# Right to Restriction — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/right-to-restriction
> Sources are cited per item. Verify against the official texts before relying on them.

Right to restrict processing of personal data

## Overview

## Legal Framework

Article 18 GDPR grants data subjects the right to restrict — rather than fully erase — the processing of their personal data. This intermediate remedy applies across four specific scenarios under Article 18(1): (a) where the data subject contests the accuracy of the data, pending the controller's verification; (b) where the processing is unlawful and the data subject opts for restriction instead of erasure; (c) where the controller no longer needs the data for its original purpose but the data subject requires it for the establishment, exercise, or defence of legal claims; and (d) where the data subject has objected under Article 21(1) pending verification of whether the controller's legitimate grounds override the data subject's interests.

When restriction is activated, the controller may — with limited exceptions — only store the data. All other processing activities are suspended unless the data subject consents, the data is needed for legal claims, or processing serves the rights of other natural or legal persons, or important public interest reasons under Article 18(2).

Article 19 imposes a cascading notification obligation: the controller must communicate any restriction of processing to each recipient to whom the personal data were disclosed, unless this proves impossible or involves disproportionate effort. Upon the data subject's request, the controller must also identify those recipients.

## Key Developments

The Court of Justice of the European Union has situated the right to restriction within the broader architecture of data subject rights. In *Österreichische Datenschutzbehörde v CRIF*, the Court confirmed that the right of access under Article 15 serves as a necessary precondition enabling data subjects to exercise downstream rights — including the right to restriction under Article 18. This establishes a practical interdependence: without effective access, restriction claims cannot meaningfully be formulated.

In *Sergejs Buivids v. Augstākā Tiesa*, the Court confirmed that video recordings stored on a hard disk drive constitute automatic processing of personal data, meaning such data falls squarely within the scope of Article 18's protections. Similarly, in *Smaranda Bara et al. v. CNAS*, the Court treated data transfers between public authorities as processing operations, confirming that restriction rights attach to data at each stage of the processing chain — including onward transfers to downstream recipients.

These rulings collectively establish that restriction obligations attach broadly to any operation involving personal data, and that controllers must be prepared to propagate restriction requests across their entire disclosure chain.

## Practical Guidance

- **Implement a restriction mechanism in processing systems.** Article 18(2) permits only storage when restriction is active. Ensure technical configurations can flag restricted records and block further processing — including automated decision-making, profiling, or onward transfers — without deleting the data.

- **Maintain a recipient log for Article 19 compliance.** The notification obligation requires controllers to identify all recipients of restricted data. Without an accurate disclosure trail, demonstrating compliance becomes impossible, and data subject requests for recipient information cannot be fulfilled.

- **Apply a disproportionate-effort test with caution.** Article 19 allows exemption from notification where it proves impossible or involves disproportionate effort, but this threshold is high and must be documented with a reasoned assessment — not assumed.

- **Train intake teams on the four Article 18(1) triggers.** Restriction requests often arrive informally or are bundled with rectification, erasure, or objection requests. Staff must recognize when restriction — rather than full erasure — is the appropriate remedy and process accordingly.

- **Coordinate restriction with parallel rights.** As confirmed in *CRIF*, restriction frequently follows an access request or accompanies an objection under Article 21. Ensure workflows connect these rights so that restriction is applied automatically where applicable, rather than requiring a separate request.

## Legislation (full text of key provisions)

### Notification obligation regarding rectification or erasure of personal data or restriction of processing

*Source: GDPR, gdpr-art-19-en, 2016-04-27 — https://overview.legal/posts/90457*

The controller shall communicate any rectification or erasure of personal data or restriction of processing carried out in accordance with Article 16, Article 17(1) and Article 18 to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort. The controller shall inform the data subject about those recipients if the data subject requests it.

### Right to restriction of processing

*Source: GDPR, gdpr-art-18-en, 2016-04-27 — https://overview.legal/posts/90445*

### Recital 67 — methods to restrict data processing

*Source: GDPR, gdpr-rec-67-en, 2016-04-27 — https://overview.legal/posts/91649*

Methods by which to restrict the processing of personal data could include, inter alia, temporarily moving the selected data to another processing system, making the selected personal data unavailable to users, or temporarily removing published data from a website. In automated filing systems, the restriction of processing should in principle be ensured by technical means in such a manner that the personal data are not subject to further processing operations and cannot be changed. The fact that the processing of personal data is restricted should be clearly indicated in the system.

### Recital 156 — safeguards for archiving research processing

*Source: GDPR, gdpr-rec-156-en, 2016-04-27 — https://overview.legal/posts/91827*

The processing of personal data for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes should be subject to appropriate safeguards for the rights and freedoms of the data subject pursuant to this Regulation. Those safeguards should ensure that technical and organisational measures are in place in order to ensure, in particular, the principle of data minimisation. The further processing of personal data for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes is to be carried out when the controller has assessed the feasibility to fulfil those purposes by processing data which do not permit or no longer permit the identification of data subjects, provided that appropriate safeguards exist (such as, for instance, pseudonymisation of the data). Member States should provide for appropriate safeguards for the processing of personal data for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes. Member States should be authorised to provide, under specific conditions and subject to appropriate safeguards for data subjects, specifications and derogations with regard to the information requirements and rights to rectification, to erasure, to be forgotten, to restriction of processing, to data portability, and to object when processing personal data for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes. The conditions and safeguards in question may entail specific procedures for data subjects to exercise those rights if this is appropriate in the light of the purposes sought by the specific processing along with technical and organisational measures aimed at minimising the processing of personal data in pursuance of the proportionality and necessity principles. The processing of personal data for scientific purposes should also comply with other relevant legislation such as on clinical trials.

## Case law

### CJEU - C‑474/24 - NADA Austria and Others

*Source: GDPRhub, 2026-07-24 — https://overview.legal/posts/108989 — original: https://gdprhub.eu/index.php?title=CJEU_-_C‑474/24_-_NADA_Austria_and_Others*

