2025, the data subject lodged a complaint with the Austrian DPA against the controller. The data subject argued that the controller had infringed their rights regarding the principles of data processing under Article 5 GDPR, the rights to rectification under Article 16 GDPR, to erasure under Article 17 GDPR and to data protection by design and by default under Article 25 GDPR. Τhe controller stated in its privacy notice that it was necessary to process customers’ personal data for registration purposes under Article 6(1)(b) GDPR. Moreover, the controller also claimed reliance on Article 6(1)(f) GDPR. During the proceedings before the DPA, the controller restructured its IT system. On 8 September 2025, the controller announced that it had implemented gender-neutral forms of address in its online shop and requested for the complaint to be dismissed. Holding — The DPA first noted that, during the proceedings, the controller had implemented the requested changes by removing gender-specific forms of address from the registration process. Since the data subject did not contest this, the DPA considered the alleged infringements of the rights to rectification and erasure to have been remedied and ended that part of the proceedings. However, it continued to examine whether the past processing had violated Article 5 GDPR and Article 25 GDPR. Regarding the processing of salutation data for the personalisation of business communications, the DPA relied on the CJEU judgment in Case C-394/23 (Mousse). In this case, the CJEU had ruled that the processing of salutation data for the personalization of business communications is neither necessary for the performance of a contract pursuant to Article 6(1)(b) GDPR nor consistent with the principle of data minimization pursuant to Article 5(1)(c) GDPR, because such processing is not required for the stated purposes. The DPA concluded that using gender-specific salutations for contract fulfilment, order processing, internal correspondence, contests, newsletters, user account registration, and delivery of goods was not strictly necessary, even under a broad interpretation. It backed this conclusion by the fact that the controller had already stopped using gender-specific salutations in direct communications, newsletters, contests, contact forms, delivery notifications, invoices, and order confirmations. The DPA therefore held that neither Article 6(1)(b) GDPR nor Article 6(1)(f) GDPR could serve as a legal basis for processing gender-specific salutations during the registration process, since the processing was not necessary. In relation to Article 6(1)(f) GDPR , the DPA accepted that the controller could in principle have a legitimate economic interest in personally addressing customers, but found that the necessity requirement was not met. The DPA found that the processing operation violated the principles of purpose limitation and data minimisation under Article 5(1)(b) GDPR and Article 5(1)(c) GDPR due to the lack of necessity of the gender-specific salutation and the availability of less intrusive alternatives. The DPA also referred to the Austrian Constitutional Court’s (Verfassungsgerichtshof) decision GZ G 77/2018, according to which a restriction to only two gender categories is incompatible with Article 8 ECHR. Regarding data protection by design and by default, the DPA held that Article 25 GDPR imposes obligations on the controller, but does not grant the data subject a subjective right to demand a specific privacy-friendly technical setting. It pointed out that while privacy-unfriendly default settings might lead to a violation of confidentiality or of the data protection principles, the data subject could not require the controller to implement specific privacy-friendly settings.

### AEPD fines El Español for disclosing minor's identity in assault video

*Source: AEPD (Spain), 2026-07-27 — https://overview.legal/posts/184546 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS-00304-2024*

