# Right to Object — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/right-to-object
> Sources are cited per item. Verify against the official texts before relying on them.

Data subject right to object to processing

## Overview

## Legal Framework

The right to object is codified in [Article 21 GDPR](/laws/gdpr/art-21) and gives data subjects a powerful mechanism to halt processing carried out under Article 6(1)(e) (public interest/official authority) or Article 6(1)(f) (legitimate interests). The right operates differently depending on the processing purpose.

For general processing under those legal bases, the data subject may object "on grounds relating to his or her particular situation," and the burden then shifts to the controller:

> "The controller shall no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims."
> — [GDPR Art. 21(1)](/laws/gdpr/art-21#par-1)

For direct marketing, the right is absolute: once the data subject objects, processing must stop—no balancing test applies. [Article 21(3)](/laws/gdpr/art-21#par-2) makes this categorical. Recital 70 reinforces that this right applies "whether with regard to initial or further processing, at any time and free of charge." Controllers must explicitly bring the objection right to the data subject's attention at the latest at the time of first communication, presented clearly and separately from other information ([Article 21(4)](/laws/gdpr/art-21#par-2)).

Crucially, the right to object does **not** apply when processing is based on consent. As the EDPB confirms, withdrawal of consent under Article 7 serves a similar function in that scenario.

## Key Developments

The CJEU established early in *Google v. Spain* that the right to object operates alongside—rather than replaces—the lawfulness assessment under Article 6. The Court confirmed a data subject may "rely in certain conditions on the right to object laid down in subparagraph (a) of the first paragraph of Article 14 of the directive," even when the controller's lawful basis is already under challenge.

In *Bavarian Lager*, the CJEU addressed the interaction between the right to object and mandatory legal obligations. The Court held that where processing constitutes a legal obligation under what was then Article 5(b) of Regulation 45/2001, "the data subject does not, in principle, have a right to object." However, where an exception to that legal obligation exists, the impact of disclosure on the data subject must still be weighed. This confirms that the right to object is not available against processing required by law, but its protective logic can influence how exceptions to such obligations are applied.

The 2025 *Mousse* ruling (C-394/23) signals continued judicial engagement with Article 21, specifically in the context of data minimisation and the collection of title and gender identity data in online travel ticket sales—demonstrating that the right to object is being tested against novel data-collection practices.

## Status of the Debate

This topic is actively contested in court. The boundaries of Article 21 are being fought over in several directions: the threshold for "compelling legitimate grounds" that override the data subject's objection, the scope of the absolute marketing objection, and how the right interacts with other legal obligations. *Bavarian Lager* established that mandatory legal processing excludes the objection right in principle, but left open how exceptions should be assessed. *Mousse* may clarify whether data minimisation failures create a presumption that an objection must succeed. No definitive court split is on record, but the tension between controllers' legitimate-interest arguments and data subjects' particular-situation objections remains unresolved at the CJEU level. A future ruling squarely addressing the evidentiary standard for "compelling legitimate grounds" would resolve the central open question.

## Practical Guidance

- **Distinguish the legal basis before responding.** If processing relies on consent, Article 21 does not apply—direct the data subject to consent withdrawal. If processing relies on Article 6(1)(e) or (f), the objection triggers the Article 21(1) balancing test.
- **Treat direct marketing objections as absolute.** No balancing exercise is permitted; cease processing immediately upon receipt of an objection under [Article 21(2)](/laws/gdpr/art-21#par-2).
- **Prepare to demonstrate compelling legitimate grounds.** Document the legitimate interest assessment and the specific grounds that override the data subject's situation, as the burden of proof rests on the controller.
- **Surface the right proactively.** At the latest at first communication with the data subject, present the objection right clearly and separately from other privacy information, as required by [Article 21(4)](/laws/gdpr/art-21#par-2).
- **Offer automated objection mechanisms for online services.** Under [Article 21(5)](/laws/gdpr/art-21#par-5), information society services must enable objections by automated means using technical specifications.

## Legislation (full text of key provisions)

### Right to object

*Source: GDPR, gdpr-art-21-en, 2016-04-27 — https://overview.legal/posts/90471*

### Recital 69 — data subject right to object

*Source: GDPR, gdpr-rec-69-en, 2016-04-27 — https://overview.legal/posts/91653*

Where personal data might lawfully be processed because processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, or on grounds of the legitimate interests of a controller or a third party, a data subject should, nevertheless, be entitled to object to the processing of any personal data relating to his or her particular situation. It should be for the controller to demonstrate that its compelling legitimate interest overrides the interests or the fundamental rights and freedoms of the data subject.

### Recital 70 — right to object to direct marketing

*Source: GDPR, gdpr-rec-70-en, 2016-04-27 — https://overview.legal/posts/91655*

Where personal data are processed for the purposes of direct marketing, the data subject should have the right to object to such processing, including profiling to the extent that it is related to such direct marketing, whether with regard to initial or further processing, at any time and free of charge. That right should be explicitly brought to the attention of the data subject and presented clearly and separately from any other information.

### Recital 73 — lawful restrictions on data subject rights

*Source: GDPR, gdpr-rec-73-en, 2016-04-27 — https://overview.legal/posts/91661*

Restrictions concerning specific principles and the rights of information, access to and rectification or erasure of personal data, the right to data portability, the right to object, decisions based on profiling, as well as the communication of a personal data breach to a data subject and certain related obligations of the controllers may be imposed by Union or Member State law, as far as necessary and proportionate in a democratic society to safeguard public security, including the protection of human life especially in response to natural or manmade disasters, the prevention, investigation and prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security, or of breaches of ethics for regulated professions, other important objectives of general public interest of the Union or of a Member State, in particular an important economic or financial interest of the Union or of a Member State, the keeping of public registers kept for reasons of general public interest, further processing of archived personal data to provide specific information related to the political behaviour under former totalitarian state regimes or the protection of the data subject or the rights and freedoms of others, including social protection, public health and humanitarian purposes. Those restrictions should be in accordance with the requirements set out in the Charter and in the European Convention for the Protection of Human Rights and Fundamental Freedoms.

### Recital 59 — modalities for data subject rights exercise

*Source: GDPR, gdpr-rec-59-en, 2016-04-27 — https://overview.legal/posts/91633*

Modalities should be provided for facilitating the exercise of the data subject's rights under this Regulation, including mechanisms to request and, if applicable, obtain, free of charge, in particular, access to and rectification or erasure of personal data and the exercise of the right to object. The controller should also provide means for requests to be made electronically, especially where personal data are processed by electronic means. The controller should be obliged to respond to requests from the data subject without undue delay and at the latest within one month and to give reasons where the controller does not intend to comply with any such requests.

