# Statistics — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/statistics
> Sources are cited per item. Verify against the official texts before relying on them.

Statistical purposes and statistical processing

## Overview

## Legal Framework

Statistical processing occupies a privileged position under the GDPR, but that privilege is conditional. [Article 5(1)(b)](/laws/gdpr/art-5#par-1-pnt-b) provides that further processing for statistical purposes "shall, in accordance with Article 89(1), not be considered to be incompatible with the initial purposes," while [Article 5(1)(e)](/laws/gdpr/art-5#par-1-pnt-e) permits longer storage periods for the same reason. Both exemptions hinge on compliance with Article 89(1), which requires appropriate safeguards for the rights and freedoms of data subjects — including data minimisation, pseudonymisation, and technical and organisational measures.

Where special categories of personal data are involved, [Article 9(2)(j)](/laws/gdpr/art-9#par-2-pnt-j) lifts the general prohibition on processing for statistical purposes, subject to Union or Member State law providing appropriate safeguards. Transparency obligations are also relaxed: under [Article 14(5)(b)](/laws/gdpr/art-14#par-5-pnt-b), the right to be informed does not apply where processing for statistical purposes makes provision of that information impossible or would involve disproportionate effort. The right to erasure is similarly limited — [Article 17(3)(d)](/laws/gdpr/art-17#par-3-pnt-d) exempts processing for statistical purposes under Article 89(1) where erasure would render impossible or seriously impair the achievement of those objectives.

## Key Developments

The CJEU's ruling in *Wirtschaftsakademie Schleswig-Holstein* established a critical principle for statistical processing: controllership is not negated by the fact that statistical output is anonymised. The Court held:

> "While the audience statistics compiled by Facebook are indeed transmitted to the fan page administrator only in anonymised form, it remains the case that the production of those statistics is based on the prior collection, by means of cookies installed by Facebook on the computers or other devices of visitors to that page"
> — [Wirtschaftsakademie ¶38](/posts/6135#seg-38)

This means that the collection and processing stages — not the final statistical output — determine responsibility and applicable obligations. Joint controllership can arise even where one operator never accesses identifiable data.

The earlier *Rynes* decision addressed the information exemption for statistical processing under Directive 95/46, the predecessor to Article 14(5)(b) GDPR. The Court confirmed that the exemption from providing information to data subjects applies specifically "for processing for statistical purposes or for the purposes of historical or scientific research" where provision of information proves impossible or disproportionate — a standard carried forward into the GDPR.

The EDPB has reinforced that anonymisation is the preferred endpoint:

> "Anonymisation is the preferred solution as soon as the purpose of the research can be achieved without the processing of personal data."
> — [EDPB Guidelines 05/2020 §160](/posts/38053#seg-160)

## Status of the Debate

This topic is actively contested in court. The boundaries of statistical processing — particularly what qualifies as a genuine statistical purpose versus a commercial analytics function — remain unsettled. Courts have diverged on whether web analytics and audience measurement constitute statistical processing under Article 89(1) or fall under general processing subject to full GDPR obligations. The *Wirtschaftsakademie* ruling narrowed the scope for avoiding controllership through anonymisation of outputs, but did not fully define the threshold for qualifying statistical purpose. What would resolve the open question is a CJEU reference addressing whether purely commercial statistical processing benefits from the Article 5(1)(b) and 17(3)(d) exemptions, or whether those provisions are reserved for public-interest or research-oriented statistics.

## Practical Guidance

- **Anchor statistical processing in Article 89(1) safeguards.** Implement data minimisation, pseudonymisation, and access controls from the outset. Document these measures — they are the legal condition for the purpose-limitation and storage-limitation exemptions under [Article 5(1)(b)](/laws/gdpr/art-5#par-1-pnt-b) and (e).

- **Plan for anonymisation as the terminal step.** Where statistical results can be achieved with anonymised data, the EDPB considers this the preferred solution. This eliminates further GDPR exposure but does not retroactively remove obligations from the collection and processing stages.

- **Do not assume anonymised output shields you from controllership.** Under *Wirtschaftsakademie*, the prior collection of personal data for statistical purposes triggers full responsibility, even if the final statistics are anonymised.

- **Assess erasure exemptions carefully.** [Article 17(3)(d)](/laws/gdpr/art-17#par-3-pnt-d) exempts statistical processing from the right to erasure only where erasure would "render impossible or seriously impair" the statistical objectives. This is a high threshold — document the impairment analysis.

- **Verify Member State law for special-category data.** [Article 9(2)(j)](/laws/gdpr/art-9#par-2-pnt-j) requires a basis in Union or Member State law with appropriate safeguards before processing health, biometric, or other special-category data for statistics.

## Legislation (full text of key provisions)

### Safeguards and derogations relating to processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes

*Source: GDPR, gdpr-art-89-en, 2016-04-27 — https://overview.legal/posts/91443*

### Recital 162 — statistical processing of personal data

*Source: GDPR, gdpr-rec-162-en, 2016-04-27 — https://overview.legal/posts/91839*

Where personal data are processed for statistical purposes, this Regulation should apply to that processing. Union or Member State law should, within the limits of this Regulation, determine statistical content, control of access, specifications for the processing of personal data for statistical purposes and appropriate measures to safeguard the rights and freedoms of the data subject and for ensuring statistical confidentiality. Statistical purposes mean any operation of collection and the processing of personal data necessary for statistical surveys or for the production of statistical results. Those statistical results may further be used for different purposes, including a scientific research purpose. The statistical purpose implies that the result of processing for statistical purposes is not personal data, but aggregate data, and that this result or the personal data are not used in support of measures or decisions regarding any particular natural person.

### Recital 163 — statistical confidentiality protection for official statistics

*Source: GDPR, gdpr-rec-163-en, 2016-04-27 — https://overview.legal/posts/91841*

The confidential information which the Union and national statistical authorities collect for the production of official European and official national statistics should be protected. European statistics should be developed, produced and disseminated in accordance with the statistical principles as set out in Article 338(2) TFEU, while national statistics should also comply with Member State law. Regulation (EC) No 223/2009 of the European Parliament and of the Council (16) provides further specifications on statistical confidentiality for European statistics.

### Recital 113 — non repetitive limited data transfers

*Source: GDPR, gdpr-rec-113-en, 2016-04-27 — https://overview.legal/posts/91741*

Transfers which can be qualified as not repetitive and that only concern a limited number of data subjects, could also be possible for the purposes of the compelling legitimate interests pursued by the controller, when those interests are not overridden by the interests or rights and freedoms of the data subject and when the controller has assessed all the circumstances surrounding the data transfer. The controller should give particular consideration to the nature of the personal data, the purpose and duration of the proposed processing operation or operations, as well as the situation in the country of origin, the third country and the country of final destination, and should provide suitable safeguards to protect fundamental rights and freedoms of natural persons with regard to the processing of their personal data. Such transfers should be possible only in residual cases where none of the other grounds for transfer are applicable. For scientific or historical research purposes or statistical purposes, the legitimate expectations of society for an increase of knowledge should be taken into consideration. The controller should inform the supervisory authority and the data subject about the transfer.

### Recital 156 — safeguards for archiving research processing

*Source: GDPR, gdpr-rec-156-en, 2016-04-27 — https://overview.legal/posts/91827*

The processing of personal data for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes should be subject to appropriate safeguards for the rights and freedoms of the data subject pursuant to this Regulation. Those safeguards should ensure that technical and organisational measures are in place in order to ensure, in particular, the principle of data minimisation. The further processing of personal data for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes is to be carried out when the controller has assessed the feasibility to fulfil those purposes by processing data which do not permit or no longer permit the identification of data subjects, provided that appropriate safeguards exist (such as, for instance, pseudonymisation of the data). Member States should provide for appropriate safeguards for the processing of personal data for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes. Member States should be authorised to provide, under specific conditions and subject to appropriate safeguards for data subjects, specifications and derogations with regard to the information requirements and rights to rectification, to erasure, to be forgotten, to restriction of processing, to data portability, and to object when processing personal data for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes. The conditions and safeguards in question may entail specific procedures for data subjects to exercise those rights if this is appropriate in the light of the purposes sought by the specific processing along with technical and organisational measures aimed at minimising the processing of personal data in pursuance of the proportionality and necessity principles. The processing of personal data for scientific purposes should also comply with other relevant legislation such as on clinical trials.

