# Processors — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/processors
> Sources are cited per item. Verify against the official texts before relying on them.

Entities that process data on behalf of controllers

## Overview

## Legal Framework

Processors—entities that process personal data on behalf of controllers—are brought within the GDPR's scope primarily through [Article 3](/laws/gdpr/art-3), which establishes territorial jurisdiction over both controllers and processors established in the Union. Article 3(2) extends that reach to processors outside the EU that offer goods or services to, or monitor the behaviour of, data subjects in the Union. For such non-EU processors, [Article 27](/laws/gdpr/art-27) imposes a mandatory designation of an in-Union representative, though this mechanism does not insulate the processor from direct legal action:

> "The designation of a representative by the controller or processor shall be without prejudice to legal actions which could be initiated against the controller or the processor themselves."
> — [GDPR Art. 27(5)](/laws/gdpr/art-27#par-5)

Article 23 permits Union or Member State law to restrict the scope of certain processor obligations—covering Articles 12 to 22 and Article 34—where restrictions respect the essence of fundamental rights and are necessary and proportionate in a democratic society. The definitions in [Article 4](/laws/gdpr/art-4) establish the breadth of "processing" that triggers processor status, encompassing operations from collection through erasure. The core obligations for processors are set out in Article 28, which requires written data processing agreements, imposes direct security duties, and governs sub-processor engagement—particularly relevant in cloud computing environments where providers routinely subcontract hosting and server capacity.

## Key Developments

The Court of Justice in *Schrems II* confirmed that both controllers and processors bear obligations under Chapter V for international transfers, emphasising that the GDPR's protection level must not be undermined:

> "Alle bepalingen van dit hoofdstuk worden toegepast opdat het door deze verordening voor natuurlijke personen gewaarborgde beschermingsniveau niet wordt ondermijnd."
> — [Schrems II ¶12](/posts/1#seg-12)

The EDPB's Guidelines 01/2021 further clarified that processors share practical breach-management responsibilities alongside controllers:

> "Every controller and processor should have plans, procedures in place for handling eventual data breaches."
> — [EDPB Guidelines 01/2021 §11](/posts/38047#seg-11)

Enforcement reinforces this: the AEPD's €200,000 fine against Alkora following a ransomware attack illustrates that DPAs scrutinise processor security measures and incident response capabilities in practice.

## Status of the Debate

The processor regime is actively contested in court. Courts diverge on the boundaries of processor obligations—particularly around sub-processor chains, cloud computing arrangements, and the allocation of liability between controllers and processors. The EDPB's Opinion 22/2024 on processor and sub-processor obligations signals ongoing regulatory effort to clarify these boundaries, but no definitive CJEU ruling has yet resolved how far processor accountability extends into complex sub-processing chains. Resolution will likely require CJEU guidance on the scope of Article 28, particularly whether processors bear independent duties of care or remain purely derivative of controller instructions.

## Practical Guidance

- Designate an EU representative under [Article 27](/laws/gdpr/art-27) if your processing falls within [Article 3(2)](/laws/gdpr/art-3#par-2); ensure the written mandate covers all processing-related queries from supervisory authorities and data subjects.
- Maintain documented breach response plans and internal reporting lines, as both controllers and processors face explicit expectations under the GDPR framework.
- Conduct regular staff training on breach identification and response, as the EDPB considers this essential for processors, not merely controllers.
- Ensure sub-processor arrangements flow down equivalent contractual obligations, particularly in cloud contexts where hosting and shared server subcontracting is standard practice.
- Verify that international transfers by processors comply with Chapter V safeguards, as *Schrems II* confirmed that processors bear transfer obligations alongside controllers.

## Legislation (full text of key provisions)

### Processor

*Source: GDPR, gdpr-art-28-en, 2016-04-27 — https://overview.legal/posts/90560*

### Processing under the authority of the controller or processor

*Source: GDPR, gdpr-art-29-en, 2016-04-27 — https://overview.legal/posts/90592*

The processor and any person acting under the authority of the controller or of the processor, who has access to personal data, shall not process those data except on instructions from the controller, unless required to do so by Union or Member State law.

### General principle for transfers

*Source: GDPR, gdpr-art-44-en, 2016-04-27 — https://overview.legal/posts/90853*

Any transfer of personal data which are undergoing processing or are intended for processing after transfer to a third country or to an international organisation shall take place only if, subject to the other provisions of this Regulation, the conditions laid down in this Chapter are complied with by the controller and processor, including for onward transfers of personal data from the third country or an international organisation to another third country or to another international organisation. All provisions in this Chapter shall be applied in order to ensure that the level of protection of natural persons guaranteed by this Regulation is not undermined.

### Right to an effective judicial remedy against a controller or processor

*Source: GDPR, gdpr-art-79-en, 2016-04-27 — https://overview.legal/posts/91344*

### Cooperation with the supervisory authority

*Source: GDPR, gdpr-art-31-en, 2016-04-27 — https://overview.legal/posts/90617*

The controller and the processor and, where applicable, their representatives, shall cooperate, on request, with the supervisory authority in the performance of its tasks.

### Transfers or disclosures not authorised by Union law

*Source: GDPR, gdpr-art-48-en, 2016-04-27 — https://overview.legal/posts/90925*

Any judgment of a court or tribunal and any decision of an administrative authority of a third country requiring a controller or processor to transfer or disclose personal data may only be recognised or enforceable in any manner if based on an international agreement, such as a mutual legal assistance treaty, in force between the requesting third country and the Union or a Member State, without prejudice to other grounds for transfer pursuant to this Chapter.

### Recital 81 — processor guarantees and contract requirements

*Source: GDPR, gdpr-rec-81-en, 2016-04-27 — https://overview.legal/posts/91677*

To ensure compliance with the requirements of this Regulation in respect of the processing to be carried out by the processor on behalf of the controller, when entrusting a processor with processing activities, the controller should use only processors providing sufficient guarantees, in particular in terms of expert knowledge, reliability and resources, to implement technical and organisational measures which will meet the requirements of this Regulation, including for the security of processing. The adherence of the processor to an approved code of conduct or an approved certification mechanism may be used as an element to demonstrate compliance with the obligations of the controller. The carrying-out of processing by a processor should be governed by a contract or other legal act under Union or Member State law, binding the processor to the controller, setting out the subject-matter and duration of the processing, the nature and purposes of the processing, the type of personal data and categories of data subjects, taking into account the specific tasks and responsibilities of the processor in the context of the processing to be carried out and the risk to the rights and freedoms of the data subject. The controller and processor may choose to use an individual contract or standard contractual clauses which are adopted either directly by the Commission or by a supervisory authority in accordance with the consistency mechanism and then adopted by the Commission. After the completion of the processing on behalf of the controller, the processor should, at the choice of the controller, return or delete the personal data, unless there is a requirement to store the personal data under Union or Member State law to which the processor is subject.

### Recital 95 — processor assistance with DPIA and prior consultation

*Source: GDPR, gdpr-rec-95-en, 2016-04-27 — https://overview.legal/posts/91705*

The processor should assist the controller, where necessary and upon request, in ensuring compliance with the obligations deriving from the carrying out of data protection impact assessments and from prior consultation of the supervisory authority.

### Recital 36 — main establishment of controller and processor

*Source: GDPR, gdpr-rec-36-en, 2016-04-27 — https://overview.legal/posts/91587*

The main establishment of a controller in the Union should be the place of its central administration in the Union, unless the decisions on the purposes and means of the processing of personal data are taken in another establishment of the controller in the Union, in which case that other establishment should be considered to be the main establishment. The main establishment of a controller in the Union should be determined according to objective criteria and should imply the effective and real exercise of management activities determining the main decisions as to the purposes and means of processing through stable arrangements. That criterion should not depend on whether the processing of personal data is carried out at that location. The presence and use of technical means and technologies for processing personal data or processing activities do not, in themselves, constitute a main establishment and are therefore not determining criteria for a main establishment. The main establishment of the processor should be the place of its central administration in the Union or, if it has no central administration in the Union, the place where the main processing activities take place in the Union. In cases involving both the controller and the processor, the competent lead supervisory authority should remain the supervisory authority of the Member State where the controller has its main establishment, but the supervisory authority of the processor should be considered to be a supervisory authority concerned and that supervisory authority should participate in the cooperation procedure provided for by this Regulation. In any case, the supervisory authorities of the Member State or Member States where the processor has one or more establishments should not be considered to be supervisory authorities concerned where the draft decision concerns only the controller. Where the processing is carried out by a group of undertakings, the main establishment of the controlling undertaking should be considered to be the main establishment of the group of undertakings, except where the purposes and means of processing are determined by another undertaking.