### Recital 50 — compatible further processing of personal data

*Source: GDPR, gdpr-rec-50-en, 2016-04-27 — https://overview.legal/posts/91615*

The processing of personal data for purposes other than those for which the personal data were initially collected should be allowed only where the processing is compatible with the purposes for which the personal data were initially collected. In such a case, no legal basis separate from that which allowed the collection of the personal data is required. If the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, Union or Member State law may determine and specify the tasks and purposes for which the further processing should be regarded as compatible and lawful. Further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes should be considered to be compatible lawful processing operations. The legal basis provided by Union or Member State law for the processing of personal data may also provide a legal basis for further processing. In order to ascertain whether a purpose of further processing is compatible with the purpose for which the personal data are initially collected, the controller, after having met all the requirements for the lawfulness of the original processing, should take into account, inter alia: any link between those purposes and the purposes of the intended further processing; the context in which the personal data have been collected, in particular the reasonable expectations of data subjects based on their relationship with the controller as to their further use; the nature of the personal data; the consequences of the intended further processing for data subjects; and the existence of appropriate safeguards in both the original and intended further processing operations. Where the data subject has given consent or the processing is based on Union or Member State law which constitutes a necessary and proportionate measure in a democratic society to safeguard, in particular, important objectives of general public interest, the controller should be allowed to further process the personal data irrespective of the compatibility of the purposes. In any case, the application of the principles set out in this Regulation and in particular the information of the data subject on those other purposes and on his or her rights including the right to object, should be ensured. Indicating possible criminal acts or threats to public security by the controller and transmitting the relevant personal data in individual cases or in several cases relating to the same criminal act or threats to public security to a competent authority should be regarded as being in the legitimate interest pursued by the controller. However, such transmission in the legitimate interest of the controller or further processing of personal data should be prohibited if the processing is not compatible with a legal, professional or other binding obligation of secrecy.

### Recital 68 — online advertising transparency requirements

*Source: DSA, dsa-rec-68-en, 2022-10-19 — https://overview.legal/posts/95533*

Online advertising plays an important role in the online environment, including in relation to the provision of online platforms, where the provision of the service is sometimes in whole or in part remunerated directly or indirectly, through advertising revenues. Online advertising can contribute to significant risks, ranging from advertisements that are themselves illegal content, to contributing to financial incentives for the publication or amplification of illegal or otherwise harmful content and activities online, or the discriminatory presentation of advertisements with an impact on the equal treatment and opportunities of citizens. In addition to the requirements resulting from Article 6 of Directive 2000/31/EC, providers of online platforms should therefore be required to ensure that the recipients of the service have certain individualised information necessary for them to understand when and on whose behalf the advertisement is presented. They should ensure that the information is salient, including through standardised visual or audio marks, clearly identifiable and unambiguous for the average recipient of the service, and should be adapted to the nature of the individual service’s online interface. In addition, recipients of the service should have information directly accessible from the online interface where the advertisement is presented, on the main parameters used for determining that a specific advertisement is presented to them, providing meaningful explanations of the logic used to that end, including when this is based on profiling. Such explanations should include information on the method used for presenting the advertisement, for example whether it is contextual or other type of advertising, and, where applicable, the main profiling criteria used; it should also inform the recipient about any means available for them to change such criteria. The requirements of this Regulation on the provision of information relating to advertising is without prejudice to the application of the relevant provisions of Regulation (EU) 2016/679, in particular those regarding the right to object, automated individual decision-making, including profiling, and specifically the need to obtain consent of the data subject prior to the processing of personal data for targeted advertising. Similarly, it is without prejudice to the provisions laid down in Directive 2002/58/EC in particular those regarding the storage of information in terminal equipment and the access to information stored therein. Finally, this Regulation complements the application of the Directive 2010/13/EU which imposes measures to enable users to declare audiovisual commercial communications in user-generated videos. It also complements the obligations for traders regarding the disclosure of commercial communications deriving from Directive 2005/29/EC.

## Case law

### Judgment of the Court (First Chamber) of 4 September 2025.#European Data Protection Supervisor v Single Resolution Board.#Appeal – Protection of natural persons with regard to the processing of personal data – Procedure for granting compensation to shareholders and creditors of a banking institution following the resolution of that institution – Decision of the European Data Protection Supervisor finding that the Single Resolution Board failed to fulfil its obligations relating to the processing

*Source: Court of Justice of the European Union, C-413/23, 2025-09-04 — https://overview.legal/posts/132136 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0413*

The European Data Protection Supervisor (EDPS) appealed a General Court judgment that annulled its decision finding the Single Resolution Board (SRB) had failed to fulfil its obligations under Regulation (EU) 2018/1725 regarding the processing of personal data in a banking resolution compensation procedure. The core legal issues concerned whether pseudonymised data transmitted to a third party constitutes "personal data" under Article 3(1), the proper interpretation of "pseudonymisation" under Article 3(6), and the scope of the controller's obligation to inform data subjects under Article 15(1)(d). The Court of Justice (First Chamber) ruled on these interpretive questions in deciding whether to set aside the General Court's judgment.

### Judgment of the Court (First Chamber) of 27 February 2025.#CK v Magistrat der Stadt Wien.#Request for a preliminary ruling from the Verwaltungsgericht Wien.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 15(1)(h) – Automated decision-making, including profiling – Scoring – Assessment of the creditworthiness of a natural person – Access to meaningful information about the logic involved in profiling – Verification of the accuracy of the infor

*Source: Court of Justice of the European Union, C-203/22, 2025-02-27 — https://overview.legal/posts/132146 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0203*

In Case C-203/22, the Court of Justice of the European Union interpreted Article 15(1)(h) of the GDPR in response to a preliminary ruling from the Verwaltungsgericht Wien concerning an individual's request for meaningful information about the logic of creditworthiness scoring conducted by Dun & Bradstreet Austria GmbH. The Court held that data subjects must receive sufficiently detailed explanations of the logic involved in automated profiling to understand how the decision was reached, while controllers may withhold information protected by trade secrets under Directive (EU) 2016/943 only insofar as such withholding does not render the information provided meaningless. The Court further clarified that data subjects may not use access rights to obtain personal data of third parties or to verify the absolute accuracy of the underlying information processed.

### HvJ EU 9 januari 2025, C‑394/23 (Mousse).

*Source: CJEU, 2025-01-09 — https://overview.legal/posts/50377 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0394*

HvJ EU 9 januari 2025, C‑394/23 (Mousse). Artikelen: 5(1)(c), 6(1), en 21 AVG Onderwerp : Beginsel van minimale gegevensverwerking Gek genoeg verwijst het HvJ EU zelf niet naar HvJ EU 1 augustus 2022, C‑184/20 (Vyriausioji tarnybinės etikos komisija), maar dat had hier ook heel logisch geweest.

### Judgment of the Court (First Chamber) of 4 October 2024.#Agentsia po vpisvaniyata v OL.#Request for a preliminary ruling from the Varhoven administrativen sad.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Publication in the commercial register of a company’s constitutive instrument containing personal data – Directive (EU) 2017/1132 – Non-compulsory personal data – Lack of consent of the data subjec

*Source: Court of Justice of the European Union, C-200/23, 2024-10-04 — https://overview.legal/posts/132161 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0200*

The Court of Justice of the European Union (First Chamber) ruled on a preliminary reference from the Bulgarian Supreme Administrative Court in a dispute between the Agentsia po vpisvaniyata (Registration Agency) and OL concerning the Agency's refusal to erase personal data contained in a company's constitutive instrument published in the commercial register. The Court held that non-compulsory personal data included in company documents under Directive (EU) 2017/1132 does not qualify as processing necessary for compliance with a legal obligation under GDPR Article 6(1)(c), and where no other valid legal basis applies (such as consent under Article 6(1)(a)), the data subject is entitled to erasure under Article 17; furthermore, publication of such data without a valid legal basis may constitute non-material damage compensable under Article 82, though the existence and amount of any compensation depends on national court assessment of the actual harm suffered. No fine was imposed, as this was a preliminary ruling proceeding.

