# Profiling — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/profiling
> Sources are cited per item. Verify against the official texts before relying on them.

Automated processing to evaluate personal aspects

## Overview

## Legal Framework

Profiling is defined in [Article 4(4) GDPR](/laws/gdpr/art-4#par-4) as a form of automated processing that evaluates personal aspects of an individual. The definition is deliberately broad, encompassing both analysis and prediction of characteristics ranging from economic situation to behaviour and location.

Profiling triggers layered transparency obligations. Where data is collected from the data subject, [Article 13(2)(f)](/laws/gdpr/art-13#par-2-pnt-f) requires information about automated decision-making. Where data is obtained indirectly, [Article 14(2)(g)](/laws/gdpr/art-14#par-2-pnt-g) imposes a parallel duty. The right of access under [Article 15(1)(h)](/laws/gdpr/art-15#par-1-pnt-h) entitles the data subject to meaningful information about the logic involved, the significance, and the envisaged consequences of such processing.

## Key Developments

The CJEU's January 2025 ruling in *Mousse* (C‑394/23) confirms that the right to object under Article 21 GDPR expressly encompasses profiling based on Article 6(1)(e) or (f), requiring controllers to cease processing unless they demonstrate compelling legitimate grounds.

> "The data subject shall have the right to object, on grounds relating to his or her particular situation, at any time to processing of personal data concerning him or her which is based on point (e) or (f) of Article 6(1), including profiling based on those provisions."
> — [CJEU, C‑394/23 (Mousse), ¶10](/posts/50377#seg-10)

The EDPB's consent guidelines reinforce that where profiling forms part of automated decision-making under Article 22, explicit consent may be required, reflecting the heightened risk to data subjects.

> "Explicit consent is required in certain situations where serious data protection risk emerge, hence, where a high level of individual control over personal data is deemed appropriate."
> — [EDPB Guidelines 05/2020, §91](/posts/38053#seg-91)

Dutch enforcement has also reached the profiling ecosystem. The AP's action against Microsoft and Xandr regarding cookie-based tracking without prior consent illustrates how profiling infrastructure built on tracking cookies falls squarely within the GDPR's scope when it enables evaluation of personal aspects.

## Status of the Debate

Profiling as a legal concept is **contested in court**. While the definition in Article 4(4) is settled, its boundaries — particularly where profiling shades into automated decision-making under Article 22 — remain actively litigated. Courts diverge on whether profiling that supports (but does not itself produce) a solely automated decision triggers Article 22's safeguards. The *Mousse* ruling clarifies the objection right but does not resolve the threshold question: at what point does profiling become "solely automated" decision-making with legal or similarly significant effects. A future CJEU reference explicitly addressing that boundary would resolve the open question.

## Practical Guidance

- **Map your profiling activities against Article 4(4).** Any automated evaluation of personal aspects — credit scoring, behavioural advertising, performance monitoring — falls within the definition and triggers transparency duties under [Article 13](/laws/gdpr/art-13) or [Article 14](/laws/gdpr/art-14).
- **Provide meaningful logic information.** Under [Article 15(1)(h)](/laws/gdpr/art-15#par-1-pnt-h), data subjects must receive not just notice that profiling occurs, but meaningful information about the logic, significance, and envisaged consequences.
- **Assess Article 22 applicability.** If profiling produces decisions with legal or similarly significant effects without meaningful human intervention, explicit consent or another Article 22(2) condition is required.
- **Honour objection rights promptly.** Per *Mousse*, an objection under Article 21 halts profiling based on legitimate interests unless the controller demonstrates compelling legitimate grounds overriding the data subject's rights.
- **Verify consent quality for tracking-based profiling.** The Microsoft/Xandr enforcement confirms that profiling infrastructure relying on cookies without valid prior consent is unlawful — ensure consent is freely given, specific, and informed per EDPB Guidelines 05/2020.

## Legislation (full text of key provisions)

### Automated individual decision-making, including profiling

*Source: GDPR, gdpr-art-22-en, 2016-04-27 — https://overview.legal/posts/90485*

### Recommender systems

*Source: DSA, dsa-art-38-en, 2022-10-19 — https://overview.legal/posts/94670*

In addition to the requirements set out in Article 27, providers of very large online platforms and of very large online search engines that use recommender systems shall provide at least one option for each of their recommender systems which is not based on profiling as defined in Article 4, point (4), of Regulation (EU) 2016/679.

### Recital 71 — automated decision making and profiling rights

*Source: GDPR, gdpr-rec-71-en, 2016-04-27 — https://overview.legal/posts/91657*

The data subject should have the right not to be subject to a decision, which may include a measure, evaluating personal aspects relating to him or her which is based solely on automated processing and which produces legal effects concerning him or her or similarly significantly affects him or her, such as automatic refusal of an online credit application or e-recruiting practices without any human intervention. Such processing includes ‘profiling’ that consists of any form of automated processing of personal data evaluating the personal aspects relating to a natural person, in particular to analyse or predict aspects concerning the data subject's performance at work, economic situation, health, personal preferences or interests, reliability or behaviour, location or movements, where it produces legal effects concerning him or her or similarly significantly affects him or her. However, decision-making based on such processing, including profiling, should be allowed where expressly authorised by Union or Member State law to which the controller is subject, including for fraud and tax-evasion monitoring and prevention purposes conducted in accordance with the regulations, standards and recommendations of Union institutions or national oversight bodies and to ensure the security and reliability of a service provided by the controller, or necessary for the entering or performance of a contract between the data subject and a controller, or when the data subject has given his or her explicit consent. In any case, such processing should be subject to suitable safeguards, which should include specific information to the data subject and the right to obtain human intervention, to express his or her point of view, to obtain an explanation of the decision reached after such assessment and to challenge the decision. Such measure should not concern a child. In order to ensure fair and transparent processing in respect of the data subject, taking into account the specific circumstances and context in which the personal data are processed, the controller should use appropriate mathematical or statistical procedures for the profiling, implement technical and organisational measures appropriate to ensure, in particular, that factors which result in inaccuracies in personal data are corrected and the risk of errors is minimised, secure personal data in a manner that takes account of the potential risks involved for the interests and rights of the data subject and that prevents, inter alia, discriminatory effects on natural persons on the basis of racial or ethnic origin, political opinion, religion or beliefs, trade union membership, genetic or health status or sexual orientation, or that result in measures having such an effect. Automated decision-making and profiling based on special categories of personal data should be allowed only under specific conditions.

### Recital 30 — online identifiers enabling personal profiling

*Source: GDPR, gdpr-rec-30-en, 2016-04-27 — https://overview.legal/posts/91575*

Natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols, such as internet protocol addresses, cookie identifiers or other identifiers such as radio frequency identification tags. This may leave traces which, in particular when combined with unique identifiers and other information received by the servers, may be used to create profiles of the natural persons and identify them.

### Recital 72 — profiling subject to regulation rules

*Source: GDPR, gdpr-rec-72-en, 2016-04-27 — https://overview.legal/posts/91659*

Profiling is subject to the rules of this Regulation governing the processing of personal data, such as the legal grounds for processing or data protection principles. The European Data Protection Board established by this Regulation (the ‘Board’) should be able to issue guidance in that context.

### Recital 10 — personal data protection safeguarding

*Source: AI Act, aiact-rec-10-en, 2024-06-12 — https://overview.legal/posts/93702*

The fundamental right to the protection of personal data is safeguarded in particular by Regulations (EU) 2016/679 (11) and (EU) 2018/1725 (12) of the European Parliament and of the Council and Directive (EU) 2016/680 of the European Parliament and of the Council (13). Directive 2002/58/EC of the European Parliament and of the Council (14) additionally protects private life and the confidentiality of communications, including by way of providing conditions for any storing of personal and non-personal data in, and access from, terminal equipment. Those Union legal acts provide the basis for sustainable and responsible data processing, including where data sets include a mix of personal and non-personal data. This Regulation does not seek to affect the application of existing Union law governing the processing of personal data, including the tasks and powers of the independent supervisory authorities competent to monitor compliance with those instruments. It also does not affect the obligations of providers and deployers of AI systems in their role as data controllers or processors stemming from Union or national law on the protection of personal data in so far as the design, the development or the use of AI systems involves the processing of personal data. It is also appropriate to clarify that data subjects continue to enjoy all the rights and guarantees awarded to them by such Union law, including the rights related to solely automated individual decision-making, including profiling. Harmonised rules for the placing on the market, the putting into service and the use of AI systems established under this Regulation should facilitate the effective implementation and enable the exercise of the data subjects’ rights and other remedies guaranteed under Union law on the protection of personal data and of other fundamental rights.

