# Social Media — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/social-media
> Sources are cited per item. Verify against the official texts before relying on them.

Social networking platforms and privacy considerations

## Overview

## Legal Framework

Social media platforms implicate multiple layers of EU data protection law. The primary governing instruments include [Article 5(3) of Directive 2002/58](/laws/ai-act/rec-16) (ePrivacy Directive) governing access to terminal equipment, the GDPR's controller responsibility provisions, and the AI Act's treatment of biometric categorisation features embedded in social networks. Under the AI Act, certain biometric filters used on social platforms fall outside the scope of biometric categorisation rules when they function as ancillary features:

> "Filters used on online social network services which categorise facial or body features to allow users to add or modify pictures or videos could also be considered to be ancillary feature as such filter cannot be used without the principal service of the social network services consisting in the sharing of content online."
> — [AI Act Recital 16](/laws/ai-act/rec-16)

The rationale is that such filters cannot operate independently of the platform's core sharing function, and their integration does not circumvent the Regulation's safeguards. However, this ancillary exemption is narrow — it hinges on objective technical dependence on the principal service.

## Key Developments

The CJEU's *Wirtschaftsakademie* ruling established a foundational principle: operators of Facebook fan pages are joint controllers alongside Facebook Ireland. The Court held that by defining audience parameters and promotional objectives, the page administrator participates in determining the purposes and means of processing visitors' personal data. Crucially, joint controller status attaches even where the administrator never directly accesses the personal data:

> "Directive 95/46 does not, where several operators are jointly responsible for the same processing, require each of them to have access to the personal data concerned."
> — [*Wirtschaftsakademie*, ¶38](/posts/6135#seg-38)

The Court was unambiguous that commercial benefit from the platform does not exempt an administrator from compliance obligations. In *Fashion ID*, the CJEU extended this analysis to social plugins, confirming that the question of whether a plugin provider gains access to information stored on a visitor's terminal equipment under Article 5(3) of the ePrivacy Directive is determinative of the lawfulness analysis. The *Schrems II* decision invalidated Privacy Shield, fundamentally reshaping how social media platforms transfer EU user data to third countries — particularly the United States — by requiring case-by-case assessment of whether third-country surveillance laws undermine adequate safeguards.

## Status of the Debate

This topic is actively contested in court. The boundaries of joint controllerhip on social platforms remain in flux: *Wirtschaftsakademie* and *Fashion ID* established broad responsibility principles, but subsequent cases have tested where that responsibility ends. The ancillary biometric categorisation exemption under the AI Act is newly introduced and untested in litigation — no court has yet interpreted the "objective technical reasons" threshold for social media filters. Additionally, post-*Schrems II* transfer mechanisms for social media data remain subject to ongoing challenge, as the EU-US Data Privacy Framework faces its own anticipated legal test. What would resolve the open questions: a CJEU reference on the outer limits of joint controller status for passive social media presence, and a ruling interpreting the AI Act's ancillary feature exemption in the context of platform-integrated biometric tools.

## Practical Guidance

- **Conduct a joint controller assessment** for any social media presence your organisation operates. Under *Wirtschaftsakademie*, defining audience parameters or promotional objectives on a platform like Facebook makes you a joint controller — document this determination and execute a joint controller arrangement under [Article 26 GDPR](/laws/ai-act/rec-16).
- **Audit social plugins** (e.g., "Like" buttons, share widgets) for compliance with Article 5(3) of the ePrivacy Directive. *Fashion ID* confirms that plugin providers' access to terminal equipment data triggers consent requirements — ensure lawful basis and transparency notices cover this.
- **Map third-country transfer routes** for all data flows involving social media platforms. Post-*Schrems II*, verify that Standard Contractual Clauses are supplemented by transfer impact assessments addressing surveillance laws in the recipient country.
- **Evaluate biometric filters** against the AI Act's ancillary feature test. If a filter cannot function without the platform's core sharing service and is not designed to circumvent the Regulation, document the technical rationale supporting the exemption.
- **Do not assume anonymity of analytics** absolves responsibility. *Wirtschaftsakademie* confirms that even where platform-provided statistics are anonymised, the underlying collection and processing of visitors' personal data remains subject to joint controller obligations.

## Legislation (full text of key provisions)

### Recital 16 — definition of biometric categorisation

*Source: AI Act, aiact-rec-16-en, 2024-06-12 — https://overview.legal/posts/93714*

The notion of ‘biometric categorisation’ referred to in this Regulation should be defined as assigning natural persons to specific categories on the basis of their biometric data. Such specific categories can relate to aspects such as sex, age, hair colour, eye colour, tattoos, behavioural or personality traits, language, religion, membership of a national minority, sexual or political orientation. This does not include biometric categorisation systems that are a purely ancillary feature intrinsically linked to another commercial service, meaning that the feature cannot, for objective technical reasons, be used without the principal service, and the integration of that feature or functionality is not a means to circumvent the applicability of the rules of this Regulation. For example, filters categorising facial or body features used on online marketplaces could constitute such an ancillary feature as they can be used only in relation to the principal service which consists in selling a product by allowing the consumer to preview the display of the product on him or herself and help the consumer to make a purchase decision. Filters used on online social network services which categorise facial or body features to allow users to add or modify pictures or videos could also be considered to be ancillary feature as such filter cannot be used without the principal service of the social network services consisting in the sharing of content online.

## Case law

### BVwG - W137 2327171-1

*Source: Federal Administrative Court, 2026-07-08 — https://overview.legal/posts/184712 — original: https://gdprhub.eu/index.php?title=BVwG_-_W137_2327171-1*

Facts — The controller, an assistant professor at a private university (the appellant), was engaged in an employment dispute with her university employer before a labour and social court. The data subject, a senior legal counsel employed by the university gave testimony as a witness in that employment proceeding. On 23 January 2025, the labour and social court ruled in the controller's favour, finding that her employment relationship continued beyond the university's purported termination date. The judgment referred to the data subject several times by her academic title and surname in connection with her witness testimony. In April 2025, the controller published the unredacted judgment in full, including the data subject's title and surname on social media. She shared a downloadable link (first via Dropbox, later via Adobe) on her public Facebook profile and in a closed Facebook group of around 230 members connected to the university community. The files were later removed by Dropbox and Adobe after the data subject reported them. The data subject's full first name and additional details could also be found by combining her academic title and surname with the university's name in a Google search, which surfaced her LinkedIn profile. The data subject filed a complaint with the Austrian DPA, arguing that the controller had no justification for naming her and had drawn her into a public dispute with her employer. The controller argued that the judgment concerned matters of wider relevance to university staff, that the Facebook group was closed and that the data subject's name and role were already public via the university directory and LinkedIn. On 15 October 2025, the DPA upheld the complaint, finding that the controller had violated the data subject's right to secrecy under §1(1) of the Austrian Data Protection Act (DSG) by publishing the judgment without a legal basis. The DPA found that a legitimate interest existed in principle, but that both publications were excessive as the judgment was made accessible to an uninvolved and disproportionately wide audience and that disclosing the data subject's name was not necessary to achieve the controller's stated purpose of informing colleagues in similar situations. The DPA noted that publishing the judgment with the data subject's name redacted would have been an equally effective, less intrusive alternative. The controller appealed, arguing that the data subject had no protectable secrecy interest because she had participated in the proceeding in a public professional capacity and had made comparable information about herself public on LinkedIn and that the DPA had failed to weigh her freedom of expression rights under Article 10 ECHR against the data subject's secrecy interest. Holding — The court dismissed the appeal in full and confirmed the DPA's decision. First, the court rejected the controller's argument that no protectable secrecy interest existed because the data subject had acted in a professional capacity. It held that, under settled national case-law, appearing in a professional role does not by itself remove a person's right to secrecy under §1(1) DSG. Second, applying the three-part test for legitimate interest under Article 6(1)(f) GDPR, the court accepted that the controller had, in principle, a legitimate interest in informing colleagues in comparable employment situations about the judgment. However, it held that publishing the data subject's surname failed the necessity requirement under this test and therefore also breached the data minimisation principle under Article 5(1)(c) GDPR. The court noted that the data subject was a witness testifying about legal matters, not the person responsible for the controller's employment contract and that naming her added nothing to the comprehensibility or persuasive value of the information the controller sought to share. Because necessity was lacking, the court found it unnecessary to conduct any further balancing of the parties' respective rights. Third, the court rejected the controller’s argument that her freedom of expression justified the full disclosure of the judgment, for which she relied on the CJEU’s judgment in Case C-345/17 (Buivids). The court held that Buivids concerned whether processing could be regarded as being carried out solely for journalistic purposes, whereas there was no indication of journalistic activity in the present case. It further held that §9 DSG, which implements Article 85 GDPR in relation to journalistic activity, was therefore inapplicable. In any event, the court stated that §9 DSG does not entirely override the principle of proportionality but establishes a different standard for balancing the competing interests. Finally, the court agreed with the DPA that redacting the data subject's name and title would have been an equally effective and only minimally burdensome alternative that would not have undermined the controller's informational purpose and held that the controller had not plausibly explained why such redaction would have been insufficient. The court accordingly found no unlawfulness in the DPA's decision and dismissed the appeal. It declared that an appeal on points of law (Revision) was not admissible, since the case did not raise a legal question of fundamental importance and was consistent with existing case-law.

