# Recipient — legal context bundle

> Curated from overview.legal on 2026-07-22. Canonical page: https://overview.legal/topics/recipient
> Sources are cited per item. Verify against the official texts before relying on them.

A person or body to which personal data are disclosed (Art 4(9) GDPR).

## Legislation (full text of key provisions)

### Definitions

*Source: ePrivacy, eprivacy-art-2-en, 2002-07-12 — https://overview.legal/posts/132169*

DefinitionsSave as otherwise provided, the definitions in Directive 95/46/EC and in Directive 2002/21/EC of the European Parliament and of the Council of 7 March 2002 on a common regulatory framework for electronic communications networks and services (Framework Directive) ( 8 ) shall apply.The following definitions shall also apply:‘user’ means any natural person using a publicly available electronic communications service, for private or business purposes, without necessarily having subscribed to this service;‘traffic data’ means any data processed for the purpose of the conveyance of a communication on an electronic communications network or for the billing thereof; ▼M2 ‘location data’ means any data processed in an electronic communications network or by an electronic communications service, indicating the geographic position of the terminal equipment of a user of a publicly available electronic communications service; ▼B ‘communication’ means any information exchanged or conveyed between a finite number of parties by means of a publicly available electronic communications service. This does not include any information conveyed as part of a broadcasting service to the public over an electronic communications network except to the extent that the information can be related to the identifiable subscriber or user receiving the information; ▼M2 ————— ▼B ‘consent’ by a user or subscriber corresponds to the data subject's consent in Directive 95/46/EC;‘value added service’ means any service which requires the processing of traffic data or location data other than traffic data beyond what is necessary for the transmission of a communication or the billing thereof;‘electronic mail’ means any text, voice, sound or image message sent over a public communications network which can be stored in the network or in the recipient's terminal equipment until it is collected by the recipient; ▼M2 ‘personal data breach’ means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed in connection with the provision of a publicly available electronic communications service in the Community.

### Notification obligation regarding rectification or erasure of personal data or restriction of processing

*Source: GDPR, gdpr-art-19-en, 2016-04-27 — https://overview.legal/posts/90457*

The controller shall communicate any rectification or erasure of personal data or restriction of processing carried out in accordance with Article 16, Article 17(1) and Article 18 to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort. The controller shall inform the data subject about those recipients if the data subject requests it.

### Right to lodge a complaint

*Source: DSA, dsa-art-53-en, 2022-10-19 — https://overview.legal/posts/94952*

Recipients of the service and any body, organisation or association mandated to exercise the rights conferred by this Regulation on their behalf shall have the right to lodge a complaint against providers of intermediary services alleging an infringement of this Regulation with the Digital Services Coordinator of the Member State where the recipient of the service is located or established. The Digital Services Coordinator shall assess the complaint and, where appropriate, transmit it to the Digital Services Coordinator of establishment, accompanied, where considered appropriate, by an opinion. Where the complaint falls under the responsibility of another competent authority in its Member State, the Digital Services Coordinator receiving the complaint shall transmit it to that authority. During these proceedings, both parties shall have the right to be heard and receive appropriate information about the status of the complaint, in accordance with national law.

### Recital 20

*Source: DSA, dsa-rec-20-en, 2022-10-19 — https://overview.legal/posts/95437*

Where a provider of intermediary services deliberately collaborates with a recipient of the services in order to undertake illegal activities, the services should not be deemed to have been provided neutrally and the provider should therefore not be able to benefit from the exemptions from liability provided for in this Regulation. This should be the case, for instance, where the provider offers its service with the main purpose of facilitating illegal activities, for example by making explicit that its purpose is to facilitate illegal activities or that its services are suited for that purpose. The fact alone that a service offers encrypted transmissions or any other system that makes the identification of the user impossible should not in itself qualify as facilitating illegal activities.

### Recital 34

*Source: DSA, dsa-rec-34-en, 2022-10-19 — https://overview.legal/posts/95465*

Relevant national authorities should be able to issue such orders against content considered illegal or orders to provide information on the basis of Union law or national law in compliance with Union law, in particular the Charter, and to address them to providers of intermediary services, including those established in another Member State. However, this Regulation should be without prejudice to Union law in the field of judicial cooperation in civil or criminal matters, including Regulation (EU) No 1215/2012 and a Regulation on European production and preservation orders for electronic evidence in criminal matters, and to national criminal or civil procedural law. Therefore, where those laws in the context of criminal or civil proceedings provide for conditions that are additional to or incompatible with the conditions provided for in this Regulation in relation to orders to act against illegal content or to provide information, the conditions provided for in this Regulation might not apply or might be adapted. In particular, the obligation on the Digital Services Coordinator from the Member State of the issuing authority to transmit a copy of the orders to all other Digital Services Coordinators might not apply in the context of criminal proceedings or might be adapted, where the applicable national criminal procedural law so provides. Furthermore, the obligation for the orders to contain a statement of reasons explaining why the information is illegal content should be adapted, where necessary, under the applicable national criminal procedural law for the prevention, investigation, detection and prosecution of criminal offences. Finally, the obligation on the providers of intermediary services to inform the recipient of the service might be delayed in accordance with applicable Union or national law, in particular in the context of criminal, civil or administrative proceedings. In addition, the orders should be issued in compliance with Regulation (EU) 2016/679 and the prohibition of general obligations to monitor information or to actively seek facts or circumstances indicating illegal activity laid down in this Regulation. The conditions and requirements laid down in this Regulation which apply to orders to act against illegal content are without prejudice to other Union acts providing for similar systems for acting against specific types of illegal content, such as Regulation (EU) 2021/784, Regulation (EU) 2019/1020, or Regulation (EU) 2017/2394 that confers specific powers to order the provision of information to Member State consumer law enforcement authorities, whilst the conditions and requirements that apply to orders to provide information are without prejudice to other Union acts providing for similar relevant rules for specific sectors. Those conditions and requirements should be without prejudice to retention and preservation rules under applicable national law, in compliance with Union law and confidentiality requests by law enforcement authorities related to the non-disclosure of information. Those conditions and requirements should not affect the possibility for Member States to require a provider of intermediary services to prevent an infringement, in compliance with Union law including this Regulation, and in particular with the prohibition of general monitoring obligations.

### Recital 55

*Source: DSA, dsa-rec-55-en, 2022-10-19 — https://overview.legal/posts/95507*

Restriction of visibility may consist in demotion in ranking or in recommender systems, as well as in limiting accessibility by one or more recipients of the service or blocking the user from an online community without the user being aware (‘shadow banning’). The monetisation via advertising revenue of information provided by the recipient of the service can be restricted by suspending or terminating the monetary payment or revenue associated to that information. The obligation to provide a statement of reasons should however not apply with respect to deceptive high-volume commercial content disseminated through intentional manipulation of the service, in particular inauthentic use of the service such as the use of bots or fake accounts or other deceptive uses of the service. Irrespective of other possibilities to challenge the decision of the provider of hosting services, the recipient of the service should always have a right to effective remedy before a court in accordance with the national law.