Facts — El León de El Español Publicaciones, S.A., the controller, operates the Spanish digital newspaper „El Español“. It published an article concerning an assault and embedded a video showing both the victim and the assailant, who was a minor. Their image and voice were disclosed without applying techniques to prevent their direct or indirect identification. The controller also published the video through its accounts on two social media platforms. The DPA initiated preliminary investigations ex officio after becoming aware of the dissemination of the video. It ordered the controller, as a precautionary measure, to immediately remove the content from the relevant URLs. The controller subsequently informed the DPA that it had removed the article and prevented access through both external links and its internal search engine. The DPA verified that the video was no longer available through the identified web addresses. The DPA subsequently initiated disciplinary proceedings for a potential infringement of Article 5(1)(c) GDPR. The controller argued that the incident was newsworthy, the video had already gone viral and the publication was protected by freedom of information. It also claimed that the video was necessary to understand the news and that the assailant’s status as a minor should be assessed in light of his apparent maturity and awareness that he was being recorded. Holding — The DPA found that the controller violated the data minimisation principle under Article 5(1)(c) GDPR. The DPA clarified that the proceedings did not concern whether the incident was newsworthy or whether the controller could report on it. Instead, the relevant question was whether publishing the identifiable image and voice of the individuals was necessary and proportionate for that purpose. According to the DPA, freedom of information and the right to data protection are not absolute. Under Article 85 GDPR, they must be reconciled on a case-by-case basis. In this case, the controller could have informed the public about the incident while using technical measures, such as blurring the individuals’ faces or altering the audio, to prevent their identification. Showing the individuals in an identifiable manner was therefore not necessary to achieve the journalistic purpose. The DPA also rejected the argument that the previous virality of the video justified its republication. Each additional publication contributed to the further dissemination of the personal data and amplified the risks and adverse effects for the data subjects. Similarly, the fact that the affected individuals had not submitted a complaint did not prevent the DPA from exercising its supervisory powers ex officio. The DPA gave particular weight to the vulnerability of the victim and to the fact that the assailant was a minor. It held that the best interests and enhanced protection of minors had to be taken into account irrespective of the minor’s alleged maturity or awareness of being recorded. The age at which a minor may consent under Article 7 LOPDGDD did not reduce the controller’s obligation to assess whether the disclosure was necessary. The DPA further noted that, pursuant to Articles 5(2) and 25 GDPR, the controller was required to assess and document the risks of the processing and implement data protection by design and by default. As a professional media organisation regularly processing personal data, the controller was expected to apply a particularly high standard of diligence and to consider less intrusive methods of publication. When determining the sanction, the DPA considered the unrestricted online dissemination of the data, the potentially unlimited audience, the controller’s negligence, the sensitive circumstances surrounding the victim and the minor, and the impact of the infringement on the rights of a minor. It therefore imposed a €20,000 fine. Under Article 58(2)(d) GDPR, the DPA also ordered the controller to demonstrate, within three months after the decision became enforceable, that it had adopted measures to prevent the excessive publication or dissemination of personal data, particularly data concerning minors. It made the earlier precautionary measure definitive and required the permanent removal of the content, while allowing its restricted preservation where necessary as evidence for administrative, police or judicial proceedings.

### CURENERGÍA COMERCIALIZADOR DE ÚLTIMO RECURSO S.A.U.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen.

*Source: Spanish Data Protection Authority (aepd), 2025-12-22 — https://overview.legal/posts/51896*

De Spaanse gegevensbeschermingsautoriteit heeft CURENERGÍA COMERCIALIZADOR DE ÚLTIMO RECURSO S.A.U. een boete van 500.000 euro opgelegd. De verantwoordelijke partij heeft een communicatietool gebruikt die niet was ontworpen in overeenstemming met het "privacy by design"-principe. Hierdoor zijn berichten met persoonlijke gegevens, die bestemd waren voor een andere klant, in handen gekomen van een onafhankelijke derde partij.

### AEPD: Digi Telecom violated Art 6(1) GDPR by issuing duplicate SIM to impersonator

*Source: AEPD (Spain), 2026-07-13 — https://overview.legal/posts/109001 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_EXP202310345*

