# Right to be Forgotten — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/recht-op-vergetelheid
> Sources are cited per item. Verify against the official texts before relying on them.

Right to have personal data erased under certain conditions

## Overview

## Legal Framework

Article 17 GDPR establishes the right to erasure, commonly known as the right to be forgotten. Under Article 17(1), a data subject may demand erasure of personal data where one of six grounds applies, including where the data are no longer necessary for the purposes for which they were collected, where consent is withdrawn, where the data subject objects under Article 21, or — critically — where the personal data have been unlawfully processed (Article 17(1)(d)). Once a valid erasure request is received, the controller must erase the data without undue delay and in any event within one month.

Article 19 GDPR extends the obligation beyond the controller's own systems: the controller must communicate any erasure to each recipient to whom the data were disclosed, unless this proves impossible or involves disproportionate effort. The data subject is entitled to information about those recipients upon request. This cascading obligation means erasure is not a localized event but a supply-chain responsibility.

The right is not absolute. Recitals 51 and 65, as confirmed in *GC and Others v CNIL*, emphasize that data protection must be balanced against other fundamental rights, including freedom of expression and information. Article 17(3) sets out explicit exemptions for processing necessary for freedom of expression, legal compliance, public health, archiving, and scientific or statistical purposes.

## Key Developments

Dutch courts have begun shaping the practical boundaries of Article 17. The Gerechtshof Arnhem-Leeuwarden confirmed that where a lawful basis such as Article 6(1)(c) (legal obligation) supports processing — in that case, BKR registration — an erasure request under Article 17(1)(d) must fail if the processing is not unlawful. The court also held that the risk of a costs order does not negate the Article 79 right to an effective judicial remedy.

The Rechtbank Rotterdam awarded compensation for immaterial damage where a controller unlawfully retained reports containing personal data, violating the data subject's private life. This signals that failure to honour a valid erasure request can trigger not only administrative fines but civil liability under Article 82.

A kantonrechter decision involving ASR insurance fraud registers illustrates the evidential burden: where a data subject claims unlawful processing and seeks erasure, the controller bears a heightened duty to substantiate the lawfulness of its processing ground. If the data are processed unlawfully, the right to erasure under Article 17(1)(d) is engaged as a matter of course.

The rectification right under Article 16 — closely linked to Article 17 — does not extend to erasing opinions, impressions, or research conclusions with which the data subject disagrees. Those must be challenged through appropriate procedures; mere disagreement is not a ground for erasure.

Enforcement remains active. The Italian Garante fined Geturhotels €6,000 for direct marketing violations involving retention of data beyond legitimate purposes, and the Romanian ANSPDCP fined Cucina di Fabio €3,000 in a similar context. The EDPB has issued Guidelines 5/2019 on erasure in search engine cases and conducted a coordinated enforcement action on implementation practices across controllers.

## Practical Guidance

- **Map all recipients before acting on an erasure request.** Article 19 requires notification to every recipient to whom the data were disclosed. Maintain a current data-flow inventory so this obligation can be met within the one-month deadline.
- **Assess lawfulness first under Article 17(1)(d).** If processing lacks a valid Article 6 basis, erasure is mandatory. Document the legal basis assessment contemporaneously — courts have placed a heightened evidential burden on controllers to justify retention.
- **Distinguish factual correction from opinion deletion.** Article 16 does not permit erasure of subjective assessments or research conclusions. Train staff handling data subject requests to identify and route such complaints to the appropriate dispute mechanism rather than auto-erasing.
- **Apply the proportionality test for downstream notification.** Article 19 allows non-notification where it is impossible or disproportionately burdensome, but this exception must be documented with a reasoned assessment, not assumed.
- **Prepare for civil exposure alongside administrative risk.** Per the Rotterdam ruling, unlawful retention can trigger Article 82 compensation claims. Erasure procedures should be integrated with the organization's damage-prevention and incident-response protocols.

## Legislation (full text of key provisions)

### Right to erasure (‘right to be forgotten’)

*Source: GDPR, gdpr-art-17-en, 2016-04-27 — https://overview.legal/posts/90426*

### Notification obligation regarding rectification or erasure of personal data or restriction of processing

*Source: GDPR, gdpr-art-19-en, 2016-04-27 — https://overview.legal/posts/90457*

The controller shall communicate any rectification or erasure of personal data or restriction of processing carried out in accordance with Article 16, Article 17(1) and Article 18 to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort. The controller shall inform the data subject about those recipients if the data subject requests it.

### Recital 66 — right to erasure online environment

*Source: GDPR, gdpr-rec-66-en, 2016-04-27 — https://overview.legal/posts/91647*

To strengthen the right to be forgotten in the online environment, the right to erasure should also be extended in such a way that a controller who has made the personal data public should be obliged to inform the controllers which are processing such personal data to erase any links to, or copies or replications of those personal data. In doing so, that controller should take reasonable steps, taking into account available technology and the means available to the controller, including technical measures, to inform the controllers which are processing the personal data of the data subject's request.

### Recital 68 — data subject data portability right

*Source: GDPR, gdpr-rec-68-en, 2016-04-27 — https://overview.legal/posts/91651*

To further strengthen the control over his or her own data, where the processing of personal data is carried out by automated means, the data subject should also be allowed to receive personal data concerning him or her which he or she has provided to a controller in a structured, commonly used, machine-readable and interoperable format, and to transmit it to another controller. Data controllers should be encouraged to develop interoperable formats that enable data portability. That right should apply where the data subject provided the personal data on the basis of his or her consent or the processing is necessary for the performance of a contract. It should not apply where processing is based on a legal ground other than consent or contract. By its very nature, that right should not be exercised against controllers processing personal data in the exercise of their public duties. It should therefore not apply where the processing of the personal data is necessary for compliance with a legal obligation to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of an official authority vested in the controller. The data subject's right to transmit or receive personal data concerning him or her should not create an obligation for the controllers to adopt or maintain processing systems which are technically compatible. Where, in a certain set of personal data, more than one data subject is concerned, the right to receive the personal data should be without prejudice to the rights and freedoms of other data subjects in accordance with this Regulation. Furthermore, that right should not prejudice the right of the data subject to obtain the erasure of personal data and the limitations of that right as set out in this Regulation and should, in particular, not imply the erasure of personal data concerning the data subject which have been provided by him or her for the performance of a contract to the extent that and for as long as the personal data are necessary for the performance of that contract. Where technically feasible, the data subject should have the right to have the personal data transmitted directly from one controller to another.

### Recital 59 — modalities for data subject rights exercise

*Source: GDPR, gdpr-rec-59-en, 2016-04-27 — https://overview.legal/posts/91633*

Modalities should be provided for facilitating the exercise of the data subject's rights under this Regulation, including mechanisms to request and, if applicable, obtain, free of charge, in particular, access to and rectification or erasure of personal data and the exercise of the right to object. The controller should also provide means for requests to be made electronically, especially where personal data are processed by electronic means. The controller should be obliged to respond to requests from the data subject without undue delay and at the latest within one month and to give reasons where the controller does not intend to comply with any such requests.

### Recital 65 — data subject rectification and erasure rights

*Source: GDPR, gdpr-rec-65-en, 2016-04-27 — https://overview.legal/posts/91645*

A data subject should have the right to have personal data concerning him or her rectified and a ‘right to be forgotten’ where the retention of such data infringes this Regulation or Union or Member State law to which the controller is subject. In particular, a data subject should have the right to have his or her personal data erased and no longer processed where the personal data are no longer necessary in relation to the purposes for which they are collected or otherwise processed, where a data subject has withdrawn his or her consent or objects to the processing of personal data concerning him or her, or where the processing of his or her personal data does not otherwise comply with this Regulation. That right is relevant in particular where the data subject has given his or her consent as a child and is not fully aware of the risks involved by the processing, and later wants to remove such personal data, especially on the internet. The data subject should be able to exercise that right notwithstanding the fact that he or she is no longer a child. However, the further retention of the personal data should be lawful where it is necessary, for exercising the right of freedom of expression and information, for compliance with a legal obligation, for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, on the grounds of public interest in the area of public health, for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, or for the establishment, exercise or defence of legal claims.