Facts — Several data subjects were subject to suspension proceedings by the Austrian Anti-Doping Legal Commission (ÖADR). Under Austrian law, the National Anti-Doping Agency (“NADA”) publishes the names of persons who have been suspended on its website. For the duration of the suspension, the website includes information such as the athlete’s name, sport practised, infringement of anti-doping rules, and the duration of the penalty. The ÖADR publishes the same information in a press release, with the addition of the prohibited substances involved. For this summary, both authorities are referred to as the controllers. The data subjects filed a complaint with the DPA on the grounds that the controllers refused their request to cease displaying their names and practised sports. They also argued that the controllers were processing sensitive data within the meaning of Article 9 and 10 GDPR, and that the undifferentiated publication system was incompatible with Article 6(3) GDPR. The DPA dismissed the complaint. In particular, one of the data subjects’ complaints was rejected on the grounds that the relevant data had not been published yet. The data subjects appealed the decision to the Federal Administrative Court (BVwG). The controllers argued that publishing the information in their website was lawful, as it was based on the legal bases of legal obligation (Article 6(1)(c) GDPR) and public interest (Article 6(1)(e) GDPR). The BVwG stayed proceedings and requested a preliminary ruling from the CJEU. The BVwG referred the following questions: Does the GDPR apply to the making information relating to athletes’ anti-doping violations publicly available through websites? If yes: Does information that an individual has committed a specific anti-doping violation fall under the scope of data relating to health within the meaning of Article 9 GDPR? Does the GDPR preclude national legislation from publishing the information mentioned above, if it does not make it possible to infer health data of the person concerned? Does the GDPR require a balancing test between the interests of the data subject and the interest of the general public of being informed of anti-doping violations every time anti-doping violations will be published? Does information that an individual has committed a specific anti-doping violation fall under the scope of data relating to criminal convictions within the meaning of Article 10 GDPR? If yes, must the decisions of the authority processing this data be subject to judicial review? Is filing a complaint before the processing takes place (but was processed during the proceedings) permissible? Or does it become permissible provided that at the time of the complaint there were specific indications that the processing was imminent or would take place in the near future? Advocate General Opinion — The AG gave his opinion on each question separately, with the exception of the third and fourth questions that were answered together. Question 1: Does the GDPR apply to the making information relating to athletes’ anti-doping violations publicly available through websites? — The AG first considered that the GDPR was applicable to this case. Under Article 2(2)(d) GDPR a situation falls outside of the scope of the GDPR when data is processed for the prevention, detection or prosecution of criminal offenses. This is because the Law Enforcement Directive (LED) applies. According to the AG, the GDPR may apply even if personal data relating to criminal convictions is processed if the controllers are not “competent authorities” within the meaning of Article 3(7) LED. If the controllers were competent authorities, the referring court would have to decide if the GDPR applies. The main question the AG addressed is whether the exception under Article 2(2)(a) GDPR applies, meaning the processing falls outside the scope of Union law; here, the AG noted that the exceptions are interpreted narrowly, and may only apply to activities intended to safeguard national security or activities classified in the same category. The AG concluded that the aim of combating anti-doping is not related to national security. The exception did not apply even if the activity fell under the competence of a Member State. Therefore, the GDPR was applicable. Question 2: Does information that an individual has committed a specific anti-doping violation fall under the scope of data relating to health within the meaning of Article 9 GDPR? — The AG first highlighted the sensitive nature of Article 9 GDPR data, which must be interpreted broadly. The AG also noted that the legal basis of the controller does not influence whether the data falls under the scope of health data. Beyond a medical context, the AG opined that the determining factor is whether it is possible to draw inferences about the health status of the data subject. In this case, the AG agreed with the reasoning of the DPA that only specific information relating to the infringements should be considered health data. This is because not all data revealed information related to the data subjects’ health. Specifically, the information regarding the anti-doping tests and its analysis should be considered health data. The AG noted that, while the name of the substance itself may not reveal information on health status, it may be possible to make indirect inferences. However, if the name is not included, the link to the health status of the data subject would be too indirect to fall under the scope of health data. Questions 5 and 6: Does information that an individual has committed a specific anti-doping violation fall under the scope of data relating to criminal convictions within the meaning of Article 10 GDPR, and must the decisions of the authority processing this data be subject to judicial review? — The AG first noted that the GDPR does not prohibit processing this data, but rather subjects it to enhanced scrutiny. The AG assessed whether the processing fell under the scope of Article 10 GDPR based on the three “Engel” criteria in ECtHR case Engel and Others v. the Netherlands. Anti-doping offenses under national law do not fall under the “criminal” classification according to Article 10 GDPR. However, the AG opined that article 10 GDPR applies if the convictions have a punitive purpose and have a degree of severity equivalent to a criminal penalty. This is a matter for the BVwG to decide. In terms of judicial review, the AG stated that the authority at issue is an “official authority” within the meaning of Article 10 GDPR. The wording itself of Article 10 GDPR does not provide for judicial review. However, the AG opined that it must be possible for an act following a decision by an official authority to be subject to judicial review. This is in light of Article 79(1) GDPR and a contextual interpretation of Article 10 GDPR. Questions 3 and 4: Does the GDPR preclude national legislation from publishing the information mentioned in the facts, and does it require a balancing test every time anti-doping violations will be published? — The AG considered, in essence, whether Articles 5(1)(a) and (c), and Article 6(3) GDPR precluded the controllers to publish the data concerned under legal obligation. The AG also considered whether the GDPR requires a case-by-case balancing of interests, or whether the proportionality test provided by the legislator is sufficient. The AG noted that the aim to deter athletes and prevent circumventing of anti-doping rules are legitimate public interest objectives in the context of combating doping in sport. Making this information public online is appropriate in order to achieve the public interest aims, with the exception of referring to the prohibited substance in question. According to the AG, this was not expressly provided for by national law, and is not required to achieve the public interests involved. However, the AG considered the publication of the personal data involved a serious interference with the fundamental rights of the data subjects. While national law provided exceptions on the publication of data (e.g. amateur athletes or vulnerable persons), the AG opined that the publication of personal data for an unlimited amount of time could be considered excessive. Therefore, the AG concluded that making this information publicly accessible is only permitted as long as it is proportionate. Finally, the AG opined that a case-by-case analysis is necessary, as the controllers must comply with data minimisation and accountability principles under the GDPR even if they are designated by national law. Question 7: Is filing a complaint before the processing takes place permissible? — Here, the AG stated that the wording of the GDPR does not seem to preclude a priori a precautionary or preventative approach by the supervisory authorities in handling complaints. Restricting the powers of a DPA to decide on cases involving processing that has already taken place would go against the objectives of the GDPR. Nonetheless, the alleged infringement of the GDPR must be appropriate, and the processing in question cannot be purely hypothetical. In this case, it would be impossible for a controller to erase data that has not been disclosed yet, unless the complaint is interpreted as seeking to prevent the data from being published. The AG stated that it is a matter for the BVwG to decide. The AG noted that the complaint would be inadmissible if it was based on Article 17 GDPR even if the processing is imminent. However, the AG opined that a complaint requesting injunctive relief is potentially admissible under the GDPR and Austrian law in the event of a threat of imminent unlawful interference with data subjects’ rights under the GDPR. This includes requesting the DPA to review a restriction of processing based on Article 18 GDPR before the start of the processing or if the processing has started, as long as the processing is not purely hypothetical. Finally, the AG considered whether a complaint could become admissible a posteriori. Here, the AG opined that it is a matter of the national law system to settle the question, while complying with the principles of effectiveness and equivalence. Holding — The Court held that the GDPR applied to the publication of information concerning anti-doping infringements. Such processing did not fall within the exception under Article 2(2)(a) GDPR, even if anti-doping policy primarily falls within Member State competence. Information that a data subject infringed anti-doping rules and was banned from competitions does not, in principle, constitute health data under Article 9 GDPR. However, it may do so where the publication identifies a prohibited substance or method and, together with other information, allows conclusions to be drawn about the data subject’s health. The Court accepted that combating doping and protecting the fairness and integrity of sport constitute objectives of general interest. Nevertheless, publishing athletes’ identities and sanctions online constitutes a serious interference with their rights. National legislation may therefore require such publication only where the controller can assess, in each case, whether the content and duration of the publication are necessary and proportionate. Publication should not continue longer than strictly necessary and may be disproportionate where a sanction is lengthy or lifelong. The Court also held that Article 10 GDPR did not apply, as the anti-doping infringements formed part of a disciplinary regime and were not criminal in nature. Finally, Article 77 GDPR allows a data subject to lodge a complaint before processing takes place where there are specific indications that the processing is imminent and not merely hypothetical. The DPA must assess the substance of such a preventive complaint.

### OLG München - 36 U 1054/25 e

*Source: Higher Regional Court Munich, 2026-06-26 — https://overview.legal/posts/184545 — original: https://gdprhub.eu/index.php?title=OLG_München_-_36_U_1054/25_e*

Facts — The data subject had used a social media platform operated by the controller, an Irish company, since 2013. The controller provided “Business Tools” to third-party website operators and app providers. These tools enabled the controller to obtain data concerning how users interacted with third-party websites and apps, including information about page visits, purchases and advertisements clicked. In November 2023, the data subject requested that the controller recognize that the processing of his personal data was contrary to the parties’ contract, erase or anonymize the personal data, provide access to the personal data and pay compensation. The data subject subsequently brought an action before the Regional Court of Munich II, seeking a declaration that the parties’ user contract did not permit the processing, cessation of the processing of personal data collected through the Business Tools on third-party websites and apps, restriction of further processing, erasure or anonymization of previously collected data and at least €5,000 in non-material damages. The relevant data included direct and indirect identifiers, such as his name, contact details, IP address and internal identifiers, as well as website URLs, visit times, app names and information about his interactions with websites and apps. The Regional Court of Munich II dismissed the action, holding that the declaratory and erasure or anonymization claims were inadmissible, the cessation claims were legally unavailable and the damages claim had not been sufficiently substantiated. In relation to the damages claim, it found that the data subject had not identified specific third-party websites or apps through which his personal data had been processed. The data subject accordingly appealed to the Higher Regional Court of Munich. Holding — The Higher Regional Court of Munich partially upheld the appeal. First, the court held that the Controller processed the data subject’s personal data under Articles 4(1) and 4(2) GDPR by receiving data transmitted through its Business Tools, associating it with a user account and storing it. The data subject was not required to identify every website, app or individual transmission because the relevant information was principally within the controller’s knowledge and it was sufficiently probable that he had been affected. Second, referring to CJEU C‑40/17 concerning the broad interpretation of “controller”, the court held that the controller was a joint controller under Articles 4(7) and 26 GDPR for the collection and transmission of the personal data. It controlled the programming of the Business Tools and participated in determining the purposes and means of processing. Allocating certain obligations to third-party website and app operators did not remove its responsibility. Third, referring to CJEU C‑252/21, the court held that the controller had not established a lawful basis for the processing of the personal data. The processing was not justified by consent under Article 6(1)(a), contractual necessity under Article 6(1)(b), a legal obligation under Article 6(1)(c), a public-interest task under Article 6(1)(e), or legitimate interests under Article 6(1)(f) GDPR. Accordingly, the court held that the controller's processing infringed Articles 5(1)(a), 5(1)(b), 5(1)(c) and 6 GDPR. Relying on CJEU C‑655/23, the court granted an injunction against future unlawful processing under German law. It also ordered restriction pending erasure under Article 18(1)(b) and erasure under Article 17(1)(d) GDPR. The court upheld the dismissal of the separate declaratory claim and also rejected anonymization of the website and app interaction data. Finally, relying on BGH VI ZR 10/24, the court awarded €1,500 in non-material damages under Article 82(1) GDPR for the data subject’s loss of control over his personal data.