### Recital 56

*Source: DSA, dsa-rec-56-en, 2022-10-19 — https://overview.legal/posts/95509*

A provider of hosting services may in some instances become aware, such as through a notice by a notifying party or through its own voluntary measures, of information relating to certain activity of a recipient of the service, such as the provision of certain types of illegal content, that reasonably justify, having regard to all relevant circumstances of which the provider of hosting services is aware, the suspicion that that recipient may have committed, may be committing or is likely to commit a criminal offence involving a threat to the life or safety of person or persons, such as offences specified in Directive 2011/36/EU of the European Parliament and of the Council (27), Directive 2011/93/EU or Directive (EU) 2017/541 of the European Parliament and of the Council (28). For example, specific items of content could give rise to a suspicion of a threat to the public, such as incitement to terrorism within the meaning of Article 21 of Directive (EU) 2017/541. In such instances, the provider of hosting services should inform without delay the competent law enforcement authorities of such suspicion. The provider of hosting services should provide all relevant information available to it, including, where relevant, the content in question and, if available, the time when the content was published, including the designated time zone, an explanation of its suspicion and the information necessary to locate and identify the relevant recipient of the service. This Regulation does not provide the legal basis for profiling of recipients of the services with a view to the possible identification of criminal offences by providers of hosting services. Providers of hosting services should also respect other applicable rules of Union or national law for the protection of the rights and freedoms of individuals when informing law enforcement authorities.

### Recital 58

*Source: DSA, dsa-rec-58-en, 2022-10-19 — https://overview.legal/posts/95513*

Recipients of the service should be able to easily and effectively contest certain decisions of providers of online platforms concerning the illegality of content or its incompatibility with the terms and conditions that negatively affect them. Therefore, providers of online platforms should be required to provide for internal complaint-handling systems, which meet certain conditions that aim to ensure that the systems are easily accessible and lead to swift, non-discriminatory, non-arbitrary and fair outcomes, and are subject to human review where automated means are used. Such systems should enable all recipients of the service to lodge a complaint and should not set formal requirements, such as referral to specific, relevant legal provisions or elaborate legal explanations. Recipients of the service who submitted a notice through the notice and action mechanism provided for in this Regulation or through the notification mechanism for content that violate the terms and conditions of the provider of online platforms should be entitled to use the complaint mechanism to contest the decision of the provider of online platforms on their notices, including when they consider that the action taken by that provider was not adequate. The possibility to lodge a complaint for the reversal of the contested decisions should be available for at least six months, to be calculated from the moment at which the provider of online platforms informed the recipient of the service of the decision.

### Recital 67

*Source: DSA, dsa-rec-67-en, 2022-10-19 — https://overview.legal/posts/95531*

Dark patterns on online interfaces of online platforms are practices that materially distort or impair, either on purpose or in effect, the ability of recipients of the service to make autonomous and informed choices or decisions. Those practices can be used to persuade the recipients of the service to engage in unwanted behaviours or into undesired decisions which have negative consequences for them. Providers of online platforms should therefore be prohibited from deceiving or nudging recipients of the service and from distorting or impairing the autonomy, decision-making, or choice of the recipients of the service via the structure, design or functionalities of an online interface or a part thereof. This should include, but not be limited to, exploitative design choices to direct the recipient to actions that benefit the provider of online platforms, but which may not be in the recipients’ interests, presenting choices in a non-neutral manner, such as giving more prominence to certain choices through visual, auditory, or other components, when asking the recipient of the service for a decision. It should also include repeatedly requesting a recipient of the service to make a choice where such a choice has already been made, making the procedure of cancelling a service significantly more cumbersome than signing up to it, or making certain choices more difficult or time-consuming than others, making it unreasonably difficult to discontinue purchases or to sign out from a given online platform allowing consumers to conclude distance contracts with traders, and deceiving the recipients of the service by nudging them into decisions on transactions, or by default settings that are very difficult to change, and so unreasonably bias the decision making of the recipient of the service, in a way that distorts and impairs their autonomy, decision-making and choice. However, rules preventing dark patterns should not be understood as preventing providers to interact directly with recipients of the service and to offer new or additional services to them. Legitimate practices, for example in advertising, that are in compliance with Union law should not in themselves be regarded as constituting dark patterns. Those rules on dark patterns should be interpreted as covering prohibited practices falling within the scope of this Regulation to the extent that those practices are not already covered under Directive 2005/29/EC or Regulation (EU) 2016/679.

### Recital 68

*Source: DSA, dsa-rec-68-en, 2022-10-19 — https://overview.legal/posts/95533*

Online advertising plays an important role in the online environment, including in relation to the provision of online platforms, where the provision of the service is sometimes in whole or in part remunerated directly or indirectly, through advertising revenues. Online advertising can contribute to significant risks, ranging from advertisements that are themselves illegal content, to contributing to financial incentives for the publication or amplification of illegal or otherwise harmful content and activities online, or the discriminatory presentation of advertisements with an impact on the equal treatment and opportunities of citizens. In addition to the requirements resulting from Article 6 of Directive 2000/31/EC, providers of online platforms should therefore be required to ensure that the recipients of the service have certain individualised information necessary for them to understand when and on whose behalf the advertisement is presented. They should ensure that the information is salient, including through standardised visual or audio marks, clearly identifiable and unambiguous for the average recipient of the service, and should be adapted to the nature of the individual service’s online interface. In addition, recipients of the service should have information directly accessible from the online interface where the advertisement is presented, on the main parameters used for determining that a specific advertisement is presented to them, providing meaningful explanations of the logic used to that end, including when this is based on profiling. Such explanations should include information on the method used for presenting the advertisement, for example whether it is contextual or other type of advertising, and, where applicable, the main profiling criteria used; it should also inform the recipient about any means available for them to change such criteria. The requirements of this Regulation on the provision of information relating to advertising is without prejudice to the application of the relevant provisions of Regulation (EU) 2016/679, in particular those regarding the right to object, automated individual decision-making, including profiling, and specifically the need to obtain consent of the data subject prior to the processing of personal data for targeted advertising. Similarly, it is without prejudice to the provisions laid down in Directive 2002/58/EC in particular those regarding the storage of information in terminal equipment and the access to information stored therein. Finally, this Regulation complements the application of the Directive 2010/13/EU which imposes measures to enable users to declare audiovisual commercial communications in user-generated videos. It also complements the obligations for traders regarding the disclosure of commercial communications deriving from Directive 2005/29/EC.

## Case law

### EWCA - Dawson-Damer v Taylor Wessing LLP

*Source: EWCA, 2026-07-17 — https://overview.legal/posts/125652 — original: https://gdprhub.eu/index.php?title=EWCA_-_Dawson-Damer_v_Taylor_Wessing_LLP*