### Recital 50 — compatible further processing of personal data

*Source: GDPR, gdpr-rec-50-en, 2016-04-27 — https://overview.legal/posts/91615*

The processing of personal data for purposes other than those for which the personal data were initially collected should be allowed only where the processing is compatible with the purposes for which the personal data were initially collected. In such a case, no legal basis separate from that which allowed the collection of the personal data is required. If the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, Union or Member State law may determine and specify the tasks and purposes for which the further processing should be regarded as compatible and lawful. Further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes should be considered to be compatible lawful processing operations. The legal basis provided by Union or Member State law for the processing of personal data may also provide a legal basis for further processing. In order to ascertain whether a purpose of further processing is compatible with the purpose for which the personal data are initially collected, the controller, after having met all the requirements for the lawfulness of the original processing, should take into account, inter alia: any link between those purposes and the purposes of the intended further processing; the context in which the personal data have been collected, in particular the reasonable expectations of data subjects based on their relationship with the controller as to their further use; the nature of the personal data; the consequences of the intended further processing for data subjects; and the existence of appropriate safeguards in both the original and intended further processing operations. Where the data subject has given consent or the processing is based on Union or Member State law which constitutes a necessary and proportionate measure in a democratic society to safeguard, in particular, important objectives of general public interest, the controller should be allowed to further process the personal data irrespective of the compatibility of the purposes. In any case, the application of the principles set out in this Regulation and in particular the information of the data subject on those other purposes and on his or her rights including the right to object, should be ensured. Indicating possible criminal acts or threats to public security by the controller and transmitting the relevant personal data in individual cases or in several cases relating to the same criminal act or threats to public security to a competent authority should be regarded as being in the legitimate interest pursued by the controller. However, such transmission in the legitimate interest of the controller or further processing of personal data should be prohibited if the processing is not compatible with a legal, professional or other binding obligation of secrecy.

### Recital 52 — public interest special data processing exceptions

*Source: GDPR, gdpr-rec-52-en, 2016-04-27 — https://overview.legal/posts/91619*

Derogating from the prohibition on processing special categories of personal data should also be allowed when provided for in Union or Member State law and subject to suitable safeguards, so as to protect personal data and other fundamental rights, where it is in the public interest to do so, in particular processing personal data in the field of employment law, social protection law including pensions and for health security, monitoring and alert purposes, the prevention or control of communicable diseases and other serious threats to health. Such a derogation may be made for health purposes, including public health and the management of health-care services, especially in order to ensure the quality and cost-effectiveness of the procedures used for settling claims for benefits and services in the health insurance system, or for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes. A derogation should also allow the processing of such personal data where necessary for the establishment, exercise or defence of legal claims, whether in court proceedings or in an administrative or out-of-court procedure.

### Recital 53 — special health data processing conditions

*Source: GDPR, gdpr-rec-53-en, 2016-04-27 — https://overview.legal/posts/91621*

Special categories of personal data which merit higher protection should be processed for health-related purposes only where necessary to achieve those purposes for the benefit of natural persons and society as a whole, in particular in the context of the management of health or social care services and systems, including processing by the management and central national health authorities of such data for the purpose of quality control, management information and the general national and local supervision of the health or social care system, and ensuring continuity of health or social care and cross-border healthcare or health security, monitoring and alert purposes, or for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, based on Union or Member State law which has to meet an objective of public interest, as well as for studies conducted in the public interest in the area of public health. Therefore, this Regulation should provide for harmonised conditions for the processing of special categories of personal data concerning health, in respect of specific needs, in particular where the processing of such data is carried out for certain health-related purposes by persons subject to a legal obligation of professional secrecy. Union or Member State law should provide for specific and suitable measures so as to protect the fundamental rights and the personal data of natural persons. Member States should be allowed to maintain or introduce further conditions, including limitations, with regard to the processing of genetic data, biometric data or data concerning health. However, this should not hamper the free flow of personal data within the Union when those conditions apply to cross-border processing of such data.

### Recital 62 — exemptions from information provision obligation

*Source: GDPR, gdpr-rec-62-en, 2016-04-27 — https://overview.legal/posts/91639*

However, it is not necessary to impose the obligation to provide information where the data subject already possesses the information, where the recording or disclosure of the personal data is expressly laid down by law or where the provision of information to the data subject proves to be impossible or would involve a disproportionate effort. The latter could in particular be the case where processing is carried out for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes. In that regard, the number of data subjects, the age of the data and any appropriate safeguards adopted should be taken into consideration.

### Recital 65 — data subject rectification and erasure rights

*Source: GDPR, gdpr-rec-65-en, 2016-04-27 — https://overview.legal/posts/91645*

A data subject should have the right to have personal data concerning him or her rectified and a ‘right to be forgotten’ where the retention of such data infringes this Regulation or Union or Member State law to which the controller is subject. In particular, a data subject should have the right to have his or her personal data erased and no longer processed where the personal data are no longer necessary in relation to the purposes for which they are collected or otherwise processed, where a data subject has withdrawn his or her consent or objects to the processing of personal data concerning him or her, or where the processing of his or her personal data does not otherwise comply with this Regulation. That right is relevant in particular where the data subject has given his or her consent as a child and is not fully aware of the risks involved by the processing, and later wants to remove such personal data, especially on the internet. The data subject should be able to exercise that right notwithstanding the fact that he or she is no longer a child. However, the further retention of the personal data should be lawful where it is necessary, for exercising the right of freedom of expression and information, for compliance with a legal obligation, for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, on the grounds of public interest in the area of public health, for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, or for the establishment, exercise or defence of legal claims.

## Case law

### USR - Us I-755/2025-8

*Source: Administrative Court in Rijeka, 2025-11-11 — https://overview.legal/posts/49225 — original: https://gdprhub.eu/index.php?title=USR_-_Us_I-755/2025-8*

Facts — The data subject was a member of the management board of Zagrebački holding, a company owned by the City of Zagreb, from 3 September 2021 until 31 March 2023. A television broadcaster published several pieces, including a video on its YouTube channel, reporting on the data subject’s resignation. The publications mentioned his name, role, employer, salary, and information on the brand of his private car. The data subject filed a complaint with the Croatian Personal Data Protection Agency (AZOP), claiming that the publication constituted unlawful processing under the GDPR because the media lacked a valid legal basis under Article 6, the reporting was inaccurate and excessive, and it did not serve any genuine public interest. He latter further claimed during the lawsuit against AZOP's decision that the authority had incorrectly and incompletely established the facts, misapplied substantive law, and breached procedural rules. He emphasized that the published personal data was unrelated to transparency in public administration, that he was neither a public figure nor a political actor, and that any public interest ended once he left office on 31 March 2023. He invoked his right to erasure under Article 17 GDPR and sought removal of the content, annulment of AZOP’s decision, or alternatively, a remittal for a new procedure. AZOP contested the lawsuit in full, maintaining that it had acted in accordance with Article 34 of the Croatian GDPR Implementation Act and Article 77 GDPR. It argued that the publication fell within a justified public interest under Article 8 of the Croatian Media Act and that it had properly carried out a balancing test between privacy (Article 8 ECHR) and freedom of expression (Article 10 ECHR). According to AZOP, the reporting was necessary, proportionate, and not sensationalistic, and did not excessively intrude on the data subject’s privacy. It added that consent was not required because the processing relied on legitimate interest under Article 6(1)(f) GDPR. Holding — The Administrative Court dismissed the action and upheld AZOP’s decision. Because Zagrebački holding is a city-owned and publicly funded company, the court considered information about the data subject’s salary, compensation for using his private vehicle in official duties, and his managerial role to be directly connected to the use of public resources. This placed the publication within the legitimate public interest in transparency recognised by Article 8 of the Media Act. In its proportionality assessment, the court accepted AZOP's application of Article 5 and 6 GDPR, emphasizing that the published data did not touch upon the data subject’s family or intimate life but related solely to his public functions. Publication was therefore limited to what was necessary to inform the public about the management of a publicly owned company. The data subject’s claims that the publication was false or harmful to his reputation did not alter the outcome, as AZOP is not empowered to determine the truthfulness or tone of journalistic content, particularly under the journalistic exemption in Article 85 GDPR. Issues of accuracy or reputational harm must instead be pursued through media-law mechanisms such as requests for correction or civil actions. On the erasure request, the court held that the right to be forgotten under Article 17 GDPR cannot override freedom of expression and information where media reporting is involved. Although the data subject no longer served on the board, the publication continued to contribute to public understanding of how a major public entity was run during his tenure, thus the public interest persisted and erasure was not justified. Finally, the court reiterated that consent was not required because Article 6 GDPR offers alternative lawful bases for processing. Since Article 6(1)(f) was satisfied, the absence of consent was irrelevant. Concluding that AZOP had properly applied the law and that the interference with the data subject’s privacy was proportionate, the court upheld the decision and denied the data subject’s claim and costs.

