# Public Sector — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/public-sector
> Sources are cited per item. Verify against the official texts before relying on them.

Processing by public authorities

## Overview

## Legal Framework

Public authorities processing personal data are governed by several key provisions. Article 4(7) GDPR explicitly includes public authorities within the definition of "controller," subjecting them to the full range of obligations. For legal basis, public bodies typically rely on Article 6(1)(c) (compliance with legal obligation) or 6(1)(e) (performance of a task carried out in the public interest or in the exercise of official authority vested in the controller), rather than consent under Article 6(1)(a). Where consent is sought, it must meet the standard of genuine free choice—Article 3:33 and 3:35 of the Dutch Civil Code apply by analogy, and Recital 42 clarifies that consent is invalid where the data subject has no real choice or cannot refuse without adverse consequences. Recital 154 permits public authorities to disclose personal data contained in official documents where Union or Member State law provides for such disclosure, requiring reconciliation of public access rights with data protection rights. Collective litigation risk also applies: under Article 3:305a of the Dutch Civil Code, foundations may bring claims bundling similar interests of affected individuals, provided those interests are suitable for aggregation and fall within the organization's statutory purpose.

## Key Developments

The Court of Justice has established that restrictions on fundamental rights by public authorities must correspond to objectives of general public interest and must not constitute disproportionate interference (V & EDPS v European Parliament). In Client Earth v EFSA, the Court emphasized that transparency in public authority decision-making enhances legitimacy and democratic accountability. The X ruling of 2013 set a ceiling on fees public authorities may charge for access requests: the fee must not exceed the cost of communicating the data, though Member States may set lower fees to ensure effective access. Commission v Germany confirmed that conferring independent status on supervisory authorities overseeing data processing outside the public sector does not deprive those authorities of democratic legitimacy. On enforcement, the Polish DPA fined the Minister of Justice €23,540 for insufficient technical and organizational measures, while the Belgian DPA fined Société Wallonne des Eaux €86,000 for lacking a valid legal basis—demonstrating that public sector bodies face the same enforcement standards as private controllers.

## Practical Guidance

- Establish legal basis under Article 6(1)(c) or 6(1)(e) rather than relying on consent, given the inherent power imbalance in public authority–data subject relationships that undermines the free choice requirement articulated in Recital 42.
- Implement disclosure protocols that reconcile public access to official documents under Recital 154 with data protection obligations, ensuring any disclosure of personal data is grounded in specific Union or Member State law.
- Cap access fees at the actual cost of communicating data per the X ruling, and consider setting lower fees to guarantee effective exercise of access rights.
- Maintain technical and organizational measures proportionate to processing risks, as the UODO enforcement against the Minister of Justice demonstrates that inadequate security measures trigger fines regardless of public sector status.
- Document the legal basis for each processing activity explicitly—the Belgian DPA's fine against a public water utility for insufficient legal basis underscores that public authorities cannot assume implied authorization.

## Legislation (full text of key provisions)

### Right to lodge a complaint

*Source: DSA, dsa-art-53-en, 2022-10-19 — https://overview.legal/posts/94952*

Recipients of the service and any body, organisation or association mandated to exercise the rights conferred by this Regulation on their behalf shall have the right to lodge a complaint against providers of intermediary services alleging an infringement of this Regulation with the Digital Services Coordinator of the Member State where the recipient of the service is located or established. The Digital Services Coordinator shall assess the complaint and, where appropriate, transmit it to the Digital Services Coordinator of establishment, accompanied, where considered appropriate, by an opinion. Where the complaint falls under the responsibility of another competent authority in its Member State, the Digital Services Coordinator receiving the complaint shall transmit it to that authority. During these proceedings, both parties shall have the right to be heard and receive appropriate information about the status of the complaint, in accordance with national law.

### Processing and public access to official documents

*Source: GDPR, gdpr-art-86-en, 2016-04-27 — https://overview.legal/posts/91431*

Personal data in official documents held by a public authority or a public body or a private body for the performance of a task carried out in the public interest may be disclosed by the authority or body in accordance with Union or Member State law to which the public authority or body is subject in order to reconcile public access to official documents with the right to the protection of personal data pursuant to this Regulation.

### Recital 8 — public administration exclusion scope

*Source: NIS2, nis2-rec-8-en, 2022-12-14 — https://overview.legal/posts/96544*

The exclusion of public administration entities from the scope of this Directive should apply to entities whose activities are predominantly carried out in the areas of national security, public security, defence or law enforcement, including the prevention, investigation, detection and prosecution of criminal offences. However, public administration entities whose activities are only marginally related to those areas should not be excluded from the scope of this Directive. For the purposes of this Directive, entities with regulatory competences are not considered to be carrying out activities in the area of law enforcement and are therefore not excluded on that ground from the scope of this Directive. Public administration entities that are jointly established with a third country in accordance with an international agreement are excluded from the scope of this Directive. This Directive does not apply to Member States’ diplomatic and consular missions in third countries or to their network and information systems, insofar as such systems are located in the premises of the mission or are operated for users in a third country.

### Recital 129 — competent authority power administrative fines

*Source: NIS2, nis2-rec-129-en, 2022-12-14 — https://overview.legal/posts/96786*

In order to ensure effective enforcement of the obligations laid down in this Directive, each competent authority should have the power to impose or request the imposition of administrative fines.

### Recital 67 — cross-border official exchange schemes for authorities

*Source: NIS2, nis2-rec-67-en, 2022-12-14 — https://overview.legal/posts/96662*

The competent authorities and the CSIRTs should be able to participate in exchange schemes for officials from other Member States, within a specific framework and, where applicable, subject to the required security clearance of officials participating in such exchange schemes, in order to improve cooperation and strengthen trust among Member States. The competent authorities should take the necessary measures to enable officials from other Member States to play an effective role in the activities of the host competent authority or the host CSIRT.

### Recital 41 — national CSIRT capabilities and resources

*Source: NIS2, nis2-rec-41-en, 2022-12-14 — https://overview.legal/posts/96610*

Member States should be adequately equipped, in terms of both technical and organisational capabilities, to prevent, detect, respond to and mitigate incidents and risks. Member States should therefore establish or designate one or more CSIRTs under this Directive and ensure that they have adequate resources and technical capabilities. The CSIRTs should comply with the requirements laid down in this Directive in order to guarantee effective and compatible capabilities to deal with incidents and risks and to ensure efficient cooperation at Union level. Member States should be able to designate existing computer emergency response teams (CERTs) as CSIRTs. In order to enhance the trust relationship between the entities and the CSIRTs, where a CSIRT is part of a competent authority, Member States should be able to consider functional separation between the operational tasks provided by the CSIRTs, in particular in relation to information sharing and assistance provided to the entities, and the supervisory activities of the competent authorities.

### Recital 134 — mutual assistance supervisory enforcement cooperation

*Source: NIS2, nis2-rec-134-en, 2022-12-14 — https://overview.legal/posts/96796*

For the purpose of ensuring entities’ compliance with their obligations laid down in this Directive, Member States should cooperate with and assist each other with regard to supervisory and enforcement measures, in particular where an entity provides services in more than one Member State or where its network and information systems are located in a Member State other than that where it provides services. When providing assistance, the requested competent authority should take supervisory or enforcement measures in accordance with national law. In order to ensure the smooth functioning of mutual assistance under this Directive, the competent authorities should use the Cooperation Group as a forum to discuss cases and particular requests for assistance.

### Recital 24 — sector-specific reporting consistency

*Source: NIS2, nis2-rec-24-en, 2022-12-14 — https://overview.legal/posts/96576*

Where provisions of a sector-specific Union legal act require essential or important entities to comply with reporting obligations that are at least equivalent in effect to the reporting obligations laid down in this Directive, the consistency and effectiveness of the handling of incident notifications should be ensured. To that end, the provisions relating to incident notifications of the sector-specific Union legal act should provide the CSIRTs, the competent authorities or the single points of contact on cybersecurity (single points of contact) under this Directive with an immediate access to the incident notifications submitted in accordance with the sector-specific Union legal act. In particular, such immediate access can be ensured if incident notifications are being forwarded without undue delay to the CSIRT, the competent authority or the single point of contact under this Directive. Where appropriate, Member States should put in place an automatic and direct reporting mechanism that ensures systematic and immediate sharing of information with the CSIRTs, the competent authorities or the single points of contact concerning the handling of such incident notifications. For the purpose of simplifying reporting and of implementing the automatic and direct reporting mechanism, Member States could, in accordance with the sector-specific Union legal act, use a single entry point.

### Recital 127 — minimum enforcement powers and proportionate penalties

*Source: NIS2, nis2-rec-127-en, 2022-12-14 — https://overview.legal/posts/96782*

In order to make enforcement effective, a minimum list of enforcement powers that can be exercised for breach of the cybersecurity risk-management measures and reporting obligations provided for in this Directive should be laid down, setting up a clear and consistent framework for such enforcement across the Union. Due regard should be given to the nature, gravity and duration of the infringement of this Directive, the material or non-material damage caused, whether the infringement was intentional or negligent, actions taken to prevent or mitigate the material or non-material damage, the degree of responsibility or any relevant previous infringements, the degree of cooperation with the competent authority and any other aggravating or mitigating factor. The enforcement measures, including administrative fines, should be proportionate and their imposition should be subject to appropriate procedural safeguards in accordance with the general principles of Union law and the Charter of Fundamental Rights of the European Union (the ‘Charter’), including the right to an effective remedy and to a fair trial, the presumption of innocence and the rights of the defence.

### Recital 40 — cross border cooperation single points contact

*Source: NIS2, nis2-rec-40-en, 2022-12-14 — https://overview.legal/posts/96608*

The single points of contact should ensure effective cross-border cooperation with relevant authorities of other Member States and, where appropriate, with the Commission and ENISA. The single points of contact should therefore be tasked with forwarding notifications of significant incidents with cross-border impact to the single points of contact of other affected Member States upon the request of the CSIRT or the competent authority. At national level, the single points of contact should enable smooth cross-sectoral cooperation with other competent authorities. The single points of contact could also be the addressees of relevant information about incidents concerning financial entities from the competent authorities under Regulation (EU) 2022/2554 which they should be able to forward, as appropriate, to the CSIRTs or the competent authorities under this Directive.

