# Consent — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/toestemming
> Sources are cited per item. Verify against the official texts before relying on them.

Freely given, specific, informed indication of data subject wishes

## Overview

## Legal Framework

Consent under the GDPR is governed primarily by Articles 4(11), 6(1)(a), 7, and 8. Article 4(11) defines consent as a freely given, specific, informed, and unambiguous indication of the data subject's wishes, expressed by a statement or clear affirmative action. Article 7 sets the conditions for valid consent: the controller must demonstrate that consent was obtained, consent must be as easy to withdraw as to give, and where processing is conditional on consent, the controller must be able to show that the data subject's freedom of choice was genuine. Article 8 imposes additional protections for children below the age of 16 (or lower where Member State law permits) in the context of information society services offered directly to children.

The requirement that consent be freely given means the data subject must have a real and free choice — the ability to refuse or withdraw consent without suffering adverse consequences. Consent cannot be considered freely given where separate consent cannot be given for different personal data processing operations that serve different purposes. This granularity requirement prevents bundling: a data subject must be able to consent to one processing activity while declining another.

## Key Developments

The CJEU's ruling in *Fashion ID GmbH & Co. KG v. Verbraucherzentrale NRW* (C-40/17) established that where multiple parties are involved in processing — such as a website operator embedding a social plugin — consent need only be obtained by a controller for the specific operations in respect of which it determines the purposes and means. This narrows the scope of consent obligations for joint controllers to their actual sphere of control, but also clarifies that each controller bears responsibility for informing data subjects about the processing it alone determines.

In *Schrems II* (C-311/18), the CJEU confirmed that Article 49(1)(a) GDPR permits transfers to third countries based on the data subject's explicit consent, but only after the data subject has been informed of the specific risks arising from the absence of an adequacy decision or appropriate safeguards. This creates a heightened informed-consent standard for international data transfers.

Enforcement actions confirm that consent failures attract significant penalties. The ICO fined MediaLab.AI €284,450 for failures on the Imgur platform, while the Hellenic DPA imposed an €80,000 fine on ONE WAY Private Company. The EDPB's Guidelines 05/2020 on consent remain the central interpretive reference, supplemented by Guidelines 06/2020 addressing the interplay between PSD2 and the GDPR.

## Practical Guidance

- **Implement granular consent mechanisms**: Separate consent toggles must be provided for each distinct processing purpose. Pre-ticked boxes, silence, or inactivity never constitute valid consent under Article 4(11).
- **Document the consent record**: Under Article 7(1), the controller bears the burden of demonstrating valid consent. Maintain logs showing what was presented, when consent was given, what information accompanied it, and the specific purposes acknowledged.
- **Ensure withdrawal is frictionless**: Article 7(3) requires that withdrawal be as easy as giving consent. A withdrawal mechanism must be accessible at all times, without requiring account login barriers or multi-step processes disproportionate to the original consent flow.
- **Apply heightened standards for transfers**: Where relying on Article 49(1)(a) for third-country transfers, obtain explicit (not merely unambiguous) consent and document that the data subject was specifically informed of the risks of transfers without adequacy decisions or safeguards.
- **Verify age for information society services**: Under Article 8, implement reasonable age verification measures for services offered to children, and obtain parental authorization where the data subject is below the applicable national age threshold.

## Legislation (full text of key provisions)

### Conditions applicable to child's consent in relation to information society services

*Source: GDPR, gdpr-art-8-en, 2016-04-27 — https://overview.legal/posts/90292*

### Conditions for consent

*Source: GDPR, gdpr-art-7-en, 2016-04-27 — https://overview.legal/posts/90282*

### Informed consent to participate in testing in real world conditions outside AI regulatory sandboxes

*Source: AI Act, aiact-art-61-en, 2024-06-12 — https://overview.legal/posts/92997*

### Exceptions

*Source: ePrivacy, eprivacy-art-10-en, 2002-07-12 — https://overview.legal/posts/132202*

ExceptionsMember States shall ensure that there are transparent procedures governing the way in which a provider of a public communications network and/or a publicly available electronic communications service may override:the elimination of the presentation of calling line identification, on a temporary basis, upon application of a subscriber requesting the tracing of malicious or nuisance calls. In this case, in accordance with national law, the data containing the identification of the calling subscriber will be stored and be made available by the provider of a public communications network and/or publicly available electronic communications service;the elimination of the presentation of calling line identification and the temporary denial or absence of consent of a subscriber or user for the processing of location data, on a per-line basis for organisations dealing with emergency calls and recognised as such by a Member State, including law enforcement agencies, ambulance services and fire brigades, for the purpose of responding to such calls.

### Definitions

*Source: ePrivacy, eprivacy-art-2-en, 2002-07-12 — https://overview.legal/posts/132169*

DefinitionsSave as otherwise provided, the definitions in Directive 95/46/EC and in Directive 2002/21/EC of the European Parliament and of the Council of 7 March 2002 on a common regulatory framework for electronic communications networks and services (Framework Directive) ( 8 ) shall apply.The following definitions shall also apply:‘user’ means any natural person using a publicly available electronic communications service, for private or business purposes, without necessarily having subscribed to this service;‘traffic data’ means any data processed for the purpose of the conveyance of a communication on an electronic communications network or for the billing thereof; ▼M2 ‘location data’ means any data processed in an electronic communications network or by an electronic communications service, indicating the geographic position of the terminal equipment of a user of a publicly available electronic communications service; ▼B ‘communication’ means any information exchanged or conveyed between a finite number of parties by means of a publicly available electronic communications service. This does not include any information conveyed as part of a broadcasting service to the public over an electronic communications network except to the extent that the information can be related to the identifiable subscriber or user receiving the information; ▼M2 ————— ▼B ‘consent’ by a user or subscriber corresponds to the data subject's consent in Directive 95/46/EC;‘value added service’ means any service which requires the processing of traffic data or location data other than traffic data beyond what is necessary for the transmission of a communication or the billing thereof;‘electronic mail’ means any text, voice, sound or image message sent over a public communications network which can be stored in the network or in the recipient's terminal equipment until it is collected by the recipient; ▼M2 ‘personal data breach’ means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed in connection with the provision of a publicly available electronic communications service in the Community.

### Recital 42 — demonstrable informed freely given consent

*Source: GDPR, gdpr-rec-42-en, 2016-04-27 — https://overview.legal/posts/91599*

Where processing is based on the data subject's consent, the controller should be able to demonstrate that the data subject has given consent to the processing operation. In particular in the context of a written declaration on another matter, safeguards should ensure that the data subject is aware of the fact that and the extent to which consent is given. In accordance with Council Directive 93/13/EEC (10) a declaration of consent pre-formulated by the controller should be provided in an intelligible and easily accessible form, using clear and plain language and it should not contain unfair terms. For consent to be informed, the data subject should be aware at least of the identity of the controller and the purposes of the processing for which the personal data are intended. Consent should not be regarded as freely given if the data subject has no genuine or free choice or is unable to refuse or withdraw consent without detriment.

### Recital 43 — freely given consent validity conditions

*Source: GDPR, gdpr-rec-43-en, 2016-04-27 — https://overview.legal/posts/91601*

In order to ensure that consent is freely given, consent should not provide a valid legal ground for the processing of personal data in a specific case where there is a clear imbalance between the data subject and the controller, in particular where the controller is a public authority and it is therefore unlikely that consent was freely given in all the circumstances of that specific situation. Consent is presumed not to be freely given if it does not allow separate consent to be given to different personal data processing operations despite it being appropriate in the individual case, or if the performance of a contract, including the provision of a service, is dependent on the consent despite such consent not being necessary for such performance.

### Recital 33 — consent for scientific research areas

*Source: GDPR, gdpr-rec-33-en, 2016-04-27 — https://overview.legal/posts/91581*

It is often not possible to fully identify the purpose of personal data processing for scientific research purposes at the time of data collection. Therefore, data subjects should be allowed to give their consent to certain areas of scientific research when in keeping with recognised ethical standards for scientific research. Data subjects should have the opportunity to give their consent only to certain areas of research or parts of research projects to the extent allowed by the intended purpose.

### Recital 161 — scientific research consent in clinical trials

*Source: GDPR, gdpr-rec-161-en, 2016-04-27 — https://overview.legal/posts/91837*

For the purpose of consenting to the participation in scientific research activities in clinical trials, the relevant provisions of Regulation (EU) No 536/2014 of the European Parliament and of the Council (15) should apply.

### Recital 32 — valid consent requirements for data processing

*Source: GDPR, gdpr-rec-32-en, 2016-04-27 — https://overview.legal/posts/91579*

Consent should be given by a clear affirmative act establishing a freely given, specific, informed and unambiguous indication of the data subject's agreement to the processing of personal data relating to him or her, such as by a written statement, including by electronic means, or an oral statement. This could include ticking a box when visiting an internet website, choosing technical settings for information society services or another statement or conduct which clearly indicates in this context the data subject's acceptance of the proposed processing of his or her personal data. Silence, pre-ticked boxes or inactivity should not therefore constitute consent. Consent should cover all processing activities carried out for the same purpose or purposes. When the processing has multiple purposes, consent should be given for all of them. If the data subject's consent is to be given following a request by electronic means, the request must be clear, concise and not unnecessarily disruptive to the use of the service for which it is provided.

