# Scientific Panel Independence — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/scientific-panel-independence-impartiality
> Sources are cited per item. Verify against the official texts before relying on them.

A specific topic is needed to address the independence and impartiality requirements that are critical for scientific panels to maintain credibility and objectivity in their advisory role.

## Overview

## Legal Framework

The independence and impartiality of scientific advisory panels is anchored in several interlocking provisions. Under the DSA, Recital 92 establishes that verification by independent experts is a structural requirement for accountability of very large online platforms and very large search engines, mandating independent auditing of compliance obligations. Recital 59 extends the independence requirement to out-of-court dispute settlement bodies, specifying that independence must be ensured not only at the institutional level but also at the level of the natural persons entrusted with resolving disputes, including through explicit rules on conflicts of interest. These provisions reflect a layered design: institutional autonomy from the entities being assessed, coupled with individual-level safeguards against financial, professional, or relational conflicts that could compromise objective judgment.

The conflict-of-interest dimension is further informed by procurement principles articulated in Dutch case law, particularly Article 2.87(1)(e) jo. 1.10b of the Aanbestedingswet 2012, which mandates exclusion of contractors where a conflict of interest cannot be resolved. The underlying rationale is that advisory credibility depends on both structural separation and demonstrable absence of conflicting interests at the decision-making level.

## Key Developments

The Gerechtshof Den Haag's June 2026 ruling in the RET/RMC matter (cases 200.361.266/01, 200.361.440/01, and 200.361.896/01) provides a concrete threshold for assessing conflict-of-interest claims. The court applied the Xafax framework, which establishes that contracts between contracting authorities and contractors can be challenged on appeal only where nullity arises under Article 3:40 BW — specifically, conflict with public order — and not merely on procurement-law grounds. The court examined whether an alleged prohibited state aid transaction (a share transfer at below-market price) created a conflict of interest warranting exclusion under Article 2.87(1)(e) Aw 2012, ultimately finding the evidence insufficient to establish that the transaction influenced the procurement procedure's pricing or outcome.

The court's reasoning establishes a materiality standard: a conflict of interest must be shown to have actually influenced, or created a real risk of influencing, the decision at issue. Speculative or unsubstantiated conflict claims do not meet this threshold. The burden rests on the party asserting the conflict to demonstrate a concrete nexus between the conflicting interest and the compromised process.

The EDPB's guidance on accreditation of certification bodies reinforces this standard at the EU level, requiring that certifying entities demonstrate structural and operational independence from the bodies they assess.

## Practical Guidance

- Establish written conflict-of-interest declarations for every panel member, covering direct and indirect financial interests, professional relationships, and prior engagements with the entity under review, consistent with the individual-level independence requirement articulated in DSA Recital 59.

- Implement a documented screening procedure at the appointment stage that assesses whether any identified conflict creates a material risk of influence on the panel's advisory output, applying the materiality threshold from the Gerechtshof Den Haag RET/RMC ruling.

- Maintain structural separation between the scientific panel and the entity being audited or assessed, ensuring that funding, staffing, and operational reporting lines do not create dependencies that would undermine the institutional independence required under DSA Recital 92.

- Where a conflict is identified that cannot be mitigated through recusal or Chinese-wall procedures, exclude the affected member or entity entirely, consistent with the exclusion standard under Article 2.87(1)(e) jo. 1.10b Aw 2012 and the nullity principles of Article 3:40 BW.

- Document the independence assessment process contemporaneously, including the rationale for any decision to retain a member despite an identified potential conflict, to create an evidentiary record that demonstrates compliance with the materiality standard if challenged.

## Legislation (full text of key provisions)

### Recital 92 — independent compliance audits for very large online platforms

*Source: DSA, dsa-rec-92-en, 2022-10-19 — https://overview.legal/posts/95581*

Given the need to ensure verification by independent experts, providers of very large online platforms and of very large online search engines should be accountable, through independent auditing, for their compliance with the obligations laid down by this Regulation and, where relevant, any complementary commitments undertaken pursuant to codes of conduct and crises protocols. In order to ensure that audits are carried out in an effective, efficient and timely manner, providers of very large online platforms and of very large online search engines should provide the necessary cooperation and assistance to the organisations carrying out the audits, including by giving the auditor access to all relevant data and premises necessary to perform the audit properly, including, where appropriate, to data related to algorithmic systems, and by answering oral or written questions. Auditors should also be able to make use of other sources of objective information, including studies by vetted researchers. Providers of very large online platforms and of very large online search engines should not undermine the performance of the audit. Audits should be performed according to best industry practices and high professional ethics and objectivity, with due regard, as appropriate, to auditing standards and codes of practice. Auditors should guarantee the confidentiality, security and integrity of the information, such as trade secrets, that they obtain when performing their tasks. This guarantee should not be a means to circumvent the applicability of audit obligations in this Regulation. Auditors should have the necessary expertise in the area of risk management and technical competence to audit algorithms. They should be independent, in order to be able to perform their tasks in an adequate and trustworthy manner. They should comply with core independence requirements for prohibited non-auditing services, firm rotation and non-contingent fees. If their independence and technical competence is not beyond doubt, they should resign or abstain from the audit engagement.

