Public Sector
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Processing by public authorities
Overview
21 sources · Jul 15, 2026Legal Framework
Public authorities processing personal data are governed by several key provisions. Article 4(7) GDPR explicitly includes public authorities within the definition of "controller," subjecting them to the full range of obligations. For legal basis, public bodies typically rely on Article 6(1)(c) (compliance with legal obligation) or 6(1)(e) (performance of a task carried out in the public interest or in the exercise of official authority vested in the controller), rather than consent under Article 6(1)(a). Where consent is sought, it must meet the standard of genuine free choice—Article 3:33 and 3:35 of the Dutch Civil Code apply by analogy, and Recital 42 clarifies that consent is invalid where the data subject has no real choice or cannot refuse without adverse consequences. Recital 154 permits public authorities to disclose personal data contained in official documents where Union or Member State law provides for such disclosure, requiring reconciliation of public access rights with data protection rights. Collective litigation risk also applies: under Article 3:305a of the Dutch Civil Code, foundations may bring claims bundling similar interests of affected individuals, provided those interests are suitable for aggregation and fall within the organization's statutory purpose.
Key Developments
The Court of Justice has established that restrictions on fundamental rights by public authorities must correspond to objectives of general public interest and must not constitute disproportionate interference (V & EDPS v European Parliament). In Client Earth v EFSA, the Court emphasized that transparency in public authority decision-making enhances legitimacy and democratic accountability. The X ruling of 2013 set a ceiling on fees public authorities may charge for access requests: the fee must not exceed the cost of communicating the data, though Member States may set lower fees to ensure effective access. Commission v Germany confirmed that conferring independent status on supervisory authorities overseeing data processing outside the public sector does not deprive those authorities of democratic legitimacy. On enforcement, the Polish DPA fined the Minister of Justice €23,540 for insufficient technical and organizational measures, while the Belgian DPA fined Société Wallonne des Eaux €86,000 for lacking a valid legal basis—demonstrating that public sector bodies face the same enforcement standards as private controllers.
Practical Guidance
- Establish legal basis under Article 6(1)(c) or 6(1)(e) rather than relying on consent, given the inherent power imbalance in public authority–data subject relationships that undermines the free choice requirement articulated in Recital 42.
- Implement disclosure protocols that reconcile public access to official documents under Recital 154 with data protection obligations, ensuring any disclosure of personal data is grounded in specific Union or Member State law.
- Cap access fees at the actual cost of communicating data per the X ruling, and consider setting lower fees to guarantee effective exercise of access rights.
- Maintain technical and organizational measures proportionate to processing risks, as the UODO enforcement against the Minister of Justice demonstrates that inadequate security measures trigger fines regardless of public sector status.
- Document the legal basis for each processing activity explicitly—the Belgian DPA's fine against a public water utility for insufficient legal basis underscores that public authorities cannot assume implied authorization.