## Case law

### Council of State upholds €600,000 DPA fine against Enschede for Wi-Fi tracking

*Source: Council of State, 2026-07-29 — https://overview.legal/posts/184682 — original: https://gdprhub.eu/index.php?title=RVS_-_202401622/1/A3*

Facts — The Municipal Executive Board of Enschede, the controller, decided to conduct continuous pedestrian counts to obtain information about visitor numbers in the city centre. From 25 May 2018, at least ten sensors captured the Media Access Control (hereinafter, MAC) addresses of devices with Wi-Fi enabled. When a sensor detected a MAC address, it was temporarily stored and converted into a pseudonymised MAC address using an algorithm. Since all sensors used the same algorithm, the same device received the same pseudonymised identifier across different locations. The resulting data included the sensor that detected the device and the date and time of detection. After several filters were applied, the data was retained for up to six months and used to estimate the number of unique visitors. The controller discontinued the pedestrian-counting system on 1 May 2020. Following an enforcement request, the Autoriteit Persoonsgegevens, the DPA, investigated the processing. It considered that the combination of pseudonymised MAC addresses and location data related to identifiable natural persons. According to the DPA, the data allowed individuals to be distinguished and could reveal lifestyle and behavioural patterns. It also identified three methods through which the controller could potentially determine the identity of device users. On 11 March 2021, the DPA imposed a fine of €600,000 on the controller for processing personal data without a legal basis between 25 May 2018 and 30 April 2020. It considered the controller responsible for determining the purposes and means of the processing and found that no legal basis under Article 6 GDPR had been established. The controller challenged the decision before the District Court of Overijssel. The Court held that the DPA had not sufficiently proven that the information processed by the controller constituted personal data. In particular, the DPA had relied on assumptions regarding the possibility of identifying device users without sufficiently investigating whether those identification methods were realistically available. The Court held that, under Recital 26 GDPR, the DPA should have assessed whether the means allegedly available to identify the individuals were reasonably likely to be used, taking into account the costs, time, available technology and technological developments. It therefore annulled the decision on the objection and revoked the original fine. The DPA appealed the judgment before the Council of State (Appeal Court). Holding — The Appeal Court dismissed the DPA’s appeal and upheld the annulment of the €600,000 fine. The Appeal Court noted that the DPA did not challenge the Court’s finding that it had failed to sufficiently investigate and substantiate the three methods through which the controller could allegedly identify individual device users. During the appeal hearing, the DPA also acknowledged that the applicable standard of proof had not been met regarding those methods. Instead, the DPA argued that natural persons had already been directly identified because the combination of MAC addresses and location data allowed the controller to distinguish and count unique visitors. According to the DPA, the ability to single out unique visitors was itself sufficient for the information to qualify as personal data under Article 4(1) GDPR, irrespective of whether the controller could determine their civil identity. However, the Appeal Court held that the DPA had not relied on this reasoning in its original decision or in its decision on the controller’s objection. In proceedings concerning an administrative fine, the DPA must conclusively establish and substantiate the alleged infringement before completing the administrative decision-making process. This requirement safeguards legal certainty and allows the alleged infringer to defend itself effectively and in a timely manner. The DPA could not wait until the judicial appeal stage to introduce a new argument explaining why the processing concerned personal data and why a punishable infringement had occurred. The Court had therefore not erred by refusing to assess this new argument. Since the DPA had not otherwise challenged the substance of the Court’s finding that the original infringement had not been sufficiently proven, the annulment of the fine remained in effect. The Appeal Court did not determine whether the pseudonymised MAC addresses and location data were, as such, personal data under the GDPR.

### CJEU - C-61/19 - Orange Romania

*Source: GDPRhub, C-61/19, 2026-07-09 — https://overview.legal/posts/83472 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-61/19_-_Orange_Romania*

EU LAW CLEANUP Facts. Facts Orange România SA is a provider of mobile telecommunications services on the Romanian market. On 28 March 2018, the Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (national Romanian data protection authority; ‘the ANSPDCP’), based on Article 32 of Law No 677/2001 (Romanian Data Protection Act) imposed an administrative penalty on Orange România (a provider of mobile telecommunication services on the Romanian market) on the ground that

### FTT: NMC should have neither confirmed nor denied holding struck-off nurse's personal data

*Source: First-Tier Tribunal, 2026-07-08 — https://overview.legal/posts/53656 — original: https://gdprhub.eu/index.php?title=FT_-_FT/EA/2024/0359*

Facts — A doctor submitted a freedom of information request to the Nursing and Midwifery Council, the controller, asking whether a named nurse had been struck off the register for misconduct under the former English National Board for Nursing or the United Kingdom Central Council for Nursing, Midwifery and Health Visiting. The controller replied that it may hold the requested information but refused disclosure under Section 40(2) FOIA, stating that the information was personal data. The doctor, the requestor, complained to the DPA, arguing that the refusal was procedurally and substantively defective. The DPA found that the controller should have neither confirmed nor denied whether it held the information under Section 40(5B) FOIA. The DPA also found that the controller breached Section 17(1) FOIA because it had failed to issue a correct refusal notice within the statutory time frame, but it did not require any further steps. The requestor appealed to the First-Tier Court. She argued, among other points, that the controller had effectively admitted holding the information, that it was bound by its initial reliance on Section 40(2) FOIA, that the nurse had consented to disclosure through the regulatory registration framework, and that there was a strong public interest in disclosure. Holding — The Court allowed the appeal in part. First, the Court held that the controller had not admitted holding the requested information. The statement that it “may” hold the information only acknowledged a possibility. It was not a confirmation that the information was held. The Court also held that, even if the controller had previously relied on Section 40(2) FOIA, this did not prevent the DPA or the Court from considering Section 40(5B) FOIA. The statutory FOIA framework allowed the relevant authority, the DPA and the Court to consider the correct exemption or exclusion. The Court then assessed whether confirming or denying that the information was held would disclose personal data. Since the request named the nurse and concerned whether that person had been struck off for misconduct, the Court held that confirmation or denial would reveal personal data about the requestor. The Court considered Article 6(1)(a) UK GDPR and rejected the argument that the requestor had consented to disclosure. The fact that professional registers may be public, or that sanctions may be published in some circumstances, did not amount to clear, specific and affirmative consent to disclosure under FOIA many years later. The Court also noted that, under the controller’s current publication policy, a striking-off sanction remains publicly available on the register for five years from the date on which the order takes effect. In this case, that publication period had long expired. The Court then considered Article 6(1)(f) UK GDPR. It accepted that the requester had a legitimate interest in the information for research purposes and that disclosure was necessary because the information was not otherwise publicly available. However, the Court held that the requestor’s privacy rights overrode that interest. The information was historic, related to professional misconduct, was no longer published on the register, and disclosure under FOIA would amount to disclosure to the public at large. As a result, the Court held that confirming or denying whether the controller held the information would breach the first data protection principle under Article 5(1)(a) UK GDPR, since the processing would not be lawful and fair. Therefore, section 40(5B)(a)(i) FOIA was applicable. The Court also applied the public interest test. It recognised a general public interest in transparency and possible public interest arising from the background to the request. However, it held that this was outweighed by the public interest in protecting the requestor’s privacy. The controller was therefore entitled to neither confirm nor deny whether it held the requested information. No fine was imposed. The only corrective outcome was a substituted decision notice. The Court found that the DPA’s decision notice should also have recorded that the controller breached Section 17(7) FOIA because its refusal notice failed to explain the requester’s right to complain to the DPA under Section 50 FOIA. The appeal was therefore allowed only on this limited procedural point and was otherwise dismissed.

### Council of State upholds CNIL cookie banner guidance: refusal via corner link as easy as

*Source: Supreme Administrative Court, 2026-06-19 — https://overview.legal/posts/53908 — original: https://gdprhub.eu/index.php?title=CE_-_N._501417*

Facts — Pour un RGPD Respecté, a French NGO that advocates for GDPR compliance, and three individuals requested the CNIL, the DPA, to partially repeal its 2020 recommendation on cookies and trackers. They challenged Figure 5, which showed a cookie banner where users could refuse cookies through a “continue without accepting” link placed in the upper-right corner. After the DPA rejected the request, the applicants asked the Court to annul that decision. They argued that refusing cookies was not as easy as accepting them and that the banner contradicted the positions of the DPA, the EDPB and the Belgian DPA. Holding — The Court dismissed the action. It held that the DPA’s decision did not require a specific statement of reasons under national administrative law. The Court also found that the refusal option was available on the same screen, was immediately accessible and used clear wording and a comparable font size. Therefore, refusing cookies was as easy as accepting them. The Court further held that the example did not contradict the positions of the DPA, the Belgian DPA or the EDPB. The DPA had therefore not made a manifest error of assessment. The requests for an injunction, periodic penalty payment and legal costs were also rejected. No fine or corrective measure was imposed.