### Recital 59 — certified out-of-court dispute settlement

*Source: DSA, dsa-rec-59-en, 2022-10-19 — https://overview.legal/posts/95515*

In addition, provision should be made for the possibility of engaging, in good faith, in the out-of-court dispute settlement of such disputes, including those that could not be resolved in a satisfactory manner through the internal complaint-handling systems, by certified bodies that have the requisite independence, means and expertise to carry out their activities in a fair, swift and cost-effective manner. The independence of the out-of-court dispute settlement bodies should be ensured also at the level of the natural persons in charge of resolving disputes, including through rules on conflict of interest. The fees charged by the out-of-court dispute settlement bodies should be reasonable, accessible, attractive, inexpensive for consumers and proportionate, and assessed on a case-by-case basis. Where an out-of-court dispute settlement body is certified by the competent Digital Services Coordinator, that certification should be valid in all Member States. Providers of online platforms should be able to refuse to engage in out-of-court dispute settlement procedures under this Regulation when the same dispute, in particular as regards the information concerned and the grounds for taking the contested decision, the effects of the decision and the grounds raised for contesting the decision, has already been resolved by or is already subject to an ongoing procedure before the competent court or before another competent out-of-court dispute settlement body. Recipients of the service should be able to choose between the internal complaint mechanism, an out-of-court dispute settlement and the possibility to initiate, at any stage, judicial proceedings. Since the outcome of the out-of-court dispute settlement procedure is not binding, the parties should not be prevented from initiating judicial proceedings in relation to the same dispute. The possibilities to contest decisions of providers of online platforms thus created should leave unaffected in all respects the possibility to seek judicial redress in accordance with the laws of the Member State concerned, and therefore should not affect the exercise of the right to an effective judicial remedy under Article 47 of the Charter. The provisions in this Regulation on out-of-court dispute settlement should not require Member States to establish such out-of-court settlement bodies.

## Case law

### Judgment of the Court (Fifth Chamber) of 9 July 2020.#European Commission v Ireland.#Failure of a Member State to fulfil obligations — Principles governing the investigation of accidents in the maritime transport sector — Directive 2009/18/EC — Article 8(1) — Parties whose interests could conflict with the task entrusted to the investigative body — Members of the investigative body simultaneously performing other functions — Failure to provide for an independent investigative body.#Case C-257/19

*Source: Court of Justice of the European Union, C-257/19, 2020-07-09 — https://overview.legal/posts/132332 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62019CJ0257*

The European Commission brought infringement proceedings against Ireland under Article 258 TFEU, alleging that Ireland failed to establish a maritime accident investigative body independent in its organization, legal structure, and decision-making from any party whose interests could conflict with its investigative task, as required by Article 8(1) of Directive 2009/18/EC. The Court of Justice (Fifth Chamber) found that Ireland had breached its obligations under the Directive by permitting members of its investigative body to simultaneously perform functions that could create conflicts of interest, thereby compromising the body's independence.

### CJEU - C-288/12 - European Commission v Hungary

*Source: GDPRhub, 2014-04-08 — https://overview.legal/posts/158449 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-288/12_-_European_Commission_v_Hungary*

Facts — On 29 September 2008, Mr Jori was appointed Data Protection Supervisor for a 6 year term, which would terminate around the end of September 2014. However, Mr Jori was asked to vacate the office on 31 December 2011. Upon proposal by the Hungarian Prime Minister, Mr Peterfalvi was appointed as Head Authority for a term of nine years. Advocate General Opinion — The AG considers that the European Commission does not dispute in any way the right of Hungary to modify its institutional set up for its data protection authority. The issue disputed is that, in changing the institutional set up, Hungary failed to fulfil its obligation to respect the independence of their supervisor by terminating its employment before the beginning of their term. Article 28(1) Dir.95/46 puts forward the need for supervision of the personal data protection by an independent authority as an essential component of the protection of individual in personal data processing. As found by the CJEU in C-518/07, the term “with complete independence” is interpreted broadly and autonomously in light of the objective to ensure the effectiveness and reliability of the supervision of data protection compliance. Moreover, the guarantee of independence is established not to grant a special status to those authorities themselves as well as their agents but rather to strengthen the protection of individuals and bodies affected by their decisions. Still from CJEU in C-518/07, the CJEU held that actions that may lead to “prior compliance” would not be consistent with the requirement of “complete independence” which Member States must guarantee their supervisory authority. The AG shares the European Commission’s view that independence of an authority must involve a term of office of predetermined duration and that his tenure must be assured until that term of office expires, unless this is precluded for overriding reasons, pre-determined by law and objectively verifiable. Such an intrinsic link between security of tenure throughout the term of office and the “complete independence” requirement is indisputable. Similarly, the independence of a judge cannot be said to be respected if their duties are prematurely terminated under cover of the dismantling of the court in which he sits and its replacement by another court, even if such court is accorded independence. The mere risk that an authority may be compelled to vacate office may expose the authority to which Article 28(1) Dir.95/46 refers to “undue intervention or pressure” and led to a form of “prior compliance” on its part. So, even if Member States have a measure of discretion to establish their institutional structure, it cannot be denied that “complete independence” as required under EU law is predicated under the existence and observance of specific and detailed rules which dispel any reasonable doubt as to the imperviousness of that authority to external factors that, directly or indirectly, may influence the authority’s decisions. Even if the Authority has a different legal status from the Supervisor and operates in accordance with different rules, it has succeeded the Supervisor in the exercise of the tasks attributed to the supervisory authority under Article 28 Dir.95/46. In relation to the claim that institutional change was decided by the constitutional authority, it is clear from the documents before the court that the Authority itself was created by “organic law”. Moreover, institutional changes cannot compromise the effectiveness of the higher obligations imposed by EU law as regards the guarantee of “complete independence”, since the primacy of EU law applied whatever the nature of the national rule at stake. Such changes cannot justify compelling the data protection Supervisor to vacate office before serving his full term. The AG thus concludes its analysis, by claiming that, by prematurely bringing to an end the term to be served by the data protection supervisory authority, Hungary failed to fulfil the obligations of Article 28 Dir.95/46. Holding — The CJEU started its analysis by stating that Article 28(1) Dir.95/46 requires Member States to set up one or more supervisory authorities with complete independence in the exercise of the duties entrusted to them. The obligation to have an independent Supervisory Authority to ensure compliance with data protection law stems directly from primary law of the EU, i.e. Article 8(3) CFR and Article 16(2) TFEU. Having an independent supervisory authority is thus an essential protection of individuals, as confirmed in C-518/07 Commission v Germany. The CJEU decided that the relevant aspect to be examined whether the requirements of Article 28(1) Dir.95/46 to ensure that each supervisory authority is able to carry out the tasks entrusted to it in complete independence entails an obligation for the Member States concerned to allow that authority to serve its full term in office. This provision shall be interpreted as meaning that supervisory authority responsible for supervising the processing of personal data must enjoy an independence allowing them to perform their duties free from external influence. The CJEU previously held that the risk that a Member States’ scrutinizing authorities could exercise a political influence over the decisions of the supervisory authorities is enough to hinder the latter in the independent performance of their tasks due to the following. First, those authorities could exercise “prior compliance”. Second, Article 28(1) Dir.95/46 requires that the supervisory authority’s decisions remain above each suspicion of partiality. In fact, if it was permitted for all Member States to compel a supervisory authority to vacate office before serving its full term, the threat of such premature termination to which that authority would be exposed throughout its term of office could lead it to enter into a form of prior compliance with the political authority, which would completely undermine the requirement of independence. In such a situation, the supervisory authority cannot be regarded as being able to operate impartially. In fact, Article 28(1) Dir.95/46 entails that the independence requirement shall be construed so that the supervisory authority can operate above all suspicions of partiality. Thus, the CJEU highlighted that the independence requirement shall cover the obligation to allow the supervisory authority to serve their full time in office and to have them vacate the office before expiry of the full term only in accordance with the rules and safeguards established by the applicable legislation. As per Article 15(1) Law of 1993, the Supervisor can be called to resign from office only if their term expire, upon death, resignation, declaration of a conflict of interest, compulsory retirement or resignation. These last grounds require a Parliament decision adopted by a two-thirds majority. The CJEU clearly stated that none of these grounds apply to the disputed dismissal and that Hungary obliged the Supervisor to vacate office in contravention of the safeguards established to protect his term of office, consequently compromising their independence as per Article 28(1) Dir.95/46. The claim advanced by Hungary that this dismissal related to an institutional change is also not applicable to the case at hand, according to the CJEU. More specifically, the CJEU considered that, when Member States implement institutional changes, they must ensure that the independence of the supervisory authority under Article 28(1) GDPR is not compromised. This holds particularly true due to the fact that the Supervisor and the subsequently-established Authority are entrusted with identical tasks. Thus, by prematurely ending to end the term served by the supervisory authority for the protection of personal data, Hungary failed to fulfil its obligations under Dir.95/46/EC on the protection of individuals with regards to the processing of personal data on the free movement of such data.

