# Professional Secrecy — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/professional-secrecy
> Sources are cited per item. Verify against the official texts before relying on them.

Confidentiality obligations for data protection personnel

## Overview

## Professional Secrecy

## Legal Framework

Professional secrecy obligations in the data protection context arise from multiple legal instruments. Article 84 of the Digital Services Act imposes a binding confidentiality duty on the Commission, the Board, Member States' competent authorities, their officials, and any other natural or legal persons involved in regulatory activities — including auditors and experts appointed under Article 72(2) DSA. These actors must not disclose information acquired or exchanged pursuant to the Regulation that falls within the scope of professional secrecy.

Under the GDPR, the Data Protection Officer's independence is structurally protected through Article 39. The DPO must perform tasks without receiving instructions from the controller or processor regarding how those tasks are carried out. The DPO cannot be dismissed or penalized for the manner in which they discharge their duties. This independence is reinforced by a conflict-of-interest prohibition: the DPO may hold other functions, but the controller must ensure those do not conflict with DPO responsibilities. Senior management positions — such as CEO, CFO, or roles involving determining the purposes and means of data processing — are inherently incompatible with the DPO role.

Article 90 GDPR provides a specific confidentiality framework, though its implementation varies by Member State. The rationale across these provisions is consistent: persons entrusted with sensitive data protection information must be shielded from both external disclosure pressure and internal organizational conflicts that could compromise their objectivity.

## Key Developments

Dutch case law illustrates the practical tension between professional secrecy and data subject access rights. In a case involving the Dean of the Bar, the court confirmed that the statutory confidentiality obligation under Article 45a(2) of the Advocatenwet justified refusing to disclose complaint file materials to the data subject. However, the court established a critical procedural mechanism: the holder of the secrecy obligation can invoke Article 8:29 of the General Administrative Law Act (Awb), requesting that the court review documents in a restricted "secrecy chamber" — allowing judicial supervision without breaching confidentiality.

A separate tax case reinforced that privacy rights under the GDPR and professional secrecy obligations can jointly justify withholding documents from interested parties, with the court accepting restricted-knowledge procedures as an adequate safeguard.

The functional privilege against testifying was addressed in a 2023 appellate decision involving a company physician. The court applied Article 165(2)(b) of the Dutch Code of Civil Procedure, evaluating whether a functional right to refuse testimony exists for professionals bound by secrecy obligations. Notably, the patient's explicit waiver — stating the physician could disclose everything — did not automatically extinguish the privilege, as the court weighed the broader public interest underlying professional secrecy.

The EDPS decision against the European Parliament underscored that transferring medical data to another EU institution constitutes an interference with Article 8 ECHR rights, regardless of the recipient's identity or intended use.

## Practical Guidance

- **Establish formal secrecy protocols for DPOs and data protection personnel** that mirror Article 39 GDPR independence requirements, including written confirmation that the DPO will not receive instructions on task execution and cannot face dismissal or penalty for their advisory conclusions.

- **Screen DPO candidates for conflict of interest** before appointment and periodically thereafter — any role involving determining processing purposes or means, or senior management responsibility, disqualifies the individual under Article 39.

- **Implement restricted-access procedures for DSAR responses involving confidential materials** — where secrecy obligations conflict with access requests, use judicial review mechanisms (such as the Awb Article 8:29 secrecy chamber procedure) rather than blanket refusals, to preserve both confidentiality and judicial oversight.

- **Train personnel on the limits of consent-based waivers** — a data subject's consent to disclosure does not necessarily override functional secrecy obligations, particularly where broader institutional or third-party interests are at stake.

- **Review AI tool deployments against confidentiality requirements** — emerging risks from AI-assisted document processing can compromise professional secrecy where sensitive regulatory or complaint data is exposed to third-party models without adequate contractual and technical safeguards.

## Legislation (full text of key provisions)

### Professional secrecy

*Source: DSA, dsa-art-84-en, 2022-10-19 — https://overview.legal/posts/95314*

Without prejudice to the exchange and to the use of information referred to in this Chapter, the Commission, the Board, Member States’ competent authorities and their respective officials, servants and other persons working under their supervision, and any other natural or legal person involved, including auditors and experts appointed pursuant to Article 72(2), shall not disclose information acquired or exchanged by them pursuant to this Regulation and of the kind covered by the obligation of professional secrecy.

### Recital 164 — supervisory authority access and professional secrecy

*Source: GDPR, gdpr-rec-164-en, 2016-04-27 — https://overview.legal/posts/91843*

As regards the powers of the supervisory authorities to obtain from the controller or processor access to personal data and access to their premises, Member States may adopt by law, within the limits of this Regulation, specific rules in order to safeguard the professional or other equivalent secrecy obligations, in so far as necessary to reconcile the right to the protection of personal data with an obligation of professional secrecy. This is without prejudice to existing Member State obligations to adopt rules on professional secrecy where required by Union law.

### Recital 85 — personal data breach notification requirements

*Source: GDPR, gdpr-rec-85-en, 2016-04-27 — https://overview.legal/posts/91685*

A personal data breach may, if not addressed in an appropriate and timely manner, result in physical, material or non-material damage to natural persons such as loss of control over their personal data or limitation of their rights, discrimination, identity theft or fraud, financial loss, unauthorised reversal of pseudonymisation, damage to reputation, loss of confidentiality of personal data protected by professional secrecy or any other significant economic or social disadvantage to the natural person concerned. Therefore, as soon as the controller becomes aware that a personal data breach has occurred, the controller should notify the personal data breach to the supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the controller is able to demonstrate, in accordance with the accountability principle, that the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where such notification cannot be achieved within 72 hours, the reasons for the delay should accompany the notification and information may be provided in phases without undue further delay.

### Recital 75 — personal data processing risks to individuals

*Source: GDPR, gdpr-rec-75-en, 2016-04-27 — https://overview.legal/posts/91665*

The risk to the rights and freedoms of natural persons, of varying likelihood and severity, may result from personal data processing which could lead to physical, material or non-material damage, in particular: where the processing may give rise to discrimination, identity theft or fraud, financial loss, damage to the reputation, loss of confidentiality of personal data protected by professional secrecy, unauthorised reversal of pseudonymisation, or any other significant economic or social disadvantage; where data subjects might be deprived of their rights and freedoms or prevented from exercising control over their personal data; where personal data are processed which reveal racial or ethnic origin, political opinions, religion or philosophical beliefs, trade union membership, and the processing of genetic data, data concerning health or data concerning sex life or criminal convictions and offences or related security measures; where personal aspects are evaluated, in particular analysing or predicting aspects concerning performance at work, economic situation, health, personal preferences or interests, reliability or behaviour, location or movements, in order to create or use personal profiles; where personal data of vulnerable natural persons, in particular of children, are processed; or where processing involves a large amount of personal data and affects a large number of data subjects.

### Recital 53 — special health data processing conditions

*Source: GDPR, gdpr-rec-53-en, 2016-04-27 — https://overview.legal/posts/91621*

Special categories of personal data which merit higher protection should be processed for health-related purposes only where necessary to achieve those purposes for the benefit of natural persons and society as a whole, in particular in the context of the management of health or social care services and systems, including processing by the management and central national health authorities of such data for the purpose of quality control, management information and the general national and local supervision of the health or social care system, and ensuring continuity of health or social care and cross-border healthcare or health security, monitoring and alert purposes, or for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, based on Union or Member State law which has to meet an objective of public interest, as well as for studies conducted in the public interest in the area of public health. Therefore, this Regulation should provide for harmonised conditions for the processing of special categories of personal data concerning health, in respect of specific needs, in particular where the processing of such data is carried out for certain health-related purposes by persons subject to a legal obligation of professional secrecy. Union or Member State law should provide for specific and suitable measures so as to protect the fundamental rights and the personal data of natural persons. Member States should be allowed to maintain or introduce further conditions, including limitations, with regard to the processing of genetic data, biometric data or data concerning health. However, this should not hamper the free flow of personal data within the Union when those conditions apply to cross-border processing of such data.