### French Supreme Admin Court partly upholds challenge to graduated response IP data decree

*Source: Supreme Administrative Court, 2026-04-30 — https://overview.legal/posts/122869 — original: https://gdprhub.eu/index.php?title=CE_-_N._433539*

Facts — Several digital rights organisations asked the Prime Minister to repeal Decree No. 2010-236 of 5 March 2010. The decree regulated an automated personal data processing system used by the French authority for freedom of communications (ARCOM, hereinafter the French authority) for France’s online copyright enforcement mechanism, known as the graduated response procedure. Under this system, the French authority could receive IP addresses linked to alleged copyright infringements and request the corresponding subscriber identity data from electronic communications operators. This data could then be used to send warnings to subscribers and, in repeated cases, refer the matter to the public prosecutor. The applicants argued that the decree allowed the French authority to access personal data linked to IP addresses without sufficient safeguards under EU law. The court had previously referred questions to the CJEU, which ruled in Case C-470/21 that such access may be allowed, but only under strict conditions. Following the CJEU judgment, the court reviewed whether the French decree complied with EU law. Holding — The court partly upheld the action. First, the court held that EU law allows the general and indiscriminate retention of IP addresses for combating criminal offences in general only where serious interference with private life is effectively excluded. This requires strict separation between different categories of retained data, secure technical safeguards and regular monitoring by an independent public authority. The court found that French law did not require electronic communications operators to retain subscriber identity data and IP-related data under these conditions. Therefore, the decree was unlawful insofar as it allowed the French authority to process data that had not necessarily been retained in compliance with EU-law safeguards. Second, the court held that the French authority may access subscriber identity data linked to IP addresses in order to identify persons suspected of online copyright infringements and send the first two warnings under the graduated response procedure. However, the court distinguished the third access to such data. At that stage, the authority is no longer dealing with an isolated identification request: it has already linked the same person’s identity twice with alleged unlawful online activity and with the protected works concerned. A third access therefore allows the authority to build a more detailed picture of the person’s conduct and may reveal sensitive aspects of their private life. It also marks a more serious procedural stage, since it may lead to a registered letter and ultimately to referral to the public prosecutor. For that reason, EU law requires prior authorisation by a court or an independent administrative body before this third access takes place. The decree did not provide for such prior review, so the court held that it was unlawful to that extent. For this third access, EU law requires prior authorisation by a court or an independent administrative body. The decree did not provide for such prior review. The court therefore held that the decree was unlawful to that extent. The court annulled the Prime Minister’s refusal to repeal the unlawful parts of the decree and ordered their repeal. It also held that the French authority must stop applying the unlawful provisions. However, the French authority may still access identity data for the first and second warnings, and may request access in serious copyright offence cases under the conditions set out in the judgment.

### OGS Zagreb - Pn-877/2023-29

*Source: Municipal Civil Court in Zagreb, 2026-01-16 — https://overview.legal/posts/52429 — original: https://gdprhub.eu/index.php?title=OGS_Zagreb_-_Pn-877/2023-29*

Facts — A data subject filed a lawsuit against Propuls d.o.o., the controller and publisher of the news portal direktno.hr, claiming that two articles published on 11 January 2023 and 31 January 2023 disclosed her personal data without her consent: The first article reported on payments related to the football club Dinamo Zagreb and included the data subject’s full name, bank account number, and payment amounts. The second article referred to the first article via a hyperlink but did not mention the data subject directly. The data subject argued that the disclosure violated her right to privacy and the protection of personal and family life under Croatian law and the GDPR. She claimed non-material damage and sought compensation as well as publication of the court decision in the controller's news portal. The controller admitted publishing the articles but argued that the information was accurate and that publishing the data served the public interest. The controller also stated that it had issued a correction upon the data subject request and argued that journalistic activity may be exempt from certain obligations under GDPR and it's exempt from liability if the facts concerned are true according to the Croatian Media Law. The evidence included the published articles, the correction request, witness testimony from journalists and the data subject, and financial records. Holding — The court held that the controller violated the data subject’s right to privacy and the protection of personal and family life. It reasoned that publishing her full name, bank account number, and payment amounts was disproportionate because the details were not necessary to inform the public about the football club payments. Following the ECHR jurisprudence, the court applied a proportionality test, balancing the controller’s freedom of expression against data subject's privacy rights under the Croatian Constitution and civil law. The court emphasised that the data subject was not a public figure, had not voluntarily exposed her private life to the media, and did not participate in public debate in a way that could justify disclosing her sensitive data. The court also addressed the controller’s argument regarding journalistic freedom. It recognised that journalists may publish personal data when there is an overriding public interest, such as exposing wrongdoing or contributing to an important debate. However, in this case, the disclosure of the data subject’s bank account and payment amounts was unnecessary for the story’s public interest. The court noted that general information about club payments could have been reported without identifying her. Regarding the harm suffered, the court found that the data subject experienced non-material damage, including emotional stress and intrusion into her private and family life. It awarded €3,000 in damages with statutory interest, while rejecting the additional claim of €3,636.14 as excessive. The court also denied the data subject’s request to publish the decision, explaining that publishing it could further disclose her personal data and undermine her privacy rights.

### Judgment of the Court (First Chamber) of 13 November 2025.#Inteligo Media SA v Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP).#Request for a preliminary ruling from the Curtea de Apel Bucureşti.#Reference for a preliminary ruling – Processing of personal data and the protection of privacy in the electronic communications sector – Directive 2002/58/EC – Article 13(1) and (2) – Unsolicited communications – Concept of communication ‘for the purposes of di

*Source: Court of Justice of the European Union, C-654/23, 2025-11-13 — https://overview.legal/posts/132132 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0654*

The Court of Justice of the European Union ruled on a preliminary reference from the Romanian Curtea de Apel Bucureşti in proceedings between Inteligo Media SA and the Romanian DPA (ANSPDCP) concerning the scope of "direct marketing" and the customer-relationship exception under Article 13 of the ePrivacy Directive (Directive 2002/58/EC) in relation to GDPR Article 6. The case addressed whether a daily newsletter sent to users who registered on an online platform to access additional content qualifies as a communication "for the purposes of direct marketing" and whether the platform registration constitutes obtaining contact details "in the context of the sale of a product or a service" under Article 13(2). The Court's ruling clarifies the interplay between the ePrivacy Directive's specific consent regime for unsolicited communications and the GDPR's general lawfulness requirements, with the underlying national proceedings involving an administrative penalty imposed by ANSPDCP for processing customers' personal data without consent.

### USR - Us I-755/2025-8

*Source: Administrative Court in Rijeka, 2025-11-11 — https://overview.legal/posts/49225 — original: https://gdprhub.eu/index.php?title=USR_-_Us_I-755/2025-8*

Facts — The data subject was a member of the management board of Zagrebački holding, a company owned by the City of Zagreb, from 3 September 2021 until 31 March 2023. A television broadcaster published several pieces, including a video on its YouTube channel, reporting on the data subject’s resignation. The publications mentioned his name, role, employer, salary, and information on the brand of his private car. The data subject filed a complaint with the Croatian Personal Data Protection Agency (AZOP), claiming that the publication constituted unlawful processing under the GDPR because the media lacked a valid legal basis under Article 6, the reporting was inaccurate and excessive, and it did not serve any genuine public interest. He latter further claimed during the lawsuit against AZOP's decision that the authority had incorrectly and incompletely established the facts, misapplied substantive law, and breached procedural rules. He emphasized that the published personal data was unrelated to transparency in public administration, that he was neither a public figure nor a political actor, and that any public interest ended once he left office on 31 March 2023. He invoked his right to erasure under Article 17 GDPR and sought removal of the content, annulment of AZOP’s decision, or alternatively, a remittal for a new procedure. AZOP contested the lawsuit in full, maintaining that it had acted in accordance with Article 34 of the Croatian GDPR Implementation Act and Article 77 GDPR. It argued that the publication fell within a justified public interest under Article 8 of the Croatian Media Act and that it had properly carried out a balancing test between privacy (Article 8 ECHR) and freedom of expression (Article 10 ECHR). According to AZOP, the reporting was necessary, proportionate, and not sensationalistic, and did not excessively intrude on the data subject’s privacy. It added that consent was not required because the processing relied on legitimate interest under Article 6(1)(f) GDPR. Holding — The Administrative Court dismissed the action and upheld AZOP’s decision. Because Zagrebački holding is a city-owned and publicly funded company, the court considered information about the data subject’s salary, compensation for using his private vehicle in official duties, and his managerial role to be directly connected to the use of public resources. This placed the publication within the legitimate public interest in transparency recognised by Article 8 of the Media Act. In its proportionality assessment, the court accepted AZOP's application of Article 5 and 6 GDPR, emphasizing that the published data did not touch upon the data subject’s family or intimate life but related solely to his public functions. Publication was therefore limited to what was necessary to inform the public about the management of a publicly owned company. The data subject’s claims that the publication was false or harmful to his reputation did not alter the outcome, as AZOP is not empowered to determine the truthfulness or tone of journalistic content, particularly under the journalistic exemption in Article 85 GDPR. Issues of accuracy or reputational harm must instead be pursued through media-law mechanisms such as requests for correction or civil actions. On the erasure request, the court held that the right to be forgotten under Article 17 GDPR cannot override freedom of expression and information where media reporting is involved. Although the data subject no longer served on the board, the publication continued to contribute to public understanding of how a major public entity was run during his tenure, thus the public interest persisted and erasure was not justified. Finally, the court reiterated that consent was not required because Article 6 GDPR offers alternative lawful bases for processing. Since Article 6(1)(f) was satisfied, the absence of consent was irrelevant. Concluding that AZOP had properly applied the law and that the interference with the data subject’s privacy was proportionate, the court upheld the decision and denied the data subject’s claim and costs.

