# Religious Beliefs — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/religious-beliefs
> Sources are cited per item. Verify against the official texts before relying on them.

Processing of religious or philosophical beliefs

## Overview

## Legal Framework

Article 9(1) GDPR establishes a general prohibition on processing personal data revealing religious or philosophical beliefs. This sits within the broader framework of special category data under Chapter II, Section III of the predecessor Directive 95/46, now carried forward and expanded under the GDPR. The prohibition reflects the heightened risk of discrimination, reputational harm, and other significant social or economic disadvantage that Recital 75 associates with such processing.

The prohibition is not absolute. Article 9(2) GDPR enumerates ten specific exceptions, including explicit consent under Article 9(2)(a), processing necessary for substantial public interest under Article 9(2)(g), and processing carried out in the course of legitimate activities by foundations or non-profit bodies with a political, philosophical, religious, or trade-union aim, provided that processing relates solely to members or persons in regular contact and the data is not disclosed outside that body without consent under Article 9(2)(d). Each exception requires a corresponding lawful basis under Article 6 GDPR in addition to the Article 9 condition.

The AI Act adds a further layer. Recital 30 of the AI Act prohibits biometric categorisation systems that infer religious or philosophical beliefs from biometric data such as facial images or fingerprints. This prohibition targets systems that deduce beliefs from physiological characteristics rather than lawful sorting of biometric datasets by objective traits like hair or eye colour.

## Key Developments

The CJEU's reasoning in *GC and Others v CNIL* confirms that the Article 9 prohibition applies to data that reveals beliefs, whether directly or through inference, and that Member States must give effect to both the prohibition and its narrowly defined exceptions. In *Minister voor Immigratie v. M*, the Court clarified that an applicant's religion listed in an official minute constitutes personal data, while purely abstract legal analysis contained in the same document does not — drawing a practical line between factual data revealing belief and interpretive commentary that may incidentally reference it.

In *Meta Platforms v. noyb*, the Court reinforced that Article 9 applies squarely to platform processing where user data reveals religious or philosophical beliefs, underscoring that social media operators cannot circumvent the prohibition by characterising such data as merely incidental to broader profiling activities.

Enforcement has been robust. Dutch municipalities were fined for unlawfully processing information about Muslim individuals, demonstrating that public-sector controllers face the same Article 9 constraints as private entities. The Belgian DPA's fine against a researcher linked to EU DisinfoLab further illustrates that academic or research contexts do not automatically exempt controllers from Article 9 obligations.

## Practical Guidance

- **Establish dual lawful bases.** Identify both an Article 6 basis and an Article 9(2) condition before processing any data revealing religious beliefs. Absence of either renders the processing unlawful regardless of purpose.
- **Apply the "reveals" test rigorously.** Data need not explicitly state a belief to fall within Article 9. If inference from combined data points would reveal religious or philosophical beliefs — through profiling, aggregation, or contextual association — the prohibition applies, as confirmed in *GC and Others v CNIL*.
- **Audit biometric systems for inference capabilities.** Under AI Act Recital 30, any system that deduces beliefs from biometric data is prohibited. Controllers deploying biometric tools must verify they sort only by objective physical traits and do not infer protected characteristics.
- **Document the Article 9(2)(d) boundary for membership organisations.** Religious or philosophical foundations may process member data under this exception, but disclosure to third parties without consent breaches the condition. Maintain internal access controls reflecting this limit.
- **Conduct Data Protection Impact Assessments.** Recital 75 explicitly links special category processing to elevated risk of discrimination and social harm. Processing religious belief data requires a DPIA under Article 35(3)(b), documenting mitigation measures and demonstrating necessity and proportionality.

## Legislation (full text of key provisions)

### Recital 30 — prohibited biometric categorisation systems

*Source: AI Act, aiact-rec-30-en, 2024-06-12 — https://overview.legal/posts/93742*

Biometric categorisation systems that are based on natural persons’ biometric data, such as an individual person’s face or fingerprint, to deduce or infer an individuals’ political opinions, trade union membership, religious or philosophical beliefs, race, sex life or sexual orientation should be prohibited. That prohibition should not cover the lawful labelling, filtering or categorisation of biometric data sets acquired in line with Union or national law according to biometric data, such as the sorting of images according to hair colour or eye colour, which can for example be used in the area of law enforcement.

### Recital 75 — personal data processing risks to individuals

*Source: GDPR, gdpr-rec-75-en, 2016-04-27 — https://overview.legal/posts/91665*

The risk to the rights and freedoms of natural persons, of varying likelihood and severity, may result from personal data processing which could lead to physical, material or non-material damage, in particular: where the processing may give rise to discrimination, identity theft or fraud, financial loss, damage to the reputation, loss of confidentiality of personal data protected by professional secrecy, unauthorised reversal of pseudonymisation, or any other significant economic or social disadvantage; where data subjects might be deprived of their rights and freedoms or prevented from exercising control over their personal data; where personal data are processed which reveal racial or ethnic origin, political opinions, religion or philosophical beliefs, trade union membership, and the processing of genetic data, data concerning health or data concerning sex life or criminal convictions and offences or related security measures; where personal aspects are evaluated, in particular analysing or predicting aspects concerning performance at work, economic situation, health, personal preferences or interests, reliability or behaviour, location or movements, in order to create or use personal profiles; where personal data of vulnerable natural persons, in particular of children, are processed; or where processing involves a large amount of personal data and affects a large number of data subjects.

## Case law

### Supreme Court upholds €300,000 fine against INPS for GDPR violations in COVID bonus data

*Source: Supreme Court, 2026-05-21 — https://overview.legal/posts/53097 — original: https://gdprhub.eu/index.php?title=Cass.Civ._-_15625/2026*

