# Supervision — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/toezicht
> Sources are cited per item. Verify against the official texts before relying on them.

Oversight and enforcement by supervisory authorities

## Overview

## Legal Framework

Supervision under the GDPR is anchored in Article 51, which mandates that each Member State designate one or more independent public authorities to monitor compliance with the Regulation. These supervisory authorities (SAs) serve a dual purpose: protecting fundamental rights and facilitating the free flow of personal data within the Union. The Court of Justice in *Schrems II* confirmed this architecture:

> "Elke lidstaat bepaalt dat één of meer onafhankelijke overheidsinstanties verantwoordelijk zijn voor het toezicht op de toepassing van deze verordening, teneinde de grondrechten en fundamentele vrijheden van natuurlijke personen in verband met de verwerking van hun persoonsgegevens te beschermen"
> — [Schrems II ¶16](/posts/1#seg-16)

The supervisory architecture inherits from the 1995 Data Protection Directive, which equipped authorities with three categories of power: investigative, interventionist, and litigious. As the Court recalled:

> "onderzoeksbevoegdheden, zoals het recht van toegang tot gegevens die het voorwerp vormen van een verwerking en het recht alle inlichtingen in te winnen die voor de uitoefening van haar toezichtstaak noodzakelijk zijn"
> — [Schrems II ¶6](/posts/1#seg-6)

Under the GDPR, these powers are elaborated in Articles 57–58, covering the full enforcement toolkit: from ordering controllers to provide information, to imposing administrative fines, to ordering suspension of processing operations. The one-stop-shop mechanism under Article 60 coordinates cross-border enforcement through a lead supervisory authority, while the EDPB resolves disputes under Article 65.

## Key Developments

The EDPB's Guidelines 01/2021 clarify the breach-notification duty that channels enforcement into supervisory oversight:

> "The GDPR introduces, in certain cases, the requirement for a personal data breach to be notified to the competent national supervisory authority"
> — [EDPB Guidelines 01/2021 §1](/posts/38047#seg-1)

Notification is mandatory unless the breach is unlikely to risk individuals' rights and freedoms — a threshold that controllers must assess and document. The EDPB also signals that controllers handling sensitive or financial data bear a heavier security burden, and that prolonged undetected breaches trigger heightened scrutiny of incident-detection capabilities.

Enforcement decisions confirm this risk-based approach. The Italian Garante fined a health authority €20,000 for publishing personal data in an official resolution, while the Spanish AEPD imposed €200,000 on an insurance broker following a ransomware breach — both illustrating that supervisory authorities actively calibrate sanctions to the sensitivity of data and the adequacy of the controller's security posture.

## Status of the Debate

This topic is actively contested in court. The *Schrems II* ruling invalidated the Privacy Shield adequacy decision partly because the Court found that US supervisory oversight mechanisms did not meet the independence and effective-remedy standards that the GDPR demands of supervisory authorities. The boundary between adequate and inadequate third-country oversight remains litigated, particularly regarding access by foreign intelligence agencies. No definitive court split has crystallised on the precise threshold for "essential equivalence" of supervisory protection, but future CJEU rulings on updated adequacy decisions or on the EU-US Data Privacy Framework will shape that standard.

## Practical Guidance

- **Map your lead supervisory authority early.** Identify your main establishment under Article 4(16) to determine which SA holds primary jurisdiction under the one-stop-shop, and engage proactively rather than awaiting an investigation.
- **Document breach risk assessments.** Article 33 requires notification within 72 hours unless the breach is unlikely to result in a risk to rights and freedoms — maintain contemporaneous records of that assessment to defend any decision not to notify.
- **Treat sensitive-data processing as high-risk.** The EDPB's guidance and DPA enforcement signal that controllers handling health, financial, or special-category data face elevated expectations on incident detection, change controls, and response automation.
- **Prepare for cross-border cooperation.** Under Article 60, multiple SAs may be concerned; ensure your internal investigation files, DPIAs, and records of processing are structured to satisfy information requests from any concerned authority, not only the lead.
- **Monitor adequacy and transfer-safeguard developments.** *Schrems II* invalidated a adequacy decision based on supervisory-oversight deficiencies; controllers transferring data outside the EU must reassess Transfer Impact Assessments whenever supervisory frameworks in destination countries change.