### Recital 80 — non-EU controller processor representative requirement

*Source: GDPR, gdpr-rec-80-en, 2016-04-27 — https://overview.legal/posts/91675*

Where a controller or a processor not established in the Union is processing personal data of data subjects who are in the Union whose processing activities are related to the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union, or to the monitoring of their behaviour as far as their behaviour takes place within the Union, the controller or the processor should designate a representative, unless the processing is occasional, does not include processing, on a large scale, of special categories of personal data or the processing of personal data relating to criminal convictions and offences, and is unlikely to result in a risk to the rights and freedoms of natural persons, taking into account the nature, context, scope and purposes of the processing or if the controller is a public authority or body. The representative should act on behalf of the controller or the processor and may be addressed by any supervisory authority. The representative should be explicitly designated by a written mandate of the controller or of the processor to act on its behalf with regard to its obligations under this Regulation. The designation of such a representative does not affect the responsibility or liability of the controller or of the processor under this Regulation. Such a representative should perform its tasks according to the mandate received from the controller or processor, including cooperating with the competent supervisory authorities with regard to any action taken to ensure compliance with this Regulation. The designated representative should be subject to enforcement proceedings in the event of non-compliance by the controller or processor.

## Case law

### SG Nürnberg - S 5 SF 65/24 DS

*Source: Social Court Nuremberg, 2026-06-10 — https://overview.legal/posts/122874 — original: https://gdprhub.eu/index.php?title=SG_Nürnberg_-_S_5_SF_65/24_DS*

Facts — The data subject (a child born in 2018), represented by her parents, was insured with the controller (a statutory health insurance provider) and participated in its digital bonus programme. The bonus programme was managed via an app. To handle the information technology operations of this programme, the controller hired the processor (an IT service provider), establishing a data processing agreement under Article 28 GDPR alongside specific information security guidelines. To provide these services, the processor utilised "MOVEit Transfer," a market-leading file transfer software developed by Progress Software Corp. On 31 May 2023, the software developer publicly announced a critical, previously unknown "zero-day" vulnerability in the software (later assigned CVE-2023-34362). At that exact moment, no security patch was available. On the very same day, 31 May 2023, the processor – alongside thousands of other companies worldwide – became the victim of a global cyberattack carried out by the hacker group "Clop." The hackers exploited this zero-day vulnerability to install a "web-shell" backdoor (typically named human2.aspx), bypassing authentication to exfiltrate database records. The compromised data included the data subject's first and last name, health insurance number, bonus points balance, and a bank account number (IBAN) belonging to her mother. No medical, health, or social security data was exfiltrated. On 1 June 2023, the developer released a security patch, which the processor installed immediately. On 2 June 2023, the German Federal Office for Information Security (BSI) issued a formal IT security warning (No. 2023-240133-1100, Version 1.1). The BSI classified the IT threat level as "3 / Orange" (business-critical), confirming active exploitation with data exfiltration. The BSI recommended immediately blocking all HTTP and HTTPS traffic to MOVEit environments, checking for specific Indicators of Compromise (IoCs) in the web server directories, and applying the newly released patch before reconnecting systems to the network. On 16 June 2023, the processor informed the controller about the incident. On 17 June 2023, the controller issued a public press release confirming that its external service provider for the bonus programme had been targeted on 31 May 2023. The release stated that the security vulnerability had been closed, that there was never any connection to the controller's internal IT systems, and that relevant supervisory authorities had been notified. The controller subsequently notified the data subject's parents. On 27 March 2024, the data subject, via legal counsel, sent a formal warning letter to the controller demanding an injunction, a declaration of liability for all potential future damages, and non-material damages of at least €3,000. Following the controller's refusal, the data subject filed a lawsuit with the Nuremberg Social Court (Sozialgericht Nürnberg), later expanding the claim to the processor as a joint defendant. Holding — The Court dismissed the lawsuit as partly inadmissible and otherwise unfounded, establishing the following legal principles: First, the Court held that a successful third-party cyberattack does not establish an irrebuttable presumption that a controller or processor failed to implement appropriate security measures under Article 32(1) GDPR and Article 5(1)(f) GDPR. To escape liability under Article 82(3) GDPR, an operator must prove they implemented robust baseline security controls (such as multi-factor authentication, encryption, and lockout policies) and applied a security patch immediately upon its release by the vendor, even if this occurred before formal alerts were issued by national IT security authorities. Second, the Court held that a claim for non-material damages under Article 82(1) GDPR based on the fear or distress of future data misuse cannot be established if the data subject is a minor who has no subjective knowledge or cognitive awareness of the data breach. Furthermore, if the compromised financial data (such as an IBAN) does not belong to the data subject personally, there is no direct risk of financial harm to them, rendering the alleged fear of financial damage unfounded. Third, the Court held that an injunction claim is inadmissible due to a lack of specificity if it merely demands that a controller stop making personal data accessible to third parties without implementing "state-of-the-art" security measures, without specifying the concrete technical or organisational measures the controller is required to take. Fourth, the Court held that a declaratory claim for potential future material damages is inadmissible under national procedural law (§ 55(1) SGG) if there is no realistic probability of future financial harm, particularly because the compromised bank account belonged to a third party (the mother) and the software vulnerability was immediately patched.

### Judgment of the Court (First Chamber) of 27 February 2025.#CK v Magistrat der Stadt Wien.#Request for a preliminary ruling from the Verwaltungsgericht Wien.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 15(1)(h) – Automated decision-making, including profiling – Scoring – Assessment of the creditworthiness of a natural person – Access to meaningful information about the logic involved in profiling – Verification of the accuracy of the infor

*Source: Court of Justice of the European Union, C-203/22, 2025-02-27 — https://overview.legal/posts/132146 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0203*

In Case C-203/22, the Court of Justice of the European Union interpreted Article 15(1)(h) of the GDPR in response to a preliminary ruling from the Verwaltungsgericht Wien concerning an individual's request for meaningful information about the logic of creditworthiness scoring conducted by Dun & Bradstreet Austria GmbH. The Court held that data subjects must receive sufficiently detailed explanations of the logic involved in automated profiling to understand how the decision was reached, while controllers may withhold information protected by trade secrets under Directive (EU) 2016/943 only insofar as such withholding does not render the information provided meaningless. The Court further clarified that data subjects may not use access rights to obtain personal data of third parties or to verify the absolute accuracy of the underlying information processed.

### Judgment of the Court (Fourth Chamber) of 11 July 2024.#Meta Platforms Ireland Limited v Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband e.V.#Request for a preliminary ruling from the Bundesgerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – First sentence of Article 12(1) – Transparency of information – Article 13(1)(c) and (e) – Obligation o

*Source: Court of Justice of the European Union, C-757/22, 2024-07-11 — https://overview.legal/posts/132250 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0757*

In a preliminary ruling requested by the German Federal Court of Justice (Bundesgerichtshof), the Court of Justice of the European Union interpreted Article 80(2) GDPR in the context of proceedings between Meta Platforms Ireland Ltd and the Bundesverband der Verbraucherzentralen und Verbraucherverbände (Consumer Association). The core issue is whether a consumer protection association may bring a representative action under Article 80(2) GDPR without a mandate from specific data subjects and independently of an actual infringement of a data subject's rights, based on a controller's alleged violation of its transparency obligations under Articles 12(1) and 13(1)(c) and (e). The Court held that such an action is permissible, finding that an infringement of the controller's information obligations constitutes an "infringement of the rights of data subjects as a result of the processing" within the meaning of Article 80(2), and that Member States may allow representative actions without requiring a specific data subject's mandate or an actual infringement of individual rights.

### Judgment of the Court (Grand Chamber) of 7 May 2024.#SO.#Request for a preliminary ruling from the Unabhängige Schiedskommission Wien.#Reference for a preliminary ruling – Admissibility – Article 267 TFEU – Concept of ‘court or tribunal’ – National arbitration committee competent to combat doping in sport – Criteria – Independence of the body making the reference – Principle of effective judicial protection – Inadmissibility of the request for a preliminary ruling.#Case C-115/22.

*Source: Court of Justice of the European Union, C-115/22, 2024-05-07 — https://overview.legal/posts/132258 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0115*

The Court of Justice of the European Union (Grand Chamber) ruled on a preliminary ruling request from the Unabhängige Schiedskommission Wien concerning the interpretation of GDPR Articles 5, 6, 9, and 10 in the context of NADA's decision to publish anti-doping sanctions against athlete SO. The Court found the request inadmissible because the national anti-doping arbitration committee does not qualify as a "court or tribunal" under Article 267 TFEU, as it lacks the requisite independence and does not provide effective judicial protection. No fine was imposed.