### Recital 73 — lawful restrictions on data subject rights

*Source: GDPR, gdpr-rec-73-en, 2016-04-27 — https://overview.legal/posts/91661*

Restrictions concerning specific principles and the rights of information, access to and rectification or erasure of personal data, the right to data portability, the right to object, decisions based on profiling, as well as the communication of a personal data breach to a data subject and certain related obligations of the controllers may be imposed by Union or Member State law, as far as necessary and proportionate in a democratic society to safeguard public security, including the protection of human life especially in response to natural or manmade disasters, the prevention, investigation and prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security, or of breaches of ethics for regulated professions, other important objectives of general public interest of the Union or of a Member State, in particular an important economic or financial interest of the Union or of a Member State, the keeping of public registers kept for reasons of general public interest, further processing of archived personal data to provide specific information related to the political behaviour under former totalitarian state regimes or the protection of the data subject or the rights and freedoms of others, including social protection, public health and humanitarian purposes. Those restrictions should be in accordance with the requirements set out in the Charter and in the European Convention for the Protection of Human Rights and Fundamental Freedoms.

## Case law

### VG Stuttgart - 1 K 12737/25

*Source: Administrative Court Stuttgart, 2026-07-14 — https://overview.legal/posts/184726 — original: https://gdprhub.eu/index.php?title=VG_Stuttgart_-_1_K_12737/25*

Facts — A resident of North Macedonia (the data subject) was expelled from German territory in September 2021, and a two-year ban on entry and residence was imposed on him. The data subject subsequently re-entered German territory without a visa in December 2024 and travelled back to North Macedonia in July 2025. A federal police directorate (the controller) assumed that the data subject had violated the ban on entry and residence. The controller determined that the data subject posed a threat within the meaning of Article 24(2) of Regulation (EU) 2018/1861, ordered an alert for refusal of entry and stay, and entered it into the Schengen Information System (SIS) in August 2025. The data subject filed a lawsuit with the Stuttgart Administrative Court in October 2025, requesting that the controller be ordered to delete the alert and alternatively to correct it or to impose a time limit on it. Holding — The court held that the lawsuit was admissible and well-founded and ordered the controller to delete the alert for refusal of entry and stay from the SIS pursuant to Articles 53(1), 24(1) and (2) of Regulation (EU) 2018/1861 in conjunction with Article 17(1) GDPR. In the present case, the personal data of the data subject was inaccurate as the requirements for the alert were no longer fulfilled: the court held it could not be assumed that the data subject’s presence on German territory posed a threat to public order or security. In addition, the court referred to the principle of proportionality and pointed out that alerts may not be stored in the SIS for longer than necessary. The data subject had clearly changed his behaviour by marrying a German citizen and filing a visa application for family reunification since his expulsion from Germany. Therefore, the court held that the grounds for erasure laid down in Article 17(1)(a) and (d) GDPR were applicable.

### OLG München - 36 U 1054/25 e

*Source: Higher Regional Court Munich, 2026-06-26 — https://overview.legal/posts/184545 — original: https://gdprhub.eu/index.php?title=OLG_München_-_36_U_1054/25_e*

Facts — The data subject had used a social media platform operated by the controller, an Irish company, since 2013. The controller provided “Business Tools” to third-party website operators and app providers. These tools enabled the controller to obtain data concerning how users interacted with third-party websites and apps, including information about page visits, purchases and advertisements clicked. In November 2023, the data subject requested that the controller recognize that the processing of his personal data was contrary to the parties’ contract, erase or anonymize the personal data, provide access to the personal data and pay compensation. The data subject subsequently brought an action before the Regional Court of Munich II, seeking a declaration that the parties’ user contract did not permit the processing, cessation of the processing of personal data collected through the Business Tools on third-party websites and apps, restriction of further processing, erasure or anonymization of previously collected data and at least €5,000 in non-material damages. The relevant data included direct and indirect identifiers, such as his name, contact details, IP address and internal identifiers, as well as website URLs, visit times, app names and information about his interactions with websites and apps. The Regional Court of Munich II dismissed the action, holding that the declaratory and erasure or anonymization claims were inadmissible, the cessation claims were legally unavailable and the damages claim had not been sufficiently substantiated. In relation to the damages claim, it found that the data subject had not identified specific third-party websites or apps through which his personal data had been processed. The data subject accordingly appealed to the Higher Regional Court of Munich. Holding — The Higher Regional Court of Munich partially upheld the appeal. First, the court held that the Controller processed the data subject’s personal data under Articles 4(1) and 4(2) GDPR by receiving data transmitted through its Business Tools, associating it with a user account and storing it. The data subject was not required to identify every website, app or individual transmission because the relevant information was principally within the controller’s knowledge and it was sufficiently probable that he had been affected. Second, referring to CJEU C‑40/17 concerning the broad interpretation of “controller”, the court held that the controller was a joint controller under Articles 4(7) and 26 GDPR for the collection and transmission of the personal data. It controlled the programming of the Business Tools and participated in determining the purposes and means of processing. Allocating certain obligations to third-party website and app operators did not remove its responsibility. Third, referring to CJEU C‑252/21, the court held that the controller had not established a lawful basis for the processing of the personal data. The processing was not justified by consent under Article 6(1)(a), contractual necessity under Article 6(1)(b), a legal obligation under Article 6(1)(c), a public-interest task under Article 6(1)(e), or legitimate interests under Article 6(1)(f) GDPR. Accordingly, the court held that the controller's processing infringed Articles 5(1)(a), 5(1)(b), 5(1)(c) and 6 GDPR. Relying on CJEU C‑655/23, the court granted an injunction against future unlawful processing under German law. It also ordered restriction pending erasure under Article 18(1)(b) and erasure under Article 17(1)(d) GDPR. The court upheld the dismissal of the separate declaratory claim and also rejected anonymization of the website and app interaction data. Finally, relying on BGH VI ZR 10/24, the court awarded €1,500 in non-material damages under Article 82(1) GDPR for the data subject’s loss of control over his personal data.

### OLG Köln - 15 W 55/26

*Source: Higher Regional Court Cologne, 2026-06-12 — https://overview.legal/posts/53657 — original: https://gdprhub.eu/index.php?title=OLG_Köln_-_15_W_55/26*

Facts — The data subject, a doctor, sought an injunction against the Controller, the operator of an online review platform, requiring the removal of, and prohibiting the future publication of, a notice stating that between six and ten reviews concerning his medical practice had been removed during the previous year following complaints relating to defamation under German law. The Regional Court of Cologne dismissed the application, following which the data subject lodged an immediate appeal before the Higher Regional Court of Cologne. The data subject argued that the notice was inaccurate because the reviews had been challenged on the basis that no genuine patient relationship existed, rather than on the ground of defamation. He submitted that the notice therefore created the false impression that he had complained of defamatory reviews, rendering the processing of his personal data unlawful. The Controller argued that complaints alleging the absence of a genuine customer or patient relationship fell within its internal category of complaints concerning defamation under German law and that publishing the number of removed reviews promoted transparency regarding its review moderation process. Holding — The court held that where a data subject seeks not only the erasure of personal data but also an injunction preventing its future publication, Article 17(1) GDPR provides a basis for both forms of relief. It further held that the journalistic exemption under Article 85(2) GDPR did not apply because the Controller's review platform, including the automated notices relating to removed reviews, did not process data for journalistic purposes. The court also held that the displayed number of removed reviews constituted personal data within the meaning of Article 4(1) GDPR because it related to an identified natural person. By storing and disclosing that information, the Controller processed personal data within the meaning of Article 4(2) GDPR. In assessing the accuracy of the notice under Article 5(1)(d) GDPR, the court considered how an average user would understand the information. It held that a prominently linked information page entitled "Defamation under German law" explained that the platform categorised not only false or reputation-damaging reviews, but also complaints alleging that the reviewer was not a genuine customer, as complaints concerning defamation. As the data subject did not dispute that he had successfully requested the removal of between six and ten reviews on the basis that the reviewers had not been genuine patients, the court concluded that users could readily understand the platform's use of the term and that the notice was factually accurate. The court also rejected the data subject's reliance on the Festzins Plus judgment (BGH, judgment of 21 September 2017 – I ZR 53/16), distinguishing that case because the corrective information there appeared only at the end of a lengthy and unclear text, whereas the notice in the present case contained a clearly highlighted hyperlink directing users to explanatory information specifically addressing the platform's categorisation of review removals. The court held that the Controller had legitimate interests in promoting transparency regarding its handling of review-removal requests and that publication of the notice was necessary for that purpose. These interests outweighed the data subject's rights because the notice related only to his professional activity, was presented in a factual manner, contained no criticism of his behavior and was not prominently displayed, appearing only after users selected the "Reviews" tab. Accordingly, the court concluded that the processing was lawful under Article 6(1)(f) GDPR and that the data subject was not entitled to erasure or an injunction preventing the future publication of the notice under Article 17(1) GDPR.