### Judgment of the General Court (Tenth Chamber, Extended Composition) of 29 January 2025 (Extracts).#Data Protection Commission v European Data Protection Board.#Protection of personal data – Article 65(1)(a) of Regulation (EU) 2016/679 – Binding decision instructing a lead supervisory authority to broaden the scope of its investigation and issue a new draft decision – Competence of the European Data Protection Board.#Joined Cases T-70/23, T-84/23 and T-111/23.

*Source: General Court, T-70/23, 2025-01-29 — https://overview.legal/posts/132152 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023TJ0070*

The Irish Data Protection Commission (DPC) challenged provisions of EDPB Binding Decisions 3/2022, 4/2022, and 5/2022, arguing the EDPB exceeded its competence under Article 65(1)(a) GDPR by requiring the DPC to broaden its investigation into Facebook, Instagram, and WhatsApp and issue new draft decisions. The core legal issue was whether the EDPB, in the consistency mechanism context, can compel a lead supervisory authority to conduct additional investigations and produce new draft decisions beyond addressing the specific relevant and reasoned objections raised by concerned supervisory authorities. The General Court dismissed the DPC's actions, upholding the EDPB's authority to issue binding decisions instructing the lead supervisory authority to carry out further investigation and issue new draft decisions.

### OLG München - 36 U 1054/25 e

*Source: Higher Regional Court Munich, 2026-06-26 — https://overview.legal/posts/184545 — original: https://gdprhub.eu/index.php?title=OLG_München_-_36_U_1054/25_e*

Facts — The data subject had used a social media platform operated by the controller, an Irish company, since 2013. The controller provided “Business Tools” to third-party website operators and app providers. These tools enabled the controller to obtain data concerning how users interacted with third-party websites and apps, including information about page visits, purchases and advertisements clicked. In November 2023, the data subject requested that the controller recognize that the processing of his personal data was contrary to the parties’ contract, erase or anonymize the personal data, provide access to the personal data and pay compensation. The data subject subsequently brought an action before the Regional Court of Munich II, seeking a declaration that the parties’ user contract did not permit the processing, cessation of the processing of personal data collected through the Business Tools on third-party websites and apps, restriction of further processing, erasure or anonymization of previously collected data and at least €5,000 in non-material damages. The relevant data included direct and indirect identifiers, such as his name, contact details, IP address and internal identifiers, as well as website URLs, visit times, app names and information about his interactions with websites and apps. The Regional Court of Munich II dismissed the action, holding that the declaratory and erasure or anonymization claims were inadmissible, the cessation claims were legally unavailable and the damages claim had not been sufficiently substantiated. In relation to the damages claim, it found that the data subject had not identified specific third-party websites or apps through which his personal data had been processed. The data subject accordingly appealed to the Higher Regional Court of Munich. Holding — The Higher Regional Court of Munich partially upheld the appeal. First, the court held that the Controller processed the data subject’s personal data under Articles 4(1) and 4(2) GDPR by receiving data transmitted through its Business Tools, associating it with a user account and storing it. The data subject was not required to identify every website, app or individual transmission because the relevant information was principally within the controller’s knowledge and it was sufficiently probable that he had been affected. Second, referring to CJEU C‑40/17 concerning the broad interpretation of “controller”, the court held that the controller was a joint controller under Articles 4(7) and 26 GDPR for the collection and transmission of the personal data. It controlled the programming of the Business Tools and participated in determining the purposes and means of processing. Allocating certain obligations to third-party website and app operators did not remove its responsibility. Third, referring to CJEU C‑252/21, the court held that the controller had not established a lawful basis for the processing of the personal data. The processing was not justified by consent under Article 6(1)(a), contractual necessity under Article 6(1)(b), a legal obligation under Article 6(1)(c), a public-interest task under Article 6(1)(e), or legitimate interests under Article 6(1)(f) GDPR. Accordingly, the court held that the controller's processing infringed Articles 5(1)(a), 5(1)(b), 5(1)(c) and 6 GDPR. Relying on CJEU C‑655/23, the court granted an injunction against future unlawful processing under German law. It also ordered restriction pending erasure under Article 18(1)(b) and erasure under Article 17(1)(d) GDPR. The court upheld the dismissal of the separate declaratory claim and also rejected anonymization of the website and app interaction data. Finally, relying on BGH VI ZR 10/24, the court awarded €1,500 in non-material damages under Article 82(1) GDPR for the data subject’s loss of control over his personal data.

### Judgment of the General Court (Tenth Chamber, Extended Composition) of 16 July 2025.#Lisa Ballmann v European Data Protection Board.#Protection of personal data – Complaint against the controller of personal data of users of an online social network in the European Union – Article 65(1)(a) of Regulation (EU) 2016/679 – Binding decision of the European Data Protection Board – Complainant’s request for access to the file prepared for the purposes of the binding decision – Refusal to grant access –

*Source: General Court, T-183/23, 2025-07-16 — https://overview.legal/posts/132139 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023TJ0183*

In Case T-183/23, Lisa Ballmann sought annulment of the European Data Protection Board's decision refusing her request for access to the file prepared for Binding Decision 3/2022, which concerned Meta Platforms Ireland's processing of personal data on Facebook. The core issue was whether the EDPB's refusal to grant the complainant access to that file—thereby limiting her ability to be heard in the Article 65(1)(a) GDPR dispute resolution procedure—was actionable and compatible with Article 41(2)(b) of the EU Charter of Fundamental Rights. The General Court ruled on the admissibility of the action and the scope of a complainant's procedural rights before the EDPB, with Meta Platforms Ireland intervening in support of the EDPB; no fine was imposed.

