# Supervisory Authorities — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/supervisory-authorities
> Sources are cited per item. Verify against the official texts before relying on them.

National data protection authorities and their powers

## Overview

## Legal Framework

Article 51(1) GDPR requires each Member State to establish one or more independent public authorities responsible for monitoring GDPR application, protecting fundamental rights, and facilitating the free flow of personal data within the Union. These supervisory authorities are vested with investigative, corrective, and advisory powers under Article 58, including the authority to issue warnings, reprimands, orders to comply, and administrative fines.

The one-stop-shop mechanism, governed by Articles 56 and 60, designates a lead supervisory authority for cross-border processing activities. The lead authority is determined by the main establishment of the controller or processor in the Union. Article 56 grants the lead authority primary competence to handle cross-border cases, while Article 60 mandates cooperation between the lead authority and other concerned authorities, requiring mutual information exchange and joint operations where relevant.

Article 65 provides a dispute resolution mechanism through the European Data Protection Board (EDPB), enabling binding decisions when supervisory authorities disagree. The exercise of supervisory powers must be subject to appropriate safeguards, including effective judicial remedy and due process, as required under Union and Member State law in accordance with the Charter of Fundamental Rights.

## Key Developments

In *Data Protection Commissioner v. Facebook Ireland Ltd and Maximillian Schrems* (Schrems II), the Court of Justice confirmed that each national supervisory authority bears responsibility for monitoring compliance with EU data protection rules, including verifying whether transfers to third countries meet GDPR requirements. Critically, the Court held that a supervisory authority must examine complaints even where a lead authority has already addressed the matter, particularly when the complaint concerns a decision subject to an adequacy finding that the authority believes violates GDPR obligations.

In *Google LLC v. CNIL*, the Court addressed the territorial scope of supervisory authority decisions, ruling that while EU law does not require de-referencing across all global versions of a search engine, it also does not prohibit a national authority from ordering such removal. The CNIL's competence to weigh privacy rights against fundamental rights standards was affirmed, establishing that national authorities may determine the appropriate territorial reach of their remedies based on domestic fundamental rights protections.

The EDPB has issued Guidelines 06/2022 on amicable settlements between supervisory authorities and controllers, and Guidelines 03/2021 on the dispute resolution procedure under Article 65(1)(a), clarifying the procedural framework for inter-authority disagreements and settlement practices.

## Practical Guidance

- **Identify your lead supervisory authority early.** Determine where your main establishment is located under Article 4(16) GDPR, as this authority will serve as the primary interlocutor for cross-border processing under Article 56. Document this determination, as it affects which national authority handles complaints and enforcement.

- **Prepare for multi-authority engagement.** Under Article 60, concerned authorities from other Member States where data subjects are affected may participate in investigations. Maintain compliance documentation that can be shared across jurisdictions without requiring country-specific reformulation.

- **Monitor EDPB binding decisions.** Article 65 dispute resolution outcomes create binding obligations across all concerned authorities. Track EDPB decisions relevant to your sector, as they establish interpretive standards that all national authorities must follow.

- **Exercise your right to judicial remedy.** Supervisory authority decisions are subject to effective judicial review under Article 78. When facing enforcement action, assess whether procedural safeguards were observed and whether the authority properly coordinated with the lead authority under Articles 60-61.

- **Account for territorial reach in remediation.** Following the *Google v. CNIL* ruling, national authorities may order remedies with extraterritorial effect. When responding to a supervisory authority order, consider whether compliance must extend beyond the ordering authority's Member State.

## Legislation (full text of key provisions)

### Right to lodge a complaint with a supervisory authority

*Source: GDPR, gdpr-art-77-en, 2016-04-27 — https://overview.legal/posts/91328*

### Tasks of the data protection officer

*Source: GDPR, gdpr-art-39-en, 2016-04-27 — https://overview.legal/posts/90744*

### Rules on the establishment of the supervisory authority

*Source: GDPR, gdpr-art-54-en, 2016-04-27 — https://overview.legal/posts/90990*

### Supervisory authority

*Source: GDPR, gdpr-art-51-en, 2016-04-27 — https://overview.legal/posts/90956*

### Cooperation between the lead supervisory authority and the other supervisory authorities concerned

*Source: GDPR, gdpr-art-60-en, 2016-04-27 — https://overview.legal/posts/91098*

### Competence of the lead supervisory authority

*Source: GDPR, gdpr-art-56-en, 2016-04-27 — https://overview.legal/posts/91010*

### Designation of the data protection officer

*Source: GDPR, gdpr-art-37-en, 2016-04-27 — https://overview.legal/posts/90711*

### Right to an effective judicial remedy against a supervisory authority

*Source: GDPR, gdpr-art-78-en, 2016-04-27 — https://overview.legal/posts/91334*

### Position of the data protection officer

*Source: GDPR, gdpr-art-38-en, 2016-04-27 — https://overview.legal/posts/90730*

### General conditions for the members of the supervisory authority

*Source: GDPR, gdpr-art-53-en, 2016-04-27 — https://overview.legal/posts/90980*

## Case law

### CJEU - C‑474/24 - NADA Austria and Others

*Source: GDPRhub, 2026-07-24 — https://overview.legal/posts/108989 — original: https://gdprhub.eu/index.php?title=CJEU_-_C‑474/24_-_NADA_Austria_and_Others*