### Judgment of the Court (Third Chamber) of 11 April 2024.#GP v juris GmbH.#Request for a preliminary ruling from the Landgericht Saarbrücken.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 82 – Right to compensation for damage caused by data processing that infringes that regulation – Concept of ‘non-material damage’ – Impact of the seriousness of the damage suffered – Liability of the controlle

*Source: Court of Justice of the European Union, C-741/21, 2024-04-11 — https://overview.legal/posts/132262 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0741*

In Case C-741/21, the Court of Justice of the European Union (Third Chamber) addressed a preliminary reference from the Landgericht Saarbrücken in proceedings between data subject GP and juris GmbH concerning GP's claim for compensation under Article 82 GDPR after the company processed his personal data for marketing purposes despite his objections. The Court held that "non-material damage" under Article 82(1) GDPR must be interpreted broadly and is not subject to a seriousness threshold, that a controller may be exempt from liability under Article 82(3) if it proves it was not in any way responsible for the infringement (including where a person acting under its authority under Article 29 was at fault), and that the criteria for administrative fines under Article 83 GDPR do not apply to the assessment of compensation amounts.

### VB v Natsionalna agentsia za prihodite

*Source: CJEU, C-340/21, 2023-12-14 — https://overview.legal/posts/51485 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0340*

Data breach alone does not establish inadequate security measures. Burden on controller to prove adequacy.

### Meta Platforms and Others v Bundeskartellamt

*Source: CJEU, C-601/21, 2023-07-04 — https://overview.legal/posts/51482 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0601*

Competition authorities can assess GDPR compliance in context of competition law proceedings.

### Judgment of the Court (First Chamber) of 22 June 2023.#Proceedings brought by J.M.#Request for a preliminary ruling from the Itä-Suomen hallinto-oikeus.#Reference for a preliminary ruling – Processing of personal data – Regulation (EU) 2016/679 – Articles 4 and 15 – Scope of the right of access to information referred to in Article 15 – Information contained in log data – Article 4 – Definition of ‘personal data’ – Definition of ‘recipients’ – Temporal application.#Case C-579/21.

*Source: Court of Justice of the European Union, C-579/21, 2023-06-22 — https://overview.legal/posts/132284 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0579*

In Case C-579/21, the Court of Justice of the European Union ruled on a preliminary reference from the Itä-Suomen hallinto-oikeus (Administrative Court of Eastern Finland) concerning a dispute between J.M. and Pankki S, a Finnish bank, after the Apulaistietosuojavaltuutettu (Assistant Data Protection Supervisor) rejected J.M.'s request for access to certain log data. The core issue was the scope of the right of access under Article 15 of the GDPR, specifically whether log data containing information about who accessed personal data and when constitutes "personal data" and whether the controller must communicate the identities of recipients. The Court held that log data relating to consultations of a data subject's personal data constitutes personal data under Article 4(1) of the GDPR, and that a data subject is entitled to obtain the identities of recipients of their data, subject only to exceptions expressly provided by law or overriding rights of third parties. No fine was imposed as this was a preliminary ruling proceeding.

### Judgment of the Court (Fifth Chamber) of 4 May 2023.#UZ v Bundesrepublik Deutschland.#Request for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 5 – Principles relating to processing – Controllership – Article 6 – Lawfulness of processing – Electronic file compiled by an administrative authority relating to an asylum application – Tra

*Source: Court of Justice of the European Union, C-60/22, 2023-05-04 — https://overview.legal/posts/132289 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0060*

In Case C-60/22, the CJEU (Fifth Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden concerning UZ, a third-country national, and the Bundesrepublik Deutschland regarding the processing of personal data in an asylum application file. The Court held that an administrative authority transmitting an electronic asylum file to a competent national court via an electronic mailbox constitutes processing under the GDPR, and that where both the authority and the court determine the purposes and means of processing, they are joint controllers under Article 26, requiring an arrangement allocating responsibility and maintaining records of processing activities under Article 30. The Court further clarified that transmission of personal data without the data subject's consent constitutes unlawful processing, triggering the right to erasure under Article 17(1)(d) and the right to restriction under Article 18(1)(b), and that national courts must disregard such unlawfully processed data. No fine was imposed.

### Judgment of the Court (First Chamber) of 12 January 2023.#RW v Österreichische Post AG.#Request for a preliminary ruling from the Oberster Gerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 15(1)(c) – Data subject’s right of access to his or her data – Information about the recipients or categories of recipient to whom the personal data have been or will be disclosed – Restrictions.#C

*Source: Court of Justice of the European Union, C-154/21, 2023-01-12 — https://overview.legal/posts/132299 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0154*

The Court of Justice of the European Union (First Chamber), in response to a preliminary reference from the Oberster Gerichtshof (Austrian Supreme Court), interpreted Article 15(1)(c) GDPR in proceedings between data subject RW and Österreichische Post AG regarding the scope of the right of access to information about recipients or categories of recipients of personal data. The Court held that controllers must provide the actual identities of specific recipients to whom personal data have been or will be disclosed, rather than merely naming categories of recipients, unless a further specification is impossible. The Court clarified that while the right of access under Article 15(1)(c) is not absolute and may be balanced against the rights and freedoms of others, including trade secrets, such restrictions must not result in a refusal to provide all information to the data subject.

### Judgment of the Court (First Chamber) of 12 January 2023.#BE v Nemzeti Adatvédelmi és Információszabadság Hatóság.#Request for a preliminary ruling from the Fővárosi Törvényszék.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Articles 77 to 79 – Remedies – Parallel exercise – Relationship – Procedural autonomy – Effectiveness of the protection rules established by that regulation – Consistent and homo

*Source: Court of Justice of the European Union, C-132/21, 2023-01-12 — https://overview.legal/posts/132298 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0132*

In Case C-132/21, the Court of Justice of the European Union (First Chamber) issued a preliminary ruling responding to a referral from the Budapest High Court concerning the parallel exercise of GDPR remedies under Articles 77, 78, and 79. The underlying dispute involved data subject BE challenging the refusal by the Nemzeti Adatvédelmi és Információszabadság Hatóság (Hungarian Data Protection Authority) of BE's request to obtain extracts from a sound recording of a shareholders' general meeting. The Court held that data subjects may simultaneously lodge a complaint with a supervisory authority and bring a judicial action against a controller, as Member States may not impose procedural rules that prevent the parallel exercise of these remedies in a manner that undermines the effective protection guaranteed by the GDPR and Article 47 of the EU Charter of Fundamental Rights.

### CE - 451423

*Source: Supreme Administrative Court, 2022-06-27 — https://overview.legal/posts/108993 — original: https://gdprhub.eu/index.php?title=CE_-_451423*