Facts — Istituto nazionale della previdenza sociale (INPS, the controller) is the Italian National Institute for Social Security. In 2021, the DPA fined the controller €300,000 for its data processing activities linked to a subsidy given during the pandemic (also called “the COVID bonus”). The DPA found that the controller had postponed its second screening of verifying the eligibility of data subjects to a later stage, on the grounds that there was a need to immediately pay the subsidy. The controller considered that politicians did not fall under the scope of eligible data subjects, as they were already enrolled in a mandatory social security scheme. The controller processed their personal data from databases to cross reference them with data subjects who had applied for the subsidy. The DPA found a violation of several GDPR principles: the principle of lawfulness (Article 5(1)(a) GDPR), data minimisation (Article 5(1)(c) GDPR), accuracy (Article 5(1)(d) GDPR) and accountability (Articles 5(2) and 24 GDPR). According to the DPA, the controller had not limited the cross referencing to data subjects that had received the allowance, but to those whose applications had already been rejected. In addition, the DPA found a violation of Articles 25 and 35 GDPR, as the controller failed to conduct a data protection impact assessment (DPIA). The DPA ordered the controller to erase all personal data that had been processed unlawfully and to carry out a DPIA before resuming its processing activities. The controller appealed the decision to the Court of Rome, and argued that the DPA’s decision was unfounded. The court upheld the appeal and dismissed the DPA’s decision. The court considered that the controller had processed data subjects’ data lawfully, as it had limited the amount of data to what was necessary to verify data subjects’ eligibility. The court also considered that the processing posed a low risk for data subjects’ rights, as the data subjects’ names were not disclosed. The DPA appealed this decision to the court. Holding — The court dismissed the appeal. The court first stated that the controller processed the data lawfully under Article 6(1)(e) GDPR (public interest) and Article 6(3)(b) GDPR. While the controller processed data of specific data subjects (politicians), the court stated that national law allowed the controller to check the eligibility of all data subjects applying for the subsidy. The controller had also obtained the personal data through public databases provided by the Chambers of Parliament and Ministry of the Interior. The court also dismissed the DPA’s arguments on data minimisation (Article 5(1)(c) GDPR). The court stated that the principle of data minimisation is not absolute, and must be balanced with other interests at stake. The court took into consideration the fact that the data was publicly available and the need to quickly verify a high number of applications during a state of emergency. According to the court, there was also no other way to check applications still under review, and concluded that there was an overriding public interest in carrying out the verification process quickly. Finally, the court considered that the controller complied with Article 25 GDPR, as it processed data lawfully and in compliance with Article 5(1)(c) GDPR. In terms of data accuracy (Article 5(1)(d) GDPR), the court dismissed the DPA’s argument that the controller’s system did not eliminate the risk of “homocodes” (identical tax numbers between two or more people). The court considered that the data collected by the Chambers of Parliament and Ministry of Interior were presumed to be accurate. The court also noted that national law foresees the risk of “homocodes” and sets specific procedures in such cases, and that no actual inaccuracies were found in the controller’s verification process. Finally, the court did not find a violation of Article 35 GDPR. The court stated that the controller did not have the obligation to conduct a DPIA, as it did not meet all the necessary criteria. According to the court, the DPA failed to explain the potential high risks of large scale processing that would have justified the need for a DPIA. Given the previous dismissed arguments, the court considered that the controller had also complied with the principle of accountability (Articles 5(2) and 24 GDPR).

### JH v Policejní prezidium

*Source: CJEU, 2025-11-20 — https://overview.legal/posts/51304 — original: https://www.annaberlee.nl/cjeu/62023CJ0057.pdf*

HvJ EU 20 november 2025, C-57/23, ECLI:EU:C:2025:905, (JH v Policejní prezidium).

### NSA - III OSK 5037/21

*Source: Supreme Administrative Court, 2025-04-29 — https://overview.legal/posts/125644 — original: https://gdprhub.eu/index.php?title=NSA_-_III_OSK_5037/21*

Facts — In March 2020, the Ombudsman requested the DPA to initiate proceedings regarding several laws that introduced an obligation for judges and prosecutors to declare their membership in an association, which would then be included in a Public Information Bulletin. The declarations of membership included associations to churches, religions, political parties, and functions similar to trade unions. The Ombudsman argued that the law was unconstitutional. In addition, the Ombudsman requested that the DPA issue an order restricting the processing of this data, specifically to prohibit the publication in the bulletin until proceedings were complete. The DPA dismissed the case in April 2020. The DPA stated that Article 6(1) GDPR provided a legal basis for the processing based on a legal obligation (Article 6(1)(c) GDPR) and necessity for the public interest (Article 6(1)(e) GDPR). Finally, the DPA stated that it did not have the competence under Article 57 GDPR to decide on the issue of constitutionality; this was a matter the Ombudsman should have taken to the Constitutional Court. The Ombudsman appealed the decision to the Court of First Instance, arguing that the DPA should have also considered whether the law fulfilled the requirements of public interest and proportionality under Article 6(3) GDPR. The Court upheld the reasoning of the DPA, stating that law has a legal basis in accordance with the GDPR. According to the Court, GDPR does not give the DPA broader powers, since the this was not foreseen by the EU legislator or provided by national law. The Ombudsman appealed the case to the Provincial Administrative Court, who dismissed the case. The Ombudsman requested the Court to reconsider, or alternatively, the Supreme Administrative Court. In addition, the Ombudsman requested the Supreme Administrative Court to refer a preliminary question to the EU Court of Justice (CJEU). The Provincial Administrative Court referred the case to the Supreme Administrative Court. In its complaint, the Ombudsman argued there was a violation of EU and national law due to the DPA’s and Court’s failure to act, as well as the law restricting the judges and prosecutor’s freedom of religion and assembly. The Ombudsman cited CJEU Case C-204/21 (European Commission v. Republic of Poland). In this case, the CJEU found that national legislation requiring judges to submit written declarations of membership in a political party violated Article 7 CFR and Article 8 CFR, as well as Article 6(1)(c) GDPR and Article 6(3) GDPR. In addition, the CJEU stated that it was insufficient for a national law to meet the formal criteria (e.g. by specifying the data processed and the storage period), it also needed to meet the qualitative criteria (public interest purpose and proportionality). Holding — The Supreme Administrative Court first dismissed the request of the Ombudsman to refer a preliminary question to the CJEU, on the basis that the case C-204/21 made the question irrelevant. Nonetheless, the Court stated that it had the obligation to take the CJEU case into account in assessing whether a national law is compatible with EU law, regardless of the issues raised in the appeal. Article 260(1) TFEU obliges the Court to take measures to ensure the implementation of a CJEU judgment stating that a Member State has not complied with its obligations under the Treaties. The Court considered that the Court of First Instance had misinterpreted Article 6(1)(c) GDPR and Article 6(1)(e) GDPR by limiting its interpretation to national laws. According to the Court, the decision did not consider the Constitution or the CFREU (Article 8 CFR and Article 10(1) CFR) and the European Convention of Human Rights (ECHR) (Article 8 ECHR and Article 9(1) ECHR and Article 9(2) ECHR ). The Court followed the reasoning of the CJEU in Case C-204/21 and concluded that the Polish law requiring judges and prosecutors to disclose their affiliation with religious, trade union and political organisations was a serious interference of their rights under the CFREU. The Polish law also violated Article 6(1)(c) GDPR and Article 6(1)(e) GDPR and Article 6(3) GDPR. The Court referred to the CJEU's reasoning in stating that the processing and publishing of judges' and prosecutors' personal data is likely to reveal their worldview and religious beliefs. This data belongs to the special category of personal data that has additional protections in accordance with Article 9(1) GDPR. The Court overturned the decision by the lower courts and the DPA.

### HvJ EU 9 januari 2025, C‑394/23 (Mousse).

*Source: CJEU, 2025-01-09 — https://overview.legal/posts/50377 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0394*

HvJ EU 9 januari 2025, C‑394/23 (Mousse). Artikelen: 5(1)(c), 6(1), en 21 AVG Onderwerp : Beginsel van minimale gegevensverwerking Gek genoeg verwijst het HvJ EU zelf niet naar HvJ EU 1 augustus 2022, C‑184/20 (Vyriausioji tarnybinės etikos komisija), maar dat had hier ook heel logisch geweest.