Facts — Several data subjects were subject to suspension proceedings by the Austrian Anti-Doping Legal Commission (ÖADR). Under Austrian law, the National Anti-Doping Agency (“NADA”) publishes the names of persons who have been suspended on its website. For the duration of the suspension, the website includes information such as the athlete’s name, sport practised, infringement of anti-doping rules, and the duration of the penalty. The ÖADR publishes the same information in a press release, with the addition of the prohibited substances involved. For this summary, both authorities are referred to as the controllers. The data subjects filed a complaint with the DPA on the grounds that the controllers refused their request to cease displaying their names and practised sports. They also argued that the controllers were processing sensitive data within the meaning of Article 9 and 10 GDPR, and that the undifferentiated publication system was incompatible with Article 6(3) GDPR. The DPA dismissed the complaint. In particular, one of the data subjects’ complaints was rejected on the grounds that the relevant data had not been published yet. The data subjects appealed the decision to the Federal Administrative Court (BVwG). The controllers argued that publishing the information in their website was lawful, as it was based on the legal bases of legal obligation (Article 6(1)(c) GDPR) and public interest (Article 6(1)(e) GDPR). The BVwG stayed proceedings and requested a preliminary ruling from the CJEU. The BVwG referred the following questions: Does the GDPR apply to the making information relating to athletes’ anti-doping violations publicly available through websites? If yes: Does information that an individual has committed a specific anti-doping violation fall under the scope of data relating to health within the meaning of Article 9 GDPR? Does the GDPR preclude national legislation from publishing the information mentioned above, if it does not make it possible to infer health data of the person concerned? Does the GDPR require a balancing test between the interests of the data subject and the interest of the general public of being informed of anti-doping violations every time anti-doping violations will be published? Does information that an individual has committed a specific anti-doping violation fall under the scope of data relating to criminal convictions within the meaning of Article 10 GDPR? If yes, must the decisions of the authority processing this data be subject to judicial review? Is filing a complaint before the processing takes place (but was processed during the proceedings) permissible? Or does it become permissible provided that at the time of the complaint there were specific indications that the processing was imminent or would take place in the near future? Advocate General Opinion — The AG gave his opinion on each question separately, with the exception of the third and fourth questions that were answered together. Question 1: Does the GDPR apply to the making information relating to athletes’ anti-doping violations publicly available through websites? — The AG first considered that the GDPR was applicable to this case. Under Article 2(2)(d) GDPR a situation falls outside of the scope of the GDPR when data is processed for the prevention, detection or prosecution of criminal offenses. This is because the Law Enforcement Directive (LED) applies. According to the AG, the GDPR may apply even if personal data relating to criminal convictions is processed if the controllers are not “competent authorities” within the meaning of Article 3(7) LED. If the controllers were competent authorities, the referring court would have to decide if the GDPR applies. The main question the AG addressed is whether the exception under Article 2(2)(a) GDPR applies, meaning the processing falls outside the scope of Union law; here, the AG noted that the exceptions are interpreted narrowly, and may only apply to activities intended to safeguard national security or activities classified in the same category. The AG concluded that the aim of combating anti-doping is not related to national security. The exception did not apply even if the activity fell under the competence of a Member State. Therefore, the GDPR was applicable. Question 2: Does information that an individual has committed a specific anti-doping violation fall under the scope of data relating to health within the meaning of Article 9 GDPR? — The AG first highlighted the sensitive nature of Article 9 GDPR data, which must be interpreted broadly. The AG also noted that the legal basis of the controller does not influence whether the data falls under the scope of health data. Beyond a medical context, the AG opined that the determining factor is whether it is possible to draw inferences about the health status of the data subject. In this case, the AG agreed with the reasoning of the DPA that only specific information relating to the infringements should be considered health data. This is because not all data revealed information related to the data subjects’ health. Specifically, the information regarding the anti-doping tests and its analysis should be considered health data. The AG noted that, while the name of the substance itself may not reveal information on health status, it may be possible to make indirect inferences. However, if the name is not included, the link to the health status of the data subject would be too indirect to fall under the scope of health data. Questions 5 and 6: Does information that an individual has committed a specific anti-doping violation fall under the scope of data relating to criminal convictions within the meaning of Article 10 GDPR, and must the decisions of the authority processing this data be subject to judicial review? — The AG first noted that the GDPR does not prohibit processing this data, but rather subjects it to enhanced scrutiny. The AG assessed whether the processing fell under the scope of Article 10 GDPR based on the three “Engel” criteria in ECtHR case Engel and Others v. the Netherlands. Anti-doping offenses under national law do not fall under the “criminal” classification according to Article 10 GDPR. However, the AG opined that article 10 GDPR applies if the convictions have a punitive purpose and have a degree of severity equivalent to a criminal penalty. This is a matter for the BVwG to decide. In terms of judicial review, the AG stated that the authority at issue is an “official authority” within the meaning of Article 10 GDPR. The wording itself of Article 10 GDPR does not provide for judicial review. However, the AG opined that it must be possible for an act following a decision by an official authority to be subject to judicial review. This is in light of Article 79(1) GDPR and a contextual interpretation of Article 10 GDPR. Questions 3 and 4: Does the GDPR preclude national legislation from publishing the information mentioned in the facts, and does it require a balancing test every time anti-doping violations will be published? — The AG considered, in essence, whether Articles 5(1)(a) and (c), and Article 6(3) GDPR precluded the controllers to publish the data concerned under legal obligation. The AG also considered whether the GDPR requires a case-by-case balancing of interests, or whether the proportionality test provided by the legislator is sufficient. The AG noted that the aim to deter athletes and prevent circumventing of anti-doping rules are legitimate public interest objectives in the context of combating doping in sport. Making this information public online is appropriate in order to achieve the public interest aims, with the exception of referring to the prohibited substance in question. According to the AG, this was not expressly provided for by national law, and is not required to achieve the public interests involved. However, the AG considered the publication of the personal data involved a serious interference with the fundamental rights of the data subjects. While national law provided exceptions on the publication of data (e.g. amateur athletes or vulnerable persons), the AG opined that the publication of personal data for an unlimited amount of time could be considered excessive. Therefore, the AG concluded that making this information publicly accessible is only permitted as long as it is proportionate. Finally, the AG opined that a case-by-case analysis is necessary, as the controllers must comply with data minimisation and accountability principles under the GDPR even if they are designated by national law. Question 7: Is filing a complaint before the processing takes place permissible? — Here, the AG stated that the wording of the GDPR does not seem to preclude a priori a precautionary or preventative approach by the supervisory authorities in handling complaints. Restricting the powers of a DPA to decide on cases involving processing that has already taken place would go against the objectives of the GDPR. Nonetheless, the alleged infringement of the GDPR must be appropriate, and the processing in question cannot be purely hypothetical. In this case, it would be impossible for a controller to erase data that has not been disclosed yet, unless the complaint is interpreted as seeking to prevent the data from being published. The AG stated that it is a matter for the BVwG to decide. The AG noted that the complaint would be inadmissible if it was based on Article 17 GDPR even if the processing is imminent. However, the AG opined that a complaint requesting injunctive relief is potentially admissible under the GDPR and Austrian law in the event of a threat of imminent unlawful interference with data subjects’ rights under the GDPR. This includes requesting the DPA to review a restriction of processing based on Article 18 GDPR before the start of the processing or if the processing has started, as long as the processing is not purely hypothetical. Finally, the AG considered whether a complaint could become admissible a posteriori. Here, the AG opined that it is a matter of the national law system to settle the question, while complying with the principles of effectiveness and equivalence. Holding — The Court held that the GDPR applied to the publication of information concerning anti-doping infringements. Such processing did not fall within the exception under Article 2(2)(a) GDPR, even if anti-doping policy primarily falls within Member State competence. Information that a data subject infringed anti-doping rules and was banned from competitions does not, in principle, constitute health data under Article 9 GDPR. However, it may do so where the publication identifies a prohibited substance or method and, together with other information, allows conclusions to be drawn about the data subject’s health. The Court accepted that combating doping and protecting the fairness and integrity of sport constitute objectives of general interest. Nevertheless, publishing athletes’ identities and sanctions online constitutes a serious interference with their rights. National legislation may therefore require such publication only where the controller can assess, in each case, whether the content and duration of the publication are necessary and proportionate. Publication should not continue longer than strictly necessary and may be disproportionate where a sanction is lengthy or lifelong. The Court also held that Article 10 GDPR did not apply, as the anti-doping infringements formed part of a disciplinary regime and were not criminal in nature. Finally, Article 77 GDPR allows a data subject to lodge a complaint before processing takes place where there are specific indications that the processing is imminent and not merely hypothetical. The DPA must assess the substance of such a preventive complaint.

### Spanish court reviews DPA decision on KFC Spain website privacy information and DPO

*Source: National Court, 2026-07-16 — https://overview.legal/posts/184690 — original: https://gdprhub.eu/index.php?title=AN_-_SAN_3154/2026*

Facts — In May 2021, a data subject lodged a complaint with the DPA against KFC Restaurants Spain, S.L.U., the controller, concerning the processing of personal data through its website. The data subject claimed that the privacy information applicable to users in the EEA was not easily accessible, as the main privacy link led to a global policy. The data subject also alleged that users could not create an account without apparently accepting promotional communications, that the registration form did not correctly link to the privacy policy and that the controller had not appointed a data protection officer. The complaint further identified deficiencies in the privacy information, including insufficient details about the identity of the controller, recipients, international transfers and retention periods. During the investigation, the controller acknowledged that certain links and checkbox descriptions had been incorrectly configured and undertook to correct them. It maintained, however, that its privacy information was provided through several interconnected documents and that it was not required to appoint a DPO. According to the controller, it did not engage in profiling, its marketing communications were based on opt-in consent and the processing of personal data was ancillary to its restaurant business. The DPA found that the information provided on the website was excessively generic and did not comply with Article 13 GDPR. It imposed a €5,000 fine and ordered the controller to bring its website into compliance. The DPA also concluded that the controller’s processing activities required the appointment of a DPO under Article 37(1)(b) GDPR. It imposed a further €20,000 fine and ordered the controller to appoint a DPO. The controller appealed both the sanctioning decision and a subsequent resolution requiring it to demonstrate that it had implemented corrective measures. Holding — The Court dismissed the appeal and upheld the total fine of €25,000. Regarding Article 13 GDPR, the Court found that the controller’s privacy information was excessively generic and did not clearly explain the purposes, legal bases and relevant circumstances of the processing. It also held that the DPA was not limited to investigating only the exact issues identified in the initial complaint. The €5,000 fine was proportionate despite the controller’s subsequent corrective action. Regarding Article 37(1)(b) GDPR, the Court held that the controller was required to appoint a DPO. Although its primary business was the provision of restaurant services, the processing of customer data was inseparable from its online ordering, marketing, loyalty and customer-management activities. The processing also involved regular and systematic monitoring, as the controller continuously collected data such as customer preferences, browsing history, IP addresses, cookies and geolocation for commercial and operational purposes. Considering the number of data subjects, the volume and variety of data, the duration of the processing and its nationwide scope, the Court concluded that the processing was carried out on a large scale.