### CJEU - C-311/18 - Facebook Ireland and Schrems

*Source: GDPRhub, 2026-07-17 — https://overview.legal/posts/125639 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-311/18_-_Facebook_Ireland_and_Schrems*

Facts — Maximillian Schrems, an Austrian citizen, had been a Facebook user since 2008. As is the case with users residing in the European Union, some of the data belonging to Mr. Schrems had been transferred by Facebook Ireland to its servers belonging to Facebook Inc., located in the United States. In 2013, Mr. Schrems complained to the Irish Data Protection Commissioner (DPC) seeking to prohibit these transfers. When this complaint was rejected, he brought an action against the decision before the Irish High Court, which in turn referred a number of questions to the CJEU, the most prominent of which was whether the EU-US adequacy decision, the so-called “Safe Harbor", was valid. In its judgment on October 6th 2015 (Case C-362/14, “Schrems I”), the CJEU invalidated the Safe Harbor and stated that, in order to be "adequate", the level of data protection offered by the third country should be “essentially equivalent” to that being offered in the EU. As a result, the High Court annulled the decision rejecting Mr. Schrems’ complaint, and referred the case back to the DPC. In the remittal “judgment” before the DPC, Facebook Ireland explained that the invalidated adequacy decision was not relevant as a large part of personal data was transferred to Facebook Inc. pursuant to Standard Contractual Clauses (SCCs). On this basis, the DPC asked Mr. Schrems to reformulate his complaint. In his reformulated complaint lodged on December 1st 2015, Mr. Schrems alleged that US law required Facebook Inc. to disclose his personal data to certain United States authorities in the context of various monitoring programs (in particular, the FISA 702 and the Executive Order 12.333). In Mr Schrems’ view, these programs contravened different data protection principles as well as Article 7 CFR, Article 8 CFR, and Article 47 CFR. After investigating the allegations made by Mr. Schrems, the DPC argued that it could not adjudicate on them until the CJEU had examined the validity of the SCCs, and so it brought proceedings before the High Court. On May 4th 2018 the High Court made the reference for a (second) preliminary ruling to the CJEU. In its reference to the CJEU, the High Court specified that Section 702 of the FISA permitted the Attorney General and the Director of National Intelligence to authorize jointly, following FISA approval, the surveillance of individuals who are not US citizens and who are located outside of the US in order to obtain foreign intelligence information. It was also affirmed that Section 702 of the FISA provided the basis for the PRISM and UPSTREAM surveillance programs. PRISM in particular, requires Internet Service Providers (ISPs) to supply the NSA with all communications to and from a ‘selector’. UPSTREAM on the other hand, permitted the NSA to copy and filter Internet traffic flows from the ‘backbone’ of the internet, granting it access to both the content of communications and their metadata. Furthermore, the High Court had found that Executive Order 12.333 (E.O. 12333) allowed the NSA to access data in transit by accessing underwater cables on the floor of the Atlantic. The High Court stated that the only limit on US surveillance activities was found in the Presidential Policy Directive (PPD-28), and even this only stated that intelligence activities should be ‘tailored as feasible’. On the basis of these findings, the High Court considered that the US carried out mass processing of personal data without ensuring a level of protection that was essentially equivalent to that which was guaranteed by Article 7 CFR and Article 8 CFR. The High Court also highlighted that EU citizens did not have the same remedies available to them as US citizens with regards to the processing of their personal data, since the Fourth Amendment to the Constitution of the United States did not apply to non-US citizens. This meant that it was particularly difficult for EU citizens to establish standing before a US court. Moreover, activities based on E.O. 12333 were not subject to judicial oversight and were not justiciable. Given the considerable effects of US surveillance law on the rights of Europeans, the High Court raised the question of whether the SCCs are valid, given that they may not be binding on the State authority of the third country. If they did not bind the third country State authority, then they are not capable of remedying a possible lack of an adequate level of protection of personal data. Dispute — The request for a preliminary ruling referred eleven questions to the Court of Justice. The topics covered in these questions were as follows: the applicability of EU law to data transfers made for commercial purposes, but further processed for national security and law enforcement purposes the relevant legislation for determining whether there has been a violation of individual rights how to assess the level of protection in a third country whether data transfers to the US violate the Charter whether the level of protection offered in the US respects or limits an individual’s right to a judicial remedy what level of protection is required to be afforded to personal data that is transferred under SCCs whether the SCCs can even be adequate as safeguards given they do not bind national authorities whether there is an obligation to suspend data flows if a data importer is subject to surveillance law what the relevance of the Privacy Shield decision is with regards to assessing safeguards whether the presence of an ombudsperson can ensure that the US provides an effective remedy to data subjects whether the SCCs violate the Charter Holding — The Court began by clarifying that the GDPR applies to the transfer of personal data for commercial purposes by an economic operator established in a Member State, to another economic operator established in a third country, even if in that country the data would be processed by the national authorities for public security, defense, and state security purposes. In particular, the Court stressed that a transfer of data is not excluded from the scope of the GDPR for the reason that it may be processed by the national authorities of a third country. Regarding the level of protection required in such an instance, the Court held that the requirements presented by the GDPR regarding safeguards, enforceable rights, and legal remedies must continue to be applied. In other words, when their data is transferred abroad, a data subject must be afforded a level of protection essentially equivalent to that which they would receive in EU. In such circumstances, in order to assess the level of protection, both existing contractual clauses between the data importer and exporter, and the potential access by public authorities in a third country must be taken into account, along with the relevant aspects of the legal system in the third country. The Court then analyzed Decision 2016/1250 (the “Privacy Shield”), which was the self-certification scheme in place for controllers based in the US. Examining the decision in light of the provisions of the Charter, the Court held that the requirements of US national security, public interest, and law enforcement do in fact interfere with the fundamental rights of persons whose data is transferred there. These limitations on the protection of personal data were not circumscribed in a way that satisfied requirements that are essentially equivalent to those required under EU law. The principle of proportionality was also not satisfied, in so far as US surveillance programs are not limited to what is ‘strictly necessary’. It was noted that the provisions in the US surveillance programs neither limited the power they conferred onto national authorities, nor granted data subjects actionable rights before the courts against the US authorities. The Court proceeded to scrutinize the Ombudsperson mechanism that had been in place under the Privacy Shield, stating that it too did not provide data subjects with a cause of action before a body which was fully independent, and that this body was limited in so far as it could not impose rules that were binding on US intelligence services. Taking all of this into account, the Court declared the Privacy Shield Decision to therefore be invalid. The Court also clarified that in the absence of an adequacy decision, the competent supervisory authorities are required to suspend or prohibit a transfer of personal data to a third country where they consider that the standard data protection clauses are not or cannot be complied with in the third country, and that the protection of the data transferred cannot be ensured by other means. Following this, the Court then examined the validity of the SCCs (Decision 2010/87). First, the Court held that the validity of the Decision was not called into question by the mere fact that the SCCs do not bind national authorities in a third country. After establishing this, the Court emphasized that the validity of the SCCs, however, did depend on whether there were effective mechanisms in place that make it possible to ensure compliance with the level of protection required by EU law. Important to note is that here the Court held that the SCCs in themselves did provide for such mechanisms. However, it went on to stress that where these mechanisms cannot be complied with, the transfers of personal data pursuant to these clauses is to be suspended or prohibited. Furthermore, there is an obligation on the data exporter and the recipient of the data to verify prior to a transfer, what the level of protection in a third country is, and whether it will be possible to comply with the requirements of the SCCs.