Facts — This case concerns a data subject access request (SAR) under the Data Protection Act (DPA) 1998. The data subjects were beneficiaries under a trust. The data controller was a firm of solicitors, holding trust money as trustees. Following the appointment of further trustees and transfer of trust money into a new trust for other discretionary beneficiaries, the data subjects challenged the validity of these appointments and served the data controller with a SAR under section 7(2) DPA 1998. The data controller refused to make the disclosure, stating that the personal data was covered by Legal Professional Privilege (LPP), and therefore exempted from disclosure under Schedule 7 para. 10 DPA 1998. Furthermore, the data controller asserted that the supply of information required a disproportionate effort. The data subjects contended that many categories of personal data held by the data controller were not privileged and that, if any, the only privilege on which the data controller could rely was litigation privilege. The data subjects applied to the court for a declaration under section 7(9) DPA 1998 that the data controller had not complied with the request and to oblige the data controller to comply with the SAR. At trial, the court agreed with the data controller and refused to make such an order. The appellate court had to determine: whether, taking a narrow view, the LLP exception is limited to documents subject only to legal professional privilege under English law; whether, if the narrow view is correct, any further search would involve "disproportionate effort" for the purposes of section 8(2) DPA 1998 so that the data controller is excused from doing so; whether the exercise of the court’s discretion under section 7(9) DPA 1998 can be refused because the data subject's real motive was to use the information in legal proceedings against the data controller. Holding — The Court of Appeal held that 'privilege' in the LLP exception is limited to legal professional privilege. It falls to the data controller to show that the supply of a copy of the information in permanent form would involve disproportionate effort. The High Court judge was wrong not to exercise its discretion under section 7(9) DPA 1998 to order the data controller to comply with the request. On Issue 1 - Extent of the Legal Professional Privilege Exception: The purpose of Directive 95/46/EC (the Directive) was to regulate the activities of data controllers on a territorial basis. Therefore, the words "legal proceedings" in sched. 7 para. 10 DPA 1998 refer to legal proceedings in any part of the UK. If Parliament had intended to legislate for events which occur outside the territory of the UK, it would have introduced provisions specifying which parts of the world were relevant for this purpose and under which conditions the privilege applied. The LPP exception is expressly limited to legal professional privilege. Documents not disclosable to a beneficiary of a trust under trust law principles are not within the LPP exception. Insofar as the exception was interpreted purposively as also including documents covered by the trustees' right of non-disclosure, the Directive would have to name appropriate objectives which could support an interpretation along these lines. However, the DPA does not contain such exceptions. The court concluded at para. 45 that the LPP exception “relieves the data controller from complying with a SAR only if there is relevant privilege according to the law of any part of the UK.” Since the data in question is not covered by the LPP under English law and no other exemption under the DPA 1998 applies, the SAR must be granted. On Issue 2 - Whether compliance with the request would involve disproportionate effort: The public interest reasons set out in the Directive for giving people control over the data held about them require that SARs should be enforced so far as possible. Under section 8(2) DPA 1998 the data controller is obliged to supply copies of information constituting personal information to the data subject, "unless …the supply of such a copy is not possible or would involve disproportionate effort." The effort, the data controller undertakes must be weighed in a proportionality exercise against the potential benefits that the provision of the information could bring to the data subject. That includes the possibility that there may be limits to a search in certain circumstances, see Ezsias v Welsh Ministers [2007] EWHC B15 (QB). The court held at para. 75 ff, that “It falls to the data controller to show that the supply of a copy of the information in permanent form would involve disproportionate effort”. However, “disproportionate effort must involve more than an assertion that it is too difficult to search through voluminous papers”. The data controller “must produce evidence to show what it has done to identify the material and to work out a plan of action.” On Issue 3 - Whether the request can be declined because the data subject intended to use the information against the data controller: The purpose of the Directive is to protect fundamental rights conferred by EU law. The court found that nothing in Directive or the DPA 1998 limits the purpose for which data subjects may request their data or allows data controllers not to provide data based solely on the on the basis of the purpose of the data subject. Also, Parliament has not expressly required data subjects to show that they have no other purpose. The court distinguished Dunn v Durham County Council [2003] 1 WLR 2305, Lin & Anor v Commissioner of Police of the Metropolis [2015] EWHC 2484 and Kololo v Metropolitan Police Commissioner [2015] 1 WLR 3702. Durant v Financial Services Authority [2004] FSR 573 at para. 27 also does not establish a “no other purpose rule” and should only be interpreted to mean that “a person could not claim that something was personal data because it would assist him in obtaining discovery or in litigation or complaints against third parties.” (para. 111) The court found that the trial judge had wrongly refused to enforce the request just because the appellants intended to use the information obtained in other proceedings. The section 7(9) DPA 1998 discretion must be applied with a view to fulfilling the purposes of the DPA.

### Judgment of the Court (Grand Chamber) of 2 December 2025.#X v Russmedia Digital SRL and Inform Media Press SRL.#Request for a preliminary ruling from the Curtea de Apel Cluj.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 4(7) – Concept of ‘controller’ – Responsibility of the operator of an online marketplace for the publication of personal data contained in advertisements placed on its online marketplace by user advertisers – Article 5(2) –

*Source: Court of Justice of the European Union, C-492/23, 2025-12-02 — https://overview.legal/posts/132130 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0492*

In Case C-492/23, the Court of Justice of the European Union (Grand Chamber) addressed a preliminary reference from the Curtea de Apel Cluj concerning whether an online marketplace operator (Russmedia Digital SRL and Inform Media Press SRL) qualifies as a data "controller" under Article 4(7) GDPR for personal data contained in advertisements published by user advertisers. The Court examined the allocation of controller responsibility, including potential joint control with user advertisers, and analyzed whether the operator's obligations under Articles 5(2), 9, 24, 25, and 32 GDPR—including prior identification of sensitive data and advertisers, refusal of unlawful advertisements, and implementation of security measures—preclude reliance on the intermediary liability exemptions under Articles 12 to 15 of Directive 2000/31/EC (E-Commerce Directive). No fine was imposed, as the ruling is an interpretive preliminary reference rather than an enforcement action.

### Judgment of the General Court (Seventh Chamber, Extended Composition) of 19 November 2025.#Amazon EU Sàrl, venant aux droits de Amazon Services Europe Sàrl v European Commission.#Digital services – Regulation (EU) 2022/2065 – Designation as a very large online platform – Plea of illegality – Admissibility – Article 33(1) and (4) of Regulation 2022/2065 – Right to respect for private and family life – Freedom to conduct a business – Right to property – Equal treatment – Freedom of expression – Da

*Source: General Court, T-367/23, 2025-11-19 — https://overview.legal/posts/132131 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023TJ0367*

Amazon EU Sàrl challenged the European Commission's decision designating Amazon Store as a very large online platform under Article 33(4) of the Digital Services Act (Regulation 2022/2065), raising pleas alleging the illegality of Articles 33(1), 38, and 39 of the regulation on grounds including violations of fundamental rights to privacy, freedom to conduct a business, property, equal treatment, and freedom of expression. The General Court (Seventh Chamber, Extended Composition) ruled on the admissibility of the plea challenging Article 33(1), finding that the application's scope was sufficiently clear and precise to permit assessment of its merits, thereby rejecting the Council's argument that the plea was inadmissible for lack of clarity.

### Judgment of the Court (First Chamber) of 13 November 2025.#Inteligo Media SA v Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP).#Request for a preliminary ruling from the Curtea de Apel Bucureşti.#Reference for a preliminary ruling – Processing of personal data and the protection of privacy in the electronic communications sector – Directive 2002/58/EC – Article 13(1) and (2) – Unsolicited communications – Concept of communication ‘for the purposes of di

*Source: Court of Justice of the European Union, C-654/23, 2025-11-13 — https://overview.legal/posts/132132 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0654*

The Court of Justice of the European Union ruled on a preliminary reference from the Romanian Curtea de Apel Bucureşti in proceedings between Inteligo Media SA and the Romanian DPA (ANSPDCP) concerning the scope of "direct marketing" and the customer-relationship exception under Article 13 of the ePrivacy Directive (Directive 2002/58/EC) in relation to GDPR Article 6. The case addressed whether a daily newsletter sent to users who registered on an online platform to access additional content qualifies as a communication "for the purposes of direct marketing" and whether the platform registration constitutes obtaining contact details "in the context of the sale of a product or a service" under Article 13(2). The Court's ruling clarifies the interplay between the ePrivacy Directive's specific consent regime for unsolicited communications and the GDPR's general lawfulness requirements, with the underlying national proceedings involving an administrative penalty imposed by ANSPDCP for processing customers' personal data without consent.