### VwGH - Ro 2022/04/0026

*Source: Austrian Administrative Supreme Court, 2024-05-17 — https://overview.legal/posts/187377 — original: https://gdprhub.eu/index.php?title=VwGH_-_Ro_2022/04/0026*

Facts — The data subjects, joint operators of a hotel and restaurant business, ran their establishment through a family business. The controller operates an online travel platform accessible in Austria, on which registered users can post reviews and experience reports about listed establishments, in addition to general information. The data subjects' business was listed on the platform without their consent and was reviewed by users a few times per month, in comments that identified the data subjects by name, including both positive and negative reviews. On 27 June 2019, the data subjects requested that the controller erase all their personal data from the platform. The controller did not comply. On 28 August 2019, the data subjects lodged a complaint with the Austrian DPA, alleging unlawful processing and a violation of their right to erasure under Article 17(1)(d) GDPR. The DPA rejected the complaint on 18 September 2020, relying on Article 6(1)(f) GDPR (legitimate interests) as the legal basis for the processing. The data subjects appealed to the Federal Administrative Court (BVwG), which held an oral hearing and dismissed the appeal on 13 May 2022. The BVwG found that the platform's processing served a legitimate interest in freedom of expression and information that the reviews concerned the data subjects' social andprofessional sphere rather than their private sphere, that it was reasonable to expect the data subjects to monitor the platform for unjustified criticism and that the controller had taken adequate measures against abusive reviews. The BVwG declared an appeal on points of law (Revision) admissible, citing the absence of Supreme Administrative Court case-law on the principles governing the balancing of interests for review platforms under Article 6(1)(f) GDPR. The data subjects appealed to the Supreme Administrative Court. Holding — The court dismissed the appeal as unfounded, addressing each contested element of the three-part test under Article 6(1)(f) GDPR (legitimate interest, necessity, no overriding interest of the data subject). On legitimate interest: The court held that the exercise of freedom of expression and information can constitute a legitimate interest under Article 6(1)(f) GDPR. It reasoned that both service recipients' freedom to express opinions about service quality and the conduct of those providing the service and prospective recipients' freedom to access such opinions, were protected by this provision and that the platform served this purpose by enabling reviews and structured searches. The court held that the controller's pursuit of commercial interests alongside this function did not undermine the legitimate interest, since Article 6(1)(f) GDPR expressly covers interests of the controller "or a third party" and the data subjects had not substantiated their claim that the controller had abandoned a neutral intermediary role. It also rejected the argument that the public's interest was too narrow to qualify as legitimate merely because the hotel's clientele was limited, holding that such considerations belong to the separate balancing-of-interests stage, not to the threshold question of whether a legitimate interest exists at all. On the sphere of privacy affected: The court agreed with the lower court that the reviews concerned the data subjects' social sphere (specifically, their professional sphere as hotel operators) rather than their private sphere, since the criticised conduct occurred in public in the course of providing services to third parties. It held that this classification does not change merely because the business could hypothetically be sold to a third party in future, such a change of circumstances could be considered if and when it actually occurred, but did not retroactively reclassify the current processing. On the reasonableness of monitoring the platform: The court held that requiring the data subjects to check the platform for reviews was not excessive, given the low frequency of reviews, the availability of an email notification service and the fact that hotel operators offering services to the public must accept a degree of observation and criticism. The court limited the relevant comparison to the controller's own platform, not all review platforms on which the business might be listed, since only a claim against this controller was at issue. On protection against abuse: The court held that the absence of identity verification for reviewers was a relevant factor in the balancing exercise, but that a blanket requirement for reviewers to identify themselves would be disproportionate, given the recognised value of anonymous expression online. It held that the controller's existing measures allowing establishment representatives to report abusive reviews for removal, were sufficient, although it criticised the lower court's findings on this point as underdeveloped. However, since the data subjects failed to show that any specific personal data would have been removed had a stricter verification system existed, this shortcoming did not establish unlawfulness in the specific case. On the second data subject's claim of heightened risk as a former political figure: The court held that a data subject wishing to invoke a "particular situation" under Article 21 GDPR must lodge an actual objection to processing on that basis; simply mentioning a past political role during proceedings did not amount to such an objection and the erasure request had in fact been based solely on unlawful processing under Article 17(1)(d) GDPR, not the objection-based ground under Article 17(1)(c) GDPR. Finally, the court declined the data subjects' request for a preliminary reference to the CJEU, noting that the CJEU has already made clear that the case-specific balancing of interests under Article 6(1)(f) GDPR is a matter for the national court. (C-252/21)

### Judgment of the Court (Third Chamber) of 11 April 2024.#GP v juris GmbH.#Request for a preliminary ruling from the Landgericht Saarbrücken.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 82 – Right to compensation for damage caused by data processing that infringes that regulation – Concept of ‘non-material damage’ – Impact of the seriousness of the damage suffered – Liability of the controlle

*Source: Court of Justice of the European Union, C-741/21, 2024-04-11 — https://overview.legal/posts/132262 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0741*

In Case C-741/21, the Court of Justice of the European Union (Third Chamber) addressed a preliminary reference from the Landgericht Saarbrücken in proceedings between data subject GP and juris GmbH concerning GP's claim for compensation under Article 82 GDPR after the company processed his personal data for marketing purposes despite his objections. The Court held that "non-material damage" under Article 82(1) GDPR must be interpreted broadly and is not subject to a seriousness threshold, that a controller may be exempt from liability under Article 82(3) if it proves it was not in any way responsible for the infringement (including where a person acting under its authority under Article 29 was at fault), and that the criteria for administrative fines under Article 83 GDPR do not apply to the assessment of compensation amounts.

### Judgment of the Court (First Chamber) of 7 December 2023.#UF and AB v Land Hessen.#Requests for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 5(1)(a) – Principle of ‘lawfulness’ – Point (f) of the first subparagraph of Article 6(1) – Necessity of processing for the purposes of the legitimate interests pursued by the controller or by

*Source: Court of Justice of the European Union, C-26/22, 2023-12-07 — https://overview.legal/posts/132278 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0026*

The Court of Justice of the European Union (First Chamber) ruled on preliminary references from the Verwaltungsgericht Wiesbaden in joined cases C-26/22 and C-64/22, concerning UF and AB's challenge to the Hessischer Beauftragter für Datenschutz und Informationsfreiheit's refusal to order SCHUFA Holding AG to delete data regarding the discharge of their remaining debts. The core issue was whether storage of such data by a credit information agency was lawful under GDPR Article 6(1)(f) and whether the supervisory authority's dismissal of the complaints satisfied Article 78's right to an effective judicial remedy. The Court held that the legitimate interests of credit agencies in assessing creditworthiness may justify retention of remaining-debt-discharge data, but the three-year storage period presumptively lawful under German law must be assessed against GDPR necessity and proportionality requirements, and that national courts must conduct full judicial review of supervisory authority decisions rather than limited deferential review. No fine was imposed.