### German Supreme Court: No GDPR basis for debt transmission to credit agency; €500 damages

*Source: German Supreme Court, 2026-05-12 — https://overview.legal/posts/53895 — original: https://gdprhub.eu/index.php?title=BGH_-_VI_ZR_375/2*

Facts — A debt collection agency (the controller) sent reminders to a customer (the data subject) for delayed installment payments related to a terminated electricity contract in November 2019. The data subject considered the claimed sums to be excessive and refused to pay. The controller transmitted the information on outstanding debts of €795 and €817 to a credit information agency, which in turn made negative entries in its database. This lowered the credit score assigned to the data subject by the credit information agency. The data subject sued the controller for disclosing outstanding receivables to the credit information agency. The court of first instance ordered the controller to revoke the negative entries contained in the credit ranking database and awarded the data subject €500 in damages. The controller appealed this decision. The appellate court held that there had been no legal basis for the transmission of personal data, as the data subject had not consented to the processing and the requirements for legitimate interests pursuant to Article 6(1)(f) GDPR were not met. However, the court considered that the data subject had not suffered any non-material damage within the meaning of Article 82 GDPR. The controller appealed the case further to the Federal Court of Justice. Holding — The Federal Court of Justice dismissed the controller’s appeal and referred the case back to the appellate court. First, the court held transmitting the personal data to the credit information agency had been unlawful due to the lack of a legal basis. It pointed out that the requirements for processing based on legitimate interests laid down in Article 6(1)(f) GDPR were not met. As such, legitimate public interests in preventing the granting of credit to those who are unable or unwilling to pay could justify the transfer of data to credit information agencies. However, no meaningful indications regarding the data subject’s ability or willingness to pay could be derived from the credit information entries at issue: the controller had failed to demonstrate the debts existed in the amount claimed. Therefore, it could not rely on legitimate interests as a legal basis. Second, the court held that the data subject was entitled to the revocation of the disputed credit information entries due to the unlawful disclosure of their personal data. According to the court, this claim could be based on 1) the application of Article 19 GDPR in conjunction with Article 17(1) (d) GDPR, 2) Article 19 GDPR in conjunction with Articles 5(1)(a), 5(2), and 24(1) GDPR, or 3) national law by analogy. Third, the court held that the data subject had suffered non-material damage within the meaning of Article 82 GDPR due to the harm caused to their economic reputation. The fact that the credit reports adversely affected the data subject’s credit score, which could then be taken into account by potential contractual partners, was enough to give rise to a claim for damages. The court pointed out that the transmission of personal data to one recipient and the risk of further transmissions to third parties already constituted loss of control; the data subject did not need to prove a feeling of helplessness, fear, or anxiety to be entitled to damages.

### BVwG - W254 2321912-1

*Source: Federal Administrative Court, 2026-04-14 — https://overview.legal/posts/125597 — original: https://gdprhub.eu/index.php?title=BVwG_-_W254_2321912-1*

Facts — The data subject, an Austrian citizen residing in Vienna, was enrolled in a distance-learning programme at a German university (the controller). When the data subject enrolled, the controller registered them under the official name shown on their identity document. The data subject experienced gender dysphoria and had chosen a gender-neutral name for themselves which was a different to their legal name. They requested the controller to rectify and replace their official name with their chosen name. They stated that the chosen name reflected better their gender identity. The controller refused the change because the data subject had not provided either an official document proving a legal name change or a dgti supplementary ID card. This is a German supplementary identity document issued by Deutsche Gesellschaft für Trans*- und Inter*geschlechtlichkeit e.V. (dgti e.V.), a German association supporting trans and intersex persons, which may certify, among other things, a chosen first name, pronouns, gender and a current photo. The controller claimed that such a document would allow it to record changes concerning pronouns and first name in its administrative system. On 6 May 2024 the data subject lodged a complaint with the Austrian DPA. They argued that the controller failed to comply with their rectification request under Article 16 GDPR. The data subject also relied on the CJEU’s judgement in Deldits case(C-247/23), which concerned the rectification of gender identity data under Article 16 GDPR. As the controller was established in Germany, the Austrian DPA considered that the Thuringian DPA was the lead supervisory authority for the cross-border processing. The Thuringian DPA held that the controller had not violated Article 16 GDPR. Because the complaint had been lodged with the Austrian DPA and the outcome was a dismissal of the complaint, Article 60(8) GDPR required the supervisory authority with which the complaint had been lodged to adopt the decision and notify the data subject. The data subject then appealed that decision before the Austrian Federal Administrative Court. They argued that the continued use of the official name resulted in misidentification and systematic misgendering. They also stated that the prerequisite to submit further documents proving the name change was excessive and disproportionate. Moreover, the data subject requested that the chosen name should at least be used in non-legally binding university systems, such as the learning platform, email address, campus card and attendance lists. The controller noted that it was legally obligated to identify students and process their data based on official identification documents. This applied, on the one hand, to the transcripts addressed in the administrative proceedings, but also to other academic achievements by students, such as individual coursework, seminar work, or work within interdisciplinary study teams. Holding — The court first confirmed that the cooperation procedure under Article 56 GDPR and Article 60 GDPR had been correctly applied. The Thuringian DPA acted as the lead supervisory authority because the controller was established in Germany. However, since the complaint was dismissed, the Austrian DPA, as the authority with which the complaint had been lodged, adopted the rejection decision pursuant to Article 60(8) GDPR. The court held that there was no violation of Article 16 GDPR. It emphasised that the accuracy of personal data must be assessed in relation to the purpose of the processing. The controller processed the official name in order to identify the student, administer the study programme, issue certificates and academic degrees that aim to be recognized outside the university and certify the student's completion of the program to third parties. The court held that in light of these processing purposes, the processed data of the data subject should be regarded as accurate within the meaning of Article 16 GDPR. Since the data subject had not officially changed their name and had not submitted any official document, the court found that the official name was not inaccurate for the controller’s stated processing purposes. It further stated that the requirement to provide proof of a name change or to present a supplementary identification document was proportionate. The court acknowledged that gender identity is protected as part of private life under Article 8 ECHR. However, it distinguished the case from Deldits. In Deldits, the issue concerned the rectification of gender data in a public register and CJEU held that a data subject requesting the correction of gender identity data may be required to provide relevant and sufficient evidence, taking into account the circumstances of the individual case, in order to establish the inaccuracy of such data. By contrast, this case concerned university administration and academic documents whose effects extend beyond the university and there was no official change of the data subject’s name. Therefore, the court maintained that the controller could continue to use the official name unless the data subject provided official proof of name change. The court further noted that the request to use the chosen name only in non-legally binding systems went beyond the original complaint.

### GC - T-318/24

*Source: Gereral Court, T-318/24, 2025-12-03 — https://overview.legal/posts/122878 — original: https://gdprhub.eu/index.php?title=GC_-_T-318/24*

Facts — An applicant (the data subject) participated in several EU staff selection procedures administered by the European Personnel Selection Office (EPSO), acting as controller, and created an EPSO account in the Talent system. After he successfully passed one selection procedure, EPSO also stored his data in its recruitment portal. EPSO managed recruitment through two IT systems, both of which generated access logs, although those logs contained limited technical information regarding the purpose of each access. Between 2022 and 2024, the data subject submitted several requests to EPSO under Article 17 of Regulation (EU) 2018/1725, seeking access to all personal data concerning him. He requested, in particular, full access logs, minutes of meetings, internal and external communications containing his personal data, information on data recipients, and the restoration of personal data deleted after the expiry of retention periods. EPSO stated that certain data did not exist, that it could not restore lawfully deleted data, and that it had already disclosed all available log data. After the data subject lodged a complaint, the European Data Protection Supervisor (EDPS) reconsidered the matter in light of the CJEU’s judgment in Pankki. The EDPS ordered EPSO to provide all available log data relating to consultations of the data subject’s profile. EPSO complied with that order by disclosing the available logs but withheld the identities of individual staff members who had accessed the data. EPSO later rejected further access requests submitted by the data subject. As a result, the data subject brought two actions before the General Court (Cases T-318/24 and T-362/24), seeking the annulment of EPSO’s decisions. The General Court joined the two cases and examined together all the pleas in law raised by the data subject. Holding — The General Court dismissed both actions in their entirety. It held that the controller did not infringe Article 17(1) or (3) of Regulation 2018/1725, as the right of access concerns personal data undergoing processing and not documents as such, nor does it require the controller to restore lawfully deleted data. The Court confirmed that Regulation 2018/1725 contains no obligation for a controller to reinstate personal data once deleted in compliance with applicable retention rules. The Court further held that the controller had no obligation to disclose additional log data, meeting minutes, or communications where it credibly asserted that no such personal data existed. The data subject failed to rebut the presumption of legality attaching to the controller’s statements regarding the non-existence of further data. Moreover , The Court held that access logs constitute personal data to which a data subject is entitled, as they reveal the existence, frequency and purpose of processing. However, employees of a controller acting under its authority are not “recipients” within the meaning of the GDPR or Regulation 2018/1725, and controllers are not required to log or disclose their identities. Disclosure of such identities is only required if strictly necessary for the effective exercise of data protection rights and subject to safeguarding employees’ rights. Since the data subject had already been informed of the purposes and recipients of processing, the absence of staff identities or detailed purposes in the logs did not infringe the right of access. It is not further apparent from the Pankki that Article 15 GDPR requires the controller to set up a logging mechanism containing information on the identity of employees who have carried out consultation operations in respect of the personal data of a person. In addition, the Court found no infringement of the principles of lawfulness, fairness, transparency, accuracy, integrity, confidentiality, or accountability under Article 4 of Regulation 2018/1725. The deletion of the data subject’s data after the expiry of retention periods was lawful and the data subject’s rights to restriction of processing and objection under Articles 20 and 23 were not applicable, as the deletion was based on a legal obligation rather than consent or legitimate interests.