### Recital 91 — high risk processing requiring impact assessment

*Source: GDPR, gdpr-rec-91-en, 2016-04-27 — https://overview.legal/posts/91697*

This should in particular apply to large-scale processing operations which aim to process a considerable amount of personal data at regional, national or supranational level and which could affect a large number of data subjects and which are likely to result in a high risk, for example, on account of their sensitivity, where in accordance with the achieved state of technological knowledge a new technology is used on a large scale as well as to other processing operations which result in a high risk to the rights and freedoms of data subjects, in particular where those operations render it more difficult for data subjects to exercise their rights. A data protection impact assessment should also be made where personal data are processed for taking decisions regarding specific natural persons following any systematic and extensive evaluation of personal aspects relating to natural persons based on profiling those data or following the processing of special categories of personal data, biometric data, or data on criminal convictions and offences or related security measures. A data protection impact assessment is equally required for monitoring publicly accessible areas on a large scale, especially when using optic-electronic devices or for any other operations where the competent supervisory authority considers that the processing is likely to result in a high risk to the rights and freedoms of data subjects, in particular because they prevent data subjects from exercising a right or using a service or a contract, or because they are carried out systematically on a large scale. The processing of personal data should not be considered to be on a large scale if the processing concerns personal data from patients or clients by an individual physician, other health care professional or lawyer. In such cases, a data protection impact assessment should not be mandatory.

### Recital 42 — prohibition of AI-predicted criminal behaviour risk assessment

*Source: AI Act, aiact-rec-42-en, 2024-06-12 — https://overview.legal/posts/93766*

In line with the presumption of innocence, natural persons in the Union should always be judged on their actual behaviour. Natural persons should never be judged on AI-predicted behaviour based solely on their profiling, personality traits or characteristics, such as nationality, place of birth, place of residence, number of children, level of debt or type of car, without a reasonable suspicion of that person being involved in a criminal activity based on objective verifiable facts and without human assessment thereof. Therefore, risk assessments carried out with regard to natural persons in order to assess the likelihood of their offending or to predict the occurrence of an actual or potential criminal offence based solely on profiling them or on assessing their personality traits and characteristics should be prohibited. In any case, that prohibition does not refer to or touch upon risk analytics that are not based on the profiling of individuals or on the personality traits and characteristics of individuals, such as AI systems using risk analytics to assess the likelihood of financial fraud by undertakings on the basis of suspicious transactions or risk analytic tools to predict the likelihood of the localisation of narcotics or illicit goods by customs authorities, for example on the basis of known trafficking routes.

### Recital 69 — prohibition of targeted ads using sensitive data

*Source: DSA, dsa-rec-69-en, 2022-10-19 — https://overview.legal/posts/95535*

When recipients of the service are presented with advertisements based on targeting techniques optimised to match their interests and potentially appeal to their vulnerabilities, this can have particularly serious negative effects. In certain cases, manipulative techniques can negatively impact entire groups and amplify societal harms, for example by contributing to disinformation campaigns or by discriminating against certain groups. Online platforms are particularly sensitive environments for such practices and they present a higher societal risk. Consequently, providers of online platforms should not present advertisements based on profiling as defined in Article 4, point (4), of Regulation (EU) 2016/679, using special categories of personal data referred to in Article 9(1) of that Regulation, including by using profiling categories based on those special categories. This prohibition is without prejudice to the obligations applicable to providers of online platforms or any other service provider or advertiser involved in the dissemination of the advertisements under Union law on protection of personal data.

### Recital 94 — very large platform recommender system adjustments

*Source: DSA, dsa-rec-94-en, 2022-10-19 — https://overview.legal/posts/95585*

The obligations on assessment and mitigation of risks should trigger, on a case-by-case basis, the need for providers of very large online platforms and of very large online search engines to assess and, where necessary, adjust the design of their recommender systems, for example by taking measures to prevent or minimise biases that lead to the discrimination of persons in vulnerable situations, in particular where such adjustment is in accordance with data protection law and when the information is personalised on the basis of special categories of personal data referred to in Article 9 of the Regulation (EU) 2016/679. In addition, and complementing the transparency obligations applicable to online platforms as regards their recommender systems, providers of very large online platforms and of very large online search engines should consistently ensure that recipients of their service enjoy alternative options which are not based on profiling, within the meaning of Regulation (EU) 2016/679, for the main parameters of their recommender systems. Such choices should be directly accessible from the online interface where the recommendations are presented.

## Case law

### VG München - M 26a K 25.5210

*Source: Administrative Court Munich, 2026-05-18 — https://overview.legal/posts/108991 — original: https://gdprhub.eu/index.php?title=VG_München_-_M_26a_K_25.5210*

Facts — The data subject had been liable to pay broadcasting contributions to the Controller, a German regional public broadcasting authority, since 2007. Following objections to several contribution assessment notices, the data subject submitted a request under Article 15 GDPR seeking a copy of all personal data processed about him by the Controller. The Controller responded by providing the categories of personal data and related information specified under § 11(8) of the German Broadcasting Contribution Treaty (RBStV), which governs data subject access requests relating to broadcasting contribution records, together with general privacy information. The data subject argued that the response was incomplete because it did not include copies of all documents containing his personal data, including correspondence with him and third parties. The Controller maintained that it had fully complied with its obligations under the RBStV. After the Controller declined to provide additional information, the data subject brought proceedings seeking disclosure of all personal data concerning him processed by the Controller. Holding — The Court held that § 11(8) of the German Broadcasting Contribution Treaty (RBStV) constituted a lawful restriction of the broader right of access under Article 15 GDPR pursuant to Article 23(1)(e) GDPR. It found that the national provision was a valid legislative measure, respected the essence of the fundamental right to data protection, and pursued an important public interest by ensuring the effective financing and administration of the public broadcasting system. The Court further held that the restriction was necessary and proportionate, noting that requiring the Controller to comply with the full scope of Article 15 GDPR across more than 44 million broadcasting contribution accounts would impose a disproportionate administrative and financial burden capable of undermining that public interest. The Court also held that § 11(8) RBStV satisfied the safeguards required under Article 23(2) GDPR by specifying the purposes of processing, categories of personal data, scope of the restriction, safeguards against misuse and unlawful access, the identity of the Controller, applicable storage periods and other statutory protections. Accordingly, while the Controller was required to disclose the categories of information specified under § 11(8) RBStV, it was not required to provide a copy of all personal data processed under Article 15(3) GDPR. As the Controller had already provided all information required under the national provision, the court dismissed the action.

### Judgment of the General Court (Tenth Chamber, Extended Composition) of 3 September 2025.#Philippe Latombe v European Commission.#Transfer of personal data to the United States – Commission Implementing Decision on the adequate level of protection of personal data ensured by the United States – Right to an effective remedy – Right to private and family life – Decisions based solely on the automated processing of personal data – Security of the processing of personal data.#Case T-553/23.

*Source: General Court, T-553/23, 2025-09-03 — https://overview.legal/posts/132137 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023TJ0553*

In Case T-553/23, French citizen Philippe Latombe sought annulment of the European Commission's Implementing Decision (EU) 2023/1795, which found that the United States ensures an adequate level of personal data protection under the EU-US Data Privacy Framework. Latombe challenged the adequacy decision on grounds including infringement of Articles 7 and 8 of the EU Charter, the right to an effective remedy, protections against solely automated decisions, and data security, arguing the framework failed to provide essentially equivalent protection to EU law. The General Court dismissed the action as unfounded, upholding the Commission's adequacy decision.