### CJEU - T‑183/23 - Ballmann v European Data Protection Board

*Source: GDPRhub, 2025-07-16 — https://overview.legal/posts/184572 — original: https://gdprhub.eu/index.php?title=CJEU_-_T‑183/23_-_Ballmann_v_European_Data_Protection_Board*

Facts — The ruling relates to the procedural aspects of a cross-border case involving Meta Platforms Ltd. The full summary for the case is available here. Context: The case against Meta — In May 2018 a Facebook user (the complainant) lodged a complaint against Meta Platforms Ireland Ltd with the Austrian DPA. In her complaint, she claimed that the collection of personal data via Facebook violated several rules of the GDPR, including Articles 6 and 9. Short after the complaint was filed, the Austrian DPA held that the case was cross-border in nature and forwarded the complaint to the Irish DPA as the lead supervisory authority. In 2021 the Irish DPA submitted a draft decision to all EEA supervisory authorities. Some of them raised “reasoned and relevant objections” to the draft within the meaning of Article 4(24) GDPR. The DPC decided not to follow some of those objections and, therefore, referred the matter to the EDPB under the GDPR’s consistency mechanism. The EDPB decided the matter in December 2022 with its Binding Decision 3/2022. Following the Binding Decision, the Irish DPA decided the complaint and fined Meta €210,000,000 over the unlawful processing of personal data for targeted advertising on Facebook. The case against the EDPB — After the dispute resolution procedure of the EDPB the complainant requested access to the case file relating to her complaint. She invoked several provisions of EU primary and secondary law, including Article 41(2)(b) of the EU Charter of Fundamental Rights (“Right to good administration”). The EDPB replied with an email to the complainant (from now on: “the Contested Decision”), granting the complainant access to some of the documents relative to the procedure based on EU Regulation 1049/2001. However, the EDPB held that the complainant had no right of access under Article 41(2)(b) CFREU. As a result, the EDPB only granted the complainant access to parts of the file. The complainant considered that the EDPB violated her rights and filed an action for the annulment of the contested decision under Article 263 TFEU. The complainant claimed that under Article 41(2)(b) CFREU, she had a right to access the EDPB case file in relation to her complaint. On this ground, she requested that the Court of Justice (General Court) set aside the Contested Decision. The EDPB, in turn, requested that the Court declare the complainant’s action inadmissible or, in the alternative, unfounded. Meta was granted the status of intervening party and put forwards the same demands as the EDPB. Holding — The Court upheld the complainant's demands and annulled the contested decision from the EDPB. The action was admissible — First, the Court held that the action was admissible. In this regard, the Court considered that the contested decision "contains a refusal to grant access to the file requested" under Article 41(2)(b) CFREU. It "immediately and irreversibly affects the applicant’s legal position" to access the EDPB case file. According to the settled case law of the CJEU, it follows that the complainant could bring an action for annulment under Article 263 TFEU. In response to an argument from the EDPB, the Court also clarified that it was not relevant that the contested decision acknowledged the complainant's limited right of access under Regulation 1049/2001. In the case at hand, the complainant would have had a broader right of access under Article 41(2)(b) CFREU than she did under the Regulation (as the EDPB itself conceded). The right of access is independent from the right to be heard — The parties put forward different interpretations of Article 41 CFREU – in particular, with regard to the relationship between paragraphs (2)(a) and (2)(b) of the provision. The EDPB claimed that paragraph (2)(a) and (2)(b) embody corollary aspects of the rights of the defence. In this interpretation, the complainant’s right of access was not protected under paragraph (2)(b) because the requirements of paragraph (2)(a) (being adversely affected), was not fulfilled. Therefore, the EDPB claimed the contested decision rightfully denied access to the file. The complainant claimed that the two paragraphs are independent from each other and embody autonomous rights. In other words: proving that the file concerned her, should have been sufficient grounds for accessing the file. The Court confirmed the complainant’s interpretation: “everyone has the right of access to his or her file based on Article 41(2)(b) of the Charter, including where that file is not linked to a procedure liable to culminate in a measure adversely affecting him or her” . Therefore, the EDPB erroneously applied the requirements of Article 41(2)(a) CFREU to the right to access the file under Article 41(2)(b) CFREU, as the complainant claimed. The file concerned the complainant — After clarifying the interpretation of Article 41 CFREU, the Court assessed whether the file for the Article 65 GDPR procedure concerned the complainant. The Court held that even though the complainant is not a formal party to the procedure under Article 65(1)(a) GDPR, the complaint plays an essential role in that procedure as it constitutes the starting point of the entire decision-making process. The Court also pointed out that the relevant and reasoned objections (of supervisory authorities concerned) form part of the procedure initiated following the complaint. In particular, these objections determine the scope of the EDPB’s binding decisions under Article 65(1)(a) GDPR. For this reason, a complainant may legitimately want to ascertain whether elements of the complaint were reproduced in the objections or the extent they have been taken into account in the binding decision. Finally, the Court held that complainants have a direct interest in the outcome of procedure, as it relates to the processing of their personal data. For these reasons, the Court held that in the case at hand, the EDPB’s file “concerned” the complainant. In consequence, the Court annulled the contested decision.

### Judgment of the Court (Fourth Chamber) of 4 October 2024.#Maximilian Schrems v Meta Platforms Ireland Limited.#Request for a preliminary ruling from the Oberster Gerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Online social networks – General terms of use relating to contracts concluded between a digital platform and a user – Personalised advertising – Article 5(1)(b) – Principle of purpos

*Source: Court of Justice of the European Union, C-446/21, 2024-10-04 — https://overview.legal/posts/132159 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0446*

In a preliminary ruling arising from proceedings between Maximilian Schrems and Meta Platforms Ireland Limited, the Court of Justice of the European Union interpreted GDPR Articles 5(1)(b), 5(1)(c), 6(1), and 9 concerning the lawfulness of processing user personal data for personalised advertising on online social networks. The Court addressed whether such processing can be deemed compatible with the original purpose of data collection under a platform's terms of use, the applicability of the data minimisation principle, and the conditions under which special categories of personal data, including data concerning sexual orientation made public by the data subject, may be processed. No fine was imposed, as the ruling provides interpretative guidance to the Austrian Supreme Court for resolution of the underlying dispute.

### Judgment of the Court (Fourth Chamber) of 11 July 2024.#Meta Platforms Ireland Limited v Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband e.V.#Request for a preliminary ruling from the Bundesgerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – First sentence of Article 12(1) – Transparency of information – Article 13(1)(c) and (e) – Obligation o

*Source: Court of Justice of the European Union, C-757/22, 2024-07-11 — https://overview.legal/posts/132250 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0757*

In a preliminary ruling requested by the German Federal Court of Justice (Bundesgerichtshof), the Court of Justice of the European Union interpreted Article 80(2) GDPR in the context of proceedings between Meta Platforms Ireland Ltd and the Bundesverband der Verbraucherzentralen und Verbraucherverbände (Consumer Association). The core issue is whether a consumer protection association may bring a representative action under Article 80(2) GDPR without a mandate from specific data subjects and independently of an actual infringement of a data subject's rights, based on a controller's alleged violation of its transparency obligations under Articles 12(1) and 13(1)(c) and (e). The Court held that such an action is permissible, finding that an infringement of the controller's information obligations constitutes an "infringement of the rights of data subjects as a result of the processing" within the meaning of Article 80(2), and that Member States may allow representative actions without requiring a specific data subject's mandate or an actual infringement of individual rights.

### Judgment of the General Court (Fifth Chamber, Extended Composition) of 24 May 2023.#Meta Platforms Ireland Ltd, formerly Facebook Ireland Ltd v European Commission.#Competition – Data market – Administrative procedure – Article 18(3) and Article 24(1)(d) of Regulation (EC) No 1/2003 – Request for information – Virtual data room – Obligation to state reasons – Legal certainty – Rights of the defence – Necessity of the information requested – Misuse of powers – Right to privacy – Proportionality –

*Source: General Court, T-451/20, 2023-05-24 — https://overview.legal/posts/132287 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62020TJ0451*

The General Court ruled on Meta Platforms Ireland Ltd's challenge against a European Commission decision requesting information under Regulation No 1/2003 in the context of a competition investigation into Facebook's data-related practices. Meta sought annulment of the contested decision, arguing, among other grounds, that the request was unnecessary, disproportionate, violated the right to privacy, and failed to provide adequate safeguards for personal data through the proposed virtual data room procedure. The judgment addresses the obligations of the Commission regarding the statement of reasons, necessity, proportionality, and rights of defense when issuing requests for information that may encompass personal data.