### Österreichische Datenschutzbehörde v CRIF

*Source: CJEU, C-487/21, 2023-10-26 — https://overview.legal/posts/51486 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0487*

Right of access includes obtaining a copy in commonly used electronic form.

### Judgment of the Court (First Chamber) of 22 June 2023.#Proceedings brought by J.M.#Request for a preliminary ruling from the Itä-Suomen hallinto-oikeus.#Reference for a preliminary ruling – Processing of personal data – Regulation (EU) 2016/679 – Articles 4 and 15 – Scope of the right of access to information referred to in Article 15 – Information contained in log data – Article 4 – Definition of ‘personal data’ – Definition of ‘recipients’ – Temporal application.#Case C-579/21.

*Source: Court of Justice of the European Union, C-579/21, 2023-06-22 — https://overview.legal/posts/132284 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0579*

In Case C-579/21, the Court of Justice of the European Union ruled on a preliminary reference from the Itä-Suomen hallinto-oikeus (Administrative Court of Eastern Finland) concerning a dispute between J.M. and Pankki S, a Finnish bank, after the Apulaistietosuojavaltuutettu (Assistant Data Protection Supervisor) rejected J.M.'s request for access to certain log data. The core issue was the scope of the right of access under Article 15 of the GDPR, specifically whether log data containing information about who accessed personal data and when constitutes "personal data" and whether the controller must communicate the identities of recipients. The Court held that log data relating to consultations of a data subject's personal data constitutes personal data under Article 4(1) of the GDPR, and that a data subject is entitled to obtain the identities of recipients of their data, subject only to exceptions expressly provided by law or overriding rights of third parties. No fine was imposed as this was a preliminary ruling proceeding.

### Judgment of the Court (First Chamber) of 12 January 2023.#RW v Österreichische Post AG.#Request for a preliminary ruling from the Oberster Gerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 15(1)(c) – Data subject’s right of access to his or her data – Information about the recipients or categories of recipient to whom the personal data have been or will be disclosed – Restrictions.#C

*Source: Court of Justice of the European Union, C-154/21, 2023-01-12 — https://overview.legal/posts/132299 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0154*

The Court of Justice of the European Union (First Chamber), in response to a preliminary reference from the Oberster Gerichtshof (Austrian Supreme Court), interpreted Article 15(1)(c) GDPR in proceedings between data subject RW and Österreichische Post AG regarding the scope of the right of access to information about recipients or categories of recipients of personal data. The Court held that controllers must provide the actual identities of specific recipients to whom personal data have been or will be disclosed, rather than merely naming categories of recipients, unless a further specification is impossible. The Court clarified that while the right of access under Article 15(1)(c) is not absolute and may be balanced against the rights and freedoms of others, including trade secrets, such restrictions must not result in a refusal to provide all information to the data subject.

### LG Rostock - 3 O 762/19

*Source: LG Rostock, 2020-09-15 — https://overview.legal/posts/122848 — original: https://gdprhub.eu/index.php?title=LG_Rostock_-_3_O_762/19*

Facts — The German consumer organisation Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband e.V. (vzbv, the claimant) filed a lawsuit against advocado GmbH (advocado, the defendant), a German-based company that runs an online platform where attorneys can offer their services. The defendant's website had used a cookie banner with pre-ticked boxes for the use of marketing and analytics cookies. This included the use of tools such as Google Analytics that entail a data transfer to third countries. The claimant argued that the data processing in connection with the placed cookies was unlawful under Article 6(1) GDPR: A user's consent under Article 6(1)(a) GDPR could not be considered valid under Articles 4(11) and 7 GDPR, especially since the boxes were pre-ticked. Moreover, the claimant claimed that the defendant had violated Articles 5(1)(a), 13/14, 26 and 44 et seqq. GDPR as it had failed to properly inform users of the scope of intended processing activities, joint controllers and international data transfers in connection with the use of cookies. The defendant stated that it had based the use of cookies on legitimate interests under Article 6(1)(f) GDPR until the CJEU issued its decision C-673/17 on 01.10.2019 ("Planet 49"). Afterwards, the defandent argued that they changed the legal basis for processing to consent under Article 6(1)(a) GDPR, which it considered valid under Articles 4(11) and 7 GDPR. The defendant also stated that it was the sole controller for the processing activities - there were no joint controllers involved, only processors. (Furthermore, the claimant had also argued that some provisions in the defendant's general terms and conditions were unlawful from a civil law / consumer protection law perspective. This will not be discussed further in this summary.) Dispute — Was it necessary to ask for the users' consent under Article 6(1)(a) GDPR or could the processing activities in connection with the use of marketing and analytics cookies be based on legitimate interest under Artilce 6(1)(f)? Was the consent given by users' when interacting with the defendant's cookie banner valid under Articles 6(1)(a), 4(11) and 7 GDPR? Did the defendant violate GDPR provisions on transparency? Was the defendant the sole controller regarding the processing activities in connection with the use of marketing and analytics cookies or were there any joint controllers? Holding — Legal basis and validity of consent — The court held that the marketing and analytics cookies used by the defendant c an only be placed with the users' consent under Article 6(1)(a) GDPR : § 15(3) Telemediengesetz that deals with such cookies must be interpreted in light of Article 5(3) e-Privacy Directive, which requires consent for cookies not strictly necessary for technical reasons. Taking into consideration the design of the cookie banner and the lack of information provided to a website user, the court held that consent given could not be considered valid under Articles 6(1)(a), 4(11) and 7 GDPR. The banner featured pre-ticked boxes and a big "OK" button. The option "use only necessary cookies" was designed to not look like an interactive button but rather a link. Consent could therefore not be considered "freely given" and was invalid. Transparency — The court further held that the defendant violated Article 13 GDPR by mentioning an incorrect transfer mechanism under Articles 44 et seqq. GDPR for data transfers in connection with the use of cookies. Sole or joint controllership when using Google Analytics? — Lastly, the court held that the use of Google Analytics results in joint controllership of the website provider using this tool and Google . Google does not qualify as the website provider's processor under Article 4(7). This is because Google does not process the data solely for the purpose of use by the website provider. Rather, Google, like other third-party providers, expressly reserves the right to process the data for its own purposes as well. The fact that the defendant and Google entered into a data processing agreement under Article 28 GDPR does not change this assessment. The court's legal view is in line with the official opinion of the "Datenschutzkonferenz", a gathering of all German DPAs.

### GC and Others v CNIL

*Source: CJEU, C-136/17, 2019-09-24 — https://overview.legal/posts/51475 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62017CJ0136*

Conditions for delisting sensitive data from search results.