### Judgment of the Court (Grand Chamber) of 2 December 2025.#X v Russmedia Digital SRL and Inform Media Press SRL.#Request for a preliminary ruling from the Curtea de Apel Cluj.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 4(7) – Concept of ‘controller’ – Responsibility of the operator of an online marketplace for the publication of personal data contained in advertisements placed on its online marketplace by user advertisers – Article 5(2) –

*Source: Court of Justice of the European Union, C-492/23, 2025-12-02 — https://overview.legal/posts/132130 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0492*

In Case C-492/23, the Court of Justice of the European Union (Grand Chamber) addressed a preliminary reference from the Curtea de Apel Cluj concerning whether an online marketplace operator (Russmedia Digital SRL and Inform Media Press SRL) qualifies as a data "controller" under Article 4(7) GDPR for personal data contained in advertisements published by user advertisers. The Court examined the allocation of controller responsibility, including potential joint control with user advertisers, and analyzed whether the operator's obligations under Articles 5(2), 9, 24, 25, and 32 GDPR—including prior identification of sensitive data and advertisers, refusal of unlawful advertisements, and implementation of security measures—preclude reliance on the intermediary liability exemptions under Articles 12 to 15 of Directive 2000/31/EC (E-Commerce Directive). No fine was imposed, as the ruling is an interpretive preliminary reference rather than an enforcement action.

### USR - Us I-755/2025-8

*Source: Administrative Court in Rijeka, 2025-11-11 — https://overview.legal/posts/49225 — original: https://gdprhub.eu/index.php?title=USR_-_Us_I-755/2025-8*

Facts — The data subject was a member of the management board of Zagrebački holding, a company owned by the City of Zagreb, from 3 September 2021 until 31 March 2023. A television broadcaster published several pieces, including a video on its YouTube channel, reporting on the data subject’s resignation. The publications mentioned his name, role, employer, salary, and information on the brand of his private car. The data subject filed a complaint with the Croatian Personal Data Protection Agency (AZOP), claiming that the publication constituted unlawful processing under the GDPR because the media lacked a valid legal basis under Article 6, the reporting was inaccurate and excessive, and it did not serve any genuine public interest. He latter further claimed during the lawsuit against AZOP's decision that the authority had incorrectly and incompletely established the facts, misapplied substantive law, and breached procedural rules. He emphasized that the published personal data was unrelated to transparency in public administration, that he was neither a public figure nor a political actor, and that any public interest ended once he left office on 31 March 2023. He invoked his right to erasure under Article 17 GDPR and sought removal of the content, annulment of AZOP’s decision, or alternatively, a remittal for a new procedure. AZOP contested the lawsuit in full, maintaining that it had acted in accordance with Article 34 of the Croatian GDPR Implementation Act and Article 77 GDPR. It argued that the publication fell within a justified public interest under Article 8 of the Croatian Media Act and that it had properly carried out a balancing test between privacy (Article 8 ECHR) and freedom of expression (Article 10 ECHR). According to AZOP, the reporting was necessary, proportionate, and not sensationalistic, and did not excessively intrude on the data subject’s privacy. It added that consent was not required because the processing relied on legitimate interest under Article 6(1)(f) GDPR. Holding — The Administrative Court dismissed the action and upheld AZOP’s decision. Because Zagrebački holding is a city-owned and publicly funded company, the court considered information about the data subject’s salary, compensation for using his private vehicle in official duties, and his managerial role to be directly connected to the use of public resources. This placed the publication within the legitimate public interest in transparency recognised by Article 8 of the Media Act. In its proportionality assessment, the court accepted AZOP's application of Article 5 and 6 GDPR, emphasizing that the published data did not touch upon the data subject’s family or intimate life but related solely to his public functions. Publication was therefore limited to what was necessary to inform the public about the management of a publicly owned company. The data subject’s claims that the publication was false or harmful to his reputation did not alter the outcome, as AZOP is not empowered to determine the truthfulness or tone of journalistic content, particularly under the journalistic exemption in Article 85 GDPR. Issues of accuracy or reputational harm must instead be pursued through media-law mechanisms such as requests for correction or civil actions. On the erasure request, the court held that the right to be forgotten under Article 17 GDPR cannot override freedom of expression and information where media reporting is involved. Although the data subject no longer served on the board, the publication continued to contribute to public understanding of how a major public entity was run during his tenure, thus the public interest persisted and erasure was not justified. Finally, the court reiterated that consent was not required because Article 6 GDPR offers alternative lawful bases for processing. Since Article 6(1)(f) was satisfied, the absence of consent was irrelevant. Concluding that AZOP had properly applied the law and that the interference with the data subject’s privacy was proportionate, the court upheld the decision and denied the data subject’s claim and costs.

### Judgment of the Court (First Chamber) of 4 October 2024.#Agentsia po vpisvaniyata v OL.#Request for a preliminary ruling from the Varhoven administrativen sad.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Publication in the commercial register of a company’s constitutive instrument containing personal data – Directive (EU) 2017/1132 – Non-compulsory personal data – Lack of consent of the data subjec

*Source: Court of Justice of the European Union, C-200/23, 2024-10-04 — https://overview.legal/posts/132161 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0200*

The Court of Justice of the European Union (First Chamber) ruled on a preliminary reference from the Bulgarian Supreme Administrative Court in a dispute between the Agentsia po vpisvaniyata (Registration Agency) and OL concerning the Agency's refusal to erase personal data contained in a company's constitutive instrument published in the commercial register. The Court held that non-compulsory personal data included in company documents under Directive (EU) 2017/1132 does not qualify as processing necessary for compliance with a legal obligation under GDPR Article 6(1)(c), and where no other valid legal basis applies (such as consent under Article 6(1)(a)), the data subject is entitled to erasure under Article 17; furthermore, publication of such data without a valid legal basis may constitute non-material damage compensable under Article 82, though the existence and amount of any compensation depends on national court assessment of the actual harm suffered. No fine was imposed, as this was a preliminary ruling proceeding.

### VwGH - Ro 2022/04/0026

*Source: Austrian Administrative Supreme Court, 2024-05-17 — https://overview.legal/posts/187377 — original: https://gdprhub.eu/index.php?title=VwGH_-_Ro_2022/04/0026*