### VG Düsseldorf - 29 K 3490/24

*Source: Administrative Court Düsseldorf, 2026-06-22 — https://overview.legal/posts/108992 — original: https://gdprhub.eu/index.php?title=VG_Düsseldorf_-_29_K_3490/24*

Facts — A district (the controller), acting as the lower water authority, initiated administrative proceedings after identifying unauthorised riverbank works and a private jetty on two riverside properties. One property belonged to a water utility company, while the other belonged to a municipality and was leased to the data subjects. During those proceedings, the controller shared the data subjects' personal data with various participants, including the owners of the affected properties, other public authorities and a lawyer who claimed to represent the data subjects. The data subjects lodged a complaint with the competent supervisory authority (LDI NRW), alleging that the controller had unlawfully processed and disclosed their personal data. They argued that their personal data had been shared with uninvolved third parties, that the controller had communicated with a lawyer whom they had not authorised, recorded a telephone conversation with an unknown person, and transmitted personal data by unencrypted email. The controller's data protection officer addressed each allegation and provided additional factual information concerning the disputed processing operations. The DPA initially informed the data subjects that no GDPR infringement was apparent, invited them to provide any additional factual information, and explained that it would obtain extracts from the controller's administrative file if there were concrete indications that it contained relevant facts not already available. The data subjects did not identify any additional facts and instead reiterated their legal position that the controller had breached its GDPR accountability obligations. The DPA rejected the complaint, concluding that no GDPR infringement could be established. The data subjects then brought an action before the Verwaltungsgericht Düsseldorf (Administrative Court Düsseldorf), seeking a fresh decision on their complaint on the basis that the DPA had failed to adequately investigate the complaint because it had not obtained the controller's administrative file before reaching its decision. Holding — The court held that Articles 57(1)(f) and 77(1) GDPR give rise to an enforceable right requiring a supervisory authority to investigate a complaint to the extent appropriate in the circumstances before determining whether a GDPR infringement has occurred. Recital 141 GDPR requires the investigation to extend as far as is appropriate in light of the circumstances of the individual case, including the significance of the complaint and the seriousness of the alleged infringement. Applying these principles, the court held that the DPA had adequately investigated the complaint. It had considered each allegation together with the detailed response provided by the controller's data protection officer, invited the data subjects to provide any additional factual information, and explained that it would obtain extracts from the administrative file if concrete indications emerged that further relevant facts required clarification. As the data subjects did not provide any additional facts and there were no objective indications that the information already available was inaccurate or incomplete, the court held that the DPA was not required to obtain the controller's administrative file or undertake further investigations in the absence of concrete indications that additional factual clarification was necessary. The court further held that the DPA had correctly concluded that no GDPR infringement had occurred. The court held that the disputed processing was lawful under Article 6(1)(e) GDPR, read together with Article 6(3) GDPR and § 88 of the German Water Resources Act (WHG), which provided the legal basis for the processing. The court also held that the transmission of personal data by email did not infringe Article 5(1)(f) GDPR because, in the circumstances of the case, transport encryption provided an appropriate level of security.

### BVwG - W254 2321912-1

*Source: Federal Administrative Court, 2026-04-14 — https://overview.legal/posts/125597 — original: https://gdprhub.eu/index.php?title=BVwG_-_W254_2321912-1*

Facts — The data subject, an Austrian citizen residing in Vienna, was enrolled in a distance-learning programme at a German university (the controller). When the data subject enrolled, the controller registered them under the official name shown on their identity document. The data subject experienced gender dysphoria and had chosen a gender-neutral name for themselves which was a different to their legal name. They requested the controller to rectify and replace their official name with their chosen name. They stated that the chosen name reflected better their gender identity. The controller refused the change because the data subject had not provided either an official document proving a legal name change or a dgti supplementary ID card. This is a German supplementary identity document issued by Deutsche Gesellschaft für Trans*- und Inter*geschlechtlichkeit e.V. (dgti e.V.), a German association supporting trans and intersex persons, which may certify, among other things, a chosen first name, pronouns, gender and a current photo. The controller claimed that such a document would allow it to record changes concerning pronouns and first name in its administrative system. On 6 May 2024 the data subject lodged a complaint with the Austrian DPA. They argued that the controller failed to comply with their rectification request under Article 16 GDPR. The data subject also relied on the CJEU’s judgement in Deldits case(C-247/23), which concerned the rectification of gender identity data under Article 16 GDPR. As the controller was established in Germany, the Austrian DPA considered that the Thuringian DPA was the lead supervisory authority for the cross-border processing. The Thuringian DPA held that the controller had not violated Article 16 GDPR. Because the complaint had been lodged with the Austrian DPA and the outcome was a dismissal of the complaint, Article 60(8) GDPR required the supervisory authority with which the complaint had been lodged to adopt the decision and notify the data subject. The data subject then appealed that decision before the Austrian Federal Administrative Court. They argued that the continued use of the official name resulted in misidentification and systematic misgendering. They also stated that the prerequisite to submit further documents proving the name change was excessive and disproportionate. Moreover, the data subject requested that the chosen name should at least be used in non-legally binding university systems, such as the learning platform, email address, campus card and attendance lists. The controller noted that it was legally obligated to identify students and process their data based on official identification documents. This applied, on the one hand, to the transcripts addressed in the administrative proceedings, but also to other academic achievements by students, such as individual coursework, seminar work, or work within interdisciplinary study teams. Holding — The court first confirmed that the cooperation procedure under Article 56 GDPR and Article 60 GDPR had been correctly applied. The Thuringian DPA acted as the lead supervisory authority because the controller was established in Germany. However, since the complaint was dismissed, the Austrian DPA, as the authority with which the complaint had been lodged, adopted the rejection decision pursuant to Article 60(8) GDPR. The court held that there was no violation of Article 16 GDPR. It emphasised that the accuracy of personal data must be assessed in relation to the purpose of the processing. The controller processed the official name in order to identify the student, administer the study programme, issue certificates and academic degrees that aim to be recognized outside the university and certify the student's completion of the program to third parties. The court held that in light of these processing purposes, the processed data of the data subject should be regarded as accurate within the meaning of Article 16 GDPR. Since the data subject had not officially changed their name and had not submitted any official document, the court found that the official name was not inaccurate for the controller’s stated processing purposes. It further stated that the requirement to provide proof of a name change or to present a supplementary identification document was proportionate. The court acknowledged that gender identity is protected as part of private life under Article 8 ECHR. However, it distinguished the case from Deldits. In Deldits, the issue concerned the rectification of gender data in a public register and CJEU held that a data subject requesting the correction of gender identity data may be required to provide relevant and sufficient evidence, taking into account the circumstances of the individual case, in order to establish the inaccuracy of such data. By contrast, this case concerned university administration and academic documents whose effects extend beyond the university and there was no official change of the data subject’s name. Therefore, the court maintained that the controller could continue to use the official name unless the data subject provided official proof of name change. The court further noted that the request to use the chosen name only in non-legally binding systems went beyond the original complaint.

### Judgment of the Court (Grand Chamber) of 10 February 2026.#WhatsApp Ireland Ltd v European Data Protection Board.#Appeal – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 63 – Consistency mechanism – Article 65 – Dispute resolution by the European Data Protection Board – Binding decision – Action for annulment – First paragraph of Article 263 TFEU – Act open to challenge – Fourth paragraph of Article 263 TFEU – Condition that the

*Source: Court of Justice of the European Union, C-97/23, 2026-02-10 — https://overview.legal/posts/132126 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0097*

WhatsApp Ireland Ltd appealed to the Court of Justice (Grand Chamber) seeking to set aside a General Court order that dismissed as inadmissible its action for annulment of EDPB Binding Decision 1/2021, which resolved a dispute among supervisory authorities regarding the Irish DPC's draft decision on WhatsApp. The core issue is whether an EDPB binding decision under Article 65 GDPR is an act open to challenge under Article 263 TFEU that is of direct concern to the controller, thereby giving the controller standing to bring an annulment action directly before the EU courts.

### Judgment of the General Court (Tenth Chamber, Extended Composition) of 16 July 2025.#Lisa Ballmann v European Data Protection Board.#Protection of personal data – Complaint against the controller of personal data of users of an online social network in the European Union – Article 65(1)(a) of Regulation (EU) 2016/679 – Binding decision of the European Data Protection Board – Complainant’s request for access to the file prepared for the purposes of the binding decision – Refusal to grant access –

*Source: General Court, T-183/23, 2025-07-16 — https://overview.legal/posts/132139 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023TJ0183*

In Case T-183/23, Lisa Ballmann sought annulment of the European Data Protection Board's decision refusing her request for access to the file prepared for Binding Decision 3/2022, which concerned Meta Platforms Ireland's processing of personal data on Facebook. The core issue was whether the EDPB's refusal to grant the complainant access to that file—thereby limiting her ability to be heard in the Article 65(1)(a) GDPR dispute resolution procedure—was actionable and compatible with Article 41(2)(b) of the EU Charter of Fundamental Rights. The General Court ruled on the admissibility of the action and the scope of a complainant's procedural rights before the EDPB, with Meta Platforms Ireland intervening in support of the EDPB; no fine was imposed.