### Judgment of the Court (First Chamber) of 27 February 2025.#CK v Magistrat der Stadt Wien.#Request for a preliminary ruling from the Verwaltungsgericht Wien.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 15(1)(h) – Automated decision-making, including profiling – Scoring – Assessment of the creditworthiness of a natural person – Access to meaningful information about the logic involved in profiling – Verification of the accuracy of the infor

*Source: Court of Justice of the European Union, C-203/22, 2025-02-27 — https://overview.legal/posts/132146 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0203*

In Case C-203/22, the Court of Justice of the European Union interpreted Article 15(1)(h) of the GDPR in response to a preliminary ruling from the Verwaltungsgericht Wien concerning an individual's request for meaningful information about the logic of creditworthiness scoring conducted by Dun & Bradstreet Austria GmbH. The Court held that data subjects must receive sufficiently detailed explanations of the logic involved in automated profiling to understand how the decision was reached, while controllers may withhold information protected by trade secrets under Directive (EU) 2016/943 only insofar as such withholding does not render the information provided meaningless. The Court further clarified that data subjects may not use access rights to obtain personal data of third parties or to verify the absolute accuracy of the underlying information processed.

### Judgment of the Court (First Chamber) of 7 December 2023.#OQ v Land Hessen.#Request for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 22 – Automated individual decision-making – Credit information agencies – Automated establishment of a probability value concerning the ability of a person to meet payment commitments in the future (‘s

*Source: Court of Justice of the European Union, C-634/21, 2023-12-07 — https://overview.legal/posts/132279 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0634*

In Case C-634/21, the CJEU addressed a preliminary ruling from the Verwaltungsgericht Wiesbaden concerning OQ's challenge against Land Hessen's refusal to order SCHUFA Holding AG to grant access to and erase personal data, including a credit score. The core issue was whether the automated calculation of a probability value ("scoring") by a credit information agency regarding a person's future ability to meet payment commitments constitutes an automated individual decision-making under Article 22(1) of the GDPR when third parties use that score for their own decisions. The Court held that such scoring does not itself amount to a decision producing legal effects under Article 22(1), as it is the third party, not the credit agency, that makes the decision based on the score.

### BVwG - W256 2227693-1

*Source: Federal Administrative Court, 2023-09-28 — https://overview.legal/posts/125664 — original: https://gdprhub.eu/index.php?title=BVwG_-_W256_2227693-1*

Facts — On 05.09.2019, the Austrian DPA (DSB) notified the controller of a customer loyalty program that they were initiating an ex officio investigation. The controller responded by answering the provided questionnaire and submitting further documents. On 23.10.2019, the DPA ruled that the investigation was justified and that the declaration of consent for profiling using certain registration methods (website, app, partner company store, flyer) did not comply with the requirements of Article 4(11) GDPR and Article 7 GDPR, nor were they provided in an intelligible way. If a contract covers several aspects, the declaration of consent must be clearly distinguishable. Regarding the website and flyer, the following was found: The website says 'Enjoy your personal benefits' without providing clear information that 'personal benefits' involves profiling. In an embedded box, the relevant points were merely referred to. Information regarding profiling was only accessible by scrolling down further. Concerning the flyer, the following information was provided under the signature field: 'This signature only applies to the declaration of consent and is voluntary. Your registration [...] is also valid without a signature.' Thus, it conveyed the impression that a signature was required to confirm the registration. Consequently, the controller was required to amend the declaration and to cease using any obtained consents for the purpose of profiling prior to 01.05.2020. The controller lodged a complaint. In addition to other information, the controller stated that the data processing was in accordance with Article 6(1)(a) GDPR, and that they had a legitimate interest under Article 6(1)(f) GDPR. The DPA ruled a preliminary decision on the complaint, thereby changing the ruling that the website and flyer did not meet the requirements under Article 6(1)(a) GDPR, and thus, the processing of personal data, collected in that cases, was forbidden. The other methods ensured that the consent was clearly separated from the rest of the registration process. The controller then filed a request for referral to the court, arguing that the DPA had exceeded their corrective powers by prohibiting the processing of the data. Furthermore, the data processing for profiling would be used to manage customer memberships under Article 6(1)(b) GDPR. Following their view, processing under Article 6(4) GDPR was applicable. Additionally, the controller denied the DPA's view that a violation of the principle of good faith would foreclose a weighing of interests under Article 6(1)(f) GDPR. The court quashed the preliminary decision as the DPA had not examined the other grounds of justification for data processing under Article 6(1) GDPR in their initial decision. The DPA then lodged an appeal to the Austrian Supreme Administrative Court (Verwaltungsgerichtshof), which overturned the court's ruling (VwGH 08.02.2022, Ro 2021/04/0033). It was the court's responsibility to examine the potential legal bases, rather than overturning the DPA's decision. Therefore, the case was returned to the court. In the meantime, the controller complied with the preliminary decision by deleting the affected personal data in 2021 and changing their registration process in 2020. Holding — First, the court found that they had to formally rule on whether the DPA's decision was lawful at the time it was ruled. It is not to be considered that the controller complied with the administrative decision and fulfilled the required steps (VwGH 28.04.2022, Ra 2022/06/0056). Second, the court held that the controller did not comply with the transparency requirements regarding the layout of their declaration of consent under Article 7(2) GDPR in both cases (website, flyer). Third, the court ruled that they could not agree with DPA's view, that an invalid declaration of consent always constitutes unlawful data processing and that a review of other grounds of justification would not be necessary (CLEU in 'Meta Platforms and Others' (C-252/21) ECLI:EU:C:2023:537). Further on, the Supreme Administrative Court ruled that both, the DPA and the court are required to examine the presence of other grounds (VwGH 08.02.2022, Ro 2021/04/0033). Fourth, the court held that the controller could not base their appeal on Article 6(4) GDPR as the data processing did not satisfy the grounds of justification, nor were other grounds apparent. Inter alia, following the CLEU's preliminary ruling in 'Meta Platforms and Others' (C-252/21) ECLI:EU:C:2023:537, three cumulative requirements must be met for data processing under Article 6(1)(f) GDPR: (1) The controller or a third party must have a legitimate interest, (2) which requires the processing of that personal data, (3) and 'the fundamental rights and freedoms of the data subject' must not outweigh those interests. There were no doubts about the controller's legitimate interest in processing the personal data in question for targeted marketing purposes, as this was both necessary and reasonable. However, the data subject should have been notified about profiling. The wording 'only if the member consents' did not constitute such a notification, and therefore the data subjects were not to be expected that their personal data was used for profiling purposes. Furthermore, the controller explicitly excluded it in their general terms and conditions. Hence, the data subject's right to secrecy overrode the controller's legitimate interest. In summary, the court dismissed the controller's complaint. Last, the court held that an appeal to the Supreme Administrative Court was admissible under Article 133(4) B-VG, as no prevailing case law concerning the implementation of a declaration of consent existed. Hence, the decision relied on a legal question of fundamental importance.