### Meta Platforms and Others v Bundeskartellamt

*Source: CJEU, C-601/21, 2023-07-04 — https://overview.legal/posts/51482 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0601*

Competition authorities can assess GDPR compliance in context of competition law proceedings.

### HvJ EU 9 januari 2025, C‑394/23 (Mousse).

*Source: CJEU, 2025-01-09 — https://overview.legal/posts/50377 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0394*

HvJ EU 9 januari 2025, C‑394/23 (Mousse). Artikelen: 5(1)(c), 6(1), en 21 AVG Onderwerp : Beginsel van minimale gegevensverwerking Gek genoeg verwijst het HvJ EU zelf niet naar HvJ EU 1 augustus 2022, C‑184/20 (Vyriausioji tarnybinės etikos komisija), maar dat had hier ook heel logisch geweest.

### Judgment of the Court (Third Chamber) of 28 November 2024.#Nemzeti Adatvédelmi és Információszabadság Hatóság v UC.#Request for a preliminary ruling from the Kúria.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data and the free movement of such data – Regulation (EU) 2016/679 – Data processed when drawing up a COVID-19 certificate – Data not collected from the data subject – Information to be provided – Exception to the obligation t

*Source: Court of Justice of the European Union, C-169/23, 2024-11-28 — https://overview.legal/posts/132158 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0169*

In Case C-169/23, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Kúria (Hungary) concerning whether the Budapest Metropolitan Government Office, as controller issuing COVID-19 immunity certificates, was required to provide information to data subjects under Article 14 GDPR where the personal data was not collected directly from them. The Court held that data generated by the controller in the context of its own processes falls within the Article 14(5)(c) exemption from the obligation to provide information, provided that Member State law ensures appropriate measures to protect the data subject's legitimate interests, including data security measures under Article 32. The Court also confirmed that supervisory authorities retain competence to handle complaints under Article 77(1) even where the Article 14(5)(c) exemption applies.

### Judgment of the Court (First Chamber) of 20 October 2022.#Digi Távközlési és Szolgáltató Kft. v Nemzeti Adatvédelmi és Információszabadság Hatóság.#Request for a preliminary ruling from the Fővárosi Törvényszék.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 5(1)(b) and (e) – Principle of ‘purpose limitation’ – Principle of ‘storage limitation’ – Creation, from an existing database, of a datab

*Source: Court of Justice of the European Union, C-77/21, 2022-10-20 — https://overview.legal/posts/132306 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0077*

In this preliminary ruling, the CJEU interpreted Articles 5(1)(b) and 5(1)(e) GDPR in proceedings between Digi Távközlési és Szolgáltató Kft. and the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) concerning a personal data breach. The Court held that creating a new database from an existing one for testing and error-correction purposes constitutes further processing requiring compatibility assessment under the purpose limitation principle, and that the storage limitation principle applies such that data must be deleted once the testing purpose is fulfilled. No fine was imposed at the EU level, as the matter was remitted to the referring Hungarian court.

### Judgment of the Court (Fifth Chamber) of 24 February 2022.#SIA 'SS' v Valsts ieņēmumu dienests.#Request for a preliminary ruling from the Administratīvā apgabaltiesa.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 2 – Scope – Article 4 – Concept of ‘processing’ – Article 5 – Principles relating to processing – Purpose limitation – Data minimisation – Article 6 – Lawfulness of processing – Proc

*Source: Court of Justice of the European Union, C-175/20, 2022-02-24 — https://overview.legal/posts/132316 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62020CJ0175*

In Case C-175/20, the Court of Justice of the EU interpreted GDPR Articles 5 and 6 in response to a preliminary ruling from the Latvian Regional Administrative Court concerning a request by the Latvian State Tax Authority for SIA 'SS' to disclose personal data from online vehicle sale advertisements for tax enforcement purposes. The Court held that national law may require controllers to provide personal data to tax authorities under Article 6(1)(c) and (e), provided the request complies with data minimisation and purpose limitation principles, meaning authorities must limit requests to what is necessary and proportionate for the specific tax investigation. No fine was imposed as this was a preliminary ruling proceeding.

### CJEU - C-439/19 - Latvijas Republikas Saeima (Penalty points)

*Source: GDPRhub, C-439/19, 2021-06-22 — https://overview.legal/posts/108995 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-439/19_-_Latvijas_Republikas_Saeima_(Penalty_points)*