Facts — The data subjects, joint operators of a hotel and restaurant business, ran their establishment through a family business. The controller operates an online travel platform accessible in Austria, on which registered users can post reviews and experience reports about listed establishments, in addition to general information. The data subjects' business was listed on the platform without their consent and was reviewed by users a few times per month, in comments that identified the data subjects by name, including both positive and negative reviews. On 27 June 2019, the data subjects requested that the controller erase all their personal data from the platform. The controller did not comply. On 28 August 2019, the data subjects lodged a complaint with the Austrian DPA, alleging unlawful processing and a violation of their right to erasure under Article 17(1)(d) GDPR. The DPA rejected the complaint on 18 September 2020, relying on Article 6(1)(f) GDPR (legitimate interests) as the legal basis for the processing. The data subjects appealed to the Federal Administrative Court (BVwG), which held an oral hearing and dismissed the appeal on 13 May 2022. The BVwG found that the platform's processing served a legitimate interest in freedom of expression and information that the reviews concerned the data subjects' social andprofessional sphere rather than their private sphere, that it was reasonable to expect the data subjects to monitor the platform for unjustified criticism and that the controller had taken adequate measures against abusive reviews. The BVwG declared an appeal on points of law (Revision) admissible, citing the absence of Supreme Administrative Court case-law on the principles governing the balancing of interests for review platforms under Article 6(1)(f) GDPR. The data subjects appealed to the Supreme Administrative Court. Holding — The court dismissed the appeal as unfounded, addressing each contested element of the three-part test under Article 6(1)(f) GDPR (legitimate interest, necessity, no overriding interest of the data subject). On legitimate interest: The court held that the exercise of freedom of expression and information can constitute a legitimate interest under Article 6(1)(f) GDPR. It reasoned that both service recipients' freedom to express opinions about service quality and the conduct of those providing the service and prospective recipients' freedom to access such opinions, were protected by this provision and that the platform served this purpose by enabling reviews and structured searches. The court held that the controller's pursuit of commercial interests alongside this function did not undermine the legitimate interest, since Article 6(1)(f) GDPR expressly covers interests of the controller "or a third party" and the data subjects had not substantiated their claim that the controller had abandoned a neutral intermediary role. It also rejected the argument that the public's interest was too narrow to qualify as legitimate merely because the hotel's clientele was limited, holding that such considerations belong to the separate balancing-of-interests stage, not to the threshold question of whether a legitimate interest exists at all. On the sphere of privacy affected: The court agreed with the lower court that the reviews concerned the data subjects' social sphere (specifically, their professional sphere as hotel operators) rather than their private sphere, since the criticised conduct occurred in public in the course of providing services to third parties. It held that this classification does not change merely because the business could hypothetically be sold to a third party in future, such a change of circumstances could be considered if and when it actually occurred, but did not retroactively reclassify the current processing. On the reasonableness of monitoring the platform: The court held that requiring the data subjects to check the platform for reviews was not excessive, given the low frequency of reviews, the availability of an email notification service and the fact that hotel operators offering services to the public must accept a degree of observation and criticism. The court limited the relevant comparison to the controller's own platform, not all review platforms on which the business might be listed, since only a claim against this controller was at issue. On protection against abuse: The court held that the absence of identity verification for reviewers was a relevant factor in the balancing exercise, but that a blanket requirement for reviewers to identify themselves would be disproportionate, given the recognised value of anonymous expression online. It held that the controller's existing measures allowing establishment representatives to report abusive reviews for removal, were sufficient, although it criticised the lower court's findings on this point as underdeveloped. However, since the data subjects failed to show that any specific personal data would have been removed had a stricter verification system existed, this shortcoming did not establish unlawfulness in the specific case. On the second data subject's claim of heightened risk as a former political figure: The court held that a data subject wishing to invoke a "particular situation" under Article 21 GDPR must lodge an actual objection to processing on that basis; simply mentioning a past political role during proceedings did not amount to such an objection and the erasure request had in fact been based solely on unlawful processing under Article 17(1)(d) GDPR, not the objection-based ground under Article 17(1)(c) GDPR. Finally, the court declined the data subjects' request for a preliminary reference to the CJEU, noting that the CJEU has already made clear that the case-specific balancing of interests under Article 6(1)(f) GDPR is a matter for the national court. (C-252/21)

### Judgment of the Court (Fifth Chamber) of 14 March 2024.#Budapest Főváros IV. Kerület Újpest Önkormányzat Polgármesteri Hivatala v Nemzeti Adatvédelmi és Információszabadság Hatóság.#Request for a preliminary ruling from the Fővárosi Törvényszék.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 58(2)(d) and (g) – Powers of the supervisory authority of a Member State – Paragraph 17(1) – Right to e

*Source: Court of Justice of the European Union, C-46/23, 2024-03-14 — https://overview.legal/posts/132267 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0046*

In a preliminary ruling requested by the Budapest High Court, the Court of Justice interpreted whether Article 58(2)(d) and (g) of the GDPR permits a national supervisory authority to order a controller to erase unlawfully processed personal data without a prior request from the data subject. The case arose from a dispute between the Budapest District IV (Újpest) municipal administration and the Hungarian National Data Protection and Freedom of Information Authority (NAIH), which had ordered the municipality to erase unlawfully processed data. The Court held that GDPR provisions do not require a prior data subject request for a supervisory authority to exercise its corrective power to order erasure of unlawfully processed personal data, as such a requirement would undermine the consistent and effective protection of fundamental rights under the GDPR.

### Judgment of the Court (Third Chamber) of 11 January 2024.#État belge v Autorité de protection des données.#Request for a preliminary ruling from the cour d'appel de Bruxelles.#Reference for a preliminary ruling – Approximation of laws – Protection of natural persons with regard to the processing of personal data and free movement of such data (General Data Protection Regulation) – Regulation (EU) 2016/679 – Point 7 of Article 4 – Concept of ‘controller’ – Official journal of a Member State – Obl

*Source: Court of Justice of the European Union, C-231/22, 2024-01-11 — https://overview.legal/posts/132274 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0231*

In Case C-231/22, the Court of Justice of the European Union interpreted Article 4(7) and Article 5(2) of the GDPR in response to a preliminary reference from the Brussels Court of Appeal in proceedings between the Belgian State and the Belgian Data Protection Authority concerning whether the managing authority of the Moniteur belge (Belgium's official journal) constitutes a "controller" under the GDPR. The central issue was whether a Member State authority that is legally obligated to publish company documents containing personal data, as prepared and submitted by third parties, determines the purposes and means of processing within the meaning of Article 4(7). The Court held that such an authority does qualify as a controller because, by disseminating the personal data to the public, it determines the means of making the data accessible and exercises autonomous control over that processing operation, even though it does not determine the content of the published documents; no fine was at issue in this preliminary ruling.

### Judgment of the Court (First Chamber) of 7 December 2023.#UF and AB v Land Hessen.#Requests for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 5(1)(a) – Principle of ‘lawfulness’ – Point (f) of the first subparagraph of Article 6(1) – Necessity of processing for the purposes of the legitimate interests pursued by the controller or by

*Source: Court of Justice of the European Union, C-26/22, 2023-12-07 — https://overview.legal/posts/132278 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0026*

The Court of Justice of the European Union (First Chamber) ruled on preliminary references from the Verwaltungsgericht Wiesbaden in joined cases C-26/22 and C-64/22, concerning UF and AB's challenge to the Hessischer Beauftragter für Datenschutz und Informationsfreiheit's refusal to order SCHUFA Holding AG to delete data regarding the discharge of their remaining debts. The core issue was whether storage of such data by a credit information agency was lawful under GDPR Article 6(1)(f) and whether the supervisory authority's dismissal of the complaints satisfied Article 78's right to an effective judicial remedy. The Court held that the legitimate interests of credit agencies in assessing creditworthiness may justify retention of remaining-debt-discharge data, but the three-year storage period presumptively lawful under German law must be assessed against GDPR necessity and proportionality requirements, and that national courts must conduct full judicial review of supervisory authority decisions rather than limited deferential review. No fine was imposed.

### Österreichische Datenschutzbehörde v CRIF

*Source: CJEU, C-487/21, 2023-10-26 — https://overview.legal/posts/51486 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0487*

Right of access includes obtaining a copy in commonly used electronic form.