### Judgment of the General Court (Fifth Chamber, Extended Composition) of 24 May 2023.#Meta Platforms Ireland Ltd, formerly Facebook Ireland Ltd v European Commission.#Competition – Data market – Administrative procedure – Article 18(3) and Article 24(1)(d) of Regulation (EC) No 1/2003 – Request for information – Virtual data room – Obligation to state reasons – Legal certainty – Rights of the defence – Necessity of the information requested – Misuse of powers – Right to privacy – Proportionality –

*Source: General Court, T-452/20, 2023-05-24 — https://overview.legal/posts/132288 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62020TJ0452*

### Judgment of the Court (Third Chamber) of 28 April 2022.#Meta Platforms Ireland Limited v Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband eV.#Request for a preliminary ruling from the Bundesgerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 80 – Representation of the data subjects by a not-for-profit association – Representative action

*Source: Court of Justice of the European Union, C-319/20, 2022-04-28 — https://overview.legal/posts/132312 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62020CJ0319*

The CJEU ruled on a preliminary reference from the German Federal Court of Justice in proceedings between Meta Platforms Ireland Limited and the Verbraucherzentrale Bundesverband (Federal Union of Consumer Organisations) concerning whether Article 80(1) GDPR permits a consumer protection association to bring a representative action independently of a specific data subject's mandate. The Court held that Article 80(1) does not allow such an association to bring proceedings on its own behalf without a mandate from data subjects, even where the alleged GDPR infringement also constitutes an unfair commercial practice or a breach of consumer protection law, though Member States may authorize this under Article 80(2). No fine was imposed in this preliminary ruling.

### Judgment of the Court (Grand Chamber) of 15 June 2021.#Facebook Ireland Ltd and Others v Gegevensbeschermingsautoriteit.#Request for a preliminary ruling from the Hof van beroep te Brussel.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Charter of Fundamental Rights of the European Union – Articles 7, 8 and 47 – Regulation (EU) 2016/679 – Cross-border processing of personal data – ‘One-stop shop’ mechanism – Sincere and effecti

*Source: Court of Justice of the European Union, C-645/19, 2021-06-15 — https://overview.legal/posts/132323 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62019CJ0645*

In Case C-645/19, the Court of Justice of the European Union (Grand Chamber) addressed a preliminary ruling from the Brussels Court of Appeal concerning Facebook Ireland Ltd and others versus the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit) regarding the scope of the GDPR's "one-stop shop" mechanism for cross-border data processing. The core issue was whether a national supervisory authority that is not the lead supervisory authority retains the competence to initiate legal proceedings and bring enforcement actions against a controller for cross-border processing violations. The Court held that non-lead supervisory authorities retain the power to bring proceedings before national courts, even regarding cross-border processing, subject to the obligation of sincere and effective cooperation under Articles 60 to 66 of the GDPR. No fine was imposed in this judgment, as it was a preliminary ruling on the interpretation of EU law.

## Guidance

### EDPB Annual Report 2022

*Source: EDPB, edpb-annual-report-2022-en, 2023-04-17 — https://overview.legal/posts/125861 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-annual-report-2022_en*

EDPB Annual Report 2022 1 2022 ANNUAL REPORT STREAMLINING ENFORCEMENT THROUGH COOPERATION An Executive Summary of this report, which provides an overview of key EDPB activities in 2022, is also available. Further details about the EDPB can be found on our website at edpb.europa.eu. 1 GLOSSARY 4 2 FOREWORD 7 3 2022 – HIGHLIGHTS 9 3.1. ENFORCEMENT COOPERATION 9 3.1.1. Vienna statement on enforcement cooperation 10 3.1.2. Guidelines 02/2022 on the application of Art. 60 GDPR 10 3.1.3. Guidelines…

### EDPB Annual Report 2023

*Source: EDPB, edpb-annual-report-2023-en, 2024-04-23 — https://overview.legal/posts/125756 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-annual-report-2023_en*

EDPB Annual Report 2023 1 2023 ANNUAL REPORT SAFEGUARDING INDIVIDUALS' DIGITAL RIGHTS 2 FOREWORD 4 HIGHLIGHTS 2023 6 1. THE EDPB SECRETARIAT 8 1.1. MISSION AND ACTIVITIES IN 2023 9 1.2. RE-ORGANISING THE SECRETARIAT IN 2023 12 2. EUROPEAN DATA PROTECTION BOARD - ACTIVITIES IN 2023 14 2.1. BINDING DECISIONS 14 2.2. CONSISTENCY OPINIONS 19 2.3. GENERAL GUIDANCE 21 2.3.1. Guidelines 03/2022 on deceptive design patterns in social media platform interfaces: how to recognise and avoid them 21 2.3.2.…

### Guidelines 03/2022 on Deceptive design patterns in social media platform interfaces: how to recognise and avoid them

*Source: EDPB, edpb-guidelines-on-deceptive-design-patterns-in-social-media-platform-interfaces-how-to-recognise, 2023-02-24 — https://overview.legal/posts/38056 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-032022-on-deceptive-design-patterns-in-social-media-platform_en*

These Guidelines offer practical recommendations to social media providers as controllers of social media, designers and users of social media platforms on how to assess and avoid so-called 'deceptive design patterns' in social media interfaces that infringe on GDPR requirements. To this end, the EDPB recommends  that  controllers  make  use  of  interdisciplinary  teams,  consisting,  among  others,  of designers,  data  protection  officers  and  decision-makers.  It  is  important  to  note  ...

### Opinion 20/2026 on the draft decision of the Dutch Supervisory Authority regarding the Controller Binding Corporate Rules of the Fluor Group

*Source: EDPB, opinion-202026-on-the-draft-decision-of-the-dutch-supervisory-en, 2026-07-07 — https://overview.legal/posts/125671 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-202026-on-the-draft-decision-of-the-dutch-supervisory_en*

Opinion 20/2026 on the draft decision of the Dutch Supervisory Authority regarding the Controller Binding Corporate Rules of the Fluor Group Adopted on 07 July 2026 1 | Adopted 2 | Adopted The European Data Protection Board Having regard to Article 63, Article 64(1)(f) and Article 47 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such…

### Opinion 21/2026 on the draft decision of the Irish Supervisory Authority regarding the Controller Binding Corporate Rules of the Flutter Group

*Source: EDPB, opinion-212026-on-the-draft-decision-of-the-irish-supervisory-en, 2026-07-07 — https://overview.legal/posts/125670 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-212026-on-the-draft-decision-of-the-irish-supervisory_en*

Opinion 21/2026 on the draft decision of the Irish Supervisory Authority regarding the Controller Binding Corporate Rules of the Flutter Group Adopted on 07 July 2026 1 | Adopted 2 | Adopted The European Data Protection Board Having regard to Article 63, Article 64(1)(f) and Article 47 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such…

### Opinion 19/2026 on the draft decision of the Dutch Supervisory Authority regarding the Processor Binding Corporate Rules of the Rubrik Group

*Source: EDPB, opinion-192026-on-the-draft-decision-of-the-dutch-supervisory-en, 2026-06-08 — https://overview.legal/posts/125672 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-192026-on-the-draft-decision-of-the-dutch-supervisory_en*

Opinion 19/2026 on the draft decision of the Dutch Supervisory Authority regarding the Processor Binding Corporate Rules of the Rubrik Group Adopted on 08 June 2026 1 | Adopted 2 | Adopted The European Data Protection Board Having regard to Article 63, Article 64(1)(f) and Article 47 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such…

### Opinion 18/2026 on the draft decision of the Dutch Supervisory Authority regarding the Controller Binding Corporate Rules of the Rubrik Group

*Source: EDPB, opinion-182026-on-the-draft-decision-of-the-dutch-supervisory-en, 2026-06-08 — https://overview.legal/posts/125673 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-182026-on-the-draft-decision-of-the-dutch-supervisory_en*