Facts — On December 28, 2022, DIGI Telecom, the controller, delivered a duplicate SIM card to an unauthorized third party without the consent of the original line holder (the data subject) The duplicate SIM card was delivered to an impersonator after they passed the established protocols for verifying the applicant's identity. The controller appealed the decision by the Spanish DPA to impose a fine because they claimed that they had appropriate security measures. The controller claims that, by focusing on the result, the Spanish DPA is acting under strict liability. The mere fact that identity theft occurred does not equal a lack of due diligence on the part of the controller. The controller also requested a reduction of the fine on the basis of Article 83(5)(a) GDPR because there were no aggravating circumstances and no special categories of data were processed Holding — The Spanish DPA found a violation of Article 6(1) GDPR because issuing a duplicate SIM card and delivering it to a person other than the telephone line holder constitutes the processing of personal data within the meaning of Article 4(1) GDPR without a legal basis because the data subject did not give consent. The DPA ruled that the controller violated their duty of care because the security measures lacked the dilligence required. According to Article 5(2) GDPR (principle of proactive responsibility) the controller must demonstrate compliance to the GDPR. Proactive responsibility means that the measures are compliant to the GDPR under normal circumstances. The controller must also demonstrate that the measures are compliant with the GDPR and that they are effective in the specific context and purposes of processing (Article 24 en 25 GDPR). The controller had a higher standard of care because of a documented risk to SIM swap attacks and the high scale of processing. Recital 74 GDPR states that the controller’s must implement effective and appropriate measures that take into account the nature, scope and context, and purposes of processing. The card allows an impersonator to access additional data through which they can carry out actions with grave consequences. The controller did not demonstrate that their security measures sufficiently protected the data subject. Factual circumstances should have alerted DIGI to the fraud: the SIM card replacement was processed at a physical store in a different province from where the data subject resided. The Spanish DPA flagged that the controller did not ask the reason for issuing the card and they did not verify whether the old SIM card was functioning. Therefore the security measures were not appropriate to prevent'SIM swap attacks' that are prevalent in the telecom context. With regard to to the height of the fine, the Spanish DPA found that no new legal arguments were made that would lead to the reduction of the fine.

### Italian DPA: AgID's automatic transfer of PEC addresses to INAD index unlawful

*Source: Garante per la protezione dei dati personali (Italy), 2026-05-28 — https://overview.legal/posts/122875 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_419/2026*

Facts — The data controller for the case is a government body called the Agency for Digital Italy (AgID). AgID is tasked with driving the adoption of digital technologies in both government and the private sector. Additionally, AgID is Italy’s soon-to-be notification authority for the AI Act. The case revolves around two public online indexes of certified email addresses: the INI-PEC and the INAD. INI-PEC is the older of the two indexes and includes, among others, the email addressess of professionals (the data subjects). INAD was created by AgID in 2023 as provided by Italian law and functions as an index of “digital domiciles” (where data subjects are supposed to get certain important communications) for both professionals and other owners of a digital email address. Shortly after setting up the INAD index, AgID automatically included the addresses of professionals from the old INI-PEC index. As a result, the addresses automatically became the digital domicile for communications not related to the professional lives of the data subjects. Data subjects were given the option to opt-out of the inclusion in the INAD index. Some data subjects complained that this processing severely infringed on their privacy. As the DPA’s decision explains, it is not uncommon for professionals to give co-workers access to their professional email addresses, on the assumption that they will only be used for strictly professional communications. When the addressess became digital domiciles, third parties (such as public bodies) started using them for communications unrelated to the data subjects' personal lives - which occasionally led to unintended data disclosures. The data subjects also claimed that the controller had not informed them about the processing, which prevented them from opting out in a timely fashion. Holding — The investigation — On the duty of information — First of all, the DPA clarified that by including email addresses in the INAD index, the controller further processed personal data for a new purpose, incompatible with the original purpose of the processing (i.e.: the inclusion of email addresses in the older index). With regards to the duty of information, the controller pointed out that it contacted professional orders to inform them about the creation of the INAD index. In the context of these communications, the controller asked professional orders to inform the data subjects about this processing of personal data and about their right to opt out. The controller stated that it did not directly contact the data subjects via their email addresses, as it feared that its emails would have been mistaken as phishing or scams . The controller later launched a more effective information campaign with the help of other government bodies; however, this campaign only took place in 2025 - two years after addresses where included in the INAD index. On the controller’s identity — The DPA’s investigation also focused on a second issue, relative to the authentication procedure for digital domiciles: for a long time, a company (InfoCamere S.c.p.a.) was erroneously listed as a service provider for the INAD index. During the investigation, the controller confirmed that InfoCamere had no role in the processing of personal data. The controller also stated that it had contacted the actual service provider in order to correct the error and that the provider had done so with great delay. The DPA's conclusion — The DPA held that until 2025, the controller had failed to inform the data subjects about the inclusion of their email address in the INAD index, in violation of Articles 5(1)(a), 5(1)(b), 5(2), 12, 14 and 25 GDPR. On these grounds, the DPA fined the controller €55,000. With regards to the erroneous indication of the service provider in the authentication screen, the DPA found that the mistake was isolated and that overall, the information provided during the procedure was still sufficient to clarify that AgID was the controller. On these grounds, the DPA found that the mistake did not, in and of itself, constitute a violation of the GDPR.

