# Pseudonymization — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/pseudonymization
> Sources are cited per item. Verify against the official texts before relying on them.

Processing data in a pseudonymized manner

## Overview

## Legal Framework

Pseudonymization is defined under Article 4(5) GDPR as the processing of personal data in such a manner that the data can no longer be attributed to a specific data subject without the use of additional information, which is kept separately and subject to technical and organizational measures to ensure non-attribution. Critically, pseudonymized data remains personal data — it does not render data anonymous and does not fall outside the GDPR's scope. The rationale is to reduce risk to data subjects by separating identifiers from the substantive data, while still permitting meaningful processing.

Article 25 GDPR reinforces this by requiring data protection by design and by default: controllers must implement appropriate technical and organizational measures both when determining processing means and during processing itself. Pseudonymization is expressly identified as an example of such a measure. Article 32 GDPR further obliges controllers to ensure ongoing confidentiality, integrity, and resilience of processing systems, under which pseudonymization serves as a recognized safeguard. Under Article 5(1)(c), data minimization principles also support pseudonymization as a means of limiting identifiability where full anonymization is not feasible.

## Key Developments

Dutch case law has established that pseudonymization is not merely optional but can function as a necessary balancing tool when courts weigh access rights against confidentiality interests. In the RET case, the Court of Appeal ordered an employer to disclose an investigation report to the employee but permitted pseudonymization of third-party references under the judiciary's pseudonymization guidelines. The court prohibited the employee from sharing the report with third parties, under a penalty of €5,000 per violation. This establishes that outright denial of access is impermissible where pseudonymization can adequately protect competing interests.

The *Peter Puškár* ruling from the CJEU clarifies that the right of access under Article 15 GDPR must be examined in its specific context and cannot be systematically refused on privacy grounds. Where pseudonymization can reconcile the data subject's access rights with third-party protections, it should be employed rather than withholding documents entirely.

The Hellenic DPA's enforcement against Hestia Publishers (€9,000 fine) demonstrates that failure to pseudonymize when disclosing personal data — particularly when revealing a data subject's identity is unnecessary for the processing purpose — constitutes a violation. The controller disclosed identity information where pseudonymization or redaction would have been appropriate.

## Practical Guidance

- **Implement pseudonymization as a default design measure** under Article 25 GDPR when processing involves large datasets or sensitive contexts. Replace direct identifiers with pseudonyms and store the key table separately, with access restricted to authorized personnel under Article 32 safeguards.

- **Apply pseudonymization when responding to access requests** involving third-party data. The RET ruling confirms that courts expect controllers to pseudonymize rather than withhold documents entirely — blanket refusals of access are not defensible where redaction or pseudonymization can resolve the conflict.

- **Maintain separation between pseudonymized data and re-identification keys.** The Article 4(5) definition requires that additional information be kept separately and subject to technical and organizational measures. Storing the re-identification key on the same server or in the same database as the pseudonymized dataset defeats the legal purpose.

- **Document the pseudonymization methodology** as part of your Article 30 records and DPIA processes where applicable. Controllers must demonstrate that the chosen technique effectively prevents attribution without the key, particularly if challenged by supervisory authorities.

- **Recognize that pseudonymized data remains within the GDPR's scope.** Do not treat pseudonymized datasets as anonymized for compliance purposes — all substantive GDPR obligations, including lawful basis requirements under Article 6 and data subject rights, continue to apply.

## Case law

### Judgment of the Court (First Chamber) of 4 September 2025.#European Data Protection Supervisor v Single Resolution Board.#Appeal – Protection of natural persons with regard to the processing of personal data – Procedure for granting compensation to shareholders and creditors of a banking institution following the resolution of that institution – Decision of the European Data Protection Supervisor finding that the Single Resolution Board failed to fulfil its obligations relating to the processing

*Source: Court of Justice of the European Union, C-413/23, 2025-09-04 — https://overview.legal/posts/132136 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0413*

The European Data Protection Supervisor (EDPS) appealed a General Court judgment that annulled its decision finding the Single Resolution Board (SRB) had failed to fulfil its obligations under Regulation (EU) 2018/1725 regarding the processing of personal data in a banking resolution compensation procedure. The core legal issues concerned whether pseudonymised data transmitted to a third party constitutes "personal data" under Article 3(1), the proper interpretation of "pseudonymisation" under Article 3(6), and the scope of the controller's obligation to inform data subjects under Article 15(1)(d). The Court of Justice (First Chamber) ruled on these interpretive questions in deciding whether to set aside the General Court's judgment.

### NSS - 1 As 183/2023-62

*Source: Supreme Administrative Court, 2026-08-04 — https://overview.legal/posts/184683 — original: https://gdprhub.eu/index.php?title=NSS_-_1_As_183/2023-62*