### BVwG - W256 2227693-1

*Source: Federal Administrative Court, 2023-09-28 — https://overview.legal/posts/125664 — original: https://gdprhub.eu/index.php?title=BVwG_-_W256_2227693-1*

Facts — On 05.09.2019, the Austrian DPA (DSB) notified the controller of a customer loyalty program that they were initiating an ex officio investigation. The controller responded by answering the provided questionnaire and submitting further documents. On 23.10.2019, the DPA ruled that the investigation was justified and that the declaration of consent for profiling using certain registration methods (website, app, partner company store, flyer) did not comply with the requirements of Article 4(11) GDPR and Article 7 GDPR, nor were they provided in an intelligible way. If a contract covers several aspects, the declaration of consent must be clearly distinguishable. Regarding the website and flyer, the following was found: The website says 'Enjoy your personal benefits' without providing clear information that 'personal benefits' involves profiling. In an embedded box, the relevant points were merely referred to. Information regarding profiling was only accessible by scrolling down further. Concerning the flyer, the following information was provided under the signature field: 'This signature only applies to the declaration of consent and is voluntary. Your registration [...] is also valid without a signature.' Thus, it conveyed the impression that a signature was required to confirm the registration. Consequently, the controller was required to amend the declaration and to cease using any obtained consents for the purpose of profiling prior to 01.05.2020. The controller lodged a complaint. In addition to other information, the controller stated that the data processing was in accordance with Article 6(1)(a) GDPR, and that they had a legitimate interest under Article 6(1)(f) GDPR. The DPA ruled a preliminary decision on the complaint, thereby changing the ruling that the website and flyer did not meet the requirements under Article 6(1)(a) GDPR, and thus, the processing of personal data, collected in that cases, was forbidden. The other methods ensured that the consent was clearly separated from the rest of the registration process. The controller then filed a request for referral to the court, arguing that the DPA had exceeded their corrective powers by prohibiting the processing of the data. Furthermore, the data processing for profiling would be used to manage customer memberships under Article 6(1)(b) GDPR. Following their view, processing under Article 6(4) GDPR was applicable. Additionally, the controller denied the DPA's view that a violation of the principle of good faith would foreclose a weighing of interests under Article 6(1)(f) GDPR. The court quashed the preliminary decision as the DPA had not examined the other grounds of justification for data processing under Article 6(1) GDPR in their initial decision. The DPA then lodged an appeal to the Austrian Supreme Administrative Court (Verwaltungsgerichtshof), which overturned the court's ruling (VwGH 08.02.2022, Ro 2021/04/0033). It was the court's responsibility to examine the potential legal bases, rather than overturning the DPA's decision. Therefore, the case was returned to the court. In the meantime, the controller complied with the preliminary decision by deleting the affected personal data in 2021 and changing their registration process in 2020. Holding — First, the court found that they had to formally rule on whether the DPA's decision was lawful at the time it was ruled. It is not to be considered that the controller complied with the administrative decision and fulfilled the required steps (VwGH 28.04.2022, Ra 2022/06/0056). Second, the court held that the controller did not comply with the transparency requirements regarding the layout of their declaration of consent under Article 7(2) GDPR in both cases (website, flyer). Third, the court ruled that they could not agree with DPA's view, that an invalid declaration of consent always constitutes unlawful data processing and that a review of other grounds of justification would not be necessary (CLEU in 'Meta Platforms and Others' (C-252/21) ECLI:EU:C:2023:537). Further on, the Supreme Administrative Court ruled that both, the DPA and the court are required to examine the presence of other grounds (VwGH 08.02.2022, Ro 2021/04/0033). Fourth, the court held that the controller could not base their appeal on Article 6(4) GDPR as the data processing did not satisfy the grounds of justification, nor were other grounds apparent. Inter alia, following the CLEU's preliminary ruling in 'Meta Platforms and Others' (C-252/21) ECLI:EU:C:2023:537, three cumulative requirements must be met for data processing under Article 6(1)(f) GDPR: (1) The controller or a third party must have a legitimate interest, (2) which requires the processing of that personal data, (3) and 'the fundamental rights and freedoms of the data subject' must not outweigh those interests. There were no doubts about the controller's legitimate interest in processing the personal data in question for targeted marketing purposes, as this was both necessary and reasonable. However, the data subject should have been notified about profiling. The wording 'only if the member consents' did not constitute such a notification, and therefore the data subjects were not to be expected that their personal data was used for profiling purposes. Furthermore, the controller explicitly excluded it in their general terms and conditions. Hence, the data subject's right to secrecy overrode the controller's legitimate interest. In summary, the court dismissed the controller's complaint. Last, the court held that an appeal to the Supreme Administrative Court was admissible under Article 133(4) B-VG, as no prevailing case law concerning the implementation of a declaration of consent existed. Hence, the decision relied on a legal question of fundamental importance.

## Guidance

### Guidelines 5/2019 on the criteria of the Right to be Forgotten in the search engines cases under the GDPR (part 1)

*Source: EDPB, edpb-guidelines-on-the-criteria-of-the-right-to-be-forgotten-in-the-search-engines-cases-under-th, 2020-07-07 — https://overview.legal/posts/38070 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-52019-on-the-criteria-of-the-right-to-be-forgotten-in-the-search_en*

The European Data Protection Board (EDPB) issued these guidelines to clarify the criteria and grounds for exercising the right to erasure (right to be forgotten) specifically in the context of search engine cases under the GDPR. The document details the six grounds under Article 17(1) that allow data subjects to request delisting, alongside the relevant exceptions, such as the right to freedom of expression and information. As a guidance instrument, it does not impose administrative fines but instead aims to harmonize how search engine providers handle and balance delisting requests across the EU.

### Opinion 39/2021 on whether Article 58(2)(g) GDPR could serve as a legal basis for a supervisory authority to order ex officio the erasure of personal data, in a situation where such request was not submitted by the data subject

*Source: EDPB, opinion-392021-on-whether-article-582g-gdpr-could-serve-as-a-en, 2021-12-14 — https://overview.legal/posts/125971 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-392021-on-whether-article-582g-gdpr-could-serve-as-a_en*

Adopted 1 Opinion 39 /2021 on whether Article 58(2) ( g) GDPR coul d serve as a legal basis for a s upervisory a uthority to order ex officio the erasure of personal data, in a situation where such request was not submitted by the data subject Adopted on 14 December 2021 Adopted 2 Adopted 3 The European Data Protection Board Having regard to Article 63 and Article 64 (2) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural…

### EDPB Annual Report 2019

*Source: EDPB, edpb-annual-report-2019-en, 2020-05-18 — https://overview.legal/posts/126163 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-annual-report-2019_en*

EDPB Annual Report 2019 1 EDPB Annual Report 2019 1 European Data Protection Board 2019 Annual Report WORKING TOGETHER FOR STRONGER RIGHTS An Executive Summary of this report, which provides an overview of key EDPB activities in 2019, is also available. Further details about the EDPB can be found on our website at edpb.europa.eu. EDPB Annual Report 2019 EDPB Annual Report 2019 2 3 FOREWORD 1 4 MISSION STATEMENT, TASKS AND PRINCIPLES 2 5 Tasks and duties Guiding principles 5 6 2.1. 2.2 . ABOUT…

### Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models

*Source: EDPB, opinion-282024-on-certain-data-protection-aspects-related-to-en, 2024-12-18 — https://overview.legal/posts/125697 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-282024-on-certain-data-protection-aspects-related-to_en*

Adopted 1 Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models Adopted on 17 December 2024 Adopted 2 Executive summary AI technologies create many opportunities and benefits across a wide range of sectors and social activities. By protecting the fundamental right to data protection, GDPR supports these opportunities and promotes other EU fundamental rights, including the right to freedom of thought, expression and information,…

### Guidelines 10/2020 on restrictions under Article 23 GDPR

*Source: EDPB, edpb-guidelines-on-restrictions-under-article-23-gdpr, 2021-10-13 — https://overview.legal/posts/38062 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-102020-on-restrictions-under-article-23-gdpr_en*

The European Data Protection Board (EDPB) issued these guidelines to clarify the scope and application of Article 23 of the GDPR, which allows Member States to restrict certain data subject rights and controller obligations. The guidelines outline the necessary conditions and safeguards, emphasizing that any restrictions must respect the essence of fundamental rights and be implemented via foreseeable, proportionate legislative measures. This document serves as authoritative guidance for interpreting the specific grounds and requirements under which Member States may legally impose such limitations.