### Italian DPA: vehicle tracking by Liguria Health Agency lawful, information duties met

*Source: Garante per la protezione dei dati personali (Italy), 2026-05-28 — https://overview.legal/posts/53883 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_382/2026*

Facts — A data subject filed a complaint before the DPA against the Liguria Health Protection Agency (the controller). The data subject was employed by the Ligurian Social and Health Care Agency, however, the organisation was later merged with the controller. According to the data subject, the controller initiated discliplinary proceedings and suspended them based on data collected unlawfully through a tracking system in the company vehicle. The data subject also argued that the controller did not sufficiently inform employees that their location was being tracked through the company vehicles. The DPA received several complaints from other data subjects, and joined the complaints. The controller argued that the geolocation system was a measure to protect its assets, to optimise the management of its vehicles, and to ensure worker safety (e.g. to ensure that an employee followed the route while carrying hazardous materials). The controller argued that it did not process employees’ personal data, as it tracked the vehicles themselves and did not link the vehicle with the employee. Finally, the controller argued that the tracking was in compliance with its workers’ statutes. Holding — The DPA first stated that the controller had complied with its information obligations. Following the collective bargaining agreement, the controller informed data subjects of how their data was going to be processed. In addition, the controller had included a notice on how their location data was processed. Therefore, the DPA did not find a violation of Article 13 GDPR. The DPA found a violation of Article 5(1)(c) GDPR. The DPA found that the controller systematically and continuously monitored employees assigned company vehicles, as they were tracked at very frequent intervals without allowing them to deactivate the tracking. The DPA found this frequent tracking particularly detrimental to data subjects’ rights and freedoms, because the controller was able to access real-time information on vehicle movements. The DPA considered that the controller processed more data than necessary for its purposes, and that it risked processing data related to data subjects’ personal lives. The controller’s need to ensure that hazardous materials are transported safely did not justify continuously monitoring employees, especially because the controller later increased the interval of monitoring to every 15 minutes. Finally, the DPA dismissed the argument that the controller only tracked vehicles and not data subjects. This is because the controller could identify the data subject at any time by checking the logbook inside the vehicles. The DPA also found a violation of Articles 5(1)(a), (b), 6 and 88 GDPR. The DPA stated that a collective bargaining agreement was a necessary but not always sufficient condition for the data processing activities to be lawful. This means that the controller must comply with both labour and data protection legislation. Given the excessive amount of data processed, the DPA found that the controller did not have a legal basis to process this data. The DPA found that the controller also unlawfully further processed the location data of data subjects for disciplinary proceedings, in violation of the principle of purpose limitation. This is because the disciplinary proceedings did not specifically concern the data subject’s movements detected by the tracking system, but rather the data subject’s failure to notify potentially dangerous situations that occurred during the performance of their duties. Finally, the DPA found a violation of Articles 25 and 35 GDPR. The DPA found that the controller failed to choose a less invasive solution during the design phase. Therefore, its processing activities did not meet the requirements of privacy by design and default (Article 25 GDPR). The controller violated Article 35 GDPR by not conducting a data protection impact assessment (DPIA) before processing data subjects’ location data. The controller’s awareness of data protection issues and evidence of introducing measures to protect data subjects was not sufficient to meet this requirement. The DPA fined the controller €6,000. The DPA took into consideration the changes the controller had made during its investigations, including adjusting the interval of tracking vehicles from every 60 seconds to every 15 minutes