Facts — OAKS Consulting s.r.o. (the company) provided consulting services concerning market access conditions for medicinal products and medical devices. Pursuant to the Czech Act on Free Access to Information, it requested information from the General Health Insurance Company of the Czech Republic concerning the treatment of patients with iron deficiency and related conditions for the period from 1 January 2010 to 31 October 2017. The request covered 183 types of diagnoses, 18 types of medical procedures, 96 DRG codes and 13 types of medications. The company stated that it wished to analyse how specific diagnoses were treated, the number of patients treated, and the frequency of related medical procedures, in order to compare clinical practice against the relevant theoretical background. The public health insurer rejected the request on the grounds that granting it would require the creation of new information. Following an appeal by the company, the Prague Municipal Court overturned the decision. The public health insurer provided then the company with five separate tables regarding the diagnoses, diagnoses in conjunction with medical procedures, the DRG codes and prescribed medications. It aggregated the parameters of the provided data as follows: five-year age groups, dates were given only at the monthly level, and healthcare providers were classified into broad geographic regions. However, it refused to add a unique random identifier which would allow linking the individual records and tables pertaining to the same patient. The public health insurer considered that providing the code would result in the disclosure of special categories of personal data. The company lodged a complaint with the Czech DPA (UOOU), which rejected it. The company filed another appeal with the Municipal Court of Prague, which dismissed the appeal. It ruled that the combination of factors such as gender, year of birth, the time and place of care, diagnoses, medications, and medical procedures could, with the addition of other information, lead to the identification of specific patients. According to the court, the random identifier would result in pseudonymisation rather than anonymisation, so the information would remain personal data pursuant to Article 4(1) GDPR. The Municipal Court also relied on modern technical capabilities for linking different sources and on the availability of a large volume of information in the media and on social media. It cited the CJEU’s decision in the Breyer case (C-582/14), according to which in order to determine whether a person is identifiable, account must be taken of all the means that could reasonably be used, both by the controller and by any other person, to identify that person. It did not follow the approach taken by the General Court in Case T-557/20 (SRB v. EDPS), which the company had cited. It ruled that the data were pseudonymised and that the requested information could not be disclosed in its entirety. The company filed a cassation appeal with the Supreme Administrative Court, arguing that the information had been anonymised. It alleged that the addition of a random code with no independent meaning would not alter their anonymous nature. It claimed that the Municipal Court had not explained what specific additional information could be used to identify the patients and had relied on hypothetical scenarios. The company stated that it was objectively impossible to obtain such data through other requests in a detailed and non-aggregated form. It also argued that iron deficiency was not a rare disease, but was associated with a large number of patients and various conditions and that the data had undergone both randomisation and generalisation so the risk of identification was therefore low. Finally, the company emphasized that the tables without the random identifier could not be used effectively for the intended analysis. It further argued that the DPA and the Municipal Court had not adequately balanced the right of access to information against the right to the protection of personal data. The DPA argued that the random identifier constituted personal data when considered in conjunction with the health data to which it would be linked. It stated that the concept of personal data was not limited to information that directly identifies an individual nor did it require that all necessary additional information be held by the same entity. Replacing direct identifiers with a code did not anonymise the data, but made it pseudonymised. Moreover, it argued that certain categories contained a relatively small number of records and that combining them with other data could make it possible to select and identify a specific insured person and their treatment history. It further argued that, even if identifiability was relative, it should be assessed in relation to all potential information applicants and their ability to obtain contextual information. The Supreme Administrative Court stayed the proceedings in the case pending the CJEU’s decision in Case C-413/23 P (EDPS v. SRB). After the judgment was issued, the company argued that whether the data were pseudonymised or anonymised should be assessed in relation to the specific recipient of the data and the means that it could reasonably use. It stated that it did not have any means of re-identification and that only specific and practically available cross-referencing possibilities should be taken into account. Holding — The court relied on Case C-413/23 and noted that pseudonymised data under Article 4(5) GDPR does not automatically constitute personal data in relation to every person. Therefore, it examined whether the company had lawful means that could reasonably be expected to be used to identify the patients directly or indirectly. The court found that the tables, without the random identifier, did not allow for the identification of specific insured individuals. It held that the requested random identifier would link the records from the different tables and allow for the aggregation of information on the diagnoses, medical procedures, hospitalizations, and medications for the same patient during the eight-year period. Certain combinations of these data, along with age group, gender, and region, could be unique and allow for the identification of patients using information from public sources. It pointed out that although iron deficiency was a very common diagnosis and some tables contained a very large number of entries, other categories were not sufficiently generalised. According to the court, in certain cases, such as rare diseases, unusual treatment combinations, or particularly young or old age, knowing even a few details about a person could make it possible to identify the corresponding record. The risk was not negligible, given that information about a person’s age, gender, hospitalization, diagnosis, or treatment could be available in the media or on social media. Consequently, the court held that adding the random identifier, in conjunction with the data already provided, would make the dataset personal data in relation to the company under Article 4(1) GDPR, including health data falling under Article 9 GDPR. The court clarified that classifying the information as personal data was not sufficient in itself to reject the request. It noted that the right of access to the information must also be balanced against patients’ right to privacy through an assessment of suitability, necessity and proportionality. It determined that the decision not to provide the random identifier was appropriate for the protection of privacy, because without it, it was impossible to link the tables and identify individual patients. It was also deemed necessary because the company insisted on receiving that specific code along with the existing tables and there was no other procedure that would constitute a lesser infringement of its right to information. The court also recognized the public interest in accessing information related to the operation of the healthcare system, but ruled that this did not outweigh the need to protect the detailed health data of potentially hundreds of thousands of insured individuals. It concluded that the refusal to provide the code was therefore proportionate. The Supreme Administrative Court therefore upheld the Municipal Court’s ruling, but partially corrected its reasoning regarding the relative nature of identifiability and the need to conduct a proportionality review. It dismissed the appeal.

### HvJ EU 9 januari 2025, C‑394/23 (Mousse).

*Source: CJEU, 2025-01-09 — https://overview.legal/posts/50377 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0394*

HvJ EU 9 januari 2025, C‑394/23 (Mousse). Artikelen: 5(1)(c), 6(1), en 21 AVG Onderwerp : Beginsel van minimale gegevensverwerking Gek genoeg verwijst het HvJ EU zelf niet naar HvJ EU 1 augustus 2022, C‑184/20 (Vyriausioji tarnybinės etikos komisija), maar dat had hier ook heel logisch geweest.

### Rotterdam Court: DPA did not err in finding ING contactless chip payments GDPR-compliant

*Source: District Court Rotterdam, 2026-06-24 — https://overview.legal/posts/96826 — original: https://gdprhub.eu/index.php?title=Rb._Rotterdam_-_ROT_25/7371*

Facts — ING Bank N.V. (the controller) is a bank. In 2022, several data subjects brought a complaint to the DPA regarding the controller’s contactless payments. The data subjects requested the controller to issue debit cards without a chip that would enable contactless payments. The controller stated that this was not possible, however, the contactless payment feature could be disabled on the data subjects’ cards. The data subjects later filed a complaint because the debit cards contained the chips even if the contactless feature was disabled. The DPA dismissed the complaint in 2024, on the grounds that further investigation would be needed to determine whether the controller violated the GDPR or not. The DPA stated that it had limited capacity and such an investigation would place a heavy burden on it. The data subjects appealed this decision to the court, who determined that the DPA had wrongfully failed to hear the data subjects during the objection phase. The DPA issued a new decision in 2025 and concluded that the controller had not violated the GDPR. The data subjects appealed this decision, arguing that the DPA had again not investigated the case sufficiently. In addition, the data subjects argued that the controller processed personal data through the debit card chip without a valid legal basis. This is because the chip allowed payments made with blocked or expired cards, meaning Article 6(1)(b) GDPR did not apply. The controller could also not rely on consent (Article 6(1)(a) GDPR) to process the data. The DPA argued that the GDPR does not require controllers to completely eliminate a risk. In addition, disabling contactless payments or blocking cards were related to the contract between the data subject and the controller; the DPA argued that this did not remove the basis to process personal data. Holding — The court found that the DPA investigated the complaint to an appropriate extent and was not required to conduct a further investigation. According to the court, the data subjects did not provide sufficient evidence that the controller’s statements were incorrect or that the DPA lacked the technical knowledge during its investigations. The court upheld the DPA’s reasoning that Article 32 GDPR does not require a security risk to be completely eliminated, and concluded that the DPA could reasonably decide that there was no violation of the GDPR. Similarly, the court upheld the DPA’s reasoning and concluded that the controller had a valid legal basis to process the data subjects’ personal data. The court saw no need to assess potential violations of other laws (e.g. fraud or forgery) or consumer law issues, on the grounds that the DPA’s investigation is limited to compliance with the GDPR. The DPA is also not required to coordinate or refer the case to other competent authorities. The court dismissed the appeal.