## Legislation (full text of key provisions)

### Right to lodge a complaint with a supervisory authority

*Source: GDPR, gdpr-art-77-en, 2016-04-27 — https://overview.legal/posts/91328*

### Cooperation between the lead supervisory authority and the other supervisory authorities concerned

*Source: GDPR, gdpr-art-60-en, 2016-04-27 — https://overview.legal/posts/91098*

### Competence of the lead supervisory authority

*Source: GDPR, gdpr-art-56-en, 2016-04-27 — https://overview.legal/posts/91010*

### International cooperation for the protection of personal data

*Source: GDPR, gdpr-art-50-en, 2016-04-27 — https://overview.legal/posts/90950*

In relation to third countries and international organisations, the Commission and supervisory authorities shall take appropriate steps to:

### Rules on the establishment of the supervisory authority

*Source: GDPR, gdpr-art-54-en, 2016-04-27 — https://overview.legal/posts/90990*

### Supervisory authority

*Source: GDPR, gdpr-art-51-en, 2016-04-27 — https://overview.legal/posts/90956*

### General aspects concerning supervision and enforcement

*Source: NIS2, nis2-art-31-en, 2022-12-14 — https://overview.legal/posts/96344*

### Supervisory and enforcement measures in relation to essential entities

*Source: NIS2, nis2-art-32-en, 2022-12-14 — https://overview.legal/posts/96354*

### Supervisory and enforcement measures in relation to important entities

*Source: NIS2, nis2-art-33-en, 2022-12-14 — https://overview.legal/posts/96417*

### General conditions for the members of the supervisory authority

*Source: GDPR, gdpr-art-53-en, 2016-04-27 — https://overview.legal/posts/90980*

## Case law

### CJEU - C‑474/24 - NADA Austria and Others

*Source: GDPRhub, 2026-07-24 — https://overview.legal/posts/108989 — original: https://gdprhub.eu/index.php?title=CJEU_-_C‑474/24_-_NADA_Austria_and_Others*