Facts — An individual lodged a constitutional complaint reference on the national Law on Road Traffic is consistent with the fundamental right to respect for private life. The individual’s legal interest was grounded to the imposition of penalty points after some road traffic offences. These points were entered in the national register of vehicles and drivers. Moreover, any company and any third person may obtain information relating to penalty points imposed on another person, either by enquiring directly at the CSDD or by using the services provided by commercial re-users. The relative Article 14(1)(2) of national law was stated that “Information relating […] to fines for the commission of road traffic offences which have been imposed on a person […] shall be regarded as information in the public domain”. Latvian Parliament intended to improve road safety through each driver who infringes traffic regulations, particularly those disregarding them systematically, be openly identified. The only requirement for disclosure of the information, which contained in the national register of vehicles and their drivers, was subject to the condition that the information seeker must provide the national identification number of the drivers about whom they wish to enquire. The CSDD handles the National Register, and they insisted that they transfer the legal ownership of the transmitted data under no circumstances. So, the re-users should use these data only to deduce the seriousness and frequency of those offences and ascertain whether a given person has committed road traffic offences. Since penalty points were classified as public data, may be re-used for commercial or non-commercial purposes other than the initial purpose for which the information was collected. However, article 14(1)(2) of the Road Traffic National Act does not impose limits on the re-use of these data relating to penalty points. Under the contracts in which CSDD concludes with commercial re-users, the acquirer affirms that it will use the information obtained in accordance with the purposes indicated in the contract and in compliance with the legislation in force. Therefore, it cannot be ruled out if any possible processing is inappropriate or disproportionate. It should be well-known to everyone that the GDPR provides enhanced protection to sensitive data. Article 10 of the GDPR refers to these data collections which are capable to give rise to social disapproval. The at-issue grant of data access is liable to stigmatise the data subject, and thereby, it is possible to constitute a serious interference with his or her private or professional life. The referring national Court also asked CJEU whether the provisions of the GDPR must be interpreted as precluding national legislation which obliges the public body responsible for the register to disclose those data to any person who requests them, without that person having to establish a specific interest in obtaining the data. Dispute — Since information relating to penalty points can be communicated upon request and transmitted for re-use to several companies, an individual filed a constitutional complaint challenging the conformity of the Act on Road Traffic with the right to privacy set out in the Latvian Constitution. Because the Latvian Parliament adopted the National Law on Road Traffic, that institution participated in the proceedings. The CSDD, which processes the data at issue, was also heard. In addition, the National Data Protection Authority, Latvia) was also invited to give their opinion as amici curiae before the referring Court. The Latvian Parliament explained that, in practice, disclosure of the information contained in the national register of vehicles and their drivers is subject to the condition that the person requesting the information must provide the national identification number of the driver about whom he or she wishes to enquire. Moreover, the CSDD pointed out that the Law on Road Traffic does not impose limits on either public access to or re-use of data relating to penalty points. As regards that they do not provide the legal transfer of the data; re-users must ensure by themselves that the information transmitted does not exceed the initial purpose for which the information was collected. However, the National Data Protection Authority expressed its doubts about whether the Law on Road Traffic is consistent with the Latvian Constitution, which lays down the right to respect for private life. In its view, the importance and the objective of the processing carried out on the basis of the provision at issue in the main proceedings are not clearly established, and it cannot, therefore, be ruled out that processing is inappropriate or disproportionate. The National Parliament considers that the provision at issue is lawful because it is justified by the objective of improving road safety, which requires that traffic offenders be openly identified and that drivers be deterred from committing offences. Also, the Right of Access to Information, which was directly included in the National Constitution, should be respected. The CSDD explained to the referring Court the functioning of the penalty points system and confirmed that the national legislation does not impose any limits on public access to and on the re-use of data relating to penalty points. Also, it pointed out that these contracts do not provide for the legal transfer of data, and these re-users shall ensure that the information transmitted to their customers does not exceed that which can be obtained from the CSDD. For example, one of the contractual terms stipulates that the acquirer of the information must use it in the manner laid down in the regulations in force and in accordance with the purposes indicated in the contract. The National Data Protection Authority was in the position to observed that, Latvia’s statistics on traffic accidents, although showing a decrease in the number of accidents, there is no proof that the penalty points system and public access to information relating to it have contributed to that favourable development. So did not rule out the possibility that the data processing at issue may be inappropriate or disproportionate. First of all, this CJEU’s proceedings do not concern the Law on Road Traffic in its entirety, but only in so far as that provision makes information relating to penalty points entered in the national vehicle register accessible to the public. That Court further considers that penalty points are personal data and must therefore be processed in accordance with the right to respect for private life. It emphasises that in assessing the scope of Article 96 of the Latvian Constitution, an account must be taken of the GDPR as well as of Article 16 TFEU and Article 8 of the Charter of Fundamental Rights of the European Union. Holding — The CJEU highlighted that the term offence refers exclusively to criminal offence and that the term remains an autonomous concept of EU law. That means that it is not decisive if an offence is classified as an administrative offence in a national legal system. In determining whether an offence qualify as criminal offence we have to recall the three Engel criteria, namely (a) the legal classification of the offence under national law; (b) the nature of the offence; and (c) the degree of severity of the penalty incurred, the objective pursued by that provision. The EU Grand Chamber first took note that a traffic offence is liable to give rise to penalties of a certain severity and those points have legal consequences which may even extend to a driving ban or to constitute a serious interference with the fundamental rights to respect for private life and to the protection of personal data, since it may give rise to social disapproval and result in stigmatisation of the data subject. Furthermore, it was asserted that disclosure of the National Road Traffic Act broadly falls within the material scope of the GDPR, and no exception is applicable. Article 2(2)(a) and (b) of the GDPR represents partly a continuation of the first indent of Article 3(2) of Directive 95/46. Therefore, the provisions of the GDPR shall not be interpreted in broader terms the Titles V and VI of the EU Treaty/Treaty of Lisbon and, in any case, border than the area of public security, defence, and State security. The Court held that the GDPR also precludes the Latvian Parliament from authoring the CSDD to disclose penalty points to economic operators in order for the data to be re-used for commercial or non-commercial purposes. Court consideration was the public disclosure and re-use of information under the view of Article 5 of the GDPR and more broadly lawful in light of the proportionality principle. The Court held that the Latvian Act goes beyond what is necessary to improve road safety as there are other less restrictive methods to achieve that objective. For example, by depriving the drivers of the right to drive a vehicle, a ban whose breach may be punished by effective sentences without public disclosure is necessary. The penalty points system aims to influence the conduct of road users by distinguishing vehicle drivers who, systematically and in bad faith, disregard road traffic rules from drivers who occasionally commit offences. However, the lack of any further condition to obtain access may result in the data being disclosed for reasons unrelated to the objective of general interest of improving road safety.

### GC and Others v CNIL

*Source: CJEU, C-136/17, 2019-09-24 — https://overview.legal/posts/51475 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62017CJ0136*

Conditions for delisting sensitive data from search results.

### VOLKER UND MARKUS SCHECKE GBR V. LAND HESSEN, EIFERT V. LAND HESSEN AND BUNDESANSTALT FUR LANDWIRTSCHAFT UND ERNAHRUNG, 9.Nov.2010 (“SCHECKE”)

*Source: CJEU, 2010-11-09 — https://overview.legal/posts/6180 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62009CJ0092&ref=6180*

Purpose for processing: The legislation at issue does base the processing on consent. Rather, it provides that they are to be informed. Thus, processing is not based on their consent. (¶ 54)

### NSS - 1 As 183/2023-62

*Source: Supreme Administrative Court, 2026-08-04 — https://overview.legal/posts/184683 — original: https://gdprhub.eu/index.php?title=NSS_-_1_As_183/2023-62*

Facts — OAKS Consulting s.r.o. (the company) provided consulting services concerning market access conditions for medicinal products and medical devices. Pursuant to the Czech Act on Free Access to Information, it requested information from the General Health Insurance Company of the Czech Republic concerning the treatment of patients with iron deficiency and related conditions for the period from 1 January 2010 to 31 October 2017. The request covered 183 types of diagnoses, 18 types of medical procedures, 96 DRG codes and 13 types of medications. The company stated that it wished to analyse how specific diagnoses were treated, the number of patients treated, and the frequency of related medical procedures, in order to compare clinical practice against the relevant theoretical background. The public health insurer rejected the request on the grounds that granting it would require the creation of new information. Following an appeal by the company, the Prague Municipal Court overturned the decision. The public health insurer provided then the company with five separate tables regarding the diagnoses, diagnoses in conjunction with medical procedures, the DRG codes and prescribed medications. It aggregated the parameters of the provided data as follows: five-year age groups, dates were given only at the monthly level, and healthcare providers were classified into broad geographic regions. However, it refused to add a unique random identifier which would allow linking the individual records and tables pertaining to the same patient. The public health insurer considered that providing the code would result in the disclosure of special categories of personal data. The company lodged a complaint with the Czech DPA (UOOU), which rejected it. The company filed another appeal with the Municipal Court of Prague, which dismissed the appeal. It ruled that the combination of factors such as gender, year of birth, the time and place of care, diagnoses, medications, and medical procedures could, with the addition of other information, lead to the identification of specific patients. According to the court, the random identifier would result in pseudonymisation rather than anonymisation, so the information would remain personal data pursuant to Article 4(1) GDPR. The Municipal Court also relied on modern technical capabilities for linking different sources and on the availability of a large volume of information in the media and on social media. It cited the CJEU’s decision in the Breyer case (C-582/14), according to which in order to determine whether a person is identifiable, account must be taken of all the means that could reasonably be used, both by the controller and by any other person, to identify that person. It did not follow the approach taken by the General Court in Case T-557/20 (SRB v. EDPS), which the company had cited. It ruled that the data were pseudonymised and that the requested information could not be disclosed in its entirety. The company filed a cassation appeal with the Supreme Administrative Court, arguing that the information had been anonymised. It alleged that the addition of a random code with no independent meaning would not alter their anonymous nature. It claimed that the Municipal Court had not explained what specific additional information could be used to identify the patients and had relied on hypothetical scenarios. The company stated that it was objectively impossible to obtain such data through other requests in a detailed and non-aggregated form. It also argued that iron deficiency was not a rare disease, but was associated with a large number of patients and various conditions and that the data had undergone both randomisation and generalisation so the risk of identification was therefore low. Finally, the company emphasized that the tables without the random identifier could not be used effectively for the intended analysis. It further argued that the DPA and the Municipal Court had not adequately balanced the right of access to information against the right to the protection of personal data. The DPA argued that the random identifier constituted personal data when considered in conjunction with the health data to which it would be linked. It stated that the concept of personal data was not limited to information that directly identifies an individual nor did it require that all necessary additional information be held by the same entity. Replacing direct identifiers with a code did not anonymise the data, but made it pseudonymised. Moreover, it argued that certain categories contained a relatively small number of records and that combining them with other data could make it possible to select and identify a specific insured person and their treatment history. It further argued that, even if identifiability was relative, it should be assessed in relation to all potential information applicants and their ability to obtain contextual information. The Supreme Administrative Court stayed the proceedings in the case pending the CJEU’s decision in Case C-413/23 P (EDPS v. SRB). After the judgment was issued, the company argued that whether the data were pseudonymised or anonymised should be assessed in relation to the specific recipient of the data and the means that it could reasonably use. It stated that it did not have any means of re-identification and that only specific and practically available cross-referencing possibilities should be taken into account. Holding — The court relied on Case C-413/23 and noted that pseudonymised data under Article 4(5) GDPR does not automatically constitute personal data in relation to every person. Therefore, it examined whether the company had lawful means that could reasonably be expected to be used to identify the patients directly or indirectly. The court found that the tables, without the random identifier, did not allow for the identification of specific insured individuals. It held that the requested random identifier would link the records from the different tables and allow for the aggregation of information on the diagnoses, medical procedures, hospitalizations, and medications for the same patient during the eight-year period. Certain combinations of these data, along with age group, gender, and region, could be unique and allow for the identification of patients using information from public sources. It pointed out that although iron deficiency was a very common diagnosis and some tables contained a very large number of entries, other categories were not sufficiently generalised. According to the court, in certain cases, such as rare diseases, unusual treatment combinations, or particularly young or old age, knowing even a few details about a person could make it possible to identify the corresponding record. The risk was not negligible, given that information about a person’s age, gender, hospitalization, diagnosis, or treatment could be available in the media or on social media. Consequently, the court held that adding the random identifier, in conjunction with the data already provided, would make the dataset personal data in relation to the company under Article 4(1) GDPR, including health data falling under Article 9 GDPR. The court clarified that classifying the information as personal data was not sufficient in itself to reject the request. It noted that the right of access to the information must also be balanced against patients’ right to privacy through an assessment of suitability, necessity and proportionality. It determined that the decision not to provide the random identifier was appropriate for the protection of privacy, because without it, it was impossible to link the tables and identify individual patients. It was also deemed necessary because the company insisted on receiving that specific code along with the existing tables and there was no other procedure that would constitute a lesser infringement of its right to information. The court also recognized the public interest in accessing information related to the operation of the healthcare system, but ruled that this did not outweigh the need to protect the detailed health data of potentially hundreds of thousands of insured individuals. It concluded that the refusal to provide the code was therefore proportionate. The Supreme Administrative Court therefore upheld the Municipal Court’s ruling, but partially corrected its reasoning regarding the relative nature of identifiability and the need to conduct a proportionality review. It dismissed the appeal.