### Judgment of the Court (First Chamber) of 4 September 2025.#European Data Protection Supervisor v Single Resolution Board.#Appeal – Protection of natural persons with regard to the processing of personal data – Procedure for granting compensation to shareholders and creditors of a banking institution following the resolution of that institution – Decision of the European Data Protection Supervisor finding that the Single Resolution Board failed to fulfil its obligations relating to the processing

*Source: Court of Justice of the European Union, C-413/23, 2025-09-04 — https://overview.legal/posts/132136 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0413*

The European Data Protection Supervisor (EDPS) appealed a General Court judgment that annulled its decision finding the Single Resolution Board (SRB) had failed to fulfil its obligations under Regulation (EU) 2018/1725 regarding the processing of personal data in a banking resolution compensation procedure. The core legal issues concerned whether pseudonymised data transmitted to a third party constitutes "personal data" under Article 3(1), the proper interpretation of "pseudonymisation" under Article 3(6), and the scope of the controller's obligation to inform data subjects under Article 15(1)(d). The Court of Justice (First Chamber) ruled on these interpretive questions in deciding whether to set aside the General Court's judgment.

### Judgment of the General Court (Seventh Chamber, Extended Composition) of 3 September 2025.#Zalando SE v European Commission.#Digital services – Regulation (EU) 2022/2065 – Designation of a very large online platform – Plea of illegality – Article 33(1) and (4) of Regulation 2022/2065 – Legal certainty – Equal treatment – Proportionality – Obligation to state reasons.#Case T-348/23.

*Source: General Court, T-348/23, 2025-09-03 — https://overview.legal/posts/132138 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023TJ0348*

In Case T-348/23, Zalando SE challenged the European Commission's April 2023 decision designating it as a very large online platform (VLOP) under the Digital Services Act (Regulation 2022/2065), arguing that its average monthly active recipients should be calculated based only on its third-party marketplace (Partner Programm) rather than its total user base. The General Court dismissed the action, upholding the Commission's determination that the concept of "active recipient" encompasses all users exposed to information on the platform, including those browsing first-party retail offerings alongside third-party seller products, and that Zalando's reported 83.3 million average monthly active recipients properly exceeded the 45 million threshold for VLOP designation. No fine was imposed in this proceeding.

### Judgment of the Court (First Chamber) of 27 February 2025.#CK v Magistrat der Stadt Wien.#Request for a preliminary ruling from the Verwaltungsgericht Wien.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 15(1)(h) – Automated decision-making, including profiling – Scoring – Assessment of the creditworthiness of a natural person – Access to meaningful information about the logic involved in profiling – Verification of the accuracy of the infor

*Source: Court of Justice of the European Union, C-203/22, 2025-02-27 — https://overview.legal/posts/132146 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0203*

In Case C-203/22, the Court of Justice of the European Union interpreted Article 15(1)(h) of the GDPR in response to a preliminary ruling from the Verwaltungsgericht Wien concerning an individual's request for meaningful information about the logic of creditworthiness scoring conducted by Dun & Bradstreet Austria GmbH. The Court held that data subjects must receive sufficiently detailed explanations of the logic involved in automated profiling to understand how the decision was reached, while controllers may withhold information protected by trade secrets under Directive (EU) 2016/943 only insofar as such withholding does not render the information provided meaningless. The Court further clarified that data subjects may not use access rights to obtain personal data of third parties or to verify the absolute accuracy of the underlying information processed.

### Judgment of the Court (Fifth Chamber) of 13 February 2025.#Criminal proceedings against ILVA A/S.#Request for a preliminary ruling from the Vestre Landsret.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 83(4) to (6) and (9) – Concept of an ‘undertaking’ – Parent company and subsidiary – Infringement of that regulation by a subsidiary – Calculation of the amount of the fine – Consideration of the total turnover of the group of which that sub

*Source: Court of Justice of the European Union, C-383/23, 2025-02-13 — https://overview.legal/posts/132149 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0383*

The Court of Justice of the European Union ruled on a preliminary reference from the Danish High Court in criminal proceedings against ILVA A/S, addressing whether the GDPR concept of "undertaking" under Article 83 permits calculating administrative fines based on the total worldwide annual turnover of a corporate group when a subsidiary commits the infringement. The Court held that "undertaking" must be interpreted consistently with EU competition law, meaning a subsidiary and its parent company may constitute a single undertaking where the parent exercises decisive influence over the subsidiary, and therefore the fine may be calculated based on the group's total consolidated turnover. No fine amount was specified in this ruling, as the Court's judgment clarifies the legal framework for fine calculation rather than imposing a specific penalty.

### Judgment of the Court (First Chamber) of 9 January 2025.#Österreichische Datenschutzbehörde v F R.#Request for a preliminary ruling from the Verwaltungsgerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 57(1)(f) and Article 57(4) – Tasks of the supervisory authority – Concepts of a ‘request’ and ‘excessive requests’ – Charging of a reasonable fee or refusal to act on requests in the e

*Source: Court of Justice of the European Union, C-416/23, 2025-01-09 — https://overview.legal/posts/132153 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0416*

In Case C-416/23, the Court of Justice of the European Union (First Chamber) ruled on a preliminary reference from the Austrian Supreme Administrative Court concerning the Austrian Data Protection Authority's (DSB) refusal to act on a complaint from individual F R regarding an alleged infringement of his right of access. The Court interpreted Article 57(4) and Article 77(1) of the GDPR, addressing the concepts of a "request" and "excessive requests" and the criteria guiding a supervisory authority's choice between charging a reasonable fee or refusing to act on manifestly unfounded or excessive requests. No fine was imposed, as the ruling solely provides interpretive guidance on the supervisory authority's tasks and obligations under the GDPR.

### Judgment of the General Court (Sixth Chamber, Extended Composition) of 8 January 2025.#Thomas Bindl v European Commission.#Processing of personal data – Protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies – Regulation (EU) 2018/1725 – Concept of ‘transfer of personal data to a third country’ – Transfer of data when visiting a website – EU Login – Action for annulment – Act not open to challenge – Inadmissibility – A

*Source: General Court, T-354/22, 2025-01-08 — https://overview.legal/posts/132155 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022TJ0354*

In Case T-354/22, Thomas Bindl sought annulment of alleged personal data transfers to third countries by the European Commission when visiting the Conference on the Future of Europe website, a declaration of failure to act on his information request, and EUR 1,200 in damages for non-material harm under Regulation (EU) 2018/1725. The General Court found the annulment action inadmissible as the alleged transfers did not constitute a challengeable act, declared there was no need to adjudicate the failure-to-act claim since the Commission had subsequently responded, and dismissed the damages claim for lack of a sufficiently serious breach and causal link. No fine was imposed.

### Judgment of the Court (Third Chamber) of 28 November 2024.#Nemzeti Adatvédelmi és Információszabadság Hatóság v UC.#Request for a preliminary ruling from the Kúria.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data and the free movement of such data – Regulation (EU) 2016/679 – Data processed when drawing up a COVID-19 certificate – Data not collected from the data subject – Information to be provided – Exception to the obligation t

*Source: Court of Justice of the European Union, C-169/23, 2024-11-28 — https://overview.legal/posts/132158 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0169*

In Case C-169/23, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Kúria (Hungary) concerning whether the Budapest Metropolitan Government Office, as controller issuing COVID-19 immunity certificates, was required to provide information to data subjects under Article 14 GDPR where the personal data was not collected directly from them. The Court held that data generated by the controller in the context of its own processes falls within the Article 14(5)(c) exemption from the obligation to provide information, provided that Member State law ensures appropriate measures to protect the data subject's legitimate interests, including data security measures under Article 32. The Court also confirmed that supervisory authorities retain competence to handle complaints under Article 77(1) even where the Article 14(5)(c) exemption applies.

