# Storage Limitation — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/storage-limitation
> Sources are cited per item. Verify against the official texts before relying on them.

Principle that data should not be kept longer than necessary

## Overview

## Legal Framework

Storage limitation is codified in [Article 5(1)(e) GDPR](/laws/gdpr/art-5#par-1-pnt-e), which requires that personal data be:

> "kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed"
> — [GDPR Art. 5(1)(e)](/laws/gdpr/art-5#par-1-pnt-e)

The provision carves out a narrow exception: longer retention is permitted only for archiving in the public interest, scientific or historical research, or statistical purposes under [Article 89(1)](/laws/gdpr/art-5). The principle operates alongside [Article 5(1)(c)](/laws/gdpr/art-5) (data minimisation) and [Article 5(1)(d)](/laws/gdpr/art-5) (accuracy), forming an interlocking lifecycle framework.

The AI Act reinforces this at the system level. [Article 17(1)(f) AI Act](/laws/ai-act/art-17#par-1-pnt-f) requires providers of high-risk AI systems to implement documented procedures covering "data retention" as part of their quality management system. [Article 10](/laws/ai-act/art-10) further requires governance over data preparation operations, implicitly tying retention to the system's intended purpose.

## Key Developments

The CJEU's ruling in *Digital Rights Ireland* established that retention regimes must guarantee not only a defined endpoint but also effective erasure. The Court found that the Data Retention Directive failed because it:

> "does not ensure the irreversible destruction of the data at the end of the data retention period."
> — [Digital Rights Ireland, ¶67](/posts/6161#seg-67)

This sets a baseline: a retention period without enforceable destruction is legally deficient.

Dutch courts have grappled with retention in practice. In the *Gemeente Weert* case, the Raad van State upheld a municipality's preservation of a mayor's deleted emails, balancing storage limitation against obligations under the Archiefwet and the Woo — retention beyond the functional deletion point was justified where archival and transparency duties required it. Conversely, in the *Beekdaelen* case, a court confronted the opposite problem: log files were destroyed under a supplier's retention policy before an individual could identify who had accessed her data, illustrating how premature erasure can itself undermine data-subject rights.

The EDPB has confirmed that the GDPR deliberately leaves retention periods to controller determination:

> "The GDPR does not specify a retention period for such documentation. Where such records contain personal data, it will be incumbent on the controller to determine the appropriate period of retention in accordance with the principles in relation to the processing of personal data"
> — [EDPB Guidelines 9/2022, §124](/posts/38058#seg-124)

## Status of the Debate

This topic is actively contested in court. The core principle — that data must not be kept longer than necessary — is settled. What remains disputed is the *calibration*: how long is "necessary" for a given purpose, and how retention interacts with conflicting legal obligations such as archival law, transparency duties, and evidentiary preservation. The *Gemeente Weert* and *Beekdaelen* cases illustrate opposite sides of this tension. No definitive court split is on record yet, but the boundaries are being fought case by case. A CJEU reference clarifying the interplay between GDPR storage limitation and sectoral retention mandates (archival, financial, law enforcement) would resolve the open question.

## Practical Guidance

- **Define purpose-specific retention periods**: Map each processing purpose to a concrete retention timeframe in your records of processing activities under [Article 30](/laws/gdpr/art-5). Generic "as long as necessary" policies are insufficient.
- **Implement automated erasure**: Destruction at the end of a retention period must be irreversible — *Digital Rights Ireland* sets this as a minimum standard. Relying on supplier-managed deletion without verification (as in *Beekdaelen*) creates compliance gaps.
- **Reconcile conflicting obligations**: Where sectoral law (e.g., Archiefwet, tax law) mandates longer retention, document the legal basis and ensure the stored data is access-restricted to the archival purpose only.
- **For AI systems, integrate retention into the QMS**: Under [Article 17(1)(f) AI Act](/laws/ai-act/art-17#par-1-pnt-f), document data retention procedures as part of the quality management system, tied to the system's intended purpose and lifecycle.
- **Review retention policies when purposes change**: If a processing purpose evolves or ceases, the retention period must be recalculated — the original timeframe does not automatically carry over.

## Legislation (full text of key provisions)

### Recital 94 — law enforcement biometric data processing compliance

*Source: AI Act, aiact-rec-94-en, 2024-06-12 — https://overview.legal/posts/93870*

Any processing of biometric data involved in the use of AI systems for biometric identification for the purpose of law enforcement needs to comply with Article 10 of Directive (EU) 2016/680, that allows such processing only where strictly necessary, subject to appropriate safeguards for the rights and freedoms of the data subject, and where authorised by Union or Member State law. Such use, when authorised, also needs to respect the principles laid down in Article 4 (1) of Directive (EU) 2016/680 including lawfulness, fairness and transparency, purpose limitation, accuracy and storage limitation.

## Case law

### Judgment of the Court (First Chamber) of 20 October 2022.#Digi Távközlési és Szolgáltató Kft. v Nemzeti Adatvédelmi és Információszabadság Hatóság.#Request for a preliminary ruling from the Fővárosi Törvényszék.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 5(1)(b) and (e) – Principle of ‘purpose limitation’ – Principle of ‘storage limitation’ – Creation, from an existing database, of a datab

*Source: Court of Justice of the European Union, C-77/21, 2022-10-20 — https://overview.legal/posts/132306 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0077*

In this preliminary ruling, the CJEU interpreted Articles 5(1)(b) and 5(1)(e) GDPR in proceedings between Digi Távközlési és Szolgáltató Kft. and the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) concerning a personal data breach. The Court held that creating a new database from an existing one for testing and error-correction purposes constitutes further processing requiring compatibility assessment under the purpose limitation principle, and that the storage limitation principle applies such that data must be deleted once the testing purpose is fulfilled. No fine was imposed at the EU level, as the matter was remitted to the referring Hungarian court.

### CE - 439360

*Source: CE, 2021-04-13 — https://overview.legal/posts/125663 — original: https://gdprhub.eu/index.php?title=CE_-_439360*

Facts — In February 2020 the French minister of the interior enacted the Decree No. 2020-151 of 20 February 2020 authorising the automated processing of personal data known as "mobile note-taking application" (Décret n° 2020-151 du 20 février 2020 portant autorisation d'un traitement automatisé de données à caractère personnel dénommé «application mobile de prise de notes» (GendNotes)). The app should be used on the occasion of preventive actions, investigations or interventions necessary for the exercise of judicial or administrative police missions. Among the data that can be collected is information relating to alleged racial or ethnic origin, political, philosophical or religious opinions, trade union membership, health or sexual activities or orientation. A group of human rights organisations filed a complaint with the French Constitutional Court. Dispute — Is the "GendNotes" App of the French national police force (Gendarmerie nationale) unlawfully processing special category personal data? Holding — The French Highest Administrative Court held that the decree infringed Article 4 of the Law of 6 January 1978, implementing GDPR in France, the Council of Europe Convention No. 108 for the Protection of Individuals with regard to Automatic Processing of Personal Data and Article 8 CFR, as it excessively infringed upon the right to respect for private life and the correlative right to protection of personal data, without providing appropriate safeguards for their protection in terms of the purpose of the processing and the nature of the data collected, as well as excessive data retention period, data sharing and data security. The Court discussed whether the decree violated Article 4 (a) GDPR, Article 4 (b) GDPR, Article 4 (c) GDPR, and Article 4 (e) GDPR and Article 9 GDPR. According to the Court, the processing of data did not comply with the principle of purpose limitation, as data is collected for future investigations or proceedings. However, the Court did not find a violation on the collect of special category data, given the fact that the decree establishes that this data can only be processed in case of "absolute necessity". Additionally, the Court noted that, even if the decree provides a limitation for the storage of the data, in practice this can be ignored, as the data may be used in different or further investigations, that would impede its erasure. However, they found that the decree was lawful in this regard, given that it clearly stated a retention period of 3 months to 1 year. Taken the above-mentioned into account, the French Highest Administrative Court decided that the data processed by the French national police force can no longer be used "in other data processing, in particular by means of a pre-information system". Therefore, the Court held: In Article 1° of the decree, the words "in other data processing, in particular by means of a pre-information system," are cancelled out. The State will pay €3,000 to every claimant. The rest of the application is rejected. The allowance to collect special category data is not overruled, as the Court argues that the decree only allows it when it is "absolutely necessary". This decision will be notified to the claimants: the Ligue des droits de l'homme, the associations Homosexualités et socialismes and Internet Society France, the associations Mousse, Stop Homophobie, Adheos and Familles A, the association AIDES, the Syndicat de la magistrature, the Syndicat des avocats de France, the Conseil national des barreaux, the Quadrature du Net and the International League against Racism and Anti-Semitism, the Prime Minister and the Minister of the Interior.