### X - BA-6S/221/2019

*Source: Regional Administrative Court Bratislava, 2025-06-25 — https://overview.legal/posts/132105 — original: https://gdprhub.eu/index.php?title=X_-_BA-6S/221/2019*

Facts — Sociálna poisťovňa, the social insurance agency (the controller), processes applications for foreign invalidity pensions and forwards related documents to the social insurance institutions of other EU Member States. A data subject applied for a Danish invalidity pension. On 22 October 2018, the controller sent the data subject's sensitive personal data (including health data, personal identification number and a Danish personal identifier) to the Danish social insurance institution by ordinary (uninsured, untracked) second-class mail rather than by registered mail. The data subject could not confirm delivery and, in November 2018, filed a request with the Slovak DPA alleging that sending sensitive data by ordinary mail, without any proof of dispatch or protection against loss, violated their data protection rights. The controller resent the documents by the same method in December 2018. The DPA's first-instance decision (13 June 2019) found that the controller had violated Article 24(1) in conjunction with Article 32(1) and (2) GDPR, because sending sensitive personal data by ordinary rather than registered mail did not ensure a level of security appropriate to the risk. The DPA ordered the controller to use registered mail for such dispatches going forward and imposed a fine of €50,000. The controller's appeal was rejected, and the Slovak DPA president upheld the first-instance decision. The controller then brought an action before the Regional Administrative Court Bratislava, arguing among other things that: the parcel had in fact been delivered (as confirmed by the Danish institution by email), registered mail offers no greater protection against loss of confidentiality than ordinary mail, only one data subject was concerned and no damage had occurred and the decision's operative part improperly referred to the data of pension applicants generally, not just the individual data subject who had filed the complaint. Holding — The court did not rule on the substance of the security measures dispute, since it found the DPA's decision unreviewable on procedural grounds. First, the court held that the operative part of the DPA's decision was contradictory and imprecise. The administrative proceedings had been triggered by, and the evidence had concerned, an alleged violation of rights of one specific data subject (loss of their parcel). However, the decision extended the finding of violation to the controller's general practice of sending all pension applicants' data by ordinary mail. The court noted that a systemic pattern affecting other data subjects could, at most, be taken into account as an aggravating circumstance when setting the fine, but it could not itself form part of the sanctioned conduct in a proceeding limited to one individual's complaint. Second, the court found that the DPA had failed to properly assess evidence submitted by the controller showing that the parcel had actually been delivered to the Danish institution. The DPA only addressed this evidence for the first time in its written observations in the court proceedings, not in the administrative decision itself, even though the decision's entire reasoning rested on the (contested) premise that the parcel had been lost. Third, the court observed that the fine had been imposed under a provision of the national Data Protection Act that only permits fines for breaches of Articles 25 to 32 GDPR, whereas the DPA's decision had also relied on Article 24(1) GDPR, which is not covered by that provision. Because of these defects, the court annulled the DPA's decision and remanded the case for further proceedings, without addressing the parties' remaining arguments on the merits . The court instructed the DPA to first clearly establish the specific conduct underlying the alleged offence and then decide the case again, addressing all evidence submitted by the controller. The court awarded the controller full reimbursement of costs.

### OVG Saarlouis - 2 A 165/24

*Source: Superior Administrative Court Saarlouis, 2025-05-13 — https://overview.legal/posts/125590 — original: https://gdprhub.eu/index.php?title=OVG_Saarlouis_-_2_A_165/24*

Facts — The data subject was an employee, the controller was the employer. On 14 January 2022, the data subject requested access to personal data from the controller under Article 15 GDPR. They did not respond. On 28 January 2022, the controller terminated the employment. On 17 February 2022, the data subject lodged a complaint with the Data Protection Authority (DPA) under Article 77 GDPR. The data subject alleged that the controller had failed to answer the access request, had taken unauthorised photographs, and had a copy of their vaccination certificate. On 24 February 2022, the employment relationship ended by a court settlement before the Labour Court. The settlement stated that all claims arising from the employment relationship and its termination, whether known or unknown and regardless of their legal basis, were settled, except for employment documents. By entering the settlement, the data subject agreed to not pursue further claims. After the settlement, the controller informed the DPA that it had not received an access request from the data subject, had not taken photographs, and had destroyed the vaccination certificate after the employee left. The data subject continued to raise issues with the DPA, including access to time-tracking data and alleged inaccuracies in the controller’s provided documents. The controller later provided partially redacted time-tracking data. On 26 July 2022, the DPA closed the administrative procedure, as it considered that the data subject no longer had a right of access under Article 15 GDPR because the settlement didn't allow for this claim. The data subject challenged the DPA’s decision before the Administrative Court. On 10 July 2024, the court dismissed the action. The data subject appealed. Holding — First, the court held that the right of access under Article 15 GDPR was, in principle, waivable. Although Article 8(2) CFR protects the right of access, the court noted that data protection law is based on self-determination, including the possibility to consent to processing under Article 7 GDPR. From this, the court inferred that a data subject could also waive the exercise of the right of access. Second, the court clarified that a waiver could not generally cover unknown future data processing. However, a waiver relating to past processing was permissible, especially after the end of an employment relationship, where the imbalance between employee and employer no longer existed. Third, the court held that the specific settlement covered the right of access under Article 15 GDPR. The clause settling all claims arising from the employment relationship and its termination, whether known or unknown and regardless of their legal basis, also included secondary claims linked to the employment relationship, such as access rights concerning employee data. The court considered the wording sufficiently clear and found no requirement to explicitly mention data protection rights. Fourth, the court noted that the data subject already knew about the access request and had raised it before concluding the settlement. Any internal intention not to waive data protection rights was legally irrelevant. Finally, the court upheld the DPA’s decision to close the procedure. Since the data subject had waived the right of access under Article 15 GDPR for past processing through the settlement, the DPA had no obligation to continue enforcement action against the employer.

### CJEU - C‑313/23, C‑316/23 and C‑332/23 - Inspektorat kam Visshia sadeben savet

*Source: GDPRhub, 2025-04-30 — https://overview.legal/posts/158459 — original: https://gdprhub.eu/index.php?title=CJEU_-_C‑313/23,_C‑316/23_and_C‑332/23_-_Inspektorat_kam_Visshia_sadeben_savet*