### HvJ EU: Privacy Shield ongeldig verklaard (Schrems II)

*Source: Hof van Justitie EU, 2020-07-16 — https://overview.legal/posts/1 — original: https://eur-lex.europa.eu/legal-content/NL/TXT/?uri=CELEX:62018CJ0311*

Het Hof van Justitie verklaart het Privacy Shield-akkoord ongeldig wegens onvoldoende waarborgen voor Europese burgers tegen toegang door Amerikaanse inlichtingendiensten.

### Amsterdam District Court: consumers seek access to ING–Google Pay data agreements

*Source: District Court Amsterdam, 2026-07-16 — https://overview.legal/posts/144027 — original: https://gdprhub.eu/index.php?title=Rb._Amsterdam_-_781904*

Facts — ING Bank (the controller) is a bank. One of the services the controller offers is to make contactless payments using an Android phone. This was initially done through its own app, however, the controller later discontinued this and offered the contactless payment through Google Pay. To activate Google Pay, data subjects have to create an account with Google. When making a payment, the controller shares data related to the payment and store to Google. Two Dutch consumer’s organisations (the “Benadeelden in Actie” Foundation, or SBIA and Consumer Union) demanded that the controller discontinue Google Pay, and requested it to share its data. The controller stated that it had reached agreements with Google regarding data processing for contactless payments, but it refused to disclose those agreements. The consumer organisations therefore filed a case with the court, requesting it to order the controller to provide access to the agreements. The organisations also requested access to additional documentation, such as (draft) decisions and research data. They argued that they questioned the lawfulness of the processing of personal data in relation to contactless payments, and needed access in order to verify whether this processing was lawful. The controller, on the other hand, argued that the argument was unsubstantiated because the processing was lawful. The organisations argued that ING and Google acted as joint controllers in accordance with Article 26 GDPR. ING disputed this, and argued that it was only a joint controller with Google for the activation of tokens when making a payment. Holding — The court also clarified that ING Bank and Google were joint controllers, in accordance with Article 26 GDPR. The court dismissed the argument that ING and Google were joint controllers only in a specific instance (activating tokens). The court stated that both companies aimed at enabling data subjects to make contact payments with their phones using Google Pay. The court considered this a jointly defined purpose. Furthermore, the companies do not limit their data exchange to tokens; for example, Google stored the payment data to generate payment summaries. In terms of further processing of the personal data by Google (e.g. for advertising purposes), the court held that the ING may have a certain duty of care. This means that ING may have the obligation to implement safeguards to prevent the processing of data for contactless payments for any other purpose. The court also stated that the data subjects can hold ING liable for a breach of this duty of care. In terms of access, the court assessed whether the organisations had this right under the code of civil procedure rather than the GDPR. The court first stated that the request for access applied to ING Bank and not ING Group (the entity the organisations had initially brought the case against). This is because the parent group ING Group did not have a banking license. The court stated that the organisations have a legitimate interest in reviewing the agreements to assess whether they are sufficient and whether the companies are processing the data lawfully. Finally, the court noted that the organisations may determine the relationship (i.e. whether a joint controllership existed) between the companies based on this access request. The court ordered the controller to provide the organisations with access to the agreements between ING and Google. This includes how data subjects’ data will be processed (business sensitive information could be redacted. However, the controller did not have to grant access to the other requested data (e.g. research data or internal correspondence).

### Data Protection Commissioner v Facebook Ireland and Maximillian Schrems

*Source: CJEU, C-311/18, 2020-07-16 — https://overview.legal/posts/51470 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0311&ref=51470*

Invalidated Privacy Shield adequacy decision and upheld validity of Standard Contractual Clauses with additional safeguards required.

### Rb. Noord-Holland - C/15/376188

*Source: District Court Noord-Holland, 2026-07-13 — https://overview.legal/posts/144035 — original: https://gdprhub.eu/index.php?title=Rb._Noord-Holland_-_C/15/376188*

Facts — Rydo Telecom (the controller) is a telecommunications provider. In 2023, a data subject made an access request following a dispute with the controller on whether the data subject received two phones they had purchased from the controller. The data subject informed the controller in a letter that they intended to claim costs in the event that it did not respond to the request. The controller began investigating the data subject and found a similar claim against PostNL (one of the controller’s suppliers). According to PostNL, the data subject had made a similar claim that it had failed to deliver the two phones. The data subject later filed a case with the Amsterdam sub district court after the controller refused to respond to the request. The court dismissed the data subject’s claim for reimbursement of €2,908, on the grounds that the data subject had accused both companies of the same issue, and had left the hearing early. The data subject continued to reiterate their access request in 2024, and received a response from the controller in 2025. The controller stated that it no longer had data related to them beyond their email address in connection to the previous lawsuit. The data subject filed a case with the sub district court in 2026, who later referred the case to the court. The data subject requested the court to order the controller to provide full access to their data, subject to a penalty for noncompliance. Holding — The court first noted that the data subject had filed approximately 20 GDPR request cases with the sub district court within one year against different controllers. The court then assessed whether the data subject’s request was abusive within the meaning of Article 12(5) GDPR. This includes an objective and subjective element following CJEU case law (Brillen Rottler). According to the CJEU, the subjective element requires the data subject to intend to obtain a benefit by artificially creating the conditions to receive said benefit. Publicly available information can be used for this assessment. The court considered that the data subject had abused their right. The court took into consideration other cases the data subject had initiated, and considered that the data subject had a financial motive for their requests rather than a genuine concern to assess their personal data or verify the lawfulness of its processing. The court gave as an example the fact that the data subject had insisted that the controller reach a settlement in the form of paying compensation or damages. The court dismissed the case. Since there was an established abuse of rights, the court saw no need to assess the merits of the data subject’s claim.