### BVerwG - 6 C 13.18

*Source: GDPRhub, 2026-07-24 — https://overview.legal/posts/158441 — original: https://gdprhub.eu/index.php?title=BVerwG_-_6_C_13.18*

Facts — Since 2016, SpaceNet AG, an ISP, has been challenging a German law which provides for an obligation to store traffic and location data of all users without any reason and across the board, arguing it is incompatible with the EU Charter of Fundamental Rights. Holding — Question referred "In the light of Articles 7, 8 and 11 and Article 52(1) of the Charter of Fundamental Rights of the European Union, on the one hand, and of Article 6 of the Charter of Fundamental Rights of the European Union and Article 4 of the Treaty on European Union, on the other hand, is Article 15 of Directive 2002/58/EC to be interpreted as precluding national legislation which obliges providers of publicly available electronic communications services to retain traffic and location data of end users of those services where that obligation does not require a specific reason in terms of location, time or region, the following data are the subject of the storage obligation in the provision of publicly available telephone services — including the transmission of short messages, multimedia messages or similar messages and unanswered or unsuccessful calls: the telephone number or other identifier of the calling and called parties as well as, in the case of call switching or forwarding, of every other line involved, the date and time of the start and end of the call or — in the case of the transmission of a short message, multimedia message or similar message — the times of dispatch and receipt of the message, and an indication of the relevant time zone, information regarding the service used, if different services can be used in the context of the telephone service, and also, in the case of mobile telephone services the International Mobile Subscriber Identity of the calling and called parties, the international identifier of the calling and called terminal equipment, in the case of pre-paid services, the date and time of the initial activation of the service, and an indication of the relevant time zone, the designations of the cells that were used by the calling and called parties at the beginning of the call, in the case of internet telephone services, the Internet Protocol addresses of the calling and the called parties and allocated user IDs, the following data are the subject of the storage obligation in the provision of publicly available internet access services: the Internet Protocol address allocated to the subscriber for internet use, a unique identifier of the connection via which the internet use takes place, as well as an allocated user ID, the date and time of the start and end of the internet use at the allocated Internet Protocol address, and an indication of the relevant time zone, in the case of mobile use, the designation of the cell used at the start of the internet connection, the following data must not be stored: the content of the communication, data regarding the internet pages accessed, data from electronic mail services, data underlying links to or from specific connections of persons, authorities and organisations in social or ecclesiastical spheres, the retention period is four weeks for location data, that is to say, the designation of the cell used, and ten weeks for the other data, effective protection of retained data against risks of misuse and against any unlawful access to that data is ensured, and the retained data may be used only to prosecute particularly serious criminal offences and to prevent a specific threat to life and limb or a person’s freedom or to the continued existence of the Federal Republic or of a Federal Land, with the exception of the Internet Protocol address allocated to a subscriber for internet use, the use of which data is permissible in the context of the provision of inventory data information for the prosecution of any criminal offence, maintaining public order and security and carrying out the tasks of the intelligence services?"

### CJEU - C-350/21 - Spetsializirana prokuratura (Retention of traffic and location data)

*Source: GDPRhub, C-350/21, 2026-07-16 — https://overview.legal/posts/122856 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-350/21_-_Spetsializirana_prokuratura_(Retention_of_traffic_and_location_data)*

Facts — In the context of criminal proceedings in Bulgaria, the prosecutor requested the Spetsializiran nakazatelen sad (Bulgarian Criminal Court) to give him access to data, including location data, concerning the telephone calls of five persons involved in a serious crime case. The case file showed that the telephone numbers were potentially used to commit the crime. Under Bulgarian national law, the retention of traffic and location data is limited to six months. Access to these data is only allowed for investigative purposes in serious offences, but the national law does not include a provision that restricts access to what is strictly necessary for the purpose. The Criminal Court therefore referred the following question to the CJEU. (1) Is national legislation (Article 251b(1) of the Zakon za elektronnite saobshtenia (Law on electronic communications)) providing for the general and indiscriminate retention of all traffic data (traffic data and location data of users of electronic means of communication) for a period of 6 months in order to fight serious crime compatible with Article 15(1) of Directive 2002/58, read in combination with Article 5(1) and recital 11 thereof, provided that the national legislation contains certain safeguards? (2) Is national legislation (Article 159a of the Nakazatelno-protsesualen kodeks (Code of Criminal Procedure)) which does not limit access to traffic data to what is strictly necessary and does not grant the persons whose traffic data are accessed by the law enforcement authorities the right to be notified thereof, provided that that does not impede criminal proceedings, or the right to a legal remedy against unlawful access compatible with Article 15(1) of Directive 2002/58, read in combination with Article 5(1) and recital 11 thereof? Holding — (1) The Court considered that Article 15(1) of Directive 2002/58 does not allow Member States to derogate from Articles 4(1) and 4(1)bis, which require providers of electronic communications services to take appropriate technical and organisational measures to ensure effective data protection. It answered the first question by stating that Article 15(1) of the Directive must be interpreted as precluding national legislation which provides for general and undifferentiated data retention as a preventive measure in the context of criminal investigations. (2) As to the second question, concerning the failure of national legislation to provide for access to data to be limited to what is strictly necessary, the Court held that national legislation must satisfy the requirement of proportionality. In particular, the legislation cannot be limited to requiring that the authorities' access to the data be in accordance with the purpose of the legislation, but must also provide for the material and procedural conditions governing that use. The Court therefore considered that national legislation which does not provide that access to stored data is limited to what is strictly necessary to achieve the purpose of that storage does not comply with the mentioned provisions. As regards information and the right of appeal for data subjects, the Court considered that the articles in question preclude national legislation which does not guarantee that data subjects are informed of the processing to the extent provided for by EU law and which does not allow any means of appeal in the event of unlawful access to such data.

### Judgment of the Court (Grand Chamber) of 20 September 2022.#Bundesrepublik Deutschland v SpaceNet AG and Telekom Deutschland GmbH.#Requests for a preliminary ruling from the Bundesverwaltungsgericht.#Reference for a preliminary ruling – Processing of personal data in the electronic communications sector – Confidentiality of communications – Providers of electronic communications services – General and indiscriminate retention of traffic and location data – Directive 2002/58/EC – Article 15(1) –

*Source: Court of Justice of the European Union, C-793/19, 2022-10-27 — https://overview.legal/posts/132305 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62019CJ0793*

In Joined Cases C-793/19 and C-794/19, the Court of Justice of the European Union (Grand Chamber) addressed preliminary references from the German Federal Administrative Court concerning the interpretation of Article 15(1) of Directive 2002/58/EC (the ePrivacy Directive) in proceedings between the Federal Republic of Germany and telecommunications providers SpaceNet AG and Telekom Deutschland GmbH. The core issue was whether EU law permits Member States to impose general and indiscriminate data retention obligations on electronic communications service providers. The Court ruled that EU law, read in light of the Charter of Fundamental Rights, precludes such general and indiscriminate retention of traffic and location data, while permitting limited, targeted retention regimes and other narrowly tailored measures subject to strict safeguards and prior review by a court or independent administrative body. No fine was imposed.