### Judgment of the Court (Eighth Chamber) of 19 December 2024.#MK v K GmbH.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 88(1) and (2) – Processing in the context of employment – Employees’ personal data – More specific rules provided for by a Member State pursuant to that Article 88 – Obligation to comply with Article 5, Article 6

*Source: Court of Justice of the European Union, C-65/23, 2024-12-19 — https://overview.legal/posts/132156 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0065*

In a preliminary ruling requested by the German Federal Labour Court (Bundesarbeitsgericht), the Court of Justice of the European Union interpreted Article 88 of the GDPR regarding Member States' ability to adopt more specific rules for processing employee data in the employment context. The case arose from a dispute between an employee (MK) and his employer (K GmbH) over compensation for non-material damage allegedly caused by the processing of personal data based on a works agreement. The Court held that Article 88 does not grant Member States or social partners a margin of discretion to deviate from the core GDPR requirements of Article 5, Article 6(1), and Article 9, meaning national courts must conduct full judicial review of whether such data processing complies with these fundamental GDPR provisions.

### Judgment of the Court (Third Chamber) of 28 November 2024.#Nemzeti Adatvédelmi és Információszabadság Hatóság v UC.#Request for a preliminary ruling from the Kúria.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data and the free movement of such data – Regulation (EU) 2016/679 – Data processed when drawing up a COVID-19 certificate – Data not collected from the data subject – Information to be provided – Exception to the obligation t

*Source: Court of Justice of the European Union, C-169/23, 2024-11-28 — https://overview.legal/posts/132158 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0169*

In Case C-169/23, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Kúria (Hungary) concerning whether the Budapest Metropolitan Government Office, as controller issuing COVID-19 immunity certificates, was required to provide information to data subjects under Article 14 GDPR where the personal data was not collected directly from them. The Court held that data generated by the controller in the context of its own processes falls within the Article 14(5)(c) exemption from the obligation to provide information, provided that Member State law ensures appropriate measures to protect the data subject's legitimate interests, including data security measures under Article 32. The Court also confirmed that supervisory authorities retain competence to handle complaints under Article 77(1) even where the Article 14(5)(c) exemption applies.

### Judgment of the Court (Grand Chamber) of 4 October 2024.#ND v DR.#Request for a preliminary ruling from the Bundesgerichtshof.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Chapter VIII – Remedies – Medicinal products marketed by a pharmacist on an online platform – Action brought before the national civil courts by a competitor of that pharmacist on the basis of the prohibition of unfair commercial practices for infringement by the pharmacist of t

*Source: Court of Justice of the European Union, C-21/23, 2024-10-04 — https://overview.legal/posts/132163 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0021*

In Case C-21/23, the Court of Justice of the European Union (Grand Chamber) ruled on a preliminary reference from the German Bundesgerichtshof in proceedings between two competing pharmacists (ND v DR) concerning whether a competitor has standing under GDPR Article 80(2) to bring a civil action against a rival for unfair commercial practices based on alleged GDPR violations involving health data processed through an online medicinal products platform. The Court addressed the interpretation of Article 9(1) GDPR and the concept of "data concerning health," clarifying the conditions for lawful processing of such special category data in the context of online pharmacy sales. No fine was imposed, as the ruling solely provides interpretative guidance on GDPR provisions regarding remedies, standing, and health data processing.

### Judgment of the Court (Fourth Chamber) of 4 October 2024.#Maximilian Schrems v Meta Platforms Ireland Limited.#Request for a preliminary ruling from the Oberster Gerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Online social networks – General terms of use relating to contracts concluded between a digital platform and a user – Personalised advertising – Article 5(1)(b) – Principle of purpos

*Source: Court of Justice of the European Union, C-446/21, 2024-10-04 — https://overview.legal/posts/132159 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0446*

In a preliminary ruling arising from proceedings between Maximilian Schrems and Meta Platforms Ireland Limited, the Court of Justice of the European Union interpreted GDPR Articles 5(1)(b), 5(1)(c), 6(1), and 9 concerning the lawfulness of processing user personal data for personalised advertising on online social networks. The Court addressed whether such processing can be deemed compatible with the original purpose of data collection under a platform's terms of use, the applicability of the data minimisation principle, and the conditions under which special categories of personal data, including data concerning sexual orientation made public by the data subject, may be processed. No fine was imposed, as the ruling provides interpretative guidance to the Austrian Supreme Court for resolution of the underlying dispute.

### Judgment of the Court (Third Chamber) of 21 December 2023.#ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, Körperschaft des öffentlichen Rechts.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 6(1) – Conditions for lawful processing – Article 9(1) to (3) – Processing of special categories of data – Data concerning heal

*Source: Court of Justice of the European Union, C-667/21, 2023-12-21 — https://overview.legal/posts/132276 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0667*

The CJEU (Third Chamber) ruled on a preliminary reference from the Bundesarbeitsgericht in a case where ZQ sought compensation from his employer, Medizinischer Dienst der Krankenversicherung Nordrhein, for allegedly unlawful processing of his health data in connection with an assessment of his working capacity. The Court addressed the conditions under which a health insurance medical service may lawfully process special categories of health data of its own employees under GDPR Articles 6(1) and 9(2)(h)/(3), and clarified the scope of the right to compensation for non-material damage under Article 82(1), including the relevance of the controller's negligence. No fine was imposed, as the ruling concerns the interpretation of GDPR provisions for the referring court's application.

### Judgment of the Court (Fifth Chamber) of 4 May 2023.#UZ v Bundesrepublik Deutschland.#Request for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 5 – Principles relating to processing – Controllership – Article 6 – Lawfulness of processing – Electronic file compiled by an administrative authority relating to an asylum application – Tra

*Source: Court of Justice of the European Union, C-60/22, 2023-05-04 — https://overview.legal/posts/132289 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0060*

In Case C-60/22, the CJEU (Fifth Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden concerning UZ, a third-country national, and the Bundesrepublik Deutschland regarding the processing of personal data in an asylum application file. The Court held that an administrative authority transmitting an electronic asylum file to a competent national court via an electronic mailbox constitutes processing under the GDPR, and that where both the authority and the court determine the purposes and means of processing, they are joint controllers under Article 26, requiring an arrangement allocating responsibility and maintaining records of processing activities under Article 30. The Court further clarified that transmission of personal data without the data subject's consent constitutes unlawful processing, triggering the right to erasure under Article 17(1)(d) and the right to restriction under Article 18(1)(b), and that national courts must disregard such unlawfully processed data. No fine was imposed.