### Judgment of the Court (Fifth Chamber) of 14 March 2024.#Budapest Főváros IV. Kerület Újpest Önkormányzat Polgármesteri Hivatala v Nemzeti Adatvédelmi és Információszabadság Hatóság.#Request for a preliminary ruling from the Fővárosi Törvényszék.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 58(2)(d) and (g) – Powers of the supervisory authority of a Member State – Paragraph 17(1) – Right to e

*Source: Court of Justice of the European Union, C-46/23, 2024-03-14 — https://overview.legal/posts/132267 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0046*

In a preliminary ruling requested by the Budapest High Court, the Court of Justice interpreted whether Article 58(2)(d) and (g) of the GDPR permits a national supervisory authority to order a controller to erase unlawfully processed personal data without a prior request from the data subject. The case arose from a dispute between the Budapest District IV (Újpest) municipal administration and the Hungarian National Data Protection and Freedom of Information Authority (NAIH), which had ordered the municipality to erase unlawfully processed data. The Court held that GDPR provisions do not require a prior data subject request for a supervisory authority to exercise its corrective power to order erasure of unlawfully processed personal data, as such a requirement would undermine the consistent and effective protection of fundamental rights under the GDPR.

### BVwG - W256 2227693-1

*Source: Federal Administrative Court, 2023-09-28 — https://overview.legal/posts/125664 — original: https://gdprhub.eu/index.php?title=BVwG_-_W256_2227693-1*

Facts — On 05.09.2019, the Austrian DPA (DSB) notified the controller of a customer loyalty program that they were initiating an ex officio investigation. The controller responded by answering the provided questionnaire and submitting further documents. On 23.10.2019, the DPA ruled that the investigation was justified and that the declaration of consent for profiling using certain registration methods (website, app, partner company store, flyer) did not comply with the requirements of Article 4(11) GDPR and Article 7 GDPR, nor were they provided in an intelligible way. If a contract covers several aspects, the declaration of consent must be clearly distinguishable. Regarding the website and flyer, the following was found: The website says 'Enjoy your personal benefits' without providing clear information that 'personal benefits' involves profiling. In an embedded box, the relevant points were merely referred to. Information regarding profiling was only accessible by scrolling down further. Concerning the flyer, the following information was provided under the signature field: 'This signature only applies to the declaration of consent and is voluntary. Your registration [...] is also valid without a signature.' Thus, it conveyed the impression that a signature was required to confirm the registration. Consequently, the controller was required to amend the declaration and to cease using any obtained consents for the purpose of profiling prior to 01.05.2020. The controller lodged a complaint. In addition to other information, the controller stated that the data processing was in accordance with Article 6(1)(a) GDPR, and that they had a legitimate interest under Article 6(1)(f) GDPR. The DPA ruled a preliminary decision on the complaint, thereby changing the ruling that the website and flyer did not meet the requirements under Article 6(1)(a) GDPR, and thus, the processing of personal data, collected in that cases, was forbidden. The other methods ensured that the consent was clearly separated from the rest of the registration process. The controller then filed a request for referral to the court, arguing that the DPA had exceeded their corrective powers by prohibiting the processing of the data. Furthermore, the data processing for profiling would be used to manage customer memberships under Article 6(1)(b) GDPR. Following their view, processing under Article 6(4) GDPR was applicable. Additionally, the controller denied the DPA's view that a violation of the principle of good faith would foreclose a weighing of interests under Article 6(1)(f) GDPR. The court quashed the preliminary decision as the DPA had not examined the other grounds of justification for data processing under Article 6(1) GDPR in their initial decision. The DPA then lodged an appeal to the Austrian Supreme Administrative Court (Verwaltungsgerichtshof), which overturned the court's ruling (VwGH 08.02.2022, Ro 2021/04/0033). It was the court's responsibility to examine the potential legal bases, rather than overturning the DPA's decision. Therefore, the case was returned to the court. In the meantime, the controller complied with the preliminary decision by deleting the affected personal data in 2021 and changing their registration process in 2020. Holding — First, the court found that they had to formally rule on whether the DPA's decision was lawful at the time it was ruled. It is not to be considered that the controller complied with the administrative decision and fulfilled the required steps (VwGH 28.04.2022, Ra 2022/06/0056). Second, the court held that the controller did not comply with the transparency requirements regarding the layout of their declaration of consent under Article 7(2) GDPR in both cases (website, flyer). Third, the court ruled that they could not agree with DPA's view, that an invalid declaration of consent always constitutes unlawful data processing and that a review of other grounds of justification would not be necessary (CLEU in 'Meta Platforms and Others' (C-252/21) ECLI:EU:C:2023:537). Further on, the Supreme Administrative Court ruled that both, the DPA and the court are required to examine the presence of other grounds (VwGH 08.02.2022, Ro 2021/04/0033). Fourth, the court held that the controller could not base their appeal on Article 6(4) GDPR as the data processing did not satisfy the grounds of justification, nor were other grounds apparent. Inter alia, following the CLEU's preliminary ruling in 'Meta Platforms and Others' (C-252/21) ECLI:EU:C:2023:537, three cumulative requirements must be met for data processing under Article 6(1)(f) GDPR: (1) The controller or a third party must have a legitimate interest, (2) which requires the processing of that personal data, (3) and 'the fundamental rights and freedoms of the data subject' must not outweigh those interests. There were no doubts about the controller's legitimate interest in processing the personal data in question for targeted marketing purposes, as this was both necessary and reasonable. However, the data subject should have been notified about profiling. The wording 'only if the member consents' did not constitute such a notification, and therefore the data subjects were not to be expected that their personal data was used for profiling purposes. Furthermore, the controller explicitly excluded it in their general terms and conditions. Hence, the data subject's right to secrecy overrode the controller's legitimate interest. In summary, the court dismissed the controller's complaint. Last, the court held that an appeal to the Supreme Administrative Court was admissible under Article 133(4) B-VG, as no prevailing case law concerning the implementation of a declaration of consent existed. Hence, the decision relied on a legal question of fundamental importance.

### Judgment of the Court (First Chamber) of 22 June 2023.#Proceedings brought by J.M.#Request for a preliminary ruling from the Itä-Suomen hallinto-oikeus.#Reference for a preliminary ruling – Processing of personal data – Regulation (EU) 2016/679 – Articles 4 and 15 – Scope of the right of access to information referred to in Article 15 – Information contained in log data – Article 4 – Definition of ‘personal data’ – Definition of ‘recipients’ – Temporal application.#Case C-579/21.

*Source: Court of Justice of the European Union, C-579/21, 2023-06-22 — https://overview.legal/posts/132284 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0579*

In Case C-579/21, the Court of Justice of the European Union ruled on a preliminary reference from the Itä-Suomen hallinto-oikeus (Administrative Court of Eastern Finland) concerning a dispute between J.M. and Pankki S, a Finnish bank, after the Apulaistietosuojavaltuutettu (Assistant Data Protection Supervisor) rejected J.M.'s request for access to certain log data. The core issue was the scope of the right of access under Article 15 of the GDPR, specifically whether log data containing information about who accessed personal data and when constitutes "personal data" and whether the controller must communicate the identities of recipients. The Court held that log data relating to consultations of a data subject's personal data constitutes personal data under Article 4(1) of the GDPR, and that a data subject is entitled to obtain the identities of recipients of their data, subject only to exceptions expressly provided by law or overriding rights of third parties. No fine was imposed as this was a preliminary ruling proceeding.

### Judgment of the Court (Fifth Chamber) of 4 May 2023.#UZ v Bundesrepublik Deutschland.#Request for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 5 – Principles relating to processing – Controllership – Article 6 – Lawfulness of processing – Electronic file compiled by an administrative authority relating to an asylum application – Tra

*Source: Court of Justice of the European Union, C-60/22, 2023-05-04 — https://overview.legal/posts/132289 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0060*

In Case C-60/22, the CJEU (Fifth Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden concerning UZ, a third-country national, and the Bundesrepublik Deutschland regarding the processing of personal data in an asylum application file. The Court held that an administrative authority transmitting an electronic asylum file to a competent national court via an electronic mailbox constitutes processing under the GDPR, and that where both the authority and the court determine the purposes and means of processing, they are joint controllers under Article 26, requiring an arrangement allocating responsibility and maintaining records of processing activities under Article 30. The Court further clarified that transmission of personal data without the data subject's consent constitutes unlawful processing, triggering the right to erasure under Article 17(1)(d) and the right to restriction under Article 18(1)(b), and that national courts must disregard such unlawfully processed data. No fine was imposed.