### VG Düsseldorf - 29 K 3490/24

*Source: Administrative Court Düsseldorf, 2026-06-22 — https://overview.legal/posts/108992 — original: https://gdprhub.eu/index.php?title=VG_Düsseldorf_-_29_K_3490/24*

Facts — A district (the controller), acting as the lower water authority, initiated administrative proceedings after identifying unauthorised riverbank works and a private jetty on two riverside properties. One property belonged to a water utility company, while the other belonged to a municipality and was leased to the data subjects. During those proceedings, the controller shared the data subjects' personal data with various participants, including the owners of the affected properties, other public authorities and a lawyer who claimed to represent the data subjects. The data subjects lodged a complaint with the competent supervisory authority (LDI NRW), alleging that the controller had unlawfully processed and disclosed their personal data. They argued that their personal data had been shared with uninvolved third parties, that the controller had communicated with a lawyer whom they had not authorised, recorded a telephone conversation with an unknown person, and transmitted personal data by unencrypted email. The controller's data protection officer addressed each allegation and provided additional factual information concerning the disputed processing operations. The DPA initially informed the data subjects that no GDPR infringement was apparent, invited them to provide any additional factual information, and explained that it would obtain extracts from the controller's administrative file if there were concrete indications that it contained relevant facts not already available. The data subjects did not identify any additional facts and instead reiterated their legal position that the controller had breached its GDPR accountability obligations. The DPA rejected the complaint, concluding that no GDPR infringement could be established. The data subjects then brought an action before the Verwaltungsgericht Düsseldorf (Administrative Court Düsseldorf), seeking a fresh decision on their complaint on the basis that the DPA had failed to adequately investigate the complaint because it had not obtained the controller's administrative file before reaching its decision. Holding — The court held that Articles 57(1)(f) and 77(1) GDPR give rise to an enforceable right requiring a supervisory authority to investigate a complaint to the extent appropriate in the circumstances before determining whether a GDPR infringement has occurred. Recital 141 GDPR requires the investigation to extend as far as is appropriate in light of the circumstances of the individual case, including the significance of the complaint and the seriousness of the alleged infringement. Applying these principles, the court held that the DPA had adequately investigated the complaint. It had considered each allegation together with the detailed response provided by the controller's data protection officer, invited the data subjects to provide any additional factual information, and explained that it would obtain extracts from the administrative file if concrete indications emerged that further relevant facts required clarification. As the data subjects did not provide any additional facts and there were no objective indications that the information already available was inaccurate or incomplete, the court held that the DPA was not required to obtain the controller's administrative file or undertake further investigations in the absence of concrete indications that additional factual clarification was necessary. The court further held that the DPA had correctly concluded that no GDPR infringement had occurred. The court held that the disputed processing was lawful under Article 6(1)(e) GDPR, read together with Article 6(3) GDPR and § 88 of the German Water Resources Act (WHG), which provided the legal basis for the processing. The court also held that the transmission of personal data by email did not infringe Article 5(1)(f) GDPR because, in the circumstances of the case, transport encryption provided an appropriate level of security.

### VB v Natsionalna agentsia za prihodite

*Source: CJEU, C-340/21, 2023-12-14 — https://overview.legal/posts/51485 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0340*

Data breach alone does not establish inadequate security measures. Burden on controller to prove adequacy.

### GC and Others v CNIL

*Source: CJEU, C-136/17, 2019-09-24 — https://overview.legal/posts/51475 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62017CJ0136*

Conditions for delisting sensitive data from search results.

### Unabhängiges Landeszentrum für Datenschutz v Wirtschaftsakademie Schleswig-Holstein

*Source: CJEU, C-210/16, 2018-06-05 — https://overview.legal/posts/51477 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62016CJ0210&ref=51477*

Facebook fan page administrators are joint controllers with Facebook.

## Guidance

### Report on stakeholder event on anonymisation and pseudonymisation of 12 December 2025

*Source: EDPB, report-on-stakeholder-event-on-anonymisation-and-en, 2026-02-18 — https://overview.legal/posts/125688 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/report-on-stakeholder-event-on-anonymisation-and_en*

Report on stakeholder event on anonymisation and pseudonymisation of 12 December 2025 1. Background The EDPB organise d a remote stakeholder event on 12 December 2025 to collect stakeholders’ input on anonymisation and pseudonymisation , following the Court of Justice of the European Union ( “ CJEU ” ) judgment in case EDPS v SRB 1 . The objective was to engage with stakeholders to inform the EDPB’s ongoing work on its guidelines 01/2025 on pseudonymisation and f orthcoming guidelines on…

### Guidelines 07/2020 on the concepts of controller and processor in the GDPR

*Source: EDPB, edpb-guidelines-on-the-concepts-of-controller-and-processor-in-the-gdpr, 2021-07-07 — https://overview.legal/posts/38069 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-072020-on-the-concepts-of-controller-and-processor-in-the-gdpr_en*

The concepts of controller, joint controller and processor play a crucial role in the application of the General Data Protection Regulation 2016/679 (GDPR), since they determine who shall be responsible for compliance with different data protection rules, and how data subjects can exercise their rights in practice. The precise meaning of these concepts and the criteria for their correct interpretation must be sufficiently clear and consistent throughout the European Economic Area (EEA). The conc...

### Guidelines 01/2021

*Source: EDPB, edpb-guidelines-on-examples-regarding-personal-data-breach-notification, 2022-01-03 — https://overview.legal/posts/38047 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-012021-on-examples-regarding-personal-data-breach-notification_en*

The European Data Protection Board (EDPB) adopted Guidelines 01/2021 on December 14, 2021, providing practical examples and analysis regarding personal data breach notification obligations under Articles 33 and 34 of the GDPR. The guidelines present hypothetical scenarios covering ransomware attacks and data exfiltration incidents, illustrating how controllers should assess risk to determine whether notification to supervisory authorities and communication to data subjects are required. The document serves as interpretive guidance for controllers evaluating breach severity, appropriate mitigation measures, and notification decisions, and does not impose any fines or sanctions.