### Judgment of the Court (Fifth Chamber) of 26 January 2023.#Criminal proceedings against V.S.#Request for a preliminary ruling from the Spetsializiran nakazatelen sad.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Directive (EU) 2016/680 – Article 4(1)(a) to (c) – Principles relating to processing of personal data – Purpose limitation – Data minimisation – Article 6(a) – Clear distinction between personal data of different categ

*Source: Court of Justice of the European Union, C-205/21, 2023-01-26 — https://overview.legal/posts/132297 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0205*

In Case C-205/21, the Court of Justice of the European Union (Fifth Chamber) issued a preliminary ruling responding to a request from the Spetsializiran nakazatelen sad (Specialised Criminal Court, Bulgaria) in criminal proceedings against V.S., who refused to consent to the collection of her biometric and genetic data by police. The Court interpreted Directive (EU) 2016/680, addressing the principles of purpose limitation and data minimisation, the lawful processing of biometric and genetic data under Member State law, the concept of "strictly necessary," and the requirement to maintain a clear distinction between personal data of different categories of data subjects in light of Articles 7, 8, 47, 48, and 52 of the EU Charter of Fundamental Rights. No fine was imposed, as the ruling solely provides interpretive guidance on the compatibility of coercive data collection from accused persons with EU data protection law.

### CJEU - C-205/21 - Ministerstvo na vatreshnite raboti

*Source: GDPRhub, 2023-01-26 — https://overview.legal/posts/158437 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-205/21_-_Ministerstvo_na_vatreshnite_raboti*

Facts — A data subject was accused of a criminal offence and refused to consent to the collection of her genetic and biometric data (Photographs and fingerprints), which the Bulgarian Police required to create a record. The data subject also refused to let the police take a sample for the purpose of creating a DNA profile. In the end, the police did not collect this data. The police went to a Bulgarian Criminal court (Spetsializiran nakazatelen sad), which was also the referring court in this case. Here, the police asked the court to authorise the forced collection of the genetic and biometric data, considering there was enough evidence to convict the data subject of the crime. The police position was mostly based on Bulgatian law (ZMVR, Law of the ministry of Home affairs) authorising the collection of biometric and genetic data for, among the others, law and order purposes. However, the referring court had doubts whether the such law was actually compliant with EU law. This Bulgarian law did refer to Article 9 GDPR, but did not refer to EU directive 2016/680. The latter is an EU directive which concerns the protection of personal data regarding processing of competent authorities for the purposes of prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties. This directive states that the processing of certain special category data, including genetic and biometric data, can be lawful if this is compliant with EU law or national law. The Bulgarian law had even taken over some of the wording from Article 10(a) of this directive for its national provision. The court determined that there were two problems resulting from the fact that this national law contained a reference to the GDPR, but did not mention the aforementioned directive. The first problem was the fact that the GDPR was not applicable to the processing of personal data with regard to criminal investigations, pursuant to Article 2(2)(d) GDPR. The second problem was the fact that Article 9 GDPR prohibited the processing of genetic and biometric data. The court also reiterated that a law enforcement purpose could not fall under one of the exceptions under Article 9(2) GDPR. The referring court referred several questions to the CJEU. The main issue was to know whether the processing of genetic and biometric data for purposes of criminal investigations in this case was permissible under the national law, despite the mention of Article 9 GDPR, and despite the fact that EU directive 2016/680 was not mentioned in the national law. Holding — First, The CJEU determined that both Article 9 GDPR and Article 10 of the directive contain provisions regarding the processing of special categories of personal data, including biometric en genetic data. Second, The CJEU determined that processing of biometric and genetic data by the police authorities could be permissible, as long as this processing fell under Article 10(a) of the directive. This meant that the processing had to be strictly necessary, with adequate safeguards and was provided for in national / EU law, pursuant to Article 52 CFR. However, it could still be unlawful to process this data, when this processing also fell within the scope of the GDPR. Third, The court stated that the requirement of authorised by Union or Member State' law in Article 10a of the directive must be interpreted pursuant to Article 52(1) CFR, which states that any limitation on the exercise of a fundamental right "must be ‘provided for by law". The legal basis which is used for this limitation (in this case, the legal basis was the Bulgarian law), must define the scope of the limitation sufficiently clearly and precisely. This meant that there should not be any uncertainty about the laws concerning - or the conditions of the processing of genetic and biometric data. However, The CJEU also noted that these conditions of processing could vary between the GDPR and the directive. In this context, The CJEU determined that the member states were free to organise their processing operations under either the GDPR or the aforementioned directive. However, member states would have to make sure that there would be no uncertainty about the fact which law would be applicable to different kinds of processing of biometric/genetic data. Fourth, The court also determined that member states were not obligated to cite the directive in the national law itself when they were transposing this directive into national law. It was therefore not necessary for the Bulgarian legislature to mention directive 2016/680 in its transposed national provisions. Fifth, the CJEU noted that national courts had the obligation to explain the national law. For this explanation, the national court had to consider the wording of the directive and the context of the directive. This was an obligation pursuant to Article 288 TFEU, which was applicable to all public bodies of a member state, including national courts. In the present case, where there was an obvious conflict between the GDPR and the directive, the national court had to provide an explanation which would keep the useful working of the directive intact. The CJEU stated that it was up to the national court to determine if the reference to Article 9 GDPR in the Bulgarian law was even correct. The court concluded that it was up to the national court to assess the case. In summary, the Court noted that the processing of the biometric and genetic data by the police could be lawful in this case if it fell under Article 10(a) of the directive. Also, the national implementation of the directive needed to have a sufficiently clear and precise legal basis for the processing of biometric/genetic data by the Bulgarian police. The fact that Article 9 GDPR was mentioned in this law was of no consequence for the legality of this processing, nor was the fact that the directive was not mentioned in the national implementation. However, the explanation by the national court of this Bulgarian law had to be sufficiently precise and clear. Also, this explanation of the national court should state in an unequivocal manner whether certain processing of biometric and genetic data would fall under the directive, or would fall under the GDPR.

## Guidance

### Guidelines 01/2022 on data subject rights - Right of access

*Source: EDPB, edpb-guidelines-on-data-subject-rights---right-of-access, 2023-04-17 — https://overview.legal/posts/38055 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-012022-on-data-subject-rights-right-of-access_en*

The right of access of data subjects is enshrined in Art. 8 of the EU Charter of Fundamental Rights. It has been a part of the European data protection legal framework since its beginning and is now further developed by more specified and precise rules in Art. 15 GDPR.

### Toolbox on essential data protection safeguards for enforcement cooperation between EEA data protection authorities and competent data protection authorities of third countries

*Source: EDPB, toolbox-on-essential-data-protection-safeguards-for-enforcement-en, 2022-03-14 — https://overview.legal/posts/125962 — original: https://www.edpb.europa.eu/documents/other-guidance/toolbox-on-essential-data-protection-safeguards-for-enforcement_en*

Adopted Toolbox on essential data protection safeguards for enforcement cooperation between EEA data protection authorities and competent data protection authorities of third countries Adopted on 14 Mar c h 2022 2 Adopted The European Data Protection Board Having regard to Article 70 (1)(u) and Article 50(a) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the…

### Guidelines 01/2021

*Source: EDPB, edpb-guidelines-on-examples-regarding-personal-data-breach-notification, 2022-01-03 — https://overview.legal/posts/38047 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-012021-on-examples-regarding-personal-data-breach-notification_en*

The European Data Protection Board (EDPB) adopted Guidelines 01/2021 on December 14, 2021, providing practical examples and analysis regarding personal data breach notification obligations under Articles 33 and 34 of the GDPR. The guidelines present hypothetical scenarios covering ransomware attacks and data exfiltration incidents, illustrating how controllers should assess risk to determine whether notification to supervisory authorities and communication to data subjects are required. The document serves as interpretive guidance for controllers evaluating breach severity, appropriate mitigation measures, and notification decisions, and does not impose any fines or sanctions.