### Italian DPA sanctions Lusha Systems for processing contact data without consent in B2B

*Source: Garante per la protezione dei dati personali (Italy), 2026-07-14 — https://overview.legal/posts/184678 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_542/2026*

Facts — Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database. It was an US company wholly owned by Lusha Systems Ltd. In April 2025, the Italian DPA (Garante) initiated an investigation after media reports revealed that telephone numbers of senior Italian officials were available on the platform. The DPA later received one complaint and one report from data subjects who had received unsolicited advertising communications. The data subjects further stated that after requesting information about the source of their contact details, they discovered that their data were available on the controller’s platform without their consent. The controller explained that, for a subscription fee, it provided its Clients with a Business Contact Card for each Contact. The controller further distinguished between “Clients”, namely customers who used the platform and accessed its B2B database, and “Contacts”, namely the individuals whose personal data were included in that database, regardless of whether they used or were aware of the platform. Clients received Contact Cards containing information such as names, professional email addresses, telephone numbers, job titles, roles and locations, which could be used for sales, marketing, recruitment, business intelligence and fraud prevention. The DPA limited its investigation to the processing of Contacts’ personal data. The controller stated that it collected and combined data from publicly available sources, specialised providers, affiliated companies and commercial partners. It also inferred missing professional email addresses through algorithms that identified standard company email patterns. Through its Community Program and integrations with email, calendar and CRM services, it could also obtain information from Clients’ professional networks and communications. The data were cross-referenced, enriched and regularly updated to reflect changes in Contacts’ professional circumstances. The controller argued that the GDPR did not apply because it was established outside the EU and provided services only to businesses. It additionally claimed that the weekly updating of Contact Cards ensured accuracy rather than constituting monitoring or profiling. The controller maintained that the collection and disclosure of the data were necessary for its own economic interest in providing accurate professional contact information and for its Clients’ interests, including fraud prevention. According to the controller, it processed only a limited range of information concerning the Contacts’ professional lives. It further claimed that individuals who made professional information publicly available, particularly through services such as LinkedIn, could reasonably expect that the information might be reused and that they could be contacted regarding professional opportunities. Regarding transparency, the controller stated that its Personal Information Notice was sent to each Contact before their information became available in the database. It explained that it notified Contacts that they had a seven-day period during which they could opt out before their information became available to Clients. The controller also maintained that excluding public officials and public figures from the database was not a requirement under the GDPR. It attributed the presence of certain public officials to technical limitations in its filtering system. It also argued that public figures had a lower expectation of privacy. After the proceedings began, the controller removed profiles connected with Italian public bodies and officials, strengthened its filters and customer-verification measures, discontinued the Community Program in Italy and extended the opt-out period to fourteen days. Holding — Regarding the territorial scope of the GDPR, the DPA acknowledged that Article 3(2)(a) GDPR could apply to the processing of Clients’ data, but not to Contacts, since they were not recipients of the service. However, it held that Article 3(2)(b) GDPR applied because the controller systematically combined, enriched and updated Contacts’ professional information in order to assess their circumstances and determine whether and how they would appear in the database. Referring to Recital 24 and Recital 30, the DPA held that monitoring did not require profiling. It noted that the systematic observation of online traces and changes in a person’s professional situation was sufficient. The fact that the processing also served data accuracy did not alter that conclusion. It