### Judgment of the Court (Grand Chamber) of 5 April 2022.#G.D. v The Commissioner of the Garda Síochána and Others.#Request for a preliminary ruling from the Supreme Court.#Reference for a preliminary ruling – Processing of personal data in the electronic communications sector – Confidentiality of the communications – Providers of electronic communications services – General and indiscriminate retention of traffic and location data – Access to data – Subsequent court supervision – Directive 2002/58

*Source: Court of Justice of the European Union, C-140/20, 2022-04-05 — https://overview.legal/posts/132314 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62020CJ0140*

In Case C-140/20, the Court of Justice of the European Union (Grand Chamber) addressed a preliminary ruling from the Irish Supreme Court concerning G.D. v. Commissioner of An Garda Síochána, which challenged the validity of Ireland's Communications (Retention of Data) Act 2011 under Directive 2002/58/EC and the EU Charter of Fundamental Rights. The Court ruled that national legislation mandating the general and indiscriminate retention of traffic and location data by electronic communications providers is incompatible with EU law, and held that a national court may not restrict the temporal effect of a declaration of invalidity of such incompatible legislation, meaning all affected data retention must cease and prior retention cannot be retrospectively validated. No fine was imposed, as this was a preliminary ruling on the interpretation and validity of EU law.

### GC - T-318/24

*Source: Gereral Court, T-318/24, 2025-12-03 — https://overview.legal/posts/122878 — original: https://gdprhub.eu/index.php?title=GC_-_T-318/24*

Facts — An applicant (the data subject) participated in several EU staff selection procedures administered by the European Personnel Selection Office (EPSO), acting as controller, and created an EPSO account in the Talent system. After he successfully passed one selection procedure, EPSO also stored his data in its recruitment portal. EPSO managed recruitment through two IT systems, both of which generated access logs, although those logs contained limited technical information regarding the purpose of each access. Between 2022 and 2024, the data subject submitted several requests to EPSO under Article 17 of Regulation (EU) 2018/1725, seeking access to all personal data concerning him. He requested, in particular, full access logs, minutes of meetings, internal and external communications containing his personal data, information on data recipients, and the restoration of personal data deleted after the expiry of retention periods. EPSO stated that certain data did not exist, that it could not restore lawfully deleted data, and that it had already disclosed all available log data. After the data subject lodged a complaint, the European Data Protection Supervisor (EDPS) reconsidered the matter in light of the CJEU’s judgment in Pankki. The EDPS ordered EPSO to provide all available log data relating to consultations of the data subject’s profile. EPSO complied with that order by disclosing the available logs but withheld the identities of individual staff members who had accessed the data. EPSO later rejected further access requests submitted by the data subject. As a result, the data subject brought two actions before the General Court (Cases T-318/24 and T-362/24), seeking the annulment of EPSO’s decisions. The General Court joined the two cases and examined together all the pleas in law raised by the data subject. Holding — The General Court dismissed both actions in their entirety. It held that the controller did not infringe Article 17(1) or (3) of Regulation 2018/1725, as the right of access concerns personal data undergoing processing and not documents as such, nor does it require the controller to restore lawfully deleted data. The Court confirmed that Regulation 2018/1725 contains no obligation for a controller to reinstate personal data once deleted in compliance with applicable retention rules. The Court further held that the controller had no obligation to disclose additional log data, meeting minutes, or communications where it credibly asserted that no such personal data existed. The data subject failed to rebut the presumption of legality attaching to the controller’s statements regarding the non-existence of further data. Moreover , The Court held that access logs constitute personal data to which a data subject is entitled, as they reveal the existence, frequency and purpose of processing. However, employees of a controller acting under its authority are not “recipients” within the meaning of the GDPR or Regulation 2018/1725, and controllers are not required to log or disclose their identities. Disclosure of such identities is only required if strictly necessary for the effective exercise of data protection rights and subject to safeguarding employees’ rights. Since the data subject had already been informed of the purposes and recipients of processing, the absence of staff identities or detailed purposes in the logs did not infringe the right of access. It is not further apparent from the Pankki that Article 15 GDPR requires the controller to set up a logging mechanism containing information on the identity of employees who have carried out consultation operations in respect of the personal data of a person. In addition, the Court found no infringement of the principles of lawfulness, fairness, transparency, accuracy, integrity, confidentiality, or accountability under Article 4 of Regulation 2018/1725. The deletion of the data subject’s data after the expiry of retention periods was lawful and the data subject’s rights to restriction of processing and objection under Articles 20 and 23 were not applicable, as the deletion was based on a legal obligation rather than consent or legitimate interests.

### CJEU - C-162/22 - Lietuvos Respublikos generalinė prokuratūra

*Source: GDPRhub, 2023-09-07 — https://overview.legal/posts/125587 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-162/22_-_Lietuvos_Respublikos_generalinė_prokuratūra*