### Guidelines 06/2020 on the interplay of the Second Payment Services Directive and the GDPR

*Source: EDPB, edpb-guidelines-on-the-interplay-of-the-second-payment-services-directive-and-the-gdpr, 2020-12-15 — https://overview.legal/posts/38139 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-062020-on-the-interplay-of-the-second-payment-services-directive-and_en*

The European Data Protection Board (EDPB) adopted Guidelines 06/2020 to clarify the interplay between the Second Payment Services Directive (PSD2) and the GDPR. The guidelines analyze the lawful grounds for processing personal data in payment services, the relationship between explicit consent under Article 94(2) PSD2 and GDPR consent requirements,

### Recommendation 01/2019 on the draft list of the European Data Protection Supervisor regarding the processing operations subject to the requirement of a data protection impact assessment (Article 39.4 of Regulation (EU) 2018/1725)

*Source: EDPB, recommendation-012019-on-the-draft-list-of-the-european-data-protection-en, 2019-07-12 — https://overview.legal/posts/126224 — original: https://www.edpb.europa.eu/documents/recommendation/recommendation-012019-on-the-draft-list-of-the-european-data-protection_en*

Adopted 1 Recommendation 01/ 2019 on the draft list of the European Data Protection Supervisor regarding the processing operations subject to the requirement of a data protection impact assessment (Article 3 9 .4 of Regulation (EU) 2018/1725) Adopted on 10 July 2019 Adopted 2 3 CONCLUSION ................................ ................................ ................................ ................................ ... 7 Adopted 3 The European Data Protection Board Having regard to Article…

### Guidelines 1/2020 on processing personal data in the context of connected vehicles and mobility related applications

*Source: EDPB, edpb-guidelines-on-processing-personal-data-in-the-context-of-connected-vehicles-and-mobility-rel, 2020-01-01 — https://overview.legal/posts/38135*

The EDPB adopted Guidelines 1/2020 to provide guidance on the application of the GDPR to the processing of personal data in connected vehicles and mobility-related applications. The guidelines address key issues including data minimisation, data protection by design and by default, transparency obligations, data subjects' rights, security, third-party data sharing, and international transfers, with practical case studies covering services provided by third parties, eCall, accidentology, anti-theft measures, and rental car information. The document does not impose fines but offers recommendations to help controllers and processors in the automotive ecosystem comply with their GDPR obligations.

### Guidelines 03/2022 on Deceptive design patterns in social media platform interfaces: how to recognise and avoid them

*Source: EDPB, edpb-guidelines-on-deceptive-design-patterns-in-social-media-platform-interfaces-how-to-recognise, 2023-02-24 — https://overview.legal/posts/38056 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-032022-on-deceptive-design-patterns-in-social-media-platform_en*

These Guidelines offer practical recommendations to social media providers as controllers of social media, designers and users of social media platforms on how to assess and avoid so-called 'deceptive design patterns' in social media interfaces that infringe on GDPR requirements. To this end, the EDPB recommends  that  controllers  make  use  of  interdisciplinary  teams,  consisting,  among  others,  of designers,  data  protection  officers  and  decision-makers.  It  is  important  to  note  ...

### Guidelines 02/2021 on virtual voice assistants

*Source: EDPB, edpb-guidelines-on-virtual-voice-assistants, 2021-07-07 — https://overview.legal/posts/38077 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-022021-on-virtual-voice-assistants_en*

A virtual voice assistant (VVA) is a service that understands voice commands and executes them or mediates with other IT systems if needed. VVAs are currently available on most smartphones and tablets, traditional computers, and, in the latest years, even standalone devices like smart speakers. VVAs act as interface between users and their computing devices and online services such as search engines  or  online  shops.  Due  to  their  role,  VVAs  have  access  to  a  huge  amount  of  personal...

## Enforcement decisions

### EU DisinfoLab: Non-compliance with general data processing principles

*Source: Belgian Data Protection Authority (APD), 2022-01-27 — https://overview.legal/posts/47138 — original: https://www.enforcementtracker.com/ETid-1023*

The Belgian DPA has fined the NGO EU DisinfoLab EUR 2,700. In 2018, the NGO published an analysis to identify the possible political origin of tweets circulating on a particularly heated controversy in France, the 'Benalla affair.' For the analysis, the organization had processed the data of 55,000 Twitter accounts, of which more than 3,300 had been classified as political. The raw data obtained from this was then published without taking minimal security precautions, such as pseudonymizing the

### Lisbon City Council: Insufficient legal basis for data processing

*Source: Portuguese Data Protection Authority (CNPD), 2021-12-21 — https://overview.legal/posts/47110 — original: https://www.enforcementtracker.com/ETid-995*

The Portuguese DPA has imposed a fine of EUR 1.25 million on the Lisbon City Council. The fine is the sum of 225 fines from various violations committed by the municipality since 2018. The municipality had sent 111 notifications about demonstrations to various departments and offices within the municipality, as well as to third parties, to ensure that they could properly perform their public duties. The notices contained, among other things, sensitive data of the demonstrators and organizers of

### HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens

*Source: HDPA (Greece), 2026-05-13 — https://overview.legal/posts/144044 — original: https://gdprhub.eu/index.php?title=HDPA_(Greece)_-_12/2026*

Facts — The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of Undesirable Aliens. In response to the Authority's request for clarifications, the competent Directorate of the Ministry of Citizen Protection informed the DPA that: • By a decision dated 27-07-2017, an entry ban and registration in the National Registry of Undesirable Aliens were imposed on the complainant for reasons of national security. • Following temporary 48-hour lifts of the measure for humanitarian reasons in 2019, the entry ban was re-imposed. • Subsequent decisions in 2020, 2023, and 2025 maintained the entry ban and renewed his registration in the National Registry of Undesirable Aliens for successive three-year periods, as the grounds for registration remained active. • The explicit grounds and documentation behind the registration were not disclosed to the complainant because the competent Directorate classified the file as restricted/classified service material. The complainant and his attorney attended a DPA hearing on 22-04-2026, arguing that the registration lacked specific, adequate, or definitive justification regarding any threat to public order or national security. They noted that the complainant has no criminal convictions, poses no threat, and possesses strong ties, residency, and business operations in the region of Northern Epirus and Greece, meaning the entry ban severely disrupts his professional and family life. Holding — According to the provisions of Article 82(1) of Law 3386/2005, foreign nationals whose presence in Greek territory constitutes a threat to national security, public safety, or public order can be registered in the National Registry of Undesirable Aliens, with registrations subject to an ex officio review every three years. Furthermore, pursuant to the provisions of Article 54(2) and Article 55(4) of Law 4624/2019 (the Greek law implementing the GDPR), the data controller is legally empowered to restrict or omit the provision of information and to deny a data subject access to their personal data when dictated by reasons of national security or public order. These national provisions are explicitly anchored in Article 23 GDPR (specifically Article 23(1)(a)GDPR and Article 23(1)(c) GDPR), which permits Member State law to restrict the scope of the obligations and data subject rights (such as the right to be informed under Article 13 GDPR - Article 14 GDPR and the right of access under Article 15 GDPR) to safeguard national security and public security. In the present case, the evidence demonstrated that the complainant's initial registration and subsequent renewals in the National Registry of Undesirable Aliens were executed lawfully for reasons of national security. The Ministry of Citizen Protection, acting as the data controller, exercised its legal discretion under these frameworks to weigh these interests and correctly determined that the underlying operational decision constitutes classified material that cannot be disclosed to the data subject. Consequently, the fundamental principles of data protection law were not breached, and the Hellenic DPA rejected the complaint as unfounded.