### Judgment of the Court (First Chamber) of 4 October 2024.#Agentsia po vpisvaniyata v OL.#Request for a preliminary ruling from the Varhoven administrativen sad.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Publication in the commercial register of a company’s constitutive instrument containing personal data – Directive (EU) 2017/1132 – Non-compulsory personal data – Lack of consent of the data subjec

*Source: Court of Justice of the European Union, C-200/23, 2024-10-04 — https://overview.legal/posts/132161 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0200*

The Court of Justice of the European Union (First Chamber) ruled on a preliminary reference from the Bulgarian Supreme Administrative Court in a dispute between the Agentsia po vpisvaniyata (Registration Agency) and OL concerning the Agency's refusal to erase personal data contained in a company's constitutive instrument published in the commercial register. The Court held that non-compulsory personal data included in company documents under Directive (EU) 2017/1132 does not qualify as processing necessary for compliance with a legal obligation under GDPR Article 6(1)(c), and where no other valid legal basis applies (such as consent under Article 6(1)(a)), the data subject is entitled to erasure under Article 17; furthermore, publication of such data without a valid legal basis may constitute non-material damage compensable under Article 82, though the existence and amount of any compensation depends on national court assessment of the actual harm suffered. No fine was imposed, as this was a preliminary ruling proceeding.

## Guidance

### Report on stakeholder event on anonymisation and pseudonymisation of 12 December 2025

*Source: EDPB, report-on-stakeholder-event-on-anonymisation-and-en, 2026-02-18 — https://overview.legal/posts/125688 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/report-on-stakeholder-event-on-anonymisation-and_en*

Report on stakeholder event on anonymisation and pseudonymisation of 12 December 2025 1. Background The EDPB organise d a remote stakeholder event on 12 December 2025 to collect stakeholders’ input on anonymisation and pseudonymisation , following the Court of Justice of the European Union ( “ CJEU ” ) judgment in case EDPS v SRB 1 . The objective was to engage with stakeholders to inform the EDPB’s ongoing work on its guidelines 01/2025 on pseudonymisation and f orthcoming guidelines on…

### Statement 5/2024 on the Recommendations of the High-Level Group on Access to Data for Effective Law Enforcement

*Source: EDPB, statement-52024-on-the-recommendations-of-the-high-level-en, 2024-11-04 — https://overview.legal/posts/125706 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-52024-on-the-recommendations-of-the-high-level_en*

Statement 5/2024 on the Recommendations of the High - Level Group on Access to Data for Effective Law Enforcement Adopted on 4 November 2024 The European Data Protection Board has adopted the following statement: In June 2023 the High - Level Group on Access to Data for Effective Law Enforcement (‘HLG’) was launched by the Presidency of the Council and the European Commission to explore “ challenges that law enforcement practitioners in the Union face in their daily work in connection to access…

### Opinion 22/2024 on certain obligations following from the reliance on processor(s) and sub-processor(s)

*Source: EDPB, opinion-222024-on-certain-obligations-following-from-the-en, 2024-10-09 — https://overview.legal/posts/125715 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-222024-on-certain-obligations-following-from-the_en*

A dopted 1 Opinion 22/2024 on certain obligations following from the reliance on processor(s) and sub - processor(s) Adopted on 7 October 2024 Adopted 2 Executive summary The Danish SA requested the EDPB to issue an opinion on matters of general application pursuant to Article 64(2) GDPR. The opinion contributes to a harmonised interpretation by the national supervisory authorities of certain aspects of Article 28 GDPR, whe re appropriate in conjunction with Chapter V GDPR. In particular, the…

### EU-US Data Privacy Framework FAQ for European individuals

*Source: EDPB, eu-us-data-privacy-framework-faq-for-european-individuals-en, 2024-07-16 — https://overview.legal/posts/125730 — original: https://www.edpb.europa.eu/documents/other-guidance/eu-us-data-privacy-framework-faq-for-european-individuals_en*

Adopted EU - U.S. DATA PRIVACY FRAMEWORK F.A.Q. FOR EUROPEAN INDIVIDUALS 1 Adopted on 16 July 2024 1 In this context, European individuals means any natural person, regardless of their nationality, whose personal data have been transferred to a U . S . company under the EU - U . S . Data Privacy Framework . A dopted 2 A dopted 3 Q1. WHAT IS THE EU - U.S. DATA PRIVACY FRAMEWORK? The EU - U.S. Data Privacy Framework (“DPF”) is a self - certification mechanism for companies in the U.S. The…

### EU-US Data Privacy Framework FAQ for European businesses

*Source: EDPB, eu-us-data-privacy-framework-faq-for-european-businesses-en, 2024-07-16 — https://overview.legal/posts/125734 — original: https://www.edpb.europa.eu/documents/other-guidance/eu-us-data-privacy-framework-faq-for-european-businesses_en*

Adopted EU - U.S. DATA PRIVACY FRAMEWORK F.A.Q. FOR EUROPEAN BUSINESSES 1 Adopted on 16 July 2024 1 In this context, European businesses refer to businesses in the EEA, which transfer or may transfer personal data to companies in the U.S. certified under the DPF. Adopted 2 Adopted 3 Q1. WHAT IS THE EU - U.S . DATA PRIVACY F RAMEWORK? The EU - U.S. Data Privacy Framework (“DPF”) is a self - certification mechanism for companies in the U.S. Companies that have self - certified under the DPF must…

### Guidelines 01/2023 on Article 37 Law Enforcement Directive

*Source: EDPB, guidelines-012023-on-article-37-law-enforcement-directive-en, 2024-06-19 — https://overview.legal/posts/125738 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-012023-on-article-37-law-enforcement-directive_en*

Adopted 1 Guidelines 0 1 / 2023 on Article 37 Law Enforcement Directive V ersion 2 . 1 Adopted on 19 June 2024 Adopted 2 Version history Version 1.0 27 September 2023 Adoption of the Guidelines for public consultation Version 2.0 19 June 2024 Adoption of the Guidelines after public consultation Version 2.1 30 September 2024 Minor corrections in footnotes 10 and 57 Adopted 3 Executive summary These guidelines provide guidance on the application of Article 37 LED, in particular on the legal…

### EDPB Annual Report 2023

*Source: EDPB, edpb-annual-report-2023-en, 2024-04-23 — https://overview.legal/posts/125756 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-annual-report-2023_en*

EDPB Annual Report 2023 1 2023 ANNUAL REPORT SAFEGUARDING INDIVIDUALS' DIGITAL RIGHTS 2 FOREWORD 4 HIGHLIGHTS 2023 6 1. THE EDPB SECRETARIAT 8 1.1. MISSION AND ACTIVITIES IN 2023 9 1.2. RE-ORGANISING THE SECRETARIAT IN 2023 12 2. EUROPEAN DATA PROTECTION BOARD - ACTIVITIES IN 2023 14 2.1. BINDING DECISIONS 14 2.2. CONSISTENCY OPINIONS 19 2.3. GENERAL GUIDANCE 21 2.3.1. Guidelines 03/2022 on deceptive design patterns in social media platform interfaces: how to recognise and avoid them 21 2.3.2.…

### Opinion 08/2024 on Valid Consent in the Context of Consent or Pay Models Implemented by Large Online Platforms

*Source: EDPB, opinion-082024-on-valid-consent-in-the-context-of-consent-or-en, 2024-04-17 — https://overview.legal/posts/125765 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-082024-on-valid-consent-in-the-context-of-consent-or_en*