## Guidance

### EDPB Leaflet

*Source: EDPB, edpb-leaflet-en, 2019-03-28 — https://overview.legal/posts/126228 — original: https://www.edpb.europa.eu/documents/other-guidance/edpb-leaflet_en*

edpb.europa.eu Editor: Secretariat of the European Data Protection Board, Rue Montoyer 30, 1047 Brussels. GDPR and your rights Data protection, a fundamental right for every EU data subject AI AI A new level of cooperation between European regulators The European Data Protection Board (EDPB), a new independent EU body, brings together all supervisory authorities in the EEA, as well as the European Data Protection Supervisor. The EDPB contributes to the consistent application of the GDPR by: •…

### Art. 29 WP Guidelines on GDPR transparency requirements (WP260 rev.01)

*Source: EDPB, edpb-guidelines-on-transparency, 2025-11-21 — https://overview.legal/posts/38076 — original: https://www.edpb.europa.eu/system/files/2023-09/wp260rev01_en.pdf*

The Article 29 Data Protection Working Party issued these guidelines (WP260 rev.01), adopted on 29 November 2017 and last revised on 11 April 2018, to provide interpretive and practical guidance on the transparency requirements under the GDPR (Articles 12–14). The document addresses the form, timing, content, and modalities of information provided to data subjects, including issues such as plain language, layered privacy notices, information for children, and exceptions to the obligation to provide information. No fines or enforcement actions are imposed, as this is a guidance document rather than an enforcement decision.

### Opinion 07/2025 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data by the European Patent Organisation

*Source: EDPB, edpb-opinion-202507-epo-adequacydecision-en, 2025-05-06 — https://overview.legal/posts/50823 — original: https://www.edpb.europa.eu/documents/adequacy/opinion-072025-regarding-the-european-commission-draft-implementing-decision_en*

EDPB, Opinion 07/2025 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data by the European Patent Organisation, 2025.

### Statement 1/2023 on the first review of the functioning of the adequacy decision for Japan

*Source: EDPB, statement-12023-on-the-first-review-of-the-functioning-of-en, 2023-07-18 — https://overview.legal/posts/125837 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-12023-on-the-first-review-of-the-functioning-of_en*

1 Statement 1/2023 on the first review of the functioning of the adequacy decision for Japan Adopted on 18 July 2023 The European Data Protection Board has adopted the following statement: On 3 April 2023, the European Commission issued the report on the first review of the functioning of the adequacy decision for Japan adopted on 23 January 2019, along with a Commission Staff Working Document (SWD(2023) 75) 1 . In its Implementing Decision (EU) 2019/419, the European Commission found, pursuant…

### Guidelines 03/2021 on the application of Article 65(1)(a) GDPR

*Source: EDPB, edpb-guidelines-on-the-application-of-article-651a-gdpr, 2023-05-24 — https://overview.legal/posts/38137 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-032021-on-the-application-of-article-651a-gdpr_en*

The European Data Protection Board (EDPB) adopted Guidelines 03/2021 to clarify the dispute resolution mechanism under Article 65(1)(a) GDPR, which governs the EDPB's authority to issue binding decisions when a Lead Supervisory Authority receives relevant and reasoned objections from Concerned Supervisory Authorities that it does not follow. The Guidelines address the procedural framework, the threshold for "relevant and reasoned" objections, the scope of the EDPB's substantive competence, and applicable procedural safeguards including the right to be heard, access to the file, and available judicial remedies.

### Guidelines 01/2022 on data subject rights - Right of access

*Source: EDPB, edpb-guidelines-on-data-subject-rights---right-of-access, 2023-04-17 — https://overview.legal/posts/38055 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-012022-on-data-subject-rights-right-of-access_en*

The right of access of data subjects is enshrined in Art. 8 of the EU Charter of Fundamental Rights. It has been a part of the European data protection legal framework since its beginning and is now further developed by more specified and precise rules in Art. 15 GDPR.

### EDPB Annual Report 2021

*Source: EDPB, edpb-annual-report-2021-en, 2022-05-12 — https://overview.legal/posts/125941 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-annual-report-2021_en*

Enhancing the depth and breadth of data protection 2 EDPB Annual Report 2021 2 ENHANCING THE DEPTH AND BREADTH OF DATA PROTECTION An Executive Summary of this report, which provides an overview of key EDPB activities in 2021, is also available. Further details about the EDPB can be found on our website at edpb.europa.eu. 3 EDPB Annual Report 2021 3 GLOSSARY 7 FOREWORD 10 2021 - HIGHLIGHTS 13 3.1. STRATEGY 2021-2023 AND WORK PROGRAMME 2021-2022 13 3.2. EDPB OPINIONS ON DRAFT UK ADEQUACY…

### Guidelines 10/2020 on restrictions under Article 23 GDPR

*Source: EDPB, edpb-guidelines-on-restrictions-under-article-23-gdpr, 2021-10-13 — https://overview.legal/posts/38062 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-102020-on-restrictions-under-article-23-gdpr_en*

The European Data Protection Board (EDPB) issued these guidelines to clarify the scope and application of Article 23 of the GDPR, which allows Member States to restrict certain data subject rights and controller obligations. The guidelines outline the necessary conditions and safeguards, emphasizing that any restrictions must respect the essence of fundamental rights and be implemented via foreseeable, proportionate legislative measures. This document serves as authoritative guidance for interpreting the specific grounds and requirements under which Member States may legally impose such limitations.

## Enforcement decisions

### CNIL fines energy supplier for mishandling data subject access and objection requests

*Source: CNIL (France), 2026-07-17 — https://overview.legal/posts/125641 — original: https://gdprhub.eu/index.php?title=CNIL_(France)_-_SAN-2022-011*