### Recital 116 — fundamental rights procedural safeguards enforcement powers

*Source: DSA, dsa-rec-116-en, 2022-10-19 — https://overview.legal/posts/95629*

In the course of the exercise of those powers, the competent authorities should comply with the applicable national rules regarding procedures and matters such as the need for a prior judicial authorisation to enter certain premises and legal professional privilege. Those provisions should in particular ensure respect for the fundamental rights to an effective remedy and to a fair trial, including the rights of defence, and, the right to respect for private life. In this regard, the guarantees provided for in relation to the proceedings of the Commission pursuant to this Regulation could serve as an appropriate point of reference. A prior, fair and impartial procedure should be guaranteed before taking any final decision, including the right to be heard of the persons concerned, and the right to have access to the file, while respecting confidentiality and professional and business secrecy, as well as the obligation to give meaningful reasons for the decisions. This should not preclude the taking of measures, however, in duly substantiated cases of urgency and subject to appropriate conditions and procedural arrangements. The exercise of powers should also be proportionate to, inter alia the nature and the overall actual or potential harm caused by the infringement or suspected infringement. The competent authorities should take all relevant facts and circumstances of the case into account, including information gathered by competent authorities in other Member States.

### Recital 50 — compatible further processing of personal data

*Source: GDPR, gdpr-rec-50-en, 2016-04-27 — https://overview.legal/posts/91615*

The processing of personal data for purposes other than those for which the personal data were initially collected should be allowed only where the processing is compatible with the purposes for which the personal data were initially collected. In such a case, no legal basis separate from that which allowed the collection of the personal data is required. If the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, Union or Member State law may determine and specify the tasks and purposes for which the further processing should be regarded as compatible and lawful. Further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes should be considered to be compatible lawful processing operations. The legal basis provided by Union or Member State law for the processing of personal data may also provide a legal basis for further processing. In order to ascertain whether a purpose of further processing is compatible with the purpose for which the personal data are initially collected, the controller, after having met all the requirements for the lawfulness of the original processing, should take into account, inter alia: any link between those purposes and the purposes of the intended further processing; the context in which the personal data have been collected, in particular the reasonable expectations of data subjects based on their relationship with the controller as to their further use; the nature of the personal data; the consequences of the intended further processing for data subjects; and the existence of appropriate safeguards in both the original and intended further processing operations. Where the data subject has given consent or the processing is based on Union or Member State law which constitutes a necessary and proportionate measure in a democratic society to safeguard, in particular, important objectives of general public interest, the controller should be allowed to further process the personal data irrespective of the compatibility of the purposes. In any case, the application of the principles set out in this Regulation and in particular the information of the data subject on those other purposes and on his or her rights including the right to object, should be ensured. Indicating possible criminal acts or threats to public security by the controller and transmitting the relevant personal data in individual cases or in several cases relating to the same criminal act or threats to public security to a competent authority should be regarded as being in the legitimate interest pursued by the controller. However, such transmission in the legitimate interest of the controller or further processing of personal data should be prohibited if the processing is not compatible with a legal, professional or other binding obligation of secrecy.

## Case law

### BVwG - W211 2281442-1

*Source: Federal Administrative Court, 2024-06-12 — https://overview.legal/posts/187484 — original: https://gdprhub.eu/index.php?title=BVwG_-_W211_2281442-1*

Facts — The data subject and the controller both worked as nurses at the same hospital, on different wards. Over ten years before the events in question, the data subject had been hospitalised as a patient on the ward where the controller worked as a nurse. The controller's daughter, a school classmate of the data subject at the time, had visited her in hospital and the data subject's hospitalisation had briefly been discussed once in a social-skills class at school, without any diagnosis being disclosed. The data subject only told her closest friends about the hospitalisation itself. The data subject was later employed as a nurse at the same hospital, on a different ward, from October to April of a subsequent year. She and the controller belonged to a shared WhatsApp group used by both wards. Around Christmas, the controller's daughter recognised the data subject from her WhatsApp profile picture and reminded the controller that the data subject had once been her patient, the controller herself had not previously made this connection. The data subject resigned from her position, with her last working day followed by sick leave through the end of her notice period. On her first day back from holiday, the controller, deputy head of her ward, discussed recent events with the ward manager, including the data subject's resignation. In the course of this conversation, the controller mentioned that her daughter had gone to school with the data subject and asked the ward manager whether she had known that the data subject had been hospitalised on the relevant ward over ten years earlier. That same day, the ward manager told the data subject that staff at the hospital were aware of her earlier hospitalisation, intending to prepare her for the possibility that colleagues might raise it. The data subject later learned, from the site manager, that it was the controller who had disclosed this information to the ward manager. The data subject alleged that this disclosure led to her being bullied in the workplace. The controller denied any obligation on employees to disclose past hospitalisations to the employer and stated she had no other motive for the disclosure. The data subject lodged a complaint with the Austrian DPA, alleging a violation of her right to secrecy. The DPA upheld the complaint, finding that although the GDPR did not directly apply to this oral disclosure, the national constitutional right to secrecy under Section 1 DSG did apply, that the disclosed health data warranted heightened protection and that the controller had not shown sufficiently weighty grounds to justify the disclosure. The controller appealed to the Federal Administrative Court, arguing that the information was already publicly available (since it had once been mentioned at school) and that the disclosure was justified as processing of manifestly public data, as processing by a professional subject to confidentiality obligations, or as necessary for assessing an employee's fitness for work. Holding — The court dismissed the appeal and confirmed the DPA's decision in full. First, the court held that the GDPR's substantive scope did not apply to this case, since it concerned a purely oral disclosure of personal data, not automated or file-based processing. The applicable standard was instead the national constitutional right to secrecy under §1 DSG, interpreted in light of GDPR principles. The court noted that the disclosed information, the fact of a past hospitalisation, qualified as health data under Article 4(15) GDPR, given the broad interpretation the CJEU applies to that concept. Second, the court held that the information was not "generally available" within the meaning of §1(1) DSG, which would have excluded any protectable secrecy interest. It reasoned that data are only "generally available" if accessible to an indeterminate group of people, not merely to a limited circle of confidants. Since the data subject had only shared her hospitalisation with a small group of close friends and even the one classroom discussion of it involved only a defined group of classmates (not the public), the general-availability exception did not apply and the data subject retained a protectable secrecy interest. Third, addressing the controller's justification arguments in turn, the court held Article 9(2)(e) GDPR (data manifestly made public by the data subject) did not apply, for the same reasons the data was not "generally available“, Article 9(2)(a) GDPR (explicit consent) did not apply, since no explicit consent to this specific disclosure had ever been given and Article 9(2)(h) GDPR (processing necessary for assessing an employee's working capacity, among other health-related purposes) did not apply, because the disclosure was not shown to be necessary. The employer had no policy of taking such hospitalisations into account, the data subject had no duty to disclose them and no concrete workplace measures were linked to the disclosure. The court emphasised that health data attracts a particularly high level of protection, meaning that even if the controller's interest had been considered on a par with the data subject's, this would not have been sufficient to justify disclosure, given that the data subject was already leaving employment within a short period, her interest in confidentiality clearly outweighed any interest of the controller. The court accordingly confirmed that the controller had violated the data subject's right to secrecy under §1 DSG and declared an appeal on points of law (Revision) inadmissible, since the case turned on an individual assessment of undisputed facts and raised no question of fundamental legal importance.