## Case law

### CJEU - C‑769/22 - European Commission v Hungary

*Source: GDPRhub, 2026-07-24 — https://overview.legal/posts/158432 — original: https://gdprhub.eu/index.php?title=CJEU_-_C‑769/22_-_European_Commission_v_Hungary*

Facts — The background In 2021 Hungary adopted "Law LXXIX of 2021 adopting stricter measures against persons convicted of paedophilia and amending certain laws for the protection of children" ("the amending law"). The law introduced a number of rules to restrict the access of minors to content portraying or promoting gender identities that do not correspond to the sex assigned at birth, sex reassignment or homosexuality. The law also introduced new rules for access to public documents, requiring public bodies to allow broad access to information about individuals convicted of sexual offences against children. The alleged purpose of the law was to protect minors. In 2021 the Commission sent a formal letter to Hungary contesting the amending law's compliance with EU law. After some unproductive back-and-forth, the Commission escalated the case to the CJEU, requesting the CJEU to declare the amending law incompatible with EU law. The European Commission filed four pleas, claiming that Hungary violated of a long list of provisions from primary and secondary EU law . Only the Commission's fourth plea invokes data protection law- specifically, Article 8(2) of the EU Charter of Fundamental Rights (CFR) ("Protection of personal data") and Article 10 GDPR ("Processing of personal data relating to criminal convictions and offences"). The fourth plea: Article 10 GDPR The alleged violation of the GDPR relates to the amended law's rules on access to information about individuals convicted of sexual offences against children. The law amended the "Law on the criminal record system" and made documents about sexual offences accessible to a broad audience. Under the new rules, any adult who is either a relative or a guardian of a minor ("authorised person"), has the right to access and share information about individuals convicted of sexual offences against children (the data subjects) from bodies with access to registered data. The Commission claimed that the amended law failed to specify with sufficient clarity who is authorised to submit a data request and, therefore, did not provide sufficient guarantees for the rights and freedoms of data subjects regarding the conditions of access to their personal data. On these grounds, the Commission claimed that the amended law infringed Article 10 of the GDPR (as well as Art. 8(2) CFR). In its defense, Hungary argued that the law accurately identified "authorised persons" when read in light of the definition of "relatives" in the Hungarian civil code. Additionally, Hungary claimed that there were two additional criteria access to personal data under Hungarian law: the authorised person must consider the relevant data to be probably necessary, and it must be disproportionately difficult for them to access the subjects' data if they are not disclosed. In other words, Hungary argued that when interpreted correctly, Hungarian law provided for three cumulative criteria for the disclosure of data about convictions for sex offences against children: (i) the disclosure was requested by an authorized person (i.e. "any adult who is either a relative of, or educates, supervises or cares for, a person who has not attained 18 years of age"- where "relative" was to be understood in the well-defined sense of Hungarian civil law); (ii) the disclosure was probably necessary to keep the minor safe; (iii) it was disproportionately difficult for the authorized person to access the data otherwise. Hungary claimed that these criteria were clearly defined and provided sufficient safeguards for data subjects. On this basis, Hungary argued that the amended law complied with Article 10 GDPR and 8(2) CFR. Advocate General Opinion — AG Cápeta clarified that, according to CJEU case law, the GDPR did not impose an absolute ban on the disclosure of personal data from public authorities. The GDPR did, however, require a balancing between the purpose of such disclosures, and the rights and freedoms of data subjects. In particular, the disclosure of personal data regarding criminal convictions, required strict justification and clear legal safeguards, because of the sensitive nature of such data. In the case at hand, the AG conceded that the data disclosure pursued an important public interest (the protection of minors). So, the question was whether the amending law correctly balanced this interest against the right to data protection. The AG opined that the amending law failed to do so and exceeded what was strictly necessary to protect minors, for two reasons. First, the AG agreed with the Commission that the notion of "authorised persons" was too broad and unclearly defined under the amending law, even when the amending law was interpreted in light of domestic civil law. In this regard, the AG pointed to the CJEU case law on the access to personal data from national authorities: in order to satisfy the requirement of proportionality, national law that allowed for such access "must lay down clear and precise rules governing the scope and application of the measure in question and imposing minimum safeguards". The AG further opined that such criteria would also apply to access from private citizens, as in the case at hand. Second, the AG considered that requirements (ii) and (iii) (i.e.: the probable necessity of the disclosure, and the difficulty of otherwise accessing the data) were overly generic and were to be assessed by the authorized person themselves. The AG argued that such a self-declaratoty regime lent itself to abuse and deprived the disclosing body of any control over the necessity and proportionality of the disclosure. For this reason, the AG opined that the amending law failed to provide the required safeguards for data subjects. On these grounds, the AG opined that the amended law was disproportionate and violated Article 10 GDPR as well as Article 8(2) CFR. Holding — The court first noted that one of the objectives of the GDPR is to ensure a high level of protection of data subjects’ fundamental rights and freedoms, in accordance with Article 1 GDPR and Article 8(1) CFR. Therefore, any processing of personal data must be lawful, in accordance with Articles 5(1)(a) and 6(1) GDPR. In addition, any legal basis other than consent (Article 6(1)(a) GDPR) must be interpreted restrictively. The court then assessed whether the processing was lawful under Article 6(1)(e) and 86 GDPR. Article 6(1)(e) GDPR provides for a legal basis based on public interest or in the exercise of official authority vested in the controller. In the case of disclosing this data, Article 86 GDPR states that this may be done to reconcile public access to official documents with the right to the protection of personal data. The court stated that, in principle, the processing of data related to criminal convictions (including its disclosure) could be lawful under Article 6(1)(e) and 10 GDPR. However, Article 10 GDPR makes the processing subject to additional restrictions (for example, the processing must provide for appropriate safeguards). In addition, limits to the fundamental rights to privacy and data protection must respect the essence of the fundamental right and be proportionate, in accordance with Article 52(1) CFR. This is especially relevant in this case, as data related to criminal convictions is particularly sensitive and its processing can be a particularly serious interference with data subjects’ fundamental rights. The court followed the reasoning of the AG in stating that the protection of minors was an important public interest. However, the court considered the amending law incompatible with Article 10 GDPR. The law was not sufficiently precise, particularly in defining the concept of “authorised person”. The court considered that the processing was not limited to what is strictly necessary, as the circle of persons potentially entitled to submit a request was too broad. Finally, the court concurred with the AG, and stated that the amending law was not proportionate. This is because it relied on the person requesting the data to justify the need to access it. Therefore, the amending law did not provide for appropriate safeguards by relying on the self-declaration regarding the necessity and proportionality of accessing the data. The court concluded that the amending law did not meet the requirements under Article 10 GDPR, meaning it could not justify its processing under Article 6(1)(e) GDPR. With this, Hungary had failed to fulfil its obligations under Article 10 GDPR and Article 8(2) CFR.

### Judgment of the Court (First Chamber) of 3 April 2025.#L. H. v Ministerstvo zdravotnictví.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 4 – Definitions – Article 6 – Lawfulness of processing – Article 86 – Public access to official documents – Data concerning the representative of a legal person – Case-law of a national court imposing an obligation to inform and consult the data subject prio

*Source: Court of Justice of the European Union, C-710/23, 2025-04-03 — https://overview.legal/posts/132145 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0710*

In Case C-710/23, the Court of Justice of the European Union (First Chamber) addressed a preliminary reference from the Czech Supreme Administrative Court concerning whether personal data of individuals acting as representatives of legal persons, contained in official documents related to COVID-19 screening test contracts, may be disclosed under GDPR Article 86 and the lawfulness of processing under Article 6. The case arose from a dispute between L.H. and the Czech Minister of Health, who had refused to disclose certain information about representatives of legal persons named in those contracts and related certificates. The Court held that data concerning a representative of a legal person constitutes personal data within the meaning of the GDPR when it allows the natural person to be identified, and that Member States may provide for public access to official documents containing such personal data, provided that the disclosure is reconciled with the right to data protection; however, a national court cannot impose a general obligation to inform and consult the data subject prior to every disclosure of official documents, as this would undermine the public's right of access to official documents.

### Judgment of the Court (Sixth Chamber) of 7 March 2024.#Endemol Shine Finland Oy.#Request for a preliminary ruling from the Itä-Suomen hovioikeus.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Articles 2, 4, 6, 10 and 86 – Data held by a court relating to the criminal convictions of a natural person – Oral disclosure of such data to a commercial company on account of a competition organised by that company – Concept of ‘processing of personal data’

*Source: Court of Justice of the European Union, C-740/22, 2024-03-07 — https://overview.legal/posts/132269 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0740*

In Case C-740/22, the Court of Justice of the European Union (Sixth Chamber) ruled on a preliminary reference from the Itä-Suomen hovioikeus (Court of Appeal, Eastern Finland) concerning whether the oral disclosure by a court of data relating to a natural person's criminal convictions to Endemol Shine Finland Oy, a commercial company organizing a competition, constitutes "processing of personal data" under the GDPR. The Court held that such oral disclosure falls within the scope of GDPR Article 2(1), as the concept of processing is not limited by the means or format of transmission, and that national legislation governing public access to official documents must reconcile the right of access with the GDPR's data protection requirements, particularly given the sensitive nature of criminal conviction data under Article 10. No fine was imposed, as the ruling solely addressed the interpretation of EU law.