emphasised that the fact that the controller also updated the information to ensure its accuracy did not prevent the processing from constituting monitoring. Regarding transparency, the DPA found that the information concerning the collection of the Contacts’ data, the purposes of the processing and the legal basis relied upon was scattered across several documents. Also, the relevant information was not easily accessible from the controller’s homepage, while the Personal Information Notice could not be located directly through the website without prior knowledge of its existence. It further pointed out that the documents were provided in English rather than in the language of the affected data subjects. The DPA held that presenting the information in this manner did not satisfy the requirement that information be concise, transparent, intelligible and easily accessible. It therefore found an infringement of Article 5(1)(a) GDPR and Article 12 GDPR. Moreover, the DPA assessed whether Article 6(1)(f) GDPR provided a valid legal basis for the processing. It examined the controller’s Legitimate Interest Assessment and considered it essentially non-existent, as it contained only generic statements on necessity and proportionality and no genuine balancing assessment. The DPA then applied the three-part test under Article 6(1)(f) GDPR. It held that making the Contacts’ data available to Clients for their own marketing and sales activities could not constitute a legitimate interest, since the disclosure of contact information to third parties for their independent advertising purposes required prior consent under the applicable national and ePrivacy framework . However, it acknowledged that the controller’s interest in fraud prevention could be considered legitimate. The DPA nevertheless found that the processing was not necessary for the purposes pursued. It held that the controller collected information extending beyond ordinary professional contact details, including third-party data contained in CRM databases, email headers and subject lines, information about calendar meetings, and browsing data collected through browser extensions or other software integrations used by Clients. It pointed out that much of this information was not publicly available but was extracted from private interpersonal communications, disclosed by Clients, obtained through integrations with information systems or acquired from third-party providers. The DPA held that the collection and combination of such extensive information was neither strictly necessary nor proportionate for creating professional Contact Cards. Furthermore, it stressed that fraud prevention could also have been achieved through less intrusive means. The DPA therefore concluded that the necessity requirement and the principle of data minimisation were not met. Regarding the balancing test, the DPA emphasised that there was no prior relationship between the controller and the Contacts. Creating a professional profile on LinkedIn or another professional platform did not create a reasonable expectation that unpublished contact details would be collected from multiple sources, continuously updated and disclosed to an unspecified number of paying customers. It further noted that the processing could expose Contacts to communications from unknown third parties for purposes they could not reasonably anticipate. The DPA concluded that the Contacts’ interests, rights and freedoms prevailed over the controller’s economic interests and that the safeguards adopted by the controller could not change this outcome. Therefore, the DPA held that Article 6(1)(f) GDPR did not provide an appropriate legal basis and found that the controller infringed Article 5(1)(a) GDPR, Article 5(1)(c) GDPR, and Article 6 GDPR. Regarding public officials, the DPA held that their status did not reduce their entitlement to data protection and that no public interest justified disclosing their direct contact details for commercial purposes. The DPA further found that the controller had been aware of the risk that public officials could be included in its database but had failed to implement sufficiently effective technical and organisational measures. Its filters recognised general titles such as “President” but failed to exclude more specific titles such as “President of the Italian Republic” and “Vice Prime Minister”. The DPA therefore found an infringement of the principle of data minimisation under Article 5(1)(c) GDPR and the obligation of data protection by design and by default under Article 25 GDPR. The DPA imposed a fine of €2,000,000. Furthermore, it prohibited any further processing of personal data of data subjects located in Italy that had been collected without an adequate legal basis and ordered their deletion.