### Judgment of the Court (Grand Chamber), 8 April 2014.#European Commission v Hungary.#Failure of a Member State to fulfil obligations — Directive 95/46/EC — Protection of individuals with regard to the processing of personal data and the free movement of such data — Article 28(1) — National supervisory authorities — Independence — National legislation prematurely bringing to an end the term served by the supervisory authority — Creation of a new supervisory authority and appointment of another per

*Source: Court of Justice of the European Union, C-288/12, 2014-04-08 — https://overview.legal/posts/132371 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62012CJ0288*

The European Commission brought an infringement action against Hungary before the Court of Justice (Grand Chamber) under Article 258 TFEU, alleging that Hungary violated Article 28(1) of Directive 95/46/EC by adopting national legislation that prematurely terminated the term of its existing data protection supervisory authority and appointed a new head. The Court ruled that Hungary had failed to fulfil its obligations, holding that the independence of supervisory authorities under Article 28(1) requires that their term of office cannot be brought to an end without legitimate justification, and that a Member State may not reduce the originally established term of office through general legislation without respecting the conditions previously governing the termination of that term. No fine was imposed in this judgment.

### Judgment of the Court (Second Chamber) of 19 October 2016.#Xabier Ormaetxea Garai and Bernardo Lorenzo Almendros v Administración del Estado.#Request for a preliminary ruling from the Tribunal Supremo.#Reference for a preliminary ruling — Electronic communications networks and services — Directive 2002/21/EC — Article 3 — Impartiality and independence of national regulatory authorities — Institutional reform — Merger of national regulatory authority with other regulatory authorities — Dismissal

*Source: Court of Justice of the European Union, C-424/15, 2016-10-19 — https://overview.legal/posts/132352 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62015CJ0424*

The CJEU ruled on a preliminary reference from the Spanish Tribunal Supremo concerning Xabier Ormaetxea Garai and Bernardo Lorenzo Almendros, who challenged their dismissal as President and board member of the Comisión del Mercado de las Telecomunicaciones following an institutional merger, against the Administración del Estado. The core issue was whether Article 3 of the Framework Directive (Directive 2002/21/EC), as amended, precludes the dismissal of the head or board members of a national regulatory authority before the expiry of their terms of office on grounds not provided for in national law at the time of their appointment. The Court held that EU law requires that grounds for dismissal be laid down in advance in national law, ensuring the independence and impartiality of national regulatory authorities.

### Korkein hallinto-oikeus (Finland) - KHO:2021:125

*Source: Supreme Administrative Court of Finland, 2021-09-10 — https://overview.legal/posts/122863 — original: https://gdprhub.eu/index.php?title=Korkein_hallinto-oikeus_(Finland)_-_KHO:2021:125*

Facts — The Regional Government of Åland had appointed Mr A as head of the regional Ålandic DPA for a probationary period of one year. Pursuant to section 10(2) of the Act on Public Officials in the Region of Åland, the Government of Åland stated that they would not propose the appointment of A to a permanent post and that A's term of office would therefore automatically come to and end after the one-year probationary period. At the end of the probationary period, the Government of Åland issued a notice confirming that Mr A's term of office had ended. Mr A however applied to the Supreme Administrative Court of Finland for the annulment of this decision, which he considered contrary to the GDPR. Holding — The Supreme Administrative Court considered that the notice issued by the Government of Åland constituted an administrative decision terminating Mr A's mandate. The Supreme Administrative Court found that, in addition to national legislation, A's role as head of the data protection authority is also regulated by EU law, and in particular by the GDPR. Although the GDPR does not contain explicit provisions regarding probationary period, the minimum length of the term of any member of any data protection authority is "no less than four years", as set in Article 54(1)(d) GDPR. As a consequence, the termination of A's mandate at the end of the probationary period could not be considered in line with the GDPR. The Supreme Administrative Court further noted that leaving Mr A without any possibility of appeal against that decision would be contrary to the right to a fair trial as protected under the Finnish Constitution, Article 19 TFEU and Article 47 CFR. As Mr A's mandate and termination had not been assessed in the light of the provisions of the GDPR, the Supreme Administrative Court concluded that the decision to terminate Mr A's mandate had to be annulled and the matter referred back to the Government of Åland for reconsideration.