Facts — Several data subjects were subject to suspension proceedings by the Austrian Anti-Doping Legal Commission (ÖADR). Under Austrian law, the National Anti-Doping Agency (“NADA”) publishes the names of persons who have been suspended on its website. For the duration of the suspension, the website includes information such as the athlete’s name, sport practised, infringement of anti-doping rules, and the duration of the penalty. The ÖADR publishes the same information in a press release, with the addition of the prohibited substances involved. For this summary, both authorities are referred to as the controllers. The data subjects filed a complaint with the DPA on the grounds that the controllers refused their request to cease displaying their names and practised sports. They also argued that the controllers were processing sensitive data within the meaning of Article 9 and 10 GDPR, and that the undifferentiated publication system was incompatible with Article 6(3) GDPR. The DPA dismissed the complaint. In particular, one of the data subjects’ complaints was rejected on the grounds that the relevant data had not been published yet. The data subjects appealed the decision to the Federal Administrative Court (BVwG). The controllers argued that publishing the information in their website was lawful, as it was based on the legal bases of legal obligation (Article 6(1)(c) GDPR) and public interest (Article 6(1)(e) GDPR). The BVwG stayed proceedings and requested a preliminary ruling from the CJEU. The BVwG referred the following questions: Does the GDPR apply to the making information relating to athletes’ anti-doping violations publicly available through websites? If yes: Does information that an individual has committed a specific anti-doping violation fall under the scope of data relating to health within the meaning of Article 9 GDPR? Does the GDPR preclude national legislation from publishing the information mentioned above, if it does not make it possible to infer health data of the person concerned? Does the GDPR require a balancing test between the interests of the data subject and the interest of the general public of being informed of anti-doping violations every time anti-doping violations will be published? Does information that an individual has committed a specific anti-doping violation fall under the scope of data relating to criminal convictions within the meaning of Article 10 GDPR? If yes, must the decisions of the authority processing this data be subject to judicial review? Is filing a complaint before the processing takes place (but was processed during the proceedings) permissible? Or does it become permissible provided that at the time of the complaint there were specific indications that the processing was imminent or would take place in the near future? Advocate General Opinion — The AG gave his opinion on each question separately, with the exception of the third and fourth questions that were answered together. Question 1: Does the GDPR apply to the making information relating to athletes’ anti-doping violations publicly available through websites? — The AG first considered that the GDPR was applicable to this case. Under Article 2(2)(d) GDPR a situation falls outside of the scope of the GDPR when data is processed for the prevention, detection or prosecution of criminal offenses. This is because the Law Enforcement Directive (LED) applies. According to the AG, the GDPR may apply even if personal data relating to criminal convictions is processed if the controllers are not “competent authorities” within the meaning of Article 3(7) LED. If the controllers were competent authorities, the referring court would have to decide if the GDPR applies. The main question the AG addressed is whether the exception under Article 2(2)(a) GDPR applies, meaning the processing falls outside the scope of Union law; here, the AG noted that the exceptions are interpreted narrowly, and may only apply to activities intended to safeguard national security or activities classified in the same category. The AG concluded that the aim of combating anti-doping is not related to national security. The exception did not apply even if the activity fell under the competence of a Member State. Therefore, the GDPR was applicable. Question 2: Does information that an individual has committed a specific anti-doping violation fall under the scope of data relating to health within the meaning of Article 9 GDPR? — The AG first highlighted the sensitive nature of Article 9 GDPR data, which must be interpreted broadly. The AG also noted that the legal basis of the controller does not influence whether the data falls under the scope of health data. Beyond a medical context, the AG opined that the determining factor is whether it is possible to draw inferences about the health status of the data subject. In this case, the AG agreed with the reasoning of the DPA that only specific information relating to the infringements should be considered health data. This is because not all data revealed information related to the data subjects’ health. Specifically, the information regarding the anti-doping tests and its analysis should be considered health data. The AG noted that, while the name of the substance itself may not reveal information on health status, it may be possible to make indirect inferences. However, if the name is not included, the link to the health status of the data subject would be too indirect to fall under the scope of health data. Questions 5 and 6: Does information that an individual has committed a specific anti-doping violation fall under the scope of data relating to criminal convictions within the meaning of Article 10 GDPR, and must the decisions of the authority processing this data be subject to judicial review? — The AG first noted that the GDPR does not prohibit processing this data, but rather subjects it to enhanced scrutiny. The AG assessed whether the processing fell under the scope of Article 10 GDPR based on the three “Engel” criteria in ECtHR case Engel and Others v. the Netherlands. Anti-doping offenses under national law do not fall under the “criminal” classification according to Article 10 GDPR. However, the AG opined that article 10 GDPR applies if the convictions have a punitive purpose and have a degree of severity equivalent to a criminal penalty. This is a matter for the BVwG to decide. In terms of judicial review, the AG stated that the authority at issue is an “official authority” within the meaning of Article 10 GDPR. The wording itself of Article 10 GDPR does not provide for judicial review. However, the AG opined that it must be possible for an act following a decision by an official authority to be subject to judicial review. This is in light of Article 79(1) GDPR and a contextual interpretation of Article 10 GDPR. Questions 3 and 4: Does the GDPR preclude national legislation from publishing the information mentioned in the facts, and does it require a balancing test every time anti-doping violations will be published? — The AG considered, in essence, whether Articles 5(1)(a) and (c), and Article 6(3) GDPR precluded the controllers to publish the data concerned under legal obligation. The AG also considered whether the GDPR requires a case-by-case balancing of interests, or whether the proportionality test provided by the legislator is sufficient. The AG noted that the aim to deter athletes and prevent circumventing of anti-doping rules are legitimate public interest objectives in the context of combating doping in sport. Making this information public online is appropriate in order to achieve the public interest aims, with the exception of referring to the prohibited substance in question. According to the AG, this was not expressly provided for by national law, and is not required to achieve the public interests involved. However, the AG considered the publication of the personal data involved a serious interference with the fundamental rights of the data subjects. While national law provided exceptions on the publication of data (e.g. amateur athletes or vulnerable persons), the AG opined that the publication of personal data for an unlimited amount of time could be considered excessive. Therefore, the AG concluded that making this information publicly accessible is only permitted as long as it is proportionate. Finally, the AG opined that a case-by-case analysis is necessary, as the controllers must comply with data minimisation and accountability principles under the GDPR even if they are designated by national law. Question 7: Is filing a complaint before the processing takes place permissible? — Here, the AG stated that the wording of the GDPR does not seem to preclude a priori a precautionary or preventative approach by the supervisory authorities in handling complaints. Restricting the powers of a DPA to decide on cases involving processing that has already taken place would go against the objectives of the GDPR. Nonetheless, the alleged infringement of the GDPR must be appropriate, and the processing in question cannot be purely hypothetical. In this case, it would be impossible for a controller to erase data that has not been disclosed yet, unless the complaint is interpreted as seeking to prevent the data from being published. The AG stated that it is a matter for the BVwG to decide. The AG noted that the complaint would be inadmissible if it was based on Article 17 GDPR even if the processing is imminent. However, the AG opined that a complaint requesting injunctive relief is potentially admissible under the GDPR and Austrian law in the event of a threat of imminent unlawful interference with data subjects’ rights under the GDPR. This includes requesting the DPA to review a restriction of processing based on Article 18 GDPR before the start of the processing or if the processing has started, as long as the processing is not purely hypothetical. Finally, the AG considered whether a complaint could become admissible a posteriori. Here, the AG opined that it is a matter of the national law system to settle the question, while complying with the principles of effectiveness and equivalence. Holding — The Court held that the GDPR applied to the publication of information concerning anti-doping infringements. Such processing did not fall within the exception under Article 2(2)(a) GDPR, even if anti-doping policy primarily falls within Member State competence. Information that a data subject infringed anti-doping rules and was banned from competitions does not, in principle, constitute health data under Article 9 GDPR. However, it may do so where the publication identifies a prohibited substance or method and, together with other information, allows conclusions to be drawn about the data subject’s health. The Court accepted that combating doping and protecting the fairness and integrity of sport constitute objectives of general interest. Nevertheless, publishing athletes’ identities and sanctions online constitutes a serious interference with their rights. National legislation may therefore require such publication only where the controller can assess, in each case, whether the content and duration of the publication are necessary and proportionate. Publication should not continue longer than strictly necessary and may be disproportionate where a sanction is lengthy or lifelong. The Court also held that Article 10 GDPR did not apply, as the anti-doping infringements formed part of a disciplinary regime and were not criminal in nature. Finally, Article 77 GDPR allows a data subject to lodge a complaint before processing takes place where there are specific indications that the processing is imminent and not merely hypothetical. The DPA must assess the substance of such a preventive complaint.