### Guidelines on the right to data portability under Regulation 2016/679, WP242 rev.01

*Source: EDPB, guidelines-on-the-right-to-data-portability-under-regulation-2016679-wp242-en, 2018-05-25 — https://overview.legal/posts/126336 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-on-the-right-to-data-portability-under-regulation-2016679-wp242_en*

J.No. 2022-7320-3298 Doc.no. 495942 Caseworker Ditte Hector Dalhoff The Danish Data Protection Agency Carl Jacobsens Vej 35 2500 Valby Denmark T 3319 3200 dt@datatilsynet.dk datatilsynet.dk VAT No. 11883729 [Name and address] Complaint about Organic Basics ApS 1. The Danish Data Protection Agency (hereinafter referred to as the ‘Danish DPA) returns to the case, where you on 20 October 2020 have complained to the Lander Commissioner for Data Protection and Freedom of Information — Free Hanseatic…

### EDPB Document on response to the request from the European Commission for clarifications on the consistent application of the GDPR, focusing on health research

*Source: EDPB, edpb-document-on-response-to-the-request-from-the-european-commission-for-en, 2021-02-02 — https://overview.legal/posts/126069 — original: https://www.edpb.europa.eu/documents/other-guidance/edpb-document-on-response-to-the-request-from-the-european-commission-for_en*

EDPB Document on r esponse to the request from the European Commission for clarifications on the consistent application of the GDPR, focusing on health research Adopted on 2 February 2021 2 Adopted 3 Adopted The European Data Protection Board Having regard to Article 70.1.b of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and…

### Guidelines 2/2018 on derogations of Article 49 under Regulation 2016/679

*Source: EDPB, edpb-guidelines-on-derogations-of-article-49, 2018-05-25 — https://overview.legal/posts/38057 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-22018-on-derogations-of-article-49-under-regulation-2016679_en*

The European Data Protection Board (EDPB) issued Guidelines 2/2018 to provide interpretive guidance on the application of Article 49 derogations for international transfers of personal data under the GDPR. The guidelines emphasize that derogations under Article 49 are exceptions to the general rule requiring an adequacy decision or appropriate safeguards, and that controllers must first exhaust transfer mechanisms under Articles 45 and 46 before resorting to these derogations. The document details specific conditions and limitations for each derogation, including explicit consent, contractual necessity, public interest, vital interests, public registers, and compelling legitimate interests.

### Opinion 15/2025 on the draft decision of the Austrian Supervisory Authority (AT SA) regarding the certification criteria of BDO Consulting GmbH

*Source: EDPB, edpb-opinion-202515-dbo-certificationcriteria-en, 2025-07-14 — https://overview.legal/posts/51079 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-152025-on-the-draft-decision-of-the-austrian_en*

Adopted 1 Opinion 15/2025 on the draft decision of the Austrian Supervisory Authority ( AT SA) regarding the certificat ion criteria of BDO Consulting GmbH Adopted on 8 July 2025 Adopted 2 Adopted 3 The European Data Protection Board Having regard to Article 63, Article 64(1)(c) and Article 42 of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of…

### Guidelines 9/2022 on personal data breach notification under GDPR

*Source: EDPB, edpb-guidelines-on-personal-data-breach-notification-under-gdpr, 2023-04-04 — https://overview.legal/posts/38058 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-92022-on-personal-data-breach-notification-under-gdpr_en*

The EDPB adopted Guidelines 9/2022 (Version 2.0, 28 March 2023) to update and replace the prior WP250 guidance on personal data breach notification under Articles 33 and 34 of the GDPR. The guidelines address the definition and types of personal data breaches, controller and processor notification obligations, the concept of a controller becoming "aware" of a breach, cross-border and non-EU establishment breach scenarios, and the conditions under which notification to supervisory authorities and data subjects is or is not required.

## Enforcement decisions

### APDCAT sanctions Madremanya City Council for exposing applicants' sensitive data in tender

*Source: APDCAT (Catalonia), 2026-07-17 — https://overview.legal/posts/184715 — original: https://gdprhub.eu/index.php?title=APDCAT_(Catalonia)_-_PS-0036/2026*

Facts — On 8 May 2025, Madremanya City Council, acting as controller, published on its notice board two administrative acts concerning a tender procedure for the award of a social housing lease. The documents expressly disclosed the identities of the applicants. On 9 May 2025, the controller replaced the original documents with revised versions in which the applicants’ names and surnames were partially redacted, leaving only their initials visible. However, the redaction was performed manually and did not effectively conceal the information, as it remained possible to infer the length of the names and surnames and to identify some of their letters. In addition to the applicants’ identifying information, the documents disclosed detailed financial data, including the exact annual net income of each household. They also revealed information concerning particularly sensitive personal circumstances, including dependency, gender-based violence and addiction, which had been used to calculate the applicants’ respective scores. No adequate anonymisation or redaction measures had been implemented. In July and November 2025, the DPA requested that the controller provide specific information concerning certain aspects of the processing. The controller’s failure to respond or cooperate hindered the DPA’s ability to exercise its investigative powers. Holding — The DPA held that the controller violated Article 5(1)(c) GDPR by publishing personal data that were not necessary for the purpose pursued. The DPA acknowledged that publishing information about the procedure could serve the objective of administrative transparency. However, transparency did not justify disclosing identifying data together with detailed financial information and sensitive personal or family circumstances. The controller had to limit the processing to data that were necessary and proportionate to that objective and consider less intrusive alternatives. The DPA found that the controller’s subsequent redaction did not amount to effective anonymisation. Although most of the characters had been concealed, the applicants could still potentially be reidentified from their initials, the length of their names and surnames and other contextual information. This risk was particularly significant because the municipality had only 277 inhabitants. The controller should therefore have applied complete anonymisation or a pseudonymisation method preventing direct or indirect identification. The DPA also held that the controller violated Article 5(1)(f) GDPR and the duty of confidentiality under Article 5 LOPDGDD. The published documents disclosed the applicants’ exact household income, household composition and scores linked to circumstances such as dependency, addiction, gender-based violence, single-parent status and age. Although this information was relevant to assessing the applications, it was unnecessary to make it publicly accessible in a form linked to identifiable individuals. The DPA considered that the violations of the data-minimisation and confidentiality principles constituted a medial concurrence of infringements. The failure to anonymise the applicants’ identities was the necessary means through which their sensitive personal and family circumstances were disclosed. Nevertheless, the DPA formally declared separate violations of Articles 5(1)(c) and 5(1)(f) GDPR. Additionally, the DPA held that the controller violated Article 31 GDPR by failing to respond to two information requests. This failure breached the controller’s duty to cooperate with the supervisory authority and obstructed the exercise of the DPA’s investigative powers.