### BVerwG - 6 C 1.24

*Source: German Federal Administrative Court, 2025-11-05 — https://overview.legal/posts/125606 — original: https://gdprhub.eu/index.php?title=BVerwG_-_6_C_1.24*

Facts — The data subject was employed by the German Federal Financial Supervisory Authority (BaFin), the public authority responsible for supervising banks, financial service providers, and insurance companies. He worked as a case officer in a specialised unit dealing with serious financial misconduct, including organised crime and terrorism financing. Due to their work, employees in this unit regularly issue binding decisions, conduct on-site inspections, and may appear as witnesses in criminal proceedings, which makes them identifiable to affected persons. Because several employees in this unit had been threatened in the past, the data subject’s home address had been blocked from disclosure in the population register for many years. When the blocking period expired, he applied for a renewal. The local registration authority refused the request on the ground that no individual threat against the claimant had been demonstrated. The lower administrative court dismissed the data subject’s appeal against the authority’s decision, while the Higher Administrative Court ordered the renewal after the data subject also appealed the first instance court’s decision. The registration authority appealed to the Federal Administrative Court. Holding — The Court dismissed the appeal and confirmed that the blocking of the address had to be granted. The Court held that an address may be blocked where there are objectively verifiable facts showing that disclosure could endanger a person’s life, health, personal freedom, or similarly protected interests. This requires an individualised risk assessment, but it does not require that the applicant has already been personally threatened. Risks arising from a specific professional activity may suffice, particularly where other persons performing essentially the same tasks have been subjected to threats or attacks. In this case, the Court had to find a balance between the public’s right to transparency of information, and the employee’s right to privacy and protection of personal data, under the GDPR and Articles 7 and 8 of the Charter of Fundamental Rights. Applying these principles, the Court found that the claimant’s work in a unit dealing with organised crime and terrorism financing, together with documented threats against colleagues in the same unit, justified the conclusion that disclosure of his address could expose him to serious risks. Where these conditions are met, the registration authority has no discretion and must block the address for the statutory period.

### OGS Zagreb - Pn-877/2023-29

*Source: Municipal Civil Court in Zagreb, 2026-01-16 — https://overview.legal/posts/52429 — original: https://gdprhub.eu/index.php?title=OGS_Zagreb_-_Pn-877/2023-29*

Facts — A data subject filed a lawsuit against Propuls d.o.o., the controller and publisher of the news portal direktno.hr, claiming that two articles published on 11 January 2023 and 31 January 2023 disclosed her personal data without her consent: The first article reported on payments related to the football club Dinamo Zagreb and included the data subject’s full name, bank account number, and payment amounts. The second article referred to the first article via a hyperlink but did not mention the data subject directly. The data subject argued that the disclosure violated her right to privacy and the protection of personal and family life under Croatian law and the GDPR. She claimed non-material damage and sought compensation as well as publication of the court decision in the controller's news portal. The controller admitted publishing the articles but argued that the information was accurate and that publishing the data served the public interest. The controller also stated that it had issued a correction upon the data subject request and argued that journalistic activity may be exempt from certain obligations under GDPR and it's exempt from liability if the facts concerned are true according to the Croatian Media Law. The evidence included the published articles, the correction request, witness testimony from journalists and the data subject, and financial records. Holding — The court held that the controller violated the data subject’s right to privacy and the protection of personal and family life. It reasoned that publishing her full name, bank account number, and payment amounts was disproportionate because the details were not necessary to inform the public about the football club payments. Following the ECHR jurisprudence, the court applied a proportionality test, balancing the controller’s freedom of expression against data subject's privacy rights under the Croatian Constitution and civil law. The court emphasised that the data subject was not a public figure, had not voluntarily exposed her private life to the media, and did not participate in public debate in a way that could justify disclosing her sensitive data. The court also addressed the controller’s argument regarding journalistic freedom. It recognised that journalists may publish personal data when there is an overriding public interest, such as exposing wrongdoing or contributing to an important debate. However, in this case, the disclosure of the data subject’s bank account and payment amounts was unnecessary for the story’s public interest. The court noted that general information about club payments could have been reported without identifying her. Regarding the harm suffered, the court found that the data subject experienced non-material damage, including emotional stress and intrusion into her private and family life. It awarded €3,000 in damages with statutory interest, while rejecting the additional claim of €3,636.14 as excessive. The court also denied the data subject’s request to publish the decision, explaining that publishing it could further disclose her personal data and undermine her privacy rights.

### Judgment of the Court (First Chamber) of 22 June 2023.#Proceedings brought by J.M.#Request for a preliminary ruling from the Itä-Suomen hallinto-oikeus.#Reference for a preliminary ruling – Processing of personal data – Regulation (EU) 2016/679 – Articles 4 and 15 – Scope of the right of access to information referred to in Article 15 – Information contained in log data – Article 4 – Definition of ‘personal data’ – Definition of ‘recipients’ – Temporal application.#Case C-579/21.