### VG Düsseldorf - 29 K 3490/24

*Source: Administrative Court Düsseldorf, 2026-06-22 — https://overview.legal/posts/108992 — original: https://gdprhub.eu/index.php?title=VG_Düsseldorf_-_29_K_3490/24*

Facts — A district (the controller), acting as the lower water authority, initiated administrative proceedings after identifying unauthorised riverbank works and a private jetty on two riverside properties. One property belonged to a water utility company, while the other belonged to a municipality and was leased to the data subjects. During those proceedings, the controller shared the data subjects' personal data with various participants, including the owners of the affected properties, other public authorities and a lawyer who claimed to represent the data subjects. The data subjects lodged a complaint with the competent supervisory authority (LDI NRW), alleging that the controller had unlawfully processed and disclosed their personal data. They argued that their personal data had been shared with uninvolved third parties, that the controller had communicated with a lawyer whom they had not authorised, recorded a telephone conversation with an unknown person, and transmitted personal data by unencrypted email. The controller's data protection officer addressed each allegation and provided additional factual information concerning the disputed processing operations. The DPA initially informed the data subjects that no GDPR infringement was apparent, invited them to provide any additional factual information, and explained that it would obtain extracts from the controller's administrative file if there were concrete indications that it contained relevant facts not already available. The data subjects did not identify any additional facts and instead reiterated their legal position that the controller had breached its GDPR accountability obligations. The DPA rejected the complaint, concluding that no GDPR infringement could be established. The data subjects then brought an action before the Verwaltungsgericht Düsseldorf (Administrative Court Düsseldorf), seeking a fresh decision on their complaint on the basis that the DPA had failed to adequately investigate the complaint because it had not obtained the controller's administrative file before reaching its decision. Holding — The court held that Articles 57(1)(f) and 77(1) GDPR give rise to an enforceable right requiring a supervisory authority to investigate a complaint to the extent appropriate in the circumstances before determining whether a GDPR infringement has occurred. Recital 141 GDPR requires the investigation to extend as far as is appropriate in light of the circumstances of the individual case, including the significance of the complaint and the seriousness of the alleged infringement. Applying these principles, the court held that the DPA had adequately investigated the complaint. It had considered each allegation together with the detailed response provided by the controller's data protection officer, invited the data subjects to provide any additional factual information, and explained that it would obtain extracts from the administrative file if concrete indications emerged that further relevant facts required clarification. As the data subjects did not provide any additional facts and there were no objective indications that the information already available was inaccurate or incomplete, the court held that the DPA was not required to obtain the controller's administrative file or undertake further investigations in the absence of concrete indications that additional factual clarification was necessary. The court further held that the DPA had correctly concluded that no GDPR infringement had occurred. The court held that the disputed processing was lawful under Article 6(1)(e) GDPR, read together with Article 6(3) GDPR and § 88 of the German Water Resources Act (WHG), which provided the legal basis for the processing. The court also held that the transmission of personal data by email did not infringe Article 5(1)(f) GDPR because, in the circumstances of the case, transport encryption provided an appropriate level of security.