Facts — Following the expiration of the prescribed time limit for submission of annual declarations of assets of judges, public prosecutors and investigating magistrates and their families, the Inspectorate at the Bulgarian Supreme Judicial Council requested the Sofia District Court to lift the banking secrecy of several judges and public prosecutors, as well as their families. The Inspectorate is comprised of an Inspector General and a panel of ten Inspectors. At the time, the terms of office of the Inspectorate members had been expired for two years and there was no provision in national law limiting the permissible extent of the extention of their duties . The referring Court was unsure as to whether the continuation of the performance of their duties by the Inspectorate past the expiry of their term undermines the independence of the Office under EU law and unsure as to the interplay between the provisions in the Bulgarian Constitution and the GDPR, and referred the following questions: (1) Must the second subparagraph of Article 19(1) TEU, read in conjunction with the second paragraph of Article 47 of [the Charter], be interpreted as meaning that it is per se or under certain conditions an infringement of the obligation incumbent on Member States to provide effective remedies sufficient to ensure independent judicial review for the functions of an authority which can impose disciplinary penalties on judges and has powers to collect data relating to their assets and liabilities to be indefinitely extended after the constitutionally stipulated term of office of that body comes to an end? If such an extension is permissible, under what conditions is that the case? (2) Must Article 2(2)(a) of [the GDPR] be interpreted as meaning that the disclosure of data covered by banking secrecy for the purposes of verifying assets and liabilities of judges and public prosecutors which are subsequently made public constitutes an activity which falls outside the scope of [EU] law? Is the answer different where that activity also includes the disclosure of data relating to family members of those judges and public prosecutors who are not judges or public prosecutors themselves? (3) If the answer to the second question is that [EU] law is applicable, must Article 4(7) of [the GDPR] be interpreted as meaning that a judicial authority which allows another State authority to access data concerning the account balances of judges and public prosecutors and their family members determines the purposes or means of the processing of personal data and is therefore a “controller” for the purposes of the processing of personal data? (4) If the answer to the second question is that [EU] law is applicable and the third question is answered in the negative, must Article 51 of [the GDPR] be interpreted as meaning that a judicial authority which allows another State authority to access data concerning the account balances of judges and public prosecutors and their family members is responsible for monitoring the application of that regulation and must therefore be classified as a “supervisory authority” in relation to those data? (5) If the answer to the second question is that [EU] law is applicable and either the third or the fourth questions are answered in the affirmative, must Article 32(1)(b) of [the GDPR] and Article 57(1)(a) of that regulation be interpreted as meaning that a judicial authority which allows another State authority to access data concerning the account balances of judges and public prosecutors and their families, is obliged, in the presence of [information] concerning a personal data breach committed in the past by the authority to which such access is to be granted, to obtain information on the data protection measures taken and to take into account the appropriateness of those measures in its decision to permit access? (6) If the answer to the second question is that [EU] law is applicable, and irrespective of the answers to the third and fourth questions, must Article 79(1) of [the GDPR], read in conjunction with Article 47 of [the Charter], be interpreted as meaning that, where the national law of a Member State provides that certain categories of data may be disclosed only after permission to do so has been granted by a court, the court so competent must of its own motion grant legal protection to the persons whose data are to be disclosed, by requiring the authority which has applied for access to the data in question and which is known to have committed a personal data breach in the past to provide information on the measures taken pursuant to Article 33(3)(d) of [the GDPR] and their effective application? Holding — Question 1: The Court ruled that that Article 19(1) TEU, read in light of Article 47 of the Charter must be interpreted as meaning that the principle of judicial independence precludes a Member State’s allowing the office holders of judicial body authorised to scrutinize the activities of judges, magistrates and public prosecutors to continue to perform their functions beyond their term where such extension does not have an explicit basis in national law which governs the exercise of such authority and where the extension is not limited in time. Question 2: The Court held that Article 2 of the GDPR must be interpreted as meaning that disclosures to judicial bodies of personal data concerning judges, public prosecutors and investigating magistrates, as well as their family members, with the view of verifying submitted declarations and are published constitutes processing within the material scope of the GDPR. The Court noted that it had previously found (Commission v Poland C-204/21) that neither the fact that information which is the subject of national provisions relates to judges nor the fact that information might have certain links with the performance of their duties is, in itself, sufficient to remove those national provisions from the scope of the GDPR. Although the proper administration of justice and rules relating to the performance and conduct of judges come within the competence of Member States, the processing in question does not fall within that category, nor is it an activity intended to safeguard national security, the Court found. Accordingly, the Court held that the processing in question comes under the material scope of the GDPR. Question 3: The Court held that Article 4(7) of the GDPR must be interpreted as meaning that a court competent to authorise disclosure by a bank to a judicial authority data relating to the bank accounts of judges, public prosecutors and magistrates, and their family members, cannot be classified as a controller under that provision. The Court reasoned that the national legislation determines the scope of such processing, the purpose of the processing and designates the body which is competent to carry it out. The national court, the Court found, confines itself to considering whether the conditions laid down in the national law are met. As such, the Court concluded that the national court determines neither the purposes nor the means and thus cannot be regarded as the controller under the GDPR. It is the designated body, in this case the Inspectorate, which is the controller. Question 4 The Court held that Article 51 of the GDPR must be interpreted as meaning that a court competent to authorise disclosure of personal data to another judicial body does not constitute a supervisory authority in the meaning of that provision. The Court reasoned that the national court has not been designated under Bulgarian law as a supervisory authority, as envisaged in Article 51(1) GDPR. Member States are also obliged to notify the Commission of such provisions adopted or amended pursuant to Chapter VI GDPR. No such notification had been made as to the designation of the national court as supervisory authority. Question 5: As the Court answered both questions 2 & 3 in the negative, no response to question 5 was necessary. Question 6: The Court held that Article 79(1) GDPR, read in light of Article 47 of the Charter, must be interpreted as meaning that a court competent to authorise disclosure of personal data to another judicial body is not required to ensure, of its own volition, the security of the personal data to be disclosed in accordance with the GDPR. This is the case even where the receiving body has, in the past, infringed those provisions of the GDPR. In reaching this conclusion, the Court highlighted the difference between supervisory authorities and their powers under the GDPR and the position of national courts. The Court also highlighted that it is the obligation of the Member State to ensure that practical arrangements have been made for the exercise of the remedies in Articles 77(1), 78(1) & 79(1).

### NSA - III OSK 5037/21

*Source: Supreme Administrative Court, 2025-04-29 — https://overview.legal/posts/125644 — original: https://gdprhub.eu/index.php?title=NSA_-_III_OSK_5037/21*

Facts — In March 2020, the Ombudsman requested the DPA to initiate proceedings regarding several laws that introduced an obligation for judges and prosecutors to declare their membership in an association, which would then be included in a Public Information Bulletin. The declarations of membership included associations to churches, religions, political parties, and functions similar to trade unions. The Ombudsman argued that the law was unconstitutional. In addition, the Ombudsman requested that the DPA issue an order restricting the processing of this data, specifically to prohibit the publication in the bulletin until proceedings were complete. The DPA dismissed the case in April 2020. The DPA stated that Article 6(1) GDPR provided a legal basis for the processing based on a legal obligation (Article 6(1)(c) GDPR) and necessity for the public interest (Article 6(1)(e) GDPR). Finally, the DPA stated that it did not have the competence under Article 57 GDPR to decide on the issue of constitutionality; this was a matter the Ombudsman should have taken to the Constitutional Court. The Ombudsman appealed the decision to the Court of First Instance, arguing that the DPA should have also considered whether the law fulfilled the requirements of public interest and proportionality under Article 6(3) GDPR. The Court upheld the reasoning of the DPA, stating that law has a legal basis in accordance with the GDPR. According to the Court, GDPR does not give the DPA broader powers, since the this was not foreseen by the EU legislator or provided by national law. The Ombudsman appealed the case to the Provincial Administrative Court, who dismissed the case. The Ombudsman requested the Court to reconsider, or alternatively, the Supreme Administrative Court. In addition, the Ombudsman requested the Supreme Administrative Court to refer a preliminary question to the EU Court of Justice (CJEU). The Provincial Administrative Court referred the case to the Supreme Administrative Court. In its complaint, the Ombudsman argued there was a violation of EU and national law due to the DPA’s and Court’s failure to act, as well as the law restricting the judges and prosecutor’s freedom of religion and assembly. The Ombudsman cited CJEU Case C-204/21 (European Commission v. Republic of Poland). In this case, the CJEU found that national legislation requiring judges to submit written declarations of membership in a political party violated Article 7 CFR and Article 8 CFR, as well as Article 6(1)(c) GDPR and Article 6(3) GDPR. In addition, the CJEU stated that it was insufficient for a national law to meet the formal criteria (e.g. by specifying the data processed and the storage period), it also needed to meet the qualitative criteria (public interest purpose and proportionality). Holding — The Supreme Administrative Court first dismissed the request of the Ombudsman to refer a preliminary question to the CJEU, on the basis that the case C-204/21 made the question irrelevant. Nonetheless, the Court stated that it had the obligation to take the CJEU case into account in assessing whether a national law is compatible with EU law, regardless of the issues raised in the appeal. Article 260(1) TFEU obliges the Court to take measures to ensure the implementation of a CJEU judgment stating that a Member State has not complied with its obligations under the Treaties. The Court considered that the Court of First Instance had misinterpreted Article 6(1)(c) GDPR and Article 6(1)(e) GDPR by limiting its interpretation to national laws. According to the Court, the decision did not consider the Constitution or the CFREU (Article 8 CFR and Article 10(1) CFR) and the European Convention of Human Rights (ECHR) (Article 8 ECHR and Article 9(1) ECHR and Article 9(2) ECHR ). The Court followed the reasoning of the CJEU in Case C-204/21 and concluded that the Polish law requiring judges and prosecutors to disclose their affiliation with religious, trade union and political organisations was a serious interference of their rights under the CFREU. The Polish law also violated Article 6(1)(c) GDPR and Article 6(1)(e) GDPR and Article 6(3) GDPR. The Court referred to the CJEU's reasoning in stating that the processing and publishing of judges' and prosecutors' personal data is likely to reveal their worldview and religious beliefs. This data belongs to the special category of personal data that has additional protections in accordance with Article 9(1) GDPR. The Court overturned the decision by the lower courts and the DPA.

### Judgment of the General Court (Tenth Chamber, Extended Composition) of 29 January 2025 (Extracts).#Data Protection Commission v European Data Protection Board.#Protection of personal data – Article 65(1)(a) of Regulation (EU) 2016/679 – Binding decision instructing a lead supervisory authority to broaden the scope of its investigation and issue a new draft decision – Competence of the European Data Protection Board.#Joined Cases T-70/23, T-84/23 and T-111/23.