### Judgment of the Court (Third Chamber) of 11 January 2024.#État belge v Autorité de protection des données.#Request for a preliminary ruling from the cour d'appel de Bruxelles.#Reference for a preliminary ruling – Approximation of laws – Protection of natural persons with regard to the processing of personal data and free movement of such data (General Data Protection Regulation) – Regulation (EU) 2016/679 – Point 7 of Article 4 – Concept of ‘controller’ – Official journal of a Member State – Obl

*Source: Court of Justice of the European Union, C-231/22, 2024-01-11 — https://overview.legal/posts/132274 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0231*

In Case C-231/22, the Court of Justice of the European Union interpreted Article 4(7) and Article 5(2) of the GDPR in response to a preliminary reference from the Brussels Court of Appeal in proceedings between the Belgian State and the Belgian Data Protection Authority concerning whether the managing authority of the Moniteur belge (Belgium's official journal) constitutes a "controller" under the GDPR. The central issue was whether a Member State authority that is legally obligated to publish company documents containing personal data, as prepared and submitted by third parties, determines the purposes and means of processing within the meaning of Article 4(7). The Court held that such an authority does qualify as a controller because, by disseminating the personal data to the public, it determines the means of making the data accessible and exercises autonomous control over that processing operation, even though it does not determine the content of the published documents; no fine was at issue in this preliminary ruling.

### HvJ EU: Privacy Shield ongeldig verklaard (Schrems II)

*Source: Hof van Justitie EU, 2020-07-16 — https://overview.legal/posts/1 — original: https://eur-lex.europa.eu/legal-content/NL/TXT/?uri=CELEX:62018CJ0311*

Het Hof van Justitie verklaart het Privacy Shield-akkoord ongeldig wegens onvoldoende waarborgen voor Europese burgers tegen toegang door Amerikaanse inlichtingendiensten.

## Guidance

### Opinion 3/2019 concerning the Questions and Answers on the interplay between the Clinical Trials Regulation (CTR) and the General Data Protection regulation (GDPR)

*Source: EDPB, opinion-32019-concerning-the-questions-and-answers-on-the-interplay-en, 2019-01-23 — https://overview.legal/posts/126252 — original: https://www.edpb.europa.eu/documents/legislative-opinion/opinion-32019-concerning-the-questions-and-answers-on-the-interplay_en*

1 Opinion 3/ 2 019 c oncerning the Questions and Answers on the interplay between the Clinical Trials Regulation (CTR) and the General Data Protection regulation (GDPR) (art. 70. 1. b)) Adopted on 23 January 2019 2 3 The European Data Protection Board Having regard to Article 70.1.b of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data,…

### EDPB-EDPS Joint Opinion 03/2022 on the Proposal for a Regulation on the European Health Data Space

*Source: EDPB, edpb-edps-joint-opinion-032022-on-the-proposal-for-a-regulation-on-en, 2022-07-12 — https://overview.legal/posts/125922 — original: https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-032022-on-the-proposal-for-a-regulation-on_en*

Adopted 1 EDPB - EDPS Joint Opinion 03 /2022 on the Proposal for a Regulation on the European Health Data Space Adopted on 12 July 2022 Adopted 2 Adopted 3 Executive Summary With this Joint Opinion, the EDPB and the EDPS aim to draw attention to a number of overarching concerns on the Proposal on the European Health Data Space and urge the co - legislature to take decisive action. The EDPB and the EDPS note that the Proposal ai ms at supporting individuals to take control of their own health…

### Statement 05/2021 on the Data Governance Act in light of the legislative developments

*Source: EDPB, statement-052021-on-the-data-governance-act-in-light-of-en, 2021-05-20 — https://overview.legal/posts/126024 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-052021-on-the-data-governance-act-in-light-of_en*

1 Statement 05/2021 on the Data Governance Act in light of the legislative developments Adopted on 19 May 2021 The European Data Protection Board has adopted the following statement: On 9 March 2021 the EDPS and the EDPB adopted the Joint Opinion on the Proposal for a Data Governance Act (DGA) 1 , which has also been presented at the European Parliament at the hearing of the LIBE Committee of 16 March 2021 2 . The EDPB is closely followin g the work of the co - legislators on this important…

### EDPB-EDPS Joint Opinion 03/2021 on the Proposal for a regulation of the European Parliament and of the Council on European data governance (Data Governance Act)

*Source: EDPB, edpb-edps-joint-opinion-032021-on-the-proposal-for-a-regulation-of-en, 2021-03-11 — https://overview.legal/posts/126050 — original: https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-032021-on-the-proposal-for-a-regulation-of_en*

1 Adopted EDPB - EDPS Joint Opinion 03 /2021 on the Proposal for a regulation of the European Parliament and of the Coun cil on European data governance (Data Governance Act) Version 1.1 2 Adopted Version history Version 1.1 09 June 2021 Minor editorial changes Version 1.0 10 March 2021 Adoption of the Joint Opinion 3 Adopted 5 Adopted The European Data Protection Board and the European Data Protection Supervisor Having regard to Article 42(2) of the Regulation 2018/1725 of 23 October 2018 on…

### Statement 03/2021 on the ePrivacy Regulation

*Source: EDPB, statement-032021-on-the-eprivacy-regulation-en, 2021-03-09 — https://overview.legal/posts/126052 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-032021-on-the-eprivacy-regulation_en*

1 Statement 03/2021 on the ePrivacy Regulation Adopted on 9 March 2021 The European Data Protection Board has adopted the following statement: The EDPB welcomes the agreed negotiati on mandate adopted by the Council on the protection of privacy and confidentiality in the use of electronic communication services ( ’ the Council ’s position ’ ) , as a positive step towards a new ePrivacy Regulation . It is of utmost importance that the EU gen eral data protection framework is rapidly complemented…

### Guidelines 5/2019 on the criteria of the Right to be Forgotten in the search engines cases under the GDPR (part 1)

*Source: EDPB, edpb-guidelines-on-the-criteria-of-the-right-to-be-forgotten-in-the-search-engines-cases-under-th, 2020-07-07 — https://overview.legal/posts/38070 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-52019-on-the-criteria-of-the-right-to-be-forgotten-in-the-search_en*

The European Data Protection Board (EDPB) issued these guidelines to clarify the criteria and grounds for exercising the right to erasure (right to be forgotten) specifically in the context of search engine cases under the GDPR. The document details the six grounds under Article 17(1) that allow data subjects to request delisting, alongside the relevant exceptions, such as the right to freedom of expression and information. As a guidance instrument, it does not impose administrative fines but instead aims to harmonize how search engine providers handle and balance delisting requests across the EU.