### BVwG - W254 2321912-1

*Source: Federal Administrative Court, 2026-04-14 — https://overview.legal/posts/125597 — original: https://gdprhub.eu/index.php?title=BVwG_-_W254_2321912-1*

Facts — The data subject, an Austrian citizen residing in Vienna, was enrolled in a distance-learning programme at a German university (the controller). When the data subject enrolled, the controller registered them under the official name shown on their identity document. The data subject experienced gender dysphoria and had chosen a gender-neutral name for themselves which was a different to their legal name. They requested the controller to rectify and replace their official name with their chosen name. They stated that the chosen name reflected better their gender identity. The controller refused the change because the data subject had not provided either an official document proving a legal name change or a dgti supplementary ID card. This is a German supplementary identity document issued by Deutsche Gesellschaft für Trans*- und Inter*geschlechtlichkeit e.V. (dgti e.V.), a German association supporting trans and intersex persons, which may certify, among other things, a chosen first name, pronouns, gender and a current photo. The controller claimed that such a document would allow it to record changes concerning pronouns and first name in its administrative system. On 6 May 2024 the data subject lodged a complaint with the Austrian DPA. They argued that the controller failed to comply with their rectification request under Article 16 GDPR. The data subject also relied on the CJEU’s judgement in Deldits case(C-247/23), which concerned the rectification of gender identity data under Article 16 GDPR. As the controller was established in Germany, the Austrian DPA considered that the Thuringian DPA was the lead supervisory authority for the cross-border processing. The Thuringian DPA held that the controller had not violated Article 16 GDPR. Because the complaint had been lodged with the Austrian DPA and the outcome was a dismissal of the complaint, Article 60(8) GDPR required the supervisory authority with which the complaint had been lodged to adopt the decision and notify the data subject. The data subject then appealed that decision before the Austrian Federal Administrative Court. They argued that the continued use of the official name resulted in misidentification and systematic misgendering. They also stated that the prerequisite to submit further documents proving the name change was excessive and disproportionate. Moreover, the data subject requested that the chosen name should at least be used in non-legally binding university systems, such as the learning platform, email address, campus card and attendance lists. The controller noted that it was legally obligated to identify students and process their data based on official identification documents. This applied, on the one hand, to the transcripts addressed in the administrative proceedings, but also to other academic achievements by students, such as individual coursework, seminar work, or work within interdisciplinary study teams. Holding — The court first confirmed that the cooperation procedure under Article 56 GDPR and Article 60 GDPR had been correctly applied. The Thuringian DPA acted as the lead supervisory authority because the controller was established in Germany. However, since the complaint was dismissed, the Austrian DPA, as the authority with which the complaint had been lodged, adopted the rejection decision pursuant to Article 60(8) GDPR. The court held that there was no violation of Article 16 GDPR. It emphasised that the accuracy of personal data must be assessed in relation to the purpose of the processing. The controller processed the official name in order to identify the student, administer the study programme, issue certificates and academic degrees that aim to be recognized outside the university and certify the student's completion of the program to third parties. The court held that in light of these processing purposes, the processed data of the data subject should be regarded as accurate within the meaning of Article 16 GDPR. Since the data subject had not officially changed their name and had not submitted any official document, the court found that the official name was not inaccurate for the controller’s stated processing purposes. It further stated that the requirement to provide proof of a name change or to present a supplementary identification document was proportionate. The court acknowledged that gender identity is protected as part of private life under Article 8 ECHR. However, it distinguished the case from Deldits. In Deldits, the issue concerned the rectification of gender data in a public register and CJEU held that a data subject requesting the correction of gender identity data may be required to provide relevant and sufficient evidence, taking into account the circumstances of the individual case, in order to establish the inaccuracy of such data. By contrast, this case concerned university administration and academic documents whose effects extend beyond the university and there was no official change of the data subject’s name. Therefore, the court maintained that the controller could continue to use the official name unless the data subject provided official proof of name change. The court further noted that the request to use the chosen name only in non-legally binding systems went beyond the original complaint.