*Source: General Court, T-70/23, 2025-01-29 — https://overview.legal/posts/132152 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023TJ0070*

The Irish Data Protection Commission (DPC) challenged provisions of EDPB Binding Decisions 3/2022, 4/2022, and 5/2022, arguing the EDPB exceeded its competence under Article 65(1)(a) GDPR by requiring the DPC to broaden its investigation into Facebook, Instagram, and WhatsApp and issue new draft decisions. The core legal issue was whether the EDPB, in the consistency mechanism context, can compel a lead supervisory authority to conduct additional investigations and produce new draft decisions beyond addressing the specific relevant and reasoned objections raised by concerned supervisory authorities. The General Court dismissed the DPC's actions, upholding the EDPB's authority to issue binding decisions instructing the lead supervisory authority to carry out further investigation and issue new draft decisions.

### Judgment of the Court (First Chamber) of 9 January 2025.#Österreichische Datenschutzbehörde v F R.#Request for a preliminary ruling from the Verwaltungsgerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 57(1)(f) and Article 57(4) – Tasks of the supervisory authority – Concepts of a ‘request’ and ‘excessive requests’ – Charging of a reasonable fee or refusal to act on requests in the e

*Source: Court of Justice of the European Union, C-416/23, 2025-01-09 — https://overview.legal/posts/132153 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0416*

In Case C-416/23, the Court of Justice of the European Union (First Chamber) ruled on a preliminary reference from the Austrian Supreme Administrative Court concerning the Austrian Data Protection Authority's (DSB) refusal to act on a complaint from individual F R regarding an alleged infringement of his right of access. The Court interpreted Article 57(4) and Article 77(1) of the GDPR, addressing the concepts of a "request" and "excessive requests" and the criteria guiding a supervisory authority's choice between charging a reasonable fee or refusing to act on manifestly unfounded or excessive requests. No fine was imposed, as the ruling solely provides interpretive guidance on the supervisory authority's tasks and obligations under the GDPR.

## Guidance

### EDPB Document Setting Forth a Co-Operation procedure for the approval of Binding Corporate Rules for controllers and processors

*Source: EDPB, edpb-document-procedure-approval-bcr-en-0, 2025-03-19 — https://overview.legal/posts/50655 — original: https://www.edpb.europa.eu/documents/procedure/edpb-document-setting-forth-a-co-operation-procedure-for-the-approval-of_en*

EDPB, EDPB Document Setting Forth a Co-Operation procedure for the approval of Binding Corporate Rules for controllers and processors, 2025.

### Opinion 11/2023 on the draft decision of the competent supervisory authority of Sweden regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR

*Source: EDPB, opinion-112023-on-the-draft-decision-of-the-competent-en, 2023-07-11 — https://overview.legal/posts/125841 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-112023-on-the-draft-decision-of-the-competent_en*

1 Adopted Opinion 11/2023 on the draft decision of the competent supervisory authority of Sweden regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR Adopted on 11 July 2023 2 Adopted 3 Adopted The European Data Protection Board Having regard to Article 63, Article 64 (1)(c), (3)-(8) and Article 41 (3) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural…

### Guidelines 8/2022 on identifying a controller or processor's lead supervisory authority

*Source: EDPB, edpb-guidelines-for-identifying-a-controller-or-processors-lead-supervisory-authority, 2023-04-17 — https://overview.legal/posts/38046 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-82022-on-identifying-a-controller-or-processors-lead-supervisory_en*

The European Data Protection Board (EDPB) adopted Guidelines 8/2022 on identifying a controller or processor's lead supervisory authority, providing updated guidance on the criteria for determining main establishment and the one-stop-shop mechanism under the GDPR. The guidelines address key concepts including cross-border processing, the "substantially affects" threshold, and the steps controllers and processors must follow to identify their lead supervisory authority. This document serves as interpretive guidance with no fines or enforcement outcomes, replacing the prior WP244 guidelines endorsed by the EDPB in 2018.

### Opinion 03/2023 on the draft decision of the competent supervisory authority of Romania regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR

*Source: EDPB, opinion-032023-on-the-draft-decision-of-the-competent-en, 2023-02-17 — https://overview.legal/posts/125871 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-032023-on-the-draft-decision-of-the-competent_en*

1 Adopted Opinion 03/2023 on the draft decision of the competent supervisory authority of Romania regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR Adopted on 3 February 2023 2 Adopted 3 Adopted The European Data Protection Board Having regard to Article 63, Article 64 (1)(c), (3)-(8) and Article 41 (3) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of…

### Opinion 02/2023 on the draft decision of the competent supervisory authority of Latvia regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to Article 41 GDPR

*Source: EDPB, opinion-022023-on-the-draft-decision-of-the-competent-en, 2023-02-17 — https://overview.legal/posts/125870 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-022023-on-the-draft-decision-of-the-competent_en*

1 Adopted Opinion 02/2023 on the draft decision of the competent supervisory authority of Latvia regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to Article 41 GDPR Adopted on 3 February 2023 2 Adopted 3 Adopted The European Data Protection Board Having regard to Article 63, Article 64 (1)(c), (3)-(8) and Article 41 (3) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of…

### Opinion 1/2023 on the draft decision of the competent supervisory authority of Croatia regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to Article 41 GDPR

*Source: EDPB, opinion-12023-on-the-draft-decision-of-the-competent-en, 2023-02-17 — https://overview.legal/posts/125874 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-12023-on-the-draft-decision-of-the-competent_en*

Adopted 1 Opinion 1/2023 on the draft decision of the competent supervisory authority of Croatia regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to Article 41 GDPR Adopted on 3 February 2023 Adopted 2 Table of c ontents 1 Summary of the Facts................................................................................................................... 4 2 Assessment…

### Opinion 14/2022 on the draft decision of the competent supervisory authority of Bulgaria regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR

*Source: EDPB, opinion-142022-on-the-draft-decision-of-the-competent-en, 2022-07-04 — https://overview.legal/posts/125933 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-142022-on-the-draft-decision-of-the-competent_en*

1 Adopted Opinion 14 / 20 22 on the draft decision of the competent supervisory authority of Bulgaria regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR Adopted on 4 July 2022 2 Adopted 3 Adopted The European Data Protection Board Having regard to Article 63, Article 64 (1)(c), (3) - (8) and Article 41 (3) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of…

### Opinion 16/2022 on the draft decision of the competent supervisory authority of Slovenia regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR

*Source: EDPB, opinion-162022-on-the-draft-decision-of-the-competent-en, 2022-07-04 — https://overview.legal/posts/125924 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-162022-on-the-draft-decision-of-the-competent_en*

1 Adopted Opinion 16 / 20 22 on the draft decision of the competent supervisory authority of Slovenia regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR Adopted on 4 July 2022 2 Adopted 3 Adopted The European Data Protection Board Having regard to Article 63, Article 64 (1)(c), (3) - (8) and Article 41 (3) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of…

## Enforcement decisions

### Belgian DPA rules on competence in cross-border cookie consent complaint involving

*Source: APD/GBA (Belgium), 2022-01-21 — https://overview.legal/posts/122841 — original: https://gdprhub.eu/index.php?title=APD/GBA_(Belgium)_-_11/2022*