### AEPD (Spain) - EXP202306354 (PS/00312/2024)

*Source: AEPD (Spain), 2026-02-11 — https://overview.legal/posts/52464 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_EXP202306354_(PS/00312/2024)*

Facts — The Spanish Data Protection Agency (AEPD) investigated Vodafone España, S.A.U. as controller after a SIM swapping incident. On 21 September 2021, an unknown third party requested a duplicate SIM card for the mobile line of a data subject. The request was made through Vodafone’s internal telephone support channel for retail stores. The caller impersonated staff and provided several data elements, including the store user code, the data subject’s identification number, the mobile phone number and digits of the ICC number of the new SIM card. Vodafone processed the request and activated the duplicate SIM card. On the same day, the data subject’s phone stopped working. Shortly afterwards, four unauthorised transactions totalling €1,996 were carried out from their bank account. The data subject contacted Vodafone, their bank and the police. Vodafone confirmed that a duplicate SIM card had been issued through a physical point of sale. After the data subject presented a complaint, during the investigation, Vodafone explained that its internal policy required store staff to call a dedicated support channel and provide identifying information before a duplicate SIM could be issued. Vodafone stated that the fraudster had provided the required information and that the security protocol in force at the time had been followed. The controller also informed the AEPD that it later adopted additional measures to reinforce the security of the duplicate SIM procedure. On the basis of these facts, the AEPD opened sanctioning proceedings against Vodafone for an alleged infringement of Article 6(1) GDPR. Holding — The AEPD found that Vodafone infringed Article 6(1) GDPR by processing the personal data of the data subject without a valid legal basis. The AEPD held that the issuance and activation of a duplicate SIM card involved the processing of personal data. Vodafone carried out this processing without the knowledge or consent of the data subject and without any other legal basis under Article 6(1) GDPR. As a result, the processing was unlawful. The AEPD rejected the controller’s argument that it had complied with its internal security protocols. The DPA stated that the existence of internal procedures did not remove the obligation to ensure that processing had a valid legal basis. The intervention of a criminal third party did not exempt the controller from responsibility where the unlawful processing occurred within its own systems and procedures. The AEPD considered that Vodafone acted at least negligently. It took into account the nature of the infringement and the link between the processing and the controller’s core business activity. The DPA imposed an administrative fine of €150,000 on Vodafone for the infringement of Article 6(1) GDPR.

## Recent developments

### ICO: How can Privacy Enhancing Technologies help with data protection compliance?

*Source: ICO, 2025-11-07 — https://overview.legal/posts/6334 — original: https://ico.org.uk/media/about-the-ico/consultations/4021464/chapter-5-anonymisation-pets.pdf#entry-362*

> How can PETs help with data protection compliance?
At a glance
• PETs can help you demonstrate a ‘data protection by design and by
default’ approach to your processing.
• PETs can help you to comply with the data minimisation principle by
ensuring you only process the data you need for your purposes, and
provide an appropriate level of security for your processing.
• You can use PETs to give access to datasets which would otherwise be
too sensitive to share, while ensuring individuals’ data is

### What Happened to the Risk-Based Approach to Data Transfers?

*Source: Future of Privacy Forum, 2022-09-27 — https://overview.legal/posts/6271 — original: https://fpf.org/blog/what-happened-to-the-risk-based-approach-to-data-transfers/#entry-912*

The GDPR incorporates the RBA for all obligations of the controller in the GDPR. Where the transfer rules are stated as obligations of the controller (rather than as absolute principles), the RBA of Article 24 therefore applies. Other than the DPAs assume, this is not contradicted by the ECJ in Schrems II nor by the EDPB recommendations on additional measures following the Schrems II judgment, according to Lokke Moerel, Professor of Global ICT Law at Tilburg University and a Dutch Cyber Security

### The 2022 annual report of the CNIL

*Source: CNIL, 2023-05-23 — https://overview.legal/posts/6201 — original: https://www.cnil.fr/en/2022-annual-report-cnil#entry-5292*

The publication of its activity report enables the CNIL to report on its actions with regard to its four major missions: inform and protect the general public, accompany and advise professionals and public authorities, anticipate and innovate to build the digital of tomorrow, and finally monitor and sanction breaches of the General Data Protection Regulation (GDPR) and the French law.
 