### CE - 439360

*Source: CE, 2021-04-13 — https://overview.legal/posts/125663 — original: https://gdprhub.eu/index.php?title=CE_-_439360*

Facts — In February 2020 the French minister of the interior enacted the Decree No. 2020-151 of 20 February 2020 authorising the automated processing of personal data known as "mobile note-taking application" (Décret n° 2020-151 du 20 février 2020 portant autorisation d'un traitement automatisé de données à caractère personnel dénommé «application mobile de prise de notes» (GendNotes)). The app should be used on the occasion of preventive actions, investigations or interventions necessary for the exercise of judicial or administrative police missions. Among the data that can be collected is information relating to alleged racial or ethnic origin, political, philosophical or religious opinions, trade union membership, health or sexual activities or orientation. A group of human rights organisations filed a complaint with the French Constitutional Court. Dispute — Is the "GendNotes" App of the French national police force (Gendarmerie nationale) unlawfully processing special category personal data? Holding — The French Highest Administrative Court held that the decree infringed Article 4 of the Law of 6 January 1978, implementing GDPR in France, the Council of Europe Convention No. 108 for the Protection of Individuals with regard to Automatic Processing of Personal Data and Article 8 CFR, as it excessively infringed upon the right to respect for private life and the correlative right to protection of personal data, without providing appropriate safeguards for their protection in terms of the purpose of the processing and the nature of the data collected, as well as excessive data retention period, data sharing and data security. The Court discussed whether the decree violated Article 4 (a) GDPR, Article 4 (b) GDPR, Article 4 (c) GDPR, and Article 4 (e) GDPR and Article 9 GDPR. According to the Court, the processing of data did not comply with the principle of purpose limitation, as data is collected for future investigations or proceedings. However, the Court did not find a violation on the collect of special category data, given the fact that the decree establishes that this data can only be processed in case of "absolute necessity". Additionally, the Court noted that, even if the decree provides a limitation for the storage of the data, in practice this can be ignored, as the data may be used in different or further investigations, that would impede its erasure. However, they found that the decree was lawful in this regard, given that it clearly stated a retention period of 3 months to 1 year. Taken the above-mentioned into account, the French Highest Administrative Court decided that the data processed by the French national police force can no longer be used "in other data processing, in particular by means of a pre-information system". Therefore, the Court held: In Article 1° of the decree, the words "in other data processing, in particular by means of a pre-information system," are cancelled out. The State will pay €3,000 to every claimant. The rest of the application is rejected. The allowance to collect special category data is not overruled, as the Court argues that the decree only allows it when it is "absolutely necessary". This decision will be notified to the claimants: the Ligue des droits de l'homme, the associations Homosexualités et socialismes and Internet Society France, the associations Mousse, Stop Homophobie, Adheos and Familles A, the association AIDES, the Syndicat de la magistrature, the Syndicat des avocats de France, the Conseil national des barreaux, the Quadrature du Net and the International League against Racism and Anti-Semitism, the Prime Minister and the Minister of the Interior.

### Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV

*Source: CJEU, C-40/17, 2019-07-29 — https://overview.legal/posts/51478 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62017CJ0040*

Website operators using Facebook Like button are joint controllers for data collection.

### HvJ EU 9 januari 2025, C‑394/23 (Mousse).

*Source: CJEU, 2025-01-09 — https://overview.legal/posts/50377 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0394*

HvJ EU 9 januari 2025, C‑394/23 (Mousse). Artikelen: 5(1)(c), 6(1), en 21 AVG Onderwerp : Beginsel van minimale gegevensverwerking Gek genoeg verwijst het HvJ EU zelf niet naar HvJ EU 1 augustus 2022, C‑184/20 (Vyriausioji tarnybinės etikos komisija), maar dat had hier ook heel logisch geweest.

### HvJ EU: Privacy Shield ongeldig verklaard (Schrems II)

*Source: Hof van Justitie EU, 2020-07-16 — https://overview.legal/posts/1 — original: https://eur-lex.europa.eu/legal-content/NL/TXT/?uri=CELEX:62018CJ0311*

Het Hof van Justitie verklaart het Privacy Shield-akkoord ongeldig wegens onvoldoende waarborgen voor Europese burgers tegen toegang door Amerikaanse inlichtingendiensten.

### Data Protection Commissioner v Facebook Ireland and Maximillian Schrems

*Source: CJEU, C-311/18, 2020-07-16 — https://overview.legal/posts/51470 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0311&ref=51470*

Invalidated Privacy Shield adequacy decision and upheld validity of Standard Contractual Clauses with additional safeguards required.

### GC and Others v CNIL

*Source: CJEU, C-136/17, 2019-09-24 — https://overview.legal/posts/51475 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62017CJ0136*

Conditions for delisting sensitive data from search results.

### VOLKER UND MARKUS SCHECKE GBR V. LAND HESSEN, EIFERT V. LAND HESSEN AND BUNDESANSTALT FUR LANDWIRTSCHAFT UND ERNAHRUNG, 9.Nov.2010 (“SCHECKE”)

*Source: CJEU, 2010-11-09 — https://overview.legal/posts/6180 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62009CJ0092&ref=6180*

Purpose for processing: The legislation at issue does base the processing on consent. Rather, it provides that they are to be informed. Thus, processing is not based on their consent. (¶ 54)

## Guidance

### Automated decision-making and profiling

*Source: EDPB, automated-decision-making-and-profiling-en, 2018-05-25 — https://overview.legal/posts/126332 — original: https://www.edpb.europa.eu/documents/guideline/automated-decision-making-and-profiling_en*

### Human Oversight of Automated Decision-Making

*Source: EDPS, 25-09-15-techdispatch-human-oversight-en, 2025-09-23 — https://overview.legal/posts/51209 — original: https://www.edps.europa.eu/system/files/2025-09/25-09-15_techdispatch-human-oversight_en.pdf*

### Statement 2/2019 on the use of personal data in the course of political campaigns

*Source: EDPB, statement-22019-on-the-use-of-personal-data-in-the-course-of-political-en, 2019-03-13 — https://overview.legal/posts/126230 — original: https://www.edpb.europa.eu/documents/statement/statement-22019-on-the-use-of-personal-data-in-the-course-of-political_en*

1 Statement 2 / 2019 on the use of personal data in the course of political campaigns Adopted on 13 March 2019 The European Data Protection Board has adopted the following statement: Engaging with voters is inherent to the democratic process. It allow s the preparation of political program me s , enable s citizens to influence politics and the develop ment of campaign s in line with citizens expectation s. Political parties , political coalitions and candidates increasingly rely on personal…

### Art. 29 WP Guidelines on GDPR transparency requirements (WP260 rev.01)

*Source: EDPB, edpb-guidelines-on-transparency, 2025-11-21 — https://overview.legal/posts/38076 — original: https://www.edpb.europa.eu/system/files/2023-09/wp260rev01_en.pdf*

The Article 29 Data Protection Working Party issued these guidelines (WP260 rev.01), adopted on 29 November 2017 and last revised on 11 April 2018, to provide interpretive and practical guidance on the transparency requirements under the GDPR (Articles 12–14). The document addresses the form, timing, content, and modalities of information provided to data subjects, including issues such as plain language, layered privacy notices, information for children, and exceptions to the obligation to provide information. No fines or enforcement actions are imposed, as this is a guidance document rather than an enforcement decision.

### Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models

*Source: EDPB, opinion-282024-on-certain-data-protection-aspects-related-to-en, 2024-12-18 — https://overview.legal/posts/125697 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-282024-on-certain-data-protection-aspects-related-to_en*

Adopted 1 Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models Adopted on 17 December 2024 Adopted 2 Executive summary AI technologies create many opportunities and benefits across a wide range of sectors and social activities. By protecting the fundamental right to data protection, GDPR supports these opportunities and promotes other EU fundamental rights, including the right to freedom of thought, expression and information,…

### Guidelines 8/2020 on the targeting of social media users

*Source: EDPB, edpb-guidelines-on-the-targeting-of-social-media-users, 2021-04-13 — https://overview.legal/posts/38073 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-82020-on-the-targeting-of-social-media-users_en*

The EDPB adopted Guidelines 8/2020 on the targeting of social media users to clarify the roles, responsibilities, and legal obligations of the various actors involved in social media targeting, including social media providers, targeters, and users. The guidelines analyze different targeting mechanisms—based on provided, observed, and inferred data—and address controller determinations, legal bases, transparency requirements, DPIAs, and the processing of special categories of data. No fines are imposed, as this is interpretive guidance intended to assist stakeholders in achieving GDPR compliance.