### French Supreme Court upholds €8M CNIL fine against Apple for App Store ad tracking

*Source: Supreme Administrative Court, 2025-10-10 — https://overview.legal/posts/122852 — original: https://gdprhub.eu/index.php?title=CE_-_473833*

Facts — The DPA imposed an €8 million administrative fine on Apple (the controller) in 2022 (CNIL - SAN-2022-025). The DPA found that Apple used identifiers stored on users’ devices to enable personalized advertising in the App Store without first obtaining valid user consent, as required by Article 82 of the French Data Protection Act, which implements Article 5(3) of the ePrivacy Directive. Apple challenged the sanction before the Supreme Administrative Court (Conseil d’État), arguing that the DPA lacked jurisdiction, that the investigation violated Apple’s procedural rights, that the advertising-related processing did not fall within the scope of Article 82, and that the case should be referred to the Court of Justice of the EU. Apple also claimed that the fine was disproportionate. Holding — The court held that reading identifiers stored on user devices for the purpose of delivering personalised advertising constitutes access to information under Article 5(3) of the ePrivacy Directive, requiring the controller to obtain the user’s prior consent. It reasoned that since this operation was to implement personalized advertising it could not fall within the exemptions to the consent requirement. The court found that the national authority was competent because the controller’s establishment within the country contributed to the advertising operations in question. It did so by marketing devices pre-equipped with the App Store where personalized advertising appears and by providing Search Ads Specialists who helped monetize and optimize that advertising space. It also rejected the controller’s claim that the authority had violated its procedural rights, finding that the right to remain silent did not apply during CNIL investigations and that the authority had lawfully carried out the investigation providing sufficient opportunity for the controller to respond. Additionally, the court rejected Apple's request to reference the case to the Court of Justice of the EU stating that there wasn't any reasonable doubt Finally, it held that the €8 million fine was proportionate, noting the scale of the processing, the number of affected users, and the economic significance of the advertising activity.

### OVG Saarlouis - 2 A 165/24

*Source: Superior Administrative Court Saarlouis, 2025-05-13 — https://overview.legal/posts/125590 — original: https://gdprhub.eu/index.php?title=OVG_Saarlouis_-_2_A_165/24*

Facts — The data subject was an employee, the controller was the employer. On 14 January 2022, the data subject requested access to personal data from the controller under Article 15 GDPR. They did not respond. On 28 January 2022, the controller terminated the employment. On 17 February 2022, the data subject lodged a complaint with the Data Protection Authority (DPA) under Article 77 GDPR. The data subject alleged that the controller had failed to answer the access request, had taken unauthorised photographs, and had a copy of their vaccination certificate. On 24 February 2022, the employment relationship ended by a court settlement before the Labour Court. The settlement stated that all claims arising from the employment relationship and its termination, whether known or unknown and regardless of their legal basis, were settled, except for employment documents. By entering the settlement, the data subject agreed to not pursue further claims. After the settlement, the controller informed the DPA that it had not received an access request from the data subject, had not taken photographs, and had destroyed the vaccination certificate after the employee left. The data subject continued to raise issues with the DPA, including access to time-tracking data and alleged inaccuracies in the controller’s provided documents. The controller later provided partially redacted time-tracking data. On 26 July 2022, the DPA closed the administrative procedure, as it considered that the data subject no longer had a right of access under Article 15 GDPR because the settlement didn't allow for this claim. The data subject challenged the DPA’s decision before the Administrative Court. On 10 July 2024, the court dismissed the action. The data subject appealed. Holding — First, the court held that the right of access under Article 15 GDPR was, in principle, waivable. Although Article 8(2) CFR protects the right of access, the court noted that data protection law is based on self-determination, including the possibility to consent to processing under Article 7 GDPR. From this, the court inferred that a data subject could also waive the exercise of the right of access. Second, the court clarified that a waiver could not generally cover unknown future data processing. However, a waiver relating to past processing was permissible, especially after the end of an employment relationship, where the imbalance between employee and employer no longer existed. Third, the court held that the specific settlement covered the right of access under Article 15 GDPR. The clause settling all claims arising from the employment relationship and its termination, whether known or unknown and regardless of their legal basis, also included secondary claims linked to the employment relationship, such as access rights concerning employee data. The court considered the wording sufficiently clear and found no requirement to explicitly mention data protection rights. Fourth, the court noted that the data subject already knew about the access request and had raised it before concluding the settlement. Any internal intention not to waive data protection rights was legally irrelevant. Finally, the court upheld the DPA’s decision to close the procedure. Since the data subject had waived the right of access under Article 15 GDPR for past processing through the settlement, the DPA had no obligation to continue enforcement action against the employer.

### Judgment of the Court (First Chamber) of 27 February 2025.#CK v Magistrat der Stadt Wien.#Request for a preliminary ruling from the Verwaltungsgericht Wien.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 15(1)(h) – Automated decision-making, including profiling – Scoring – Assessment of the creditworthiness of a natural person – Access to meaningful information about the logic involved in profiling – Verification of the accuracy of the infor

*Source: Court of Justice of the European Union, C-203/22, 2025-02-27 — https://overview.legal/posts/132146 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0203*

In Case C-203/22, the Court of Justice of the European Union interpreted Article 15(1)(h) of the GDPR in response to a preliminary ruling from the Verwaltungsgericht Wien concerning an individual's request for meaningful information about the logic of creditworthiness scoring conducted by Dun & Bradstreet Austria GmbH. The Court held that data subjects must receive sufficiently detailed explanations of the logic involved in automated profiling to understand how the decision was reached, while controllers may withhold information protected by trade secrets under Directive (EU) 2016/943 only insofar as such withholding does not render the information provided meaningless. The Court further clarified that data subjects may not use access rights to obtain personal data of third parties or to verify the absolute accuracy of the underlying information processed.

### HvJ EU 9 januari 2025, C‑394/23 (Mousse).

*Source: CJEU, 2025-01-09 — https://overview.legal/posts/50377 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0394*

HvJ EU 9 januari 2025, C‑394/23 (Mousse). Artikelen: 5(1)(c), 6(1), en 21 AVG Onderwerp : Beginsel van minimale gegevensverwerking Gek genoeg verwijst het HvJ EU zelf niet naar HvJ EU 1 augustus 2022, C‑184/20 (Vyriausioji tarnybinės etikos komisija), maar dat had hier ook heel logisch geweest.

## Guidance

### Guidelines 05/2020 on consent under Regulation 2016/679

*Source: EDPB, edpb-guidelines-on-consent, 2020-05-04 — https://overview.legal/posts/38053 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-052020-on-consent-under-regulation-2016679_en*

The European Data Protection Board (EDPB) adopted Guidelines 05/2020 on consent under Regulation 2016/679 to provide detailed interpretive guidance on the requirements for valid consent under the GDPR, including the elements of freely given, specific, informed, and unambiguous consent, as well as the conditions for explicit consent and the obligation to demonstrate consent. The guidelines address practical issues such as power imbalances, conditionality, granularity, detriment, and the minimum content requirements for informing data subjects. No fines are imposed, as this is a guidance document rather than an enforcement decision.

### Opinion 3/2019 concerning the Questions and Answers on the interplay between the Clinical Trials Regulation (CTR) and the General Data Protection regulation (GDPR)

*Source: EDPB, opinion-32019-concerning-the-questions-and-answers-on-the-interplay-en, 2019-01-23 — https://overview.legal/posts/126252 — original: https://www.edpb.europa.eu/documents/legislative-opinion/opinion-32019-concerning-the-questions-and-answers-on-the-interplay_en*

1 Opinion 3/ 2 019 c oncerning the Questions and Answers on the interplay between the Clinical Trials Regulation (CTR) and the General Data Protection regulation (GDPR) (art. 70. 1. b)) Adopted on 23 January 2019 2 3 The European Data Protection Board Having regard to Article 70.1.b of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data,…

### Guidelines 2/2018 on derogations of Article 49 under Regulation 2016/679

*Source: EDPB, edpb-guidelines-on-derogations-of-article-49, 2018-05-25 — https://overview.legal/posts/38057 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-22018-on-derogations-of-article-49-under-regulation-2016679_en*

The European Data Protection Board (EDPB) issued Guidelines 2/2018 to provide interpretive guidance on the application of Article 49 derogations for international transfers of personal data under the GDPR. The guidelines emphasize that derogations under Article 49 are exceptions to the general rule requiring an adequacy decision or appropriate safeguards, and that controllers must first exhaust transfer mechanisms under Articles 45 and 46 before resorting to these derogations. The document details specific conditions and limitations for each derogation, including explicit consent, contractual necessity, public interest, vital interests, public registers, and compelling legitimate interests.