### Statement on restrictions on data subject rights in connection to the state of emergency in Member States

*Source: EDPB, statement-on-restrictions-on-data-subject-rights-in-connection-to-the-state-of-en, 2020-06-02 — https://overview.legal/posts/126146 — original: https://www.edpb.europa.eu/documents/statement/statement-on-restrictions-on-data-subject-rights-in-connection-to-the-state-of_en*

1 Statement on restrictions on data subject rights in connection to the state of emergency 1 in Member States Adopted on 2 June 2020 The European Data Protection Board has adopted the following statement: 1. The EDPB has been informed of the adoption by the Hungarian government of the Decree 179/2020 of 4 May 2020 on the derogations from certain data protection and access to information provisions during the state of danger 2 . Under Article 1, this Decree provides that, with respect to…

### Guidelines 05/2020 on consent under Regulation 2016/679

*Source: EDPB, edpb-guidelines-on-consent, 2020-05-04 — https://overview.legal/posts/38053 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-052020-on-consent-under-regulation-2016679_en*

The European Data Protection Board (EDPB) adopted Guidelines 05/2020 on consent under Regulation 2016/679 to provide detailed interpretive guidance on the requirements for valid consent under the GDPR, including the elements of freely given, specific, informed, and unambiguous consent, as well as the conditions for explicit consent and the obligation to demonstrate consent. The guidelines address practical issues such as power imbalances, conditionality, granularity, detriment, and the minimum content requirements for informing data subjects. No fines are imposed, as this is a guidance document rather than an enforcement decision.

### EDPB Leaflet

*Source: EDPB, edpb-leaflet-en, 2019-03-28 — https://overview.legal/posts/126228 — original: https://www.edpb.europa.eu/documents/other-guidance/edpb-leaflet_en*

edpb.europa.eu Editor: Secretariat of the European Data Protection Board, Rue Montoyer 30, 1047 Brussels. GDPR and your rights Data protection, a fundamental right for every EU data subject AI AI A new level of cooperation between European regulators The European Data Protection Board (EDPB), a new independent EU body, brings together all supervisory authorities in the EEA, as well as the European Data Protection Supervisor. The EDPB contributes to the consistent application of the GDPR by: •…

## Enforcement decisions

### Greek DPA: Google breached Art. 17 GDPR erasure right over outdated criminal case links

*Source: HDPA (Greece), 2023-06-29 — https://overview.legal/posts/125608 — original: https://gdprhub.eu/index.php?title=HDPA_(Greece)_-_54/2024*

Facts — In 2020, the data subject filed a complaint with the DPA against Google LLC (the controller) for failing to fulfill their right to erasure (Article 17 GDPR) concerning links - referring to criminal charges - appearing in search results based on their name. The data subject argued that these results contained outdated information about a closed criminal case involving them. The controller partially complied with the request but retained one link. The data subject then identified additional publications that required deletion. However, the controller failed to act within the 30-day deadline stipulated by Article 12(3) GDPR. Instead, it responded with an automated message, attributing the delay to the Covid-19 pandemic and claiming that the erasure request was incomplete because it lacked the court judgment clearing the data subject of charges. Before the DPA, the data subject argued that the pandemic is not a valid justification for delays and that the erasure request form does not allow attachments, preventing them from submitting supporting documents. The controller stated that it provides multiple channels for data subjects to request data erasure, including direct email contact with its DPO and the retained link in question referred to a comment, which allegedly did not meet the criteria for erasure or contain any information directly linking it to the data subject. Holding — The DPA found Google LLC to be the controller as it is responsible for the deletion process not Google Hellas/Athens. The DPA found, that contrary to the controller's statement the remaining link could be associated with the data subject’s identity and past criminal cases. Thus, the DPA held, that the erasure request must be fulfilled unless the controller demonstrates compelling and lawful reasons for continuing processing (Article 21(1) GDPR), which the DPA found lacking. The DPA held that the lack of an attachment option hinders the effective exercise of data subjects' rights, as they are forced to seek alternative communication methods. Thus, the controller fails to facilitate the erasure request process. Additionally the court found, that the controller did not comply with Article 12(3) GDPR, as a general, automated response does not meet it’s requirements and the contact link for the controller’s DPO did not include any contact details, making direct communication impossible in breach of Article 37(7) GDPR. Based on these findings, the DPA ordered the controller to: Provide an attachment option in the erasure request submission form. Stop sending automated responses to submitted requests. Publish the contact details of its DPO. Delete the remaining link, as requested by the data subject.

### HDPA (Greece) 33/2020 — Employee's access and erasure claims against the American College

*Source: HDPA (Greece), 2026-07-24 — https://overview.legal/posts/158444 — original: https://gdprhub.eu/index.php?title=HDPA_(Greece)_-_33/2020*