### Guidelines 2/2019 on the processing of personal data under Article 6(1)(b) GDPR in the context of the provision of online services to data subjects

*Source: EDPB, guidelines-22019-on-the-processing-of-personal-data-under-article-61b-gdpr-in-en, 2019-10-16 — https://overview.legal/posts/126202 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-22019-on-the-processing-of-personal-data-under-article-61b-gdpr-in_en*

1 Adopted Guidelines 2/2019 on the processing of personal data under Article 6(1)(b) GDPR in the context of the provision of online services to data subjects Version 2.0 8 October 2019 2 Adopted Version history Version 2.0 8 October 2019 Adoption of the Guidelines after public consultation Version 1.0 9 April 2019 Adoption of the Guidelines for publication consultation 3 Adopted 1 Part 1 – Introduction ................................ ................................…

### Opinion 01/2019 on the draft list of the competent supervisory authority of the Principality of Liechtenstein regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-012019-on-the-draft-list-of-the-competent-supervisory-en, 2019-01-23 — https://overview.legal/posts/126254 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-012019-on-the-draft-list-of-the-competent-supervisory_en*

Adopted 1 EDPB Plenary Meeting, 22 - 23 January 2019 Opinion 01 /201 9 on the draft list of the competent supervisory authority of the Principality of Liechtenstein regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 23 January 201 9 Adopted 2 Table of c ontents 1 Summary of the Facts ................................ ................................ ................................ ..................... 4 2…

## Enforcement decisions

### Italian DPA sanctions Lusha Systems for processing contact data without consent in B2B

*Source: Garante per la protezione dei dati personali (Italy), 2026-07-14 — https://overview.legal/posts/184678 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_542/2026*

Facts — Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database. It was an US company wholly owned by Lusha Systems Ltd. In April 2025, the Italian DPA (Garante) initiated an investigation after media reports revealed that telephone numbers of senior Italian officials were available on the platform. The DPA later received one complaint and one report from data subjects who had received unsolicited advertising communications. The data subjects further stated that after requesting information about the source of their contact details, they discovered that their data were available on the controller’s platform without their consent. The controller explained that, for a subscription fee, it provided its Clients with a Business Contact Card for each Contact. The controller further distinguished between “Clients”, namely customers who used the platform and accessed its B2B database, and “Contacts”, namely the individuals whose personal data were included in that database, regardless of whether they used or were aware of the platform. Clients received Contact Cards containing information such as names, professional email addresses, telephone numbers, job titles, roles and locations, which could be used for sales, marketing, recruitment, business intelligence and fraud prevention. The DPA limited its investigation to the processing of Contacts’ personal data. The controller stated that it collected and combined data from publicly available sources, specialised providers, affiliated companies and commercial partners. It also inferred missing professional email addresses through algorithms that identified standard company email patterns. Through its Community Program and integrations with email, calendar and CRM services, it could also obtain information from Clients’ professional networks and communications. The data were cross-referenced, enriched and regularly updated to reflect changes in Contacts’ professional circumstances. The controller argued that the GDPR did not apply because it was established outside the EU and provided services only to businesses. It additionally claimed that the weekly updating of Contact Cards ensured accuracy rather than constituting monitoring or profiling. The controller maintained that the collection and disclosure of the data were necessary for its own economic interest in providing accurate professional contact information and for its Clients’ interests, including fraud prevention. According to the controller, it processed only a limited range of information concerning the Contacts’ professional lives. It further claimed that individuals who made professional information publicly available, particularly through services such as LinkedIn, could reasonably expect that the information might be reused and that they could be contacted regarding professional opportunities. Regarding transparency, the controller stated that its Personal Information Notice was sent to each Contact before their information became available in the database. It explained that it notified Contacts that they had a seven-day period during which they could opt out before their information became available to Clients. The controller also maintained that excluding public officials and public figures from the database was not a requirement under the GDPR. It attributed the presence of certain public officials to technical limitations in its filtering system. It also argued that public figures had a lower expectation of privacy. After the proceedings began, the controller removed profiles connected with Italian public bodies and officials, strengthened its filters and customer-verification measures, discontinued the Community Program in Italy and extended the opt-out period to fourteen days. Holding — Regarding the territorial scope of the GDPR, the DPA acknowledged that Article 3(2)(a) GDPR could apply to the processing of Clients’ data, but not to Contacts, since they were not recipients of the service. However, it held that Article 3(2)(b) GDPR applied because the controller systematically combined, enriched and updated Contacts’ professional information in order to assess their circumstances and determine whether and how they would appear in the database. Referring to Recital 24 and Recital 30, the DPA held that monitoring did not require profiling. It noted that the systematic observation of online traces and changes in a person’s professional situation was sufficient. The fact that the processing also served data accuracy did not alter that conclusion. It emphasised that the fact that the controller also updated the information to ensure its accuracy did not prevent the processing from constituting monitoring. Regarding transparency, the DPA found that the information concerning the collection of the Contacts’ data, the purposes of the processing and the legal basis relied upon was scattered across several documents. Also, the relevant information was not easily accessible from the controller’s homepage, while the Personal Information Notice could not be located directly through the website without prior knowledge of its existence. It further pointed out that the documents were provided in English rather than in the language of the affected data subjects. The DPA held that presenting the information in this manner did not satisfy the requirement that information be concise, transparent, intelligible and easily accessible. It therefore found an infringement of Article 5(1)(a) GDPR and Article 12 GDPR. Moreover, the DPA assessed whether Article 6(1)(f) GDPR provided a valid legal basis for the processing. It examined the controller’s Legitimate Interest Assessment and considered it essentially non-existent, as it contained only generic statements on necessity and proportionality and no genuine balancing assessment. The DPA then applied the three-part test under Article 6(1)(f) GDPR. It held that making the Contacts’ data available to Clients for their own marketing and sales activities could not constitute a legitimate interest, since the disclosure of contact information to third parties for their independent advertising purposes required prior consent under the applicable national and ePrivacy framework . However, it acknowledged that the controller’s interest in fraud prevention could be considered legitimate. The DPA nevertheless found that the processing was not necessary for the purposes pursued. It held that the controller collected information extending beyond ordinary professional contact details, including third-party data contained in CRM databases, email headers and subject lines, information about calendar meetings, and browsing data collected through browser extensions or other software integrations used by Clients. It pointed out that much of this information was not publicly available but was extracted from private interpersonal communications, disclosed by Clients, obtained through integrations with information systems or acquired from third-party providers. The DPA held that the collection and combination of such extensive information was neither strictly necessary nor proportionate for creating professional Contact Cards. Furthermore, it stressed that fraud prevention could also have been achieved through less intrusive means. The DPA therefore concluded that the necessity requirement and the principle of data minimisation were not met. Regarding the balancing test, the DPA emphasised that there was no prior relationship between the controller and the Contacts. Creating a professional profile on LinkedIn or another professional platform did not create a reasonable expectation that unpublished contact details would be collected from multiple sources, continuously updated and disclosed to an unspecified number of paying customers. It further noted that the processing could expose Contacts to communications from unknown third parties for purposes they could not reasonably anticipate. The DPA concluded that the Contacts’ interests, rights and freedoms prevailed over the controller’s economic interests and that the safeguards adopted by the controller could not change this outcome. Therefore, the DPA held that Article 6(1)(f) GDPR did not provide an appropriate legal basis and found that the controller infringed Article 5(1)(a) GDPR, Article 5(1)(c) GDPR, and Article 6 GDPR. Regarding public officials, the DPA held that their status did not reduce their entitlement to data protection and that no public interest justified disclosing their direct contact details for commercial purposes. The DPA further found that the controller had been aware of the risk that public officials could be included in its database but had failed to implement sufficiently effective technical and organisational measures. Its filters recognised general titles such as “President” but failed to exclude more specific titles such as “President of the Italian Republic” and “Vice Prime Minister”. The DPA therefore found an infringement of the principle of data minimisation under Article 5(1)(c) GDPR and the obligation of data protection by design and by default under Article 25 GDPR. The DPA imposed a fine of €2,000,000. Furthermore, it prohibited any further processing of personal data of data subjects located in Italy that had been collected without an adequate legal basis and ordered their deletion.