### Austrian DSB: sharing ADHD diagnosis from public forum post did not breach Art. 9 GDPR

*Source: DSB (Austria), 2025-12-03 — https://overview.legal/posts/108990 — original: https://gdprhub.eu/index.php?title=DSB_(Austria)_-_2025-0.968.031*

Facts — A data subject published a post concerning their ADHD diagnosis on a publicly accessible online forum under a pseudonym. A person (the controller) who was a follower of the data subject and had previously been in personal contact with them, knew that the pseudonym belonged to the data subject. The controller subsequently sent a WhatsApp message to a mutual acquaintance stating that the data subject had received an ADHD diagnosis and included a link to the forum post. The data subject lodged a complaint with the Austrian DPA (DSB), arguing that their health data had been disclosed to a third party. They alleged that the controller by forwarding the pseudonymous forum profile, had unequivocally linked it to their real identity. Holding — The DPA held that the data subject was identifiable to the controller as regards the publication of the forum post under her profile name. Since the post also included information concerning her gender, age and diagnosis, it concluded that it constituted her personal data under Article 4(1) GDPR. The DPA further held that the prohibition on processing special categories of personal data under Article 9(1) GDPR did not apply because the data subject had manifestly made their health data public within the meaning of Article 9(2)(e) GDPR. It reasoned that actively disclosing the ADHD diagnosis in a publicly accessible forum constituted an unambiguous and conscious act by which the data subject made the information available to the public. The DPA therefore dismissed the complaint as unfounded.

### Hestia Publishers & Booksellers I. D. Kollaros & Co. S.A.: Insufficient technical and organisational measures to ensure information security

*Source: Hellenic Data Protection Authority (HDPA), 2025-07-21 — https://overview.legal/posts/49036 — original: https://www.enforcementtracker.com/ETid-2921*

The Greek DPA has imposed a fine of EUR 9,000 on Hestia Publishers & Booksellers I. D. Kollaros & Co. S.A. The controller disclosed the identity of an anonymous author by including their legal name alongside other personal data and the pseudonym under which their work was published.

### DSB (Austria) - 2021-0.698.184

*Source: DSB (Austria), 2021-10-08 — https://overview.legal/posts/262252 — original: https://gdprhub.eu/index.php?title=DSB_(Austria)_-_2021-0.698.184*

Facts — The data subject was a shareholder and managing director of two companies. The controller operated a free online search platform that allowed users to look up companies registered in the Austrian companies register and see, for a given company, which natural persons held positions such as shareholder or managing director, as well as an overlay showing what other companies those persons were connected to. The controller obtained the underlying data from a commercial information provider, which in turn sourced it from the Federal Ministry of Justice under a data-reuse agreement covering companies register documents. The controller funded the free service through advertising displayed on the platform. The data subject had no contractual relationship with the controller. A direct name search for the data subject on the controller's platform returned no results, however, searching for a company in which he held a position returned his name together with his role (managing director, sole shareholder with a 100% stake) and through an „i“ icon, an overlay listing his positions in other companies. The data subject complained to the Austrian DPA, arguing that the controller published his name without any contract between them and without any identifiable legitimate interest justifying the publication. The controller argued that its processing pursued a legitimate commercial interest, enabling business participants to research potential contractual partners and pointed out that companies register data was already public and accessible to anyone under national law, including via other commercial and official information services. Holding — First, the DPA rejected the controller's argument that the data was already available and therefore outside the scope of a secrecy interest altogether. It held, citing CJEU case-law C-73/07, that a blanket assumption that lawfully published data cannot be subject to a legitimate secrecy interest is incompatible with EU law requirements. Second, the DPA held that the controller's processing constituted a new form of data use requiring independent justification, because the controller did not merely reproduce publicly accessible companies register data, but recombined and cross-linked it, thereby creating additional informational value beyond what a simple companies register search would reveal. Third, applying the balancing test under Article 6(1)(f) GDPR and Section 1(2) DSG, the DPA found that the controller had a legitimate interest in operating its platform, both a commercial interest of its own (generating advertising revenue) and a legitimate interest of platform users and market participants generally in being able to assess a business partner's other company affiliations. The DPA weighed this against the data subject's interest in secrecy and concluded that the balance favoured the controller, for three reasons: 1. the underlying data's general availability in the companies register reduced (though did not eliminate) its protection-worthiness 2. the data related exclusively to the data subject's professional sphere as someone who had voluntarily chosen to participate in commercial life as a shareholder and managing director 3. the resulting interference with his data protection rights was accordingly of low intensity. The DPA therefore rejected the complaint as unfounded.

### DSB: Medical student fined for recording dementia patient video without Art 9 GDPR basis

*Source: DSB (Austria), 2026-01-12 — https://overview.legal/posts/96832 — original: https://gdprhub.eu/index.php?title=DSB_(Austria)_-_2026-0.016.479*

Facts — A medical student (the controller) worked as a ward attendant at a hospital. Her duties were to remain in the immediate vicinity of patients, ensure their safety and notify the nursing staff immediately when necessary. While assigned to a patient with dementia (the data subject), she recorded a video of him wearing a hospital gown and throwing a newspaper to the floor. She subsequently sent the video to a fellow student through a messaging service. The recording lasted about eleven seconds. Holding — The DPA treated the medical student as the controller of the relevant processing pursuant to Article 4(7) GDPR because she decided to record the data subject and disclose the video to a third party. It found that the context of the video, the data subject’s clothing and behaviour revealed information concerning his health within the meaning of Article 4(15) GDPR. The video therefore contained special categories of personal data. The DPA noted that an applicable condition under Article 9(2) GDPR was required for the processing. The DPA found that the controller lacked a legal basis for the relevant processing. It emphasized that the controller could not rely on Article 6(1)(f) GDPR since Article 9(2) GDPR restricts processing based on legitimate interest. The DPA pointed out that no scientific purpose was apparent for this recording and disclosure. It further noted that the video recording of the data subject was made for the purpose of exchanging comments with a fellow student. It therefore held that the processing also lacked a legitimate purpose under Article 5(1)(b) GDPR. The DPA concluded that the controller infringed Article 5(1)(a) GDPR, Article 5(1)(b) GDPR, Article 6(1) GDPR and Article 9(2) GDPR. It found that she had acted intentionally, as she had knowingly recorded and transmitted the video and was aware that the processing was unlawful. It imposed a fine of €200, with twelve hours’ substitute imprisonment if the fine proved uncollectible.