Facts — The Lithuanian Prosecutor General´s Office investigated one of its public prosecutors, who was found responsible of misconduct in its office. The research into the public prosecutor´s misconduct was authorised by a court order, allowing for the interception and recording of data transmitted over electronic communication. Following these findings, the Prosecutor General´s Office dismissed the public prosecutor from office. The public prosecutor contested the decision before the Regional Administrative Court (Vilniaus apygardos administracinis teisma), which dismissed the claim due to the lawfulness of the criminal intelligence operations and process behind the data gathered. The controller then appealed the case to the Supreme Administrative Court (Lietuvos vyriausiasis administracinis teisma), as he alleged that the access by intelligence bodies to traffic data and actual content of electronic communications was such a serious interference with fundamental rights that access could only be granted to combat serious crime. The Supreme Administrative Court considered it apparent that Article 15(1) ePrivacy Directive 2002/58/EC, together with Article 3ePrivacy Directive 2002/58/EC thereof, extends the scope of that directive only to legislative measures requiring providers of electronic communications services to grant the competent national authorities access to data (as found in C-623/17 Privacy International). Moreover, it follows from C-746/18 Prokuratuur, that only actions to combat serious crime and measures to prevent serious threats to public security are capable of justifying serious interference with Article 7 CFR and Article 8 CFR (hereinafter: the Charter). However, the CJEU did not yet rule on the impact of the subsequent use of the data concerned on the interference with fundamental rights. The Supreme Administrative Court doubted whether such subsequent use constituted a serious interference with Article 7 CFR and Article 8 CFR, and whether such use is justifiable only for the purposes of combating serious crime and preventing serious threats to public security. Thus, the Supreme Administrative Court of Lithuania referred to the CJEU the following preliminary question: - Whether Article 15(1) ePrivacy Directive 2002/58/EC precludes the use, in connection with investigations into corruption-related misconduct in office, of personal data relating to electronic communications retained, pursuant to an authorised order, by providers of electronic communications services and subsequently made available to the competent authorities to combat serious crime? Holding — The CJEU pointed out that the referring court only questions the subsequent use of personal data retained by electronic communication providers on the basis of Article 15(1) Directive 2002/58. Thus, the data to be considered in this preliminary ruling decision is the data retained on the basis of Article 65(2) of Lithuanian Law on Electronic Communications, which, together with Annex I, requires electronic service providers to retain, generally and indiscriminately, traffic and location data relating to such communications for the purpose of combating serious crime. The CJEU considered that the subsequent use of traffic and location data relating to electronic communications, to combat serious crime, is only possible on two conditions: - retention of those data by providers of electronic communications services must be consistent with Article 15(1) ePrivacy Directive 2002/58/EC; and - access to those data granted to the competent authorities must be itself consistent with that provision. In C-793/19 SpaceNet and Telekom Deutschland, legislation allowing the pre-emptive retention of traffic and location data was considered not in line with EU law. However, legislation allowing for data retention under strict requirements to combat serous crime and prevent serious threats to public security was allowed under ePrivacy Directive 2002/58/EC. In light of these preliminary remarks, the CJEU started its analysis by stating that Article 15 ePrivacy Directive 2002/58/EC allows Member States to introduce exceptions to the obligations laid out in Article 5(1) ePrivacy Directive 2002/58/EC for the safeguard of national security, defence and public security, and the prevention, investigation, detection and prosecution of criminal offences or of unauthorised use of the electronic communication system. However, the CJEU considered that Article 15 ePrivacy Directive 2002/58/EC cannot expand excessively the exception to the principle of confidentiality and data storage present in Article 5 Directive 2002/58. Thus, the CJEU reiterated that the objectives listed in Article 15(1) ePrivacy Directive 2002/58/EC is exhaustive. Once having established that no other objectives can be added to the ones laid out in Article 15 ePrivacy Directive 2002/58/EC, the CJEU considered that there is a hierarchy behind the objectives according to their importance, which in turn needs to be balanced against the seriousness of the interference to an individual´s life it entails (C-140/20 Commissioner of An Garda Síochána and Others). The objective of safeguarding national security exceeds in importance the other objectives of Article 15 Directive 2002/58 and, thus, can justify more serious interference with Article 7 CFR and 8 CFR. Differently, with regards to the objective of preventing, investigating, detecting and prosecuting criminal offenses, only actions to combat serious crime and serious threats to public security can justify a serious interference with Article 7 CFR and Article 8 CFR. Thus, deciding whether there is a justification to the limitations to Article 5 ePrivacy Directive 2002/58/EC, Article 6 ePrivacy Directive 2002/58/EC and Article 9 ePrivacy Directive 2002/58/EC depends on the seriousness of the interference stemming from this limitation and on the importance of public interest objective pursued by that limitation in relation to its seriousness (C-511/18 La Quadrature du Net and Others). This reasoning applies mutatis mutandis to the subsequent use of traffic of location data retained by providers of electronic communications services ex Article 15(1) ePrivacy Directive 2002/58/EC. In the case at hand, for the CJEU, the fact that the referring Supreme Administrative Court did not indicate any threat to public security in its documents, and that investigating a misconduct in office does not correspond to the objective of prosecuting and punishing criminal offenses, ex Article 15(1) ePrivacy Directive 2002/58/EC, proves that investigations of misconduct in office does not fall within the category of combating serious crime. Therefore, the CJEU found that Article 15(1) ePrivacy Directive 2002/58/EC, read in the light of Article 7 CFR, Article 8 CFR, Article 11 CFR and Article 52(1) CFR, does not allow the use, in connection with investigations into corruption-related misconduct in office, of personal data relating to electronic communications which have been retained by providers of electronic communications services and which have subsequently been made available to the competent authorities for the purpose of combating serious crime.

### Judgment of the Court (Fifth Chamber) of 24 February 2022.#SIA 'SS' v Valsts ieņēmumu dienests.#Request for a preliminary ruling from the Administratīvā apgabaltiesa.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 2 – Scope – Article 4 – Concept of ‘processing’ – Article 5 – Principles relating to processing – Purpose limitation – Data minimisation – Article 6 – Lawfulness of processing – Proc

*Source: Court of Justice of the European Union, C-175/20, 2022-02-24 — https://overview.legal/posts/132316 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62020CJ0175*

In Case C-175/20, the Court of Justice of the EU interpreted GDPR Articles 5 and 6 in response to a preliminary ruling from the Latvian Regional Administrative Court concerning a request by the Latvian State Tax Authority for SIA 'SS' to disclose personal data from online vehicle sale advertisements for tax enforcement purposes. The Court held that national law may require controllers to provide personal data to tax authorities under Article 6(1)(c) and (e), provided the request complies with data minimisation and purpose limitation principles, meaning authorities must limit requests to what is necessary and proportionate for the specific tax investigation. No fine was imposed as this was a preliminary ruling proceeding.

### Judgment of the Court (Grand Chamber) of 2 March 2021.#Criminal proceedings against H. K.#Request for a preliminary ruling from the Riigikohus.#Reference for a preliminary ruling – Processing of personal data in the electronic communications sector – Directive 2002/58/EC – Providers of electronic communications services – Confidentiality of the communications – Limitations – Article 15(1) – Articles 7, 8 and 11 and Article 52(1) of the Charter of Fundamental Rights of the European Union – Legisl

*Source: Court of Justice of the European Union, C-746/18, 2021-03-02 — https://overview.legal/posts/132324 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0746*

In Case C-746/18, the CJEU Grand Chamber addressed a preliminary reference from the Estonian Supreme Court (Riigikohus) concerning whether EU law permits national legislation authorizing general and indiscriminate retention of traffic and location data by electronic communications providers and subsequent access by national authorities for criminal investigations. The Court reaffirmed that general and indiscriminate data retention is incompatible with Articles 7, 8, and 11 of the Charter and Article 15(1) of Directive 2002/58/EC, while allowing targeted retention with strict safeguards; it further held that data retained unlawfully may not be used as evidence in criminal proceedings, though national courts must assess whether access was independently justified and proportionate.

### Judgment of the Court (Grand Chamber) of 21 December 2016.#Tele2 Sverige AB v Post- och telestyrelsen and Secretary of State for the Home Department v Tom Watson and Others.#Requests for a preliminary ruling from the Kammarrätten i Stockholm and the Court of Appeal (England & Wales) (Civil Division).#Reference for a preliminary ruling — Electronic communications — Processing of personal data — Confidentiality of electronic communications — Protection — Directive 2002/58/EC — Articles 5, 6 and 9

*Source: Court of Justice of the European Union, C-203/15, 2016-12-21 — https://overview.legal/posts/132351 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62015CJ0203*

In Joined Cases C-203/15 and C-698/15, the Court of Justice of the European Union (Grand Chamber) addressed preliminary references from Swedish and UK courts regarding the compatibility of national data retention laws with Directive 2002/58/EC and the Charter of Fundamental Rights. The Court held that EU law precludes national legislation mandating the general and indiscriminate retention of traffic and location data by electronic communications service providers, and that access to retained data must be subject to prior review by a court or independent administrative authority, except in urgent cases. No fine was imposed as the ruling concerned the interpretation of EU law for the referring courts.

### Council of State: Tax Authority satisfied GDPR access request on FSV fraud registration

*Source: Council of State, 2026-08-05 — https://overview.legal/posts/187482 — original: https://gdprhub.eu/index.php?title=RVS_-_202307578/1/A3*

Facts — The personal data of an individual was stored in the Fraud Detection System (FSV), an application used by the Dutch Tax Authority between 2012 and 2020 to record potential indicators of tax fraud. The Minister of Finance was the controller. The data subject submitted an access request under Article 15 GDPR. In particular, she requested information about the personal data processed, the purposes of the processing, the recipients of the data, its source and retention period, and any automated decision-making concerning her. The controller provided an overview of the personal data stored in the FSV and answered the data subject’s questions. The data subject objected to the decision, claiming that the controller had not disclosed all information relating to her registration. The controller rejected the objection. It explained that the data subject had been selected for a manual review of her tax return under Project 1043, an anti-fraud initiative launched by the Dutch Tax, and was consequently registered in the FSV. It also stated that the data was accessible only to employees of the Tax Authority and had not been disclosed to other organisations. The District Court of Amsterdam dismissed the data subject’s appeal. It held that the proceedings concerned compliance with the GDPR access request and not the lawfulness of her inclusion in the FSV or any alleged resulting damage. The data subject appealed this judgment before the Council of State. Holding — The Council of State dismissed the appeal and upheld the judgment of the District Court. The Court held that there was no evidence that the controller had incorrectly applied Article 15 GDPR. The controller had provided an overview of all personal data concerning the data subject processed in the FSV, explained the purposes of the processing and clarified the circumstances of her registration under Project 1043. Although the data subject suspected that the controller held additional information, she did not provide concrete evidence supporting this claim. The Court also found no indication that she had been classified as a fraudster or that her personal data had been disclosed to other organisations. The Court further clarified that the lawfulness of the data subject’s registration in the FSV, the deletion of her data and any claim for compensation fell outside the scope of the access proceedings. Consequently, the Court confirmed the contested judgment and did not award litigation costs.