### CNPD (Portugal) - Deliberação 2019/494

*Source: CNPD (Portugal), 2019-09-03 — https://overview.legal/posts/122872 — original: https://gdprhub.eu/index.php?title=CNPD_(Portugal)_-_Deliberação_2019/494*

Facts — In its Opinion 20/2018 concerning the draft of Law 58/2019 which ensures the implementation of the GDPR in the portuguese national legal framework, the DPA drew the attention of the national legislator to a set of provisions that could potentially violate EU law, particularly the GDPR. The DPA emphasized the primacy of EU law as outlined in the EU treaties, particularly reflecting on Article 288 of the Treaty on the Functioning of the European Union (TFEU) and reinforced by the jurisprudence of the CJEU, which has consistently stated that national laws cannot obstruct the direct applicability of EU regulations and must comply with EU law to ensure uniform implementation across the Member States. However, Law 58/2019 came into force without incorporating all of the DPA's recommendations. The DPA explains that the decision to not apply some of its provisions aims to ensure legal certainty, reinforcing the importance of consistent GDPR application without being hindered by conflicting national rules. Holding — The DPA has decided to disapply the following provisions of Law 58/2019, in cases of personal data processing under its review due to their conflict with the GDPR: Article 2(1)(2): This article broadens the territorial scope of the GDPR to encompass all personal data processing within national territory and processing linked to national establishments outside the territory. The DPA believes this contradicts Article 3 and Article 56 of the GDPR, which outlines the applicable law in cross-border situations. Additionally, it undermines the one-stop-shop mechanism and fails to address instances where the GDPR applies, such as in Portuguese embassies, consulates, ships, and aircraft. Article 20(1): This article states that the right to be informed and the right of access cannot be exercised when a duty of secrecy is imposed on the data controller/processor. In the view of the DPA, this article lacks legal relevance in relation to the GDPR, as it merely repeats provisions already present in the GDPR, particularly concerning the possibility of restricting the data subject's right to information in cases where data collection is indirect and a legal duty of confidentiality exists. Regarding the possibility of restricting the right to information when collecting data directly from the data subject, this right can only be restricted under the provisions of Article 23 GDPR, and Law58/2019 does not meet the requirements therein, thus contradicting the norms of the GDPR and the Charter of Fundamental Rights. Article 23: This article allows public authorities to reuse personal data for any public interest without ensuring compliance with principles of purpose limitation and data minimization (Article 5 GDPR) and could lead to potential misuse of personal data and a violation of individuals’ rights, as it does not ensure that the reuse of data serves the original purpose for which it was collected nor respecting the requirements imposed in Article 23 GDPR. Article 28(3)(a): The employee's consent cannot be the legal basis if the processing results in a legal or economic advantage for the employee. The Portuguese DPA considers it to be a contraction of the doctrine established by European institutions, which accepts employee consent in situations where the act of giving or refusing consent does not, in itself, have negative consequences for the employee. The DPA therefore believes that this provision does not protect the dignity, fundamental rights, and legitimate interests of employees, and thus fails to meet the requirements set forth in Article 9 (2) (b) and Article 88 GDPR. Regime of Administrative Offenses – Articles 37, 38, and 39: The DPA notes that some of the violations outlined in the law contradict the exhaustive list provided in the GDPR (Article 83). The DPA also criticizes the distinction in sanctioning frameworks based on the size of companies and the collective or individual nature of the entities conducting data processing, as the impact on personal data does not depend on those characteristics but rather on the nature of the activity being carried out. Article 61(2) states that "if the expiration of consent is the reason for terminating a contract in which the data subject is a party, the processing of data is lawful until this occurs." The DPA notes that this provision is incongruent, conflating two types of legal basis: consent and contract execution. The contract in which the data subject is a party is sufficient to justify the processing of the data necessary for its execution. Regarding the reasons that led to publish this decision, the Portuguese DPA clarifies that it did so in order to ensure the transparency of its future decision-making processes and, in this regard, contribute to legal certainty and security. It also clarifies that the non-application, in future specific cases, of the legal provisions listed above results in the direct application of the GDPR provisions that were manifestly restricted, contradicted, or compromised in their useful effect.

### HDPA (Greece) 32/2020: School unlawfully rejected religion-exemption request

*Source: HDPA (Greece), 2020-09-07 — https://overview.legal/posts/125637 — original: https://gdprhub.eu/index.php?title=HDPA_(Greece)_-_32/2020*