*Source: Court of Justice of the European Union, C-579/21, 2023-06-22 — https://overview.legal/posts/132284 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0579*

In Case C-579/21, the Court of Justice of the European Union ruled on a preliminary reference from the Itä-Suomen hallinto-oikeus (Administrative Court of Eastern Finland) concerning a dispute between J.M. and Pankki S, a Finnish bank, after the Apulaistietosuojavaltuutettu (Assistant Data Protection Supervisor) rejected J.M.'s request for access to certain log data. The core issue was the scope of the right of access under Article 15 of the GDPR, specifically whether log data containing information about who accessed personal data and when constitutes "personal data" and whether the controller must communicate the identities of recipients. The Court held that log data relating to consultations of a data subject's personal data constitutes personal data under Article 4(1) of the GDPR, and that a data subject is entitled to obtain the identities of recipients of their data, subject only to exceptions expressly provided by law or overriding rights of third parties. No fine was imposed as this was a preliminary ruling proceeding.

## Guidance

### Opinion 1/2023 on the draft decision of the competent supervisory authority of Croatia regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to Article 41 GDPR

*Source: EDPB, opinion-12023-on-the-draft-decision-of-the-competent-en, 2023-02-17 — https://overview.legal/posts/125874 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-12023-on-the-draft-decision-of-the-competent_en*

Adopted 1 Opinion 1/2023 on the draft decision of the competent supervisory authority of Croatia regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to Article 41 GDPR Adopted on 3 February 2023 Adopted 2 Table of c ontents 1 Summary of the Facts................................................................................................................... 4 2 Assessment…

### Opinion 9/2019 on the Austrian data protection supervisory authority draft accreditation requirements for a code of conduct monitoring body pursuant to article 41 GDPR

*Source: EDPB, opinion-92019-on-the-austrian-data-protection-supervisory-en, 2019-07-12 — https://overview.legal/posts/126220 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-92019-on-the-austrian-data-protection-supervisory_en*

adopted Opinion 9 /201 9 on the Austrian d ata protection supervisory authority draft accreditation requirements for a code of conduct monitoring body pursuant to a rticle 41 GDPR Adopted on 9 Jul y 201 9 2 adopted Contents 1 Summary of the Facts ................................ ................................ ................................ ..................... 4 2 Assessment ................................ ................................ ................................…

### Opinion 03/2023 on the draft decision of the competent supervisory authority of Romania regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR

*Source: EDPB, opinion-032023-on-the-draft-decision-of-the-competent-en, 2023-02-17 — https://overview.legal/posts/125871 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-032023-on-the-draft-decision-of-the-competent_en*

1 Adopted Opinion 03/2023 on the draft decision of the competent supervisory authority of Romania regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR Adopted on 3 February 2023 2 Adopted 3 Adopted The European Data Protection Board Having regard to Article 63, Article 64 (1)(c), (3)-(8) and Article 41 (3) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of…

### Opinion 15/2022 on the draft decision of the competent supervisory authority of Luxembourg regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR

*Source: EDPB, opinion-152022-on-the-draft-decision-of-the-competent-en, 2022-07-04 — https://overview.legal/posts/125926 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-152022-on-the-draft-decision-of-the-competent_en*

Adopted Opinion 15 / 20 22 on the draft decision of the competent supervisory authority of Luxembourg regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR Adopted on 4 July 2022 Adopted Adopted The European Data Protection Board Having regard to Article 63, Article 64 (1)(c), (3) - (8) and Article 41 (3) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of…

### Opinion 16/2022 on the draft decision of the competent supervisory authority of Slovenia regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR

*Source: EDPB, opinion-162022-on-the-draft-decision-of-the-competent-en, 2022-07-04 — https://overview.legal/posts/125924 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-162022-on-the-draft-decision-of-the-competent_en*

1 Adopted Opinion 16 / 20 22 on the draft decision of the competent supervisory authority of Slovenia regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR Adopted on 4 July 2022 2 Adopted 3 Adopted The European Data Protection Board Having regard to Article 63, Article 64 (1)(c), (3) - (8) and Article 41 (3) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of…

### Opinion 24/2021 on the draft decision of the competent supervisory authority of Slovakia regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR

*Source: EDPB, opinion-242021-on-the-draft-decision-of-the-competent-en, 2021-07-20 — https://overview.legal/posts/126004 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-242021-on-the-draft-decision-of-the-competent_en*

1 Adopted Opinion 24 / 20 21 on the draft decision of the competent supervisory authority of Slovakia regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR Adopted on 20 July 2021 2 Adopted 3 Adopted The European Data Protection Board Having regard to Article 63, Article 64 (1)(c), (3) - (8) and Article 41 (3) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of…

### Opinion 23/2021 on the draft decision of the competent supervisory authority of Czech Republic regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR

*Source: EDPB, opinion-232021-on-the-draft-decision-of-the-competent-en, 2021-07-20 — https://overview.legal/posts/126006 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-232021-on-the-draft-decision-of-the-competent_en*

1 Adopted Opinion 23 / 20 21 on the draft decision of the competent supervisory authority of Czech Republic regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR Adopted on 20 July 2021 2 Adopted 3 Adopted The European Data Protection Board Having regard to Article 63, Article 64 (1)(c), (3) - (8) and Article 41 (3) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the…

### Opinion 10/2021 on the draft decision of the competent supervisory authority of Hungary regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR

*Source: EDPB, opinion-102021-on-the-draft-decision-of-the-competent-en, 2021-03-23 — https://overview.legal/posts/126045 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-102021-on-the-draft-decision-of-the-competent_en*

Adopted Opinion 10 / 20 21 on the draft decision of the competent supervisory authority of Hungary regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR Adopted on 23 March 2021 Adopted Adopted The European Data Protection Board Having regard to Article 63, Article 64 (1)(c), (3) - (8) and Article 41 (3) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural…

## Enforcement decisions

### Persónuvernd (Iceland) - 2020061979

*Source: Persónuvernd (Iceland), 2022-06-29 — https://overview.legal/posts/6316 — original: https://gdprhub.eu/index.php?title=Persónuvernd_(Iceland)_-_2020061979*