### Guidelines 2/2020 on articles 46 (2) (a) and 46 (3) (b) of Regulation 2016/679 for transfers of personal data between EEA and non-EEA public authorities and bodies

*Source: EDPB, guidelines-22020-on-articles-46-2-a-and-46-3-b-of-regulation-2016679-for-en, 2020-12-15 — https://overview.legal/posts/126098 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-22020-on-articles-46-2-a-and-46-3-b-of-regulation-2016679-for_en*

Adopted 1 Guidelines 2/2020 on a rticles 46 (2) (a) and 46 (3) (b) of Regulation 2016/679 for transfers of personal data between EEA and non - EEA public authorities and bodies Version 2 .0 Adopted on 1 5 December 2020 Adopted 2 Version history Version 2.0 15 December 2020 Adoption of the Guidelines after public consultation Version 1.0 18 February 2020 Adoption of the Guidelines for public consulation Adopted 3 Adopted 4 The European Data Protection Board Having regard to Article 70 (1e) of…

### Report on stakeholder event on anonymisation and pseudonymisation of 12 December 2025

*Source: EDPB, report-on-stakeholder-event-on-anonymisation-and-en, 2026-02-18 — https://overview.legal/posts/125688 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/report-on-stakeholder-event-on-anonymisation-and_en*

Report on stakeholder event on anonymisation and pseudonymisation of 12 December 2025 1. Background The EDPB organise d a remote stakeholder event on 12 December 2025 to collect stakeholders’ input on anonymisation and pseudonymisation , following the Court of Justice of the European Union ( “ CJEU ” ) judgment in case EDPS v SRB 1 . The objective was to engage with stakeholders to inform the EDPB’s ongoing work on its guidelines 01/2025 on pseudonymisation and f orthcoming guidelines on…

## Enforcement decisions

### APD/GBA (Belgium) - 115/2022

*Source: APD/GBA (Belgium), 2022-07-19 — https://overview.legal/posts/6317 — original: https://gdprhub.eu/index.php?title=APD/GBA_(Belgium)_-_115/2022*

Facts — During a meeting where the data subject was not present, the data subject's manager (controller) announced her departure and read out a document issued by the company doctor, stating that she was unfit to work and would leave the company. This statement was also included in the minutes of that meeting. When the data subject discovered this, she filed a complaint against the controller with the Belgian DPA for unlawfully disclosing health related personal data to third parties. She added that the minutes were then saved on the controller´s server, freely accessible to all its staff, including from other departments. Holding — The DPA noted that the data subject did not dispute the lawfulness of processing of the information that she was unfit to work, but the subsequent communication about her health to her colleagues and other staff members. The DPA noted that it was not able to verify whether the minutes were actually made available on the controller's server. However if that were the case, this would amount to an additional processing activity and the following findings of the infringement also apply. The DPA first assessed whether the further processing was compatible with the purpose of the original processing (Article 5(1)(b) GDPR). It found that the purpose of the original processing was personnel management. The DPA held that the data subject could not reasonably expect that the same data would be communicated widely beyond the persons authorised for personnel management. Especially considering the sensitive nature of the data. Therefore the DPA held that the further processing was incompatible with the purpose of the original processing. As the further processing was incompatible with the purpose of the original processing, the DPA noted that it could only be lawful if it had its own legal basis pursuant to Article 9(2) juncto Article 6(1). However the DPA found that this was also not present. Therefore, the DPA held that the controller did not have a proper legal basis for processing the data subject's health related data and thereby violated Article 5(1)(b) juncto Article 6(4) and Article 9(2). The DPA issued a reprimand against the controller. The DPA noted that it was not competent to issue a fine as the controller was a public authority.

### HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens

*Source: HDPA (Greece), 2026-05-13 — https://overview.legal/posts/144044 — original: https://gdprhub.eu/index.php?title=HDPA_(Greece)_-_12/2026*

Facts — The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of Undesirable Aliens. In response to the Authority's request for clarifications, the competent Directorate of the Ministry of Citizen Protection informed the DPA that: • By a decision dated 27-07-2017, an entry ban and registration in the National Registry of Undesirable Aliens were imposed on the complainant for reasons of national security. • Following temporary 48-hour lifts of the measure for humanitarian reasons in 2019, the entry ban was re-imposed. • Subsequent decisions in 2020, 2023, and 2025 maintained the entry ban and renewed his registration in the National Registry of Undesirable Aliens for successive three-year periods, as the grounds for registration remained active. • The explicit grounds and documentation behind the registration were not disclosed to the complainant because the competent Directorate classified the file as restricted/classified service material. The complainant and his attorney attended a DPA hearing on 22-04-2026, arguing that the registration lacked specific, adequate, or definitive justification regarding any threat to public order or national security. They noted that the complainant has no criminal convictions, poses no threat, and possesses strong ties, residency, and business operations in the region of Northern Epirus and Greece, meaning the entry ban severely disrupts his professional and family life. Holding — According to the provisions of Article 82(1) of Law 3386/2005, foreign nationals whose presence in Greek territory constitutes a threat to national security, public safety, or public order can be registered in the National Registry of Undesirable Aliens, with registrations subject to an ex officio review every three years. Furthermore, pursuant to the provisions of Article 54(2) and Article 55(4) of Law 4624/2019 (the Greek law implementing the GDPR), the data controller is legally empowered to restrict or omit the provision of information and to deny a data subject access to their personal data when dictated by reasons of national security or public order. These national provisions are explicitly anchored in Article 23 GDPR (specifically Article 23(1)(a)GDPR and Article 23(1)(c) GDPR), which permits Member State law to restrict the scope of the obligations and data subject rights (such as the right to be informed under Article 13 GDPR - Article 14 GDPR and the right of access under Article 15 GDPR) to safeguard national security and public security. In the present case, the evidence demonstrated that the complainant's initial registration and subsequent renewals in the National Registry of Undesirable Aliens were executed lawfully for reasons of national security. The Ministry of Citizen Protection, acting as the data controller, exercised its legal discretion under these frameworks to weigh these interests and correctly determined that the underlying operational decision constitutes classified material that cannot be disclosed to the data subject. Consequently, the fundamental principles of data protection law were not breached, and the Hellenic DPA rejected the complaint as unfounded.

### APD/GBA (Belgium) - 85/2022

*Source: APD/GBA (Belgium), 2022-05-25 — https://overview.legal/posts/122843 — original: https://gdprhub.eu/index.php?title=APD/GBA_(Belgium)_-_85/2022*