### USR - Us I-755/2025-8

*Source: Administrative Court in Rijeka, 2025-11-11 — https://overview.legal/posts/49225 — original: https://gdprhub.eu/index.php?title=USR_-_Us_I-755/2025-8*

Facts — The data subject was a member of the management board of Zagrebački holding, a company owned by the City of Zagreb, from 3 September 2021 until 31 March 2023. A television broadcaster published several pieces, including a video on its YouTube channel, reporting on the data subject’s resignation. The publications mentioned his name, role, employer, salary, and information on the brand of his private car. The data subject filed a complaint with the Croatian Personal Data Protection Agency (AZOP), claiming that the publication constituted unlawful processing under the GDPR because the media lacked a valid legal basis under Article 6, the reporting was inaccurate and excessive, and it did not serve any genuine public interest. He latter further claimed during the lawsuit against AZOP's decision that the authority had incorrectly and incompletely established the facts, misapplied substantive law, and breached procedural rules. He emphasized that the published personal data was unrelated to transparency in public administration, that he was neither a public figure nor a political actor, and that any public interest ended once he left office on 31 March 2023. He invoked his right to erasure under Article 17 GDPR and sought removal of the content, annulment of AZOP’s decision, or alternatively, a remittal for a new procedure. AZOP contested the lawsuit in full, maintaining that it had acted in accordance with Article 34 of the Croatian GDPR Implementation Act and Article 77 GDPR. It argued that the publication fell within a justified public interest under Article 8 of the Croatian Media Act and that it had properly carried out a balancing test between privacy (Article 8 ECHR) and freedom of expression (Article 10 ECHR). According to AZOP, the reporting was necessary, proportionate, and not sensationalistic, and did not excessively intrude on the data subject’s privacy. It added that consent was not required because the processing relied on legitimate interest under Article 6(1)(f) GDPR. Holding — The Administrative Court dismissed the action and upheld AZOP’s decision. Because Zagrebački holding is a city-owned and publicly funded company, the court considered information about the data subject’s salary, compensation for using his private vehicle in official duties, and his managerial role to be directly connected to the use of public resources. This placed the publication within the legitimate public interest in transparency recognised by Article 8 of the Media Act. In its proportionality assessment, the court accepted AZOP's application of Article 5 and 6 GDPR, emphasizing that the published data did not touch upon the data subject’s family or intimate life but related solely to his public functions. Publication was therefore limited to what was necessary to inform the public about the management of a publicly owned company. The data subject’s claims that the publication was false or harmful to his reputation did not alter the outcome, as AZOP is not empowered to determine the truthfulness or tone of journalistic content, particularly under the journalistic exemption in Article 85 GDPR. Issues of accuracy or reputational harm must instead be pursued through media-law mechanisms such as requests for correction or civil actions. On the erasure request, the court held that the right to be forgotten under Article 17 GDPR cannot override freedom of expression and information where media reporting is involved. Although the data subject no longer served on the board, the publication continued to contribute to public understanding of how a major public entity was run during his tenure, thus the public interest persisted and erasure was not justified. Finally, the court reiterated that consent was not required because Article 6 GDPR offers alternative lawful bases for processing. Since Article 6(1)(f) was satisfied, the absence of consent was irrelevant. Concluding that AZOP had properly applied the law and that the interference with the data subject’s privacy was proportionate, the court upheld the decision and denied the data subject’s claim and costs.

### CE - 449212

*Source: CE, 2021-03-04 — https://overview.legal/posts/125660 — original: https://gdprhub.eu/index.php?title=CE_-_449212*

Facts — On December, 7 2020, the French DPA imposed a financial penalty of 60 Million euros fine against Google LLC and a 40 million euros against Google Ireland Limited in accordance with the General Data Protection Regulation (GDPR) and ePrivacy Directive 2002/58/EC, for lack of transparency, inadequate information and lack of valid consent regarding for violating the regulation on cookies while operating the website google.fr. The sanction was accompanied by an order to comply with article 82 of the French Law on data protection (Law Informatique et Libertés), under three months on penalty of a €100,000 fine per day of delay. The companies appealed to the Conseil d’État in interim procedure against the CNIL's decision, arguing that the French DPA was not the competent authority because it was not the lead supervisory authority for Google LLC or Google Ireland Limited. Dispute — Is the CNIL territorially competent to investigate and sanction a company for violating the information principle when depositing cookies if it is not the lead supervisory authority of the company? The CNIL considered that Google does have EU headquarters in Ireland, but that this Irish entity ‘did not have a decision making power’ in relation to the relevant cross-border data processing activities to which the complaints related. For that reason the CNIL decided that the One Stop Shop mechanism did not apply and that the CNIL, like any other European supervisory authority, was therefore competent to make a decision. Holding — The Conseil d’État rejected the request made by Google and ruled that the French DPA was territorially competent on this matter even though it is not the lead supervisory authority. The court stated that Article 82 of the Law Informatique et Libertés was a transposition of Article 5(3) ePrivacy Directive 2002/58/EC into French Law when dealing with cookies and that the CNIL is charged with enforcing this Directive. As such, the one-stop shop mechanism provided for in Article 56 GDPR does not apply in the present case.

### CJEU - C-614/10 - Commission v. Austria

*Source: GDPRhub, 2012-10-16 — https://overview.legal/posts/125643 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-614/10_-_Commission_v._Austria*

Facts — On 5 July 2005 the European Commission sent a letter of formal notice to the Republic of Austria in which it claimed that the organisation of the Austrian Data Protection Commission (Datenschutzkommission – DSK) failed to satisfy the criterion of independence set out in the second subparagraph of Article 28(1) Directive 95/46/EC. The Commission did not consider the observations of the Republic of Austria satisfactory and, therefore, issued a reasoned opinion pursuant to Article 258(1) TFEU. On 9 December 2009, the European Commission brought the matter in front of the Court of Justice of the European Union. The Commission and the EDPS noted that, according to the then-current national law, the managing member of DSK needed to be a member of the Federal Chancellery (Bundeskanzleramt). More in general, they pointed out that the office of DSK was structurally integrated with the departments of the Chancellery. They argued that this was contrary to the criterion of independence set out in the second subparagraph of Article 28(1) Directive 95/46/EC, as staff members were subject to the supervision of the Chancellery. The Republic of Austria argued that the requirement of set by the second subparagraph of Article 28(1) Directive 95/46/EC relates to “functional independence” and that the DSK had such independence, since § 37(1) of the then-in force Austrian Data Protection Code (Datenschutzgesetz - DSG 2000) provided for its members to be independent and not to be bound by instructions given by the government. It pointed out that the managing member did not necessarily need to be a member of the Chancellery and could be chosen among lawyers working in the federal public administration. Holding — Firstly, the court noted that Article 8(3) CFR, Article 16(2) TFEU and Article 28(1) Directive 95/46/EC require Member States to have a supervisory authority which have complete independence. The court found that the independence of the supervisory authority is an essential component of the protection of individuals with regard to the processing of personal data. Secondly, the court set aside the argument of the Republic of Austria that the DSK has a sufficient degree of independence since it satisfied the condition of independence inherent in Article 267 TFEU for it to qualify as a court or tribunal of a Member State. The court held that the notion of “complete independence” under data protection law is autonomous and independent from the one under Article 267 TFEU. Thirdly, the court gave its interpretation of the concept of “complete independence” set by Article 28(1) Directive 95/46/EC. To do that, the court referred to its previous judgement C-518/07, Commission v. Germany. In this judgement, it had held that this concept should be interpreted as meaning that the supervisory authorities must enjoy an independence which allows them to perform their duties free from any external influence, direct or indirect, which is liable to have an effect on their decisions. Applying this principle to the case at hand, the court found that the requisite of functional independence, like the one accorded to the DSK, is a condition which is essential to have a “complete independence”. However, this condition by itself is not sufficient to protect that supervisory authority from all external influence. On the contrary, according to the court, some pieces of Austrian legislation did not allow the DSK to be completely free from any indirect influence. For example, according to § 36(3) and § 38(1) DSG 2000 the managing member of the DSK is a federal official. Moreover, § 45(1) of the 1979 Law on the conditions of service of officials (Beamten-Dienstrechtsgesetz 1979 - BDG 1979) grants the hierarchical superior an extensive power of supervision over their officials and to encourage the promotion of their staff. Furthermore, the court held that the fact that the staff of the DSK was composed by federal officials was not compliant with the independence requirement, given that these officials are subject to supervision by the Federal Chancellery within the terms of § 45(1) BDG 1979. Finally, the court noted that the Federal Chancellor has the right to be informed at all times by the chairman and the managing member of all aspects of the work of the DSK, according to Article 20(2) of the Federal Constitutional Law (Bundes Verfassungsgesetz – BVG) and § 38(2) DSG 2000. On this matter, the court ruled that such a right to information is also liable to subject the DSK to indirect influence, given that it is far-reaching as it covers “all aspects of the work of the DSK” and that it is unconditional. On these grounds, the CJEU held that, by failing to take all of the measures necessary to ensure that the legislation in force in Austria meets the requirement of independence, the Republic of Austria has failed to fulfil its obligations under Article 28(1) Directive 95/46/EC.