Facts — The controller is a limited liability company whose business is the supply and production of electricity and gas in France. Several data subjects sent complainants to the French DPA (CNIL) that they had encountered difficulties in exercising their rights of access to personal information about them, and objection to receiving commercial prospecting telephone calls from the controller. The complaints concerned data subject requests for rectification of personal data, late, erroneous, or no response to access to personal data and access to the origin of personal data, failure to cease processing of personal data after objection to the processing of data for commercial prospecting (marketing) purposes, and request for personal data deletion. The DPA appointed a rapporteur that carried out an audit of the website of the controller and investigated the various complaints of the data subjects. The controller in its defence argued that 1) the data subjects' access requests were not sent by the data subjects to the controller’s dedicated unit and that the person who received the requests did not know how to identify their purpose; 2) the procedures it had put in place were not respected because of human error; 3) there were a large number of requests received in 2020 during the health crisis and this was impeded by the disruptions that followed; 4) there were difficulties in obtaining the necessary information from its business partners, thus unable to properly inform data subjects about the source of their data; 3) It had taken steps to modify its processing activities to comply with the relevant applicable laws; 4) The breach affected barely a fraction of its customers. Beyond the direct complaints made by the data subjects, the DPA in its investigation noted that when subscribing online on the controller's website, the subscription form had no option for users to object to the use of their personal data for marketing purposes. The subscription form informed users that their personal data may be used by the controller to present offers to them at a later date. On this point, the controller argued that 5) the CPCE did not apply to the online subscription form, since the collection of personal data through the form was not intended to promote the company's products or services, but to offer assistance to the user in order to help them finalize the current subscription. Holding — The DPA held that the lack of an option for a user to object to the processing of their personal data for marketing purposes, at the time of collection, constitutes a breach of the provisions of article L. 34-5 of the French Post and Electronic Telecommunications Code (CPCE). The DPA observed that, in certain cases, the data subjects contacted for marketing purposes were not provided with any information required in Article 14 GDPR, such as the purposes of the processing or the existence of the various rights. They were not informed that the call was being recorded, nor of their right to object to it. The DPA observed that the controller had failed to respond, supplied erroneous responses, or responded late to several data subject requests, beyond the deadlines set by Article 12 GDPR, often after several reminders from the data subject. The DPA observed that the controller failed to process the various data subject’s requests for access to personal data, their origin, as well as access to recordings of telephone conversations concerning the data subjects within the time limit set with the obligations of Article 15 GDPR. The DPA finally observed that the controller continued to process the personal data of data subjects after objections from the data subjects to the processing of their personal data in breach of Article 21 GDPR. The DPA held that the controller cannot rely on its difficulties in obtaining information from its commercial partners to justify its failure to provide a response to the applicants in accordance with the applicable provisions. It is the duty of the controller to organize itself in such a way as to be able to ensure that requests for access are processed in accordance with the applicable provisions and, in particular, to provide information on the origin of the data. The DPA further held that although data subjects did not send their access requests directly to the unit in charge of responding to them, it is up to the controller, as long as the requests, one of which was directly addressed to the data protection officer, were received in clear terms by the controller, to process them within the time limits provided for and to ensure that they were transmitted to the competent department responsible for handling such requests. For these violations, the DPA fined the controller €1,000,000. The controller argued against the publication of the penalty decision, on the ground that publication would be disproportionate in light of the limited nature of the alleged breaches and its compliance. It also claimed that publication of the penalty would have a significant impact on the controller’s image and that it would be favorable to its main competitors, in a very competitive market. The DPA also decided to make its decision public on the CNIL website and on the Légifrance website and held that the controller will no longer be identified by name after a period of two years from its publication. The DPA noted that the company has taken measures to bring its processing into compliance with the applicable laws, and the efforts made by the company to comply throughout the procedure. The DPA also noted that the controller’s agents have had to attend awareness training on the subjects of the complaints.

### SPAIN DPA: Insufficient fulfilment of information obligations

*Source: Spanish Data Protection Authority (aepd), 2023-06-16 — https://overview.legal/posts/47992 — original: https://www.enforcementtracker.com/ETid-1877*

The Spanish DPA has imposed a fine of EUR 2,000 on a controller for failing to provide data subjects with sufficient information to exercise their right to object.

### Tensa Art Design SA: Insufficient fulfilment of data subjects rights

*Source: Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), 2023-04-24 — https://overview.legal/posts/47899 — original: https://www.enforcementtracker.com/ETid-1784*

The Romanian DPA has imposed a fine of EUR 1,000 on Tensa Art Design SA. The controller failed to comply with a data subject's right to object.

### APD/GBA (Belgium) - 117/2022

*Source: APD/GBA (Belgium), 2022-07-26 — https://overview.legal/posts/6318 — original: https://gdprhub.eu/index.php?title=APD/GBA_(Belgium)_-_117/2022*

Facts — The data subject was a former customer of the controller (which remained unknown). The data subject received direct marketing from the controller. The data subject objected to the further processing of its personal data while also requesting access to all personal data processed by the controller and the legal basis used to send the direct marketing. The controller responded within 30 days, confirming that the data subject would no longer receive direct marketing and provided all processed data, including the applicable legal bases. The data subject then submitted a complaint at the DPA stating that the controller cannot rely on legitimate interest for processing its email adress as the data subject was a former, not current customer. Holding — The DPA held that a controller is allowed to rely on legitimate interest to send direct marketing, including former customers under certain conditions, pursuant to Recital 47 GDPR and its Guidance 01/2020 on Direct Marketing (nr. 168). In its Guidance, it was stated that when there was no relationship between the controller and data subject, or when it goes back a long time, legitimate interest cannot be invoked, as direct marketing is not part of the data subject's reasonable expectations. The DPA followed that because the relationship between the controller and the data subject ended not that long ago (around two years prior), a contrario, the data subject could reasonably expect that his data would still be used for direct marketing. Hence the controller could use legitimate interest as a legal basis. In addition, the controller confirmed that the processing for direct marketing is only done up to two years after the cancellation of the service. The DPA therefore held that the controller did not breach the GDPR and dismissed the case.

### AEPD (Spain) - PS/00259/2020

*Source: AEPD (Spain), 2021-07-06 — https://overview.legal/posts/184544 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS/00259/2020*

Facts — A data subject exercised their right to object to receiving commercial communications against a bank (Bankia/Caixabank), after what whose DPO confirmed that the right had been correctly exercised. However, two years after that, the data subject received a letter from the bank which envelope contained a commercial communication, promoting and informing about the bank's services. The data subject lodged a complaint with the Spanish DPA (AEPD). The bank alleged that it was not a commercial communication but a mere standard envelope like the banners and signs that they display at their offices, that include information about the bank's services, and that the letter inside was just information sent to the client regarding the services that they had contracted. The bank also stated that it was not a direct marketing action, as it did not include any profiling or made use of individual preferences, but was general information sent to their clients. They alleged that they were relying on a legitimate interest for this. The bank also alleged that they had not processed their client's data for marketing purposes, since the processing was done to send the letter, and the envelope containing the commercial message was just accidental to it, but the data was not processed for that purpose. Holding — The Spanish DPA determined that the actions performed by the bank were nevertheless commercial communications with a marketing purpose, and that the controller did not have a legal basis for doing so, as the bank could not rely on a legitimate interest since the data subject had exercised their right to object, in accordance to Article 21 GDPR. The Spanish DPA also made reference to Recitals 69 and 70. The AEPD also noted that the privacy policy of the bank declared that commercial communications were based on consent, contrary to what the controller alleged during the procedure. Therefore, the AEPD concluded that there had been a violation of Article 6(1)(f) and fined the controller €50,000, compelling it to implement the necessary measures to prevent the sending of commercial communications to data subjects that have objected to them. The Spanish DPA took into account the lack of diligence, the scope of the infringing behaviour (even if in this case there was an only claimant, the lack of measures to prevent it may make it happen regarding other clients), the link between the controller's activity and the infringement, and the recidivism of the controller; and the fact that the entity was assimilated by another entity, so the infringement could be attributed to the latter entity, as a mitigating factor.