### Italian Garante sanctions EstEnergy for automated creditworthiness scoring in energy

*Source: Garante per la protezione dei dati personali (Italy), 2026-07-03 — https://overview.legal/posts/184565 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_484/2026*

Facts — EstEnergy S.p.A. (hereinafter, the controller) is an Italian energy company supplying natural gas, electricity and related services. Before entering into contracts, the controller assessed the creditworthiness of potential customers through an internal and an external credit check. The internal assessment involved verifying whether potential customers had outstanding debts not only with the controller but also with Hera Comm S.p.A (hereinafter, the corporate group). The assessment was conducted on behalf of the controller by Hera S.p.A. (hereinafter, the processor), which returned an “OK” or “KO” result. Where the internal assessment returned an “OK”, the controller conducted an external assessment using credit information supplied by Experian Italia S.p.A. and commercial information provided by Cerved Group S.p.A. This information was combined using the “CGS-X” software provided by Major 1 S.r.l. (hereinafter, the software provider and processor). The software generated an integrated creditworthiness score and several underlying sub-scores. On the basis of the result, the controller could refuse to enter into an energy supply contract. The DPA received several complaints from data subjects whose requests for energy supply had been rejected on the basis of their risk profiles. However, when the data subjects contacted the credit and commercial information providers, they were informed that the relevant databases did not contain negative information or adverse events concerning them. The data subjects also submitted access requests under Article 15 GDPR. Although the controller responded within the applicable time limits, it did not provide the CGS-X score, the underlying sub-scores or meaningful information about the logic and criteria used to calculate the profiles. Instead, the controller referred the data subjects to the credit and commercial information providers. Following the complaints, the DPA consolidated the proceedings and initiated an ex officio investigation. It conducted inspections at the premises of the processor, the software provider and processor, and the credit and commercial information providers. The investigation also established that the controller retained the information obtained through the credit checks. Through the processor, the controller subsequently analysed this information to potentially refine the corporate group’s customer rating system. Between 2022 and March 2024, this processing concerned more than one million data subjects. Holding — The DPA held that the controller’s creditworthiness assessment infringed Articles 5(1)(a), (b), (d) and (e), 12, 13, 14, 15 and 28 GDPR. First, the controller failed to provide transparent information about the internal assessment of customers’ previous debts and the sharing of such information within the corporate group. The instructions given to the processor also did not adequately cover these processing operations. The DPA therefore found violations of Articles 5(1)(a), 13, 14 and 28 GDPR. Second, the controller provided incomplete responses to access requests. It did not disclose the CGS-X score, the underlying sub-scores or meaningful information on the logic and criteria used to generate the creditworthiness profile. Referring the data subjects to the credit and commercial information providers did not discharge the controller’s obligations under Articles 12 and 15 GDPR. Third, the controller had not established a justified retention period for the data collected during the external assessment. Applying a general ten-year retention period for accounting records was not shown to be necessary for the creditworthiness assessment, in violation of Article 5(1)(e) GDPR. The DPA also found that reusing credit and commercial information to refine the corporate group’s rating system was incompatible with the original purpose for which the data had been collected. Since the retained information could become outdated, this processing also violated the purpose limitation and accuracy principles under Articles 5(1)(b) and (d) GDPR. The DPA ordered the controller to adopt a compliant access-response template, provide the relevant information to the data subjects involved and establish procedures enabling rectification, human intervention and the possibility to challenge decisions. The controller had six months to demonstrate compliance. Finally, the DPA imposed a €1,400,000 fine, taking into account the seriousness and scale of the infringements, the impact on approximately one million data subjects and the risk of refusal of essential energy services. It also considered the controller’s cooperation, lack of previous relevant infringements and remedial measures as mitigating factors.

### LfD (Lower Saxony) - Fine EUR 900,000 against bank

*Source: LfD (Lower Saxony), 2022-09-28 — https://overview.legal/posts/6319 — original: https://gdprhub.eu/index.php?title=LfD_(Lower_Saxony)_-_Fine_EUR_900,000_against_bank*

Facts — A commercial bank (controller) used personal data of current and former customers (data subjects) to identify customers with an affinity for digital media usage, in order to address them more intensely through electronic communication channels for further commercial communication (advertisement). A service provider analyzed digital usage behavior on behalf of the controller, including the total amount of app-store purchases, the usage frequency of bank statement printers as well as the total amount of transfers in online banking system (in comparison to the offline usage in their local branch offices). The results were compared and further enriched with data from a commercial credit reporting agency. Most customers were informed in advance, but no consent under Article 6(1)(a) GDPR was obtained. The controller based the data analysis, data enrichment and the subsequent creation of customer profiles on legitimate interest as per Article 6(1)(f) GDPR. Holding — The DPA found that the analysis of large amounts of data to create customer profiles could not be based on Article 6(1)(f). It followed that processing based on a legitimate interest requires a balancing act between the interest of the controller and the fundamental rights and freedoms if the data subject. The controller had to consider the reasonable expectations of the data subjects. The DPA argued that a data subject could not reasonably expect large amounts of its personal data to be analyzed by the controller to better target its advertising. Third-party data enrichment, like the use of commercial credit reporting agency data, further overrides the interest of the controller and tips the balancing test in favor of the data subject. The DPA held that in addition, data enrichment from a third-party source and linking it to profiles could also not be based on legitimate interest. This could potentially link data from all areas of life to an accurate customer profile, which could also not be reasonably expected by a customer. Customer consent (see Article 6(1)(a)) is required. The controller cooperated with the DPA throughout the process. For the violation, the DPA fined the controller €900,000.

### Garante per la protezione dei dati personali (Italy) - 9788429

*Source: Garante per la protezione dei dati personali (Italy), 2022-07-07 — https://overview.legal/posts/122853 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_9788429*

Facts — Social media platform TikTok (the controller) provided personalized advertising to its users (the data subjects) on the legal basis of consent (Article 6(1)(a) GDPR). In June 2022, the controller announced that a new privacy policy would come into effect on 13 July 2022. Under the new policy, the controller would only serve personalize advertising to users over 18 years of age and on the legal basis of the legitimate interest of the controller (Article 6(1)(f) GDPR). The Italian DPA started an investigation and found that personalized advertisement would likely involve the use of cookies or other tracking mechanisms. Holding — Regarding the competence of the Italian DPA, it should be noted that the Irish DPA is the lead supervisory authority for the controller’s data processing activities under the GDPR's "one-stop-shop" mechanism. The Italian DPA acknowledged the Irish DPA’s position in its decision. However, the Italian DPA held the ePrivacy Directive to be applicable to the processing of cookies by the controller and held itself competent to enforce the Directive. The DPA referenced Recital 173 GDPR and EDPB Opinion 05/2020 on this point. The DPA held that the controller’s new privacy policy violated Article 5(3) ePrivacy Directive 2002/58/EC. The Article only allows the controller to process cookies and use similar tracking mechanisms with the user’s consent . For this reason, legitimate interest under Article 6(1)(f) GDPR is not a valid legal basis for the processing of cookies. The Italian DPA also held that the controller violated Article 122 of the Italian Privacy Code (d. lgs. 30 giugno 2003, n. 196). Article 122 is a direct transposition of Article 5(3) ePrivacy Directive. The violation of the Code constitutes a direct consequence of the violation of the Directive. The DPA issued a warning against the controller.