## Guidance

### Guidelines on processing of personal data through blockchain technologies

*Source: EDPB, guidelines-on-processing-of-personal-data-through-blockchain-technologies-en, 2026-07-07 — https://overview.legal/posts/125668 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-on-processing-of-personal-data-through-blockchain-technologies_en*

Guidelines 02/2025 on processing of personal data through blockchain technologies Version 2.0 Adopted on 07 July 2026 1 | Adopted Version history Version Date Adoption information version 1.1 08 April 2025 adoption of the guidelines before public consultation version 2.0 07 July 2026 adoption of the guidelines after public consultation 3 | Adopted 4 | Adopted The European Data Protection Board Having regard to Article 70 (1)(e) of the Regulation 2016/679/EU of the European Parliament and of the…

### Statement 2/2025 on the implementation of the PNR Directive in light of CJEU Judgment C-817/19

*Source: CJEU, edpb-statement-20250313-implementation-of-the-pnr-directive-in-light-of-the-cjeu-judgment-en, 2025-03-14 — https://overview.legal/posts/50657 — original: https://www.edpb.europa.eu/documents/statement/statement-22025-on-the-implementation-of-the-pnr-directive-in-light-of-cjeu_en*

Adopted 1 Statement 2/2025 on the implementation of the PNR Directive in light of CJEU Judgment C - 817/19 Adopted on 13 March 2025 Adopted 2 3 Final remarks ................................ ................................ ................................ ................................ . 11 Adopted 3 The European Data Protection Board has adopted the following statement: 1 BACKGROUND AND PURPOSE OF THIS STATEMENT 1. On 21 June 2022, the Court of Justice of the European Union (CJEU) rendered…

### Guidelines 02/2021 on virtual voice assistants

*Source: EDPB, edpb-guidelines-on-virtual-voice-assistants, 2021-07-07 — https://overview.legal/posts/38077 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-022021-on-virtual-voice-assistants_en*

A virtual voice assistant (VVA) is a service that understands voice commands and executes them or mediates with other IT systems if needed. VVAs are currently available on most smartphones and tablets, traditional computers, and, in the latest years, even standalone devices like smart speakers. VVAs act as interface between users and their computing devices and online services such as search engines  or  online  shops.  Due  to  their  role,  VVAs  have  access  to  a  huge  amount  of  personal...

### Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020

*Source: EDPB, edpb-guidelines-on-data-protection-by-design-and-by-default, 2020-10-20 — https://overview.legal/posts/38054 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-42019-on-article-25-data-protection-by-design-and-by-default_en*

The European Data Protection Board (EDPB) adopted these guidelines (Version 2.0) to provide interpretive guidance on Article 25 of the GDPR, which mandates data protection by design and by default. The guidelines address controllers' obligations to implement appropriate technical and organizational measures and necessary safeguards into processing operations, including the dimensions of data minimization required by default. No fines or enforcement actions are at issue, as this is a guidance document intended to assist controllers in complying with their Article 25 obligations.

### Statement on the processing of personal data in the context of reopening of borders following the COVID-19 outbreak

*Source: EDPB, statement-on-the-processing-of-personal-data-in-the-context-of-reopening-of-en, 2020-06-16 — https://overview.legal/posts/126144 — original: https://www.edpb.europa.eu/documents/statement/statement-on-the-processing-of-personal-data-in-the-context-of-reopening-of_en*

1 Statement on the processing of personal data in the context of reopening of borders following the COVID - 19 outbreak Adopted on 16 June 2020 The European Data Protection Board has adopted the following statement: 1. In the Communication from the Commission on the third assessment of the application of the temporary restriction on non - essential travel to the EU from 11 June 2020, the Schengen Member States and Schengen Associated State s are invited to lift internal border controls by 15…

### Report on stakeholder event on anonymisation and pseudonymisation of 12 December 2025

*Source: EDPB, report-on-stakeholder-event-on-anonymisation-and-en, 2026-02-18 — https://overview.legal/posts/125688 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/report-on-stakeholder-event-on-anonymisation-and_en*

Report on stakeholder event on anonymisation and pseudonymisation of 12 December 2025 1. Background The EDPB organise d a remote stakeholder event on 12 December 2025 to collect stakeholders’ input on anonymisation and pseudonymisation , following the Court of Justice of the European Union ( “ CJEU ” ) judgment in case EDPS v SRB 1 . The objective was to engage with stakeholders to inform the EDPB’s ongoing work on its guidelines 01/2025 on pseudonymisation and f orthcoming guidelines on…

### Art. 29 WP Guidelines on GDPR transparency requirements (WP260 rev.01)

*Source: EDPB, edpb-guidelines-on-transparency, 2025-11-21 — https://overview.legal/posts/38076 — original: https://www.edpb.europa.eu/system/files/2023-09/wp260rev01_en.pdf*

The Article 29 Data Protection Working Party issued these guidelines (WP260 rev.01), adopted on 29 November 2017 and last revised on 11 April 2018, to provide interpretive and practical guidance on the transparency requirements under the GDPR (Articles 12–14). The document addresses the form, timing, content, and modalities of information provided to data subjects, including issues such as plain language, layered privacy notices, information for children, and exceptions to the obligation to provide information. No fines or enforcement actions are imposed, as this is a guidance document rather than an enforcement decision.

### Statement 1/2025 on Age Assurance

*Source: EDPB, statement-12025-on-age-assurance-en, 2025-02-12 — https://overview.legal/posts/125696 — original: https://www.edpb.europa.eu/documents/statement/statement-12025-on-age-assurance_en*

1 Statement 1/2025 on Age Assurance Adopted on 11 February 2025 1 The European Data Protection Board has adopted the following statement: 1. BACKGROUND AND PURPOSE OF THIS STATEMENT 1. The European regulatory framework calls for the increased protection of children in the digital environment. For example, the Audiovisual Media Services Directive 2 , which Member States have transposed into their national laws, highlights the possibility to implement age verification measures (Articles 6a and…

## Enforcement decisions

### Garante per la protezione dei dati personali (Italy) - 9794895

*Source: Garante per la protezione dei dati personali (Italy), 2022-06-09 — https://overview.legal/posts/6314 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_9794895*