### Telekom Romania Communications SA: Insufficient fulfilment of data subjects rights

*Source: Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), 2021-05-13 — https://overview.legal/posts/46791 — original: https://www.enforcementtracker.com/ETid-676*

The Romanian DPA (ANSPDCP) has imposed a fine of EUR 2,000 on Telekom Romania Communications SA. The controller had made an advertising call to the data subject although the latter had exercised his right to object to the processing of his personal data for marketing and advertising purposes by requesting the controller to delete his telephone number and e-mail address from the Telekom database.

### H&M Hennes & Mauritz GBC AB: Insufficient fulfilment of data subjects rights

*Source: Data Protection Authority of Sweden, 2023-10-17 — https://overview.legal/posts/48185 — original: https://www.enforcementtracker.com/ETid-2070*

The Swedish DPA has imposed a fine of EUR 30,000 on H&M for sending out marketing messages, despite the fact that data subjects had exercised their right to objection. Six data subjects had filed a complaint against the controller with the DPA. The DPA found that the controller did not have sufficient systems and procedures in place to facilitate data subjects exercising their right to object to direct marketing.

### Italian DPA sanctions Lusha Systems for processing contact data without consent in B2B

*Source: Garante per la protezione dei dati personali (Italy), 2026-07-14 — https://overview.legal/posts/184678 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_542/2026*

Facts — Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database. It was an US company wholly owned by Lusha Systems Ltd. In April 2025, the Italian DPA (Garante) initiated an investigation after media reports revealed that telephone numbers of senior Italian officials were available on the platform. The DPA later received one complaint and one report from data subjects who had received unsolicited advertising communications. The data subjects further stated that after requesting information about the source of their contact details, they discovered that their data were available on the controller’s platform without their consent. The controller explained that, for a subscription fee, it provided its Clients with a Business Contact Card for each Contact. The controller further distinguished between “Clients”, namely customers who used the platform and accessed its B2B database, and “Contacts”, namely the individuals whose personal data were included in that database, regardless of whether they used or were aware of the platform. Clients received Contact Cards containing information such as names, professional email addresses, telephone numbers, job titles, roles and locations, which could be used for sales, marketing, recruitment, business intelligence and fraud prevention. The DPA limited its investigation to the processing of Contacts’ personal data. The controller stated that it collected and combined data from publicly available sources, specialised providers, affiliated companies and commercial partners. It also inferred missing professional email addresses through algorithms that identified standard company email patterns. Through its Community Program and integrations with email, calendar and CRM services, it could also obtain information from Clients’ professional networks and communications. The data were cross-referenced, enriched and regularly updated to reflect changes in Contacts’ professional circumstances. The controller argued that the GDPR did not apply because it was established outside the EU and provided services only to businesses. It additionally claimed that the weekly updating of Contact Cards ensured accuracy rather than constituting monitoring or profiling. The controller maintained that the collection and disclosure of the data were necessary for its own economic interest in providing accurate professional contact information and for its Clients’ interests, including fraud prevention. According to the controller, it processed only a limited range of information concerning the Contacts’ professional lives. It further claimed that individuals who made professional information publicly available, particularly through services such as LinkedIn, could reasonably expect that the information might be reused and that they could be contacted regarding professional opportunities. Regarding transparency, the controller stated that its Personal Information Notice was sent to each Contact before their information became available in the database. It explained that it notified Contacts that they had a seven-day period during which they could opt out before their information became available to Clients. The controller also maintained that excluding public officials and public figures from the database was not a requirement under the GDPR. It attributed the presence of certain public officials to technical limitations in its filtering system. It also argued that public figures had a lower expectation of privacy. After the proceedings began, the controller removed profiles connected with Italian public bodies and officials, strengthened its filters and customer-verification measures, discontinued the Community Program in Italy and extended the opt-out period to fourteen days. Holding — Regarding the territorial scope of the GDPR, the DPA acknowledged that Article 3(2)(a) GDPR could apply to the processing of Clients’ data, but not to Contacts, since they were not recipients of the service. However, it held that Article 3(2)(b) GDPR applied because the controller systematically combined, enriched and updated Contacts’ professional information in order to assess their circumstances and determine whether and how they would appear in the database. Referring to Recital 24 and Recital 30, the DPA held that monitoring did not require profiling. It noted that the systematic observation of online traces and changes in a person’s professional situation was sufficient. The fact that the processing also served data accuracy did not alter that conclusion. It emphasised that the fact that the controller also updated the information to ensure its accuracy did not prevent the processing from constituting monitoring. Regarding transparency, the DPA found that the information concerning the collection of the Contacts’ data, the purposes of the processing and the legal basis relied upon was scattered across several documents. Also, the relevant information was not easily accessible from the controller’s homepage, while the Personal Information Notice could not be located directly through the website without prior knowledge of its existence. It further pointed out that the documents were provided in English rather than in the language of the affected data subjects. The DPA held that presenting the information in this manner did not satisfy the requirement that information be concise, transparent, intelligible and easily accessible. It therefore found an infringement of Article 5(1)(a) GDPR and Article 12 GDPR. Moreover, the DPA assessed whether Article 6(1)(f) GDPR provided a valid legal basis for the processing. It examined the controller’s Legitimate Interest Assessment and considered it essentially non-existent, as it contained only generic statements on necessity and proportionality and no genuine balancing assessment. The DPA then applied the three-part test under Article 6(1)(f) GDPR. It held that making the Contacts’ data available to Clients for their own marketing and sales activities could not constitute a legitimate interest, since the disclosure of contact information to third parties for their independent advertising purposes required prior consent under the applicable national and ePrivacy framework . However, it acknowledged that the controller’s interest in fraud prevention could be considered legitimate. The DPA nevertheless found that the processing was not necessary for the purposes pursued. It held that the controller collected information extending beyond ordinary professional contact details, including third-party data contained in CRM databases, email headers and subject lines, information about calendar meetings, and browsing data collected through browser extensions or other software integrations used by Clients. It pointed out that much of this information was not publicly available but was extracted from private interpersonal communications, disclosed by Clients, obtained through integrations with information systems or acquired from third-party providers. The DPA held that the collection and combination of such extensive information was neither strictly necessary nor proportionate for creating professional Contact Cards. Furthermore, it stressed that fraud prevention could also have been achieved through less intrusive means. The DPA therefore concluded that the necessity requirement and the principle of data minimisation were not met. Regarding the balancing test, the DPA emphasised that there was no prior relationship between the controller and the Contacts. Creating a professional profile on LinkedIn or another professional platform did not create a reasonable expectation that unpublished contact details would be collected from multiple sources, continuously updated and disclosed to an unspecified number of paying customers. It further noted that the processing could expose Contacts to communications from unknown third parties for purposes they could not reasonably anticipate. The DPA concluded that the Contacts’ interests, rights and freedoms prevailed over the controller’s economic interests and that the safeguards adopted by the controller could not change this outcome. Therefore, the DPA held that Article 6(1)(f) GDPR did not provide an appropriate legal basis and found that the controller infringed Article 5(1)(a) GDPR, Article 5(1)(c) GDPR, and Article 6 GDPR. Regarding public officials, the DPA held that their status did not reduce their entitlement to data protection and that no public interest justified disclosing their direct contact details for commercial purposes. The DPA further found that the controller had been aware of the risk that public officials could be included in its database but had failed to implement sufficiently effective technical and organisational measures. Its filters recognised general titles such as “President” but failed to exclude more specific titles such as “President of the Italian Republic” and “Vice Prime Minister”. The DPA therefore found an infringement of the principle of data minimisation under Article 5(1)(c) GDPR and the obligation of data protection by design and by default under Article 25 GDPR. The DPA imposed a fine of €2,000,000. Furthermore, it prohibited any further processing of personal data of data subjects located in Italy that had been collected without an adequate legal basis and ordered their deletion.