 


Download the 2022 annual report (in French)
Informing and protecting
The actions carried out this year

### DeFine is a calculator for GDPR fines based on method of the EDPB

*Source: Kromann Reumert, 2022-02-01 — https://overview.legal/posts/6310 — original: https://www.khlaw.com/define#entry-14*

> DeFine is a translation into a calculator of part of the methodology proposed by the European Data Protection Board to calculate GDPR fines (see EDPB, Guidelines 04/2022 on the calculation of administrative fines under the GDPR, 12 May 2022, available online; it was subject to a public consultation until 27 June 2022).

### “Social media profiles and phone contacts” used as proof of identity for deportations

*Source: European Digital Rights, 2023-03-29 — https://overview.legal/posts/6226 — original: https://edri.org/our-work/social-media-profiles-and-phone-contacts-used-as-proof-of-identity-for-deportations/#entry-4248*

> 
					Thirteen non-EU countries sometimes accept “social media profiles and phone contacts” as evidence of identity for the purpose of deportations, according to an internal European Commission assessment of third country cooperation on readmission.

## Literature

### Implementing a by design and by default approach

*Source: Journal of Data Protection Privacy, 2019-07-01 — https://overview.legal/posts/132574 — original: https://doi.org/10.69554/oynn8092*

Building upon the concept of privacy by design, security and data protection by design and by default are important obligations within the General Data Protection Regulation (GDPR) and associated national legislation. This paper seeks to summarise some practical approaches to develop effective capability to deliver by design requirements: (1) a whole project lifecycle design approach; (2) a contextual riskbased approach; (3) the use of goals and principles approach; and (4) integration of safegu

### PROTECTION OF DATA SUBJECT RIGHTS IN THE TRANSFER OF PERSONAL DATA BETWEEN DATA CONTROLLERS IN INDONESIA: A COMPARATIVE ANALYSIS OF THE PDP LAW AND THE EU GDPR

*Source: Awang Long Law Review, 2026-01-16 — https://overview.legal/posts/132506 — original: https://doi.org/10.56301/awl.v8i2.1827*

The rapid digital transformation and growth of e-commerce in Indonesia have triggered a high volume of personal data transfers between controllers. while Article 55 of the Personal Data Protection Law (UU PDP) provides only a general authorization without clear technical guidance, creating legal uncertainty and risks to data subject rights. This study analyzes the legal uncertainty of UU PDP’s regulation of controller-to-controller data transfers compared to the EU GDPR and proposes an accountab

### Unprotected Processing by Default vs Data Protection by Design and by Default Under the GDPR for Schrems II and GDPR

*Source: SSRN Electronic Journal, 2022-01-01 — https://overview.legal/posts/132477 — original: https://doi.org/10.2139/ssrn.4018408*

### If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation

*Source: Computer law & security review, 2026-01-23 — https://overview.legal/posts/53843 — original: https://doi.org/10.1016/j.clsr.2025.106251*

As the General Data Protection Regulation (GDPR) approaches its tenth anniversary, the European legislator is considering reforms thereto. This article offers a set of research-based suggestions for what such reforms could look like, based on two assumptions. First, that the GDPR is overall a solid piece of legislation that upholds the enduring objectives and principles of data protection law. Second, that any improvement cannot compromise the level of protection of fundamental rights currently

### Effective Regulation through Design – Aligning the ePrivacy Regulation with the EU General Data Protection Regulation (GDPR): Tracking Technologies in Personalised Internet Content and the Data Protection by Design Approach

*Source: SSRN Electronic Journal, 2021-01-01 — https://overview.legal/posts/132422 — original: https://doi.org/10.2139/ssrn.3945471*

## Related topics

- **Privacy by Design** — https://overview.legal/topics/privacy-by-design
  Embedding data protection into system design from the outset
- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Privacy by Design & Default** — https://overview.legal/topics/data-protection-by-design-default-article-25
  This topic is essential as it specifically addresses Article 25 GDPR requirements for implementing data protection principles through design and default setting
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Accountability** — https://overview.legal/topics/accountability
  Principle of demonstrating GDPR compliance
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing

---
Generated by overview.legal · https://overview.legal/topics/privacy-by-default · 2026-08-22