Facts — The Municipality of Policoro (Basilicata), implemented the use of CCTV cameras to monitor and fight waste abandonment within its territory. A data subject complained the Municipality had breached their data protection right of fair, transparent and lawful processing under art. 5(1)(a) as the sign signaling the CCTV monitoring referred to an outdated legislative decree. They also alleged a breach of art. 5(1)(e) and art. 13 GDPR, in so far the municipality never defined a data retention period for each processing purpose pursued. The last complaint moved forward by the data subject was that by being legally represented in Court by the same lawyer, who also acted as DPO of Policoro, the Municipality gave rise to a conflict of interest situation and breached art. 38(6) GDPR. The Municipality argued that the claim had been done in front of the Justice of Peace, who had no competency to decide on issues of privacy. It was also alleged the judgement only pertained an administrative matter, without rising any data protection concerns or a situation of conflict of interest with the Municipality's DPO. The last argument alleged the processing and retention of the CCTV footage was related to illegal dumps within the municipal territory, meaning the filming had been carried out in the course of judicial police investigations and the data retention periods of the GDPR did not apply in this case. Holding — The Italian DPA held that in this case the Municipality was carrying activities of data processing, by surveilling public entities by means of surveillance cameras. It also noted, that in par. 41 of the Guidelines 3/2019 on the Processing of Personal Data by Video Devices, waste management is "among the institutional activities entrusted to local authorities". This means the surveillance done by the Municipality of Policoro, a task carried out in the public interest in connection with the exercise of official authority as per art.6(1)(e) GDPR, was unrelated to public security and/or judicial police and obliging the controller to comply with data protection principles. The DPA found that the information provided in regards to the processing of personal data by means of surveillance cameras, did not meet the requirements of conciseness, transparency, intelligibility and easy readability contained in art. 5(1)(a) GDPR. The Municipality of Policoro had failed to provide suitable first-level information to the data subject, in so far the sign signaling the CCTV surveillance made reference to an outdated legislative decree (d.lgs 196/03) instead of the one currently in force (d.lgs 101/18). Furthermore, the data controller failed to provide the data subject with an adequate notice on second-level processing of their data. The signage did not include information on the most suitable impacts of the processing or an indication of a website, where to consult an extended version of the explanation. The DPA also found a violation of art. 13 GDPR as well as the principles of storage limitation and accountability in art. 5(1)(e) and art. 5(2). It stated that "the longer the intended storage period (especially if longer than 72 hours), the more reasoned the analysis referring to the legitimacy of the purpose and necessity of storage must be". In this case, the data controller not only failed to set a maximum retention period for the images taken for the purpose of combating illegal littering, but also established the administrative fines for the violation two months after the images were recorded. This did not allow for the data controller to respect the principle of accountability. Lastly, the DPA addressed the alleged conflict of interest raised by the involvement of the Policoro's DPO in the legal proceedings brought against the data subject. The DPA ruled DPOs "may perform other duties and functions," with the understanding that "the controller must ensure that such duties and functions do not give rise to a conflict of interest." The DPA also made reference to the Article 29 WP's Guidelines on Data Protection Officers, in which it is urged to not designate DPOs already acting as defense counsel for the same court. In the case at hand, it resulted that the DPO shared with the Municipality an interest in obtaining a rejection of the appeal. Consequently, the Italian Garante held this to be in violation of art. 38(6) GDPR, as well the fact that it undermined the DPO's independence. The Italian DPA held a cumulative breach of art. 5(1)(a) and (e) and (2) (in conjunction with article 24), 12, 13 and 38(6) GDPR. It balanced the fact that the personal data processing affected all other citizens, who passed through the areas under surveillance, against the lack of previous violations committed by the data controller. The DPA issued a fine of €26,000 EUR to the Municipality of Policoro.

### Italian Garante sanctions EstEnergy for automated creditworthiness scoring in energy

*Source: Garante per la protezione dei dati personali (Italy), 2026-07-03 — https://overview.legal/posts/184565 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_484/2026*

Facts — EstEnergy S.p.A. (hereinafter, the controller) is an Italian energy company supplying natural gas, electricity and related services. Before entering into contracts, the controller assessed the creditworthiness of potential customers through an internal and an external credit check. The internal assessment involved verifying whether potential customers had outstanding debts not only with the controller but also with Hera Comm S.p.A (hereinafter, the corporate group). The assessment was conducted on behalf of the controller by Hera S.p.A. (hereinafter, the processor), which returned an “OK” or “KO” result. Where the internal assessment returned an “OK”, the controller conducted an external assessment using credit information supplied by Experian Italia S.p.A. and commercial information provided by Cerved Group S.p.A. This information was combined using the “CGS-X” software provided by Major 1 S.r.l. (hereinafter, the software provider and processor). The software generated an integrated creditworthiness score and several underlying sub-scores. On the basis of the result, the controller could refuse to enter into an energy supply contract. The DPA received several complaints from data subjects whose requests for energy supply had been rejected on the basis of their risk profiles. However, when the data subjects contacted the credit and commercial information providers, they were informed that the relevant databases did not contain negative information or adverse events concerning them. The data subjects also submitted access requests under Article 15 GDPR. Although the controller responded within the applicable time limits, it did not provide the CGS-X score, the underlying sub-scores or meaningful information about the logic and criteria used to calculate the profiles. Instead, the controller referred the data subjects to the credit and commercial information providers. Following the complaints, the DPA consolidated the proceedings and initiated an ex officio investigation. It conducted inspections at the premises of the processor, the software provider and processor, and the credit and commercial information providers. The investigation also established that the controller retained the information obtained through the credit checks. Through the processor, the controller subsequently analysed this information to potentially refine the corporate group’s customer rating system. Between 2022 and March 2024, this processing concerned more than one million data subjects. Holding — The DPA held that the controller’s creditworthiness assessment infringed Articles 5(1)(a), (b), (d) and (e), 12, 13, 14, 15 and 28 GDPR. First, the controller failed to provide transparent information about the internal assessment of customers’ previous debts and the sharing of such information within the corporate group. The instructions given to the processor also did not adequately cover these processing operations. The DPA therefore found violations of Articles 5(1)(a), 13, 14 and 28 GDPR. Second, the controller provided incomplete responses to access requests. It did not disclose the CGS-X score, the underlying sub-scores or meaningful information on the logic and criteria used to generate the creditworthiness profile. Referring the data subjects to the credit and commercial information providers did not discharge the controller’s obligations under Articles 12 and 15 GDPR. Third, the controller had not established a justified retention period for the data collected during the external assessment. Applying a general ten-year retention period for accounting records was not shown to be necessary for the creditworthiness assessment, in violation of Article 5(1)(e) GDPR. The DPA also found that reusing credit and commercial information to refine the corporate group’s rating system was incompatible with the original purpose for which the data had been collected. Since the retained information could become outdated, this processing also violated the purpose limitation and accuracy principles under Articles 5(1)(b) and (d) GDPR. The DPA ordered the controller to adopt a compliant access-response template, provide the relevant information to the data subjects involved and establish procedures enabling rectification, human intervention and the possibility to challenge decisions. The controller had six months to demonstrate compliance. Finally, the DPA imposed a €1,400,000 fine, taking into account the seriousness and scale of the infringements, the impact on approximately one million data subjects and the risk of refusal of essential energy services. It also considered the controller’s cooperation, lack of previous relevant infringements and remedial measures as mitigating factors.

### CZECH REPUBLIC DPA: Non-compliance with general data processing principles

*Source: Czech DPA (UOOU), 2019-03-21 — https://overview.legal/posts/46133 — original: https://www.enforcementtracker.com/ETid-18*

Data was not only processed if adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed ('data minimisation') and not only kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed ('storage limitation').

### NAIH fines online store HUF 2M for unclear and incomplete privacy notice

*Source: NAIH (Hungary), 2026-07-22 — https://overview.legal/posts/156361 — original: https://gdprhub.eu/index.php?title=NAIH_(Hungary)_-_NAIH-11443-3/2026*

Facts — The DPA initiated an investigation into the GDPR compliance of an online store (the controller) processing the data of its customers (the data subjects) in April 2025. The processing activities in question included, inter alia, cookies, registration, billing, shipping, consumer complaint, and processing of orders. The privacy notice of the company operating the online store had been in force unchanged from May 2018 to May 2025, and the period under investigation extended from 1 January 2020 to 27 June 2025. Holding — The DPA held that the controller had violated Articles 12(1), 13(1)(c), (d) and (f), and 13(2)(a) GDPR and issued the controller a fine of HUF 2,000,000 (€5,500). In addition, the DPA ordered the controller to bring its data processing operations into compliance with the GDPR and to amend the content of its privacy notice. First, the DPA found an infringement of Article 12(1) GDPR: the structure of the privacy notice was confusing and difficult to follow. The privacy notice also contained incomplete, incorrect, and unnecessary information as well as repetitive details. Based on this, the DPA concluded that the controller had failed to provide data subjects with information regarding the processing of personal data that was sufficiently concise, transparent, intelligible and easily accessible. Second, the DPA held that the controller had also violated Articles 13(1)(c), (d) and (f) GDPR by failing to specify a legal basis for certain processing operations such as the use of cookies, not specifying its legitimate interests when relying on Article 6(1)(f) GDPR as a legal basis, and not providing detailed information regarding the safeguards ensuring the lawfulness of data transfers to the United States. Finally, the DPA found a violation of Article 13(2)(a) GDPR as the controller had also failed to provide the data subjects information on the period for which the personal data processed would be stored.