### Guidelines 06/2020 on the interplay of the Second Payment Services Directive and the GDPR

*Source: EDPB, edpb-guidelines-on-the-interplay-of-the-second-payment-services-directive-and-the-gdpr, 2020-12-15 — https://overview.legal/posts/38139 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-062020-on-the-interplay-of-the-second-payment-services-directive-and_en*

The European Data Protection Board (EDPB) adopted Guidelines 06/2020 to clarify the interplay between the Second Payment Services Directive (PSD2) and the GDPR. The guidelines analyze the lawful grounds for processing personal data in payment services, the relationship between explicit consent under Article 94(2) PSD2 and GDPR consent requirements,

### Opinion 7/2018 on the draft list of the competent supervisory authority of Greece regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-72018-on-the-draft-list-of-the-competent-supervisory-en, 2018-10-03 — https://overview.legal/posts/126272 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-72018-on-the-draft-list-of-the-competent-supervisory_en*

Opinion 7 /2018 on the draft list of the competent supervisory authority of Greece regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 25th September 2018 2 Contents 1. Summary of the Facts ................................ ................................ ................................ ........ 4 2. Assessment ................................ ................................ ................................…

### Opinion 13/2018 on the draft list of the competent supervisory authority of Lithuania regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-132018-on-the-draft-list-of-the-competent-supervisory-en, 2018-10-03 — https://overview.legal/posts/126307 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-132018-on-the-draft-list-of-the-competent-supervisory_en*

Opinion 13 /2018 on the draft list of the competent supervisory authority of Lithuania regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 25th September 2018 2 Contents 1. Summary of the Facts ................................ ................................ ................................ ........ 4 2. Assessment ................................ ................................ ................................…

### Opinion 18/2018 on the draft list of the competent supervisory authority of Portugal regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-182018-on-the-draft-list-of-the-competent-supervisory-en, 2018-10-03 — https://overview.legal/posts/126297 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-182018-on-the-draft-list-of-the-competent-supervisory_en*

Opinion 18 /2018 on the draft list of the competent supervisory authority of Portugal regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 25th September 2018 2 Contents 1. Summary of the Facts ................................ ................................ ................................ ........ 4 2. Assessment ................................ ................................ ................................…

### Opinion 21/2018 on the draft list of the competent supervisory authority of Slovakia regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-212018-on-the-draft-list-of-the-competent-supervisory-en, 2018-10-03 — https://overview.legal/posts/126305 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-212018-on-the-draft-list-of-the-competent-supervisory_en*

Opinion 21 /2018 on the draft list of the competent supervisory authority of Slovakia regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 25th September 2018 2 Contents 1. Summary of the Facts ................................ ................................ ................................ ........ 4 2. Assessment ................................ ................................ ................................…

## Enforcement decisions

### Italian DPA sanctions Lusha Systems for processing contact data without consent in B2B

*Source: Garante per la protezione dei dati personali (Italy), 2026-07-14 — https://overview.legal/posts/184678 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_542/2026*

Facts — Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database. It was an US company wholly owned by Lusha Systems Ltd. In April 2025, the Italian DPA (Garante) initiated an investigation after media reports revealed that telephone numbers of senior Italian officials were available on the platform. The DPA later received one complaint and one report from data subjects who had received unsolicited advertising communications. The data subjects further stated that after requesting information about the source of their contact details, they discovered that their data were available on the controller’s platform without their consent. The controller explained that, for a subscription fee, it provided its Clients with a Business Contact Card for each Contact. The controller further distinguished between “Clients”, namely customers who used the platform and accessed its B2B database, and “Contacts”, namely the individuals whose personal data were included in that database, regardless of whether they used or were aware of the platform. Clients received Contact Cards containing information such as names, professional email addresses, telephone numbers, job titles, roles and locations, which could be used for sales, marketing, recruitment, business intelligence and fraud prevention. The DPA limited its investigation to the processing of Contacts’ personal data. The controller stated that it collected and combined data from publicly available sources, specialised providers, affiliated companies and commercial partners. It also inferred missing professional email addresses through algorithms that identified standard company email patterns. Through its Community Program and integrations with email, calendar and CRM services, it could also obtain information from Clients’ professional networks and communications. The data were cross-referenced, enriched and regularly updated to reflect changes in Contacts’ professional circumstances. The controller argued that the GDPR did not apply because it was established outside the EU and provided services only to businesses. It additionally claimed that the weekly updating of Contact Cards ensured accuracy rather than constituting monitoring or profiling. The controller maintained that the collection and disclosure of the data were necessary for its own economic interest in providing accurate professional contact information and for its Clients’ interests, including fraud prevention. According to the controller, it processed only a limited range of information concerning the Contacts’ professional lives. It further claimed that individuals who made professional information publicly available, particularly through services such as LinkedIn, could reasonably expect that the information might be reused and that they could be contacted regarding professional opportunities. Regarding transparency, the controller stated that its Personal Information Notice was sent to each Contact before their information became available in the database. It explained that it notified Contacts that they had a seven-day period during which they could opt out before their information became available to Clients. The controller also maintained that excluding public officials and public figures from the database was not a requirement under the GDPR. It attributed the presence of certain public officials to technical limitations in its filtering system. It also argued that public figures had a lower expectation of privacy. After the proceedings began, the controller removed profiles connected with Italian public bodies and officials, strengthened its filters and customer-verification measures, discontinued the Community Program in Italy and extended the opt-out period to fourteen days. Holding — Regarding the territorial scope of the GDPR, the DPA acknowledged that Article 3(2)(a) GDPR could apply to the processing of Clients’ data, but not to Contacts, since they were not recipients of the service. However, it held that Article 3(2)(b) GDPR applied because the controller systematically combined, enriched and updated Contacts’ professional information in order to assess their circumstances and determine whether and how they would appear in the database. Referring to Recital 24 and Recital 30, the DPA held that monitoring did not require profiling. It noted that the systematic observation of online traces and changes in a person’s professional situation was sufficient. The fact that the processing also served data accuracy did not alter that conclusion. It emphasised that the fact that the controller also updated the information to ensure its accuracy did not prevent the processing from constituting monitoring. Regarding transparency, the DPA found that the information concerning the collection of the Contacts’ data, the purposes of the processing and the legal basis relied upon was scattered across several documents. Also, the relevant information was not easily accessible from the controller’s homepage, while the Personal Information Notice could not be located directly through the website without prior knowledge of its existence. It further pointed out that the documents were provided in English rather than in the language of the affected data subjects. The DPA held that presenting the information in this manner did not satisfy the requirement that information be concise, transparent, intelligible and easily accessible. It therefore found an infringement of Article 5(1)(a) GDPR and Article 12 GDPR. Moreover, the DPA assessed whether Article 6(1)(f) GDPR provided a valid legal basis for the processing. It examined the controller’s Legitimate Interest Assessment and considered it essentially non-existent, as it contained only generic statements on necessity and proportionality and no genuine balancing assessment. The DPA then applied the three-part test under Article 6(1)(f) GDPR. It held that making the Contacts’ data available to Clients for their own marketing and sales activities could not constitute a legitimate interest, since the disclosure of contact information to third parties for their independent advertising purposes required prior consent under the applicable national and ePrivacy framework . However, it acknowledged that the controller’s interest in fraud prevention could be considered legitimate. The DPA nevertheless found that the processing was not necessary for the purposes pursued. It held that the controller collected information extending beyond ordinary professional contact details, including third-party data contained in CRM databases, email headers and subject lines, information about calendar meetings, and browsing data collected through browser extensions or other software integrations used by Clients. It pointed out that much of this information was not publicly available but was extracted from private interpersonal communications, disclosed by Clients, obtained through integrations with information systems or acquired from third-party providers. The DPA held that the collection and combination of such extensive information was neither strictly necessary nor proportionate for creating professional Contact Cards. Furthermore, it stressed that fraud prevention could also have been achieved through less intrusive means. The DPA therefore concluded that the necessity requirement and the principle of data minimisation were not met. Regarding the balancing test, the DPA emphasised that there was no prior relationship between the controller and the Contacts. Creating a professional profile on LinkedIn or another professional platform did not create a reasonable expectation that unpublished contact details would be collected from multiple sources, continuously updated and disclosed to an unspecified number of paying customers. It further noted that the processing could expose Contacts to communications from unknown third parties for purposes they could not reasonably anticipate. The DPA concluded that the Contacts’ interests, rights and freedoms prevailed over the controller’s economic interests and that the safeguards adopted by the controller could not change this outcome. Therefore, the DPA held that Article 6(1)(f) GDPR did not provide an appropriate legal basis and found that the controller infringed Article 5(1)(a) GDPR, Article 5(1)(c) GDPR, and Article 6 GDPR. Regarding public officials, the DPA held that their status did not reduce their entitlement to data protection and that no public interest justified disclosing their direct contact details for commercial purposes. The DPA further found that the controller had been aware of the risk that public officials could be included in its database but had failed to implement sufficiently effective technical and organisational measures. Its filters recognised general titles such as “President” but failed to exclude more specific titles such as “President of the Italian Republic” and “Vice Prime Minister”. The DPA therefore found an infringement of the principle of data minimisation under Article 5(1)(c) GDPR and the obligation of data protection by design and by default under Article 25 GDPR. The DPA imposed a fine of €2,000,000. Furthermore, it prohibited any further processing of personal data of data subjects located in Italy that had been collected without an adequate legal basis and ordered their deletion.