Facts — The respondent owns a website 'YourOnlineChoices', through which data subjects can control their ad experience online. When browsing the web and visiting different websites, they can control which non-essential (e.g. for advertising purposes) cookies they accept or refuse. If they choose to turn off interest-based advertising, they still see advertisements on the internet, but these are not adapted to their suspected interests or preferences. The Belgian DPA received a complaint via the Internal Market Information (IMI) system from the Berlin DPA regarding the illegitimate use of cookies on a website. More specifically, the complainant stated that (i) the tool for selecting advertising preferences did not work (cookie opt-out option for third parties does not work) and that consent was therefore not freely given; (ii) the website forced users to accept cookies in order to be able to select their advertising preferences. Holding — On cross-border processing - competence of the Belgian DPA The DPA first had to determine whether it was competent. According to Article 56 GDPR "the supervisory authority of the main establishment[...] of the controller shall be competent to at as lead supervisory authority for cross-border processing[...]". The Belgian DPA was found to be competent because the defendant had its sole place of business in Belgium, although its activities were deemed to substantially affect or be likely to affect data subjects in several Member States, including Germany. Obligation to set cookies in order to select advertising preferences on the website & "Cookie wall" practice (violation of Article 7 GDPR) - Complaint not upheld Second, the DPA had to determine whether the operator of the website lawfully placed a cookie on the complainant's device. The complainant argued that their consent was not freely given because they could not have used the website without giving it. Indeed, in its recent guidelines, the EDPB condemned the practice of making the provision of a service or access to a website conditional on accepting the placement of non-necessary cookies on the user's device. However, in this case the cookie in question was strictly necessary for the functioning of the website. The respondent indeed showed that the fact that the cookie needed to be placed in order to use certain parts of the website (namely the homepage / terms and conditions / Protecting your privacy-page) and thus the legal basis in order to process this personal data and place this cookie was not consent, but legitimate interest of the data controller (Article 6(1)(f) GDPR) Use of cookies without prior information given to the user (violation of the transparency principle - Article 5 GDPR) - Complaint upheld Third, the DPA assessed whether it was lawful to place the aforementioned cookie without providing certain information about such processing. The DPA restated that the purpose of the transparency principle is that the data subject should be able to determine what the scope and consequences of the processing encompass before it occurs. Thus, controllers are required to at least provide information on (i) the duration of the operation of cookies and (ii) whether the cookie is a first or third party one. When viewing the website, the DPA's investigation showed that even before any information could be delivered to the user, a cookie was loaded in the browser because it was otherwise technically impossible to display the necessary information in the user's language. The DPA held that due to the absence of language selection by the user, it would have been appropriate to display the information regarding the use of cookies in English, a widespread language commonly used by other websites. Thus, the Belgian DPA issued a reprimand to the operator of 'YourOnlineChoices.com' for violating Article 12 GDPR and Article 13 GDPR and ordered them to comply with their processing register - specifically to mention the third party countries personal data was sent to. Additionally, the Belgian DPA also shares some interesting insights regarding the processing of cookies: definition of 'trackers'; different types of cookies; valid consent under GDPR and ePrivacy Directive - transparency obligations

### ANSPDCP (Romania) - Fine against Ascendex Technology SRL

*Source: ANSPDCP (Romania), 2026-07-09 — https://overview.legal/posts/83474 — original: https://gdprhub.eu/index.php?title=ANSPDCP_(Romania)_-_Fine_against_Ascendex_Technology_SRL*

Facts — The Romanian DPA (ANSPDCP) launched an investigation into the cryptocurrency exchange platform Ascendex Technology SRL (the controller). The DPA was notified by the French DPA (CNIL) regarding a complaint filed by a data subject in France against the controller. Since the controller’s sole establishment was in Romania and its processing substantially affected data subjects in multiple Member States, which constituted cross-border processing under Article 4(23)(b) GDPR, the Romanian DPA accepted its role as the lead supervisory authority. During the investigation, the DPA found that the controller handled the data subject’s erasure request only after approximately 12 months. It noted that the controller did not provide a final response regarding the fulfilment of the request nor justified the delay. The DPA also found that, in similar erasure requests submitted by other data subjects from various EU Member States and from outside the EU, the controller had taken up to 37 months to process the requests. Holding — The DPA held that the controller violated Article 12(1) GDPR and Article 12(3) GDPR, read in conjunction with Article 17 GDPR and fined it RON 57,839 (€11,000). Furthermore, it ordered the controller, under Article 58(2)(c) GDPR and Article 58(2)(d) GDPR, to provide an appropriate response to the data subject, as well as to other data subjects in similar situations, regarding the handling of their erasure requests. It also ordered the controller to implement measures for the regular staff training on the correct, clear, transparent and timely handling of data subject requests within the statutory deadlines. In addition, the DPA informed the other concerned supervisory authorities, including the French DPA, of the investigation’s findings and the proposed measures, in accordance with the cooperation procedure under Article 60 GDPR.

### EDPB - Binding Decision 1/2026

*Source: EDPB, 2026-05-28 — https://overview.legal/posts/144037 — original: https://gdprhub.eu/index.php?title=EDPB_-_Binding_Decision_1/2026*

Facts — On 10 August 2021, a data subject represented by noyb lodged a complaint with the Austrian DPA against Vlaamse Radio- en Televisieomroeporganisatie (VRT), the controller. The complaint concerned the controller’s cookie banner and alleged infringements of Articles 5(1)(a), 6(1)(a), 12(1), 12(2) and 13(1)(c) GDPR, as well as Article 5(3) ePrivacy Directive. It formed part of a wider project involving similar cookie banner complaints submitted by noyb across the EEA. The Austrian DPA transferred the complaint to the Belgian DPA, which acted as the lead supervisory authority. In its draft decision, the DPA proposed dismissing the complaint without examining its merits. It considered that the data subject and noyb had abused the rights provided under Articles 77 and 80(1) GDPR. The DPA relied on factors including the standardised and partly automated preparation of the complaints, noyb’s role in selecting the targeted controllers, the relationship between the data subject and noyb, and the broader strategic objectives pursued by the organisation. It considered that both the objective and subjective elements required to establish an abuse of rights were present. The Austrian DPA raised a relevant and reasoned objection under Article 60(4) GDPR. It argued that the circumstances did not demonstrate an abuse of rights and requested that the complaint be examined on its merits in accordance with Article 57(1)(f) GDPR. As the DPA did not follow the objection, it referred the dispute to the EDPB under Article 65(1)(a) GDPR. Holding — The EDPB first held that it was competent to decide the dispute. Its powers under Article 65(1)(a) GDPR are not limited to determining whether a controller infringed the GDPR. They also cover disputes concerning whether an action envisaged by a supervisory authority, including the dismissal of a complaint, complies with the GDPR. The EDPB found that the Austrian DPA’s objection met the requirements of Article 4(24) GDPR. The objection was directly connected to the draft decision, proposed a different outcome and sufficiently demonstrated the risks that the dismissal would create for data subjects’ rights and the consistent application of the GDPR. On the merits, the EDPB recalled that the prohibition of abuse of rights must be interpreted strictly, particularly where its application may restrict the fundamental right to data protection and the rights provided by Articles 77 and 80(1) GDPR. The supervisory authority alleging abuse bears the burden of establishing both its objective and subjective elements on the basis of sufficient evidence. Regarding the objective element, the EDPB acknowledged that noyb had organised a project involving predefined selection criteria, standardised complaints and automated tools. However, the data subject had validly mandated noyb under Article 80(1) GDPR and had lodged a complaint concerning an alleged infringement of their own data protection rights. Consequently, the objectives of Articles 77 and 80(1) GDPR had been fulfilled rather than circumvented. Regarding the subjective element, the EDPB found no evidence that the complaint had been submitted to obtain an undue advantage unrelated to the purposes of the GDPR. The objectives pursued by noyb could not be separated from those of the data subject merely because the organisation had played a leading role in preparing the complaint. Nor was there evidence that the data subject or noyb had sought compensation or another financial benefit. The EDPB therefore concluded that the data subject had not abused the right to lodge a complaint under Article 77 GDPR or the right to be represented under Article 80(1) GDPR. It instructed the DPA not to dismiss the complaint on that basis, to assess it on its merits and to submit a new draft decision to the supervisory authorities concerned under Article 60(3) GDPR.

### Modern Barber: Insufficient cooperation with supervisory authority

*Source: Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), 2019-11-26 — https://overview.legal/posts/46263 — original: https://www.enforcementtracker.com/ETid-148*

The company did not comply with measures ordered by the National Supervisory Authority.

### Entrepreneur: Insufficient cooperation with supervisory authority

*Source: Polish National Personal Data Protection Office (UODO), 2025-07-28 — https://overview.legal/posts/48879 — original: https://www.enforcementtracker.com/ETid-2764*

The Polish DPA has imposed a fine of EUR 4,400 on an Entrepreneur. The controller failed to adequatly react to a request from the DPA.

### Dincă Viorel George: Insufficient cooperation with supervisory authority

*Source: Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), 2025-06-18 — https://overview.legal/posts/48837 — original: https://www.enforcementtracker.com/ETid-2722*

The Romanian DPA has imposed a fine of EUR 200 on a private individual. The controller failed to react to communication from the supervisory authority.