Facts — The French DPA had received a complaint on 28 May 2018 regarding the lawfulness of processing by Amazon Europe Core ('Provider' or 'The company'). The French DPA had forwarded this complaint to the Luxembourg DPA under the 'one stop shop' mechanism of Article 56 GDPR. The luxembourg DPA started an investigation regarding Amazon's use of cookies and its compliance with the GDPR and the ePrivacy directive. However, the French DPA started its own investigation into Amazon's compliance with Article 82 of the French Data protection act, a national implementation of Article 5(3) of the ePrivacy directive. (directive 2002/58/EC). This investigation regarding Article 82 had resulted in decision SAN-2020-013. In this decision, the French DPA fined Amazon €35,000,000 for the failure to obtain prior consent and the failure to inform users of their rights with regards to the processing of their data, which was mandatory under Article 82 of the Data Protection Act. The DPA found that when a user visited the "Amazon.fr" site, a large number of cookies with advertising purposes were automatically placed on the data subjects computer. Because this type of cookie was not essential to the service provided by the controller, the DPA considered that the controller had not complied with the obligation to obtain the consent of Internet users before depositing the cookies. Amazon appealed this decision at the Conseil d'Etat, the French Supreme Administrative Court, and requested its annulment. Amazon also asked the Conseil to refer several questions to the CJEU for a preliminary ruling. Among other arguments, Amazon claimed that the French DPA had made an incorrect interpretation of the law regarding its competence and had disregarded its competence by imposing the contested sanction. The controller also stated that the involvement of the French DPA, when the Luxembourg DPA was already involved, constituted a violation of Article 50 of the Charter of Fundamental Rights. According to this article, the same person may not be prosecuted more than once for the same acts. Holding — With regard to the application of the "one-stop shop" mechanism and the CNIL's jurisdiction: The Conseil ruled that the application and enforcement of the ePrivacy directive was the responsibility of national DPAs according to Article 15a of the directive. The "one-stop shop" mechanism did not apply in this case, even when there was a form of a cross-border processing. The Conseil also stated that the absence of a 'one-stop shop' mechanism did not imply any infringement of Article 50 of the Charter of Fundamental Rights, because the DPA only ruled on breaches of national law transposing EU law in the contested decision, and not on GDPR related violations. The Conseil also assessed the compatibility of Article 3 of the French Data protection Act with the ePrivacy Directive. The Conseil determined that Directive 2002/58/EC did not prevent the French DPA to apply the French data protection Act (including Article 82). The Directive would therefore also not prevent the French DPA from penalising the controller for supposed violations of Article 82 of the French data protection Act. Therefore, the Conseil established that the French DPA could enforce the French data protection act against any person or legal entity responsible for the processing of data who had an establishment in France, irrespective of the location of the principal establishment of the responsible entity. This enforcement by the DPA would also not constitute violations of articles 49 (Freedom of establishment) or 56 (Freedom to provide services) of the TFEU. With regard to the sanction imposed by the CNIL: The Conseil deemed that the applicant was sufficiently informed regarding the scope of the DPA's investigations, the facts and the legal grounds on which the sanction was based. Moreover, the Conseil considered that the applicant was given sufficient time to present its defence. The Conseil also ruled that the involvement of the French DPA, while the Luxembourg DPA was the lead supervisory authority, was not enough to constitute a breach of the equality of arms principle. Amazon had argued that the involvement of the French DPA in the procedure had enabled the French DPA to gain access to privileged and confidential information and had used this information as a basis for its own decision. The Conseil determined that Amazon did not provide enough proof for this argument and stated that Amazon was not able to prove that was the procedure contrary to Article 15a(4) of Directive 2002/58/EC. On a possible violation of Article 50 of the Charter of Fundamental Rights: The Conseil explained, based on the CJEU's case law (Aklagaren v Akerberg Fransson C-617/10, Powszechny Zaklad Ubezpieczen na Zycie SA of C-617/17 and bpost SA v Belgian Competition Authority C-117/20), that the principle invoked by the applicant, that the same person may not be the subject of several proceeding in respect of the same facts, was not violated by the French DPA. The Conseil stated that the principle could only be enforced when criminal proceedings had been definitively terminated. This was in particular the case when a criminal penalty had become final. The Conseil held that Amazon was not found to be the subject of a final sanction issued by the Luxembourg DPA for the facts that had resulted in the €35,000,000 fine in the contested decision. The Conseil rejected the applicant's claim for a reference for a preliminary ruling on the matter. Regarding the application of French Data Protection Act by the French DPA, Amazon had argued that the legal framework regarding cookies was not stable and unclear at the time when proceedings against Amazon were started. The Conseil concluded that it had published guidelines detailing obligations for entities under the applicable law, and considered that the fact that other national supervisory authorities had taken divergent positions in interpreting the conditions and procedures applicable to the collection of user consent had no bearing on the application of the French Data Protection Act by the French DPA. On the proportionality of the sanction imposed: Taking into account the elements assessed by the French DPA to calculate the imposed fine, the Conseil ruled that the DPA had not imposed a disproportionate penalty on the controller. Consequently, the Conseil rejected the entirety of controller's claims.

## Guidance

### Opinion 22/2024 on certain obligations following from the reliance on processor(s) and sub-processor(s)

*Source: EDPB, opinion-222024-on-certain-obligations-following-from-the-en, 2024-10-09 — https://overview.legal/posts/125715 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-222024-on-certain-obligations-following-from-the_en*

A dopted 1 Opinion 22/2024 on certain obligations following from the reliance on processor(s) and sub - processor(s) Adopted on 7 October 2024 Adopted 2 Executive summary The Danish SA requested the EDPB to issue an opinion on matters of general application pursuant to Article 64(2) GDPR. The opinion contributes to a harmonised interpretation by the national supervisory authorities of certain aspects of Article 28 GDPR, whe re appropriate in conjunction with Chapter V GDPR. In particular, the…

### Translations proofread by EDPB Members. This language version has not yet been proofread.

*Source: EDPB, edpb-van-de-tekst-in-de-afbeeldingen-in-de-bijlage, 2025-11-21 — https://overview.legal/posts/38114 — original: https://www.edpb.europa.eu/system/files/2023-12/edpb_guidelines_05-2021_translations-of-visual-examples-in-annex_nl.pdf*

The European Data Protection Board (EDPB) published a Dutch language translation table for key GDPR terminology used in its guidance documents, including terms such as "controller" (verwerkingsverantwoordelijke), "processor" (verwerker), and "data transfer" (gegevensdoorgifte). The document is explicitly marked as a translation that has not yet been proofread by EDPB Members, indicating it is a draft or provisional language version. This translation resource serves to support consistent Dutch-language usage of GDPR concepts across EDPB guidance materials.

### Opinion 18/2021 on the draft Standard Contractual Clauses submitted by the LT SA (Article 28(8) GDPR)

*Source: EDPB, opinion-182021-on-the-draft-standard-contractual-clauses-en, 2021-05-19 — https://overview.legal/posts/126032 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-182021-on-the-draft-standard-contractual-clauses_en*

1 Adopted Opinion 18 /2021 on the draft Standard Contractual Clauses sub mitted by the LT SA (Article 28( 8 ) GDPR) Adopted on 19 May 2021 2 Adopted 3 Adopted The European Data Protection Board Having rega rd to Article 28(8), Article 63 and Article 64(1 ) (d), (3) - (8) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repe…

### Opinion 17/2020 on the draft Standard Contractual Clauses submitted by the SI SA (Article 28(8) GDPR)

*Source: EDPB, opinion-172020-on-the-draft-standard-contractual-clauses-en, 2020-05-19 — https://overview.legal/posts/126161 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-172020-on-the-draft-standard-contractual-clauses_en*

1 Adopted Opinion 17 /2020 on the draft Standard Contractual Clauses sub mitted by the SI SA (Article 28( 8 ) GDPR) Adopted on 19 May 2020 2 Adopted 4 Final Remarks ................................ ................................ ................................ ................................ .. 9 3 Adopted The European Data Protection Board Having rega rd to Article 28(8), Article 63 and Article 64(1 ) (d), (3) - (8) of the Regulation 2016/679/EU of the European Parliament and of the…

### Opinion 14/2019 on the draft Standard Contractual Clauses submitted by the DK SA (Article 28(8) GDPR)

*Source: EDPB, opinion-142019-on-the-draft-standard-contractual-clauses-en, 2019-07-12 — https://overview.legal/posts/126212 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-142019-on-the-draft-standard-contractual-clauses_en*

Adopted 1 Opinion 14/2019 on the draft Standard Contractual Clauses sub mitted by the DK SA (Article 28( 8 ) GDPR) Adopted on 9 July 2019 Adopted 2 1 CONTENTS 2 Summary of the Facts ................................ ................................ ................................ .................... 4 3 Assessment ................................ ................................ ................................ ................................ .... 5 3.1 General reasoning of the Board…

### Opinion 19/2026 on the draft decision of the Dutch Supervisory Authority regarding the Processor Binding Corporate Rules of the Rubrik Group

*Source: EDPB, opinion-192026-on-the-draft-decision-of-the-dutch-supervisory-en, 2026-06-08 — https://overview.legal/posts/125672 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-192026-on-the-draft-decision-of-the-dutch-supervisory_en*

Opinion 19/2026 on the draft decision of the Dutch Supervisory Authority regarding the Processor Binding Corporate Rules of the Rubrik Group Adopted on 08 June 2026 1 | Adopted 2 | Adopted The European Data Protection Board Having regard to Article 63, Article 64(1)(f) and Article 47 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such…

### Opinion 17/2026 on the draft decision of the Dutch Supervisory Authority regarding the Processor Binding Corporate Rules of the Infor Group

*Source: EDPB, opinion-172026-on-the-draft-decision-of-the-dutch-supervisory-en, 2026-05-11 — https://overview.legal/posts/125676 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-172026-on-the-draft-decision-of-the-dutch-supervisory_en*

Opinion 17 / 2026 on the draft decision of the Dutch Supervisory Authority regarding the Processor Binding Corporate Rules of the Infor Group Adopted on 11 May 2026 1 | Adopted 2 | Adopted The European Data Protection Board Having regard to Article 63, Article 64(1)(f) and Article 47 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such…