### AKI (Estonia) - No. 2.1-1/24/397-890-38

*Source: AKI (Estonia), 2026-04-16 — https://overview.legal/posts/53882 — original: https://gdprhub.eu/index.php?title=AKI_(Estonia)_-_No._2.1-1/24/397-890-38*

Facts — OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic. On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had failed to provide all personal data requested. The controller only partially complied after several requests from the DPA. Although the DPA closed the part of the case concerning the access request, it continued investigating the controller’s processing of patients’ personal data when providing Invisalign treatment. The service required the controller to collect and transfer patients’ health data to Align Technology, Inc. However, the contractual documents did not clearly establish whether Align Technology acted as a processor, an independent controller or a joint controller. The controller stated that Align Technology largely determined the conditions of the service, including the consent form and the processing arrangements, and that individual clinics could not unilaterally amend these conditions. The DPA also found that the information provided to patients was incomplete and fragmented. The consent form and privacy information did not clearly explain the legal basis and purposes of processing, the parties involved, data recipients, retention periods, transfers outside the European Union or the safeguards applied to such transfers. Parts of the information were only available in English on external websites. Holding — The DPA held that the controller had failed to demonstrate that the processing carried out in connection with the Invisalign service was lawful and transparent under Articles 5(1)(a) and 5(2) GDPR. First, the DPA found that the parties’ roles had not been properly determined. Under Article 4(7) GDPR, the assessment had to be based on which party actually determined the purposes and means of processing, rather than solely on the contractual description of the relationship. The controller decided whether Invisalign treatment was suitable for a patient and collected the relevant health data. It therefore acted as a controller in relation to the treatment. However, Align Technology exercised significant control over the subsequent processing, including the data collected, the recipients, retention arrangements, the use of other service providers and transfers outside the European Union. The DPA therefore considered that Align Technology could not simply be regarded as a processor acting only on documented instructions under Article 28(3)(a) GDPR. On the available evidence, it was at least a joint controller under Article 26 GDPR. The DPA ordered the controller to review the contractual relationship. If Align Technology acted as a processor, the agreement had to comply with Article 28 GDPR, including the requirements concerning subprocessors under Article 28(2). If the parties were joint controllers, they had to allocate their respective responsibilities under Article 26 GDPR. Second, the DPA found that the consent obtained from patients was invalid. The consent form did not provide sufficient information for patients to understand the processing and therefore did not meet Articles 4(11), 6(1)(a), 7 and 9(2)(a) GDPR. The DPA also noted that healthcare processing may, depending on the operation concerned, rely on Article 6(1)(b) GDPR together with Article 9(2)(h) GDPR. However, the controller had not clearly identified the applicable legal bases for the different processing activities. The privacy information also failed to comply with Articles 12, 13 and 14 GDPR. Patients were required to consult several documents and external websites, some of which contained incomplete or inconsistent information. The controller had therefore not ensured that the information was easily accessible, understandable and available in Estonian. The DPA further referred to Article 25 GDPR when emphasising that the controller had to ensure that the processing arrangements and safeguards complied with the GDPR. Under Article 58(2)(d) GDPR and § 56(1) of the Estonian Personal Data Protection Act, the DPA ordered the controller to clarify the parties’ roles, conclude an Article 26 arrangement or Article 28 agreement, amend the consent form and privacy policy, and publish the required information in Estonian. No administrative fine was imposed. However, failure to comply could result in a penalty payment of €1,000 for each unfulfilled point or subpoint of the order, imposed repeatedly until compliance.

### AEPD investigates University of Navarra over student COVID-19 vaccination status requests

*Source: AEPD (Spain), 2026-07-16 — https://overview.legal/posts/122842 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_EXP202102529*

Facts — A student handed in a complaint against the University of Navarra because they asked the students to fill in their vaccination status. The complainant understands this as a breach of the data protection regulation because it would access the students medical records. The grounds are based on an e-mail from the University of Navarra, in which it announces to collaborate with the Navarro Health Service in the Vaccination against COVID-19 and it asks the students to inform about their vaccination status. On October 26, 2021 the University of Navarra replied to the complaint that the students were not coerced to give the information, but they were given the possibility to do so. The University does not process the personal data of the students without their explicit consent. The consent would in no case be vitiated since no condition has been established that could nullify the correct will of the interested party to the processing. There is no measure contrary to the interests of those students who do not provide the information freely and voluntarily. The sole purpose of the communication made is to comply with the objective of the collaboration agreement reached with the Government of Navarra by virtue of the actions taken in its place against SARS-CoV-2 pandemic. The complaint filed was admitted for processing on November 24, 2021 in Accordance with Article 65 of the LOPDGDD. The collaboration was known to the public. There is a press release stating the fact that the University of Navarra should communicate the list of persons who are to receive the vaccine so that their identity can be recorded in the health databases. This is in compliance with a legal obligation in terms of prevention of legal risks. This is due to the severity of the pandemic. The form for acceptance of the data processing states that the compliance with the form is voluntary. The first field of the form is the request for consent. Furthermore it is added that the information provided will not be communicated to third parties unless the health authorities require it. This clause can also be accepted. Holding — The Court does not consider that there is a violation of the provisions of the regulation in force regarding protection, and there is no substantive issue to support such an allegation. In accordance with the functions that Article 57 (1) a, f and h of Regulation (EU) 2016/679 GDPR confers to each supervisory authority and according to the provisions of Articles 47 and 48 (1) of LOPDGDD, the Director of the Spanish Data Protection Agency is competent to resolve these investigative actions. In light of provisions (Article 4 (15) GDPR, Article 9 GDPR, Article 6 GDPR) the vaccination of a person against Covid-19 implies the provision of a health care service. Therefore the information about whether or not an identified natural person has received the Covid-19 vaccine is in the nature of personal data concerning health, falling within the category of special of sensitive data regulated in Article 9 GDPR. The task of the University was to provide the Navarra Health Department, Osasunbidea, with the lists of the people who were going to receive the vaccine so that they could be registered in the health database. The students that wanted to fill out the form on the vaccination were fully informed about the processing of the data, this is on the legal obligation to take care of the health of students in Article 7.1.n Royal Decree 1791/2010. It has not been possible to prove that the students were forced to provide information on their vaccination status. The transfer of data is completely voluntary and informed, requesting the consent of the person concerned and the data is (if even) only transferred to health authorities. No evidence has been found to prove the existence of an infringement within the competence of the Spanish Data Protection Agency. The interested parties may file an appeal.

### Austrian DSB: Marketing agency violated GDPR by recording phone interviews without valid

*Source: DSB (Austria), 2026-01-19 — https://overview.legal/posts/184689 — original: https://gdprhub.eu/index.php?title=DSB_(Austria)_-_2025-1.049.138*

Facts — The controller was a digital marketing agency whose employees pre-screened potential applicants for its clients. As part of this process, applicants (data subjects) were contacted and interviewed by telephone. A former employee of the controller was examined as a witness by the Austrian DPA (DSB) and provided evidence concerning the recordings. The telephone interviews generally followed a particular pattern. The employees contacted data subjects in the name of the relevant client, stated that their application appeared interesting, presented the position, asked about their qualifications and professional experience and, where appropriate, arranged an in-person interview. The calls were recorded from beginning to end and stored for an indefinite period. In some cases, data subjects were not informed that the call was being recorded. In other cases, the employee asked during the call whether recording would be acceptable. In one such call, the data subject responded, “Uh, yeah.” Moreover, a superior employee had encouraged other employees through an intranet message to record and store interviews for training purposes, including without obtaining the data subject's consent. The controller argued that it had been unaware of the recording practice. It submitted that the employee who had instructed the others to make the recordings was neither a managing director nor an authorised signatory and had no authority to issue such instructions. According to the controller, the statement that interviews could be recorded “even without consent” resulted from personal overzealousness and legal recklessness and did not reflect the controller’s internal procedures. As legal bases for the processing, the controller stated that it relied on consent under Article 6(1)(a) GDPR and legitimate interests under Article 6(1)(f) GDPR. It claimed that data subjects had been expressly asked for consent at the beginning of the application process and that the recordings served the legitimate interest of improving employee performance. Holding — The DPA relied on the CJEU’s judgment in Case C-807/21 (Deutsche Wohnen) and held that a legal entity may be liable not only for infringements committed by its representatives, managers or executives, but also for infringements committed by any person acting within the scope of its business activities and on its behalf. It acknowledged that an exception may apply where an employee acts outside that framework and exclusively for personal purposes. The DPA determined that the supervising employee had ordered the processing within the scope of their employment relationship and in the controller’s interest. It pointed out that the controller could therefore not avoid responsibility by claiming that it had been unaware of the practice or that the employee lacked formal authority to issue instructions. The DPA held that no consent had been obtained in some cases and that, where consent had been sought, it was neither timely nor valid. It stated that consent must be obtained before processing begins. However, it noted that the recordings had already been activated before the calls began, due to the fact that the recordings included the opening greetings. It held that asking for consent during the recorded call was too late. The DPA further held that one data subject’s response, “Uh, yeah,” did not constitute an unambiguous affirmative act. It also considered that a job interview, similarly to an existing employment relationship, is characterised by a structural imbalance of power. Moreover, it emphasised that the data subjects had not been informed of the true identity of the controller, because its employees presented themselves as acting for the client companies. It concluded that the data subject could therefore not have given valid consent and that processing could not be based on Article 6(1)(a) GDPR. Furthermore, the DPA examined whether the recordings could be justified by legitimate interests. It underlined that a controller relying on Article 6(1)(f) GDPR must comply with the corresponding transparency obligations. Specifically, pursuant to Article 13(1)(d) GDPR, the legitimate interests pursued must be communicated when the personal data is collected. Referring to Case C-394/23 (Mousse) the DPA held that the collection could not be based on Article 6(1)(f) GDPR where that information had not been provided in time. It found that the data subjects had either not been informed at all of the legitimate interest pursued or had been informed only after the collection of their personal data had begun. It held accordingly that the processing could not be based on Article 6(1)(f) GDPR. The DPA concluded that the recording and storage of the interviews lacked a legal basis and infringed Article 6(1) GDPR in conjunction with Article 5(1)(a) GDPR. In addition, the DPA held that the recordings were not necessary for the training purpose as less intrusive alternatives, such as simulated interviews between employees, could have achieved the same objective. It therefore found a violation of the principle of data minimisation under Article 5(1)(c) GDPR. It further found that the indefinite retention of the recordings was also unnecessary and violated the principle of storage limitation under Article 5(1)(e) GDPR. The DPA also found that the controller had failed to comply with its transparency obligations. In some cases, data subjects received no information about the processing. In others, information was provided only after the processing had begun. The data subjects were also not informed of the identity of the actual controller, because the employees presented themselves as representatives of the client companies. It therefore found an infringement of Article 5(1)(a) GDPR in conjunction with Article 12 GDPR and Article 13 GDPR. The DPA found that the controller had acted at least negligently. It imposed a fine of €25,500 for the infringements.