A dopted 1 Opinion 08/2024 on Valid Consent in the Context of Consent or Pay Models Implemented by Large Online Platforms Adopted on 17 April 2024 Adopted 2 Adopted 3 Executive summary The Dutch, Norwegian and German (Hamburg) supervisory authorities requested the EDPB to issue an opinion on the question of under which circumstances and conditions ’consent or pay’ models relating to behavioural advertising can be implemented by large online platforms in a way that constitutes valid, and in…

## Enforcement decisions

### CNIL (France) - SAN-2020-013

*Source: CNIL (France), 2020-12-07 — https://overview.legal/posts/125659 — original: https://gdprhub.eu/index.php?title=CNIL_(France)_-_SAN-2020-013*

Facts — Between December 2019 and May 2020, the CNIL conducted three online and one on-site investigations on Amazon Europe Core (AEC), a subsidiary company of the Amazon group operating the shopping site amazon.fr. These investigations aimed at assessing the company's compliance with the French data protection law. The French DPA reported several infringements of the data protection law by AEC when placing cookies. The company responded by contesting the competence of the CNIL on this matter due to the fact that its main establishment is located in Luxembourg and by challenging the legality of the investigation procedure. Dispute — Is the French DPA competent to sanction a company whose main establishment is not located in France? Does the investigation procedure of the CNIL infringes with the right to a fair trial as guaranteed by Article 6 of the European Convention for the Protection of Human Rights and Fundamental Freedoms? Did AEC infringe on the French data protection law by placing cookies on the user's computer prior to any action on its part? Did AEC failed to properly inform the user of its use of cookies? Holding — The CNIL considered itself competent to investigate AEC and ruled that the company infringed on the French data protection law and on the Directive 2002/58/EC (ePrivacy) while placing cookies. As a consequence, the CNIL imposed a € 35000000 fine on AEC, coupled with an injunction to comply with the Law within three months with a € 100000 penalty per overdue day. Due to the seriousness of the wrongdoings and the high number of Amazon services' users, the CNIL decided to make this sanction publicly available for a two year period. On the territorial competence of the CNIL — AEC argued that the French DPA is not competent to investigate on its activity due to the one-stop-shop principle of GDPR. To support this claim, AEC higlights that the CNIL's investigation initial purpose was, among other things, to ensure that the company complied with GDPR, meaning that the sanction could only be given by the authority relevant to the main establishment of the company in the EU. Furthermore, AEC argued that even though the investigation dealt with cookies which are regulated by the Directive ePrivacy, cookies cannot be dissociated from personal data processing, meaning that the GDPR rules on national competence should prevail. The CNIL rejected this interpretation and deemed itself competent as it was not only investigating GDPR infringements but also breaches of the Directive ePrivacy, transcribed into French law. It reminded that GDPR and ePrivacy each had their own investigating procedure when dealing with their respective requirements. Also, it clarifies that ePrivacy applies as a specialia generalibus derogant rule, based on the interpretation of Article 95 GDPR in the line of the Rec (173) GDPR and Article 1(2) and 15a of the ePrivacy Directive. The CNIL added that the investigation focused on the amazon.fr website targeting french customers. On the legality of the investigation procedure — Regarding the legality of the procedure, AEC accuses the investigating party of submitting the company to questions without telling the purpose and legal basis of the controls carried out. This meant that the company could not exercise its right not to contribute to its own indictment . AEC also argued that the investigating party's method, involving reproducing a user's path was inaccurate as it did not allow to differentiate between Amazon's cookies and the ones placed by third parties when visiting other websites. The CNIL responded by quoting Article 18 of the French data protection law which states that the investigated body has to answer to the CNIL's questions without the CNIL having to justify them and that at the time of those questions no accusation was being made against AEC. Regarding the investigation method, the CNIL argued that it reproduced several user's path in order to determine which cookies were placed when visiting the Amazon website and that it excluded from the perimeter of the investigation those that originated from a third party website. As such, the CNIL considers its investigation procedure to be licit. On the placement of cookies prior to any action from the user — While investigating, the CNIL noticed that more than 40 cookies for commercial purposes were placed on the user's device prior to any act of consent from its part. AEC responded that its cookie practice is subject to the Luxembourg law and not the French law and that Luxembourg allowed to base the consent on the cookie parameters of the web browser. The company added that it changed its french cookie policy in September 2020, but affirmed that it never infringed on the Luxembourg law on cookies. The CNIL rejected this argumentation, considering that the website targeted french customers, and that cookies for commercial purposes always require consent from the data subject as they are not part of the exemptions listed in Article 5(3) of the Directive ePrivacy transcribed in Article 82 of the French data protection law. On the information of the user regarding cookies — The amazon.fr website displayed the following notice regarding cookies: "By using this site, you agree to os ar use of cookies to provide and improve our services. Further information" The DPA found that this wording is not sufficient in order to comply with the transparency principle as it did not provide the data subject with any information on how to exercise its rights or oppose cookies. It added that the expression "to provide and improve our services" does not inform the user of the commercial purposes of some cookies. Finally, the CNIL reminded Amazon that it had already pronounced several sanctions on insufficient information regarding cookies.

### ICO (UK) - KRA Consultancy Ltd

*Source: ICO (UK), 2026-05-20 — https://overview.legal/posts/53105 — original: https://gdprhub.eu/index.php?title=ICO_(UK)_-_KRA_Consultancy_Ltd*

Facts — The Information Commissioner, the DPA, investigated KRA Consultancy Ltd, the controller, in relation to unsolicited direct marketing SMS messages promoting debt-related services. The case was initially connected to investigations into other companies and individuals involved in mass SMS marketing. During these investigations, the DPA identified links between the controller, debt advice websites, bulk SMS platforms, short URLs and complaints submitted by subscribers to the 7726 spam reporting service. The controller was found to have used different trading names, websites and bulk messaging services to send large volumes of SMS messages to subscribers. These messages promoted debt write-off or debt solution services and invited recipients to click links leading to websites operated by, or connected to, the controller. The DPA also found evidence that the controller used personal data obtained from loan decline datasets and other third-party sources. The controller did not demonstrate that the subscribers had provided valid consent to receive marketing SMS messages about debt solutions. The DPA further found that the controller used so-called “fake bailiff messages” to pressure individuals into responding. These messages suggested that enforcement agents or bailiffs would attend the recipient’s address. The DPA considered that these messages targeted financially vulnerable individuals and were likely to cause distress. During the investigation, the DPA executed search warrants and seized electronic devices. The evidence included WhatsApp messages, SMS messages, access to bulk SMS platforms, customer communications, call recordings and internal group chats. These showed that the controller was involved in the transmission or instigation of the SMS messages and had sought to make the messages difficult to trace. Holding — The DPA held that the controller infringed Regulation 22 PECR by transmitting or instigating the transmission of unsolicited direct marketing SMS messages without valid consent. The DPA found that, between 24 April 2022 and 29 May 2025, 5,575,715 direct marketing SMS messages were delivered by, or at the instigation of, the controller. These messages generated over 60,000 complaints to the 7726 spam reporting service. The DPA considered that the controller could not rely on valid consent. Consent under PECR must meet the UK GDPR standard, meaning that it must be freely given, specific, informed and unambiguous. The DPA found no evidence that the subscribers had specifically consented to receive marketing from the controller. The use of old or purchased datasets, and the absence of adequate due diligence, did not meet the required standard. The DPA also held that the controller infringed Regulation 23 PECR. The controller had concealed its identity by using generic trading names, anonymous websites and messaging services designed to make the SMS activity untraceable. The DPA considered this conduct especially serious because recipients were not properly informed of who was behind the marketing communications. The DPA found that the infringement was serious due to the very high volume of messages, the number of complaints and the nature of the marketing. It also found that the infringement was deliberate. The controller had obtained loan decline data, failed to verify consent, used fake bailiff messages and sought repeated assurances that the messages could not be traced. In the alternative, the DPA found that the controller was at least negligent. The controller knew or ought to have known about the risk of non-compliance, given the DPA’s public guidance on direct marketing and consent. The controller nevertheless failed to take reasonable steps to prevent the contraventions. As aggravating factors, the DPA considered that the controller concealed its identity, targeted financially vulnerable individuals, sent distressing fake bailiff messages, provided debt-related advice despite not being FCA-authorised, misled the DPA during the search warrant, obstructed the investigation and continued unlawful marketing activity after the warrant. The DPA found no mitigating factors. The DPA therefore issued a monetary penalty of £300,000. The penalty could be reduced to £240,000 if paid early and if no appeal was lodged.