Facts — The Icelandic DPA started an investigation into a genetic research company. More specifically, to assess the company's Data Protection Officer (DPO), as well as the performance of the DPO's tasks. The DPA requested information from the company to determine if and how the company's DPO was compatible with Article 38 GDPR. The DPA stated that the decision to investigate the DPO was made with the intention of ensuring compliance, not because it assumed the requirements of the GDPR were not being followed. The DPA wrote two letters, but the company did not respond to any of them within the prescribed deadlines. After a phone call, the DPA received a response almost two months after the first letter had been sent. Holding — After reviewing the responses from the controller, the Icelandic DPA concluded that there were no violations in relation to the obligations to appoint a DPO (Article 37), to involve the DPO in relevant matters (Article 38(1)), and to provide the DPO with the necessary resources (Article 38(2)). However, the DPA held that the controller violated the obligation to ensure the DPO's independence pursuant to Article 38(3). The acting DPO at the time of the investigation also held the position of deputy CEO, senior lawyer and board member. The DPA held that that could lead to a conflict of interest. The current DPO also held the position of senior lawyer. The DPA held that this also constituted a conflict of interest. The DPA instructed the controller to ensure that the acting DPO would not be responsible for other tasks and duties that may lead to a conflict of interest. The DPA further noted that the despite the delayed answers, it would not impose a fine, taking into account the fact that the information was eventually received as well as the COVID-19 outbreak.

### Company: Lack of appointment of data protection officer

*Source: Austrian Data Protection Authority (dsb), 2024-10-16 — https://overview.legal/posts/48888 — original: https://www.enforcementtracker.com/ETid-2773*

The Austrian DPA has imposed a fine on a company. The controller appointed a DPO who had a conflict of interest, meaning the person was not suitable for the role.

### Proximus SA: Insufficient involvement of data protection officer

*Source: Belgian Data Protection Authority (APD), 2020-04-28 — https://overview.legal/posts/46387 — original: https://www.enforcementtracker.com/ETid-272*

According to the data protection authority, the company's data protection officer was not sufficiently involved in the processing of personal data breaches and the company did not have a system in place to prevent a conflict of interest of the DPO, who also held numerous other positions within the company (head of compliance and audit department), which led the DPA to the conclusion that the company's DPO was not able to work independently.

### Garante per la protezione dei dati personali (Italy) - 9794895

*Source: Garante per la protezione dei dati personali (Italy), 2022-06-09 — https://overview.legal/posts/6314 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_9794895*

Facts — The Municipality of Policoro (Basilicata), implemented the use of CCTV cameras to monitor and fight waste abandonment within its territory. A data subject complained the Municipality had breached their data protection right of fair, transparent and lawful processing under art. 5(1)(a) as the sign signaling the CCTV monitoring referred to an outdated legislative decree. They also alleged a breach of art. 5(1)(e) and art. 13 GDPR, in so far the municipality never defined a data retention period for each processing purpose pursued. The last complaint moved forward by the data subject was that by being legally represented in Court by the same lawyer, who also acted as DPO of Policoro, the Municipality gave rise to a conflict of interest situation and breached art. 38(6) GDPR. The Municipality argued that the claim had been done in front of the Justice of Peace, who had no competency to decide on issues of privacy. It was also alleged the judgement only pertained an administrative matter, without rising any data protection concerns or a situation of conflict of interest with the Municipality's DPO. The last argument alleged the processing and retention of the CCTV footage was related to illegal dumps within the municipal territory, meaning the filming had been carried out in the course of judicial police investigations and the data retention periods of the GDPR did not apply in this case. Holding — The Italian DPA held that in this case the Municipality was carrying activities of data processing, by surveilling public entities by means of surveillance cameras. It also noted, that in par. 41 of the Guidelines 3/2019 on the Processing of Personal Data by Video Devices, waste management is "among the institutional activities entrusted to local authorities". This means the surveillance done by the Municipality of Policoro, a task carried out in the public interest in connection with the exercise of official authority as per art.6(1)(e) GDPR, was unrelated to public security and/or judicial police and obliging the controller to comply with data protection principles. The DPA found that the information provided in regards to the processing of personal data by means of surveillance cameras, did not meet the requirements of conciseness, transparency, intelligibility and easy readability contained in art. 5(1)(a) GDPR. The Municipality of Policoro had failed to provide suitable first-level information to the data subject, in so far the sign signaling the CCTV surveillance made reference to an outdated legislative decree (d.lgs 196/03) instead of the one currently in force (d.lgs 101/18). Furthermore, the data controller failed to provide the data subject with an adequate notice on second-level processing of their data. The signage did not include information on the most suitable impacts of the processing or an indication of a website, where to consult an extended version of the explanation. The DPA also found a violation of art. 13 GDPR as well as the principles of storage limitation and accountability in art. 5(1)(e) and art. 5(2). It stated that "the longer the intended storage period (especially if longer than 72 hours), the more reasoned the analysis referring to the legitimacy of the purpose and necessity of storage must be". In this case, the data controller not only failed to set a maximum retention period for the images taken for the purpose of combating illegal littering, but also established the administrative fines for the violation two months after the images were recorded. This did not allow for the data controller to respect the principle of accountability. Lastly, the DPA addressed the alleged conflict of interest raised by the involvement of the Policoro's DPO in the legal proceedings brought against the data subject. The DPA ruled DPOs "may perform other duties and functions," with the understanding that "the controller must ensure that such duties and functions do not give rise to a conflict of interest." The DPA also made reference to the Article 29 WP's Guidelines on Data Protection Officers, in which it is urged to not designate DPOs already acting as defense counsel for the same court. In the case at hand, it resulted that the DPO shared with the Municipality an interest in obtaining a rejection of the appeal. Consequently, the Italian Garante held this to be in violation of art. 38(6) GDPR, as well the fact that it undermined the DPO's independence. The Italian DPA held a cumulative breach of art. 5(1)(a) and (e) and (2) (in conjunction with article 24), 12, 13 and 38(6) GDPR. It balanced the fact that the personal data processing affected all other citizens, who passed through the areas under surveillance, against the lack of previous violations committed by the data controller. The DPA issued a fine of €26,000 EUR to the Municipality of Policoro.