### Supreme Court upholds €300,000 fine against INPS for GDPR violations in COVID bonus data

*Source: Supreme Court, 2026-05-21 — https://overview.legal/posts/53097 — original: https://gdprhub.eu/index.php?title=Cass.Civ._-_15625/2026*

Facts — Istituto nazionale della previdenza sociale (INPS, the controller) is the Italian National Institute for Social Security. In 2021, the DPA fined the controller €300,000 for its data processing activities linked to a subsidy given during the pandemic (also called “the COVID bonus”). The DPA found that the controller had postponed its second screening of verifying the eligibility of data subjects to a later stage, on the grounds that there was a need to immediately pay the subsidy. The controller considered that politicians did not fall under the scope of eligible data subjects, as they were already enrolled in a mandatory social security scheme. The controller processed their personal data from databases to cross reference them with data subjects who had applied for the subsidy. The DPA found a violation of several GDPR principles: the principle of lawfulness (Article 5(1)(a) GDPR), data minimisation (Article 5(1)(c) GDPR), accuracy (Article 5(1)(d) GDPR) and accountability (Articles 5(2) and 24 GDPR). According to the DPA, the controller had not limited the cross referencing to data subjects that had received the allowance, but to those whose applications had already been rejected. In addition, the DPA found a violation of Articles 25 and 35 GDPR, as the controller failed to conduct a data protection impact assessment (DPIA). The DPA ordered the controller to erase all personal data that had been processed unlawfully and to carry out a DPIA before resuming its processing activities. The controller appealed the decision to the Court of Rome, and argued that the DPA’s decision was unfounded. The court upheld the appeal and dismissed the DPA’s decision. The court considered that the controller had processed data subjects’ data lawfully, as it had limited the amount of data to what was necessary to verify data subjects’ eligibility. The court also considered that the processing posed a low risk for data subjects’ rights, as the data subjects’ names were not disclosed. The DPA appealed this decision to the court. Holding — The court dismissed the appeal. The court first stated that the controller processed the data lawfully under Article 6(1)(e) GDPR (public interest) and Article 6(3)(b) GDPR. While the controller processed data of specific data subjects (politicians), the court stated that national law allowed the controller to check the eligibility of all data subjects applying for the subsidy. The controller had also obtained the personal data through public databases provided by the Chambers of Parliament and Ministry of the Interior. The court also dismissed the DPA’s arguments on data minimisation (Article 5(1)(c) GDPR). The court stated that the principle of data minimisation is not absolute, and must be balanced with other interests at stake. The court took into consideration the fact that the data was publicly available and the need to quickly verify a high number of applications during a state of emergency. According to the court, there was also no other way to check applications still under review, and concluded that there was an overriding public interest in carrying out the verification process quickly. Finally, the court considered that the controller complied with Article 25 GDPR, as it processed data lawfully and in compliance with Article 5(1)(c) GDPR. In terms of data accuracy (Article 5(1)(d) GDPR), the court dismissed the DPA’s argument that the controller’s system did not eliminate the risk of “homocodes” (identical tax numbers between two or more people). The court considered that the data collected by the Chambers of Parliament and Ministry of Interior were presumed to be accurate. The court also noted that national law foresees the risk of “homocodes” and sets specific procedures in such cases, and that no actual inaccuracies were found in the controller’s verification process. Finally, the court did not find a violation of Article 35 GDPR. The court stated that the controller did not have the obligation to conduct a DPIA, as it did not meet all the necessary criteria. According to the court, the DPA failed to explain the potential high risks of large scale processing that would have justified the need for a DPIA. Given the previous dismissed arguments, the court considered that the controller had also complied with the principle of accountability (Articles 5(2) and 24 GDPR).

### Judgment of the Court (First Chamber) of 27 February 2025.#CK v Magistrat der Stadt Wien.#Request for a preliminary ruling from the Verwaltungsgericht Wien.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 15(1)(h) – Automated decision-making, including profiling – Scoring – Assessment of the creditworthiness of a natural person – Access to meaningful information about the logic involved in profiling – Verification of the accuracy of the infor

*Source: Court of Justice of the European Union, C-203/22, 2025-02-27 — https://overview.legal/posts/132146 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0203*

In Case C-203/22, the Court of Justice of the European Union interpreted Article 15(1)(h) of the GDPR in response to a preliminary ruling from the Verwaltungsgericht Wien concerning an individual's request for meaningful information about the logic of creditworthiness scoring conducted by Dun & Bradstreet Austria GmbH. The Court held that data subjects must receive sufficiently detailed explanations of the logic involved in automated profiling to understand how the decision was reached, while controllers may withhold information protected by trade secrets under Directive (EU) 2016/943 only insofar as such withholding does not render the information provided meaningless. The Court further clarified that data subjects may not use access rights to obtain personal data of third parties or to verify the absolute accuracy of the underlying information processed.

### Judgment of the Court (Third Chamber) of 28 November 2024.#Nemzeti Adatvédelmi és Információszabadság Hatóság v UC.#Request for a preliminary ruling from the Kúria.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data and the free movement of such data – Regulation (EU) 2016/679 – Data processed when drawing up a COVID-19 certificate – Data not collected from the data subject – Information to be provided – Exception to the obligation t

*Source: Court of Justice of the European Union, C-169/23, 2024-11-28 — https://overview.legal/posts/132158 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0169*

In Case C-169/23, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Kúria (Hungary) concerning whether the Budapest Metropolitan Government Office, as controller issuing COVID-19 immunity certificates, was required to provide information to data subjects under Article 14 GDPR where the personal data was not collected directly from them. The Court held that data generated by the controller in the context of its own processes falls within the Article 14(5)(c) exemption from the obligation to provide information, provided that Member State law ensures appropriate measures to protect the data subject's legitimate interests, including data security measures under Article 32. The Court also confirmed that supervisory authorities retain competence to handle complaints under Article 77(1) even where the Article 14(5)(c) exemption applies.

### VB v Natsionalna agentsia za prihodite

*Source: CJEU, C-340/21, 2023-12-14 — https://overview.legal/posts/51485 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0340*

Data breach alone does not establish inadequate security measures. Burden on controller to prove adequacy.

### Judgment of the General Court (Fifth Chamber, Extended Composition) of 24 May 2023.#Meta Platforms Ireland Ltd, formerly Facebook Ireland Ltd v European Commission.#Competition – Data market – Administrative procedure – Article 18(3) and Article 24(1)(d) of Regulation (EC) No 1/2003 – Request for information – Virtual data room – Obligation to state reasons – Legal certainty – Rights of the defence – Necessity of the information requested – Misuse of powers – Right to privacy – Proportionality –

*Source: General Court, T-451/20, 2023-05-24 — https://overview.legal/posts/132287 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62020TJ0451*

The General Court ruled on Meta Platforms Ireland Ltd's challenge against a European Commission decision requesting information under Regulation No 1/2003 in the context of a competition investigation into Facebook's data-related practices. Meta sought annulment of the contested decision, arguing, among other grounds, that the request was unnecessary, disproportionate, violated the right to privacy, and failed to provide adequate safeguards for personal data through the proposed virtual data room procedure. The judgment addresses the obligations of the Commission regarding the statement of reasons, necessity, proportionality, and rights of defense when issuing requests for information that may encompass personal data.