### GOOGLE IRELAND LIMITED: Onvoldoende juridische basis voor de verwerking van gegevens.

*Source: French Data Protection Authority (CNIL), 2025-09-01 — https://overview.legal/posts/52129*

De Franse autoriteit voor gegevensbescherming heeft GOOGLE IRELAND LIMITED een boete van 125.000.000 euro opgelegd. Bij het aanmaken van een account voor de diensten van de verantwoordelijke, heeft deze de procedure voor toestemming voor cookies zodanig ontworpen dat een vrije, geïnformeerde toestemming niet mogelijk was. De betrokkene kon alleen kiezen tussen de gratis dienst met gepersonaliseerde marketing of een betaalde versie zonder dit. De verantwoordelijke heeft ook haar e-maildienst zo ontworpen dat advertenties getoond konden worden in gebieden waar betrokkene normaal gesproken...

### APD/GBA (Belgium) - 113/2024

*Source: APD/GBA (Belgium), 2024-09-06 — https://overview.legal/posts/122855 — original: https://gdprhub.eu/index.php?title=APD/GBA_(Belgium)_-_113/2024*

Facts — A data subject visited four website operated by MediaHuis, namely: Gazet van Antwerpen; De Standaard; Het Nieuwsblad; Het Belang van Limburg. On each website there was a cookie banner which: Didn’t contain a reject button within its first layer;Buttons colours were misleading; It was not as easy to withdraw consent as it was to give it; Contained a reference to the legal basis of legitimate interest. The data subject filed four complaints referring to abovementioned cookie banners with the Belgian DPA (ADP/GBA). noyb was appointed by the data subject as their representative under Article 80(1) GDPR. MediaHuis was assigned the role of data controller. According to the controller, the law, especially Article 7(3) GDPR or Article 4(11) GDPR, didn’t prescribe the controller to implement reject button within the first layer of the cookie banner or to use different colours for the buttons or to implement consent withdrawal option in a particular way. The fact that the cookie banners were not in line with the guidelines of different data protection authorities and the EDPB, as mentioned by the data subject, did not amount to violation of the GDPR. Moreover, the data subject gave their consent for processing activities of the controller and, for that reason, they had no interest to bring a case before the DPA. Holding — The DPA found the controller violated the Article 5(1)(a) GDPR, Article 6(1)(a) GDPR, Article 7(3) GDPR. Firstly, the DPA clarified that for the consent to be freely and unambiguously given under Article 6(1)(a) GDPR and Article 5(3) ePrivacy Directive, the reject button had to be presented alongside the accept button. Otherwise, the data subject would have no real alternative to consenting for placing and processing cookies. Secondly, the buttons’ colours used by the controller were of deceptive nature. They inclined a data subject to give a consent for the cookies processing. Because of that, the controller was in breach of Article 5(1)(a) GDPR. Since the cookie banner was lacking of the reject button within its first layer, and the colours used were misleading, the DPA order the controller to bring the cookie banner into compliance with the GDPR within 45 days. The order was combined with a penalty of €25,000 per day and per each website concerned, due if the controller fails to implement the ordered changes. The maximum amount of total penalty was set on €10,000,000. Thirdly, the controller violated Article 7(3) GDPR. To withdraw the consent given, a data subject had to perform more actions - “click more” – whilst to give a consent only one click sufficed. Nevertheless, the controller updated their websites by adding the reject button to the first layer of cookie banner and the option to withdraw the consent, using the manage link at the bottom of each website. The violation was remedied, accordingly the DPA reprimanded the controller. Fourthly, the legitimate interest called upon by the controller covered placing and processing of the cookies, which were not “strictly necessary”. The controller’s cookies were of different kind, including the analytical cookies. Especially for the latter, the application of Article 6(1)(f) GDPR is per se excluded and the consent needed to be obtained. Furthermore, by adding the legitimate interest to be a “back-up” legal basis for the cookies related processing, the controller mislead the data subject. The controller violated then Article 6(1)(a) GDPR. Nonetheless, the DPA reprimanded the controller that the legal basis for placing and processing of analytical cookies and other cookies that were not “strictly necessary cookies only was a consent under Article 6(1)(a) GDPR. In answer to the controller’s claims, the DPA emphasised that: the fact that the data subject gave a consent didn’t deprive them from starting the case before the DPA; the guidelines of the EDPB were not legally binding, as pointed by the controller, but they played important role regarding the interpretation of the GDPR. In addition, the DPA excluded alleged pressure put on the data subject by noyb to initiate the proceedings. The controller argued the relationship between the data subject, being a trainee at noyb, was instructed to lodge the complaints with the DPA. Hence there was no legal interest of the data subject in the case at hand. However, for the DPA statements of that kind were unfounded, bearing in mind the facts of the case. In particular, the outcome of the data subject’s hearing before the DPA that proved the data subject’s interest being involved.

### CNIL (France) - SAN-2023-012

*Source: CNIL (France), 2023-07-13 — https://overview.legal/posts/125588 — original: https://gdprhub.eu/index.php?title=CNIL_(France)_-_SAN-2023-012*

Facts — This decision follows from a previous decision of the French DPA (SAN 2021-023 of 31 December 2021), in which said DPA fined Google LLC €90,000,000 and Google Ireland Limited €60,000,000 for violating Article 82 French Data Protection Act. This Act transposes the ePrivacy Directive into domestic French law. Article 82 of the French Data Protection Act is the national equivalent to Article 5(3) ePrivacy Directive 2002/58/EC, which stipulates that the storing of user information or the gaining of access to information already stored, is only permitted on the condition that the user has already given their informed consent. The French DPA had fined Google LLC and Google Ireland Limited in decision SAN 2021-023 for failing to offer users a way of rejecting cookies. It ordered Google to bring its processing activities into compliance and imposed an additional periodic fine of €100,000 per day if Google failed to bring its processing activities into compliance within 3 months. On 24 April 2022, Google sent the French DPA its proposed cookie amendments, which included a button titled "reject all." Between April and June 2022, Google sent further information to the French DPA, and on 5 August 2022, the French DPA re-investigated the matter to ensure that the updated cookie system was compliant. On 25 January 2023 the French DPA requested further information from Google on their system, which Google provided on 28 April 2023. Holding — The French DPA held that Google's updated cookie system was compliant, as the implementation of the "reject all" button offered a means of users refusing the storage of and access to their information, pursuant to Article 82 French Data Protection Act. Consequently, the French DPA decided to dismiss the periodic fine of €100,000 per day in the case of non-compliance, as the updated cookie banner was lawful.