### CJEU - Case C 312/24 - Darashev

*Source: GDPRhub, 2025-09-04 — https://overview.legal/posts/158443 — original: https://gdprhub.eu/index.php?title=CJEU_-_Case_C_312/24_-_Darashev*

Facts — The data subject is a police officer, holding various positions at the Internal Security directorate-general of the Bulgarian Ministry of the Interior (controller). In March 2016, investigative proceedings were commenced concerning an unknown offender in connection with an offence of theft. A few days later, the data subject was arrested and after being detained in police custody for 24 hours, he was released. Subsequently, he was neither placed under formal investigation nor charged, but he was the subject of several investigative measures, which in the course of 2016, were suspended without the offender having been identified. The controller stored the data about the criminal investigation on his personnel file, as provided by the ministerial instruction relating to personnel files, issued as a regulatory act pursuant to the statutory authorisation provided for in the Law on the Ministry of the Interior (ZMVR). The data subject continued his duties as a police officer and took part in selection procedures for promotion to other posts within the Ministry but he was rejected. The data subject brought an action before the Sofia District Court (Sofiyski rayonen sad) seeking compensation for non-material damage for the fact that he has not been promoted or transferred to other duties on account of his having been a suspect in the investigation. In addition, he asked that his name be erased from the database kept by the controller, in which he is mentioned as a suspect. In this context the court decided to stay the proceedings and to refer some questions to the CJEU for a preliminary ruling, regarding the interplay of the GDPR with the Law Enforcement Directive (LED), and more specifically regarding the storage of data concerning the official in his personnel file. The questions were combined and reformulated by the AG as follows: whether Article 2(1) GDPR and Article 9(1) LED are to be interpreted as meaning that the GDPR applies to the storing, by a public authority in the personnel file of one of its officials, of data regarding that official’s status as a suspect in a criminal investigation, where the data have been collected by an organisational unit within that public authority in the performance of its duties as a competent authority within the meaning of LED. whether Article 17(3) GDPR, read in conjunction with Article 6(1)(c) and Article 6(3) thereof, is to be interpreted as meaning that the storage, in a police officer’s personnel file, of personal data relating to a criminal investigation in which that officer was the subject of investigative measures, as a suspect, and which was discontinued, may be considered lawful for the purposes of compliance with a legal obligation to which the public authority that is his employer is subject under national law, as controller, merely on account of the nature of the duties which that officer is required to perform. Holding — Regarding the first question about the scope of the GDPR, the AG responded positively, that the GDPR does apply in this case, provided that the storage of that data pursues purposes other than those set out in Article 1(1) LED, purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties. Regarding the second question, the AG responded negatively, that the storage of the data subject’s data in this case was not lawful. First, he clarified that within the meaning of Article 6(3) GDPR, the storage of personal data could be based on a legal obligation being defined in a national law other that a law stricto sensu, though in accordance with national constitutional law. Therefore, in this case, the ministerial instruction was considered an appropriate legal basis. Nevertheless, the AG expressed doubts as to the foreseeability of the purposes of the processing, which, in accordance with Article 6(3) GDPR must be determined by the legal basis of the processing. As laid down in the ministerial instruction, the purpose of the storage was for reasons of ‘change of duties’. The AG considered that this, did not appear to meet an objective of public interest, for the purposes of Article 6(3) GDPR. Furthermore, he failed to see how the nature of the duties of maintaining public order, which fall to the data subject, could justify the storage of the data at issue in his personnel file. In conclusion, the AG opined that the storage of the data at issue was not lawful and that the data subject had the right to have them erased, pursuant to Article 17(1)(d) GDPR.

### Judgment of the General Court (Tenth Chamber, Extended Composition) of 29 January 2025 (Extracts).#Data Protection Commission v European Data Protection Board.#Protection of personal data – Article 65(1)(a) of Regulation (EU) 2016/679 – Binding decision instructing a lead supervisory authority to broaden the scope of its investigation and issue a new draft decision – Competence of the European Data Protection Board.#Joined Cases T-70/23, T-84/23 and T-111/23.

*Source: General Court, T-70/23, 2025-01-29 — https://overview.legal/posts/132152 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023TJ0070*

The Irish Data Protection Commission (DPC) challenged provisions of EDPB Binding Decisions 3/2022, 4/2022, and 5/2022, arguing the EDPB exceeded its competence under Article 65(1)(a) GDPR by requiring the DPC to broaden its investigation into Facebook, Instagram, and WhatsApp and issue new draft decisions. The core legal issue was whether the EDPB, in the consistency mechanism context, can compel a lead supervisory authority to conduct additional investigations and produce new draft decisions beyond addressing the specific relevant and reasoned objections raised by concerned supervisory authorities. The General Court dismissed the DPC's actions, upholding the EDPB's authority to issue binding decisions instructing the lead supervisory authority to carry out further investigation and issue new draft decisions.

### CE - 449209

*Source: CE, 2022-01-28 — https://overview.legal/posts/122847 — original: https://gdprhub.eu/index.php?title=CE_-_449209*

Facts — On 7 December 2020, the French DPA (CNIL) imposed two fines totaling € 100 million on Google LLC and Google Ireland Ltd for violating Article 82 of the French Data Protection Act (which transposes the ePrivacy Directive). Google (1) had not obtained the user’s consent before depositing advertising cookies in the user’s terminal equipment, (2) had lacked to provide information, and (3) had not implemented a mechanism to refuse the cookies. Google did not agree with the CNIL’s decision and brought the issue before court. First, it claimed that, since there is cross-border processing, the Irish DPA (DPC) is the lead supervisory authority since Google’s main establishment in the EU is in Ireland, and the CNIL therefore did not have competence to rule on this matter according to the one-stop-shop mechanism. Second, it found the fine to be disproportionate. Hence, it requested the Council of State to annul the decision, and to refer two preliminary questions to the CJEU, asking: (1) whether the one-stop-shop mechanism provided for in Article 56 GDPR is excluded in the context of cross-border processing that falls within the scope of both the ePrivacy Directive and the GDPR, and (2) whether Article 15a ePrivacy Directive violates the right to data protection because does not provide an obligation, but rather an option, “for the competent national regulatory authorities to adopt measures to ensure effective cross-border cooperation in the enforcement of national laws adopted pursuant to the directive and to create harmonised conditions for the provision of services involving cross-border data flows”. Holding — The Council of State rejected Google’s appeal. First, according to the Council, the ePrivacy Directive, implemented in the French Data Protection Act, does not provide for the application of the one-stop-shop mechanism as mentioned in Article 56 GDPR. Although the requirements for consent are regulated by the GDPR the deposit of cookies is regulated by the ePrivacy Directive. Hence, even if cross-border processing takes place, the CNIL is competent to monitor compliance with the objectives of such Directive. The Council then notes that “it follows that, as regards the control of the operations of access and recording of information in the terminals of users in France of an electronic communications service, even if they are the result of cross-border processing, the measures to monitor the application of the provisions transposing the objectives of Directive 2002/58/EC fall within the competence conferred on the CNIL by the Law of 6 January 1978.” The Council stipulated that there is no need to refer preliminary questions to the CJEU, because it had no doubt as to whether the one-stop-shop mechanism should be excluded in the context of cookies. Second, the Council rejected Google’s argument that their right of defense had been infringed by the CNIL because they did not provide a prior formal notice, since it is not required to provide such a formal notice before imposing a sanction. Third, on the substance of the matter, the Council confirmed the three violations of Article 82 of the Data Protection Act: (1) not obtaining the user’s consent before depositing advertising cookies in the user’s terminal equipment, (2) not providing clear information on the deposit of cookies, and (3) not implementing a mechanism to refuse the cookies. Lastly, the Council stated that the fines were not disproportionate in light of the financial capacities of the “two” companies. It considered Google’s market share of more than 90% with (an estimated) 47 million users in France and the large profits that follow from the targeted online advertisement. Moreover, it stated that Google did not genuinely cooperated with the CNIL since it did not provide advertising revenues, and the breaches were serious.

### WELTIMMO S.R.O. V. NEMZETI A DATVEDELMI ES INFORMACIOSZABADSAGH ATOSAG (HUNGARIAN DPA), 1.10.15 (“WELTIMMO”)

*Source: CJEU, 2015-10-01 — https://overview.legal/posts/5956 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0230*

Data protection authorities powers and cooperation: In the event that the Hungarian DPA should consider that Weltimmo has an establishment not in Hungary, but in another Member State, it may exercise its powers only within its own territory, and it may, irrespective of the applicable law and before even knowing which national law is applicable, thereby investigate the complaint. If it becomes apparent that it is the law of another Member State that applies, that DPA cannot impose penalties outsi

### Judgment of the Court (Grand Chamber), 16 October 2012.#European Commission v Republic of Austria.#Failure of a Member State to fulfil obligations – Directive 95/46/EC – Processing of personal data and free movement of such data – Protection of natural persons – Article 28(1) – National supervisory authority – Independence – Supervisory authority and the Federal Chancellery – Personal and organisational links.#Case C‑614/10.

*Source: Court of Justice of the European Union, C-614/10, 2012-10-16 — https://overview.legal/posts/132377 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62010CJ0614*

The European Commission brought an infringement action against the Republic of Austria under Article 258 TFEU, alleging that Austria failed to ensure the independence of its Data Protection Commission (DSK) as required by the second subparagraph of Article 28(1) of Directive 95/46/EC. The Commission challenged the personal and organisational links between the DSK and the Federal Chancellery, including the Federal Chancellor's authority to establish the DSK's office, provide staff, and be informed of all aspects of the DSK's work. The Court ruled that Austria had failed to fulfil its obligations under the Directive by not guaranteeing the DSK's complete independence in exercising its functions.

### VG Düsseldorf - 29 K 3490/24

*Source: Administrative Court Düsseldorf, 2026-06-22 — https://overview.legal/posts/108992 — original: https://gdprhub.eu/index.php?title=VG_Düsseldorf_-_29_K_3490/24*

Facts — A district (the controller), acting as the lower water authority, initiated administrative proceedings after identifying unauthorised riverbank works and a private jetty on two riverside properties. One property belonged to a water utility company, while the other belonged to a municipality and was leased to the data subjects. During those proceedings, the controller shared the data subjects' personal data with various participants, including the owners of the affected properties, other public authorities and a lawyer who claimed to represent the data subjects. The data subjects lodged a complaint with the competent supervisory authority (LDI NRW), alleging that the controller had unlawfully processed and disclosed their personal data. They argued that their personal data had been shared with uninvolved third parties, that the controller had communicated with a lawyer whom they had not authorised, recorded a telephone conversation with an unknown person, and transmitted personal data by unencrypted email. The controller's data protection officer addressed each allegation and provided additional factual information concerning the disputed processing operations. The DPA initially informed the data subjects that no GDPR infringement was apparent, invited them to provide any additional factual information, and explained that it would obtain extracts from the controller's administrative file if there were concrete indications that it contained relevant facts not already available. The data subjects did not identify any additional facts and instead reiterated their legal position that the controller had breached its GDPR accountability obligations. The DPA rejected the complaint, concluding that no GDPR infringement could be established. The data subjects then brought an action before the Verwaltungsgericht Düsseldorf (Administrative Court Düsseldorf), seeking a fresh decision on their complaint on the basis that the DPA had failed to adequately investigate the complaint because it had not obtained the controller's administrative file before reaching its decision. Holding — The court held that Articles 57(1)(f) and 77(1) GDPR give rise to an enforceable right requiring a supervisory authority to investigate a complaint to the extent appropriate in the circumstances before determining whether a GDPR infringement has occurred. Recital 141 GDPR requires the investigation to extend as far as is appropriate in light of the circumstances of the individual case, including the significance of the complaint and the seriousness of the alleged infringement. Applying these principles, the court held that the DPA had adequately investigated the complaint. It had considered each allegation together with the detailed response provided by the controller's data protection officer, invited the data subjects to provide any additional factual information, and explained that it would obtain extracts from the administrative file if concrete indications emerged that further relevant facts required clarification. As the data subjects did not provide any additional facts and there were no objective indications that the information already available was inaccurate or incomplete, the court held that the DPA was not required to obtain the controller's administrative file or undertake further investigations in the absence of concrete indications that additional factual clarification was necessary. The court further held that the DPA had correctly concluded that no GDPR infringement had occurred. The court held that the disputed processing was lawful under Article 6(1)(e) GDPR, read together with Article 6(3) GDPR and § 88 of the German Water Resources Act (WHG), which provided the legal basis for the processing. The court also held that the transmission of personal data by email did not infringe Article 5(1)(f) GDPR because, in the circumstances of the case, transport encryption provided an appropriate level of security.