### VG Ansbach - 14 K 19.01274

*Source: VG Ansbach, 2021-09-22 — https://overview.legal/posts/158450 — original: https://gdprhub.eu/index.php?title=VG_Ansbach_-_14_K_19.01274*

Facts — In December 2018, the data subject filed with the DPA (the defendant in this case), a complaint under Article 77 GDPR against a lawyer who had represented the data subject in a traffic accident, before he terminated the mandate. In court proceedings after this termination, in which the lawyer's fee claim was at issue, the lawyer had submitted to the court a volume of documents containing extracts of all correspondence with the opposing insurance company, in which personal data and business secrets had not been blacked out. Since data subject had not released the lawyer from data protection and confidentiality, the data subject perceived this to be a breach of confidentiality. By letter dated 30 March 2016, the data subject contacted the lawyer regarding this breach. The data subject also complained to the Court about the lawyer's conduct, but this did not lead to any action undertaken by the Court. DPA acknowledged receipt of the complaint by letter dated 7 January 2019. In response to this complaint dated 31 May 2019, the DPA informed the data subject that it did not see any breach of data protection law in the conduct complained of and that there was therefore no reason for further supervisory measures pursuant to Article 58 GDPR. The lawyer was under no obligation to make the data subject's data unidentifiable when forwarding it to the court. According to the DPA, this processing was legitimised under Article 6(1)(f) GDPR since the pursuit of fee claims undoubtedly constitutes a legitimate interest of the lawyer. Moreover, the DPA held that, insofar as the personal data transferred were data belonging to special categories of data within the meaning of Article 9(1) GDPR (such as information on the consequences of the accident/injuries suffered by the data subject in the accident), the additional requirements of Article 9(2) GDPR were also met, as the transfer had been necessary for the assertion of legal claims. The data subject then brought the action to the Court, requesting her complaint to be accepted pursuant to Article 77 GDPR. Holding — The Court dismissed the action and found that the data subject's complaint of 29 December 2018 did not constitute a complaint under Article 77 GDPR, but a "submission" within the meaning of Article 28(4) of Directive 95/46/EC. In the present case the data subject claimed that a data protection breach occured in March 2016. As the GDPR has only been applicable since 25 May 2018, the conduct of the lawyer could therefore not have infringed the GDPR, as it was not yet applicable at that time. There was no transitional provision in German law stipulating that the GDPR also applied to facts before the above-mentioned date. The Court noted that the entry-into-force of the GDPR according to Article 99 GDPR represents a clear break between the old and the new law. Since the German legislator - unlike the Austrian legislator, for example - did not enact a transitional provision which, under certain circumstances, ordered the application of the new law also to breaches of data protection provisions committed before its entry into force, breaches committed before that date are fully subject to the old law.

### EWCA - Dawson-Damer v Taylor Wessing LLP

*Source: EWCA, 2026-07-17 — https://overview.legal/posts/125652 — original: https://gdprhub.eu/index.php?title=EWCA_-_Dawson-Damer_v_Taylor_Wessing_LLP*

Facts — This case concerns a data subject access request (SAR) under the Data Protection Act (DPA) 1998. The data subjects were beneficiaries under a trust. The data controller was a firm of solicitors, holding trust money as trustees. Following the appointment of further trustees and transfer of trust money into a new trust for other discretionary beneficiaries, the data subjects challenged the validity of these appointments and served the data controller with a SAR under section 7(2) DPA 1998. The data controller refused to make the disclosure, stating that the personal data was covered by Legal Professional Privilege (LPP), and therefore exempted from disclosure under Schedule 7 para. 10 DPA 1998. Furthermore, the data controller asserted that the supply of information required a disproportionate effort. The data subjects contended that many categories of personal data held by the data controller were not privileged and that, if any, the only privilege on which the data controller could rely was litigation privilege. The data subjects applied to the court for a declaration under section 7(9) DPA 1998 that the data controller had not complied with the request and to oblige the data controller to comply with the SAR. At trial, the court agreed with the data controller and refused to make such an order. The appellate court had to determine: whether, taking a narrow view, the LLP exception is limited to documents subject only to legal professional privilege under English law; whether, if the narrow view is correct, any further search would involve "disproportionate effort" for the purposes of section 8(2) DPA 1998 so that the data controller is excused from doing so; whether the exercise of the court’s discretion under section 7(9) DPA 1998 can be refused because the data subject's real motive was to use the information in legal proceedings against the data controller. Holding — The Court of Appeal held that 'privilege' in the LLP exception is limited to legal professional privilege. It falls to the data controller to show that the supply of a copy of the information in permanent form would involve disproportionate effort. The High Court judge was wrong not to exercise its discretion under section 7(9) DPA 1998 to order the data controller to comply with the request. On Issue 1 - Extent of the Legal Professional Privilege Exception: The purpose of Directive 95/46/EC (the Directive) was to regulate the activities of data controllers on a territorial basis. Therefore, the words "legal proceedings" in sched. 7 para. 10 DPA 1998 refer to legal proceedings in any part of the UK. If Parliament had intended to legislate for events which occur outside the territory of the UK, it would have introduced provisions specifying which parts of the world were relevant for this purpose and under which conditions the privilege applied. The LPP exception is expressly limited to legal professional privilege. Documents not disclosable to a beneficiary of a trust under trust law principles are not within the LPP exception. Insofar as the exception was interpreted purposively as also including documents covered by the trustees' right of non-disclosure, the Directive would have to name appropriate objectives which could support an interpretation along these lines. However, the DPA does not contain such exceptions. The court concluded at para. 45 that the LPP exception “relieves the data controller from complying with a SAR only if there is relevant privilege according to the law of any part of the UK.” Since the data in question is not covered by the LPP under English law and no other exemption under the DPA 1998 applies, the SAR must be granted. On Issue 2 - Whether compliance with the request would involve disproportionate effort: The public interest reasons set out in the Directive for giving people control over the data held about them require that SARs should be enforced so far as possible. Under section 8(2) DPA 1998 the data controller is obliged to supply copies of information constituting personal information to the data subject, "unless …the supply of such a copy is not possible or would involve disproportionate effort." The effort, the data controller undertakes must be weighed in a proportionality exercise against the potential benefits that the provision of the information could bring to the data subject. That includes the possibility that there may be limits to a search in certain circumstances, see Ezsias v Welsh Ministers [2007] EWHC B15 (QB). The court held at para. 75 ff, that “It falls to the data controller to show that the supply of a copy of the information in permanent form would involve disproportionate effort”. However, “disproportionate effort must involve more than an assertion that it is too difficult to search through voluminous papers”. The data controller “must produce evidence to show what it has done to identify the material and to work out a plan of action.” On Issue 3 - Whether the request can be declined because the data subject intended to use the information against the data controller: The purpose of the Directive is to protect fundamental rights conferred by EU law. The court found that nothing in Directive or the DPA 1998 limits the purpose for which data subjects may request their data or allows data controllers not to provide data based solely on the on the basis of the purpose of the data subject. Also, Parliament has not expressly required data subjects to show that they have no other purpose. The court distinguished Dunn v Durham County Council [2003] 1 WLR 2305, Lin & Anor v Commissioner of Police of the Metropolis [2015] EWHC 2484 and Kololo v Metropolitan Police Commissioner [2015] 1 WLR 3702. Durant v Financial Services Authority [2004] FSR 573 at para. 27 also does not establish a “no other purpose rule” and should only be interpreted to mean that “a person could not claim that something was personal data because it would assist him in obtaining discovery or in litigation or complaints against third parties.” (para. 111) The court found that the trial judge had wrongly refused to enforce the request just because the appellants intended to use the information obtained in other proceedings. The section 7(9) DPA 1998 discretion must be applied with a view to fulfilling the purposes of the DPA.