Facts — The complainant, making use of the Greek Ministry of Education and Religion's Order 12773/Δ2/23.01.2015, filed in the name of their son an exemption request from the participation in the religious education course, from praying, from church attendance and generally from any religious activity at their high school due to religious conscience related reasons. The high school rejected the complainant's request with the argument that the application did not include a solemn statement that the son was not Orthodox Christian. The complainant then provided the school with this solemn statement, but their request was again rejected this time as overdue and their son had to continue attending the religious education course. Furthermore, the complainant claimed that, based on a court decision, they requested by the school the erasing of all data pertaining to their son's religious beliefs (presence/absence log, grades, evaluation of all kinds), an event that the high school itself denied that ever happened. The complainant added that even though the school allowed to the student to stop attending the religious education course and despite the right to erase data entertained by the parent, it did include a grade of 18/20 for the religious education course on the pupil's grade certificate for the first four-month term, an event that the school again completely denied. In addition, the complainant claimed that the inscription of the pupils' conduct on school leaving certificates based on Law 4692/2020 does not serve any specific purposes and results to the unnecessary inclusion in an official document of the pupils' personal data, something that might lead to negative evaluation, stigma or even negative differential treatment of the pupil concerned in the future. The complainant also claimed that the respective Ministry had not proceeded with any measures regarding the process of the exemption despite the ECHR's Decision of the case Papageorgiou and Others v. Greece that convicted the latter for the violation of the right to education in light of the right to religious freedom. On its part, the Ministry contested the fact that no measures have been taken whatsoever, while it underlined that the inscription of the pupils' conduct on school leaving certificates is absolutely in accordance with the core of education's purpose as found in Article 16(2) of the Greek Constitution and sees to the forming of free and responsible citizens. The Ministry also highlighted that under the new Ministry of Education and Religion Order 104795/ΓΔ4/10.08.2020, the exemption from the religious education course requires a solemn statement from the pupil themselves, if they are an adult, or from their parents that states the necessity of the exemption due to religious conscience related reasons. Dispute — Holding — The HDPA underlined that Article 13(1) of the Greek Constitution guarantees the freedom of religious conscience, including the negative side of religious freedom, meaning the right for someone to be an atheist or not belong to any religion (according to Article 9 ECHR as well). Article 13(1) is inextricably linked with the general freedom of thought, while they both constitute crucial elements pertaining to human dignity (Article 2(1) Greek Constitution) and to the right to freely form one's personality (Article 5(1) Greek Constitution). The HDPA focused on the aspect of freedom of thought and freedom of religious conscience that has to do with a person's right to not disclose their thoughts and beliefs, a right closely linked to the right to protect one's personal data (Article 9A Greek Constitution, Article 9 GDPR). All these rights, combined with the right to respect the beliefs of the parents during the education of their children (Article 2(2) 1st Additional Protocol to the ECHR), leads to the right of exemption from the religious education course for every student whose parents have different beliefs, religious, philosophical or others, in comparison to those found in the religious education course's contents, while this right can be exercised by the student themselves provided that they have the necessary maturity to proceed with such a decision. The HDPA pointed out that during the exemption procedure the principle of data minimisation applies (Article 5(1)(c) GDPR), so as for the parents and their children to not have to disclose, either directly or indirectly, their religious or non-religious beliefs. The HDPA referred to its own past Decision 28/2019, where it held that the disclosure of the fact that a student is not Orthodox Christian in order to apply for an exemption was not in accordance with the negative religious freedom, meaning the right of parents and children to not disclose their religious beliefs as this right was explained above, while it also was not in accordance with the principle of the necessity for the processing of personal data, since the invocation of conscience reasons in general should have been enough (without the need of further referring to the belief or non-belief in a certain religion). The same line of thought was followed by the ECHR in the Papageorgiou and Others v. Greece Case, where the Court held that the Order 12773/Δ2/23.01.2015 was indeed violating the right of a person to not disclose their religion or religious beliefs and to not be directed towards a behaviour that may lead to assumptions as to whether this person has or has not certain beliefs. Thus, in the ECHR's opinion a simple statement of exemption should be enough, without any reference to religious conscience reasons or even to conscience reasons in general. The HDPA also referred to the Council Of State's Plenary Decisions 660/2018 and 1749/2019 where the same conclusion was in fact reached as regards the existence of the right to exemption due to religious conscience reasons, without the Council of State excluding the possibility of exemption with the invocation of conscience reasons in general. Having noted all that, the HDPA held that reasons supporting the right to exemption do not only include religious beliefs, but also non-religious beliefs. More precisely, the HDPA held that in this particular case there indeed was a violation of Articles 13(1) & 9A of the Greek Constitution, as well as of Article 2(2) 1st Additional Protocol to the ECHR, since the school did not have the right to deny the exemption from the religious education course with the argument that the application lacked a solemn statement that the pupil was not Orthodox Christian. Additionally, the HDPA held that there was also a violation of Article 9A of the Greek Constitution per se due to the school's denial to erase from their records the pupil's personal data that pointed out he was not Orthodox Christian. Regarding the issue of the pupils' conduct, the HDPA held that the classification of pupils' conduct indeed serves an educational purpose, while the inclusion of this classification in school records does not violate the legal framework pertaining to the protection of personal data. But, the inscription of the pupils' conduct on their school leaving certificates violates the principle of proportionality of Article 5 GDPR, since third persons and entities can be authorised access to these documents, since such an inscription does not serve the purpose of the certificate which is to clarify the performance of the pupils and to prove the completion of their studies, and since such an inscription may indeed lead to stigma and negative differential treatment of the pupils in the future. All in all, the HDPA held that the invocation of conscience reasons is enough for the exemption to take place, it called upon the school and the respective Ministry to erase all data pertaining to the pupil's religious beliefs, and held that the inscription of the pupils' conduct on their school leaving certificates was illegal.

### AEPD: Digi Telecom violated Art 6(1) GDPR by issuing duplicate SIM to impersonator

*Source: AEPD (Spain), 2026-07-13 — https://overview.legal/posts/109001 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_EXP202310345*

Facts — On December 28, 2022, DIGI Telecom, the controller, delivered a duplicate SIM card to an unauthorized third party without the consent of the original line holder (the data subject) The duplicate SIM card was delivered to an impersonator after they passed the established protocols for verifying the applicant's identity. The controller appealed the decision by the Spanish DPA to impose a fine because they claimed that they had appropriate security measures. The controller claims that, by focusing on the result, the Spanish DPA is acting under strict liability. The mere fact that identity theft occurred does not equal a lack of due diligence on the part of the controller. The controller also requested a reduction of the fine on the basis of Article 83(5)(a) GDPR because there were no aggravating circumstances and no special categories of data were processed Holding — The Spanish DPA found a violation of Article 6(1) GDPR because issuing a duplicate SIM card and delivering it to a person other than the telephone line holder constitutes the processing of personal data within the meaning of Article 4(1) GDPR without a legal basis because the data subject did not give consent. The DPA ruled that the controller violated their duty of care because the security measures lacked the dilligence required. According to Article 5(2) GDPR (principle of proactive responsibility) the controller must demonstrate compliance to the GDPR. Proactive responsibility means that the measures are compliant to the GDPR under normal circumstances. The controller must also demonstrate that the measures are compliant with the GDPR and that they are effective in the specific context and purposes of processing (Article 24 en 25 GDPR). The controller had a higher standard of care because of a documented risk to SIM swap attacks and the high scale of processing. Recital 74 GDPR states that the controller’s must implement effective and appropriate measures that take into account the nature, scope and context, and purposes of processing. The card allows an impersonator to access additional data through which they can carry out actions with grave consequences. The controller did not demonstrate that their security measures sufficiently protected the data subject. Factual circumstances should have alerted DIGI to the fraud: the SIM card replacement was processed at a physical store in a different province from where the data subject resided. The Spanish DPA flagged that the controller did not ask the reason for issuing the card and they did not verify whether the old SIM card was functioning. Therefore the security measures were not appropriate to prevent'SIM swap attacks' that are prevalent in the telecom context. With regard to to the height of the fine, the Spanish DPA found that no new legal arguments were made that would lead to the reduction of the fine.

### Researcher: Non-compliance with general data processing principles

*Source: Belgian Data Protection Authority (APD), 2022-01-27 — https://overview.legal/posts/47137 — original: https://www.enforcementtracker.com/ETid-1022*

The Belgian DPA has fined a researcher EUR 1,200. The fine was issued in connection with another fine against the NGO EU DisinfoLab. The researcher was employed at the NGO. In 2018, the NGO published an analysis to identify the possible political origin of tweets circulating on a particularly heated controversy in France, the 'Benalla affair.' For the analysis, the organization had processed the data of 55,000 Twitter accounts, of which more than 3,300 had been classified as political. The raw d

### Permanent TSB: Insufficient technical and organisational measures to ensure information security

*Source: Data Protection Authority of Ireland, 2026-05-08 — https://overview.legal/posts/53597 — original: https://www.enforcementtracker.com/ETid-3146*

Data Protection Authority of Ireland fined Permanent TSB €277,500 on 2026-05-08 for: Insufficient technical and organisational measures to ensure information security.