### AKI (Estonia) - No. 2.1-1/24/397-890-38

*Source: AKI (Estonia), 2026-04-16 — https://overview.legal/posts/53882 — original: https://gdprhub.eu/index.php?title=AKI_(Estonia)_-_No._2.1-1/24/397-890-38*

Facts — OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic. On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had failed to provide all personal data requested. The controller only partially complied after several requests from the DPA. Although the DPA closed the part of the case concerning the access request, it continued investigating the controller’s processing of patients’ personal data when providing Invisalign treatment. The service required the controller to collect and transfer patients’ health data to Align Technology, Inc. However, the contractual documents did not clearly establish whether Align Technology acted as a processor, an independent controller or a joint controller. The controller stated that Align Technology largely determined the conditions of the service, including the consent form and the processing arrangements, and that individual clinics could not unilaterally amend these conditions. The DPA also found that the information provided to patients was incomplete and fragmented. The consent form and privacy information did not clearly explain the legal basis and purposes of processing, the parties involved, data recipients, retention periods, transfers outside the European Union or the safeguards applied to such transfers. Parts of the information were only available in English on external websites. Holding — The DPA held that the controller had failed to demonstrate that the processing carried out in connection with the Invisalign service was lawful and transparent under Articles 5(1)(a) and 5(2) GDPR. First, the DPA found that the parties’ roles had not been properly determined. Under Article 4(7) GDPR, the assessment had to be based on which party actually determined the purposes and means of processing, rather than solely on the contractual description of the relationship. The controller decided whether Invisalign treatment was suitable for a patient and collected the relevant health data. It therefore acted as a controller in relation to the treatment. However, Align Technology exercised significant control over the subsequent processing, including the data collected, the recipients, retention arrangements, the use of other service providers and transfers outside the European Union. The DPA therefore considered that Align Technology could not simply be regarded as a processor acting only on documented instructions under Article 28(3)(a) GDPR. On the available evidence, it was at least a joint controller under Article 26 GDPR. The DPA ordered the controller to review the contractual relationship. If Align Technology acted as a processor, the agreement had to comply with Article 28 GDPR, including the requirements concerning subprocessors under Article 28(2). If the parties were joint controllers, they had to allocate their respective responsibilities under Article 26 GDPR. Second, the DPA found that the consent obtained from patients was invalid. The consent form did not provide sufficient information for patients to understand the processing and therefore did not meet Articles 4(11), 6(1)(a), 7 and 9(2)(a) GDPR. The DPA also noted that healthcare processing may, depending on the operation concerned, rely on Article 6(1)(b) GDPR together with Article 9(2)(h) GDPR. However, the controller had not clearly identified the applicable legal bases for the different processing activities. The privacy information also failed to comply with Articles 12, 13 and 14 GDPR. Patients were required to consult several documents and external websites, some of which contained incomplete or inconsistent information. The controller had therefore not ensured that the information was easily accessible, understandable and available in Estonian. The DPA further referred to Article 25 GDPR when emphasising that the controller had to ensure that the processing arrangements and safeguards complied with the GDPR. Under Article 58(2)(d) GDPR and § 56(1) of the Estonian Personal Data Protection Act, the DPA ordered the controller to clarify the parties’ roles, conclude an Article 26 arrangement or Article 28 agreement, amend the consent form and privacy policy, and publish the required information in Estonian. No administrative fine was imposed. However, failure to comply could result in a penalty payment of €1,000 for each unfulfilled point or subpoint of the order, imposed repeatedly until compliance.

### DHL PARCEL IBERIA, S.L.: Overtreding van de algemene principes voor gegevensverwerking.

*Source: Spanish Data Protection Authority (aepd), 2025-09-22 — https://overview.legal/posts/52075*

De Spaanse autoriteit voor gegevensbescherming (DPA) heeft DHL PARCEL IBERIA, S.L. een boete van 3.000 euro opgelegd. Het bedrijf had het privé telefoonnummer van de ontvanger op een pakket gedrukt, waardoor het zichtbaar was voor derden. De oorspronkelijke boete van 5.000 euro is verlaagd naar 3.000 euro vanwege de directe betaling en de erkenning van verantwoordelijkheid door het bedrijf.

### DHL PARCEL IBERIA, S.L.: Non-compliance with general data processing principles

*Source: Spanish Data Protection Authority (aepd), 2025-09-22 — https://overview.legal/posts/49001 — original: https://www.enforcementtracker.com/ETid-2886*

The Spanish DPA has imposed a fine of EUR 3,000 on DHL PARCEL IBERIA, S.L. The conroller printed the private phone number of the recipient on a parcel, making it visible to third parties. The original fine of EUR 5,000 was reduced to EUR 3,000 due to immediate payment and admission of responsibility by the controller.

### IBERCAJA BANCO, S.A.: Overtreding van de algemene principes voor gegevensverwerking.

*Source: Spanish Data Protection Authority (aepd), 2025-06-20 — https://overview.legal/posts/52238*

De Spaanse autoriteit voor gegevensbescherming (DPA) heeft IBERCAJA BANCO, S.A. een boete van 42.000 euro opgelegd. Tijdens een bankoverboeking heeft de verantwoordelijke partij meer gegevens dan nodig doorgegeven aan de ontvanger van de betaling. De oorspronkelijke boete van 70.000 euro is verlaagd tot 42.000 euro vanwege de directe betaling en de erkenning van verantwoordelijkheid door de verantwoordelijke partij.

### IBERCAJA BANCO, S.A.: Non-compliance with general data processing principles

*Source: Spanish Data Protection Authority (aepd), 2025-06-20 — https://overview.legal/posts/48861 — original: https://www.enforcementtracker.com/ETid-2746*

The Spanish DPA imposed a fine of EUR 42,000 on IBERCAJA BANCO, S.A. During a bank transfer, the controller transmitted more data then necessary to the recipient of the payment. The original fine of EUR 70,000 was reduced to EUR 42,000 due to immediate payment and admission of responsibility by the controller.