### Judgment of the Court (Third Chamber) of 21 December 2023.#ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, Körperschaft des öffentlichen Rechts.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 6(1) – Conditions for lawful processing – Article 9(1) to (3) – Processing of special categories of data – Data concerning heal

*Source: Court of Justice of the European Union, C-667/21, 2023-12-21 — https://overview.legal/posts/132276 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0667*

The CJEU (Third Chamber) ruled on a preliminary reference from the Bundesarbeitsgericht in a case where ZQ sought compensation from his employer, Medizinischer Dienst der Krankenversicherung Nordrhein, for allegedly unlawful processing of his health data in connection with an assessment of his working capacity. The Court addressed the conditions under which a health insurance medical service may lawfully process special categories of health data of its own employees under GDPR Articles 6(1) and 9(2)(h)/(3), and clarified the scope of the right to compensation for non-material damage under Article 82(1), including the relevance of the controller's negligence. No fine was imposed, as the ruling concerns the interpretation of GDPR provisions for the referring court's application.

### French Supreme Admin Court partly upholds challenge to graduated response IP data decree

*Source: Supreme Administrative Court, 2026-04-30 — https://overview.legal/posts/122869 — original: https://gdprhub.eu/index.php?title=CE_-_N._433539*

Facts — Several digital rights organisations asked the Prime Minister to repeal Decree No. 2010-236 of 5 March 2010. The decree regulated an automated personal data processing system used by the French authority for freedom of communications (ARCOM, hereinafter the French authority) for France’s online copyright enforcement mechanism, known as the graduated response procedure. Under this system, the French authority could receive IP addresses linked to alleged copyright infringements and request the corresponding subscriber identity data from electronic communications operators. This data could then be used to send warnings to subscribers and, in repeated cases, refer the matter to the public prosecutor. The applicants argued that the decree allowed the French authority to access personal data linked to IP addresses without sufficient safeguards under EU law. The court had previously referred questions to the CJEU, which ruled in Case C-470/21 that such access may be allowed, but only under strict conditions. Following the CJEU judgment, the court reviewed whether the French decree complied with EU law. Holding — The court partly upheld the action. First, the court held that EU law allows the general and indiscriminate retention of IP addresses for combating criminal offences in general only where serious interference with private life is effectively excluded. This requires strict separation between different categories of retained data, secure technical safeguards and regular monitoring by an independent public authority. The court found that French law did not require electronic communications operators to retain subscriber identity data and IP-related data under these conditions. Therefore, the decree was unlawful insofar as it allowed the French authority to process data that had not necessarily been retained in compliance with EU-law safeguards. Second, the court held that the French authority may access subscriber identity data linked to IP addresses in order to identify persons suspected of online copyright infringements and send the first two warnings under the graduated response procedure. However, the court distinguished the third access to such data. At that stage, the authority is no longer dealing with an isolated identification request: it has already linked the same person’s identity twice with alleged unlawful online activity and with the protected works concerned. A third access therefore allows the authority to build a more detailed picture of the person’s conduct and may reveal sensitive aspects of their private life. It also marks a more serious procedural stage, since it may lead to a registered letter and ultimately to referral to the public prosecutor. For that reason, EU law requires prior authorisation by a court or an independent administrative body before this third access takes place. The decree did not provide for such prior review, so the court held that it was unlawful to that extent. For this third access, EU law requires prior authorisation by a court or an independent administrative body. The decree did not provide for such prior review. The court therefore held that the decree was unlawful to that extent. The court annulled the Prime Minister’s refusal to repeal the unlawful parts of the decree and ordered their repeal. It also held that the French authority must stop applying the unlawful provisions. However, the French authority may still access identity data for the first and second warnings, and may request access in serious copyright offence cases under the conditions set out in the judgment.

### Judgment of the Court (Third Chamber) of 11 April 2024.#GP v juris GmbH.#Request for a preliminary ruling from the Landgericht Saarbrücken.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 82 – Right to compensation for damage caused by data processing that infringes that regulation – Concept of ‘non-material damage’ – Impact of the seriousness of the damage suffered – Liability of the controlle

*Source: Court of Justice of the European Union, C-741/21, 2024-04-11 — https://overview.legal/posts/132262 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0741*

In Case C-741/21, the Court of Justice of the European Union (Third Chamber) addressed a preliminary reference from the Landgericht Saarbrücken in proceedings between data subject GP and juris GmbH concerning GP's claim for compensation under Article 82 GDPR after the company processed his personal data for marketing purposes despite his objections. The Court held that "non-material damage" under Article 82(1) GDPR must be interpreted broadly and is not subject to a seriousness threshold, that a controller may be exempt from liability under Article 82(3) if it proves it was not in any way responsible for the infringement (including where a person acting under its authority under Article 29 was at fault), and that the criteria for administrative fines under Article 83 GDPR do not apply to the assessment of compensation amounts.

### Judgment of the Court (Third Chamber) of 25 January 2024.#BL v MediaMarktSaturn Hagen-Iserlohn GmbH.#Request for a preliminary ruling from the Amtsgericht Hagen.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Interpretation of Articles 5, 24, 32 and 82 – Assessment of the validity of Article 82 – Inadmissibility of the request for an assessment of validity – Right to compensation for damage caused by

*Source: Court of Justice of the European Union, C-687/21, 2024-01-25 — https://overview.legal/posts/132272 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0687*

In Case C-687/21, the Court of Justice of the European Union interpreted Articles 5, 24, 32, and 82 of the GDPR in response to a preliminary ruling request from the Amtsgericht Hagen in proceedings between data subject BL and MediaMarktSaturn Hagen-Iserlohn GmbH concerning alleged non-material damage from personal data transmitted to an unauthorized third party due to employee error. The Court held that a controller's infringement of GDPR security obligations through employee error can give rise to a right to compensation under Article 82, that the severity of the infringement may be relevant to assessing both the appropriateness of protective measures and the existence of damage, and that the concept of non-material damage should be interpreted broadly without requiring a minimum threshold of severity. No fine was imposed, as the ruling addresses interpretation of GDPR provisions rather than administrative penalties.

## Guidance

### Toolbox on essential data protection safeguards for enforcement cooperation between EEA data protection authorities and competent data protection authorities of third countries

*Source: EDPB, toolbox-on-essential-data-protection-safeguards-for-enforcement-en, 2022-03-14 — https://overview.legal/posts/125962 — original: https://www.edpb.europa.eu/documents/other-guidance/toolbox-on-essential-data-protection-safeguards-for-enforcement_en*

Adopted Toolbox on essential data protection safeguards for enforcement cooperation between EEA data protection authorities and competent data protection authorities of third countries Adopted on 14 Mar c h 2022 2 Adopted The European Data Protection Board Having regard to Article 70 (1)(u) and Article 50(a) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the…

### Guidelines 2/2020 on articles 46 (2) (a) and 46 (3) (b) of Regulation 2016/679 for transfers of personal data between EEA and non-EEA public authorities and bodies

*Source: EDPB, guidelines-22020-on-articles-46-2-a-and-46-3-b-of-regulation-2016679-for-en, 2020-12-15 — https://overview.legal/posts/126098 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-22020-on-articles-46-2-a-and-46-3-b-of-regulation-2016679-for_en*

Adopted 1 Guidelines 2/2020 on a rticles 46 (2) (a) and 46 (3) (b) of Regulation 2016/679 for transfers of personal data between EEA and non - EEA public authorities and bodies Version 2 .0 Adopted on 1 5 December 2020 Adopted 2 Version history Version 2.0 15 December 2020 Adoption of the Guidelines after public consultation Version 1.0 18 February 2020 Adoption of the Guidelines for public consulation Adopted 3 Adopted 4 The European Data Protection Board Having regard to Article 70 (1e) of…