### AKI (Estonia) - No. 2.1-1/24/397-890-38

*Source: AKI (Estonia), 2026-04-16 — https://overview.legal/posts/53882 — original: https://gdprhub.eu/index.php?title=AKI_(Estonia)_-_No._2.1-1/24/397-890-38*

Facts — OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic. On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had failed to provide all personal data requested. The controller only partially complied after several requests from the DPA. Although the DPA closed the part of the case concerning the access request, it continued investigating the controller’s processing of patients’ personal data when providing Invisalign treatment. The service required the controller to collect and transfer patients’ health data to Align Technology, Inc. However, the contractual documents did not clearly establish whether Align Technology acted as a processor, an independent controller or a joint controller. The controller stated that Align Technology largely determined the conditions of the service, including the consent form and the processing arrangements, and that individual clinics could not unilaterally amend these conditions. The DPA also found that the information provided to patients was incomplete and fragmented. The consent form and privacy information did not clearly explain the legal basis and purposes of processing, the parties involved, data recipients, retention periods, transfers outside the European Union or the safeguards applied to such transfers. Parts of the information were only available in English on external websites. Holding — The DPA held that the controller had failed to demonstrate that the processing carried out in connection with the Invisalign service was lawful and transparent under Articles 5(1)(a) and 5(2) GDPR. First, the DPA found that the parties’ roles had not been properly determined. Under Article 4(7) GDPR, the assessment had to be based on which party actually determined the purposes and means of processing, rather than solely on the contractual description of the relationship. The controller decided whether Invisalign treatment was suitable for a patient and collected the relevant health data. It therefore acted as a controller in relation to the treatment. However, Align Technology exercised significant control over the subsequent processing, including the data collected, the recipients, retention arrangements, the use of other service providers and transfers outside the European Union. The DPA therefore considered that Align Technology could not simply be regarded as a processor acting only on documented instructions under Article 28(3)(a) GDPR. On the available evidence, it was at least a joint controller under Article 26 GDPR. The DPA ordered the controller to review the contractual relationship. If Align Technology acted as a processor, the agreement had to comply with Article 28 GDPR, including the requirements concerning subprocessors under Article 28(2). If the parties were joint controllers, they had to allocate their respective responsibilities under Article 26 GDPR. Second, the DPA found that the consent obtained from patients was invalid. The consent form did not provide sufficient information for patients to understand the processing and therefore did not meet Articles 4(11), 6(1)(a), 7 and 9(2)(a) GDPR. The DPA also noted that healthcare processing may, depending on the operation concerned, rely on Article 6(1)(b) GDPR together with Article 9(2)(h) GDPR. However, the controller had not clearly identified the applicable legal bases for the different processing activities. The privacy information also failed to comply with Articles 12, 13 and 14 GDPR. Patients were required to consult several documents and external websites, some of which contained incomplete or inconsistent information. The controller had therefore not ensured that the information was easily accessible, understandable and available in Estonian. The DPA further referred to Article 25 GDPR when emphasising that the controller had to ensure that the processing arrangements and safeguards complied with the GDPR. Under Article 58(2)(d) GDPR and § 56(1) of the Estonian Personal Data Protection Act, the DPA ordered the controller to clarify the parties’ roles, conclude an Article 26 arrangement or Article 28 agreement, amend the consent form and privacy policy, and publish the required information in Estonian. No administrative fine was imposed. However, failure to comply could result in a penalty payment of €1,000 for each unfulfilled point or subpoint of the order, imposed repeatedly until compliance.

### Selectra S.p.A.: Non-compliance with general data processing principles

*Source: Italian Data Protection Authority (Garante), 2024-07-17 — https://overview.legal/posts/48598 — original: https://www.enforcementtracker.com/ETid-2483*

The Italian DPA has imposed a fine of EUR 80,000 on Selectra S.p.A.. A former employee had lodged a complaint with the DPA on the grounds that the controller was able to access their e-mail inbox even after the termination of the employment relationship. The DPA found that such a long retention period for e-mails (in some cases three years after the termination of the employment relationship) was excessive. The DPA also found that the controller had not provided the data subjects with sufficient

### Company: Non-compliance with general data processing principles

*Source: National Commission for Data Protection (CNPD), 2022-06-30 — https://overview.legal/posts/47422 — original: https://www.enforcementtracker.com/ETid-1307*

The DPA of Luxembourg (CNPD) has imposed a fine of EUR 1,400 on a company. The controller had installed location sensors on a number of cars in its fleet. The purpose of this was to protect the company's assets, optimal fleet management and optimize the workflow, among other things. Some of the location data collected by the controller was stored for a year. The DPA states that this was clearly excessive and not necessary for the purposes of the processing. The DPA considered this to be a violat

### Gyldendal A/S: Non-compliance with general data processing principles

*Source: Danish Data Protection Authority (Datatilsynet), 2022-06-22 — https://overview.legal/posts/47356 — original: https://www.enforcementtracker.com/ETid-1241*

The Danish DPA has fined publisher Gyldendal A/S EUR 134,000. During its investigation, the DPA found that the company had kept the data of approximately 685,000 unsubscribed members of Gyldendal's book clubs longer than necessary. Instead of deleting the data of the deregistered book club members, Gyldendal kept the data in a database. The data of approximately 395,000 of the former members affected were kept for more than 10 years. In addition, the DPA found that Gyldendal did not have a proce

## Recent developments

### CJEU clarifies GDPR principles of purpose limitation and storage limitation

*Source: NL EU Court Expert, 2022-10-30 — https://overview.legal/posts/6247 — original: https://ecer.minbuza.nl/-/eu-hof-verduidelijkt-de-beginselen-van-doelbinding-en-opslagbeperking-uit-de-avg?redirect=%2Fecer%2Fnieuws%3Fq%3Dprivacy%2520OR%2520avg%26f%3D%26t%3D#entry-1209*

The purpose limitation principle does not preclude a controller from capturing and storing in a test database established for testing and error correction purposes personal data previously collected and stored in another database. However, such "further processing" of personal data must be compatible with the specific purposes for which the personal data were originally collected. The principle of storage limitation precludes the retention of personal data in that test database for longer than n

### Collection and retention, by the French blood donation service (EFS), of personal data reflecting applicant’s presumed sexual orientation without proven factual basis: violation of Article 8 of the Convention

*Source: ECHR, 2022-09-08 — https://overview.legal/posts/6283 — original: https://hudoc.echr.coe.int/eng-press#entry-367*

In today’s Chamber judgment1 in the case of Drelon v. France (application no. 3153/16) the
European Court of Human Rights held, unanimously, that there had been:
a violation of Article 8 (right to respect for private and family life) of the European Convention on
Human Rights.