## Guidance

### Guidelines 2/2020 on articles 46 (2) (a) and 46 (3) (b) of Regulation 2016/679 for transfers of personal data between EEA and non-EEA public authorities and bodies

*Source: EDPB, guidelines-22020-on-articles-46-2-a-and-46-3-b-of-regulation-2016679-for-en, 2020-12-15 — https://overview.legal/posts/126098 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-22020-on-articles-46-2-a-and-46-3-b-of-regulation-2016679-for_en*

Adopted 1 Guidelines 2/2020 on a rticles 46 (2) (a) and 46 (3) (b) of Regulation 2016/679 for transfers of personal data between EEA and non - EEA public authorities and bodies Version 2 .0 Adopted on 1 5 December 2020 Adopted 2 Version history Version 2.0 15 December 2020 Adoption of the Guidelines after public consultation Version 1.0 18 February 2020 Adoption of the Guidelines for public consulation Adopted 3 Adopted 4 The European Data Protection Board Having regard to Article 70 (1e) of…

### Coordinated Enforcement Action, implementation of the right of access by controllers

*Source: EDPB, edpb-cef-report-2024-20250116-rightofaccess-en, 2025-01-20 — https://overview.legal/posts/50412 — original: https://www.edpb.europa.eu/documents/coordinated-enforcement-framework/coordinated-enforcement-action-implementation-of-the_en*

EDPB 20 jan 2025, Coordinated Enforcement Action, implementation of the right of access by controllers.

### EDPB-EDPS Joint Opinion 01/2023 on the Proposal for a Regulation of the European Parliament and of the Council laying down additional procedural rules relating to the enforcement of Regulation (EU) 2016/679

*Source: EDPB, edpb-edps-joint-opinion-012023-on-the-proposal-for-a-regulation-of-en, 2023-09-19 — https://overview.legal/posts/125829 — original: https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-012023-on-the-proposal-for-a-regulation-of_en*

EDPB - EDPS Jo in t O p in i o n 0 1 / 2 0 2 3 on t h e P roposa l f o r a Regu l a t i o n o f t h e E u rop ean Pa r l i amen t a nd o f t h e Counc i l l a y i n g d own add i t i o n a l p ro cedu r a l r u l e s r e l a t i n g t o t h e e n fo r c emen t o f Regu l a t i o n ( EU ) 2 0 1 6 / 6 7 9 Adop t ed o n 1 9 S ep t embe r 202 3 Adopted 2 Article 22 ................................ ................................ ................................ ................................…

### Overview on resources made available by Member States to the Data Protection Authorities and on enforcement actions by the Data Protection Authorities

*Source: EDPB, overview-on-resources-made-available-by-member-states-to-en, 2021-08-11 — https://overview.legal/posts/125988 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/overview-on-resources-made-available-by-member-states-to_en*

1 Overview on resources made available by Member States to the Data Protection Authorities and on enforcement actions by the Data Protection Authorities 05 August 2021 2 Table of co n tent Background ................................ ................................ ................................ ................................ ......... 3 Introduction ................................ ................................ ................................ ................................ ........ 3…

### Opinion 8/2019 on the competence of a supervisory authority in case of a change in circumstances relating to the main or single establishment

*Source: EDPB, opinion-82019-on-the-competence-of-a-supervisory-authority-in-en, 2019-07-12 — https://overview.legal/posts/126208 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-82019-on-the-competence-of-a-supervisory-authority-in_en*

Adopted 1 Opinion 8 /2019 on the competence of a supervisory authority in case of a change in circumstances relating to the main or single establishment Adopted on 9 July 2019 Adopted 2 Table of c ontents 1 SUMMARY OF THE FACTS ................................ ................................ ................................ ................ 3 2 ON THE COMPETENCE OF THE BOARD TO ADOPT AN OPINION UNDER ARTICLE 64.2 ON THIS TOPIC ................................ ................................…

### Opinion 4/2019 on the draft AA between EEA and non-EEA Financial Supervisory Authorities

*Source: EDPB, opinion-42019-on-the-draft-aa-between-eea-and-non-eea-en, 2019-02-12 — https://overview.legal/posts/126248 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-42019-on-the-draft-aa-between-eea-and-non-eea_en*

adopted 1 Opinion 4 / 2019 on the draft Administrative Arrangement for the transfer of personal data between European Economic Area (“EEA”) Financial Supervisory Authorities and non - EEA Financial Supervisory Authorities Adopted on 12 February 2019 adopted 2 4 Final remarks ................................ ................................ ................................ ................................ ... 8 adopted 3 The European Data Protection Board Having regard to Article 63, Article 64…

### Draft administrative arrangement following EDPB opinion 04/2019 for the transfer of personal data between each of the European Economic Area (“EEA”) Authorities set out in Appendix A and each of the non-EEA Authorities set out in Appendix B

*Source: EDPB, draft-administrative-arrangement-following-edpb-opinion-en, 2019-01-07 — https://overview.legal/posts/126258 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/draft-administrative-arrangement-following-edpb-opinion_en*

Draft January 7 , 201 9 Draft administrative a rrangement for the transfer of personal data between Each of t he European Economic Area (“ E EA ”) Authorities set out in Appendix A and Each of t he non - E EA Authorities set out in Appendix B each a n “ Authority ”, together the “ Authorities ” , acting in good faith, will apply the safeguards specified in th is administrative arrangement (“Arrangement”) to the transfer of personal data between them , recognizing the importance of the…

### Template for Cross-Regulatory Cooperation Agreements

*Source: EDPB, template-for-cross-regulatory-cooperation-agreements-en, 2026-07-07 — https://overview.legal/posts/125669 — original: https://www.edpb.europa.eu/documents/other-guidance/template-for-cross-regulatory-cooperation-agreements_en*

1 | Adopted Template for Cross-Regulatory Cooperation Agreements Adopted by the EDPB on July 7 th 2026 2 | Adopted Explanatory note Cross-regulatory cooperation between data protection supervisory authorities (DPAs) and other national and EU competent authorities has become increasingly important as legal and practical challenges emerge at the intersection of different regulatory fields. Cooperation agreements can be an important basis to organise and strengthen cooperation and dialogue between…

## Enforcement decisions

### Privacy Appeals Board: Datatilsynet may demand information from OpenX under GDPR Art.

*Source: Datatilsynet (Norway), 2020-09-07 — https://overview.legal/posts/122844 — original: https://gdprhub.eu/index.php?title=Datatilsynet_(Norway)-_20/02254*

Facts — The Norwegian Consumer Council (Forbrukerrådet) filed three complaints against the gay/bi dating app Grindr and five adtech companies that received personal data through the app. Subsequently, Datatilsynet sent a request for more information from one of the adtech companies; OpenX. OpenX refused to respond on the basis that Datatilsynet does not have legal grounds to impose such a request on them, because, in their opinion, the issue relates to the Electronic Communications Act § 2(7)(b) (cf. Article 5(3) ePrivacy Directive 2002/58/EC), where the Norwegian Communications Authority is the right supervisory authority (and not Datatilsynet), and filed a complaint to the Privacy Appeals Board. Dispute — Does the Datatilsynet have the legal grounds (as a supervisory authority) to impose a request for information on OpenX? Holding — The Privacy Appeals Board rejected OpenX's complaint as they concluded that Datatilsynet has legal grounds to impose such requests for information as per Article 58(1) GDPR.

### HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens

*Source: HDPA (Greece), 2026-05-13 — https://overview.legal/posts/144044 — original: https://gdprhub.eu/index.php?title=HDPA_(Greece)_-_12/2026*

Facts — The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of Undesirable Aliens. In response to the Authority's request for clarifications, the competent Directorate of the Ministry of Citizen Protection informed the DPA that: • By a decision dated 27-07-2017, an entry ban and registration in the National Registry of Undesirable Aliens were imposed on the complainant for reasons of national security. • Following temporary 48-hour lifts of the measure for humanitarian reasons in 2019, the entry ban was re-imposed. • Subsequent decisions in 2020, 2023, and 2025 maintained the entry ban and renewed his registration in the National Registry of Undesirable Aliens for successive three-year periods, as the grounds for registration remained active. • The explicit grounds and documentation behind the registration were not disclosed to the complainant because the competent Directorate classified the file as restricted/classified service material. The complainant and his attorney attended a DPA hearing on 22-04-2026, arguing that the registration lacked specific, adequate, or definitive justification regarding any threat to public order or national security. They noted that the complainant has no criminal convictions, poses no threat, and possesses strong ties, residency, and business operations in the region of Northern Epirus and Greece, meaning the entry ban severely disrupts his professional and family life. Holding — According to the provisions of Article 82(1) of Law 3386/2005, foreign nationals whose presence in Greek territory constitutes a threat to national security, public safety, or public order can be registered in the National Registry of Undesirable Aliens, with registrations subject to an ex officio review every three years. Furthermore, pursuant to the provisions of Article 54(2) and Article 55(4) of Law 4624/2019 (the Greek law implementing the GDPR), the data controller is legally empowered to restrict or omit the provision of information and to deny a data subject access to their personal data when dictated by reasons of national security or public order. These national provisions are explicitly anchored in Article 23 GDPR (specifically Article 23(1)(a)GDPR and Article 23(1)(c) GDPR), which permits Member State law to restrict the scope of the obligations and data subject rights (such as the right to be informed under Article 13 GDPR - Article 14 GDPR and the right of access under Article 15 GDPR) to safeguard national security and public security. In the present case, the evidence demonstrated that the complainant's initial registration and subsequent renewals in the National Registry of Undesirable Aliens were executed lawfully for reasons of national security. The Ministry of Citizen Protection, acting as the data controller, exercised its legal discretion under these frameworks to weigh these interests and correctly determined that the underlying operational decision constitutes classified material that cannot be disclosed to the data subject. Consequently, the fundamental principles of data protection law were not breached, and the Hellenic DPA rejected the complaint as unfounded.