### Guidelines 03/2020 on the processing of data concerning health for the purpose of scientific research in the context of the COVID-19 outbreak

*Source: EDPB, guidelines-032020-on-the-processing-of-data-concerning-health-for-the-purpose-en, 2020-04-21 — https://overview.legal/posts/126170 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-032020-on-the-processing-of-data-concerning-health-for-the-purpose_en*

Adopted 1 Guidelines 03 /2020 on the processing of data concerning health for the purpose of scientific research in the context of the COVID - 19 outbreak Adopted on 21 April 2020 Adopted 2 Version history Version 1.1 30 April 2020 Minor corrections Version 1. 0 21 April 2020 Adoption of the Guidelines Adopted 3 Adopted 4 The European Data Protection Board Having regard to Article 70 (1) (e) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the…

### Opinion 3/2019 concerning the Questions and Answers on the interplay between the Clinical Trials Regulation (CTR) and the General Data Protection regulation (GDPR)

*Source: EDPB, opinion-32019-concerning-the-questions-and-answers-on-the-interplay-en, 2019-01-23 — https://overview.legal/posts/126252 — original: https://www.edpb.europa.eu/documents/legislative-opinion/opinion-32019-concerning-the-questions-and-answers-on-the-interplay_en*

1 Opinion 3/ 2 019 c oncerning the Questions and Answers on the interplay between the Clinical Trials Regulation (CTR) and the General Data Protection regulation (GDPR) (art. 70. 1. b)) Adopted on 23 January 2019 2 3 The European Data Protection Board Having regard to Article 70.1.b of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data,…

### Draft administrative arrangement following EDPB opinion 04/2019 for the transfer of personal data between each of the European Economic Area (“EEA”) Authorities set out in Appendix A and each of the non-EEA Authorities set out in Appendix B

*Source: EDPB, draft-administrative-arrangement-following-edpb-opinion-en, 2019-01-07 — https://overview.legal/posts/126258 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/draft-administrative-arrangement-following-edpb-opinion_en*

Draft January 7 , 201 9 Draft administrative a rrangement for the transfer of personal data between Each of t he European Economic Area (“ E EA ”) Authorities set out in Appendix A and Each of t he non - E EA Authorities set out in Appendix B each a n “ Authority ”, together the “ Authorities ” , acting in good faith, will apply the safeguards specified in th is administrative arrangement (“Arrangement”) to the transfer of personal data between them , recognizing the importance of the…

### Article 29 Working Party - Guidelines on transparency under Regulation 2016/679

*Source: EDPB, article-29-working-party-guidelines-on-transparency-under-regulation-2016679-en, 2018-04-11 — https://overview.legal/posts/126340 — original: https://www.edpb.europa.eu/documents/guideline/article-29-working-party-guidelines-on-transparency-under-regulation-2016679_en*

ARTICLE 29 DATA PROTECTION WORKING PARTY This Working Party was set up under Article 29 of Directive 95/46/EC. It is an independent European advisory body on data protection and privacy. Its tasks are descr bed in Article 30 of Directive 95/46/EC and Article 15 of Directive 2002/58/EC. The secretariat is provided by Directorate C (Fundamental Rights and Union Citizenship) of the Europe an Commission, Directorate General Justice, B - 1049 Brussels, Belgium, Office No MO - 59 02/013. Website:…

### Art. 29 WP Guidelines on GDPR transparency requirements (WP260 rev.01)

*Source: EDPB, edpb-guidelines-on-transparency, 2025-11-21 — https://overview.legal/posts/38076 — original: https://www.edpb.europa.eu/system/files/2023-09/wp260rev01_en.pdf*

The Article 29 Data Protection Working Party issued these guidelines (WP260 rev.01), adopted on 29 November 2017 and last revised on 11 April 2018, to provide interpretive and practical guidance on the transparency requirements under the GDPR (Articles 12–14). The document addresses the form, timing, content, and modalities of information provided to data subjects, including issues such as plain language, layered privacy notices, information for children, and exceptions to the obligation to provide information. No fines or enforcement actions are imposed, as this is a guidance document rather than an enforcement decision.

### Guidelines 01/2023 on Article 37 Law Enforcement Directive

*Source: EDPB, guidelines-012023-on-article-37-law-enforcement-directive-en, 2024-06-19 — https://overview.legal/posts/125738 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-012023-on-article-37-law-enforcement-directive_en*

Adopted 1 Guidelines 0 1 / 2023 on Article 37 Law Enforcement Directive V ersion 2 . 1 Adopted on 19 June 2024 Adopted 2 Version history Version 1.0 27 September 2023 Adoption of the Guidelines for public consultation Version 2.0 19 June 2024 Adoption of the Guidelines after public consultation Version 2.1 30 September 2024 Minor corrections in footnotes 10 and 57 Adopted 3 Executive summary These guidelines provide guidance on the application of Article 37 LED, in particular on the legal…

## Enforcement decisions

### APDCAT sanctions Madremanya City Council for exposing applicants' sensitive data in tender

*Source: APDCAT (Catalonia), 2026-07-17 — https://overview.legal/posts/184715 — original: https://gdprhub.eu/index.php?title=APDCAT_(Catalonia)_-_PS-0036/2026*

Facts — On 8 May 2025, Madremanya City Council, acting as controller, published on its notice board two administrative acts concerning a tender procedure for the award of a social housing lease. The documents expressly disclosed the identities of the applicants. On 9 May 2025, the controller replaced the original documents with revised versions in which the applicants’ names and surnames were partially redacted, leaving only their initials visible. However, the redaction was performed manually and did not effectively conceal the information, as it remained possible to infer the length of the names and surnames and to identify some of their letters. In addition to the applicants’ identifying information, the documents disclosed detailed financial data, including the exact annual net income of each household. They also revealed information concerning particularly sensitive personal circumstances, including dependency, gender-based violence and addiction, which had been used to calculate the applicants’ respective scores. No adequate anonymisation or redaction measures had been implemented. In July and November 2025, the DPA requested that the controller provide specific information concerning certain aspects of the processing. The controller’s failure to respond or cooperate hindered the DPA’s ability to exercise its investigative powers. Holding — The DPA held that the controller violated Article 5(1)(c) GDPR by publishing personal data that were not necessary for the purpose pursued. The DPA acknowledged that publishing information about the procedure could serve the objective of administrative transparency. However, transparency did not justify disclosing identifying data together with detailed financial information and sensitive personal or family circumstances. The controller had to limit the processing to data that were necessary and proportionate to that objective and consider less intrusive alternatives. The DPA found that the controller’s subsequent redaction did not amount to effective anonymisation. Although most of the characters had been concealed, the applicants could still potentially be reidentified from their initials, the length of their names and surnames and other contextual information. This risk was particularly significant because the municipality had only 277 inhabitants. The controller should therefore have applied complete anonymisation or a pseudonymisation method preventing direct or indirect identification. The DPA also held that the controller violated Article 5(1)(f) GDPR and the duty of confidentiality under Article 5 LOPDGDD. The published documents disclosed the applicants’ exact household income, household composition and scores linked to circumstances such as dependency, addiction, gender-based violence, single-parent status and age. Although this information was relevant to assessing the applications, it was unnecessary to make it publicly accessible in a form linked to identifiable individuals. The DPA considered that the violations of the data-minimisation and confidentiality principles constituted a medial concurrence of infringements. The failure to anonymise the applicants’ identities was the necessary means through which their sensitive personal and family circumstances were disclosed. Nevertheless, the DPA formally declared separate violations of Articles 5(1)(c) and 5(1)(f) GDPR. Additionally, the DPA held that the controller violated Article 31 GDPR by failing to respond to two information requests. This failure breached the controller’s duty to cooperate with the supervisory authority and obstructed the exercise of the DPA’s investigative powers.