### Clinic: Insufficient involvement of data protection officer

*Source: Data Protection Authority of Berlin, 2021-01-01 — https://overview.legal/posts/47337 — original: https://www.enforcementtracker.com/ETid-1222*

The DPA from Berlin has imposed a fine on a clinic. The clinic had appointed the clinic manager, who was also a shareholder of the clinic, as the data protection officer. A data protection officer may perform other tasks and duties, but the company must ensure that other tasks and duties do not lead to a conflict of interest. In the present case, however, there was such a conflict of interest. On the one hand, the clinic manager had to make economic decisions in his executive position, and on th

### Bank: Insufficient involvement of data protection officer

*Source: Belgian Data Protection Authority (APD), 2021-12-16 — https://overview.legal/posts/47109 — original: https://www.enforcementtracker.com/ETid-994*

The Belgian DPA has imposed a fine of EUR 75,000 on a bank. The DPA identified a conflict of interest regarding the data protection officer. In addition to his work as data protection officer, he was also head of a department to which he had to report in his capacity as data protection officer. The DPA considered this to be a violation of Art. 38 (6) GDPR.

### Austrian DSB rules 360-degree feedback unlawful without specific works agreement

*Source: DSB (Austria), 2026-03-20 — https://overview.legal/posts/187479 — original: https://gdprhub.eu/index.php?title=DSB_(Austria)_-_2025-0.960.016*

Facts — The data subject was employed by an Austrian stock corporation (the controller) from August 2018 to June 2025. They worked as a manager in the controller’s finance department, with technical and disciplinary responsibility for up to five employees. The controller operated a 360-degree feedback process under which the data subject completed a self-assessment and 17 other individuals, including their supervisor, three subordinates and other employees, evaluated their leadership behaviour across 27 categories. Both the data subject and their supervisor had access to the results. The process was also used for other managers within the company. On 1 August 2025, the data subject lodged a complaint with the Austrian DPA, alleging a violation of their right to confidentiality. They argued that the processing carried out as part of the 360-degree feedback process required a specific works agreement and was therefore unlawful in the absence of one. The controller had concluded a framework works agreement with the central works council on the processing of employee data, as well as a supplementary agreement concerning its HR system. However, there was no specific works agreement covering the 360-degree feedback process. The controller alleged that it relied on its legitimate interests under Article 6(1)(f) GDPR and on the performance of the employment contract under Article 6(1)(b) GDPR. It argued that a works agreement would merely specify its legitimate interests and that the absence of such an agreement did not render the processing unlawful. It further maintained that whether a works agreement was required was a labour-law issue that could not be determined in the proceedings before the DPA The data subject responded that the processing of personal data in a 360-degree feedback process served to evaluate employees and therefore constituted a measure within the meaning of § 96 of the Austrian Labour Constitution Act (ArbVG). Section 96 ArbVG lists certain workplace measures that can be introduced only with the works council’s consent through a works agreement. Holding — The DPA first found that the data subject was an employee covered by the Austrian Labour Constitution Act, rather than a senior executive excluded from its scope. It further held that the assessments of the data subject’s leadership behaviour constituted personal data. The DPA explained that Article 88 GDPR enables Member States to adopt, through legislation or collective agreements, more specific rules protecting the rights and freedoms of individuals in the context of employment-related processing. Such rules must include appropriate safeguards for, among other things, human dignity, legitimate interests and the fundamental rights of data subjects. Recital 155 GDPR expressly refers to works agreements as a possible instrument for implementing such rules. It further stated that Austria had made use of the opening clause in Article 88 GDPR and that § 96 ArbVG constituted one of the more specific national rules protecting employees in the context of personal data processing. It determined that the 360-degree feedback process constituted a systematic and standardised assessment of employees falling under both § 96(1)(2) ArbVG, concerning personnel questionnaires, and § 96(1)(3) ArbVG, concerning monitoring measures affecting human dignity. It held that under § 96 ArbVG, the processing therefore required the works council’s consent through a valid works agreement. It pointed out that the controller’s existing works agreements did not cover the 360-degree feedback process or the categories of personal data collected through it. It therefore held that the processing could not be based on a works agreement under Article 88(1) GDPR in conjunction with § 96 ArbVG. The DPA held that the controller could not rely on Article 6(1)(f) GDPR. It stated that although personnel management and improving employee performance might generally constitute legitimate interests, an interest pursued through processing contrary to national law could not be regarded as lawful. It concluded that since the mandatory works council consent had not been obtained, the interest could not be regarded as legitimate under Article 6(1)(f) GDPR. Moreover, it pointed out that Article 6(1)(b) GDPR was also inapplicable because the feedback process was not necessary for the performance of the employment contract. It reasoned that the employment relationship could be performed without it, and the process was not applied to all employees. The DPA therefore found that the processing was unlawful and violated the data subject’s right to confidentiality. It prohibited the controller from continuing the 360-degree feedback process for employees covered by the ArbVG until a valid works agreement was concluded.

### Company: Insufficient involvement of data protection officer

*Source: Data Protection Authority of Berlin, 2022-09-20 — https://overview.legal/posts/47513 — original: https://www.enforcementtracker.com/ETid-1398*

The DPA of Berlin has imposed a fine of EUR 525,000 on the subsidiary of a Berlin-based e-commerce group. The company had appointed a data protection officer, who however was also the managing director of two service companies that processed personal data on behalf of the very same company for which they acted as data protection officer. These service companies are also part of the group to which the e-commerce company belongs. The DPA considered this to be a conflict of interest and found a vio

## Recent developments

### De IJslandse toezichthouder heeft geoordeeld dat er sprake is van een belangenconflict wanneer een Functionaris Gegevensbescherming (FG) tegelijkertijd ook de hoofdjurist van een bedrijf is.