The applications concerned, first, the collection and retention, by the French blood donation service
(EFS) of personal data reflecting the applicant’s presumed sexual orientation – together with the
rejection of his criminal complaint for discrimination – and, second, the refusal of his offers to
donate blood, together with the dismissal by the Conseil d’État of his judicial review application
challenging an order of 5 April 2016 which amended the selection criteria for blood donors.
Addressing the first application, the Court found that the collection and retention of sensitive
personal data constituted an interference with the applicant’s right to respect for his private life.
That interference had a foreseeable legal basis as the authorities’ discretionary power to set up a
health database for such purpose was sufficiently regulated by the then applicable Law of 6 January
1978. Whilst the collection and

### Respondent has no right to erasure of personal data

*Source: IT en Recht, 2023-03-01 — https://overview.legal/posts/6236 — original: https://www.itenrecht.nl/artikelen/geintimeerde-heeft-geen-recht-op-wissing-van-persoonsgegevens#entry-3985*

Hague Court of Appeal February 3, 2023, IT 4226; ECLI:NL:GHDHA:2023:306 (Veilig Thuis v. the respondent) In this case, a man requested the deletion of his personal data processed by Veilig Thuis. The court ruled that Veilig Thuis's processing of the man's data was lawful under the Social Support Act (Wmo) and that the request for data deletion was therefore denied. Safe Home is not obliged to erase the man's personal data in order to comply with the legal obligation under Article 17(1)(e) AVG, b

### CJEU: PNR Directive Valid if Limited to the “Strictly Necessary”

*Source: eucrim, 2022-08-04 — https://overview.legal/posts/6292 — original: https://eucrim.eu/news/cjeu-pnr-directive-valid-if-limited-to-the-strictly-necessary/#entry-388*

> In a landmark ruling of 21 June 2022, the CJEU (Grand Chamber), upheld the EU’s regime to collect and use records of travellers, provided that it is strictly interpreted in line with the EU’s fundamental rights. In addition, indiscriminate processing of the data in cases of flights carried out only within the EU is banned unless there is a threat of terrorism. In general, the passengers’ data must also be deleted after six months at the latest.

### A-G: rechtmatig verzamelde en opgeslagen persoonsgegevens mogen onder voorwaarden tijdelijk in een extra interne databank worden bewaard

*Source: NL EU Court Expert, 2022-04-09 — https://overview.legal/posts/6307 — original: https://ecer.minbuza.nl/-/a-g-rechtmatig-verzamelde-en-opgeslagen-persoonsgegevens-mogen-onder-voorwaarden-tijdelijk-in-een-extra-interne-databank-worden-bewaard?redirect=%2Fecer%2Fnieuws%3Fq%3Dprivacy%2520OR%2520avg%26f%3D%26t%3D#entry-306*

Lawfully collected and stored personal data may be retained in an additional internal database, to the extent that it pursues the same data processing purposes as the original data collection. That is the opinion of Advocate General Pikamäe to the EU Court in response to questions from a Hungarian judge.

## Literature

### HOW GDPR TREATS AUTOMATED DECISION-MAKING

*Source: Journal Scientific and Applied Research, 2025-11-14 — https://overview.legal/posts/132599 — original: https://doi.org/10.46687/jsar.v28i1.435*

This article examines how the General Data Protection Regulation (GDPR) regulates automated decision-making, including profiling, in the context of personal data processing. It analyzes the main provisions of Article 22 of the Regulation, as well as the conditions under which fully automated decisions that produce legal effects or significantly affect data subjects are permitted. The article highlights the rights of data subjects – the right to human intervention, the right to express their poin

### GDPR: A new challenge for personal data protection

*Source: Bankarstvo, 2017-01-01 — https://overview.legal/posts/132473 — original: https://doi.org/10.5937/bankarstvo1704166m*

stručni članak Erne Mraznica Raiffeisen banka ad Beograd erne.mraznica@raiffeisenbank.rs GDPR - NOVI IZAZOV ZAŠTITE PODATAKA O LIČNOSTI Rezime Dana 4. maja 2016. godine objavljena je Opšta Uredba o zaštiti podataka o ličnosti u Sl. glasniku EU, koja će se primenjivati od 25. maja 2018. godine. Cilj propisa je harmonizacija zaštite podataka o ličnosti na nivou EU, veći stepen kontrole za lica čiji se podaci obrađuju i unapređeno upravljanje savremenim rizicima iz ove oblasti. Banke, po prirodi svog poslovanja, spadaju među najveće rukovaoce podataka o ličnosti i u postupku usklađivanja sa obavezama utvrđenih Uredbom biće u prilici da izvrše punu analizu svog postojećeg regulatornog i infrastrukturnog okvira zaštite podataka o ličnosti. Istovremeno, pruža im se prilika da isprave eventualne nedostatke u postojećim procesima, odnosno da značajno povećaju svest organizacije o standardima zaštite podataka o ličnosti, posebno imajući u vidu zaprećene stroge sankcije za slučaj neusklađenosti. Ključne reči : GDPR, podatak o ličnosti, osnovni principi, prava lica, rukovalac, obrada podataka, transfer podataka, sankcije, usklađivanje JEL : F52, G14 doi: 10.5937/bankarstvo1704166M 166 Bankars

### La Quadrature du Net II and Data Retention under Article 15(1) ePrivacy Directive: CJEU Walks a Tightrope on IP Addresses Retention and Access for Public Authorities in Non-Serious Crime

*Source: European Data Protection Law Review, 2025-01-01 — https://overview.legal/posts/132457 — original: https://doi.org/10.21552/edpl/2025/2/17*

La Quadrature du Net II and Data Retention under Article 15(1) ePrivacy Directive Citation for published version (APA): Elisabeth Dekhuijzen, A. (2025). La Quadrature du Net II and Data Retention under Article 15(1) ePrivacy Directive: CJEU Walks a Tightrope on IP Addresses Retention and Access for Public Authorities in Non- Serious Crime. European Data Protection Law Review , 11 (2), 253-258. https://doi.org/10.21552/edpl/2025/2/17 Document status and date: Published: 01/01/2025 DOI: 10.21552/edpl/2025/2/17 Document Version: Publisher's PDF, also known as Version of record Document license: Taverne Please check the document version of this publication: • A submitted manuscript is the version of the article upon submission and before peer-review. There can be important differences between the submitted version and the official published version of record. People interested in the research are advised to contact the author for the final version of the publication, or visit the DOI to the publisher's website. • The final author version and the galley proof are versions of the publication after peer review. • The final published version features the final layout of the paper including

### The impact of the GDPR on background screening in the UK

*Source: Journal of Data Protection Privacy, 2018-02-01 — https://overview.legal/posts/132626 — original: https://doi.org/10.69554/zdnz3309*

This paper seeks to focus on the practical implications of General Data Protection Regulation (GDPR) compliance for employers who conduct pre-employment vetting. While it is primarily focused on the employer, it does also give mention to the vetting companies themselves. The focus is on the main areas of impact of the GDPR and is not an exhaustive analysis of the topic. These include: (1) lawful basis for processing; (2) the use of criminal record checks; (3) contracts and legal obligations of e

### PROTECTION OF DATA SUBJECT RIGHTS IN THE TRANSFER OF PERSONAL DATA BETWEEN DATA CONTROLLERS IN INDONESIA: A COMPARATIVE ANALYSIS OF THE PDP LAW AND THE EU GDPR

*Source: Awang Long Law Review, 2026-01-16 — https://overview.legal/posts/132506 — original: https://doi.org/10.56301/awl.v8i2.1827*

The rapid digital transformation and growth of e-commerce in Indonesia have triggered a high volume of personal data transfers between controllers. while Article 55 of the Personal Data Protection Law (UU PDP) provides only a general authorization without clear technical guidance, creating legal uncertainty and risks to data subject rights. This study analyzes the legal uncertainty of UU PDP’s regulation of controller-to-controller data transfers compared to the EU GDPR and proposes an accountab

## Related topics

- **Retention Period** — https://overview.legal/topics/bewaartermijn
  The duration for which personal data may be stored
- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Data Controller** — https://overview.legal/topics/verwerkingsverantwoordelijke
  The entity that determines purposes and means of processing personal data

---
Generated by overview.legal · https://overview.legal/topics/storage-limitation · 2026-08-22