### CNPD (Portugal) - Deliberação 2019/494

*Source: CNPD (Portugal), 2019-09-03 — https://overview.legal/posts/122872 — original: https://gdprhub.eu/index.php?title=CNPD_(Portugal)_-_Deliberação_2019/494*

Facts — In its Opinion 20/2018 concerning the draft of Law 58/2019 which ensures the implementation of the GDPR in the portuguese national legal framework, the DPA drew the attention of the national legislator to a set of provisions that could potentially violate EU law, particularly the GDPR. The DPA emphasized the primacy of EU law as outlined in the EU treaties, particularly reflecting on Article 288 of the Treaty on the Functioning of the European Union (TFEU) and reinforced by the jurisprudence of the CJEU, which has consistently stated that national laws cannot obstruct the direct applicability of EU regulations and must comply with EU law to ensure uniform implementation across the Member States. However, Law 58/2019 came into force without incorporating all of the DPA's recommendations. The DPA explains that the decision to not apply some of its provisions aims to ensure legal certainty, reinforcing the importance of consistent GDPR application without being hindered by conflicting national rules. Holding — The DPA has decided to disapply the following provisions of Law 58/2019, in cases of personal data processing under its review due to their conflict with the GDPR: Article 2(1)(2): This article broadens the territorial scope of the GDPR to encompass all personal data processing within national territory and processing linked to national establishments outside the territory. The DPA believes this contradicts Article 3 and Article 56 of the GDPR, which outlines the applicable law in cross-border situations. Additionally, it undermines the one-stop-shop mechanism and fails to address instances where the GDPR applies, such as in Portuguese embassies, consulates, ships, and aircraft. Article 20(1): This article states that the right to be informed and the right of access cannot be exercised when a duty of secrecy is imposed on the data controller/processor. In the view of the DPA, this article lacks legal relevance in relation to the GDPR, as it merely repeats provisions already present in the GDPR, particularly concerning the possibility of restricting the data subject's right to information in cases where data collection is indirect and a legal duty of confidentiality exists. Regarding the possibility of restricting the right to information when collecting data directly from the data subject, this right can only be restricted under the provisions of Article 23 GDPR, and Law58/2019 does not meet the requirements therein, thus contradicting the norms of the GDPR and the Charter of Fundamental Rights. Article 23: This article allows public authorities to reuse personal data for any public interest without ensuring compliance with principles of purpose limitation and data minimization (Article 5 GDPR) and could lead to potential misuse of personal data and a violation of individuals’ rights, as it does not ensure that the reuse of data serves the original purpose for which it was collected nor respecting the requirements imposed in Article 23 GDPR. Article 28(3)(a): The employee's consent cannot be the legal basis if the processing results in a legal or economic advantage for the employee. The Portuguese DPA considers it to be a contraction of the doctrine established by European institutions, which accepts employee consent in situations where the act of giving or refusing consent does not, in itself, have negative consequences for the employee. The DPA therefore believes that this provision does not protect the dignity, fundamental rights, and legitimate interests of employees, and thus fails to meet the requirements set forth in Article 9 (2) (b) and Article 88 GDPR. Regime of Administrative Offenses – Articles 37, 38, and 39: The DPA notes that some of the violations outlined in the law contradict the exhaustive list provided in the GDPR (Article 83). The DPA also criticizes the distinction in sanctioning frameworks based on the size of companies and the collective or individual nature of the entities conducting data processing, as the impact on personal data does not depend on those characteristics but rather on the nature of the activity being carried out. Article 61(2) states that "if the expiration of consent is the reason for terminating a contract in which the data subject is a party, the processing of data is lawful until this occurs." The DPA notes that this provision is incongruent, conflating two types of legal basis: consent and contract execution. The contract in which the data subject is a party is sufficient to justify the processing of the data necessary for its execution. Regarding the reasons that led to publish this decision, the Portuguese DPA clarifies that it did so in order to ensure the transparency of its future decision-making processes and, in this regard, contribute to legal certainty and security. It also clarifies that the non-application, in future specific cases, of the legal provisions listed above results in the direct application of the GDPR provisions that were manifestly restricted, contradicted, or compromised in their useful effect.

### Grupo Valsor Y Losan, S.L.: Insufficient technical and organisational measures to ensure information security

*Source: Spanish Data Protection Authority (aepd), 2020-02-14 — https://overview.legal/posts/46321 — original: https://www.enforcementtracker.com/ETid-206*

The controller had disclosed personal data to a third party in a property purchase agreement (breach of principles of integrity and confidentiality of personal data)

### Tietosuojavaltuutetun toimisto (Finland) - TSV/4630/2023

*Source: Tietosuojavaltuutetun toimisto (Finland), 2026-07-22 — https://overview.legal/posts/184713 — original: https://gdprhub.eu/index.php?title=Tietosuojavaltuutetun_toimisto_(Finland)_-_TSV/4630/2023*

Facts — A company that provides comparison services for loans and financial products (the controller) received a loan application submitted on the data subject’s behalf in October 2022. The data subject made an access request in November 2022 – they suspected the misuse of their personal data as they had not submitted the loan application themselves. The data subject provided their name, phone number, and email address as identifying information in connection with the access request. The controller did not provide the requested information; instead, it asked the data subject to disclose their residential address and personal identification number as well as to sign the access request electronically using strong authentication in order to verify their identity. The data subject refused to comply with this request and filed a complaint with the DPA, stating that the controller’s procedure for verifying the identity of the data subject in connection with an access request violated Articles 5(1)(c), 12(2) and (6), and 25(2) GDPR. The controller considered the additional information necessary to identify the correct individual and avoid providing the data subject’s information to an unauthorised third party. Holding — The DPA found no GDPR violation and held that the controller was entitled to request the data subject to provide additional information necessary to verify their identity pursuant to Article 12(6) GDPR. The controller’s procedure was also in line with the principle of data minimisation laid down in Article 5(1)(c) GDPR. According to the DPA, the personal data originally provided by the data subject when making the access request could not be considered sufficient identifying information since several people might have the same name and the email address and the phone number of the data subject could also be known to third parties. The DPA considered that the controller had a legitimate reason to request that the data subject provide additional information to verify their identity, as the controller processes personal data concerning the financial status of its customers.

### HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens

*Source: HDPA (Greece), 2026-05-13 — https://overview.legal/posts/144044 — original: https://gdprhub.eu/index.php?title=HDPA_(Greece)_-_12/2026*