Opinion 18/2026 on the draft decision of the Dutch Supervisory Authority regarding the Controller Binding Corporate Rules of the Rubrik Group Adopted on 08 June 2026 1 | Adopted 2 | Adopted The European Data Protection Board Having regard to Article 63, Article 64(1)(f) and Article 47 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such…

### Opinion 17/2026 on the draft decision of the Dutch Supervisory Authority regarding the Processor Binding Corporate Rules of the Infor Group

*Source: EDPB, opinion-172026-on-the-draft-decision-of-the-dutch-supervisory-en, 2026-05-11 — https://overview.legal/posts/125676 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-172026-on-the-draft-decision-of-the-dutch-supervisory_en*

Opinion 17 / 2026 on the draft decision of the Dutch Supervisory Authority regarding the Processor Binding Corporate Rules of the Infor Group Adopted on 11 May 2026 1 | Adopted 2 | Adopted The European Data Protection Board Having regard to Article 63, Article 64(1)(f) and Article 47 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such…

## Enforcement decisions

### Garante per la protezione dei dati personali (Italy) - 9788429

*Source: Garante per la protezione dei dati personali (Italy), 2022-07-07 — https://overview.legal/posts/122853 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_9788429*

Facts — Social media platform TikTok (the controller) provided personalized advertising to its users (the data subjects) on the legal basis of consent (Article 6(1)(a) GDPR). In June 2022, the controller announced that a new privacy policy would come into effect on 13 July 2022. Under the new policy, the controller would only serve personalize advertising to users over 18 years of age and on the legal basis of the legitimate interest of the controller (Article 6(1)(f) GDPR). The Italian DPA started an investigation and found that personalized advertisement would likely involve the use of cookies or other tracking mechanisms. Holding — Regarding the competence of the Italian DPA, it should be noted that the Irish DPA is the lead supervisory authority for the controller’s data processing activities under the GDPR's "one-stop-shop" mechanism. The Italian DPA acknowledged the Irish DPA’s position in its decision. However, the Italian DPA held the ePrivacy Directive to be applicable to the processing of cookies by the controller and held itself competent to enforce the Directive. The DPA referenced Recital 173 GDPR and EDPB Opinion 05/2020 on this point. The DPA held that the controller’s new privacy policy violated Article 5(3) ePrivacy Directive 2002/58/EC. The Article only allows the controller to process cookies and use similar tracking mechanisms with the user’s consent . For this reason, legitimate interest under Article 6(1)(f) GDPR is not a valid legal basis for the processing of cookies. The Italian DPA also held that the controller violated Article 122 of the Italian Privacy Code (d. lgs. 30 giugno 2003, n. 196). Article 122 is a direct transposition of Article 5(3) ePrivacy Directive. The violation of the Code constitutes a direct consequence of the violation of the Directive. The DPA issued a warning against the controller.

### AEPD (Spain) - E/03783/2020

*Source: AEPD (Spain), 2026-07-15 — https://overview.legal/posts/108996 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_E/03783/2020*

Facts — The Directorate for National Security of the Ministry of Interior issued guidelines for the police forces to monitor news and social networks to spot fake news and misinformation, to prevent some actors from causing social stress, in light of the covid-19 pandemic. This came to the Spanish DPA (AEPD) knowledge, that launched an investigation to verify that such behaviour complied with the personal data regulations. Such guidelines were issued to prevent and minimize the effects of misinformation, with extreme vigilance and monitoring of networks and websites where false messages and information aimed at increasing social stress are disseminated, and, where appropriate, calling for the intervention measures provided for in the applicable legislation". According to the guidelines, within the surveillance and monitoring of networks and web pages, intervention shall only be carried out in accordance with the aforementioned purposes and principles and always under the protection of the applicable legislation. Also, personal data will only be processed when there is sign of a criminal offence, in accordance with the Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data. If such activities were related to national security, then the processed would be carried out with basis on the national legislation regarding state secrets and classified matters. In their response to the DPA, the Directorate for National Security also stated that they do not collect personal data, but only carry out a daily observation of news or public information from social networks, where the information collected relates to data of a public nature, shared by its authors through social networks and public media, consisting primarily of the content of the communication and the medium of dissemination. For this, specialized officers from the Spanish Civil Guard ("Guardia Civil") browse the news and create anonymous users to monitor (read) social networks such as Twitter, Facebook, Instagram, Badoo and other websites. Afterwards, reports with reference to cybercrime, cyberterrorism, hacktivism, cyberattacks, misinformation and news summaries are issued. If there is a sign of a criminal offence, evidence is gathered. Such reports are stored for 5 years. Holding — The DPA concluded that there was no violation of the GDPR, that is not applicable in accordance with its Article 2, nor with the Directive (EU) 2016/680, as personal data were not processed, as the reports showed, and there was no evidence that there was any illegal additional processing. Therefore, the presumption of innocence principle applied. Hence, the AEPD archived the case.

### Italian DPA sanctions Lusha Systems for processing contact data without consent in B2B

*Source: Garante per la protezione dei dati personali (Italy), 2026-07-14 — https://overview.legal/posts/184678 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_542/2026*