### CNPD (Portugal) - Deliberação 2019/494

*Source: CNPD (Portugal), 2019-09-03 — https://overview.legal/posts/122872 — original: https://gdprhub.eu/index.php?title=CNPD_(Portugal)_-_Deliberação_2019/494*

Facts — In its Opinion 20/2018 concerning the draft of Law 58/2019 which ensures the implementation of the GDPR in the portuguese national legal framework, the DPA drew the attention of the national legislator to a set of provisions that could potentially violate EU law, particularly the GDPR. The DPA emphasized the primacy of EU law as outlined in the EU treaties, particularly reflecting on Article 288 of the Treaty on the Functioning of the European Union (TFEU) and reinforced by the jurisprudence of the CJEU, which has consistently stated that national laws cannot obstruct the direct applicability of EU regulations and must comply with EU law to ensure uniform implementation across the Member States. However, Law 58/2019 came into force without incorporating all of the DPA's recommendations. The DPA explains that the decision to not apply some of its provisions aims to ensure legal certainty, reinforcing the importance of consistent GDPR application without being hindered by conflicting national rules. Holding — The DPA has decided to disapply the following provisions of Law 58/2019, in cases of personal data processing under its review due to their conflict with the GDPR: Article 2(1)(2): This article broadens the territorial scope of the GDPR to encompass all personal data processing within national territory and processing linked to national establishments outside the territory. The DPA believes this contradicts Article 3 and Article 56 of the GDPR, which outlines the applicable law in cross-border situations. Additionally, it undermines the one-stop-shop mechanism and fails to address instances where the GDPR applies, such as in Portuguese embassies, consulates, ships, and aircraft. Article 20(1): This article states that the right to be informed and the right of access cannot be exercised when a duty of secrecy is imposed on the data controller/processor. In the view of the DPA, this article lacks legal relevance in relation to the GDPR, as it merely repeats provisions already present in the GDPR, particularly concerning the possibility of restricting the data subject's right to information in cases where data collection is indirect and a legal duty of confidentiality exists. Regarding the possibility of restricting the right to information when collecting data directly from the data subject, this right can only be restricted under the provisions of Article 23 GDPR, and Law58/2019 does not meet the requirements therein, thus contradicting the norms of the GDPR and the Charter of Fundamental Rights. Article 23: This article allows public authorities to reuse personal data for any public interest without ensuring compliance with principles of purpose limitation and data minimization (Article 5 GDPR) and could lead to potential misuse of personal data and a violation of individuals’ rights, as it does not ensure that the reuse of data serves the original purpose for which it was collected nor respecting the requirements imposed in Article 23 GDPR. Article 28(3)(a): The employee's consent cannot be the legal basis if the processing results in a legal or economic advantage for the employee. The Portuguese DPA considers it to be a contraction of the doctrine established by European institutions, which accepts employee consent in situations where the act of giving or refusing consent does not, in itself, have negative consequences for the employee. The DPA therefore believes that this provision does not protect the dignity, fundamental rights, and legitimate interests of employees, and thus fails to meet the requirements set forth in Article 9 (2) (b) and Article 88 GDPR. Regime of Administrative Offenses – Articles 37, 38, and 39: The DPA notes that some of the violations outlined in the law contradict the exhaustive list provided in the GDPR (Article 83). The DPA also criticizes the distinction in sanctioning frameworks based on the size of companies and the collective or individual nature of the entities conducting data processing, as the impact on personal data does not depend on those characteristics but rather on the nature of the activity being carried out. Article 61(2) states that "if the expiration of consent is the reason for terminating a contract in which the data subject is a party, the processing of data is lawful until this occurs." The DPA notes that this provision is incongruent, conflating two types of legal basis: consent and contract execution. The contract in which the data subject is a party is sufficient to justify the processing of the data necessary for its execution. Regarding the reasons that led to publish this decision, the Portuguese DPA clarifies that it did so in order to ensure the transparency of its future decision-making processes and, in this regard, contribute to legal certainty and security. It also clarifies that the non-application, in future specific cases, of the legal provisions listed above results in the direct application of the GDPR provisions that were manifestly restricted, contradicted, or compromised in their useful effect.

### Italian DPA: AgID's automatic transfer of PEC addresses to INAD index unlawful

*Source: Garante per la protezione dei dati personali (Italy), 2026-05-28 — https://overview.legal/posts/122875 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_419/2026*

Facts — The data controller for the case is a government body called the Agency for Digital Italy (AgID). AgID is tasked with driving the adoption of digital technologies in both government and the private sector. Additionally, AgID is Italy’s soon-to-be notification authority for the AI Act. The case revolves around two public online indexes of certified email addresses: the INI-PEC and the INAD. INI-PEC is the older of the two indexes and includes, among others, the email addressess of professionals (the data subjects). INAD was created by AgID in 2023 as provided by Italian law and functions as an index of “digital domiciles” (where data subjects are supposed to get certain important communications) for both professionals and other owners of a digital email address. Shortly after setting up the INAD index, AgID automatically included the addresses of professionals from the old INI-PEC index. As a result, the addresses automatically became the digital domicile for communications not related to the professional lives of the data subjects. Data subjects were given the option to opt-out of the inclusion in the INAD index. Some data subjects complained that this processing severely infringed on their privacy. As the DPA’s decision explains, it is not uncommon for professionals to give co-workers access to their professional email addresses, on the assumption that they will only be used for strictly professional communications. When the addressess became digital domiciles, third parties (such as public bodies) started using them for communications unrelated to the data subjects' personal lives - which occasionally led to unintended data disclosures. The data subjects also claimed that the controller had not informed them about the processing, which prevented them from opting out in a timely fashion. Holding — The investigation — On the duty of information — First of all, the DPA clarified that by including email addresses in the INAD index, the controller further processed personal data for a new purpose, incompatible with the original purpose of the processing (i.e.: the inclusion of email addresses in the older index). With regards to the duty of information, the controller pointed out that it contacted professional orders to inform them about the creation of the INAD index. In the context of these communications, the controller asked professional orders to inform the data subjects about this processing of personal data and about their right to opt out. The controller stated that it did not directly contact the data subjects via their email addresses, as it feared that its emails would have been mistaken as phishing or scams . The controller later launched a more effective information campaign with the help of other government bodies; however, this campaign only took place in 2025 - two years after addresses where included in the INAD index. On the controller’s identity — The DPA’s investigation also focused on a second issue, relative to the authentication procedure for digital domiciles: for a long time, a company (InfoCamere S.c.p.a.) was erroneously listed as a service provider for the INAD index. During the investigation, the controller confirmed that InfoCamere had no role in the processing of personal data. The controller also stated that it had contacted the actual service provider in order to correct the error and that the provider had done so with great delay. The DPA's conclusion — The DPA held that until 2025, the controller had failed to inform the data subjects about the inclusion of their email address in the INAD index, in violation of Articles 5(1)(a), 5(1)(b), 5(2), 12, 14 and 25 GDPR. On these grounds, the DPA fined the controller €55,000. With regards to the erroneous indication of the service provider in the authentication screen, the DPA found that the mistake was isolated and that overall, the information provided during the procedure was still sufficient to clarify that AgID was the controller. On these grounds, the DPA found that the mistake did not, in and of itself, constitute a violation of the GDPR.

### EDPS - 2020-1013

*Source: EDPS, 2022-01-05 — https://overview.legal/posts/122849 — original: https://gdprhub.eu/index.php?title=EDPS_-_2020-1013*