*Source: GDPRhub, 2022-09-28 — https://overview.legal/posts/51805*

De IJslandse Autoriteit Persoonsgegevens (SA) heeft vastgesteld dat er sprake is van een belangenconflict wanneer een Functionaris Gegevensbescherming (FG) tegelijkertijd ook de senior jurist, plaatsvervangend CEO of bestuurslid van een bedrijf is. Een FG kan echter wel de functie van compliance officer bekleden.

### Can the roles of DPO and whistleblowing officer be merged?

*Source: IAPP, 2023-03-28 — https://overview.legal/posts/6228 — original: https://iapp.org/news/a/can-be-the-role-of-data-protection-officer-and-whistleblowing-officer-merged-in-one-person#entry-4228*

> 
																						Personal data protection and whistleblowing are two different topics — different regulations with different purposes, scope and requirements. But, in fact, they are closer than they seem, especially for practical reasons.
Both data protection governance and whistleblowing systems are often exercised by the same unit —  the compliance department — or even by the same person. This solution offers several advantages, but also some problematic points that need to be highligh

### Het Italiaanse bedrijf SA heeft juridische stappen ondernomen tegen een gemeente vanwege het gebruik van haar videosurveillance systeem en omdat het haar Functionaris Gegevensbescherming (FG) heeft aangesteld om de gemeente in een rechtszaak te vertegenwoordigen.

*Source: GDPRhub, 2022-09-28 — https://overview.legal/posts/51807*

Tenslotte oordeelde de gegevensbeschermingsautoriteit dat de verantwoordelijke, door de functionaris gegevensbescherming (FG) te betrekken bij de verdediging in rechtszaken, de FG in een positie van belangenconflict bracht, in strijd met artikel 38(6) van de AVG. Dit was met name omdat dit ertoe leidde dat de betrokkene het gevoel had niet in staat te zijn om contact op te nemen met de FG met betrekking tot kwesties die verband houden met de verwerking van hun persoonlijke gegevens en de uitoefening van hun rechten zoals uiteengezet in artikel 38(4) van de AVG.

### Berlin DPA imposes 525K euro fine over DPO violation

*Source: IAPP, 2022-09-22 — https://overview.legal/posts/6275 — original: https://iapp.org/news/a/berlin-dpa-imposes-525k-fine-over-dpo-violation#entry-482*

> The Berlin Commissioner for Data Protection and Freedom of Information issued a 525,000 euro fine to a Berlin-based retailer for violation of data protection officer requirements under the \[GDPR]. An investigation found an alleged conflict of interest concerning the DPO's employment status and decision-making responsibilities that violated Article 38(6) of the GDPR. The company received a warning from the regulator in 2021.

### EU-Hof: gegevens waaruit indirect de seksuele geaardheid van een persoon kan worden afgeleid vormen gevoelige gegevens in de zin van de AVG

*Source: NL EU Court Expert, 2022-08-17 — https://overview.legal/posts/6290 — original: https://ecer.minbuza.nl/-/eu-hof-gegevens-waaruit-indirect-de-seksuele-geaardheid-van-een-persoon-kan-worden-afgeleid-vormen-gevoelige-gegevens-in-de-zin-van-de-avg?redirect=%2Fecer%2Fnieuws%3Fq%3Dprivacy%2520OR%2520avg%26f%3D%26t%3D#entry-300*

The processing of personal data that may indirectly reveal sensitive information about an individual, such as information about their sexual orientation, may qualify as processing of "special categories of personal data" within the meaning of the AVG. The processing of such sensitive data is prohibited in principle. This is the EU Court's answer to questions from a Lithuanian judge.

## Literature

### Event-Driven Compliance: Reconciling Privacy Regulation with Real-Time Advertising Infrastructure

*Source: Journal of Computer Science and Technology Studies, 2025-11-26 — https://overview.legal/posts/53852 — original: https://doi.org/10.32996/jcsts.2025.7.12.20*

Programmatic advertising ecosystem functions based on distributed, event-driven frameworks that handle user data across enterprise limits in milliseconds, with basic contradictions with the present-day privacy laws such as GDPR, ePrivacy Directive, and CCPA/CPRA. The system of real-time bidding projects the identifiers of users and the cues of their behavior to many prospective advertisers, creating compliance risks that are multiplicative beyond jurisdictional lines. This manuscript formalizes

### The AI Act and the future of STEM education in Europe: rethinking pedagogy, assessment, and teacher agency

*Source: Frontiers in Education, 2026-07-02 — https://overview.legal/posts/53829 — original: https://doi.org/10.3389/feduc.2026.1845045*

Generative artificial intelligence (AI) is swiftly transforming STEM education, presenting pedagogical, ethical, and regulatory challenges. The Artificial Intelligence Act, a comprehensive legislative framework emphasizing transparency, accountability, and human oversight, is implemented throughout Europe. This paper analyzes the necessity of re-evaluating STEM education in light of the convergence between generative AI and the AI Act. The paper posits that, grounded in pedagogy, evaluation, and

### The Magician’s Eye

*Source: Journal of Ethics and Emerging Technologies, 2026-07-01 — https://overview.legal/posts/53832 — original: https://doi.org/10.55613/jeet.v36i2.239*

David Eliot trained as a card magician before turning to AI research. His Artificially Intelligent sets out to democratise AI for general readers, and on its own terms it succeeds: the history is rich, the writing is clear, and the central argument that AI is socially constructed and democratically redirectable is held with conviction. This review reads the book alongside the regulatory architecture being built on the same theory of agency: the EU AI Act, the harmonised standards beneath it, the

## Related topics

- **Notified Body Independence** — https://overview.legal/topics/notified-body-independence-impartiality
  Notified bodies must maintain strict independence and impartiality standards, which are critical operational obligations that warrant a dedicated topic for deta
- **Monitoring** — https://overview.legal/topics/monitoring
  Systematic observation and tracking of individuals
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities

---
Generated by overview.legal · https://overview.legal/topics/scientific-panel-independence-impartiality · 2026-08-22