Facts — On 16 January 2019, the Executive-committee of the Belgian DPA (GBA) started an investigation on the use of cookies on Belgian media websites. The controller in this case is Roularta Media Group. The investigation revealed the following potential violations. First, the placement of unnecessary cookies prior to consent of the data subject. Second, the placement of statistical cookies without consent. Third, pre-ticked boxes to grant consent for cookies from partners. Fourth, the placement of a disclaimer for third-party cookies. Fifth, false and inadequate information in their privacy policy. Sixth, unjustified retention periods for the storage of cookies. Lastly, revoking consent was impossible. In fact, this placed more cookies. The controller argued that statistical cookies are used for aggregated basic statistics, necessary for the business model of the website. No personal data is being processed for this activity, as such, the GDPR does not apply. The controller argued that regarding the statistical cookies, the personal data was anonymised. The controller further argued that the Belgian DPA did not provide adequate guidelines for companies to comply with the GDPR. The controller refers to e.g. the French and Dutch DPA, who have provided this. Holding — Regarding the placement of cookies, the DPA first noted that cookies can only be placed without prior consent when they are (1) strictly necessary for the transmission of communication or (2) to provide a service that is explicitly requested by the user. The DPA held that the controller violated Article 6(1)(a) and Article 5(3) ePrivacy Directive 2002/58/EC, as some of the cookies placed without prior consent were found to be not strictly necessary. The controller even admitted to the placement of unnecessary cookies without obtaining prior consent. Regarding the placement of statistical cookies in particular, the DPA noted - with reference to her decision in 12/2019 - that these also require prior consent. The DPA observed that the placement and reading of these cookies on the terminal equipment of users revealed their IP-addresses to the controller. The DPA disregarded the defence of the controller that the IP-addresses were anonymised, and found that they were instead pseudonimised. This makes the data subjects indirectly identifiable and thus the GDPR applicable. The DPA therefore held that the controller violated Article 6(1)(a) and Article 5(3) ePrivacy Directive 2002/58/EC by not obtaining prior consent. Regarding the pre-ticked boxes for the cookies from partner companies, the DPA argued that this cannot constitute lawful consent by the definition of Article 4(11) (and with reference to Planet49). The DPA thus found another violation of Article 6(1)(a). The DPA held that regarding the disclaimer placed on their website for third-party cookies, the controller violated the principle of accountability laid down in Article 5(2). The DPA stated that controllers are responsible for compliance with the GDPR and the demonstration thereof (Article 24). The DPA found that the privacy policy of the controller contained false, incomplete and insufficient information. The DPA therefore held that the controller violated Article 12(1), as it did not communicate the information referred to in of Article 13 and Article 14 in a "concise, transparent, intelligible and easily accessible form". The DPA furthermore held that the controller violated the principle of storage limitation laid down in Article 5(1)(e) by not proactively defining the criteria for the storage of cookies. Lastly, the DPA found that the controller violated Article 7(3), as withdrawing consent was made impossible by the controllers cookie-management tool. The DPA noted that withdrawing consent must be as easy as providing consent for users. The DPA found that the alleged absence of concrete guidelines is not a valid argument against a violation of data protection legislation. The DPA held that it is the responsibility of the controller to comply with the law and further noted that numerous guidelines for companies to ensure compliance with the GDPR already exist. The DPA fined the controller €50.000. The DPA further ordered the controller to get its processing of personal data - for which a violation was established - in compliance with the GDPR within 3 months.

### Datatilsynet (Denmark) - 2020-422-0026

*Source: Datatilsynet (Denmark), 2022-09-28 — https://overview.legal/posts/6312 — original: https://gdprhub.eu/index.php?title=Datatilsynet_(Denmark)_-_2020-422-0026*

Facts — The Danish DPA had decided to investigate three research projects of Region Syddanmark (the controller) with regards to its processing activities, the use of processors, data processing agreements and processor audit practices. Holding — The DPA first held that, based on the information provided by the controller, there were no indications that the controller's assessment of the legal bases for the processing were incorrect. The DPA then held that the use of processors had been lawful and that the relevant data processing agreements satisfied the requirements of Article 28 GDPR. However, the DPA reprimanded the controller, partly for its lack of clear auditing procedures, and partly for not actually conducting audits in line with the routines that did exist. The DPA held that the accountability principle in Article 5 GDPR entails an obligation for the controller to oversee the security of the data processing operations performed by a processor. The DPA highlighted that entering into a data processing agreement that contains security obligations is not sufficient, and that the controller must also oversee that the processor actually adheres to the agreement. The fact that the controller had auditing procedures in place was not good enough if these auditing procedures were not being followed in practice.

### AEPD investigates University of Navarra over student COVID-19 vaccination status requests

*Source: AEPD (Spain), 2026-07-16 — https://overview.legal/posts/122842 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_EXP202102529*

Facts — A student handed in a complaint against the University of Navarra because they asked the students to fill in their vaccination status. The complainant understands this as a breach of the data protection regulation because it would access the students medical records. The grounds are based on an e-mail from the University of Navarra, in which it announces to collaborate with the Navarro Health Service in the Vaccination against COVID-19 and it asks the students to inform about their vaccination status. On October 26, 2021 the University of Navarra replied to the complaint that the students were not coerced to give the information, but they were given the possibility to do so. The University does not process the personal data of the students without their explicit consent. The consent would in no case be vitiated since no condition has been established that could nullify the correct will of the interested party to the processing. There is no measure contrary to the interests of those students who do not provide the information freely and voluntarily. The sole purpose of the communication made is to comply with the objective of the collaboration agreement reached with the Government of Navarra by virtue of the actions taken in its place against SARS-CoV-2 pandemic. The complaint filed was admitted for processing on November 24, 2021 in Accordance with Article 65 of the LOPDGDD. The collaboration was known to the public. There is a press release stating the fact that the University of Navarra should communicate the list of persons who are to receive the vaccine so that their identity can be recorded in the health databases. This is in compliance with a legal obligation in terms of prevention of legal risks. This is due to the severity of the pandemic. The form for acceptance of the data processing states that the compliance with the form is voluntary. The first field of the form is the request for consent. Furthermore it is added that the information provided will not be communicated to third parties unless the health authorities require it. This clause can also be accepted. Holding — The Court does not consider that there is a violation of the provisions of the regulation in force regarding protection, and there is no substantive issue to support such an allegation. In accordance with the functions that Article 57 (1) a, f and h of Regulation (EU) 2016/679 GDPR confers to each supervisory authority and according to the provisions of Articles 47 and 48 (1) of LOPDGDD, the Director of the Spanish Data Protection Agency is competent to resolve these investigative actions. In light of provisions (Article 4 (15) GDPR, Article 9 GDPR, Article 6 GDPR) the vaccination of a person against Covid-19 implies the provision of a health care service. Therefore the information about whether or not an identified natural person has received the Covid-19 vaccine is in the nature of personal data concerning health, falling within the category of special of sensitive data regulated in Article 9 GDPR. The task of the University was to provide the Navarra Health Department, Osasunbidea, with the lists of the people who were going to receive the vaccine so that they could be registered in the health database. The students that wanted to fill out the form on the vaccination were fully informed about the processing of the data, this is on the legal obligation to take care of the health of students in Article 7.1.n Royal Decree 1791/2010. It has not been possible to prove that the students were forced to provide information on their vaccination status. The transfer of data is completely voluntary and informed, requesting the consent of the person concerned and the data is (if even) only transferred to health authorities. No evidence has been found to prove the existence of an infringement within the competence of the Spanish Data Protection Agency. The interested parties may file an appeal.

### AEPD (Spain) - EXP202203606

*Source: AEPD (Spain), 2022-04-22 — https://overview.legal/posts/125657 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_EXP202203606*

Facts — Resolution No. R/00665/2022 is highlighted by a case concerning a claimant (namely A.A.A) and a respondent party (namely Securitas Direct España, S.A). The claimant filed against the respondent party for not having been duly attended to his right of access and deletion enshrined in Articles 15 to 22 GDPR, Articles 13 to 18 LOPDGDD and Article 17 GDPR respectively. The conflict of law arose in this case when a sufficiently legally established response was not generated by the respondent to the claimants request. Furthermore, the claim was transferred to the respondent so that the entity could proceed with its analysis and provide a response to the claimant within a period of one month. The Director of the Spanish Data Protection Agency agreed to admit the claim for processing and the parties concerned were informed of the maximum term for resolution, that being six months. The competence of the Spanish Data Protection Agency is refined by Article 55 GDPR in the promotion of an obligation between controllers and processors to deal with complaints issued by data subjects. The result of the said transfer did not allow the claimants issues to be understood as satisfied. Consequently, due to the lack of attention delegated to the claimants rights further set forth in Article 15 GDPR, Article 16 GDPR, Article 17 GDPR, Article 18 GDPR, Article 19 GDPR, Article 20 GDPR, Article 21 GDPR and Article 22 GDPR, an agreement to admit for processing was initiated. Holding — The Director of the Spanish Data Protection Agency went on to note that considering the purpose of the outlined procedure was to ensure that the rights of affected parties were fully restored, the complaint that gave rise to this procedure should be upheld on formal grounds due to the fact that the right of access had been complied with and the right of erasure had been duly denied (on the applicable grounds of Article 17 GDPR).