### Judgment of the Court (First Chamber) of 12 January 2023.#RW v Österreichische Post AG.#Request for a preliminary ruling from the Oberster Gerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 15(1)(c) – Data subject’s right of access to his or her data – Information about the recipients or categories of recipient to whom the personal data have been or will be disclosed – Restrictions.#C

*Source: Court of Justice of the European Union, C-154/21, 2023-01-12 — https://overview.legal/posts/132299 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0154*

The Court of Justice of the European Union (First Chamber), in response to a preliminary reference from the Oberster Gerichtshof (Austrian Supreme Court), interpreted Article 15(1)(c) GDPR in proceedings between data subject RW and Österreichische Post AG regarding the scope of the right of access to information about recipients or categories of recipients of personal data. The Court held that controllers must provide the actual identities of specific recipients to whom personal data have been or will be disclosed, rather than merely naming categories of recipients, unless a further specification is impossible. The Court clarified that while the right of access under Article 15(1)(c) is not absolute and may be balanced against the rights and freedoms of others, including trade secrets, such restrictions must not result in a refusal to provide all information to the data subject.

### VOLKER UND MARKUS SCHECKE GBR V. LAND HESSEN, EIFERT V. LAND HESSEN AND BUNDESANSTALT FUR LANDWIRTSCHAFT UND ERNAHRUNG, 9.Nov.2010 (“SCHECKE”)

*Source: CJEU, 2010-11-09 — https://overview.legal/posts/6180 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62009CJ0092&ref=6180*

Purpose for processing: The legislation at issue does base the processing on consent. Rather, it provides that they are to be informed. Thus, processing is not based on their consent. (¶ 54)

### CJEU Bavarian Lager: Disclosing personal data in access-to-documents requests is

*Source: CJEU, 2010-06-29 — https://overview.legal/posts/6182 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62008CJ0028&ref=6182*

Processing: Communication of personal data in response to a request for access to documents constitutes processing. (¶69)

## Guidance

### Opinion 14/2026 on the Europrivacy certification criteria regarding their approval by the Board as European Data Protection Seal pursuant to Article 42.5 GDPR

*Source: EDPB, opinion-142026-on-the-europrivacy-certification-criteria-en, 2026-04-16 — https://overview.legal/posts/125682 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-142026-on-the-europrivacy-certification-criteria_en*

Opinion 14 / 2026 on the Europrivacy certification criteria regarding their approval by the Board as European Data Protection Seal pursuant to Article 42.5 GDPR Adopted on 15 April 2026 1 | Adopted 2 | Adopted The European Data Protection Board Having regard to Article 63, Article 64 (2) and Article 42 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free…

### Opinion 07/2025 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data by the European Patent Organisation

*Source: EDPB, edpb-opinion-202507-epo-adequacydecision-en, 2025-05-06 — https://overview.legal/posts/50823 — original: https://www.edpb.europa.eu/documents/adequacy/opinion-072025-regarding-the-european-commission-draft-implementing-decision_en*

EDPB, Opinion 07/2025 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data by the European Patent Organisation, 2025.

### Opinion 15/2023 on the draft decision of the Dutch Supervisory Authority regarding the Brand Compliance certification criteria

*Source: EDPB, opinion-152023-on-the-draft-decision-of-the-dutch-supervisory-en, 2023-09-19 — https://overview.legal/posts/125831 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-152023-on-the-draft-decision-of-the-dutch-supervisory_en*

Adopted 1 Opinion 15/2023 on the draft decision of the Dutch Supervisory Authority regarding the Brand Compliance certification criteria Adopted on 19 09 2023 Adopted 2 Adopted 3 The European Data Protection Board Having regard to Article 63, Article 64(1)(c) and Article 42 of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and…

### Guidelines 01/2022 on data subject rights - Right of access

*Source: EDPB, edpb-guidelines-on-data-subject-rights---right-of-access, 2023-04-17 — https://overview.legal/posts/38055 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-012022-on-data-subject-rights-right-of-access_en*

The right of access of data subjects is enshrined in Art. 8 of the EU Charter of Fundamental Rights. It has been a part of the European data protection legal framework since its beginning and is now further developed by more specified and precise rules in Art. 15 GDPR.

### EDPB-EDPS Joint Opinion 2/2022 on the Proposal of the European Parliament and of the Council on harmonised rules on fair access to and use of data (Data Act)

*Source: EDPB, edpb-edps-joint-opinion-22022-on-the-proposal-of-the-european-en, 2022-05-04 — https://overview.legal/posts/125945 — original: https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-22022-on-the-proposal-of-the-european_en*

1 Adopted EDPB - EDP S Joint Opinion 2/2022 on the Proposal of the European Parliament and of the Council on harmonised rules on fair access to and use of data (Data Act) Adopted on 4 May 2022 2 Adopted Executive s ummary With this Joint Opinion, the EDPB and the EDPS aim to draw attention to a number of overarching concerns on the Proposal on Data Act and urge the co - legislature to take decisive action. The EDPB and EDPS note that the Proposal would apply to a broad range of products and…

### Toolbox on essential data protection safeguards for enforcement cooperation between EEA data protection authorities and competent data protection authorities of third countries

*Source: EDPB, toolbox-on-essential-data-protection-safeguards-for-enforcement-en, 2022-03-14 — https://overview.legal/posts/125962 — original: https://www.edpb.europa.eu/documents/other-guidance/toolbox-on-essential-data-protection-safeguards-for-enforcement_en*

Adopted Toolbox on essential data protection safeguards for enforcement cooperation between EEA data protection authorities and competent data protection authorities of third countries Adopted on 14 Mar c h 2022 2 Adopted The European Data Protection Board Having regard to Article 70 (1)(u) and Article 50(a) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the…

### Opinion 1/2022 on the draft decision of the Luxembourg Supervisory Authority regarding the GDPR – CARPA certification criteria

*Source: EDPB, opinion-12022-on-the-draft-decision-of-the-luxembourg-en, 2022-02-08 — https://overview.legal/posts/125965 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-12022-on-the-draft-decision-of-the-luxembourg_en*

Adopted 1 Opinion 1/2022 on the draft decision of the Luxembourg Supervisory Authority regarding the GDPR – CARPA certification criteria Adopted on 1 February 2022 Adopted 2 Adopted 3 The European Data Protection Board Having regard to Article 63, Article 64(1)(c) and Article 42 of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and…

### Opinion 39/2021 on whether Article 58(2)(g) GDPR could serve as a legal basis for a supervisory authority to order ex officio the erasure of personal data, in a situation where such request was not submitted by the data subject

*Source: EDPB, opinion-392021-on-whether-article-582g-gdpr-could-serve-as-a-en, 2021-12-14 — https://overview.legal/posts/125971 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-392021-on-whether-article-582g-gdpr-could-serve-as-a_en*

Adopted 1 Opinion 39 /2021 on whether Article 58(2) ( g) GDPR coul d serve as a legal basis for a s upervisory a uthority to order ex officio the erasure of personal data, in a situation where such request was not submitted by the data subject Adopted on 14 December 2021 Adopted 2 Adopted 3 The European Data Protection Board Having regard to Article 63 and Article 64 (2) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural…

## Enforcement decisions

### AEPD sanctions ACVIL Aparcamientos for denying access to parking surveillance footage

*Source: AEPD (Spain), 2026-07-21 — https://overview.legal/posts/144029 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS-00159-2025*

Facts — On 13 December 2024, the DPA received a complaint against ACVIL Aparcamientos, S.L.U., the controller, concerning a request for video surveillance footage from a car park. The data subject’s vehicle had allegedly been damaged while parked in a facility operated by the controller. On 23 February 2024, the data subject’s legal representative requested access to the footage recorded between 12 and 19 February 2024. The request sought the images showing the collision or, alternatively, the licence plate of the vehicle responsible. The data subject also expressly requested that the controller preserve the relevant footage because it was required for the establishment, exercise or defence of legal claims. The controller acknowledged receipt of the request but did not provide a substantive response until 4 April 2024, after the one-month period under the GDPR had expired. It stated that the footage could only be disclosed to the police or a judge and instructed the data subject to file a police report. After the data subject challenged that requirement and reiterated both the access and preservation requests, the controller responded that it would not provide the recordings and that the footage had already been deleted. During the proceedings, the controller argued that the request was excessive because it covered footage from 16 cameras over several days, amounting to approximately 3,072 hours of recordings. It also maintained that the footage contained personal data relating to numerous third parties and that it was not established that the damage had occurred inside the car park. The controller acknowledged, however, that it had not explained these considerations to the data subject, asked the data subject to narrow the request or notified an extension of the response period. Holding — The DPA held that the controller infringed Articles 15 and 18 GDPR. Regarding Article 15 GDPR, the DPA found that the controller failed to respond to the access request within the one-month period required under Article 12(3) GDPR. Although the controller considered the request complex and excessive, it neither informed the data subject of an extension within the initial one-month period nor explained why it considered the request excessive. The DPA noted that the controller could have asked the data subject to provide additional information to narrow the search. It could also have reviewed the recordings and provided only the footage necessary for the specific incident, applying measures such as blurring or limiting the disclosed extract to protect third parties. The DPA rejected the controller’s position that the footage could only be provided following a request from the police or a court. The exercise of the right of access was not conditional on the prior filing of a police report. The controller was required to assess the request under the GDPR and provide a reasoned and timely response. The failure to respond in time resulted in the deletion of the requested footage. Consequently, the data subject was prevented from obtaining information that could have been relevant to identifying the person responsible for the damage and pursuing a legal claim. Regarding Article 18 GDPR, the DPA held that the data subject had expressly requested the preservation of the recordings for the establishment, exercise or defence of legal claims. Under Article 18(1)(c) GDPR, processing must be restricted where the controller no longer needs the data for its original purposes but the data subject requires it for legal claims. The controller did not address this request and deleted the footage under its ordinary retention schedule. The DPA considered that Article 22(3) Spanish Data Protection Act (LOPDGDD), which generally requires video surveillance images to be erased within one month, did not justify disregarding a valid restriction request. Once the data subject requested preservation for potential legal proceedings, the controller was required to retain the relevant images rather than erase them. The DPA also linked the preservation of the evidence to the data subject’s right to effective judicial protection under Article 24(1) of the Spanish Constitution. Deleting the footage made it more difficult for the data subject to identify the responsible party and exercise their rights before a court. The DPA initially imposed two fines of €75,000: one for the infringement of Article 15 GDPR and one for the infringement of Article 18 GDPR, amounting to €150,000 in total. The controller acknowledged liability and voluntarily paid the fine. Under Article 85 of Spanish Administrative (Law 39/2015), it received a 20% reduction for acknowledging liability and a further 20% reduction for voluntary payment. Consequently, the initial fine of €150,000 was reduced by 40% to a final amount of €90,000. The DPA also ordered the controller to adopt the compliance measures specified in the decision initiating the proceedings and to report their implementation to the DPA within three months after the decision became final and enforceable.