Facts — The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of Undesirable Aliens. In response to the Authority's request for clarifications, the competent Directorate of the Ministry of Citizen Protection informed the DPA that: • By a decision dated 27-07-2017, an entry ban and registration in the National Registry of Undesirable Aliens were imposed on the complainant for reasons of national security. • Following temporary 48-hour lifts of the measure for humanitarian reasons in 2019, the entry ban was re-imposed. • Subsequent decisions in 2020, 2023, and 2025 maintained the entry ban and renewed his registration in the National Registry of Undesirable Aliens for successive three-year periods, as the grounds for registration remained active. • The explicit grounds and documentation behind the registration were not disclosed to the complainant because the competent Directorate classified the file as restricted/classified service material. The complainant and his attorney attended a DPA hearing on 22-04-2026, arguing that the registration lacked specific, adequate, or definitive justification regarding any threat to public order or national security. They noted that the complainant has no criminal convictions, poses no threat, and possesses strong ties, residency, and business operations in the region of Northern Epirus and Greece, meaning the entry ban severely disrupts his professional and family life. Holding — According to the provisions of Article 82(1) of Law 3386/2005, foreign nationals whose presence in Greek territory constitutes a threat to national security, public safety, or public order can be registered in the National Registry of Undesirable Aliens, with registrations subject to an ex officio review every three years. Furthermore, pursuant to the provisions of Article 54(2) and Article 55(4) of Law 4624/2019 (the Greek law implementing the GDPR), the data controller is legally empowered to restrict or omit the provision of information and to deny a data subject access to their personal data when dictated by reasons of national security or public order. These national provisions are explicitly anchored in Article 23 GDPR (specifically Article 23(1)(a)GDPR and Article 23(1)(c) GDPR), which permits Member State law to restrict the scope of the obligations and data subject rights (such as the right to be informed under Article 13 GDPR - Article 14 GDPR and the right of access under Article 15 GDPR) to safeguard national security and public security. In the present case, the evidence demonstrated that the complainant's initial registration and subsequent renewals in the National Registry of Undesirable Aliens were executed lawfully for reasons of national security. The Ministry of Citizen Protection, acting as the data controller, exercised its legal discretion under these frameworks to weigh these interests and correctly determined that the underlying operational decision constitutes classified material that cannot be disclosed to the data subject. Consequently, the fundamental principles of data protection law were not breached, and the Hellenic DPA rejected the complaint as unfounded.

### CEDICO, CENTRO DE DIAGNÓSTICO POR LA IMÁGEN, S.L.: Non-compliance with general data processing principles

*Source: Spanish Data Protection Authority (aepd), 2021-09-20 — https://overview.legal/posts/46959 — original: https://www.enforcementtracker.com/ETid-844*

The Spanish DPA (AEPD) has imposed a fine on CEDICO, CENTRO DE DIAGNÓSTICO POR LA IMÁGEN, S.L.. The data subject filed a complaint with the AEPD. He had requested an MRI scan of his knee due to an accident at work. In addition, he had contacted his insurance company in order to obtain a sick leave. The insurance company then contacted the controller, who transmitted the data subject's medical records. In doing so, the controller also provided the insurer with the report of a previous MRI scan of

### aiComply S.r.l.: Insufficient technical and organisational measures to ensure information security

*Source: Italian Data Protection Authority (Garante), 2021-06-10 — https://overview.legal/posts/46923 — original: https://www.enforcementtracker.com/ETid-808*

The identity of whistleblowers must be protected by special confidentiality rules, as the information processed is particularly sensitive and the risk of retaliation and discrimination in the work environment is high. In this context, the controller is obliged to comply with the principles of data protection and to ensure the integrity and security of the data. Against this background, the Italian Data Protection Authority (Garante) fined Aeroporto Guglielmo Marconi di Bologna S.p.a. EUR 40,000

### Basketball Federation of Castilla and Leon: Insufficient legal basis for data processing

*Source: Spanish Data Protection Authority (aepd), 2020-08-28 — https://overview.legal/posts/46501 — original: https://www.enforcementtracker.com/ETid-386*

The Basketball Association transmitted personal data to third parties, which were subsequently published on the Internet without consent of the data subjects. In addition, the data protection authority found that the Basketball Federation also disclosed personal data to a newspaper, violating - in addition - the principle of integrity and confidentiality (Art. 5 (1) f) GDPR).

## Recent developments

### Three recommendations from the AP (Autoriteit Persoonsgegevens - Dutch Data Protection Authority) compiled together.

*Source: Government, 2025-03-10 — https://overview.legal/posts/52247*

Three recommendations from the Dutch Authority for the Financial Markets (Autoriteit Financiële Markten - AP) combined: (regarding the handling of data breaches; a task to improve the privacy organization of the Tax Authority; and exemption from the obligation of tax confidentiality in cases of suspected violations of tax integrity under Article 67, paragraph 3, of the Act on Financial Supervision).

### EU-wetgeving inzake datagovernance definitief vastgesteld

*Source: NL EU Court Expert, 2022-06-08 — https://overview.legal/posts/6302 — original: https://ecer.minbuza.nl/-/eu-wetgeving-inzake-datagovernance-definitief-vastgesteld?redirect=%2Fecer%2Fnieuws%3Fq%3Dprivacy%2520OR%2520avg%26f%3D%26t%3D#entry-303*

The new data governance regulation sets out the conditions for the reuse of certain government data. In addition, the regulation provides a notification and oversight framework for the provision of data mediation services. Furthermore, the regulation contains a framework for the voluntary registration of entities that collect and process data made available for altruistic purposes. The rules will apply from September 2023.

### Europol wordt gevraagd om persoonlijke gegevens over te dragen aan een Nederlandse activist.

*Source: Fair Trials, 2022-09-15 — https://overview.legal/posts/51821*

De Europese Toezichthouder op de Bescherming van Persoonsgegevens heeft Europol opgedragen om persoonlijke gegevens over te dragen aan de Nederlandse activist Frank van der Linde. Dit besluit is het resultaat van een onderzoek van twee jaar naar de manier waarop Europol de persoonlijke gegevens van Van der Linde bewaart en verwerkt.

### Het Italiaanse bedrijf SA heeft juridische stappen ondernomen tegen een gemeente vanwege het gebruik van haar videosurveillance systeem en omdat het haar Functionaris Gegevensbescherming (FG) heeft aangesteld om de gemeente in een rechtszaak te vertegenwoordigen.

*Source: GDPRhub, 2022-09-28 — https://overview.legal/posts/51807*

Tenslotte oordeelde de gegevensbeschermingsautoriteit dat de verantwoordelijke, door de functionaris gegevensbescherming (FG) te betrekken bij de verdediging in rechtszaken, de FG in een positie van belangenconflict bracht, in strijd met artikel 38(6) van de AVG. Dit was met name omdat dit ertoe leidde dat de betrokkene het gevoel had niet in staat te zijn om contact op te nemen met de FG met betrekking tot kwesties die verband houden met de verwerking van hun persoonlijke gegevens en de uitoefening van hun rechten zoals uiteengezet in artikel 38(4) van de AVG.

### Europol told to hand over personal data to Dutch activist

*Source: Fair Trials, 2022-09-15 — https://overview.legal/posts/6280 — original: https://www.fairtrials.org/articles/news/fair-trials-welcomes-a-decision-by-the-european-data-protection-supervisor-edps-ordering-europol-to-hand-over-personal-data-to-dutch-activist-frank-van-der-linde/#entry-356*

The European Data Protection Supervisor ordered Europol to hand over personal data to Dutch activist Frank van der Linde. The decision is the result of a two-year investigation into Europol's possession and storage of van der Linde's personal data.

## Literature

### Does de-identification require consent under the GDPR and English common law?

*Source: Journal of Data Protection Privacy, 2020-06-01 — https://overview.legal/posts/132522 — original: https://doi.org/10.69554/wzzy1745*

Data de-identification has many benefits in the context of the General Data Protection Regulation (GDPR). One of the recurring questions is whether consent is required to anonymise or de-identify data. In this paper, the authors make the case that no consent is required for anonymisation or other forms of de-identification under the GDPR, although additional conditions have to be met where special category data is anonymised. Further, under the English equitable duty of confidentiality, consent

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Integrity and Confidentiality Principle** — https://overview.legal/topics/integrity-confidentiality-principle
  While security and beveiliging topics exist, there is no dedicated topic for the integrity and confidentiality principle specifically as articulated in GDPR Art
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Law Enforcement** — https://overview.legal/topics/law-enforcement
  Processing for law enforcement purposes

---
Generated by overview.legal · https://overview.legal/topics/professional-secrecy · 2026-08-22