### Tele2 Sverige Aktiebolag: Insufficient technical and organisational measures to ensure information security

*Source: Data Protection Authority of Sweden, 2023-06-30 — https://overview.legal/posts/48052 — original: https://www.enforcementtracker.com/ETid-1937*

The Swedish DPA has imposed a fine of EUR 1 million on Tele2 Sverige Aktiebolag. The Austrian organization None of your Business (NOYB) had filed a complaint against the company in light of the Schrems II judgment, stating that the company was unlawfully transferring personal data to the US. The company had used Google Analytics for visitor statistics and based the data processing by the statistics tool on the EU standard contractual clauses, as no adequacy decision had been issued by the EU Com

### CDON AB: Insufficient technical and organisational measures to ensure information security

*Source: Data Protection Authority of Sweden, 2023-06-30 — https://overview.legal/posts/48053 — original: https://www.enforcementtracker.com/ETid-1938*

The Swedish DPA has imposed a fine of EUR 25,000 on CDON AB. The Austrian organization None of your Business (NOYB) had filed a complaint against the company in light of the Schrems II judgment, stating that the company was unlawfully transferring personal data to the US. The company had used Google Analytics for visitor statistics and based the data processing by the statistics tool on the EU standard contractual clauses in the absence of an EU Commission adequacy decision for the USA. In the c

## Recent developments

### Data Protection Day: Only 1.3% of cases before EU DPAs result in a fine

*Source: noyb - European Center for Digital Rights, 2025-01-28 — https://overview.legal/posts/53164 — original: https://noyb.eu/en/data-protection-day-only-13-cases-eu-dpas-result-fine*

National Administrative Procedures and DPA inactivity When the General Data Protection Regulation (GDPR) came into force in 2018, it ushered in a new era of data protection in the EU. At least on paper. Consumers were given the tools to stand up for their fundamental rights, while authorities received serious investigatory powers and the ability to sanction breaches with hefty fines. Nearly 7 years later, the reality is much bleaker. On the occasion of this year’s Data Protection Day on 28 Janua

### A-G: rechtmatig verzamelde en opgeslagen persoonsgegevens mogen onder voorwaarden tijdelijk in een extra interne databank worden bewaard

*Source: NL EU Court Expert, 2022-04-09 — https://overview.legal/posts/6307 — original: https://ecer.minbuza.nl/-/a-g-rechtmatig-verzamelde-en-opgeslagen-persoonsgegevens-mogen-onder-voorwaarden-tijdelijk-in-een-extra-interne-databank-worden-bewaard?redirect=%2Fecer%2Fnieuws%3Fq%3Dprivacy%2520OR%2520avg%26f%3D%26t%3D#entry-306*

Lawfully collected and stored personal data may be retained in an additional internal database, to the extent that it pursues the same data processing purposes as the original data collection. That is the opinion of Advocate General Pikamäe to the EU Court in response to questions from a Hungarian judge.

### Health data and use of cookies: DOCTISSIMO fined €380,000

*Source: CNIL, 2023-05-17 — https://overview.legal/posts/6202 — original: https://www.cnil.fr/en/health-data-and-use-cookies-doctissimo-fined-eu380000#entry-5237*

Background information
Following a complaint by the PRIVACY INTERNATIONAL association, the CNIL carried out four investigations into DOCTISSIMO. The doctissimo.fr website mainly offers articles, tests, quizzes and discussion forums related to health and well-being for the general public.
During its investigations, the CNIL noted several infringements, in particular concerning the duration of data retention, the collection of health data via online tests, the security of data as well as the wayco

### Mensenrechtenorganisaties bekritiseren de geautomatiseerde gegevensuitwisseling voor de samenwerking tussen de politie (voorstel Prüm II).

*Source: eucrim, 2022-10-05 — https://overview.legal/posts/51798*

Het netwerk European Digital Rights (EDRi) heeft een position paper gepubliceerd over het voorgestelde Europees regelgevend kader voor geautomatiseerde gegevensuitwisseling ter bevordering van de samenwerking tussen politie, bekend als "Prüm II". Dit omvat momenteel voornamelijk een netwerk voor gegevensuitwisseling (waarbij nationale DNA-databases, vingerafdrukken en voertuigregistraties met elkaar worden verbonden). Het voorziet in een uitbreiding van dit netwerk, waarbij gezichtsherkenningstechnologie wordt toegevoegd en, op vrijwillige basis, "politiedossiers".

Het position paper werpt verschillende belangrijke vragen op over...

### Voorbij de kwestie van data-eigendom.

*Source: SSRN, 2022-10-09 — https://overview.legal/posts/51793*

Voorstellen over het eigendom van data zijn misplaatst en zouden averechts werken als ze zouden worden doorgevoerd. In plaats daarvan moet hervorming van de privacywetgeving zich richten op het versterken van de bestaande beperkingen op het gebruik van persoonlijke gegevens, zo stelt dit artikel.

## Literature

### If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation

*Source: Computer law & security review, 2026-01-23 — https://overview.legal/posts/53843 — original: https://doi.org/10.1016/j.clsr.2025.106251*

As the General Data Protection Regulation (GDPR) approaches its tenth anniversary, the European legislator is considering reforms thereto. This article offers a set of research-based suggestions for what such reforms could look like, based on two assumptions. First, that the GDPR is overall a solid piece of legislation that upholds the enduring objectives and principles of data protection law. Second, that any improvement cannot compromise the level of protection of fundamental rights currently

### GDPR - General Data Protection Regulation on Sites Requiring Accessibility

*Source: Innovative STEM Education, 2021-06-29 — https://overview.legal/posts/132420 — original: https://doi.org/10.55630/stem.2021.0305*

The paper describes what GDPR - General Data Protection Regulation is and why it matters for business, institutions and other legal entities, who need to collect personal data in order to provide and deliver services or products. They have to apply and describe to consumers’ principles and general rules to protect their data. Rules include reasons why personal data collection is necessary, transparency how and by who it will be used and stored and for how long, as well as safety measures to not

### Event-Driven Compliance: Reconciling Privacy Regulation with Real-Time Advertising Infrastructure

*Source: Journal of Computer Science and Technology Studies, 2025-11-26 — https://overview.legal/posts/53852 — original: https://doi.org/10.32996/jcsts.2025.7.12.20*

Programmatic advertising ecosystem functions based on distributed, event-driven frameworks that handle user data across enterprise limits in milliseconds, with basic contradictions with the present-day privacy laws such as GDPR, ePrivacy Directive, and CCPA/CPRA. The system of real-time bidding projects the identifiers of users and the cues of their behavior to many prospective advertisers, creating compliance risks that are multiplicative beyond jurisdictional lines. This manuscript formalizes

### Tracing the Impact of GDPR on Global Data Privacy

*Source: International Journal of Science and Research (IJSR), 2024-09-05 — https://overview.legal/posts/132625 — original: https://doi.org/10.21275/sr24906110537*

International Journal of Science and Research (IJSR) ISSN: 2319-7064 SJIF (2022): 7.942 Volume 13 Issue 9, September 2024 Fully Refereed | Open Access | Double Blind Peer Reviewed Journal www.ijsr.net Tracing the Impact of GDPR on Global Data Privacy Khushal Chauhan 1 , Mayur Ghawate 2 , Saachi Joshi 3 , Shrikant Kawade 4 1 Vishwakarma University, Department of Science and Technology, Kondhwa, Pune- 411048, India Email: khushal0519[at]gmail.com 2 Vishwakarma University, Department of Science and Technology, Kondhwa, Pune- 411048, India Corresponding Author Email: mayurghawate17[at]gmail.com 3 Vishwakarma University, Department of Science and Technology, Kondhwa, Pune- 411048, India Email: saachi.joshi26903[at]gmail.com 4 Vishwakarma University, Department of Science and Technology, Kondhwa, Pune- 411048, India Email: shrikantsk1224[at]gmail.com Abstract: The General Data Protection Regulation GDPR, enacted in May 2018, has reshaped data protection standards globally, enforcing strict requirements on organizations to protect personal data. This paper evaluates the impact of GDPR on modern cybersecurity practices, analyzing its influence on organizational policies, case studies of ma

## Tools

### GDPR Enforcement Tracker (fines and penalties database)

*Source: CMS, 2026-07-17 — https://overview.legal/posts/125626 — original: https://www.enforcementtracker.com/*

Continuously updated database by CMS of thousands of GDPR fines and penalties across all member states: authority, amount, date, sector, violated articles and a summary per decision, with filtering and statistics. The de-facto reference for fine benchmarking.

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Consent** — https://overview.legal/topics/toestemming
  Freely given, specific, informed indication of data subject wishes
- **Identification** — https://overview.legal/topics/identificatie
  Methods and processes for identifying individuals
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities

---
Generated by overview.legal · https://overview.legal/topics/statistics · 2026-08-22