Facts — Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database. It was an US company wholly owned by Lusha Systems Ltd. In April 2025, the Italian DPA (Garante) initiated an investigation after media reports revealed that telephone numbers of senior Italian officials were available on the platform. The DPA later received one complaint and one report from data subjects who had received unsolicited advertising communications. The data subjects further stated that after requesting information about the source of their contact details, they discovered that their data were available on the controller’s platform without their consent. The controller explained that, for a subscription fee, it provided its Clients with a Business Contact Card for each Contact. The controller further distinguished between “Clients”, namely customers who used the platform and accessed its B2B database, and “Contacts”, namely the individuals whose personal data were included in that database, regardless of whether they used or were aware of the platform. Clients received Contact Cards containing information such as names, professional email addresses, telephone numbers, job titles, roles and locations, which could be used for sales, marketing, recruitment, business intelligence and fraud prevention. The DPA limited its investigation to the processing of Contacts’ personal data. The controller stated that it collected and combined data from publicly available sources, specialised providers, affiliated companies and commercial partners. It also inferred missing professional email addresses through algorithms that identified standard company email patterns. Through its Community Program and integrations with email, calendar and CRM services, it could also obtain information from Clients’ professional networks and communications. The data were cross-referenced, enriched and regularly updated to reflect changes in Contacts’ professional circumstances. The controller argued that the GDPR did not apply because it was established outside the EU and provided services only to businesses. It additionally claimed that the weekly updating of Contact Cards ensured accuracy rather than constituting monitoring or profiling. The controller maintained that the collection and disclosure of the data were necessary for its own economic interest in providing accurate professional contact information and for its Clients’ interests, including fraud prevention. According to the controller, it processed only a limited range of information concerning the Contacts’ professional lives. It further claimed that individuals who made professional information publicly available, particularly through services such as LinkedIn, could reasonably expect that the information might be reused and that they could be contacted regarding professional opportunities. Regarding transparency, the controller stated that its Personal Information Notice was sent to each Contact before their information became available in the database. It explained that it notified Contacts that they had a seven-day period during which they could opt out before their information became available to Clients. The controller also maintained that excluding public officials and public figures from the database was not a requirement under the GDPR. It attributed the presence of certain public officials to technical limitations in its filtering system. It also argued that public figures had a lower expectation of privacy. After the proceedings began, the controller removed profiles connected with Italian public bodies and officials, strengthened its filters and customer-verification measures, discontinued the Community Program in Italy and extended the opt-out period to fourteen days. Holding — Regarding the territorial scope of the GDPR, the DPA acknowledged that Article 3(2)(a) GDPR could apply to the processing of Clients’ data, but not to Contacts, since they were not recipients of the service. However, it held that Article 3(2)(b) GDPR applied because the controller systematically combined, enriched and updated Contacts’ professional information in order to assess their circumstances and determine whether and how they would appear in the database. Referring to Recital 24 and Recital 30, the DPA held that monitoring did not require profiling. It noted that the systematic observation of online traces and changes in a person’s professional situation was sufficient. The fact that the processing also served data accuracy did not alter that conclusion. It emphasised that the fact that the controller also updated the information to ensure its accuracy did not prevent the processing from constituting monitoring. Regarding transparency, the DPA found that the information concerning the collection of the Contacts’ data, the purposes of the processing and the legal basis relied upon was scattered across several documents. Also, the relevant information was not easily accessible from the controller’s homepage, while the Personal Information Notice could not be located directly through the website without prior knowledge of its existence. It further pointed out that the documents were provided in English rather than in the language of the affected data subjects. The DPA held that presenting the information in this manner did not satisfy the requirement that information be concise, transparent, intelligible and easily accessible. It therefore found an infringement of Article 5(1)(a) GDPR and Article 12 GDPR. Moreover, the DPA assessed whether Article 6(1)(f) GDPR provided a valid legal basis for the processing. It examined the controller’s Legitimate Interest Assessment and considered it essentially non-existent, as it contained only generic statements on necessity and proportionality and no genuine balancing assessment. The DPA then applied the three-part test under Article 6(1)(f) GDPR. It held that making the Contacts’ data available to Clients for their own marketing and sales activities could not constitute a legitimate interest, since the disclosure of contact information to third parties for their independent advertising purposes required prior consent under the applicable national and ePrivacy framework . However, it acknowledged that the controller’s interest in fraud prevention could be considered legitimate. The DPA nevertheless found that the processing was not necessary for the purposes pursued. It held that the controller collected information extending beyond ordinary professional contact details, including third-party data contained in CRM databases, email headers and subject lines, information about calendar meetings, and browsing data collected through browser extensions or other software integrations used by Clients. It pointed out that much of this information was not publicly available but was extracted from private interpersonal communications, disclosed by Clients, obtained through integrations with information systems or acquired from third-party providers. The DPA held that the collection and combination of such extensive information was neither strictly necessary nor proportionate for creating professional Contact Cards. Furthermore, it stressed that fraud prevention could also have been achieved through less intrusive means. The DPA therefore concluded that the necessity requirement and the principle of data minimisation were not met. Regarding the balancing test, the DPA emphasised that there was no prior relationship between the controller and the Contacts. Creating a professional profile on LinkedIn or another professional platform did not create a reasonable expectation that unpublished contact details would be collected from multiple sources, continuously updated and disclosed to an unspecified number of paying customers. It further noted that the processing could expose Contacts to communications from unknown third parties for purposes they could not reasonably anticipate. The DPA concluded that the Contacts’ interests, rights and freedoms prevailed over the controller’s economic interests and that the safeguards adopted by the controller could not change this outcome. Therefore, the DPA held that Article 6(1)(f) GDPR did not provide an appropriate legal basis and found that the controller infringed Article 5(1)(a) GDPR, Article 5(1)(c) GDPR, and Article 6 GDPR. Regarding public officials, the DPA held that their status did not reduce their entitlement to data protection and that no public interest justified disclosing their direct contact details for commercial purposes. The DPA further found that the controller had been aware of the risk that public officials could be included in its database but had failed to implement sufficiently effective technical and organisational measures. Its filters recognised general titles such as “President” but failed to exclude more specific titles such as “President of the Italian Republic” and “Vice Prime Minister”. The DPA therefore found an infringement of the principle of data minimisation under Article 5(1)(c) GDPR and the obligation of data protection by design and by default under Article 25 GDPR. The DPA imposed a fine of €2,000,000. Furthermore, it prohibited any further processing of personal data of data subjects located in Italy that had been collected without an adequate legal basis and ordered their deletion.

### Meta Platforms Ireland Limited: Non-compliance with general data processing principles

*Source: Data Protection Authority of Ireland, 2023-01-04 — https://overview.legal/posts/47658 — original: https://www.enforcementtracker.com/ETid-1543*

The Irish DPA (DPC) has fined Meta Platforms Ireland Limited EUR 390 million. The DPA has imposed a fine of EUR 210 million for violations related to the provision of its Facebook service and EUR 180 million for violations related to the provision of its Instagram service. The Austrian organization 'None of Your Business' (NOYB) had filed a complaint with the DPA on behalf of two individuals. Meta had updated its terms of service shortly before the GDPR came into force. In its new terms of servi

### BfDI (Germany) - 24-191 II

*Source: BfDI (Germany), 2022-01-27 — https://overview.legal/posts/125601 — original: https://gdprhub.eu/index.php?title=BfDI_(Germany)_-_24-191_II*

Facts — The data subject is a customer and user of services by the Deutsche Telekom AG (controller), the biggest telecommunications and internet provider in Europe. The data subject requested access from the controller to all of his data under Article 15 GDPR. He also requested to have his data transmitted in a portable format under Article 20 GDPR. The controller responded to both requests. The data subject, however, considered that both responses were not complete. He argued that information about his traffic data, his contracts with the controller and his requests to the controller's customer service were missing. Furthermore, the data subject criticised that the controller did not list all recipients in its answer, but only the "most important" ones, that the origin of the data was not specified and that the storage duration was not mentioned. He, therefore, lodged a complaint with the German Federal Data Protection Authority (Der Bundesbeauftragte für den Datenschutz und die Informationsfreiheit - BfDI). Holding — The BfDI partially upheld the complaint. It confirmed the data subject's view that the controller is obligated under Article 15 GDPR to name all recipients and not only the "most important" ones, to specify the origin of the data and to mention the deletion date. However, the DPA found it was not necessary to list each and every individual transfer to a recipient. With regard to the contract documents, the DPA found that it was sufficient that the controller referred the data subject to the online customer portal where the data subject could retrieve those documents. Regarding the data subject’s requests to the customer service of the controller, the DPA found that these requests are usually handled manually by phone or by paper and not automatically. Accordingly, the DPA concluded that Article 20(1)(b) GDPR was not met. Furthermore, the DPA held that the data collected in the course of service requests must be deleted immediately after the purpose has been achieved, that means after the request has been resolved, or, if the data is to be used for other purposes, it must be anonymised. Consequently, the DPA reasoned that the controller could not have provided this data in its answer to the request under Article 15 GDPR. Regarding the traffic data, the DPA reasoned that a data subject has no right to access traffic data under Article 15 GDPR because § 11 TTDSG (Telekommunikation-Telemedien-Datenschutz-Gesetz), which is an implementation of Article 7 ePrivacy Directive and lays down the right to receive itemized bills, takes precedence according to Article 95 GDPR. In the case at hand, the DPA concluded that the data subject did not invoke § 11 TTDSG since the data subject blackened this part of his submissions. Furthermore, the DPA held that by taking the principle of dataminimisation and Article 11 GDPR into account, the controller is only allowed to store IP addresses seven days. Since the IP addresses which were stored at the time of the request have already been deleted, the controller can no longer provide information about them. The DPA also determined that the controller was not obliged to give the data subject access to location data (Cell-ID) because the data subject did not sufficiently demonstrate that he was the sole user of the mobile phone in question. The DPA took the view that, since location data is very sensitive, the data subject must show that no one else was using the cellphone. Lastly, the DPA clarified that the controller is not allowed to record the content transmitted in an online session. Therefore, it found that it was impossible for the the controller to provide information on the visited websites under Articles 15 and 20 GDPR.

### Clinic owner: Insufficient legal basis for data processing

*Source: Spanish Data Protection Authority (aepd), 2024-07-05 — https://overview.legal/posts/48577 — original: https://www.enforcementtracker.com/ETid-2462*

The Spanish DPA has fined the owner of a plastic surgery clinic EUR 10,000. The controller posted before-and-after pictures of an individual who had undergone surgery at the clinic on social media (Facebook and Instagram) without obtaining the individual’s consent.