### APD/GBA (Belgium) - 85/2022

*Source: APD/GBA (Belgium), 2022-05-25 — https://overview.legal/posts/122843 — original: https://gdprhub.eu/index.php?title=APD/GBA_(Belgium)_-_85/2022*

Facts — On 16 January 2019, the Executive-committee of the Belgian DPA (GBA) started an investigation on the use of cookies on Belgian media websites. The controller in this case is Roularta Media Group. The investigation revealed the following potential violations. First, the placement of unnecessary cookies prior to consent of the data subject. Second, the placement of statistical cookies without consent. Third, pre-ticked boxes to grant consent for cookies from partners. Fourth, the placement of a disclaimer for third-party cookies. Fifth, false and inadequate information in their privacy policy. Sixth, unjustified retention periods for the storage of cookies. Lastly, revoking consent was impossible. In fact, this placed more cookies. The controller argued that statistical cookies are used for aggregated basic statistics, necessary for the business model of the website. No personal data is being processed for this activity, as such, the GDPR does not apply. The controller argued that regarding the statistical cookies, the personal data was anonymised. The controller further argued that the Belgian DPA did not provide adequate guidelines for companies to comply with the GDPR. The controller refers to e.g. the French and Dutch DPA, who have provided this. Holding — Regarding the placement of cookies, the DPA first noted that cookies can only be placed without prior consent when they are (1) strictly necessary for the transmission of communication or (2) to provide a service that is explicitly requested by the user. The DPA held that the controller violated Article 6(1)(a) and Article 5(3) ePrivacy Directive 2002/58/EC, as some of the cookies placed without prior consent were found to be not strictly necessary. The controller even admitted to the placement of unnecessary cookies without obtaining prior consent. Regarding the placement of statistical cookies in particular, the DPA noted - with reference to her decision in 12/2019 - that these also require prior consent. The DPA observed that the placement and reading of these cookies on the terminal equipment of users revealed their IP-addresses to the controller. The DPA disregarded the defence of the controller that the IP-addresses were anonymised, and found that they were instead pseudonimised. This makes the data subjects indirectly identifiable and thus the GDPR applicable. The DPA therefore held that the controller violated Article 6(1)(a) and Article 5(3) ePrivacy Directive 2002/58/EC by not obtaining prior consent. Regarding the pre-ticked boxes for the cookies from partner companies, the DPA argued that this cannot constitute lawful consent by the definition of Article 4(11) (and with reference to Planet49). The DPA thus found another violation of Article 6(1)(a). The DPA held that regarding the disclaimer placed on their website for third-party cookies, the controller violated the principle of accountability laid down in Article 5(2). The DPA stated that controllers are responsible for compliance with the GDPR and the demonstration thereof (Article 24). The DPA found that the privacy policy of the controller contained false, incomplete and insufficient information. The DPA therefore held that the controller violated Article 12(1), as it did not communicate the information referred to in of Article 13 and Article 14 in a "concise, transparent, intelligible and easily accessible form". The DPA furthermore held that the controller violated the principle of storage limitation laid down in Article 5(1)(e) by not proactively defining the criteria for the storage of cookies. Lastly, the DPA found that the controller violated Article 7(3), as withdrawing consent was made impossible by the controllers cookie-management tool. The DPA noted that withdrawing consent must be as easy as providing consent for users. The DPA found that the alleged absence of concrete guidelines is not a valid argument against a violation of data protection legislation. The DPA held that it is the responsibility of the controller to comply with the law and further noted that numerous guidelines for companies to ensure compliance with the GDPR already exist. The DPA fined the controller €50.000. The DPA further ordered the controller to get its processing of personal data - for which a violation was established - in compliance with the GDPR within 3 months.

## Recent developments

### DSB (Austria) - DSB-D124.1749

*Source: GDPRhub, 2026-08-18 — https://overview.legal/posts/291293 — original: https://gdprhub.eu/index.php?title=DSB_(Austria)_-_DSB-D124.1749*

The DPA dismissed the data subject&#039;s complaint about their social security number shared with a financial service provider to obtain financial aid from the controller as it was only used as an identifier and was therefore not considered sensitive. English Summary. Facts. The controller shared the data subject&#039;s social security number with a financial service provider in order to provide financial aid, to which the data subject did not consent. On 17.02.2020, the data subject lodged a c

### 1,741 “informed” consents with one click?! GDPR complaint against dict.cc filed

*Source: noyb - European Center for Digital Rights, 2026-07-30 — https://overview.legal/posts/184576 — original: https://noyb.eu/en/1741-informed-consents-one-click-gdpr-complaint-against-dictcc-filed*

Cookie Banners Today, noyb has filed a complaint against the popular online dictionary dict.cc. The GDPR requires that consent is freely given, informed, specific and unambiguous. However, when visiting dict.cc, users are nudged into consenting to online tracking by a staggering 1,741 (!) “partners” with a single click. This makes it impossible for users to know exactly who has access to their data and how it is actually used. While dict.cc is an extreme example, requests to blindly waive your r

### Nordic Media Giant Schibsted switches to “Pay or Okay” – complaint filed!

*Source: noyb - European Center for Digital Rights, 2026-06-03 — https://overview.legal/posts/53125 — original: https://noyb.eu/en/nordic-media-giant-schibsted-switches-pay-or-okay-complaint-filed*

Forced Consent & Consent Bypass Today, the Norwegian Consumer Council (Forbrukerrådet) and noyb have filed a complaint against the Norwegian news publisher Schibsted for implementing a “Pay or Okay” system across its products. Schibsted is one of the largest news publishers in the Nordics and owns well-known brands such as TV4, Aftenposten E24 and VG. The company’s introduction of “Pay or Okay” sets a dangerous precedent for free consent across the Nordic countries, which follows the wide-spread

### noyb success: ORF.at must correct misleading cookie banner

*Source: noyb - European Center for Digital Rights, 2026-05-21 — https://overview.legal/posts/53126 — original: https://noyb.eu/en/noyb-success-orfat-must-correct-misleading-cookie-banner*

Cookie Banners The Austrian Broadcasting Corporation (ORF) must amend its cookie banner on ORF.at to bring it into line with the GDPR. This has now been decided by the Federal Administrative Court (BVwG), thereby upholding a decision made by the Austrian Data Protection Authority in 2024. Specifically, the ORF must ensure that the buttons to ‘accept’ or ‘reject’ tracking cookies are designed equally so that visitors are not tricked into agreeing. Currently, the ‘Accept’ option is misleadingly hi

### Conseil d'État upholds Criteo's €40M GDPR fine

*Source: noyb - European Center for Digital Rights, 2026-03-13 — https://overview.legal/posts/53130 — original: https://noyb.eu/en/conseil-detat-upholds-criteos-eu40m-gdpr-fine*

Data Subject Rights The French Data Protection Authority (CNIL) fined Criteo, a major online advertisement and tracking company in Europe, €40 million for violating the GDPR. This decision is based on complaints filed by noyb and Privacy International in December 2018. The CNIL found that the company failed to comply with data subject rights under the GDPR and could not prove that they obtained valid consent. The Conseil d’Etat rejected CRITEO's appeal and upheld the fine. Original Press Release

## Literature

### If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation

*Source: Computer law & security review, 2026-01-23 — https://overview.legal/posts/53843 — original: https://doi.org/10.1016/j.clsr.2025.106251*

As the General Data Protection Regulation (GDPR) approaches its tenth anniversary, the European legislator is considering reforms thereto. This article offers a set of research-based suggestions for what such reforms could look like, based on two assumptions. First, that the GDPR is overall a solid piece of legislation that upholds the enduring objectives and principles of data protection law. Second, that any improvement cannot compromise the level of protection of fundamental rights currently

### Grounds for Lawful Processing of Personal Data in GDPR and Personal Data Protection Bill 2018, India (PDPB): Section – I: Consent.

*Source: SSRN Electronic Journal, 2019-01-01 — https://overview.legal/posts/132467 — original: https://doi.org/10.2139/ssrn.3718235*

### HOW GDPR TREATS AUTOMATED DECISION-MAKING

*Source: Journal Scientific and Applied Research, 2025-11-14 — https://overview.legal/posts/132599 — original: https://doi.org/10.46687/jsar.v28i1.435*

This article examines how the General Data Protection Regulation (GDPR) regulates automated decision-making, including profiling, in the context of personal data processing. It analyzes the main provisions of Article 22 of the Regulation, as well as the conditions under which fully automated decisions that produce legal effects or significantly affect data subjects are permitted. The article highlights the rights of data subjects – the right to human intervention, the right to express their poin

### Writing case reports, consent for publication and General Data Protection Regulation (GDPR)

*Source: Case Reports in Women's Health, 2020-07-01 — https://overview.legal/posts/132523 — original: https://doi.org/10.1016/j.crwh.2020.e00204*

### Privacy vs. business convenience: the Mousse judgment and the future of data protection in the EU

*Source: Unio - EU Law Journal, 2025-06-18 — https://overview.legal/posts/53865 — original: https://doi.org/10.21814/unio.11.1.6632*

The Mousse ruling represents a pivotal moment in EU data protection law, reinforcing strict limitations on personal data processing and clarifying the legal standards under the General Data Protection Regulation (GDPR). The Court of Justice of the European Union (CJEU) reaffirmed that data collection must be objectively indispensable for a specified legal basis, rejecting broad interpretations of contractual necessity and legitimate interest. Additionally, the ruling confirms that the right to o

## Tools

### CNIL GDPR guide for developers

*Source: CNIL, 2026-07-04 — https://overview.legal/posts/53810 — original: https://github.com/LINCnil/GDPR-Developer-Guide*

Open-source best-practice guide by the French DPA translating GDPR obligations into concrete development practice: data minimisation in code, managing consent, securing data flows, retention, and preparing for data subject rights — organised in 16 practical sheets.

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Law Enforcement** — https://overview.legal/topics/law-enforcement
  Processing for law enforcement purposes
- **Data Controller** — https://overview.legal/topics/verwerkingsverantwoordelijke
  The entity that determines purposes and means of processing personal data

---
Generated by overview.legal · https://overview.legal/topics/toestemming · 2026-08-22