### NAIH fines online store HUF 2M for unclear and incomplete privacy notice

*Source: NAIH (Hungary), 2026-07-22 — https://overview.legal/posts/156361 — original: https://gdprhub.eu/index.php?title=NAIH_(Hungary)_-_NAIH-11443-3/2026*

Facts — The DPA initiated an investigation into the GDPR compliance of an online store (the controller) processing the data of its customers (the data subjects) in April 2025. The processing activities in question included, inter alia, cookies, registration, billing, shipping, consumer complaint, and processing of orders. The privacy notice of the company operating the online store had been in force unchanged from May 2018 to May 2025, and the period under investigation extended from 1 January 2020 to 27 June 2025. Holding — The DPA held that the controller had violated Articles 12(1), 13(1)(c), (d) and (f), and 13(2)(a) GDPR and issued the controller a fine of HUF 2,000,000 (€5,500). In addition, the DPA ordered the controller to bring its data processing operations into compliance with the GDPR and to amend the content of its privacy notice. First, the DPA found an infringement of Article 12(1) GDPR: the structure of the privacy notice was confusing and difficult to follow. The privacy notice also contained incomplete, incorrect, and unnecessary information as well as repetitive details. Based on this, the DPA concluded that the controller had failed to provide data subjects with information regarding the processing of personal data that was sufficiently concise, transparent, intelligible and easily accessible. Second, the DPA held that the controller had also violated Articles 13(1)(c), (d) and (f) GDPR by failing to specify a legal basis for certain processing operations such as the use of cookies, not specifying its legitimate interests when relying on Article 6(1)(f) GDPR as a legal basis, and not providing detailed information regarding the safeguards ensuring the lawfulness of data transfers to the United States. Finally, the DPA found a violation of Article 13(2)(a) GDPR as the controller had also failed to provide the data subjects information on the period for which the personal data processed would be stored.

### Italian Garante sanctions Hera Comm for automated credit-check refusals of contracts

*Source: Garante per la protezione dei dati personali (Italy), 2026-07-03 — https://overview.legal/posts/184557 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_483/2026*

Facts — Several data subjects lodged complaints with the Italian DPA (Garante) after Hera Comm S.p.A., an energy supplier (the controller), declined to conclude electricity or gas contracts with them because its checks had resulted in a negative risk assessment. The controller had used a credit-check procedure to assess the creditworthiness of prospective customers before entering into such contracts. The credit-check procedure consisted of an internal and an external assessment. During the internal assessment, Hera S.p.A. (processor A) checked whether the prospective customer had outstanding debts towards the controller or EstEnergy S.p.A., another energy supplier within the same corporate group. The assessment returned an OK or KO result. The controller’s privacy notice stated that customer data could be disclosed to other companies within the Hera Group and to third parties contractually linked to the Group. Where the internal assessment returned an OK result, an external assessment was carried out using software called “CGS-X”, provided by Major 1 S.r.l. (processor B). Through the software, databases operated by Experian Italia S.p.A. (the credit-information provider) and Cerved Group S.p.A. (the commercial-information provider) were consulted. The software combined the scores supplied by the two external data providers to generate an integrated creditworthiness score, which was transmitted to systems operated by processor A. Those systems applied the criteria established under the controller’s group credit policy and returned a final OK or KO result. The data subjects alleged that the refusal of their applications resulted from the external creditworthiness assessment. When they subsequently contacted the two external data providers, the providers stated that their systems did not contain negative information or adverse events concerning them. The data subjects then submitted access requests to the controller. The controller replied that their risk profiles were based on automated scoring using information obtained from external databases and directed them to the two external data providers for further details. The replies did not identify the CGS-X score and did not explain the logic or criteria used in the assessment. At the time of the inspection, the controller had not set a specific retention period for the external-assessment data and instead applied a general ten-year period used for accounting documentation. It also reused credit-check data, including information from external providers and previous debts, for analyses aimed at refining its group’s rating system. Between 2022 and March 2024, this processing concerned 1,003,657 individuals. During the proceedings, the controller and the other energy supplier entered into a joint-controller arrangement under Article 26 GDPR concerning the internal assessment and updated the relevant privacy information. Under that arrangement, the two joint controllers also undertook to appoint processor A for the processing carried out as part of the internal assessment. The controller subsequently adopted a five-year retention period for creditworthiness data and discontinued the analyses concerning the refinement of the rating system. Holding — The DPA considered that the information provided by the controller did not describe the intra-group sharing and use of data concerning previous debts with sufficient specificity. It found that the general references to disclosures within the corporate group did not provide information about the processing operations connected with the internal assessment. The DPA also found that the instructions provided to processor A did not cover the processing of information concerning debts owed by customers to the other energy supplier. It therefore found infringements of Article 5(1)(a) GDPR, Article 13 GDPR, Article 14 GDPR and Article 28 GDPR. The DPA noted that, under the joint-controller arrangement, the internal assessment was carried out jointly by the two energy suppliers on the basis of Article 6(1)(f) GDPR. However, it found that the processing carried out before the conclusion of that arrangement was unlawful. The DPA also found that the responses to the access requests did not meet the requirements of Article 12 GDPR and Article 15 GDPR. It noted that the access requests had been submitted to the controller which was required to provide all personal data and information relating to the processing. It pointed out additionally that the information to be provided should include the integrated score, the contributing scores, and meaningful information about the logic and criteria applied. Moreover, referring to the CJEU’s judgment in Case C-203/22 (Dun & Bradstreet Austria), the DPA stated that the requirement to provide meaningful information about the logic involved could not be satisfied merely by disclosing a complex mathematical formula or by providing a detailed description of every stage of the automated process. It emphasized that the controller was required to describe the procedure and principles actually applied in a concise and understandable manner, enabling the data subject to understand which personal data were used and how they contributed to the result. The DPA considered that the information provided did not enable the data subjects fully to assess the lawfulness of the processing or the accuracy of the data used. It also limited their ability to request rectification, obtain human intervention, express their views and contest the decision. The DPA further found that the application of a general ten-year retention period to the credit-check data had not been sufficiently justified in relation to the purpose of assessing a specific contractual application. The controller had not demonstrated the necessity of retaining the scores and related reports for that period. The DPA concluded that the controller violated Article 5(1)(e) GDPR. Furthermore, the DPA considered that the use of data obtained from the credit-information provider and the commercial-information provider for analyses concerning the refinement of the controller’s group rating model pursued a further purpose incompatible with the original purpose for which those data had been collected. It also found that retaining and subsequently reusing data obtained from the two external providers created a risk that the information would no longer be up to date. It therefore found infringements of Article 5(1)(b) GDPR and Article 5(1)(d) GDPR. The DPA imposed a fine of €5,800,000. It also ordered the controller to define a new response template for access requests, including the relevant scores and meaningful information about the logic and criteria applied, and to provide the revised response to the complainants. The controller was further required to establish a procedure enabling data subjects to request the rectification of inaccurate or incomplete data, obtain human intervention, express their views and contest the decision.

### AEPD (Spain) - PS/00259/2020

*Source: AEPD (Spain), 2021-07-06 — https://overview.legal/posts/184544 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS/00259/2020*

Facts — A data subject exercised their right to object to receiving commercial communications against a bank (Bankia/Caixabank), after what whose DPO confirmed that the right had been correctly exercised. However, two years after that, the data subject received a letter from the bank which envelope contained a commercial communication, promoting and informing about the bank's services. The data subject lodged a complaint with the Spanish DPA (AEPD). The bank alleged that it was not a commercial communication but a mere standard envelope like the banners and signs that they display at their offices, that include information about the bank's services, and that the letter inside was just information sent to the client regarding the services that they had contracted. The bank also stated that it was not a direct marketing action, as it did not include any profiling or made use of individual preferences, but was general information sent to their clients. They alleged that they were relying on a legitimate interest for this. The bank also alleged that they had not processed their client's data for marketing purposes, since the processing was done to send the letter, and the envelope containing the commercial message was just accidental to it, but the data was not processed for that purpose. Holding — The Spanish DPA determined that the actions performed by the bank were nevertheless commercial communications with a marketing purpose, and that the controller did not have a legal basis for doing so, as the bank could not rely on a legitimate interest since the data subject had exercised their right to object, in accordance to Article 21 GDPR. The Spanish DPA also made reference to Recitals 69 and 70. The AEPD also noted that the privacy policy of the bank declared that commercial communications were based on consent, contrary to what the controller alleged during the procedure. Therefore, the AEPD concluded that there had been a violation of Article 6(1)(f) and fined the controller €50,000, compelling it to implement the necessary measures to prevent the sending of commercial communications to data subjects that have objected to them. The Spanish DPA took into account the lack of diligence, the scope of the infringing behaviour (even if in this case there was an only claimant, the lack of measures to prevent it may make it happen regarding other clients), the link between the controller's activity and the infringement, and the recidivism of the controller; and the fact that the entity was assimilated by another entity, so the infringement could be attributed to the latter entity, as a mitigating factor.

### HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens

*Source: HDPA (Greece), 2026-05-13 — https://overview.legal/posts/144044 — original: https://gdprhub.eu/index.php?title=HDPA_(Greece)_-_12/2026*

Facts — The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of Undesirable Aliens. In response to the Authority's request for clarifications, the competent Directorate of the Ministry of Citizen Protection informed the DPA that: • By a decision dated 27-07-2017, an entry ban and registration in the National Registry of Undesirable Aliens were imposed on the complainant for reasons of national security. • Following temporary 48-hour lifts of the measure for humanitarian reasons in 2019, the entry ban was re-imposed. • Subsequent decisions in 2020, 2023, and 2025 maintained the entry ban and renewed his registration in the National Registry of Undesirable Aliens for successive three-year periods, as the grounds for registration remained active. • The explicit grounds and documentation behind the registration were not disclosed to the complainant because the competent Directorate classified the file as restricted/classified service material. The complainant and his attorney attended a DPA hearing on 22-04-2026, arguing that the registration lacked specific, adequate, or definitive justification regarding any threat to public order or national security. They noted that the complainant has no criminal convictions, poses no threat, and possesses strong ties, residency, and business operations in the region of Northern Epirus and Greece, meaning the entry ban severely disrupts his professional and family life. Holding — According to the provisions of Article 82(1) of Law 3386/2005, foreign nationals whose presence in Greek territory constitutes a threat to national security, public safety, or public order can be registered in the National Registry of Undesirable Aliens, with registrations subject to an ex officio review every three years. Furthermore, pursuant to the provisions of Article 54(2) and Article 55(4) of Law 4624/2019 (the Greek law implementing the GDPR), the data controller is legally empowered to restrict or omit the provision of information and to deny a data subject access to their personal data when dictated by reasons of national security or public order. These national provisions are explicitly anchored in Article 23 GDPR (specifically Article 23(1)(a)GDPR and Article 23(1)(c) GDPR), which permits Member State law to restrict the scope of the obligations and data subject rights (such as the right to be informed under Article 13 GDPR - Article 14 GDPR and the right of access under Article 15 GDPR) to safeguard national security and public security. In the present case, the evidence demonstrated that the complainant's initial registration and subsequent renewals in the National Registry of Undesirable Aliens were executed lawfully for reasons of national security. The Ministry of Citizen Protection, acting as the data controller, exercised its legal discretion under these frameworks to weigh these interests and correctly determined that the underlying operational decision constitutes classified material that cannot be disclosed to the data subject. Consequently, the fundamental principles of data protection law were not breached, and the Hellenic DPA rejected the complaint as unfounded.

## Recent developments

### Drivers' Request for Personal Data Access and Automated Decision-Making Information from Ola Netherlands BV: Balancing Personal Data Protection with the Needs of Drivers

*Source: Dutch Courts, 2023-04-04 — https://overview.legal/posts/6216 — original: https://deeplink.rechtspraak.nl/uitspraak?id=ECLI:NL:GHAMS:2023:804&pk_campaign=rss&pk_medium=rss&pk_keyword=uitspraken#entry-4299*

Request by drivers to Ola Netherlands BV for access as referred to in Article 15 (1) AVG to certain personal data concerning them (including "ratings" given by passengers) and for information as referred to in Article 15 (1) (h) AVG (information on the existence of automated decision-making within the meaning of Article 22 AVG). Protection of passengers' personal data. Is...

### Court of Amsterdam on GDPR request on information about the existence of automated decision-making at Uber

*Source: Dutch Courts, 2023-04-04 — https://overview.legal/posts/6218 — original: https://deeplink.rechtspraak.nl/uitspraak?id=ECLI:NL:GHAMS:2023:793&pk_campaign=rss&pk_medium=rss&pk_keyword=uitspraken#entry-4301*

Request from Uber drivers to Uber for information under Article 15(1)(h) AVG (information about the existence of automated decision-making within the meaning of Article 22 AVG) after their accounts were deactivated by Uber; scope of information right under Article 15(1)(h) AVG. Are the deactivation decisions based solely on automated ver...

### Garante onderzoekt het gebruik van "cookie walls".

*Source: Garante Privacy, 2022-10-25 — https://overview.legal/posts/51828*

De Garante (de Italiaanse Autoriteit voor de bescherming van persoonsgegevens) merkt op dat de Europese wetgeving inzake de bescherming van persoonsgegevens in principe niet verhindert dat de eigenaar van een website de toegang tot content voor gebruikers afhankelijk maakt van hun toestemming voor het verzamelen van gegevens voor profilering (via cookies of andere trackingtools), of, als alternatief, van het betalen van een bedrag. Dit verwijst naar de initiatieven die de afgelopen dagen zijn genomen door verschillende online kranten, websites en bedrijven die actief zijn op internet.

### AEPD publishes GDPR Risk Assessment

*Source: AEPD, 2022-10-11 — https://overview.legal/posts/6259 — original: https://evalua-riesgo.aepd.es/index_en.html#entry-1032*

> GDPR RISK ASSESSMENT is intended to assist controllers and processors to identify the risk factors for the rights and freedoms of data subjects whose data are present in the processing, to make an initial assessment of the intrinsic risk, including the need to perform a DPIA, and to estimate the residual risk if measures and safeguards are used to mitigate the specific risk factors.

### De Griekse toezichthouder heeft Clearview AI een boete van 20 miljoen euro opgelegd.

*Source: IAPP, 2022-10-20 — https://overview.legal/posts/51829*

Een overzicht van de boete die aan IAPP is opgelegd: https://iapp.org/news/a/a-rundown-of-the-greek-dpas-clearview-ai-fine-findings

## Literature

### HOW GDPR TREATS AUTOMATED DECISION-MAKING

*Source: Journal Scientific and Applied Research, 2025-11-14 — https://overview.legal/posts/132599 — original: https://doi.org/10.46687/jsar.v28i1.435*

This article examines how the General Data Protection Regulation (GDPR) regulates automated decision-making, including profiling, in the context of personal data processing. It analyzes the main provisions of Article 22 of the Regulation, as well as the conditions under which fully automated decisions that produce legal effects or significantly affect data subjects are permitted. The article highlights the rights of data subjects – the right to human intervention, the right to express their poin

### CJEU: The Rating of a Natural Person’s Creditworthiness by a Credit Rating Agency Constitutes Profiling and Can Be an Automated Decision under Article 22 GDPR

*Source: European Data Protection Law Review, 2024-01-01 — https://overview.legal/posts/132601 — original: https://doi.org/10.21552/edpl/2024/1/17*

### Implications of GDPR and EU Adequacy Decision for Regulation of Profiling and Automated Decision-making in Korea

*Source: Chungnam Law Review, 2022-11-30 — https://overview.legal/posts/132602 — original: https://doi.org/10.33982/clr.2022.11.30.4.189*

### Article 22 GDPR on Automated Individual Decision-Making: Prohibition or Data Subject Right?

*Source: European Data Protection Law Review, 2022-01-01 — https://overview.legal/posts/132543 — original: https://doi.org/10.21552/edpl/2022/2/6*

### Regulating Automated Decision-Making: An Analysis of Control over Processing and Additional Safeguards in Article 22 of the GDPR.

*Source: European Data Protection Law Review, 2021-01-01 — https://overview.legal/posts/132596 — original: https://doi.org/10.21552/edpl/2021/2/6*

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Automated Decision-Making** — https://overview.legal/topics/geautomatiseerde-besluitvorming
  Processing involving automated decisions without human involvement
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Marketing** — https://overview.legal/topics/marketing
  Use of personal data for marketing and advertising purposes
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Human Resources** — https://overview.legal/topics/human-resources
  Processing of employee and HR data

---
Generated by overview.legal · https://overview.legal/topics/profiling · 2026-08-22