### AEPD (Spain) - EXP202203606

*Source: AEPD (Spain), 2022-04-22 — https://overview.legal/posts/125657 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_EXP202203606*

Facts — Resolution No. R/00665/2022 is highlighted by a case concerning a claimant (namely A.A.A) and a respondent party (namely Securitas Direct España, S.A). The claimant filed against the respondent party for not having been duly attended to his right of access and deletion enshrined in Articles 15 to 22 GDPR, Articles 13 to 18 LOPDGDD and Article 17 GDPR respectively. The conflict of law arose in this case when a sufficiently legally established response was not generated by the respondent to the claimants request. Furthermore, the claim was transferred to the respondent so that the entity could proceed with its analysis and provide a response to the claimant within a period of one month. The Director of the Spanish Data Protection Agency agreed to admit the claim for processing and the parties concerned were informed of the maximum term for resolution, that being six months. The competence of the Spanish Data Protection Agency is refined by Article 55 GDPR in the promotion of an obligation between controllers and processors to deal with complaints issued by data subjects. The result of the said transfer did not allow the claimants issues to be understood as satisfied. Consequently, due to the lack of attention delegated to the claimants rights further set forth in Article 15 GDPR, Article 16 GDPR, Article 17 GDPR, Article 18 GDPR, Article 19 GDPR, Article 20 GDPR, Article 21 GDPR and Article 22 GDPR, an agreement to admit for processing was initiated. Holding — The Director of the Spanish Data Protection Agency went on to note that considering the purpose of the outlined procedure was to ensure that the rights of affected parties were fully restored, the complaint that gave rise to this procedure should be upheld on formal grounds due to the fact that the right of access had been complied with and the right of erasure had been duly denied (on the applicable grounds of Article 17 GDPR).

### Italian DPA: Enna Health Authority violated GDPR by publishing judicial data

*Source: Garante per la protezione dei dati personali (Italy), 2026-07-18 — https://overview.legal/posts/109000 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_471/2026*

Facts — The provincial Health Authority of Enna (the controller) published a resolution that contained the personal data of a data subject (specifically related to their judicial records). The data subject contacted the controller and requested the controller to remove or redact the data. The controller responded that it would remove it promptly, however, the data subjects’ data remained in a separate page of the controller’s website. The data subject later brought a complaint to the DPA. The controller stated that it completely removed the data subject’s personal data after the DPA requested it, including data that was accidentally included in its website. Holding — The DPA found a violation of Articles 5, 6 and 10 GDPR. The DPA first clarified that the controller processed data related to the commission of crimes or pending criminal proceedings involving the data subject. This data fell under the scope of Article 10 GDPR, meaning the controller had specific obligations for the processing activity to be lawful. The DPA considered that the controller had processed this data unlawfully by publishing it, and had failed to comply with the principle of lawfulness (Article 5(1)(a) GDPR) and data minimisation (Article 5(1)(c) GDPR). The DPA also found a violation of Article 17 GDPR. The DPA stated that the controller failed to adequately respond to the data subject’s request for erasure by not recognising that the data remained visible in a different section of its website. The DPA fined the controller €20,000.

### CNIL fines energy supplier for mishandling data subject access and objection requests

*Source: CNIL (France), 2026-07-17 — https://overview.legal/posts/125641 — original: https://gdprhub.eu/index.php?title=CNIL_(France)_-_SAN-2022-011*

Facts — The controller is a limited liability company whose business is the supply and production of electricity and gas in France. Several data subjects sent complainants to the French DPA (CNIL) that they had encountered difficulties in exercising their rights of access to personal information about them, and objection to receiving commercial prospecting telephone calls from the controller. The complaints concerned data subject requests for rectification of personal data, late, erroneous, or no response to access to personal data and access to the origin of personal data, failure to cease processing of personal data after objection to the processing of data for commercial prospecting (marketing) purposes, and request for personal data deletion. The DPA appointed a rapporteur that carried out an audit of the website of the controller and investigated the various complaints of the data subjects. The controller in its defence argued that 1) the data subjects' access requests were not sent by the data subjects to the controller’s dedicated unit and that the person who received the requests did not know how to identify their purpose; 2) the procedures it had put in place were not respected because of human error; 3) there were a large number of requests received in 2020 during the health crisis and this was impeded by the disruptions that followed; 4) there were difficulties in obtaining the necessary information from its business partners, thus unable to properly inform data subjects about the source of their data; 3) It had taken steps to modify its processing activities to comply with the relevant applicable laws; 4) The breach affected barely a fraction of its customers. Beyond the direct complaints made by the data subjects, the DPA in its investigation noted that when subscribing online on the controller's website, the subscription form had no option for users to object to the use of their personal data for marketing purposes. The subscription form informed users that their personal data may be used by the controller to present offers to them at a later date. On this point, the controller argued that 5) the CPCE did not apply to the online subscription form, since the collection of personal data through the form was not intended to promote the company's products or services, but to offer assistance to the user in order to help them finalize the current subscription. Holding — The DPA held that the lack of an option for a user to object to the processing of their personal data for marketing purposes, at the time of collection, constitutes a breach of the provisions of article L. 34-5 of the French Post and Electronic Telecommunications Code (CPCE). The DPA observed that, in certain cases, the data subjects contacted for marketing purposes were not provided with any information required in Article 14 GDPR, such as the purposes of the processing or the existence of the various rights. They were not informed that the call was being recorded, nor of their right to object to it. The DPA observed that the controller had failed to respond, supplied erroneous responses, or responded late to several data subject requests, beyond the deadlines set by Article 12 GDPR, often after several reminders from the data subject. The DPA observed that the controller failed to process the various data subject’s requests for access to personal data, their origin, as well as access to recordings of telephone conversations concerning the data subjects within the time limit set with the obligations of Article 15 GDPR. The DPA finally observed that the controller continued to process the personal data of data subjects after objections from the data subjects to the processing of their personal data in breach of Article 21 GDPR. The DPA held that the controller cannot rely on its difficulties in obtaining information from its commercial partners to justify its failure to provide a response to the applicants in accordance with the applicable provisions. It is the duty of the controller to organize itself in such a way as to be able to ensure that requests for access are processed in accordance with the applicable provisions and, in particular, to provide information on the origin of the data. The DPA further held that although data subjects did not send their access requests directly to the unit in charge of responding to them, it is up to the controller, as long as the requests, one of which was directly addressed to the data protection officer, were received in clear terms by the controller, to process them within the time limits provided for and to ensure that they were transmitted to the competent department responsible for handling such requests. For these violations, the DPA fined the controller €1,000,000. The controller argued against the publication of the penalty decision, on the ground that publication would be disproportionate in light of the limited nature of the alleged breaches and its compliance. It also claimed that publication of the penalty would have a significant impact on the controller’s image and that it would be favorable to its main competitors, in a very competitive market. The DPA also decided to make its decision public on the CNIL website and on the Légifrance website and held that the controller will no longer be identified by name after a period of two years from its publication. The DPA noted that the company has taken measures to bring its processing into compliance with the applicable laws, and the efforts made by the company to comply throughout the procedure. The DPA also noted that the controller’s agents have had to attend awareness training on the subjects of the complaints.

### HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens

*Source: HDPA (Greece), 2026-05-13 — https://overview.legal/posts/144044 — original: https://gdprhub.eu/index.php?title=HDPA_(Greece)_-_12/2026*

Facts — The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of Undesirable Aliens. In response to the Authority's request for clarifications, the competent Directorate of the Ministry of Citizen Protection informed the DPA that: • By a decision dated 27-07-2017, an entry ban and registration in the National Registry of Undesirable Aliens were imposed on the complainant for reasons of national security. • Following temporary 48-hour lifts of the measure for humanitarian reasons in 2019, the entry ban was re-imposed. • Subsequent decisions in 2020, 2023, and 2025 maintained the entry ban and renewed his registration in the National Registry of Undesirable Aliens for successive three-year periods, as the grounds for registration remained active. • The explicit grounds and documentation behind the registration were not disclosed to the complainant because the competent Directorate classified the file as restricted/classified service material. The complainant and his attorney attended a DPA hearing on 22-04-2026, arguing that the registration lacked specific, adequate, or definitive justification regarding any threat to public order or national security. They noted that the complainant has no criminal convictions, poses no threat, and possesses strong ties, residency, and business operations in the region of Northern Epirus and Greece, meaning the entry ban severely disrupts his professional and family life. Holding — According to the provisions of Article 82(1) of Law 3386/2005, foreign nationals whose presence in Greek territory constitutes a threat to national security, public safety, or public order can be registered in the National Registry of Undesirable Aliens, with registrations subject to an ex officio review every three years. Furthermore, pursuant to the provisions of Article 54(2) and Article 55(4) of Law 4624/2019 (the Greek law implementing the GDPR), the data controller is legally empowered to restrict or omit the provision of information and to deny a data subject access to their personal data when dictated by reasons of national security or public order. These national provisions are explicitly anchored in Article 23 GDPR (specifically Article 23(1)(a)GDPR and Article 23(1)(c) GDPR), which permits Member State law to restrict the scope of the obligations and data subject rights (such as the right to be informed under Article 13 GDPR - Article 14 GDPR and the right of access under Article 15 GDPR) to safeguard national security and public security. In the present case, the evidence demonstrated that the complainant's initial registration and subsequent renewals in the National Registry of Undesirable Aliens were executed lawfully for reasons of national security. The Ministry of Citizen Protection, acting as the data controller, exercised its legal discretion under these frameworks to weigh these interests and correctly determined that the underlying operational decision constitutes classified material that cannot be disclosed to the data subject. Consequently, the fundamental principles of data protection law were not breached, and the Hellenic DPA rejected the complaint as unfounded.

### DSB Austria: Online shop violated GDPR by ignoring request to stop gender-specific

*Source: DSB (Austria), 2025-11-24 — https://overview.legal/posts/158460 — original: https://gdprhub.eu/index.php?title=DSB_(Austria)_-_2025-0.950.759*

Facts — On 18 September 2023, a data subject created a customer account with a public limited company operating an online shop (the controller). It allowed customers to place orders either as guests or through an optional customer account. During the registration process, the data subject's personal data was collected, including a gender-specific title. The only options provided for the title were "Mr." and "Ms.", with no option to select no title. The data subject selected “Ms.” during the registration process. The data subject then informed the controller about this situation and requested that it should refrain from using gender-specific forms of address regarding them. The controller initially assured the data subject that it would inform the relevant department. Later, the controller communicated that implementing the requested adjustment was currently not technically feasible, but that a solution was being worked on. On 14 May 2025, the data subject received a newsletter from the controller in which a gender specific salutation (specifically "Ms.") was used. On 16 May 2025, the data subject lodged a complaint with the Austrian DPA against the controller. The data subject argued that the controller had infringed their rights regarding the principles of data processing under Article 5 GDPR, the rights to rectification under Article 16 GDPR, to erasure under Article 17 GDPR and to data protection by design and by default under Article 25 GDPR. Τhe controller stated in its privacy notice that it was necessary to process customers’ personal data for registration purposes under Article 6(1)(b) GDPR. Moreover, the controller also claimed reliance on Article 6(1)(f) GDPR. During the proceedings before the DPA, the controller restructured its IT system. On 8 September 2025, the controller announced that it had implemented gender-neutral forms of address in its online shop and requested for the complaint to be dismissed. Holding — The DPA first noted that, during the proceedings, the controller had implemented the requested changes by removing gender-specific forms of address from the registration process. Since the data subject did not contest this, the DPA considered the alleged infringements of the rights to rectification and erasure to have been remedied and ended that part of the proceedings. However, it continued to examine whether the past processing had violated Article 5 GDPR and Article 25 GDPR. Regarding the processing of salutation data for the personalisation of business communications, the DPA relied on the CJEU judgment in Case C-394/23 (Mousse). In this case, the CJEU had ruled that the processing of salutation data for the personalization of business communications is neither necessary for the performance of a contract pursuant to Article 6(1)(b) GDPR nor consistent with the principle of data minimization pursuant to Article 5(1)(c) GDPR, because such processing is not required for the stated purposes. The DPA concluded that using gender-specific salutations for contract fulfilment, order processing, internal correspondence, contests, newsletters, user account registration, and delivery of goods was not strictly necessary, even under a broad interpretation. It backed this conclusion by the fact that the controller had already stopped using gender-specific salutations in direct communications, newsletters, contests, contact forms, delivery notifications, invoices, and order confirmations. The DPA therefore held that neither Article 6(1)(b) GDPR nor Article 6(1)(f) GDPR could serve as a legal basis for processing gender-specific salutations during the registration process, since the processing was not necessary. In relation to Article 6(1)(f) GDPR , the DPA accepted that the controller could in principle have a legitimate economic interest in personally addressing customers, but found that the necessity requirement was not met. The DPA found that the processing operation violated the principles of purpose limitation and data minimisation under Article 5(1)(b) GDPR and Article 5(1)(c) GDPR due to the lack of necessity of the gender-specific salutation and the availability of less intrusive alternatives. The DPA also referred to the Austrian Constitutional Court’s (Verfassungsgerichtshof) decision GZ G 77/2018, according to which a restriction to only two gender categories is incompatible with Article 8 ECHR. Regarding data protection by design and by default, the DPA held that Article 25 GDPR imposes obligations on the controller, but does not grant the data subject a subjective right to demand a specific privacy-friendly technical setting. It pointed out that while privacy-unfriendly default settings might lead to a violation of confidentiality or of the data protection principles, the data subject could not require the controller to implement specific privacy-friendly settings.

### NAIH (Hungary) - NAIH-4667-10/2022

*Source: NAIH (Hungary), 2022-09-22 — https://overview.legal/posts/122837 — original: https://gdprhub.eu/index.php?title=NAIH_(Hungary)_-_NAIH-4667-10/2022*

Facts — A minor student (the data subject) alleged that his grade had been amended before the semester grading meeting without notification. The parent of the data subject requested access to his personal data contained in the eKRÉTA (Public Education Registration and Study Fund) system. This system was used by the school (the controller) to record and capture the grade history of pupils, including the data subject. The controller failed to provide the requested personal data. However, it did ask KRÉTA (the processor) whether additional information regarding manipulation of grades can be exracted from the system and informed the parent that no such possibility existed. Consequently, the parent of the data subject filed a complaint with the Hungarian DPA. The parent submitted that the overwriting and deletion of the data subject's grades could not be tracked on the eKRÉTA administrative interface accessible to parents. The parent proved their right of representation before the DPA with the child's birth certificate. The DPA initiated an investigation into the matter. Holding — The DPA reitarrated, based on the definitions of the GDPR, that a subject grade is data related to the data subject's academic evaluation and should be considered personal data. Hence, any operation performed on the data is considered data processing. In the present case, the personal data was allegedly modified or overwritten at a time other than when the semester grade notice was issued to pupils. With regard to the personal data of a minor, the parent is not considered to be the data subject pursuant to Article 4(1) GDPR. At the same time, the parent can submit a data subject request to the controller on behalf of the minor data subject. The parent wanted to exercise this right in order to have access to the information related to the management of the grade, regarding the overwriting and deletion of the grade, based on Article 15(1) GDPR. The purpose was to establish the legality of the data management on behalf of the controller. The DPA confirmed that the processor (the KRÉTA system) provided information on of the date on which the grades were entered, following a request from the controller. However, the processor could not track whether a certain grade entry was overwritten or deleted form the system. This request was in compliance with Article 28(3) GDPR since the data controller validated the data subject's request by asking for the information in question from the data processor. The DPA found that the allegation that the personal data in question had been manipulated was not substantiated and that the controller had not committed any infringement in the course of complying with the data subject's request to access the data in question. The DPA noted that the accessed data was not provided to the data subject, not in an attempt to conceal any manipulated merits, but rather due to the fact that the requested data was not in the controller's possession yet. The DPA concluded that the general data processing of the controller did not directly affect the rights or legitimate interest of the data subject. In view of this, the DPA rejected the complaint.