Facts — In January 2021, noyb filed a complaint against the European Parliament on behalf of six Members of the European Parliament over an internal coronavirus testing website. The issues raised were: confusing and unclear cookie banners, vague and unclear data protection notices, and the illegal transfer of data to the US. Holding — On data controllership — According to the EDPS, the processor may enjoy a considerable degree of autonomy in providing its services and may identify the ‘non-essential’ elements of the processing operation. Furthermore, the processor may advise or propose certain measures in this respect, but it is up to the controller to decide whether to accept such advice or proposals. The analysis of the EDPS shows that the European Parliament (EP) delegated some aspects on the setting up and functioning of the website to Ecolog. The EDPS considers the EP acts as the sole data controller for the processing in question (i.e. the operation of the Parliament’s dedicated website) whereas Ecolog acts as a processor. After having assessed the instructions given by the EP to the processor, the EDPS concluded that the EP did not show the necessary diligence required from a data controller and, ultimately, failed to comply with the Regulation on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data 2018/1725 (hereafter Regulation 2018/1725), in particular with Articles 26(1) and 29(1). Moreover, the EDPS considered that the EP failed to provide the necessary detailed instructions to Ecolog for the setting up of the website, including the drafting of the data protection notice. The absence of documented instructions is therefore in violation of Article 29(3) Regulation 2018/1725. Transparency and information requirements — The EDPS confirmed that the data protection notice published at the time of the complaint did not reflect the processing done by the EP, since it merely consisted of a copy of the testing center of Zaventem's airport. Moreover, the reference made in the document to Article 6(1)(f) GDPR was wrong since it stems from the same error. The EDPS confirmed that the EP did not meet its transparency requirements. The EDPS also analysed the updated version of the data protection notice during the procedure and raised several remaining -and even new- inconsistencies and issues. Among other things, the following problems persisted after the data protection notice was updated: a mere reference to Article 15 and 16 Regulation 2018/1725 is misleading as it should apply in its entirety; the reference to the processing of health data is not correct since no such data are processed in the case at hand; the retention period mentioned is not precise enough; the sections of the data protection notices relating to the recipients of the personal data fail to make any reference to the processor; inconsistencies between the different linguistic versions of the data protection notices were still observed: The English and German versions refer to Ecolog and the Laboratory van Poucke as processors under Article 29 Regulation 2018/1725, whereas the French version refers to them as controllers (‘responsables du traitement’). Moreover, the DPO’s contact details on the website refer to Ecolog in all three linguistic versions of the website, when they should be referring to the Parliament Cookies and transfers of personal data to the US — The EDPS confirmed that tracking cookies, such as the Stripe and the Google analytics cookies, are considered personal data, even if the traditional identity parameters of the tracked users are unknown or have been deleted by the tracker after collection. In the same vein, the EDPS rejected the EP's argument and confirmed that upon installation on a device, a cookie cannot be considered ‘inactive’. Every time a user visited Ecolog’s website, personal data was transferred to Stripe through the Stripe cookie, which contained an identifier. The EDPS reached the conclusion that a transfer of data was taking place to the US, via the use of Google and Stripe cookies, since Google Analytics is hosted in the US and the data protection notice referred to a Standard Contractual Clause (SCC) for the transfer of data outside of the EU. However, the Parliament provided no documentation, evidence or other information regarding the contractual, technical or organisational measures in place to ensure an essentially equivalent level of protection to the personal data transferred to the US in the context of the use of cookies on the website. Cookie banner on the Parliament’s dedicated website — The EDPS reminded that: before setting cookies or any other technology falling within the scope of Article 5(3) ePrivacy Directive 2002/58/EC (hereafter ePrivacy Directive), the EU institution must provide the user with adequate information on what is accessed or stored on the user’s terminal equipment, on the purposes of this action and the means for expressing their consent; no action may be performed before the consent is collected. In addition, users must be enabled to withdraw their consent at any time; ‘cookie walls’ are not in line with Regulation 2018/1725, meaning that for consent to be freely given, access to the website’s service and functionalities should not depend on the users’ consent for cookies that are not strictly necessary in the sense described above; in case personal data collected through the cookies are shared with third parties such as analytics partners, the cookie banner should draw the user's attention to it. The EDPS reached the conclusion that the cookie banners in all three languages were not in line with the definition of consent under Article 3(15) Regulation 2018/1725, nor did they meet the requirements of Article 37 Regulation 2018/1725 and Article 5(3) ePrivacy Directive. The cookie banner further failed to provide transparent information regarding the processing of personal data in relation to the cookies on the website. Request for access to personal data — The Parliament was aware that the complainants’ personal data had been processed through the cookies, which were present on the website for the period between 30 September to 4 November 2020, since transfers of personal data had taken place. Consequently, and especially following the EDPS’ inquiry on the matter, the Parliament should have replied to the complainants’ access to personal data request. The Parliament should have provided the relevant information even if it was aware that the processing of the personal data in question was unlawful, as the main purpose of the right of access under Article 15 GDPR is precisely to enable data subjects to become aware of the processing and verify the lawfulness thereof, or exercise other data subject rights. Conclusion — The EDPS concludes that the Parliament has infringed the following articles of Regulation 2018/1725: Articles 26(1) and 29(1) due to its failure to fulfil its responsibilities as controller and use a processor providing sufficient guarantees to implement appropriate technical and organisational measures; Article 29(3) due to its failure to provide documentation relating to the detailed instructions given to the processor for the setting up and functioning of the website; Articles 4(1)(a) and 14, 4(2), and 15 due to its failure to respect the principle of transparency, accountability and the data subjects’ right to information because of the inaccurate data protection notice and cookie banner on the dedicated website; Article 46 and Article 48(2)(b) of the Regulation, due to its reliance on the Standard Contractual Clauses in the absence of a demonstration that data subjects’ personal data transferred to the US were provided an essential equivalent level of protection; Article 37 read in the light of Article 5(3) of the ePrivacy Directive, due to its failure to protect information (the cookies) transmitted to, stored in, related to, processed by and collected from the users’ terminal equipment; Articles 17 and 14(4) due to its failure to reply to the data subjects’ request for access to their personal data. On the basis of the above, the EDPS decides: to issue a reprimand to the Parliament in accordance with Article 58(2)(b) Regulation 2018/1725 for the above infringements; to order the Parliament, pursuant to Article 58(2)(b) Regulation 2018/1725:, to update its data protection notices in the dedicated website in order to provide all relevant information relating to the processing of personal data. The Parliament should address this order within one month from the date of the decision.

### AKI (Estonia) - No. 2.1-1/24/397-890-38

*Source: AKI (Estonia), 2026-04-16 — https://overview.legal/posts/53882 — original: https://gdprhub.eu/index.php?title=AKI_(Estonia)_-_No._2.1-1/24/397-890-38*

Facts — OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic. On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had failed to provide all personal data requested. The controller only partially complied after several requests from the DPA. Although the DPA closed the part of the case concerning the access request, it continued investigating the controller’s processing of patients’ personal data when providing Invisalign treatment. The service required the controller to collect and transfer patients’ health data to Align Technology, Inc. However, the contractual documents did not clearly establish whether Align Technology acted as a processor, an independent controller or a joint controller. The controller stated that Align Technology largely determined the conditions of the service, including the consent form and the processing arrangements, and that individual clinics could not unilaterally amend these conditions. The DPA also found that the information provided to patients was incomplete and fragmented. The consent form and privacy information did not clearly explain the legal basis and purposes of processing, the parties involved, data recipients, retention periods, transfers outside the European Union or the safeguards applied to such transfers. Parts of the information were only available in English on external websites. Holding — The DPA held that the controller had failed to demonstrate that the processing carried out in connection with the Invisalign service was lawful and transparent under Articles 5(1)(a) and 5(2) GDPR. First, the DPA found that the parties’ roles had not been properly determined. Under Article 4(7) GDPR, the assessment had to be based on which party actually determined the purposes and means of processing, rather than solely on the contractual description of the relationship. The controller decided whether Invisalign treatment was suitable for a patient and collected the relevant health data. It therefore acted as a controller in relation to the treatment. However, Align Technology exercised significant control over the subsequent processing, including the data collected, the recipients, retention arrangements, the use of other service providers and transfers outside the European Union. The DPA therefore considered that Align Technology could not simply be regarded as a processor acting only on documented instructions under Article 28(3)(a) GDPR. On the available evidence, it was at least a joint controller under Article 26 GDPR. The DPA ordered the controller to review the contractual relationship. If Align Technology acted as a processor, the agreement had to comply with Article 28 GDPR, including the requirements concerning subprocessors under Article 28(2). If the parties were joint controllers, they had to allocate their respective responsibilities under Article 26 GDPR. Second, the DPA found that the consent obtained from patients was invalid. The consent form did not provide sufficient information for patients to understand the processing and therefore did not meet Articles 4(11), 6(1)(a), 7 and 9(2)(a) GDPR. The DPA also noted that healthcare processing may, depending on the operation concerned, rely on Article 6(1)(b) GDPR together with Article 9(2)(h) GDPR. However, the controller had not clearly identified the applicable legal bases for the different processing activities. The privacy information also failed to comply with Articles 12, 13 and 14 GDPR. Patients were required to consult several documents and external websites, some of which contained incomplete or inconsistent information. The controller had therefore not ensured that the information was easily accessible, understandable and available in Estonian. The DPA further referred to Article 25 GDPR when emphasising that the controller had to ensure that the processing arrangements and safeguards complied with the GDPR. Under Article 58(2)(d) GDPR and § 56(1) of the Estonian Personal Data Protection Act, the DPA ordered the controller to clarify the parties’ roles, conclude an Article 26 arrangement or Article 28 agreement, amend the consent form and privacy policy, and publish the required information in Estonian. No administrative fine was imposed. However, failure to comply could result in a penalty payment of €1,000 for each unfulfilled point or subpoint of the order, imposed repeatedly until compliance.

### UAT Comuna Albeni: Insufficient cooperation with supervisory authority

*Source: Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), 2023-09-25 — https://overview.legal/posts/48161 — original: https://www.enforcementtracker.com/ETid-2046*

The Romanian DPA has fined UAT Comuna Albeni EUR 2,000 for failing to provide information requested by the DPA during an investigation.