### SOPHIE ET VOILA, S.L: Insufficient legal basis for data processing

*Source: Spanish Data Protection Authority (aepd), 2022-09-16 — https://overview.legal/posts/47507 — original: https://www.enforcementtracker.com/ETid-1392*

The Spanish DPA has imposed a fine of EUR 10,000 on SOPHIE ET VOILA, S.L..The wedding dress company had published a picture of a customer in a wedding dress on its Instagram account without the customer's consent. For this reason, the DPA determined that the processing of the customer's personal data was unlawful.

### EU DisinfoLab: Non-compliance with general data processing principles

*Source: Belgian Data Protection Authority (APD), 2022-01-27 — https://overview.legal/posts/47138 — original: https://www.enforcementtracker.com/ETid-1023*

The Belgian DPA has fined the NGO EU DisinfoLab EUR 2,700. In 2018, the NGO published an analysis to identify the possible political origin of tweets circulating on a particularly heated controversy in France, the 'Benalla affair.' For the analysis, the organization had processed the data of 55,000 Twitter accounts, of which more than 3,300 had been classified as political. The raw data obtained from this was then published without taking minimal security precautions, such as pseudonymizing the

## Recent developments

### Datatilsynet (Norway) - 23/00435-62

*Source: GDPRhub, 2026-08-21 — https://overview.legal/posts/291399 — original: https://gdprhub.eu/index.php?title=Datatilsynet_(Norway)_-_23/00435-62*

The DPA found that pharmaceutical company unlawfully continued using an influencer’s personal data after their contract expired and fined it NOK 205,000 for breaching its duty to cooperate under Article 31 GDPR. English Summary. Facts. Lab Pharma AS, the controller, is a Norwegian manufacturer of dietary supplements which markets and sells its products online. In 2016, an influencer, the data subject, entered into an agreement with the controller under which she would promote its products on her

### GDPRhub style guide

*Source: GDPRhub, 2026-08-18 — https://overview.legal/posts/291292 — original: https://gdprhub.eu/index.php?title=GDPRhub_style_guide*

Cleared up "the DPA" and "million"/"billion" Example: The Romanian DPA fined Facebook Romania RON 25,000 (€5,000).Example: The Romanian DPA fined Facebook Romania RON 25,000 (€5,000). If the amount is over a million, please use "m" for million and "bn" for billion (in the English sense, i.e. thousand million (1,000,000,000). Consistent indication of dates. Consistent indication of dates ::Example: The German Bundesdatenschutzgesetz (BDSG) becomes the "German Federal Data Protection Act (&#039;&#

### LinkedIn locks your GDPR rights behind a paywall

*Source: noyb - European Center for Digital Rights, 2026-05-05 — https://overview.legal/posts/53127 — original: https://noyb.eu/en/linkedin-locks-your-gdpr-rights-behind-paywall*

Data Subject Rights LinkedIn tracks the visits to profile pages. However, if you want to see who has visited your own profile, you have to pay. The Microsoft subsidiary uses these and other ‘insights’ as an incentive for people to sign up for its paid Premium membership. It is unclear whether this tracking of visitors is legal. What is clear, however, is that if this data is displayed as part of a premium membership, it should also be accessible in response to an access request under Article 15

### TikTok unlawfully tracks your shopping habits – and your use of dating apps

*Source: noyb - European Center for Digital Rights, 2025-12-17 — https://overview.legal/posts/49176 — original: https://noyb.eu/en/tiktok-unlawfully-tracks-your-shopping-habits-and-your-use-dating-apps*

Online & Mobile tracking TikTok not only tracks its users while they are using the TikTok app itself, but it is increasingly integrated with many other websites and apps. For example, TikTok was able to track a person’s Grindr usage on his smartphone. However, that’s not all: In addition to tracking users across the digital space, TikTok also refuses to provide an interested users with a copy of all of their personal data. Therefore, noyb has filed two complaints against TikTok and its data-shar

### ‘Pay or Okay’ study: Users prefer a tracking-free “third option”

*Source: noyb - European Center for Digital Rights, 2025-12-04 — https://overview.legal/posts/49178 — original: https://noyb.eu/en/pay-or-okay-study-users-prefer-tracking-free-third-option*

Cookie Banners So-called ‘Pay or Okay’ systems are on the rise in Europe. Instead of giving users a choice to either accept or reject ad tracking, Pay or Okay systems require a payment if you want to refuse to give your “consent”. This nudges 99.9% of users to consent, even if they actually don’t want to do so. Given the upcoming guidelines by the European Data Protection Board on this highly controversial approach, noyb has commissioned a study about user choices. Download the user study on Pay

## Literature

### Is the GDPR efficient in protecting EU citizens against the privacy risks raised by social media?

*Source: Journal of Data Protection Privacy, 2025-06-01 — https://overview.legal/posts/132556 — original: https://doi.org/10.69554/xact2373*

The General Data Protection Regulation (GDPR) was adopted for a noble cause: protecting European Union (EU) citizens’ privacy and the EU social model founded on the values of dignity, freedom, democracy, equality, the rule of law and respect for human rights. Thanks to the magnitude of its fines, the GDPR attracted much attention from media, companies and legislators far beyond the EU and greatly helped expand the protection of personal data worldwide. Seven years after coming into force, howeve

### Automating the Design and Development of Usable, GDPR-Aware Web Forms

*Source: SN Computer Science, 2026-07-14 — https://overview.legal/posts/132119 — original: https://doi.org/10.1007/s42979-026-05219-7*

Abstract Personal data collection in web applications should follow mandated legislative frameworks such as the EU General Data Protection Regulation (GDPR) principles. Among others, web data collection forms should provide clear and transparent explanations regarding the purposes of the collection. At the same time, for users’ ease, such forms should follow standard usability principles. There have been works studying the merging of usability principles and privacy standards. Building on this l

### Data protection in the AI era: benchmarking EU GDPR and AIA, to reform Saudi Data Protection law

*Source: Cogent Social Sciences, 2026-04-07 — https://overview.legal/posts/132557 — original: https://doi.org/10.1080/23311886.2026.2652554*

### If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation

*Source: Computer law & security review, 2026-01-23 — https://overview.legal/posts/53843 — original: https://doi.org/10.1016/j.clsr.2025.106251*

As the General Data Protection Regulation (GDPR) approaches its tenth anniversary, the European legislator is considering reforms thereto. This article offers a set of research-based suggestions for what such reforms could look like, based on two assumptions. First, that the GDPR is overall a solid piece of legislation that upholds the enduring objectives and principles of data protection law. Second, that any improvement cannot compromise the level of protection of fundamental rights currently

### PROTECTION OF DATA SUBJECT RIGHTS IN THE TRANSFER OF PERSONAL DATA BETWEEN DATA CONTROLLERS IN INDONESIA: A COMPARATIVE ANALYSIS OF THE PDP LAW AND THE EU GDPR

*Source: Awang Long Law Review, 2026-01-16 — https://overview.legal/posts/132506 — original: https://doi.org/10.56301/awl.v8i2.1827*

The rapid digital transformation and growth of e-commerce in Indonesia have triggered a high volume of personal data transfers between controllers. while Article 55 of the Personal Data Protection Law (UU PDP) provides only a general authorization without clear technical guidance, creating legal uncertainty and risks to data subject rights. This study analyzes the legal uncertainty of UU PDP’s regulation of controller-to-controller data transfers compared to the EU GDPR and proposes an accountab

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities
- **International Transfer** — https://overview.legal/topics/internationale-doorgifte
  Transfer of personal data outside the EU/EEA

---
Generated by overview.legal · https://overview.legal/topics/social-media · 2026-08-22