### Opinion 5/2026 on the draft decision of the Dutch Supervisory Authority regarding the Processor Binding Corporate Rules of the Arcadis Group

*Source: EDPB, opinion-52026-on-the-draft-decision-of-the-dutch-supervisory-en, 2026-02-10 — https://overview.legal/posts/125691 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-52026-on-the-draft-decision-of-the-dutch-supervisory_en*

Opinion 5 / 2026 on the draft decision of the Dutch Supervisory Authority regarding the Processor Binding Corporate Rules of the Arcadis Group Adopted on 10 February 2026 1 | Adopted 2 | Adopted The European Data Protection Board Having regard to Article 63, Article 64(1)(f) and Article 47 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of…

## Enforcement decisions

### AKI (Estonia) - No. 2.1-1/24/397-890-38

*Source: AKI (Estonia), 2026-04-16 — https://overview.legal/posts/53882 — original: https://gdprhub.eu/index.php?title=AKI_(Estonia)_-_No._2.1-1/24/397-890-38*

Facts — OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic. On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had failed to provide all personal data requested. The controller only partially complied after several requests from the DPA. Although the DPA closed the part of the case concerning the access request, it continued investigating the controller’s processing of patients’ personal data when providing Invisalign treatment. The service required the controller to collect and transfer patients’ health data to Align Technology, Inc. However, the contractual documents did not clearly establish whether Align Technology acted as a processor, an independent controller or a joint controller. The controller stated that Align Technology largely determined the conditions of the service, including the consent form and the processing arrangements, and that individual clinics could not unilaterally amend these conditions. The DPA also found that the information provided to patients was incomplete and fragmented. The consent form and privacy information did not clearly explain the legal basis and purposes of processing, the parties involved, data recipients, retention periods, transfers outside the European Union or the safeguards applied to such transfers. Parts of the information were only available in English on external websites. Holding — The DPA held that the controller had failed to demonstrate that the processing carried out in connection with the Invisalign service was lawful and transparent under Articles 5(1)(a) and 5(2) GDPR. First, the DPA found that the parties’ roles had not been properly determined. Under Article 4(7) GDPR, the assessment had to be based on which party actually determined the purposes and means of processing, rather than solely on the contractual description of the relationship. The controller decided whether Invisalign treatment was suitable for a patient and collected the relevant health data. It therefore acted as a controller in relation to the treatment. However, Align Technology exercised significant control over the subsequent processing, including the data collected, the recipients, retention arrangements, the use of other service providers and transfers outside the European Union. The DPA therefore considered that Align Technology could not simply be regarded as a processor acting only on documented instructions under Article 28(3)(a) GDPR. On the available evidence, it was at least a joint controller under Article 26 GDPR. The DPA ordered the controller to review the contractual relationship. If Align Technology acted as a processor, the agreement had to comply with Article 28 GDPR, including the requirements concerning subprocessors under Article 28(2). If the parties were joint controllers, they had to allocate their respective responsibilities under Article 26 GDPR. Second, the DPA found that the consent obtained from patients was invalid. The consent form did not provide sufficient information for patients to understand the processing and therefore did not meet Articles 4(11), 6(1)(a), 7 and 9(2)(a) GDPR. The DPA also noted that healthcare processing may, depending on the operation concerned, rely on Article 6(1)(b) GDPR together with Article 9(2)(h) GDPR. However, the controller had not clearly identified the applicable legal bases for the different processing activities. The privacy information also failed to comply with Articles 12, 13 and 14 GDPR. Patients were required to consult several documents and external websites, some of which contained incomplete or inconsistent information. The controller had therefore not ensured that the information was easily accessible, understandable and available in Estonian. The DPA further referred to Article 25 GDPR when emphasising that the controller had to ensure that the processing arrangements and safeguards complied with the GDPR. Under Article 58(2)(d) GDPR and § 56(1) of the Estonian Personal Data Protection Act, the DPA ordered the controller to clarify the parties’ roles, conclude an Article 26 arrangement or Article 28 agreement, amend the consent form and privacy policy, and publish the required information in Estonian. No administrative fine was imposed. However, failure to comply could result in a penalty payment of €1,000 for each unfulfilled point or subpoint of the order, imposed repeatedly until compliance.

### Datatilsynet (Denmark) - 2020-422-0026

*Source: Datatilsynet (Denmark), 2022-09-28 — https://overview.legal/posts/6312 — original: https://gdprhub.eu/index.php?title=Datatilsynet_(Denmark)_-_2020-422-0026*

Facts — The Danish DPA had decided to investigate three research projects of Region Syddanmark (the controller) with regards to its processing activities, the use of processors, data processing agreements and processor audit practices. Holding — The DPA first held that, based on the information provided by the controller, there were no indications that the controller's assessment of the legal bases for the processing were incorrect. The DPA then held that the use of processors had been lawful and that the relevant data processing agreements satisfied the requirements of Article 28 GDPR. However, the DPA reprimanded the controller, partly for its lack of clear auditing procedures, and partly for not actually conducting audits in line with the routines that did exist. The DPA held that the accountability principle in Article 5 GDPR entails an obligation for the controller to oversee the security of the data processing operations performed by a processor. The DPA highlighted that entering into a data processing agreement that contains security obligations is not sufficient, and that the controller must also oversee that the processor actually adheres to the agreement. The fact that the controller had auditing procedures in place was not good enough if these auditing procedures were not being followed in practice.

### UODO (Poland) - DKN.5131.7.2022

*Source: UODO (Poland), 2026-04-13 — https://overview.legal/posts/53109 — original: https://gdprhub.eu/index.php?title=UODO_(Poland)_-_DKN.5131.7.2022*

Facts — An electricity sales company (the controller) had outsourced some of its operations to two processors and one sub-processor. Employees of the sub-processor had used a smartphone application between July 2020 and March 2021 to send pictures of customer contracts containing the personal data of individuals residing at addresses visited during door-to-door sales (the data subjects). The controller had not authorised this practice, and former employees of the sub-processor could still access the personal data through the app. The controller identified the use of the app as a data breach and notified the supervisory authority about it in April 2021. The DPA initiated administrative proceedings in March 2022. Holding — First, the DPA held that the controller had violated the principles of integrity and confidentiality enshrined in Article 5(1)(f) and the principle of accountability laid down in Article 5(2) GDPR. It had also violated Articles 24(1), 25(1), 28(1), 32(1) and 32(2) GDPR, which specify these principles. The DPA issued the controller a reprimand. The DPA found the controller had failed to implement appropriate technical and organisational measures itself and also failed to properly verify whether the (sub-)processors had provided sufficient guarantees that they had implemented such measures. The data protection agreements required in Article 28(1) GDPR were very general in nature, and none of the parties in the chain of contracts had conducted a risk analysis to select appropriate security measures. In addition, the controller had not continuously monitored the processing activities. Second, the DPA held that the two processor and the sub-processor had violated Articles 32(1) and 32(2) GDPR read in conjunction with Article 28(4) GDPR. They had all failed to implement appropriate technical and organisational measures to ensure the security of personal data processing. The sub-processor was largely held responsible for the data breach – it had started using the app to process customers’ personal data without authorisation from the controller or the processors. Furthermore, the DPA pointed out the sub-processor should have verified whether the application would allow access to the personal data through it even after the termination of the employment relationship. The DPA reprimanded the processors and fined the sub-processor €2,415.