### Hestia Publishers & Booksellers, I. D. Kollaros & Co. S.A.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen.

*Source: Hellenic Data Protection Authority (HDPA), 2025-07-21 — https://overview.legal/posts/52189*

De Griekse autoriteit voor gegevensbescherming heeft een boete van 9.000 euro opgelegd aan Hestia Publishers & Booksellers I. D. Kollaros & Co. S.A. De verantwoordelijke partij heeft de identiteit van een anonieme auteur onthuld door hun volledige naam te vermelden, naast andere persoonlijke gegevens en het pseudoniem waaronder hun werk is gepubliceerd.

### Romanian Post National Company: Insufficient technical and organisational measures to ensure information security

*Source: Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), 2020-07-30 — https://overview.legal/posts/46474 — original: https://www.enforcementtracker.com/ETid-359*

Processing of personal data, namely the telephone numbers and e-mail addresses of 81 data subjects, by the Romanian Post as data controller, failing appropriate technical and organisational measures, such as pseudonymisation.

### Austrian DSB: Marketing agency violated GDPR by recording phone interviews without valid

*Source: DSB (Austria), 2026-01-19 — https://overview.legal/posts/184689 — original: https://gdprhub.eu/index.php?title=DSB_(Austria)_-_2025-1.049.138*

Facts — The controller was a digital marketing agency whose employees pre-screened potential applicants for its clients. As part of this process, applicants (data subjects) were contacted and interviewed by telephone. A former employee of the controller was examined as a witness by the Austrian DPA (DSB) and provided evidence concerning the recordings. The telephone interviews generally followed a particular pattern. The employees contacted data subjects in the name of the relevant client, stated that their application appeared interesting, presented the position, asked about their qualifications and professional experience and, where appropriate, arranged an in-person interview. The calls were recorded from beginning to end and stored for an indefinite period. In some cases, data subjects were not informed that the call was being recorded. In other cases, the employee asked during the call whether recording would be acceptable. In one such call, the data subject responded, “Uh, yeah.” Moreover, a superior employee had encouraged other employees through an intranet message to record and store interviews for training purposes, including without obtaining the data subject's consent. The controller argued that it had been unaware of the recording practice. It submitted that the employee who had instructed the others to make the recordings was neither a managing director nor an authorised signatory and had no authority to issue such instructions. According to the controller, the statement that interviews could be recorded “even without consent” resulted from personal overzealousness and legal recklessness and did not reflect the controller’s internal procedures. As legal bases for the processing, the controller stated that it relied on consent under Article 6(1)(a) GDPR and legitimate interests under Article 6(1)(f) GDPR. It claimed that data subjects had been expressly asked for consent at the beginning of the application process and that the recordings served the legitimate interest of improving employee performance. Holding — The DPA relied on the CJEU’s judgment in Case C-807/21 (Deutsche Wohnen) and held that a legal entity may be liable not only for infringements committed by its representatives, managers or executives, but also for infringements committed by any person acting within the scope of its business activities and on its behalf. It acknowledged that an exception may apply where an employee acts outside that framework and exclusively for personal purposes. The DPA determined that the supervising employee had ordered the processing within the scope of their employment relationship and in the controller’s interest. It pointed out that the controller could therefore not avoid responsibility by claiming that it had been unaware of the practice or that the employee lacked formal authority to issue instructions. The DPA held that no consent had been obtained in some cases and that, where consent had been sought, it was neither timely nor valid. It stated that consent must be obtained before processing begins. However, it noted that the recordings had already been activated before the calls began, due to the fact that the recordings included the opening greetings. It held that asking for consent during the recorded call was too late. The DPA further held that one data subject’s response, “Uh, yeah,” did not constitute an unambiguous affirmative act. It also considered that a job interview, similarly to an existing employment relationship, is characterised by a structural imbalance of power. Moreover, it emphasised that the data subjects had not been informed of the true identity of the controller, because its employees presented themselves as acting for the client companies. It concluded that the data subject could therefore not have given valid consent and that processing could not be based on Article 6(1)(a) GDPR. Furthermore, the DPA examined whether the recordings could be justified by legitimate interests. It underlined that a controller relying on Article 6(1)(f) GDPR must comply with the corresponding transparency obligations. Specifically, pursuant to Article 13(1)(d) GDPR, the legitimate interests pursued must be communicated when the personal data is collected. Referring to Case C-394/23 (Mousse) the DPA held that the collection could not be based on Article 6(1)(f) GDPR where that information had not been provided in time. It found that the data subjects had either not been informed at all of the legitimate interest pursued or had been informed only after the collection of their personal data had begun. It held accordingly that the processing could not be based on Article 6(1)(f) GDPR. The DPA concluded that the recording and storage of the interviews lacked a legal basis and infringed Article 6(1) GDPR in conjunction with Article 5(1)(a) GDPR. In addition, the DPA held that the recordings were not necessary for the training purpose as less intrusive alternatives, such as simulated interviews between employees, could have achieved the same objective. It therefore found a violation of the principle of data minimisation under Article 5(1)(c) GDPR. It further found that the indefinite retention of the recordings was also unnecessary and violated the principle of storage limitation under Article 5(1)(e) GDPR. The DPA also found that the controller had failed to comply with its transparency obligations. In some cases, data subjects received no information about the processing. In others, information was provided only after the processing had begun. The data subjects were also not informed of the identity of the actual controller, because the employees presented themselves as representatives of the client companies. It therefore found an infringement of Article 5(1)(a) GDPR in conjunction with Article 12 GDPR and Article 13 GDPR. The DPA found that the controller had acted at least negligently. It imposed a fine of €25,500 for the infringements.