## Recent developments

### GDPR complaint against X (Twitter) over illegal micro-targeting for chat control ads

*Source: noyb - European Center for Digital Rights, 2023-12-14 — https://overview.legal/posts/53207 — original: https://noyb.eu/en/gdpr-complaint-against-x-twitter-over-illegal-micro-targeting-chat-control-ads*

Political Microtargeting, Manipulation & Tracking Today, noyb filed a complaint against X (Twitter) for unlawfully using the political views and religious beliefs of its users for targeted advertising. The company used this specially protected data to determine whether people should or should not see an ad campaign by the EU Commission’s Directorate General for Migration and Home Affairs, which tried to ralley support for the proposed “chat control” in the Netherlands. In November, this unlawful

### Tien gemeenten beboet voor illegaal verwerken van informatie over islamitische mensen

*Source: Autoriteit Persoonsgegevens, 2026-02-05 — https://overview.legal/posts/52420 — original: https://autoriteitpersoonsgegevens.nl/actueel/tien-gemeenten-beboet-voor-illegaal-verwerken-van-informatie-over-islamitische-mensen*

De Autoriteit Persoonsgegevens (AP) legt tien gemeenten een boete op van in totaal 250.000 euro. De reden is dat zij dossiers met gevoelige informatie over islamitische inwoners hebben verwerkt, zonder dat deze inwoners dat wisten. De gemeenten hebben daarmee de Algemene verordening gegevensbescherming (AVG) overtreden. Zij mochten deze informatie niet hebben. Ook hebben zij hiermee gegevens over de religie en politieke voorkeuren van mensen verwerkt, terwijl dit vrijwel altijd verboden is.

### De Autoriteit Persoonsgegevens publiceert een rapport over de risicoanalyse van de AVG (Algemene Verordening Gegevensbescherming).

*Source: AEPD, 2022-10-11 — https://overview.legal/posts/51791*

De GDPR-risicoanalyse is bedoeld om controllers en verwerkers te helpen bij het identificeren van de risicofactoren voor de rechten en vrijheden van de betrokkenen, wiens gegevens worden verwerkt. Het doel is om een eerste inschatting te maken van het inherente risico, inclusief de noodzaak om een Privacy Impact Assessment (DIA) uit te voeren, en om het resterende risico te schatten als maatregelen en beveiligingsmechanismen worden gebruikt om specifieke risicofactoren te verminderen.

### States Tried to Censor Kids Online. Courts, and EFF, Mostly Stopped Them: 2025 in Review

*Source: Electronic Frontier Foundation, 2025-12-31 — https://overview.legal/posts/49264 — original: https://www.eff.org/deeplinks/2025/12/states-tried-censor-kids-online-courts-and-eff-mostly-stopped-them-2025-review*

Lawmakers in at least a dozen states believe that they can pass laws blocking young people from social media or require them to get their parents’ permission before logging on. Fortunately, nearly every trial court to review these laws has ruled that they are unconstitutional. It’s not just courts telling these lawmakers they are wrong. EFF has spent the past year filing friend-of-the-court briefs in courts across the country explaining how these laws violate young people’s First Amendment right

### States attempted to censor the online activities of children. Courts and the Electronic Frontier Foundation (EFF) largely managed to prevent this: a look back at 2025.

*Source: Electronic Frontier Foundation, 2025-12-31 — https://overview.legal/posts/52015*

In at least a dozen states, lawmakers believe they can pass laws that prohibit young people from accessing social media, or that require them to obtain parental consent before logging in. Fortunately, almost all courts that have reviewed these laws have ruled that they violate the constitution. It's not just the courts telling these lawmakers they are wrong. The Electronic Frontier Foundation (EFF) has filed briefs with courts across the country over the past year, explaining how these laws violate the freedom of speech of young people, as protected by the First Amendment.

## Literature

### GDPR: A new challenge for personal data protection

*Source: Bankarstvo, 2017-01-01 — https://overview.legal/posts/132473 — original: https://doi.org/10.5937/bankarstvo1704166m*

stručni članak Erne Mraznica Raiffeisen banka ad Beograd erne.mraznica@raiffeisenbank.rs GDPR - NOVI IZAZOV ZAŠTITE PODATAKA O LIČNOSTI Rezime Dana 4. maja 2016. godine objavljena je Opšta Uredba o zaštiti podataka o ličnosti u Sl. glasniku EU, koja će se primenjivati od 25. maja 2018. godine. Cilj propisa je harmonizacija zaštite podataka o ličnosti na nivou EU, veći stepen kontrole za lica čiji se podaci obrađuju i unapređeno upravljanje savremenim rizicima iz ove oblasti. Banke, po prirodi svog poslovanja, spadaju među najveće rukovaoce podataka o ličnosti i u postupku usklađivanja sa obavezama utvrđenih Uredbom biće u prilici da izvrše punu analizu svog postojećeg regulatornog i infrastrukturnog okvira zaštite podataka o ličnosti. Istovremeno, pruža im se prilika da isprave eventualne nedostatke u postojećim procesima, odnosno da značajno povećaju svest organizacije o standardima zaštite podataka o ličnosti, posebno imajući u vidu zaprećene stroge sankcije za slučaj neusklađenosti. Ključne reči : GDPR, podatak o ličnosti, osnovni principi, prava lica, rukovalac, obrada podataka, transfer podataka, sankcije, usklađivanje JEL : F52, G14 doi: 10.5937/bankarstvo1704166M 166 Bankars

### GDPR - General Data Protection Regulation on Sites Requiring Accessibility

*Source: Innovative STEM Education, 2021-06-29 — https://overview.legal/posts/132420 — original: https://doi.org/10.55630/stem.2021.0305*

The paper describes what GDPR - General Data Protection Regulation is and why it matters for business, institutions and other legal entities, who need to collect personal data in order to provide and deliver services or products. They have to apply and describe to consumers’ principles and general rules to protect their data. Rules include reasons why personal data collection is necessary, transparency how and by who it will be used and stored and for how long, as well as safety measures to not

## Related topics

- **Types of Special Categories of Personal Data** — https://overview.legal/topics/special-categories-data-types
  A dedicated topic is needed to comprehensively cover the specific types and definitions of special categories of personal data, including racial/ethnic origin, 
- **Special Categories of Data** — https://overview.legal/topics/bijzondere-persoonsgegevens
  Sensitive data requiring enhanced protection (health, biometric, etc.)
- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Political Opinions** — https://overview.legal/topics/political-opinions
  Processing of political views and affiliations
- **Consent** — https://overview.legal/topics/toestemming
  Freely given, specific, informed indication of data subject wishes

---
Generated by overview.legal · https://overview.legal/topics/religious-beliefs · 2026-08-22