### Italian Garante sanctions Hera Comm for automated credit-check refusals of contracts

*Source: Garante per la protezione dei dati personali (Italy), 2026-07-03 — https://overview.legal/posts/184557 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_483/2026*

Facts — Several data subjects lodged complaints with the Italian DPA (Garante) after Hera Comm S.p.A., an energy supplier (the controller), declined to conclude electricity or gas contracts with them because its checks had resulted in a negative risk assessment. The controller had used a credit-check procedure to assess the creditworthiness of prospective customers before entering into such contracts. The credit-check procedure consisted of an internal and an external assessment. During the internal assessment, Hera S.p.A. (processor A) checked whether the prospective customer had outstanding debts towards the controller or EstEnergy S.p.A., another energy supplier within the same corporate group. The assessment returned an OK or KO result. The controller’s privacy notice stated that customer data could be disclosed to other companies within the Hera Group and to third parties contractually linked to the Group. Where the internal assessment returned an OK result, an external assessment was carried out using software called “CGS-X”, provided by Major 1 S.r.l. (processor B). Through the software, databases operated by Experian Italia S.p.A. (the credit-information provider) and Cerved Group S.p.A. (the commercial-information provider) were consulted. The software combined the scores supplied by the two external data providers to generate an integrated creditworthiness score, which was transmitted to systems operated by processor A. Those systems applied the criteria established under the controller’s group credit policy and returned a final OK or KO result. The data subjects alleged that the refusal of their applications resulted from the external creditworthiness assessment. When they subsequently contacted the two external data providers, the providers stated that their systems did not contain negative information or adverse events concerning them. The data subjects then submitted access requests to the controller. The controller replied that their risk profiles were based on automated scoring using information obtained from external databases and directed them to the two external data providers for further details. The replies did not identify the CGS-X score and did not explain the logic or criteria used in the assessment. At the time of the inspection, the controller had not set a specific retention period for the external-assessment data and instead applied a general ten-year period used for accounting documentation. It also reused credit-check data, including information from external providers and previous debts, for analyses aimed at refining its group’s rating system. Between 2022 and March 2024, this processing concerned 1,003,657 individuals. During the proceedings, the controller and the other energy supplier entered into a joint-controller arrangement under Article 26 GDPR concerning the internal assessment and updated the relevant privacy information. Under that arrangement, the two joint controllers also undertook to appoint processor A for the processing carried out as part of the internal assessment. The controller subsequently adopted a five-year retention period for creditworthiness data and discontinued the analyses concerning the refinement of the rating system. Holding — The DPA considered that the information provided by the controller did not describe the intra-group sharing and use of data concerning previous debts with sufficient specificity. It found that the general references to disclosures within the corporate group did not provide information about the processing operations connected with the internal assessment. The DPA also found that the instructions provided to processor A did not cover the processing of information concerning debts owed by customers to the other energy supplier. It therefore found infringements of Article 5(1)(a) GDPR, Article 13 GDPR, Article 14 GDPR and Article 28 GDPR. The DPA noted that, under the joint-controller arrangement, the internal assessment was carried out jointly by the two energy suppliers on the basis of Article 6(1)(f) GDPR. However, it found that the processing carried out before the conclusion of that arrangement was unlawful. The DPA also found that the responses to the access requests did not meet the requirements of Article 12 GDPR and Article 15 GDPR. It noted that the access requests had been submitted to the controller which was required to provide all personal data and information relating to the processing. It pointed out additionally that the information to be provided should include the integrated score, the contributing scores, and meaningful information about the logic and criteria applied. Moreover, referring to the CJEU’s judgment in Case C-203/22 (Dun & Bradstreet Austria), the DPA stated that the requirement to provide meaningful information about the logic involved could not be satisfied merely by disclosing a complex mathematical formula or by providing a detailed description of every stage of the automated process. It emphasized that the controller was required to describe the procedure and principles actually applied in a concise and understandable manner, enabling the data subject to understand which personal data were used and how they contributed to the result. The DPA considered that the information provided did not enable the data subjects fully to assess the lawfulness of the processing or the accuracy of the data used. It also limited their ability to request rectification, obtain human intervention, express their views and contest the decision. The DPA further found that the application of a general ten-year retention period to the credit-check data had not been sufficiently justified in relation to the purpose of assessing a specific contractual application. The controller had not demonstrated the necessity of retaining the scores and related reports for that period. The DPA concluded that the controller violated Article 5(1)(e) GDPR. Furthermore, the DPA considered that the use of data obtained from the credit-information provider and the commercial-information provider for analyses concerning the refinement of the controller’s group rating model pursued a further purpose incompatible with the original purpose for which those data had been collected. It also found that retaining and subsequently reusing data obtained from the two external providers created a risk that the information would no longer be up to date. It therefore found infringements of Article 5(1)(b) GDPR and Article 5(1)(d) GDPR. The DPA imposed a fine of €5,800,000. It also ordered the controller to define a new response template for access requests, including the relevant scores and meaningful information about the logic and criteria applied, and to provide the revised response to the complainants. The controller was further required to establish a procedure enabling data subjects to request the rectification of inaccurate or incomplete data, obtain human intervention, express their views and contest the decision.

### UODO (Poland) - DKN.5131.5.2025

*Source: UODO (Poland), 2026-05-25 — https://overview.legal/posts/184680 — original: https://gdprhub.eu/index.php?title=UODO_(Poland)_-_DKN.5131.5.2025*

Facts — A provincial government unit carrying out land consolidation and exchange work (the controller) had entrusted tasks involving the processing of landowners’ (the data subjects’) personal data to a specialised entity established for this purpose (the processor). In January 2023, a work laptop belonging to an employee of the processor was stolen from the trunk of a car parked in a parking garage. This resulted in a breach of confidentiality of the data subjects’ personal data, including names, addresses, ID numbers, and land registry numbers. The controller notified this data breach to the DPA later in January 2023. The DPA conducted an investigation and initiated administrative proceedings regarding the GDPR compliance of the processing operations carried out by the controller and the processor in March 2025. Holding — The DPA issued the controller a fine of PLN 21,000 (€4,900) and the processor a fine of PLN 12,500 (€2,900). First, the DPA held that the controller had violated Articles 24(1), 25(1), 32(1), and 32(2) GDPR by failing to implement appropriate technical and organisational measures to ensure the security of personal data processing – the controller had failed to demonstrate that it had conducted a thorough risk assessment in a manner that would have allowed for the selection of adequate security measures. These infringements resulted in the violations of the principles of integrity, confidentiality and accountability laid down in Articles 5(1)(f) and 5(2) GDPR. Second, the DPA found that the controller had also violated Article 28(1) GDPR: it had failed to verify the adequacy of the technical and organisational measures implemented by the processor. Finally, the DPA came to the conclusion that the processor had infringed Articles 32(1) and 32(2) GDPR in conjunction with Articles 28(3)(c) and 28(3)(f) GDPR. The DPA held that the processor had failed to assist the controller in fulfilling its obligations and contributed to the controller’s GDPR violations. Unlike the controller, the processor had conducted a risk assessment covering the processing operations at issue; however, the processor had not implemented security measures to protect data stored on laptops used outside of its office premises, such as encryption.

### EDPS finds Commission infringed purpose limitation and data transfer rules in Microsoft

*Source: EDPS, 2024-03-08 — https://overview.legal/posts/125645 — original: https://gdprhub.eu/index.php?title=EDPS_-_2021-0518*