## Recent developments

### One-Stop-Shop case digest on right to object and right to erasure updated

*Source: European Data Protection Board, 2026-06-25 — https://overview.legal/posts/53055 — original: https://www.edpb.europa.eu/news/one-stop-shop-case-digest-on-right-to-object-and-right-to-erasure-updated_en*

Brussels, 25 June - The EDPB has published an update of the One-Stop-Shop (OSS) case digest on right to object and right to erasure. This project has been developed in the framework of the of the Support Pool of Experts programme, which aims to support cooperation among Data Protection Authorities (DPAs).Thematic one-stop-shop case digests are drafted on the basis of one-stop-shop decisions taken from the EDPB’s public register (based on Art.60 GDPR). Such case digests complement the EDPB's publ

### Dirkzwager: ABRvS geeft uitleg aan het AVG-begrip "de instelling, uitoefening of onderbouwing van een rechtsvordering"

*Source: Dirkzwager, 2022-10-05 — https://overview.legal/posts/6332 — original: https://www.dirkzwager.nl/kennis/artikelen/abrvs-geeft-uitleg-aan-het-avg-begrip-de-instelling-uitoefening-of-onderbouwing-van-een-rechtsvordering/#entry-968*

> Privacybescherming is niet absoluut. Dat staat zelfs letterlijk zo in de privacywetgeving. De AVG bevat daarom ook allerlei uitzonderingen. Een van de uitzonderingen die enkele keren terugkomt in de AVG ziet op de verwerking van persoonsgegevens in het kader van "de instelling, uitoefening of onderbouwing van een rechtsvordering". Tot op heden was echter niet heel erg duidelijk wat die woorden nu precies betekenen. Een recente uitspraak van de Afdeling bestuursrechtspraak van de Raad van State

### Record fine for Instagram following EDPB intervention

*Source: EDPB, 2022-09-15 — https://overview.legal/posts/6279 — original: https://edpb.europa.eu/news/news/2022/record-fine-instagram-following-edpb-intervention_en#entry-378*

> Following the EDPB’s binding dispute resolution decision of July 28th, the Irish Data Protection Authority (DPA) has adopted its decision regarding Instagram (Meta Platforms Ireland Limited (Meta IE)) and has issued a record GDPR fine of €405 million.

### Please note that this is not about opting out of the European Health Data Space (EHDS) itself, but rather about the opt-out mechanism that is provided for within the EHDS.

*Source: Government, 2025-04-09 — https://overview.legal/posts/52184*

Concise government statement, opt-out from the European Health Data Space (EHDS) and other commitments. Please note that this is not an opt-out from the EHDS itself, but rather an opt-out regulated within the EHDS.

### European regulators are finalizing a decision blocking Meta from transferring data to the US

*Source: Politico, 2022-08-22 — https://overview.legal/posts/6286 — original: https://www.politico.eu/article/norway-wants-facebook-to-be-fined-for-illegal-data-transfers/#entry-1190*

> “Based on the facts of the case, we do not see how [Meta] could have continued its personal data transfers following the Schrems II judgment had it acted in accordance with the GDPR,” the Norwegian objection reads.

## Literature

### The right not to be subject to automated decision-making under the General Data Protection Regulation: Standard permission or default prohibition?

*Source: Journal of Data Protection Privacy, 2017-09-01 — https://overview.legal/posts/132608 — original: https://doi.org/10.69554/fouz3166*

The right not to be subject to automated decision-making which has a legal or similar effect was originally taken up in the 1995 Privacy Directive and is thus not a new right in the General Data Protection Regulation (GDPR). The 1995 Privacy Directive left room for interpretation of its rights and obligations, of which the EU member states have made use. Some member states have interpreted the right as a ban on automated decision-making, while other member states allow automated decisions to whi

### Privacy vs. business convenience: the Mousse judgment and the future of data protection in the EU

*Source: Unio - EU Law Journal, 2025-06-18 — https://overview.legal/posts/53865 — original: https://doi.org/10.21814/unio.11.1.6632*

The Mousse ruling represents a pivotal moment in EU data protection law, reinforcing strict limitations on personal data processing and clarifying the legal standards under the General Data Protection Regulation (GDPR). The Court of Justice of the European Union (CJEU) reaffirmed that data collection must be objectively indispensable for a specified legal basis, rejecting broad interpretations of contractual necessity and legitimate interest. Additionally, the ruling confirms that the right to o

### HOW GDPR TREATS AUTOMATED DECISION-MAKING

*Source: Journal Scientific and Applied Research, 2025-11-14 — https://overview.legal/posts/132599 — original: https://doi.org/10.46687/jsar.v28i1.435*

This article examines how the General Data Protection Regulation (GDPR) regulates automated decision-making, including profiling, in the context of personal data processing. It analyzes the main provisions of Article 22 of the Regulation, as well as the conditions under which fully automated decisions that produce legal effects or significantly affect data subjects are permitted. The article highlights the rights of data subjects – the right to human intervention, the right to express their poin

### Can the GPC standard eliminate consent banners in the EU?

*Source: Computer law & security review, 2025-12-10 — https://overview.legal/posts/53850 — original: https://doi.org/10.1016/j.clsr.2026.106332*

In the EU, the General Data Protection Regulation and the ePrivacy Directive mandate informed consent for behavioural advertising and use of tracking technologies. However, the ubiquity of consent banners and popups has led to widespread consent fatigue and questions regarding the effectiveness of these mechanisms in protecting users' data. In contrast, users in California and other US jurisdictions can utilize Global Privacy Control (GPC), a browser-based privacy signal that automatically broad

### Recommendations for Creating Codes of Conduct for Processing Personal Data in Biobanking Based on the GDPR art.40

*Source: Frontiers in Genetics, 2021-11-12 — https://overview.legal/posts/132560 — original: https://doi.org/10.3389/fgene.2021.711614*

Personal data protection has become a fundamental normative challenge for biobankers and scientists researching human biological samples and associated data. The General Data Protection Regulation (GDPR) harmonises the law on protecting personal data throughout Europe and allows developing codes of conduct for processing personal data based on GDPR art. 40. Codes of conduct are a soft law measure to create protective standards for data processing adapted to the specific area, among others, to bi

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Consent** — https://overview.legal/topics/toestemming
  Freely given, specific, informed indication of data subject wishes
- **Law Enforcement** — https://overview.legal/topics/law-enforcement
  Processing for law enforcement purposes

---
Generated by overview.legal · https://overview.legal/topics/right-to-object · 2026-08-22