### Austrian DSB rules 360-degree feedback unlawful without specific works agreement

*Source: DSB (Austria), 2026-03-20 — https://overview.legal/posts/187479 — original: https://gdprhub.eu/index.php?title=DSB_(Austria)_-_2025-0.960.016*

Facts — The data subject was employed by an Austrian stock corporation (the controller) from August 2018 to June 2025. They worked as a manager in the controller’s finance department, with technical and disciplinary responsibility for up to five employees. The controller operated a 360-degree feedback process under which the data subject completed a self-assessment and 17 other individuals, including their supervisor, three subordinates and other employees, evaluated their leadership behaviour across 27 categories. Both the data subject and their supervisor had access to the results. The process was also used for other managers within the company. On 1 August 2025, the data subject lodged a complaint with the Austrian DPA, alleging a violation of their right to confidentiality. They argued that the processing carried out as part of the 360-degree feedback process required a specific works agreement and was therefore unlawful in the absence of one. The controller had concluded a framework works agreement with the central works council on the processing of employee data, as well as a supplementary agreement concerning its HR system. However, there was no specific works agreement covering the 360-degree feedback process. The controller alleged that it relied on its legitimate interests under Article 6(1)(f) GDPR and on the performance of the employment contract under Article 6(1)(b) GDPR. It argued that a works agreement would merely specify its legitimate interests and that the absence of such an agreement did not render the processing unlawful. It further maintained that whether a works agreement was required was a labour-law issue that could not be determined in the proceedings before the DPA The data subject responded that the processing of personal data in a 360-degree feedback process served to evaluate employees and therefore constituted a measure within the meaning of § 96 of the Austrian Labour Constitution Act (ArbVG). Section 96 ArbVG lists certain workplace measures that can be introduced only with the works council’s consent through a works agreement. Holding — The DPA first found that the data subject was an employee covered by the Austrian Labour Constitution Act, rather than a senior executive excluded from its scope. It further held that the assessments of the data subject’s leadership behaviour constituted personal data. The DPA explained that Article 88 GDPR enables Member States to adopt, through legislation or collective agreements, more specific rules protecting the rights and freedoms of individuals in the context of employment-related processing. Such rules must include appropriate safeguards for, among other things, human dignity, legitimate interests and the fundamental rights of data subjects. Recital 155 GDPR expressly refers to works agreements as a possible instrument for implementing such rules. It further stated that Austria had made use of the opening clause in Article 88 GDPR and that § 96 ArbVG constituted one of the more specific national rules protecting employees in the context of personal data processing. It determined that the 360-degree feedback process constituted a systematic and standardised assessment of employees falling under both § 96(1)(2) ArbVG, concerning personnel questionnaires, and § 96(1)(3) ArbVG, concerning monitoring measures affecting human dignity. It held that under § 96 ArbVG, the processing therefore required the works council’s consent through a valid works agreement. It pointed out that the controller’s existing works agreements did not cover the 360-degree feedback process or the categories of personal data collected through it. It therefore held that the processing could not be based on a works agreement under Article 88(1) GDPR in conjunction with § 96 ArbVG. The DPA held that the controller could not rely on Article 6(1)(f) GDPR. It stated that although personnel management and improving employee performance might generally constitute legitimate interests, an interest pursued through processing contrary to national law could not be regarded as lawful. It concluded that since the mandatory works council consent had not been obtained, the interest could not be regarded as legitimate under Article 6(1)(f) GDPR. Moreover, it pointed out that Article 6(1)(b) GDPR was also inapplicable because the feedback process was not necessary for the performance of the employment contract. It reasoned that the employment relationship could be performed without it, and the process was not applied to all employees. The DPA therefore found that the processing was unlawful and violated the data subject’s right to confidentiality. It prohibited the controller from continuing the 360-degree feedback process for employees covered by the ArbVG until a valid works agreement was concluded.

## Recent developments

### Dirkzwager: ABRvS geeft uitleg aan het AVG-begrip "de instelling, uitoefening of onderbouwing van een rechtsvordering"

*Source: Dirkzwager, 2022-10-05 — https://overview.legal/posts/6332 — original: https://www.dirkzwager.nl/kennis/artikelen/abrvs-geeft-uitleg-aan-het-avg-begrip-de-instelling-uitoefening-of-onderbouwing-van-een-rechtsvordering/#entry-968*

> Privacybescherming is niet absoluut. Dat staat zelfs letterlijk zo in de privacywetgeving. De AVG bevat daarom ook allerlei uitzonderingen. Een van de uitzonderingen die enkele keren terugkomt in de AVG ziet op de verwerking van persoonsgegevens in het kader van "de instelling, uitoefening of onderbouwing van een rechtsvordering". Tot op heden was echter niet heel erg duidelijk wat die woorden nu precies betekenen. Een recente uitspraak van de Afdeling bestuursrechtspraak van de Raad van State

### De Autoriteit Persoonsgegevens publiceert een rapport over de risicoanalyse van de AVG (Algemene Verordening Gegevensbescherming).

*Source: AEPD, 2022-10-11 — https://overview.legal/posts/51791*

De GDPR-risicoanalyse is bedoeld om controllers en verwerkers te helpen bij het identificeren van de risicofactoren voor de rechten en vrijheden van de betrokkenen, wiens gegevens worden verwerkt. Het doel is om een eerste inschatting te maken van het inherente risico, inclusief de noodzaak om een Privacy Impact Assessment (DIA) uit te voeren, en om het resterende risico te schatten als maatregelen en beveiligingsmechanismen worden gebruikt om specifieke risicofactoren te verminderen.

## Literature

### The Court of Justice on the Excessiveness of Access Requests under the GDPR

*Source: European Journal of Risk Regulation, 2026-07-09 — https://overview.legal/posts/83502 — original: https://doi.org/10.1017/err.2026.10117*

Abstract This case note comments on the preliminary ruling of the Court of Justice of the EU in Case C-526/24 Brillen Rottler v TC of 19 March 2026, which addresses the abuse of rights under the General Data Protection Regulation (GDPR), specifically in the context of requests for access to personal data under Article 15 GDPR and compensation under Article 82 GDPR. First, the Court held that even a first access request may be regarded as “excessive” where the controller demonstrates that it was

### HOW GDPR TREATS AUTOMATED DECISION-MAKING

*Source: Journal Scientific and Applied Research, 2025-11-14 — https://overview.legal/posts/132599 — original: https://doi.org/10.46687/jsar.v28i1.435*

This article examines how the General Data Protection Regulation (GDPR) regulates automated decision-making, including profiling, in the context of personal data processing. It analyzes the main provisions of Article 22 of the Regulation, as well as the conditions under which fully automated decisions that produce legal effects or significantly affect data subjects are permitted. The article highlights the rights of data subjects – the right to human intervention, the right to express their poin

### The data subject’s right to access to information under GDPR and the right of the data controller to protect its know-how

*Source: Przegląd Prawniczy Uniwersytetu im. Adam Mickiewicza, 2023-12-30 — https://overview.legal/posts/132546 — original: https://doi.org/10.14746/ppuam.2023.15.09*

The data subject’s right to access information on data processing has a very broad meaning. Considering the latest developments in this field (mainly the CJEU ruling on Austrian posts and EDPB guidelines) one can draw the conclusion that the controller’s right to protect its confidential in-formation is limited and less valuable than the data subject’s rights. However, this may lead to unfair and unequal treatment of companies and data subjects. When looking at this right in a more systematic pe

### Recommendations for Creating Codes of Conduct for Processing Personal Data in Biobanking Based on the GDPR art.40

*Source: Frontiers in Genetics, 2021-11-12 — https://overview.legal/posts/132560 — original: https://doi.org/10.3389/fgene.2021.711614*

Personal data protection has become a fundamental normative challenge for biobankers and scientists researching human biological samples and associated data. The General Data Protection Regulation (GDPR) harmonises the law on protecting personal data throughout Europe and allows developing codes of conduct for processing personal data based on GDPR art. 40. Codes of conduct are a soft law measure to create protective standards for data processing adapted to the specific area, among others, to bi

### GDPR: A new challenge for personal data protection

*Source: Bankarstvo, 2017-01-01 — https://overview.legal/posts/132473 — original: https://doi.org/10.5937/bankarstvo1704166m*

stručni članak Erne Mraznica Raiffeisen banka ad Beograd erne.mraznica@raiffeisenbank.rs GDPR - NOVI IZAZOV ZAŠTITE PODATAKA O LIČNOSTI Rezime Dana 4. maja 2016. godine objavljena je Opšta Uredba o zaštiti podataka o ličnosti u Sl. glasniku EU, koja će se primenjivati od 25. maja 2018. godine. Cilj propisa je harmonizacija zaštite podataka o ličnosti na nivou EU, veći stepen kontrole za lica čiji se podaci obrađuju i unapređeno upravljanje savremenim rizicima iz ove oblasti. Banke, po prirodi svog poslovanja, spadaju među najveće rukovaoce podataka o ličnosti i u postupku usklađivanja sa obavezama utvrđenih Uredbom biće u prilici da izvrše punu analizu svog postojećeg regulatornog i infrastrukturnog okvira zaštite podataka o ličnosti. Istovremeno, pruža im se prilika da isprave eventualne nedostatke u postojećim procesima, odnosno da značajno povećaju svest organizacije o standardima zaštite podataka o ličnosti, posebno imajući u vidu zaprećene stroge sankcije za slučaj neusklađenosti. Ključne reči : GDPR, podatak o ličnosti, osnovni principi, prava lica, rukovalac, obrada podataka, transfer podataka, sankcije, usklađivanje JEL : F52, G14 doi: 10.5937/bankarstvo1704166M 166 Bankars

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities
- **Right to be Forgotten** — https://overview.legal/topics/recht-op-vergetelheid
  Right to have personal data erased under certain conditions
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers

---
Generated by overview.legal · https://overview.legal/topics/right-to-restriction · 2026-08-22