### mBank: Insufficient fulfilment of data breach notification obligations

*Source: Polish National Personal Data Protection Office (UODO), 2024-08-20 — https://overview.legal/posts/48572 — original: https://www.enforcementtracker.com/ETid-2457*

The Polish DPA has fined mBank EUR 940,000. The bank had suffered a data breach in which an employee of the controller sent documents containing customer data to the wrong recipient. The documents contained information such as names, account numbers, dates of birth and ID card numbers. Although the documents were returned to mBank, the envelope had been opened , meaning that third parties may have had access to the documents. During its investigation, the DPA found that, although the controller

## Recent developments

### noyb takes Swedish tax authority to court for selling people’s personal data

*Source: noyb - European Center for Digital Rights, 2025-04-03 — https://overview.legal/posts/53158 — original: https://noyb.eu/en/noyb-takes-swedish-tax-authority-court-selling-peoples-personal-data*

Data Subject Rights In most countries, the government knows when you were born, your social security number, where you live, how much you earn and how much your house is worth. Sweden is a bit different though. There, the tax authority doesn’t just use this information for administrative purposes – but sells it to data brokers who publish it online. This is a violation of EU law. Earlier this year, a Swedish data subject asked the country’s tax authority to stop selling his data. The country’s S

### Update on noyb’s 101 complaints on EU-US data transfers – only one country shines

*Source: noyb - European Center for Digital Rights, 2020-09-22 — https://overview.legal/posts/53345 — original: https://noyb.eu/en/update-noybs-101-complaints-eu-us-data-transfers*

Data Transfers Just over a month ago, noyb filed 101 complaints against several companies based in the EU/EEA because they continue to use Google Analytics and Facebook Connect on their websites – thereby transferring personal data to Google and Facebook in the US. According to the CJEU judgement of 16 July 2020, such data transfers are illegal because Google and Facebook are subject to US surveillance laws and must disclose data of European users to US intelligence services. Hardly any reaction

### Complaint: Amazon doesn’t allow baseline TLS security

*Source: noyb - European Center for Digital Rights, 2020-03-02 — https://overview.legal/posts/53371 — original: https://noyb.eu/en/complaint-amazon-doesnt-allow-baseline-tls-security*

Data Security Baseline email security missing. During their route to the recipient, emails are handled by different entities, nodes and service providers which may intercept, manipulate and unlawfully use the content. In order to reduce these risks, it is a baseline industry standard to use so-called TLS encryption. View complaint (PDF) “TLS is like an envelope around a letter. If not used, anyone can read the content of an email in transfer.” Stefano Rossetti, privacy lawyer at noyb Surprisingl

### Unprecedented appearance by European Commissioner for Home Affairs, innovating on quicksand, and the cabinet vs. online confidentiality

*Source: European Digital Rights, 2023-03-29 — https://overview.legal/posts/6225 — original: https://edri.org/our-work/unprecedented-appearance-by-european-commissioner-for-home-affairs-innovating-on-quicksand-and-the-cabinet-vs-online-confidentiality/#entry-4247*

> 
					Read through the most interesting developments at the intersection of human rights and technology from the Netherlands. This is the second update in this series.

### De Autoriteit Persoonsgegevens publiceert een rapport over de risicoanalyse van de AVG (Algemene Verordening Gegevensbescherming).

*Source: AEPD, 2022-10-11 — https://overview.legal/posts/51791*

De GDPR-risicoanalyse is bedoeld om controllers en verwerkers te helpen bij het identificeren van de risicofactoren voor de rechten en vrijheden van de betrokkenen, wiens gegevens worden verwerkt. Het doel is om een eerste inschatting te maken van het inherente risico, inclusief de noodzaak om een Privacy Impact Assessment (DIA) uit te voeren, en om het resterende risico te schatten als maatregelen en beveiligingsmechanismen worden gebruikt om specifieke risicofactoren te verminderen.

## Literature

### PROTECTION OF DATA SUBJECT RIGHTS IN THE TRANSFER OF PERSONAL DATA BETWEEN DATA CONTROLLERS IN INDONESIA: A COMPARATIVE ANALYSIS OF THE PDP LAW AND THE EU GDPR

*Source: Awang Long Law Review, 2026-01-16 — https://overview.legal/posts/132506 — original: https://doi.org/10.56301/awl.v8i2.1827*

The rapid digital transformation and growth of e-commerce in Indonesia have triggered a high volume of personal data transfers between controllers. while Article 55 of the Personal Data Protection Law (UU PDP) provides only a general authorization without clear technical guidance, creating legal uncertainty and risks to data subject rights. This study analyzes the legal uncertainty of UU PDP’s regulation of controller-to-controller data transfers compared to the EU GDPR and proposes an accountab

### Artificial Intelligence in Decision-making: A Test of Consistency between the “EU AI Act” and the “General Data Protection Regulation”

*Source: Athens Journal of Law, 2025-01-02 — https://overview.legal/posts/132443 — original: https://doi.org/10.30958/ajl.11-1-3*

The recent Regulation that sets down harmonised rules on Artificial Intelligence in the European Union, known as the "AI Act," includes a significant requirement for human oversight in high-risk AI systems during their use (art. 14). This requirement embodies the "human-in-command" approach, ensuring both legal and ethical compliance. The AI Act is intended to complement the General Data Protection Regulation (hereinafter GDPR), thereby forming a consistent and comprehensive legal framework. Thi

### Understanding the GDPR from a requirements engineering perspective—a systematic mapping study on regulatory data protection requirements

*Source: Requirements Engineering, 2024-07-10 — https://overview.legal/posts/132590 — original: https://doi.org/10.1007/s00766-024-00423-4*

Abstract Data protection compliance is critical from a requirements engineering (RE) perspective, both from a software development lifecycle (SDLC) perspective and regulatory compliance. Not including these requirements from the early phases of the SDLC can prove costly and challenging afterward. The general data protection regulation (GDPR) from the European Union (EU) sets a list of requirements that organizations working within its scope should satisfy. However, these requirements are complex

### The data subject’s right to access to information under GDPR and the right of the data controller to protect its know-how

*Source: Przegląd Prawniczy Uniwersytetu im. Adam Mickiewicza, 2023-12-30 — https://overview.legal/posts/132546 — original: https://doi.org/10.14746/ppuam.2023.15.09*

The data subject’s right to access information on data processing has a very broad meaning. Considering the latest developments in this field (mainly the CJEU ruling on Austrian posts and EDPB guidelines) one can draw the conclusion that the controller’s right to protect its confidential in-formation is limited and less valuable than the data subject’s rights. However, this may lead to unfair and unequal treatment of companies and data subjects. When looking at this right in a more systematic pe

### Data Protection Regulation and International Arbitration: Can There Be Harmonious Coexistence (with the GDPR Requirements Concerning Cross-Border Data Transfer)?

*Source: Legal Issues in the Digital Age, 2021-07-27 — https://overview.legal/posts/132548 — original: https://doi.org/10.17323/2713-2749.2021.2.21.48*

Recent global trends are producing powerful growth in the digital environment, and its spread is prompting adoption of strict and comprehensive regulation to ensure data protection. This results in a number of difficulties, one of which is lack of consistency between data protection regulation and the regulatory regimes applicable to specific industries and institutions. That inconsistency is particularly evident in the field of international arbitration — one of the most widely used and conveni

## Tools

### Data Privacy Framework program — participant list

*Source: US Department of Commerce, 2026-07-17 — https://overview.legal/posts/125630 — original: https://www.dataprivacyframework.gov/list*

The official searchable list of US organisations self-certified under the EU-US Data Privacy Framework (the adequacy basis for EU→US transfers since 2023). Checking a recipient's active DPF status is the required first step before relying on the framework.

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities
- **Public Authority** — https://overview.legal/topics/overheid
  Government bodies and their data processing activities
- **Data Controller** — https://overview.legal/topics/verwerkingsverantwoordelijke
  The entity that determines purposes and means of processing personal data

---
Generated by overview.legal · https://overview.legal/topics/recipient · 2026-07-22