## Recent developments

### Council deletes revised definition of personal data from GDPR omnibus

*Source: EURactiv, 2026-02-20 — https://overview.legal/posts/52808 — original: https://www.euractiv.com/news/council-deletes-revised-definition-of-personal-data-from-gdpr-omnibus/*

The EDPB's upcoming updated guidelines on pseudonymisation are also given more prominence in a compromise text, obtained by Euractiv

### Stakeholder event on anonymisation and pseudonymisation: express your interest

*Source: EDPB, 2025-11-17 — https://overview.legal/posts/49125 — original: https://www.edpb.europa.eu/news/news/2025/stakeholder-event-anonymisation-and-pseudonymisation-express-your-interest_en*

Brussels, 17 November - The EDPB organises a remote event to collect stakeholders’ input on anonymisation and pseudonymisation on implications of the judgement of the Court of Justice of the European Union (CJEU) in EDPS v Single Resolution Board (SRB). The event will take place on 12 December 2025 (time to be confirmed). This will be an opportunity to inform and support the EDPB’s ongoing work on these topics as per its work programme 2024-2025 and it reflects the EDPB’s commitment to stakehold

### Evenement voor stakeholders over anonimisering en pseudonimisering: geef uw interesse aan.

*Source: EDPB, 2025-11-17 — https://overview.legal/posts/51725*

Brussel, 17 november - Het EDPB organiseert een online evenement om input van belanghebbenden te verzamelen over anonimisering en pseudonimisering, en over de implicaties van het vonnis van het Gerechtshof van de Europese Unie (HvEU) in de zaak EDPS tegen het Single Resolution Board (SRB). Het evenement zal plaatsvinden op 12 december 2025 (tijdstip volgt). Dit biedt een gelegenheid om het EDPB te informeren en te ondersteunen bij zijn lopende werk op deze onderwerpen, zoals uiteengezet in het werkprogramma 2024-2025, en het weerspiegelt de toewijding van het EDPB aan de betrokkenheid van belanghebbenden.

### De Autoriteit Persoonsgegevens publiceert een rapport over de risicoanalyse van de AVG (Algemene Verordening Gegevensbescherming).

*Source: AEPD, 2022-10-11 — https://overview.legal/posts/51791*

De GDPR-risicoanalyse is bedoeld om controllers en verwerkers te helpen bij het identificeren van de risicofactoren voor de rechten en vrijheden van de betrokkenen, wiens gegevens worden verwerkt. Het doel is om een eerste inschatting te maken van het inherente risico, inclusief de noodzaak om een Privacy Impact Assessment (DIA) uit te voeren, en om het resterende risico te schatten als maatregelen en beveiligingsmechanismen worden gebruikt om specifieke risicofactoren te verminderen.

### AEPD publishes GDPR Risk Assessment

*Source: AEPD, 2022-10-11 — https://overview.legal/posts/6259 — original: https://evalua-riesgo.aepd.es/index_en.html#entry-1032*

> GDPR RISK ASSESSMENT is intended to assist controllers and processors to identify the risk factors for the rights and freedoms of data subjects whose data are present in the processing, to make an initial assessment of the intrinsic risk, including the need to perform a DPIA, and to estimate the residual risk if measures and safeguards are used to mitigate the specific risk factors.

## Literature

### GDPR principles in Data protection encourage pseudonymization through most popular and full-personalized devices - mobile phones

*Source: Procedia Computer Science, 2019-01-01 — https://overview.legal/posts/132584 — original: https://doi.org/10.1016/j.procs.2019.04.043*

### POJAM OSOBNOG PODATKA U TUMAČENJU SUDA EUROPSKE UNIJE

*Source: Zbornik radova. Aktualnosti građanskog i trgovačkog zakonodavstva i pravne prakse, 2026-07-06 — https://overview.legal/posts/83510 — original: https://doi.org/10.47960/2744-2918.23.2026.281*

U radu se istražuje evolucija pojma osobnih podataka u kontekstu pseudonimizacije kroz analizu recentne sudske prakse i regulatornih smjernica. Središnji dio rada fokusiran je na presudu Suda Europske Unije u predmetu EDPS protiv SRB, kojom se potvrđuje kontinuitet relativnog poimanja pojma osobnog podatka u kontekstu provođenja postupka pseudonimizacije osobnih podataka. Hoće li se određeni podatak smatrati osobnim ovisi, tako, o tome tko podatak obrađuje i raspolaže li i kojim dodatnim informa

### If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation

*Source: Computer law & security review, 2026-01-23 — https://overview.legal/posts/53843 — original: https://doi.org/10.1016/j.clsr.2025.106251*

As the General Data Protection Regulation (GDPR) approaches its tenth anniversary, the European legislator is considering reforms thereto. This article offers a set of research-based suggestions for what such reforms could look like, based on two assumptions. First, that the GDPR is overall a solid piece of legislation that upholds the enduring objectives and principles of data protection law. Second, that any improvement cannot compromise the level of protection of fundamental rights currently

### The data subject’s right to access to information under GDPR and the right of the data controller to protect its know-how

*Source: Przegląd Prawniczy Uniwersytetu im. Adam Mickiewicza, 2023-12-30 — https://overview.legal/posts/132546 — original: https://doi.org/10.14746/ppuam.2023.15.09*

The data subject’s right to access information on data processing has a very broad meaning. Considering the latest developments in this field (mainly the CJEU ruling on Austrian posts and EDPB guidelines) one can draw the conclusion that the controller’s right to protect its confidential in-formation is limited and less valuable than the data subject’s rights. However, this may lead to unfair and unequal treatment of companies and data subjects. When looking at this right in a more systematic pe

### GDPR Implementation Series ∙ Hungary: Introduction to the GDPR Application and a Brief History of Data Protection

*Source: European Data Protection Law Review, 2019-01-01 — https://overview.legal/posts/132426 — original: https://doi.org/10.21552/edpl/2019/4/11*

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Profiling** — https://overview.legal/topics/profiling
  Automated processing to evaluate personal aspects
- **Human Resources** — https://overview.legal/topics/human-resources
  Processing of employee and HR data
- **Law Enforcement** — https://overview.legal/topics/law-enforcement
  Processing for law enforcement purposes
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing

---
Generated by overview.legal · https://overview.legal/topics/pseudonymization · 2026-08-22