Facts — Following an investigation in 2019-2020, the EDPS issued recommendations and the Commission modified the ILA. The EDPS investigated whether these modifications were sufficient to bring processing in compliance with data protection requirements and found infringements. Data accessed by Microsoft include identity and contact data of users (when signing on to the service and when checking the licenses), data generated by the users while using the software and data generated by Microsoft based on the usage of the software. The EDPS found that the processing presents significant risks as it monitors the behaviour of users, combines datasets and uses artificial intelligence. Reference date is the 12th May 2021, the date when the investigation was launched. Some measures were taken meanwhile by the Commission, which were taken into account in the recommendations issued. Holding — The EDPS found infringements with regards to purpose limitation, transfers to a third country and further, unathorised disclosure of personal data. Purpose limitation: The EDPS found that it was not sufficiently defined in the International License Agreement (ILA) which types of personal data are to be processed for which purposes. Instead, there was only a list of purposes stating that Microsoft uses these data for: troubleshooting billing remunerating Microsoft staff, internal reporting and business modelling, financial reporting following the use of the system for own reasons (analytics) to improve the service security risk management protection of intellectual property These stated purposes were considered to be too vague and general pursuant to the Art 29 WP. The Commission and Microsoft could not demonstrate that all these data were necessary and that a less intrusive collection of data would be insufficient to achieve the purposes cited. In addition, some of these purposes were actually not in the interest of the Commission but for purposes of individual to Microsoft (like remuneration of their personnel). In this case, the processor acts as controller; thus, these purposes and the data used for this purposes should have been precisely defined. Also, if data were used for purposes other than for which they were collected, the compatibility of these new purposes with the original ones should have been assessed. As a processor, Microsoft should have processed the personal data on documented instructions by the Commission. This was not ensured as the Commission did not issue sufficiently clear documented instructions to Microsoft. For example, though the Commission gave instructions for analytics and improvement of the service, these instructions were not sufficiently detailed and precise and did not exclusively concern uses of data for the purposes of the controller. Some instructions were given orally, but this was not enabled by the ILA and the oral instructions were not documented. The Commission did not assess whether it is necessary and proportionate to transmit data to Microsoft Ireland and its sub-processors. Further details of this infringement are given under the part on further unauthorised disclosure or personal data. Transfer to third countries : The Commission transferred personal data to Microsoft, a company established in the US. This raises questions about adequacy for such transfers to a third country. After the reference date, the Commission adopted the Transatlantic Data Privacy Framework (TDPF), which is an adequacy decision in respect of recipients in the US who register under this framework. The EDPS found that even when the software and data storage is property of Microsoft, it is directly transferred to these subcontractors and cannot therefore be covered by the TDPF to Microsoft US and onward transfer from Microsoft US to other subcontractors under SCCs. The EDPS found that in was not clearly specified in the ILA what types of personal data can be transferred to which recipients in which third country. The Commission also did not appraise the transfers and therefore could not determine whether any supplementary measures are necessary. In addition, the Commission should have performed a data transfer impact assessment and (as there are no SCCs applicable by EUIs as exporters) should have submitted the DPAs with these processors or subprocessors in third countries to the EDPS for approval. Because it failed to do this, the Commission did not implement effective supplementary measures for these transfers. Another issue was that the “EU storage guarantee” offered by Microsoft did not cover all types of data. Some data may be accessible to recipients in third countries. The “EU Data Boundary” also has numerous exceptions and exclusions which cover customer data, service generated data, diagnostic data and professional services data. Further unauthorised disclosure or personal data: A specific reference was made to Article 9 Regulation (EU) 2018/1725, which concerns transmission of personal data by EU institutions to recipients established in the EU. According to the EDPS, this article is also applicable to transmission of personal data to processors of EUIs. Therefore all transmission of personal data should be in the public interest and if the data subject’s legitimate interests may be prejudiced, the controller has to weigh the competing interests and establish that it is proportionate to transmit the personal data. The purpose of management and functioning of the Commission, use of products the staff is familiar with etc. was not found to be the purpose of processing of the personal data by MS. As long as the purposes are not specified, specific and explicit, it is not possible to do this balancing. In addition, the EDPS found that the Commission did not ensure that transfers take place “solely to allow tasks within the competence of the controller to be carried out”. The EDPS determined that organisational and contractual measures to restrict/prevent access of third country authorities were not sufficient, and that further technical measures are thus necessary. The EDPS also found that the organisational measures applied are only limiting transfers but does not ensure that transfers are protected. Further, the encryption is only found to be an adequate measure if the controller is in control of the encryption key. In this case, customers control the keys, but Microsoft has access to the encryption key, and thus, even when law does not oblige it to decrypt the data on an authority request, it may do it voluntarily. Also, the ILA does not detail encryption of data other than “customer data”, i.e. diagnostic data, service generated data or professional services data. The contract also enabled the processor not to notify the Commission about a request of disclosure also when EU or Member State law did not prohibit this notification and enabled recipients in third countries not to notify requests for disclosure also when the law prohibiting it did not constitute a necessary and proportionate measure in a democratic society respecting the essence of the fundamental rights and freedoms recognised by the Charter.

### Datatilsynet (Denmark) - 2020-431-0061 (Helsingor decision no. 4)

*Source: Datatilsynet (Denmark), 2022-09-28 — https://overview.legal/posts/6313 — original: https://gdprhub.eu/index.php?title=Datatilsynet_(Denmark)_-_2020-431-0061_(Helsingor_decision_no._4)*

Facts — This is the Danish DPA's fourth decision in the case relating to Helsingor municipality's processing of personal data in primary and lower secondary school. Helsingor municipality, the controller, has been using Google Chromebooks and Workspace for Education in violation of several GDPR requirements, as detailed in the first decision of September 2021, the second decision of 14 July 2022 and the third decision of 18 August 2022. Following the third decision, the municipality submitted more documentation and also requested a consultation with the DPA as per Article 36 GDPR. Holding — The DPA temporarily suspended its processing ban against Helsingor municipality until 5 November 2022, and also ordered the municipality to: Change the data processing agreement with Google so that the DPA's remarks in their 14 July and 18 August decisions, are implemented. This includes, at a minimum, a clarification of where and if Google acts as a sole controller and any uncertainties that may entail that Google acts beyond their role as a processor, see Article 28(3)(a) GDPR. Document that all transfers of personal data to insecure third countries, are in line with the GDPR. Describe all data flows and identify the personal data that are shared with the vendor, and clarify when the vendor acts as a sole or joint controller. This documentation must include the whole technology stack used by the municipality (for this processing activity). Update their data protection impact assessment based on all identified risks. Consult the DPA if the DPIA shows any high risks the municipality is not able to mitigate. If any processing activities are still not in line with the GDPR before the DPA's deadline 3 November 2022, present a final plan for bringing them in line with the GDPR.

### EDPS - 2020-1013

*Source: EDPS, 2022-01-05 — https://overview.legal/posts/122849 — original: https://gdprhub.eu/index.php?title=EDPS_-_2020-1013*

Facts — In January 2021, noyb filed a complaint against the European Parliament on behalf of six Members of the European Parliament over an internal coronavirus testing website. The issues raised were: confusing and unclear cookie banners, vague and unclear data protection notices, and the illegal transfer of data to the US. Holding — On data controllership — According to the EDPS, the processor may enjoy a considerable degree of autonomy in providing its services and may identify the ‘non-essential’ elements of the processing operation. Furthermore, the processor may advise or propose certain measures in this respect, but it is up to the controller to decide whether to accept such advice or proposals. The analysis of the EDPS shows that the European Parliament (EP) delegated some aspects on the setting up and functioning of the website to Ecolog. The EDPS considers the EP acts as the sole data controller for the processing in question (i.e. the operation of the Parliament’s dedicated website) whereas Ecolog acts as a processor. After having assessed the instructions given by the EP to the processor, the EDPS concluded that the EP did not show the necessary diligence required from a data controller and, ultimately, failed to comply with the Regulation on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data 2018/1725 (hereafter Regulation 2018/1725), in particular with Articles 26(1) and 29(1). Moreover, the EDPS considered that the EP failed to provide the necessary detailed instructions to Ecolog for the setting up of the website, including the drafting of the data protection notice. The absence of documented instructions is therefore in violation of Article 29(3) Regulation 2018/1725. Transparency and information requirements — The EDPS confirmed that the data protection notice published at the time of the complaint did not reflect the processing done by the EP, since it merely consisted of a copy of the testing center of Zaventem's airport. Moreover, the reference made in the document to Article 6(1)(f) GDPR was wrong since it stems from the same error. The EDPS confirmed that the EP did not meet its transparency requirements. The EDPS also analysed the updated version of the data protection notice during the procedure and raised several remaining -and even new- inconsistencies and issues. Among other things, the following problems persisted after the data protection notice was updated: a mere reference to Article 15 and 16 Regulation 2018/1725 is misleading as it should apply in its entirety; the reference to the processing of health data is not correct since no such data are processed in the case at hand; the retention period mentioned is not precise enough; the sections of the data protection notices relating to the recipients of the personal data fail to make any reference to the processor; inconsistencies between the different linguistic versions of the data protection notices were still observed: The English and German versions refer to Ecolog and the Laboratory van Poucke as processors under Article 29 Regulation 2018/1725, whereas the French version refers to them as controllers (‘responsables du traitement’). Moreover, the DPO’s contact details on the website refer to Ecolog in all three linguistic versions of the website, when they should be referring to the Parliament Cookies and transfers of personal data to the US — The EDPS confirmed that tracking cookies, such as the Stripe and the Google analytics cookies, are considered personal data, even if the traditional identity parameters of the tracked users are unknown or have been deleted by the tracker after collection. In the same vein, the EDPS rejected the EP's argument and confirmed that upon installation on a device, a cookie cannot be considered ‘inactive’. Every time a user visited Ecolog’s website, personal data was transferred to Stripe through the Stripe cookie, which contained an identifier. The EDPS reached the conclusion that a transfer of data was taking place to the US, via the use of Google and Stripe cookies, since Google Analytics is hosted in the US and the data protection notice referred to a Standard Contractual Clause (SCC) for the transfer of data outside of the EU. However, the Parliament provided no documentation, evidence or other information regarding the contractual, technical or organisational measures in place to ensure an essentially equivalent level of protection to the personal data transferred to the US in the context of the use of cookies on the website. Cookie banner on the Parliament’s dedicated website — The EDPS reminded that: before setting cookies or any other technology falling within the scope of Article 5(3) ePrivacy Directive 2002/58/EC (hereafter ePrivacy Directive), the EU institution must provide the user with adequate information on what is accessed or stored on the user’s terminal equipment, on the purposes of this action and the means for expressing their consent; no action may be performed before the consent is collected. In addition, users must be enabled to withdraw their consent at any time; ‘cookie walls’ are not in line with Regulation 2018/1725, meaning that for consent to be freely given, access to the website’s service and functionalities should not depend on the users’ consent for cookies that are not strictly necessary in the sense described above; in case personal data collected through the cookies are shared with third parties such as analytics partners, the cookie banner should draw the user's attention to it. The EDPS reached the conclusion that the cookie banners in all three languages were not in line with the definition of consent under Article 3(15) Regulation 2018/1725, nor did they meet the requirements of Article 37 Regulation 2018/1725 and Article 5(3) ePrivacy Directive. The cookie banner further failed to provide transparent information regarding the processing of personal data in relation to the cookies on the website. Request for access to personal data — The Parliament was aware that the complainants’ personal data had been processed through the cookies, which were present on the website for the period between 30 September to 4 November 2020, since transfers of personal data had taken place. Consequently, and especially following the EDPS’ inquiry on the matter, the Parliament should have replied to the complainants’ access to personal data request. The Parliament should have provided the relevant information even if it was aware that the processing of the personal data in question was unlawful, as the main purpose of the right of access under Article 15 GDPR is precisely to enable data subjects to become aware of the processing and verify the lawfulness thereof, or exercise other data subject rights. Conclusion — The EDPS concludes that the Parliament has infringed the following articles of Regulation 2018/1725: Articles 26(1) and 29(1) due to its failure to fulfil its responsibilities as controller and use a processor providing sufficient guarantees to implement appropriate technical and organisational measures; Article 29(3) due to its failure to provide documentation relating to the detailed instructions given to the processor for the setting up and functioning of the website; Articles 4(1)(a) and 14, 4(2), and 15 due to its failure to respect the principle of transparency, accountability and the data subjects’ right to information because of the inaccurate data protection notice and cookie banner on the dedicated website; Article 46 and Article 48(2)(b) of the Regulation, due to its reliance on the Standard Contractual Clauses in the absence of a demonstration that data subjects’ personal data transferred to the US were provided an essential equivalent level of protection; Article 37 read in the light of Article 5(3) of the ePrivacy Directive, due to its failure to protect information (the cookies) transmitted to, stored in, related to, processed by and collected from the users’ terminal equipment; Articles 17 and 14(4) due to its failure to reply to the data subjects’ request for access to their personal data. On the basis of the above, the EDPS decides: to issue a reprimand to the Parliament in accordance with Article 58(2)(b) Regulation 2018/1725 for the above infringements; to order the Parliament, pursuant to Article 58(2)(b) Regulation 2018/1725:, to update its data protection notices in the dedicated website in order to provide all relevant information relating to the processing of personal data. The Parliament should address this order within one month from the date of the decision.