### Persónuvernd (Iceland) - 2020061979

*Source: Persónuvernd (Iceland), 2022-06-29 — https://overview.legal/posts/6316 — original: https://gdprhub.eu/index.php?title=Persónuvernd_(Iceland)_-_2020061979*

Facts — The Icelandic DPA started an investigation into a genetic research company. More specifically, to assess the company's Data Protection Officer (DPO), as well as the performance of the DPO's tasks. The DPA requested information from the company to determine if and how the company's DPO was compatible with Article 38 GDPR. The DPA stated that the decision to investigate the DPO was made with the intention of ensuring compliance, not because it assumed the requirements of the GDPR were not being followed. The DPA wrote two letters, but the company did not respond to any of them within the prescribed deadlines. After a phone call, the DPA received a response almost two months after the first letter had been sent. Holding — After reviewing the responses from the controller, the Icelandic DPA concluded that there were no violations in relation to the obligations to appoint a DPO (Article 37), to involve the DPO in relevant matters (Article 38(1)), and to provide the DPO with the necessary resources (Article 38(2)). However, the DPA held that the controller violated the obligation to ensure the DPO's independence pursuant to Article 38(3). The acting DPO at the time of the investigation also held the position of deputy CEO, senior lawyer and board member. The DPA held that that could lead to a conflict of interest. The current DPO also held the position of senior lawyer. The DPA held that this also constituted a conflict of interest. The DPA instructed the controller to ensure that the acting DPO would not be responsible for other tasks and duties that may lead to a conflict of interest. The DPA further noted that the despite the delayed answers, it would not impose a fine, taking into account the fact that the information was eventually received as well as the COVID-19 outbreak.

### FUENSANTA S.L.: Insufficient cooperation with supervisory authority

*Source: Spanish Data Protection Authority (aepd), 2021-11-23 — https://overview.legal/posts/47028 — original: https://www.enforcementtracker.com/ETid-913*

The controller failed to provide information requested by the Spanish DPA (AEPD) for investigative purposes.

## Recent developments

### ANSPDCP (Romania) - ANSPDCP (Romania) - Fine against Poliserv JG (PJG) SRL

*Source: GDPRhub, 2026-08-21 — https://overview.legal/posts/291402 — original: https://gdprhub.eu/index.php?title=ANSPDCP_(Romania)_-_ANSPDCP_(Romania)_-_Fine_against_Poliserv_JG_(PJG)_SRL*

The Romanian DPA imposed a fine of RON 15,728 (€ 3,000) on a car dealer for failing to implement appropriate technical and organisational measures in order to guarantee the security of its processing, in breach of Article 32 GDPR. English Summary. Facts. A personal data breach occurred because of a cyberattack made possible through a phishing method that stole the credentials of a controller account with administrator privileges. Thus, the personal data of individual customers (at least their fi

### Datatilsynet (Norway) - 23/00435-62

*Source: GDPRhub, 2026-08-21 — https://overview.legal/posts/291399 — original: https://gdprhub.eu/index.php?title=Datatilsynet_(Norway)_-_23/00435-62*

The DPA found that pharmaceutical company unlawfully continued using an influencer’s personal data after their contract expired and fined it NOK 205,000 for breaching its duty to cooperate under Article 31 GDPR. English Summary. Facts. Lab Pharma AS, the controller, is a Norwegian manufacturer of dietary supplements which markets and sells its products online. In 2016, an influencer, the data subject, entered into an agreement with the controller under which she would promote its products on her

### DPC (Ireland) - IN-19-9-4

*Source: GDPRhub, 2026-08-18 — https://overview.legal/posts/291263 — original: https://gdprhub.eu/index.php?title=DPC_(Ireland)_-_IN-19-9-4*

The DPA fined the HSE €300,000 for inadequate security measures which enabled a ransomware attack affecting health data of 84,000 people, alongside violations of Articles 28, 30 and 34 GDPR.The DPA fined the HSE €300,000 for inadequate security measures which enabled a ransomware attack affecting health data of 84,000 people, alongside violations of Articles 28, 30 and 34 GDPR. English Summary. English Summary On 8 October 2019, the DPA initiated an own-volition inquiry to determine whether the

### VG Berlin - 42 K 73/25

*Source: GDPRhub, 2026-08-18 — https://overview.legal/posts/291280 — original: https://gdprhub.eu/index.php?title=VG_Berlin_-_42_K_73/25*

A court annulled a reprimand issued by the DPA and held that requiring a photo ID to access outdoor swimming pools and video surveillance in the entry and exit areas constituted necessary processing for a task carried out in the public interest.A court held that requiring a photo ID to access outdoor swimming pools and video surveillance in the entry and exit areas were necessary to prevent crimes and provide safety to swimmers and staff members. Therefore, the court considered the processing la

### GDPRhub style guide

*Source: GDPRhub, 2026-08-18 — https://overview.legal/posts/291292 — original: https://gdprhub.eu/index.php?title=GDPRhub_style_guide*

Cleared up "the DPA" and "million"/"billion" Example: The Romanian DPA fined Facebook Romania RON 25,000 (€5,000).Example: The Romanian DPA fined Facebook Romania RON 25,000 (€5,000). If the amount is over a million, please use "m" for million and "bn" for billion (in the English sense, i.e. thousand million (1,000,000,000). Consistent indication of dates. Consistent indication of dates ::Example: The German Bundesdatenschutzgesetz (BDSG) becomes the "German Federal Data Protection Act (&#039;&#

## Literature

### GDPR Implementation Series ∙ Belgium: Substantial Reform of Supervisory Authority and Framework Implementing Act Finally Adopted

*Source: European Data Protection Law Review, 2018-01-01 — https://overview.legal/posts/132496 — original: https://doi.org/10.21552/edpl/2018/3/14*

### Commercial, but Legitimate Interest: The Court of Justice Calls the Dutch Data Protection Authority to Order

*Source: European Data Protection Law Review, 2025-01-01 — https://overview.legal/posts/132586 — original: https://doi.org/10.21552/edpl/2025/1/19*

### Portugal ∙ Profiling the Portuguese Data Protection Officer in the Context of GDPR

*Source: European Data Protection Law Review, 2022-01-01 — https://overview.legal/posts/132571 — original: https://doi.org/10.21552/edpl/2022/4/13*

### Complete Independence of national Data Protection Supervisory Authorities: About persons, czars and data governance in Belgian debates

*Source: European Law Blog, 2021-12-24 — https://overview.legal/posts/132495 — original: https://doi.org/10.21428/9885764c.7197cf15*

### `Data Protection, Privacy Regulators and Supervisory Authorities` by Jacob Kornbeck

*Source: Journal of Data Protection Privacy, 2021-03-01 — https://overview.legal/posts/132492 — original: https://doi.org/10.69554/jyow6251*

## Tools

### GDPRhub — case law and DPA decision wiki

*Source: noyb, 2026-07-17 — https://overview.legal/posts/125627 — original: https://gdprhub.eu/*

Open wiki by noyb collecting court decisions and DPA decisions on the GDPR from all over Europe, each with structured metadata (authority, articles, fine, date), an English summary and a machine translation of the full decision.

### CNIL record of processing activities template

*Source: CNIL, 2026-07-17 — https://overview.legal/posts/125621 — original: https://www.cnil.fr/en/record-processing-activities*

The French DPA's explanation of the Article 30 record-keeping obligation with a simplified downloadable register template aimed at SMEs: one sheet per processing activity covering purposes, data categories, recipients, transfers, retention and security measures.

### CNIL GDPR guide for developers

*Source: CNIL, 2026-07-04 — https://overview.legal/posts/53810 — original: https://github.com/LINCnil/GDPR-Developer-Guide*

Open-source best-practice guide by the French DPA translating GDPR obligations into concrete development practice: data minimisation in code, managing consent, securing data flows, retention, and preparing for data subject rights — organised in 16 practical sheets.

### CNIL PIA software (privacy impact assessment tool)

*Source: CNIL, 2026-07-04 — https://overview.legal/posts/53803 — original: https://www.cnil.fr/en/privacy-impact-assessment-pia*

Free, open-source software by the French DPA that guides controllers through a data protection impact assessment (DPIA) as required by Article 35 GDPR: contextualise the processing, assess necessity/proportionality, evaluate risks and document measures. Available as desktop app and self-hostable web version, in many languages.

### CookieViz — visualise web tracking (CNIL)

*Source: CNIL, 2026-07-17 — https://overview.legal/posts/125634 — original: https://github.com/LINCnil/CookieViz*

Open-source tool by the French DPA's innovation lab that visualises in real time which third parties are notified while you browse: cookies set, trackers loaded and the network of data flows between sites — useful for demonstrations and cookie audits.

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Processing Agreement** — https://overview.legal/topics/verwerkersovereenkomst
  Contract between controller and processor defining processing terms
- **Data Controller** — https://overview.legal/topics/verwerkingsverantwoordelijke
  The entity that determines purposes and means of processing personal data

---
Generated by overview.legal · https://overview.legal/topics/supervisory-authorities · 2026-08-22