Facts — The data subject was under the employment of the College for a certain period of time, during which two female students of the College filed a complaint against the complainant regarding the latter's posts on social media that violated the College's Code of Conduct due to their homophobic and racist content. After this event, the College decided to move the complainant to a different position, while reacting to this situation the complainant argued that he had suffered a defamation by the College and requested the altering of the situation. The College asked the complainant to appear to the new position, something the complainant never did, but, nevertheless, the College continued paying the complainant's salary up to the ending point of their contract. Then, the data subject/complainant filed a request to the American College of Greece, asking for access to and copies of their personal data the latter is keeping in its records given the employment relationship between the two, while they specifically requested access to the two complaints made by the two students. With the same request, the data subject asked for the erasure of their personal data from the College's records, since the reason for which the data had been collected and were being kept was no longer valid, since the employment relationship between the complainant and the College had expired. In addition, with the same request, the complainant revoked their - possibly given silently - consent for the keeping and processing of their personal data by the College. The complainant claimed that there was no response from the College to their request. The HDPA requested the College's response to the situation. The latter claimed that the request under question only came into its attention via the HDPA's request for response to the claims. It justified this situation by mentioning that the employee who received the request was not in a good state of health, while the period when the request was filed was a period of heavy workload at the College. The College further underlined that, as soon as the request came to its attention, it contacted the complainant and: i) fulfilled their right to access their data by informing them for all data currently kept by the College and for providing information on how to get copies of all personal data, but not for the data referring to the personal information of one female student of the College who had filed a complaint against the data subject/complainant regarding the latter's behaviour, since the student expressed her not willingness for her name and complained to be known. The College also sent a question to the HDPA regarding the existence or not of their legal responsibility to provide access to the details of the complaint made by the student who expressed her not willingness to be known, as well as regarding the conditions under which such an access should be provided. This question, as the HDPA found, was never answered. ii) informed the complainant that the right to erasure could only be partly fulfilled, since some of the personal data being kept by the College must continue being kept due to the existence of the legal necessity for their existence, in order for the College to be able to fulfil some of its legal responsibilities, according to the provisions of Article 17(3)f GDPR, 250-253 Civil Law Code, and 95 Law 4387/2016. Moreover, the College claimed that it had the right to deny the fulfilment of the complainant's right to access and erasure, according to article 12(5)b GDPR, since the respective request has been made in a manifestly unfounded or excessive and repetitive manner. Answering to the College's claims, the complainant argued that the College is not fulfilling their rights to access and erasure, as well as that the College is not properly justifying the excessive or unfounded manner of the complainant's requests based on the said GDPR article. Additionally, the complainant argued that their right to access had never been fulfilled as their relevant request to the College was only answered by the latter with the explanation that the College had sent a question to the HDPA regarding the legality of fulfilling such a request, but with no information being provided later on by the College. Thus, the complainant underlined that, under Article 55 of Law 4629/2019, the College had the legal responsibility, as a data processor, to inform the data subject for all the data being kept and processed and to fulfil the data subject's right to access before fulfilling their right to erasure. Dispute — Whether the American College of Greece violated the complainant's right to access and erasure of their personal data? Holding — The HDPA confirmed its jurisdiction to rule on the complaint regarding a possible violation of the rights to access to and erasure of personal data, according to Articles 51,55,57,58 GDPR and Articles 9,13,15 of Law 4624/2019. On the contrary, it underlined its lack of jurisdiction to rule on the dispute of the complainant and the American College of Greece as regards the conditions of the employment relationship between them. The HDPA, after presenting the principles of data processing of Article 5(1) GDPR, underlined that, based on Article 5(2) GDPR, it is the data processor's responsibility to conform and to be able to prove their conformity with these principles at all times and by themselves (principle of accountability). Additionally, the HDPA stated that, in accordance with Article 8(1) of the Charter of Fundamental Rights of the EU, Article 9A of the Greek Constitution, and the Recital 4 of GDPR, the right to protection of personal data is not an absolute right, but a right that should be perceived always in connection to its function within society and a right that should be weighted in connection to other fundamental rights, always according to the principle of proportionality. Furthermore, the HDPA referred to Articles 12 and 15 GDPR regarding the right to access personal data, while it also underlined the restrictions to this right that Articles 23 GDPR and 33 Law 4624/2019 provide. More specifically, Article 33 mentions that the right to access cannot be fulfilled when: "1) [...] b) the data i) were recorded just because they could not have been erased due to legal provisions for the necessity of their keeping or ii) exclusively serve purposes of protection or control of data, and the provision of information would require a disproportional effort and the necessary technical and organisational measures render the processing of the data impossible for other purposes. 2) The reasons for the denial of provision of information to the data subject should be justified. The denial must be justified to the data subject, unless the provision of the real and legal reasons on which the denial is based would put the purpose of the denial into danger. [...] 4) The right to information on their data according to Article 15 GDPR does not apply, to the degree that through the provision of information other information, that according to a legal provision or to their nature, especially due to a third party's interest, must remain confidential, would be revealed. " Adding to this, the HDPA noted its past Decision 73/2010, where it judged that "the information of who is complaining against the accused constitutes an information that refers to the latter and is included in the right to access [...] . More specifically, the right to know the source of the data means that the data processor must inform the data subject of the source of the data (HDPA Decisions 4/2005, 39/2005). The HDPA has ruled that the "source" can also be a third party (natural person) (HDPA Decisions 4/2003 & 43/2003, where it is underlined that the accused has the right to access the text of the complaint and to know - when the complaint is eponymous - the name of the complainant, without the matter of whether the complainant is a third party or not being examined). After all, the knowledge of the source of the data is necessary for the data subject to be able to exercise their further rights [...]. Therefore, the HDPA underlined that the name of the female student in included in the content of the term personal data for which the data subject has the right to access, according to Article 15(1)g GDPR. Thus, the HDPA held that the College as a data controller, according to Article 4(7) GDPR, fulfilled the right to access of the complainant via the provision of copies of the data being kept. But, as concerns the non provision of the information for the complaint made by the second female student, the College violated Article 15 GDPR regarding the right to access, since it connected the provision of access to those with the consent of the female student, without examining Article 15 GDPR or Article 33 Law 2462/2019. In addition, from the merits of the case, there is no evidence for the existence of any danger faced by the female student nor is there any claim by the College or the female student for such a danger, given as well that the College did not pursue a disciplinary process against the complainant, while it also continued their salary payments even though the complainant denied to work in the new position where they were transferred. {Here there was a separate opinion of one member of the HDPA, highlighting that the text of the female student's complaint should have been provided to the complainant but with the covering of all relevant data pointing to the female student's identity.}. Additionally, the College's claim for the sickness of their employee and the work overload have no effect over the responsibility of the College to respond to the complainant's request, while there is also no effect on this responsibility from the fact that the HDPA did not answer to the College's request for its Opinion, since the HDPA did not have jurisdiction to impose to the data processor the provision to a third person of data nor had a complained been filed to the HDPA by th data subject (the female student) so as to open up the HDPA's jurisdiction (Article 5 Law 2472/1997, HDPA Opinions 4/2009, 6/2013, HDPA Decision 8/2019). Furthermore, the HDPA held that the complainant's claim that the College did not prove the unfounded or excessive character of their request is of no meaning, since the College responded to their request, even though with delay. The HDPA also held that the complainant's claim for the implementation of Article 55(5) Law 4624/2019 is unfounded, as its provisions cannot be implemented in this case. Lastly, the HDPA referred to Article 17 GDPR on the right to erasure and the restrictions of this non-absolute right provided in par.3 of the said Article and in Article 34 Law 4624/2019. Thus, the HDPA underlined that in the case under question the College as a data processor fulfilled the complainant's right to erasure. The HDPA held that there is, in this case, a legal case of exception from the right to erasure concerning the data referring to the complainant's employment relationship with the College that the latter is required to be keeping based on Article 17(3)b & e GDPR. Additionally, the HDPA held that the College has the legal right to keep the data referring to the two complaints made by the students according to Articles 17(3)e GDPR and 34(1) Law 4624/2019. Therefore, the HDPA held that the College partly fulfilled the data subject's right to access, since it did not provide information on the second female student's complaint, including her name, in violation of Articles 5,15 GDPR, 33 Law 4624/2019. Thus, the HDPA, making use of its corrective powers of Article 58(2)c GDPR, ordered the College to provide the complainant with the relevant information. Additionally, the HDPA held that the College fulfilled the right to access but in violation of the deadlines for such a fulfilment provided by Article 12(3) & (4) GDPR. For this reason, an administrative fine of 1000 EUR was imposed (83(5)b GDPR). Lastly, the HDPA held that the College fulfilled the complainant's right to erasure but in violation of the deadlines provided for such a fulfilment by Article 12(3) & (4) GDPR. For this reason, an administrative fine of 1000 EUR was imposed (Article 83(5)b GDPR).

### Corint Logistic SRL.: Insufficient fulfilment of data subjects rights

*Source: Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), 2024-05-30 — https://overview.legal/posts/48463 — original: https://www.enforcementtracker.com/ETid-2348*

The Romanian DPA has imposed a fine of EUR 2,000 on Corint Logistic SRL. A customer had filed a complaint with the DPA because they had received advertising text messages from the controller, even though they had exercised their right to erasure and received confirmation that their personal data had been deleted.

### KUGELCHEN PROPIERTIES, S.L.: Insufficient legal basis for data processing

*Source: Spanish Data Protection Authority (aepd), 2023-07-07 — https://overview.legal/posts/48058 — original: https://www.enforcementtracker.com/ETid-1943*

The Spanish DPA has imposed a fine of EUR 2,000 on KUGELCHEN PROPIERTIES, S.L.. The controller had continued to process data of the data subject, despite exercising their right to erasure.

### Bper Banca S.p.A.: Insufficient fulfilment of data subjects rights

*Source: Italian Data Protection Authority (Garante), 2022-09-15 — https://overview.legal/posts/47575 — original: https://www.enforcementtracker.com/ETid-1460*

The Italian DPA has imposed a fine of EUR 10,000 on Bper Banca S.p.A.. An individual had filed a complaint with the DPA regarding the failure to fulfill their right to erasure of personal data. The individual had requested the bank to delete their personal data processed by the bank. The bank then asked the data subject to send their identification documents in order to verify their identity for the purpose of fulfilling their request. The data subject submitted their data, but did not receive a

### Kutxabank, S.A.: Insufficient fulfilment of data subjects rights

*Source: Spanish Data Protection Authority (aepd), 2021-04-08 — https://overview.legal/posts/46745 — original: https://www.enforcementtracker.com/ETid-630*

The Spanish DPA (AEPD) has imposed a fine of EUR 100,000 on Kutxabank, S.A.. Following a complaint from a former customer, claiming that the bank did not comply with his request to erasure of his data, the DPA started an investigation against the controller. The data subject had already been a customer of the bank in the past. At that time, he had exercised his right to erasure of his data. When he tried to open a new account with the controller, he was informed that this was not possible as his

### Anmavas 61, S.L.: Insufficient cooperation with supervisory authority

*Source: Spanish Data Protection Authority (aepd), 2020-11-18 — https://overview.legal/posts/46567 — original: https://www.enforcementtracker.com/ETid-452*

The Spanish DPA (AEPD) imposed a fine on Anmavas 61, S.L. for neither granting nor justifiably denying the right to erasure to the data subject, even after receiving a warning issued by the AEPD.