## Recent developments

### ICO (UK) - ACRO Criminal Records Office

*Source: GDPRhub, 2026-08-21 — https://overview.legal/posts/291401 — original: https://gdprhub.eu/index.php?title=ICO_(UK)_-_ACRO_Criminal_Records_Office*

The ICO reprimanded ACRO for failing to implement appropriate security measures, including effective patch management and security monitoring, resulting in prolonged unauthorised access to systems containing sensitive personal data. English Summary. Facts. ACRO Criminal Records Office, the processor, is a national police unit providing public services including Police Certificates, International Child Protection Certificates, Subject Access Requests and Record Deletion Requests. It processes per

### Artikel 40 van de AVG (Algemene Verordening Gegevensbescherming).

*Source: GDPRhub, 2026-01-05 — https://overview.legal/posts/51680*

Commentaar: Codes van Gedrag (CoC) zijn vrijwillige instrumenten die specifieke regels voor gegevensbescherming vaststellen voor bepaalde categorieën van verantwoordelijken en verwerkers. Met andere woorden, een CoC kan een handleiding vormen voor een groep verantwoordelijken en verwerkers, waarin beschreven staat hoe een verwerking die voldoet aan de AVG er in een specifieke verwerkingssituatie uitziet. <ref>EDPB, ‘Richtlijnen 1/2019 over Codes van Gedrag en Toezichthoudende Instanties onder Verordening 2016/679’, 4 juni 2019 (versie 2.0), voetnoot 7 (beschikbaar op [https://ww

### What Happened to the Risk-Based Approach to Data Transfers?

*Source: Future of Privacy Forum, 2022-09-27 — https://overview.legal/posts/6271 — original: https://fpf.org/blog/what-happened-to-the-risk-based-approach-to-data-transfers/#entry-912*

The GDPR incorporates the RBA for all obligations of the controller in the GDPR. Where the transfer rules are stated as obligations of the controller (rather than as absolute principles), the RBA of Article 24 therefore applies. Other than the DPAs assume, this is not contradicted by the ECJ in Schrems II nor by the EDPB recommendations on additional measures following the Schrems II judgment, according to Lokke Moerel, Professor of Global ICT Law at Tilburg University and a Dutch Cyber Security

### The Italian Supervisory Authority fined a company 120 000 EUR for tracking five employees who drove company cars

*Source: European Data Protection Board, 2026-06-04 — https://overview.legal/posts/53062 — original: https://www.edpb.europa.eu/news/the-italian-supervisory-authority-fined-a-company-120-000-eur-for-tracking-five-employees-who_en*

Background informationDate of final decision: 27 November 2025National caseController: Pioneer Hi-Bred Italia Sementi s.r.l.Legal Reference(s): Article 5 (Principles relating to processing of personal data), Article 6 (Lawfulness of processing), Article 13 (Information to be provided where personal data are collected from the data subject), Article 28 (Processor), Article 88Decision: Administrative fine, Compliance order, Erasure order Key words: Administrative fine, Principles relating to proce

### CNIL (France) - SAN-2025-014

*Source: GDPRhub, 2026-01-13 — https://overview.legal/posts/51881*

The data protection authority (DPA) has imposed a fine of 1 million euros on a data processor for failing to delete user personal data, processing that data for purposes that conflict with contractual agreements, and failing to maintain a record of processing activities. The data protection authority (DPA) has imposed a fine of €1,000,000 on a data processor for failing to delete user personal data, processing that data for purposes that conflict with contractual agreements, and failing to maintain a record of processing activities. Finally, the DPA found that...

## Literature

### Data Controller, Processor or a Joint Controller: Towards Reaching GDPR Compliance in the Data and Technology Driven World

*Source: SSRN Electronic Journal, 2020-01-01 — https://overview.legal/posts/132509 — original: https://doi.org/10.2139/ssrn.3584207*

### European Union ∙ EDPB Opinion 14/2019 on Standard Contractual Clauses for Processors under Article 28(8) GDPR

*Source: European Data Protection Law Review, 2019-01-01 — https://overview.legal/posts/132531 — original: https://doi.org/10.21552/edpl/2019/4/10*

### GDPR Implementation Series ∙ Cyprus: A Look into the Law for the Effective Application of the GDPR

*Source: European Data Protection Law Review, 2019-01-01 — https://overview.legal/posts/132507 — original: https://doi.org/10.21552/edpl/2019/3/13*

### GDPR Implementation Series ∙ Netherlands: The GDPR Implementation Act

*Source: European Data Protection Law Review, 2018-01-01 — https://overview.legal/posts/132478 — original: https://doi.org/10.21552/edpl/2018/3/15*

### If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation

*Source: Computer law & security review, 2026-01-23 — https://overview.legal/posts/53843 — original: https://doi.org/10.1016/j.clsr.2025.106251*

As the General Data Protection Regulation (GDPR) approaches its tenth anniversary, the European legislator is considering reforms thereto. This article offers a set of research-based suggestions for what such reforms could look like, based on two assumptions. First, that the GDPR is overall a solid piece of legislation that upholds the enduring objectives and principles of data protection law. Second, that any improvement cannot compromise the level of protection of fundamental rights currently

## Tools

### ICO documentation templates (records of processing, Article 30)

*Source: ICO, 2026-07-17 — https://overview.legal/posts/125620 — original: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/documentation/*

Guidance plus downloadable controller and processor documentation templates for the Article 30 record of processing activities: what must be recorded, who is exempt, and spreadsheet templates organisations can adopt directly.

### Standard Contractual Clauses (SCCs) for international transfers

*Source: European Commission, 2026-07-04 — https://overview.legal/posts/53805 — original: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en*

The European Commission's modernised standard contractual clauses (2021) for transfers of personal data to third countries under Article 46(2)(c) GDPR, plus the controller-processor SCCs under Article 28(7). Includes the official Word/PDF templates for all four transfer modules.

## Related topics

- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities
- **Data Controller** — https://overview.legal/topics/verwerkingsverantwoordelijke
  The entity that determines purposes and means of processing personal data

---
Generated by overview.legal · https://overview.legal/topics/processors · 2026-08-22