### Italian DPA sanctions Lusha Systems for processing contact data without consent in B2B

*Source: Garante per la protezione dei dati personali (Italy), 2026-07-14 — https://overview.legal/posts/184678 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_542/2026*

Facts — Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database. It was an US company wholly owned by Lusha Systems Ltd. In April 2025, the Italian DPA (Garante) initiated an investigation after media reports revealed that telephone numbers of senior Italian officials were available on the platform. The DPA later received one complaint and one report from data subjects who had received unsolicited advertising communications. The data subjects further stated that after requesting information about the source of their contact details, they discovered that their data were available on the controller’s platform without their consent. The controller explained that, for a subscription fee, it provided its Clients with a Business Contact Card for each Contact. The controller further distinguished between “Clients”, namely customers who used the platform and accessed its B2B database, and “Contacts”, namely the individuals whose personal data were included in that database, regardless of whether they used or were aware of the platform. Clients received Contact Cards containing information such as names, professional email addresses, telephone numbers, job titles, roles and locations, which could be used for sales, marketing, recruitment, business intelligence and fraud prevention. The DPA limited its investigation to the processing of Contacts’ personal data. The controller stated that it collected and combined data from publicly available sources, specialised providers, affiliated companies and commercial partners. It also inferred missing professional email addresses through algorithms that identified standard company email patterns. Through its Community Program and integrations with email, calendar and CRM services, it could also obtain information from Clients’ professional networks and communications. The data were cross-referenced, enriched and regularly updated to reflect changes in Contacts’ professional circumstances. The controller argued that the GDPR did not apply because it was established outside the EU and provided services only to businesses. It additionally claimed that the weekly updating of Contact Cards ensured accuracy rather than constituting monitoring or profiling. The controller maintained that the collection and disclosure of the data were necessary for its own economic interest in providing accurate professional contact information and for its Clients’ interests, including fraud prevention. According to the controller, it processed only a limited range of information concerning the Contacts’ professional lives. It further claimed that individuals who made professional information publicly available, particularly through services such as LinkedIn, could reasonably expect that the information might be reused and that they could be contacted regarding professional opportunities. Regarding transparency, the controller stated that its Personal Information Notice was sent to each Contact before their information became available in the database. It explained that it notified Contacts that they had a seven-day period during which they could opt out before their information became available to Clients. The controller also maintained that excluding public officials and public figures from the database was not a requirement under the GDPR. It attributed the presence of certain public officials to technical limitations in its filtering system. It also argued that public figures had a lower expectation of privacy. After the proceedings began, the controller removed profiles connected with Italian public bodies and officials, strengthened its filters and customer-verification measures, discontinued the Community Program in Italy and extended the opt-out period to fourteen days. Holding — Regarding the territorial scope of the GDPR, the DPA acknowledged that Article 3(2)(a) GDPR could apply to the processing of Clients’ data, but not to Contacts, since they were not recipients of the service. However, it held that Article 3(2)(b) GDPR applied because the controller systematically combined, enriched and updated Contacts’ professional information in order to assess their circumstances and determine whether and how they would appear in the database. Referring to Recital 24 and Recital 30, the DPA held that monitoring did not require profiling. It noted that the systematic observation of online traces and changes in a person’s professional situation was sufficient. The fact that the processing also served data accuracy did not alter that conclusion. It emphasised that the fact that the controller also updated the information to ensure its accuracy did not prevent the processing from constituting monitoring. Regarding transparency, the DPA found that the information concerning the collection of the Contacts’ data, the purposes of the processing and the legal basis relied upon was scattered across several documents. Also, the relevant information was not easily accessible from the controller’s homepage, while the Personal Information Notice could not be located directly through the website without prior knowledge of its existence. It further pointed out that the documents were provided in English rather than in the language of the affected data subjects. The DPA held that presenting the information in this manner did not satisfy the requirement that information be concise, transparent, intelligible and easily accessible. It therefore found an infringement of Article 5(1)(a) GDPR and Article 12 GDPR. Moreover, the DPA assessed whether Article 6(1)(f) GDPR provided a valid legal basis for the processing. It examined the controller’s Legitimate Interest Assessment and considered it essentially non-existent, as it contained only generic statements on necessity and proportionality and no genuine balancing assessment. The DPA then applied the three-part test under Article 6(1)(f) GDPR. It held that making the Contacts’ data available to Clients for their own marketing and sales activities could not constitute a legitimate interest, since the disclosure of contact information to third parties for their independent advertising purposes required prior consent under the applicable national and ePrivacy framework . However, it acknowledged that the controller’s interest in fraud prevention could be considered legitimate. The DPA nevertheless found that the processing was not necessary for the purposes pursued. It held that the controller collected information extending beyond ordinary professional contact details, including third-party data contained in CRM databases, email headers and subject lines, information about calendar meetings, and browsing data collected through browser extensions or other software integrations used by Clients. It pointed out that much of this information was not publicly available but was extracted from private interpersonal communications, disclosed by Clients, obtained through integrations with information systems or acquired from third-party providers. The DPA held that the collection and combination of such extensive information was neither strictly necessary nor proportionate for creating professional Contact Cards. Furthermore, it stressed that fraud prevention could also have been achieved through less intrusive means. The DPA therefore concluded that the necessity requirement and the principle of data minimisation were not met. Regarding the balancing test, the DPA emphasised that there was no prior relationship between the controller and the Contacts. Creating a professional profile on LinkedIn or another professional platform did not create a reasonable expectation that unpublished contact details would be collected from multiple sources, continuously updated and disclosed to an unspecified number of paying customers. It further noted that the processing could expose Contacts to communications from unknown third parties for purposes they could not reasonably anticipate. The DPA concluded that the Contacts’ interests, rights and freedoms prevailed over the controller’s economic interests and that the safeguards adopted by the controller could not change this outcome. Therefore, the DPA held that Article 6(1)(f) GDPR did not provide an appropriate legal basis and found that the controller infringed Article 5(1)(a) GDPR, Article 5(1)(c) GDPR, and Article 6 GDPR. Regarding public officials, the DPA held that their status did not reduce their entitlement to data protection and that no public interest justified disclosing their direct contact details for commercial purposes. The DPA further found that the controller had been aware of the risk that public officials could be included in its database but had failed to implement sufficiently effective technical and organisational measures. Its filters recognised general titles such as “President” but failed to exclude more specific titles such as “President of the Italian Republic” and “Vice Prime Minister”. The DPA therefore found an infringement of the principle of data minimisation under Article 5(1)(c) GDPR and the obligation of data protection by design and by default under Article 25 GDPR. The DPA imposed a fine of €2,000,000. Furthermore, it prohibited any further processing of personal data of data subjects located in Italy that had been collected without an adequate legal basis and ordered their deletion.

## Recent developments

### In short:

*Source: Government, 2025-03-24 — https://overview.legal/posts/52206*

Regarding the Data Protection Regulation, it should be noted that: "The Data Protection Authority (AP) is designated as the supervisory body for the section concerning the collection of data by government agencies in situations of exceptional necessity, and for the specific provisions relating to the processing of personal data, as well as for the explanation of audiovisual materials..."

### Kort:

*Source: Government, 2025-03-24 — https://overview.legal/posts/50675 — original: https://www.tweedekamer.nl/kamerstukken/kamervragen/detail?id=2025D10009&amp;did=2025D10009*

inzake de Dataverordening wordt opgemerkt : "De AP wordt aangewezen als toezichthouder voor het onderdeel dat gaat over het opvragen van gegevens door overheidsinstanties in situaties van uitzonderlijke noodzaak en specifieke bepalingen die zien op verwerking van persoonsgegevens en uitleg van AV...

### EU-wetgeving inzake datagovernance definitief vastgesteld

*Source: NL EU Court Expert, 2022-06-08 — https://overview.legal/posts/6302 — original: https://ecer.minbuza.nl/-/eu-wetgeving-inzake-datagovernance-definitief-vastgesteld?redirect=%2Fecer%2Fnieuws%3Fq%3Dprivacy%2520OR%2520avg%26f%3D%26t%3D#entry-303*

The new data governance regulation sets out the conditions for the reuse of certain government data. In addition, the regulation provides a notification and oversight framework for the provision of data mediation services. Furthermore, the regulation contains a framework for the voluntary registration of entities that collect and process data made available for altruistic purposes. The rules will apply from September 2023.

### Europese Commissie presenteert nieuwe regels om seksueel misbruik van kinderen op internet te voorkomen en te bestrijden

*Source: NL EU Court Expert, 2022-05-13 — https://overview.legal/posts/6305 — original: https://ecer.minbuza.nl/-/europese-commissie-presenteert-nieuwe-regels-om-seksueel-misbruik-van-kinderen-op-internet-te-voorkomen-en-te-bestrijden?redirect=%2Fecer%2Fnieuws%3Fq%3Dprivacy%2520OR%2520avg%26f%3D%26t%3D#entry-304*

The proposed rules would require online service providers to detect, report and remove child sexual abuse material on their services. Those providers must also assess the risk of their services being used to distribute child sexual abuse material. A new European Center on Child Sexual Abuse will provide support to providers, law enforcement and victims.

### Three recommendations from the AP (Autoriteit Persoonsgegevens - Dutch Data Protection Authority) compiled together.

*Source: Government, 2025-03-10 — https://overview.legal/posts/52247*

Three recommendations from the Dutch Authority for the Financial Markets (Autoriteit Financiële Markten - AP) combined: (regarding the handling of data breaches; a task to improve the privacy organization of the Tax Authority; and exemption from the obligation of tax confidentiality in cases of suspected violations of tax integrity under Article 67, paragraph 3, of the Act on Financial Supervision).

## Literature

### GDPR Implementation Series ∙ Malta: An Overview of the GDPR Implementation

*Source: European Data Protection Law Review, 2020-01-01 — https://overview.legal/posts/132480 — original: https://doi.org/10.21552/edpl/2020/4/15*

### GDPR Implementation Series ∙ Netherlands: The GDPR Implementation Act

*Source: European Data Protection Law Review, 2018-01-01 — https://overview.legal/posts/132478 — original: https://doi.org/10.21552/edpl/2018/3/15*

### GDPR Implementation Series ∙ Portugal: A Brief Overview of the GDPR Implementation

*Source: European Data Protection Law Review, 2019-01-01 — https://overview.legal/posts/132482 — original: https://doi.org/10.21552/edpl/2019/4/12*

### GDPR Implementation Series ∙ Italy: The Legislative Procedure for National Harmonisation with the GDPR

*Source: European Data Protection Law Review, 2018-01-01 — https://overview.legal/posts/132485 — original: https://doi.org/10.21552/edpl/2018/4/12*

### GDPR Implementation Series ∙ Romania: Overview of the GDPR Implementation

*Source: European Data Protection Law Review, 2018-01-01 — https://overview.legal/posts/132479 — original: https://doi.org/10.21552/edpl/2018/3/16*

## Related topics

- **Public Authority** — https://overview.legal/topics/overheid
  Government bodies and their data processing activities
- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Law Enforcement** — https://overview.legal/topics/law-enforcement
  Processing for law enforcement purposes
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing

---
Generated by overview.legal · https://overview.legal/topics/public-sector · 2026-08-22