### DSB (Austria) - 2020-0.303.727

*Source: DSB (Austria), 2020-09-01 — https://overview.legal/posts/158430 — original: https://gdprhub.eu/index.php?title=DSB_(Austria)_-_2020-0.303.727*

Facts — In June 2019, the complainant requested erasure of her personal data from the respondent's website, claiming that an article on that website contained wrong statements about her. After the respondent’s refusal to do so, the complainant lodged a complaint with the DSB. The respondent argued that publishing the article on its website qualified as processing carried out for journalistic purposes under Article 85 GDPR and § 9(1) of the Austrian Data Protection Act (Datenschutzgesetz - DSG). Due to the derogations in § 9(1) DSG, the DSB would hence not be competent to handle the complaint. Dispute — Is the DSB competent to handle the complaint or is the processing on the respondent's website subject to Article 85 GDPR and § 9(1) of the Austrian Data Protection Act? Did the respondent violate the complaint's right to erasure under Article 17 GDPR? Holding — The DSB held, that the respondent qualifies as a media company under § 1(1)(6) of the Austrian Media Act, because it is a company which creates the content of the medium and handles the production, distribution, broadcasting and retrievability of the medium. It further held, that the data processing (publishing the complainant's personal data in an online article) was carried out for journalistic purposes . As the complainant is an former politician and the article revolved around legal procedures that she is involved in there was a public interest in mentioning the complainant's name. Under Article 9(1) DSG, Chapter III and Chapter VI of the GDPR do not apply on data processing carried out by media companies for journalistic purposes. Such GDPR violations must be tried before civil courts. Hence, the DSB considered itself not competent, rejected the complaint and did not investigate the alleged violation of Article 17 GDPR.

## Recent developments

### One-Stop-Shop case digest on right to object and right to erasure updated

*Source: European Data Protection Board, 2026-06-25 — https://overview.legal/posts/53055 — original: https://www.edpb.europa.eu/news/one-stop-shop-case-digest-on-right-to-object-and-right-to-erasure-updated_en*

Brussels, 25 June - The EDPB has published an update of the One-Stop-Shop (OSS) case digest on right to object and right to erasure. This project has been developed in the framework of the of the Support Pool of Experts programme, which aims to support cooperation among Data Protection Authorities (DPAs).Thematic one-stop-shop case digests are drafted on the basis of one-stop-shop decisions taken from the EDPB’s public register (based on Art.60 GDPR). Such case digests complement the EDPB's publ

### EDPB identifies challenges hindering the full implementation of the right to erasure

*Source: European Data Protection Board, 2026-02-18 — https://overview.legal/posts/52724 — original: https://www.edpb.europa.eu/news/news/2026/edpb-identifies-challenges-hindering-full-implementation-right-erasure_en*

Brussels, 18 February - The European Data Protection Board (EDPB) has adopted a report on its Coordinated Enforcement Framework (CEF) action on the right to be forgotten (Art.17 GDPR). The Board selected this topic as it is one of the most frequently exercised GDPR rights and one about which DPAs frequently receive complaints from individuals. The main objectives of this coordinated action are to ensure that the right to erasure is effectively exercised by individuals in Europe and understand ho

### Respondent has no right to erasure of personal data

*Source: IT en Recht, 2023-03-01 — https://overview.legal/posts/6236 — original: https://www.itenrecht.nl/artikelen/geintimeerde-heeft-geen-recht-op-wissing-van-persoonsgegevens#entry-3985*

Hague Court of Appeal February 3, 2023, IT 4226; ECLI:NL:GHDHA:2023:306 (Veilig Thuis v. the respondent) In this case, a man requested the deletion of his personal data processed by Veilig Thuis. The court ruled that Veilig Thuis's processing of the man's data was lawful under the Social Support Act (Wmo) and that the request for data deletion was therefore denied. Safe Home is not obliged to erase the man's personal data in order to comply with the legal obligation under Article 17(1)(e) AVG, b

### "The Right to Erasure: a Legal Analysis of Deleting Personal Information from Veilig Thuis' Records"

*Source: Dutch Courts, 2023-02-28 — https://overview.legal/posts/6237 — original: https://deeplink.rechtspraak.nl/uitspraak?id=ECLI:NL:GHDHA:2023:306&pk_campaign=rss&pk_medium=rss&pk_keyword=uitspraken#entry-3967*

Request for destruction of Safe Home files; admissibility; right to erasure of personal data under the AVG and Wmo

### DPC welcomes publication of EDPB CEF implementation report on right to be forgotten

*Source: DPC Ireland, 2026-02-20 — https://overview.legal/posts/53038 — original: https://www.dataprotection.ie/en/news-media/latest-news/dpc-welcomes-publication-edpb-cef-implementation-report-right-be-forgotten*

DPC welcomes publication of EDPB CEF implementation report on right to be forgotten

## Literature

### Forgetful AI: AI and the Right to Erasure under the GDPR

*Source: European Data Protection Law Review, 2020-01-01 — https://overview.legal/posts/132542 — original: https://doi.org/10.21552/edpl/2020/3/8*

### IMPACT OF GDPR ON UKRAINIAN PERSONAL DATA PROTECTION LEGISLATION

*Source: Pravo ta nauki, 2018-12-30 — https://overview.legal/posts/132472 — original: https://doi.org/10.66556/2522-4549.1519.koshovyi-b*

The article examines the impact of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation – GDPR), which entered into force on 25 May 2018, on Ukrainian personal data protection legislation. The main novelties of GDPR are analyzed, including the principle of accountability, the right to erasure (right to be

### HOW GDPR TREATS AUTOMATED DECISION-MAKING

*Source: Journal Scientific and Applied Research, 2025-11-14 — https://overview.legal/posts/132599 — original: https://doi.org/10.46687/jsar.v28i1.435*

This article examines how the General Data Protection Regulation (GDPR) regulates automated decision-making, including profiling, in the context of personal data processing. It analyzes the main provisions of Article 22 of the Regulation, as well as the conditions under which fully automated decisions that produce legal effects or significantly affect data subjects are permitted. The article highlights the rights of data subjects – the right to human intervention, the right to express their poin

### The data subject’s right to access to information under GDPR and the right of the data controller to protect its know-how

*Source: Przegląd Prawniczy Uniwersytetu im. Adam Mickiewicza, 2023-12-30 — https://overview.legal/posts/132546 — original: https://doi.org/10.14746/ppuam.2023.15.09*

The data subject’s right to access information on data processing has a very broad meaning. Considering the latest developments in this field (mainly the CJEU ruling on Austrian posts and EDPB guidelines) one can draw the conclusion that the controller’s right to protect its confidential in-formation is limited and less valuable than the data subject’s rights. However, this may lead to unfair and unequal treatment of companies and data subjects. When looking at this right in a more systematic pe

### GDPR: A new challenge for personal data protection

*Source: Bankarstvo, 2017-01-01 — https://overview.legal/posts/132473 — original: https://doi.org/10.5937/bankarstvo1704166m*

stručni članak Erne Mraznica Raiffeisen banka ad Beograd erne.mraznica@raiffeisenbank.rs GDPR - NOVI IZAZOV ZAŠTITE PODATAKA O LIČNOSTI Rezime Dana 4. maja 2016. godine objavljena je Opšta Uredba o zaštiti podataka o ličnosti u Sl. glasniku EU, koja će se primenjivati od 25. maja 2018. godine. Cilj propisa je harmonizacija zaštite podataka o ličnosti na nivou EU, veći stepen kontrole za lica čiji se podaci obrađuju i unapređeno upravljanje savremenim rizicima iz ove oblasti. Banke, po prirodi svog poslovanja, spadaju među najveće rukovaoce podataka o ličnosti i u postupku usklađivanja sa obavezama utvrđenih Uredbom biće u prilici da izvrše punu analizu svog postojećeg regulatornog i infrastrukturnog okvira zaštite podataka o ličnosti. Istovremeno, pruža im se prilika da isprave eventualne nedostatke u postojećim procesima, odnosno da značajno povećaju svest organizacije o standardima zaštite podataka o ličnosti, posebno imajući u vidu zaprećene stroge sankcije za slučaj neusklađenosti. Ključne reči : GDPR, podatak o ličnosti, osnovni principi, prava lica, rukovalac, obrada podataka, transfer podataka, sankcije, usklađivanje JEL : F52, G14 doi: 10.5937/bankarstvo1704166M 166 Bankars

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Consent** — https://overview.legal/topics/toestemming
  Freely given, specific, informed indication of data subject wishes
- **Law Enforcement** — https://overview.legal/topics/law-enforcement
  Processing for law enforcement purposes
- **Human Resources** — https://overview.legal/topics/human-resources
  Processing of employee and HR data

---
Generated by overview.legal · https://overview.legal/topics/recht-op-vergetelheid · 2026-08-22