### Judgment of the Court (Grand Chamber) of 10 February 2026.#WhatsApp Ireland Ltd v European Data Protection Board.#Appeal – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 63 – Consistency mechanism – Article 65 – Dispute resolution by the European Data Protection Board – Binding decision – Action for annulment – First paragraph of Article 263 TFEU – Act open to challenge – Fourth paragraph of Article 263 TFEU – Condition that the

*Source: Court of Justice of the European Union, C-97/23, 2026-02-10 — https://overview.legal/posts/132126 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0097*

WhatsApp Ireland Ltd appealed to the Court of Justice (Grand Chamber) seeking to set aside a General Court order that dismissed as inadmissible its action for annulment of EDPB Binding Decision 1/2021, which resolved a dispute among supervisory authorities regarding the Irish DPC's draft decision on WhatsApp. The core issue is whether an EDPB binding decision under Article 65 GDPR is an act open to challenge under Article 263 TFEU that is of direct concern to the controller, thereby giving the controller standing to bring an annulment action directly before the EU courts.

### Judgment of the General Court (Tenth Chamber, Extended Composition) of 16 July 2025.#Lisa Ballmann v European Data Protection Board.#Protection of personal data – Complaint against the controller of personal data of users of an online social network in the European Union – Article 65(1)(a) of Regulation (EU) 2016/679 – Binding decision of the European Data Protection Board – Complainant’s request for access to the file prepared for the purposes of the binding decision – Refusal to grant access –

*Source: General Court, T-183/23, 2025-07-16 — https://overview.legal/posts/132139 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023TJ0183*

In Case T-183/23, Lisa Ballmann sought annulment of the European Data Protection Board's decision refusing her request for access to the file prepared for Binding Decision 3/2022, which concerned Meta Platforms Ireland's processing of personal data on Facebook. The core issue was whether the EDPB's refusal to grant the complainant access to that file—thereby limiting her ability to be heard in the Article 65(1)(a) GDPR dispute resolution procedure—was actionable and compatible with Article 41(2)(b) of the EU Charter of Fundamental Rights. The General Court ruled on the admissibility of the action and the scope of a complainant's procedural rights before the EDPB, with Meta Platforms Ireland intervening in support of the EDPB; no fine was imposed.

### CJEU - C‑313/23, C‑316/23 and C‑332/23 - Inspektorat kam Visshia sadeben savet

*Source: GDPRhub, 2025-04-30 — https://overview.legal/posts/158459 — original: https://gdprhub.eu/index.php?title=CJEU_-_C‑313/23,_C‑316/23_and_C‑332/23_-_Inspektorat_kam_Visshia_sadeben_savet*

Facts — Following the expiration of the prescribed time limit for submission of annual declarations of assets of judges, public prosecutors and investigating magistrates and their families, the Inspectorate at the Bulgarian Supreme Judicial Council requested the Sofia District Court to lift the banking secrecy of several judges and public prosecutors, as well as their families. The Inspectorate is comprised of an Inspector General and a panel of ten Inspectors. At the time, the terms of office of the Inspectorate members had been expired for two years and there was no provision in national law limiting the permissible extent of the extention of their duties . The referring Court was unsure as to whether the continuation of the performance of their duties by the Inspectorate past the expiry of their term undermines the independence of the Office under EU law and unsure as to the interplay between the provisions in the Bulgarian Constitution and the GDPR, and referred the following questions: (1) Must the second subparagraph of Article 19(1) TEU, read in conjunction with the second paragraph of Article 47 of [the Charter], be interpreted as meaning that it is per se or under certain conditions an infringement of the obligation incumbent on Member States to provide effective remedies sufficient to ensure independent judicial review for the functions of an authority which can impose disciplinary penalties on judges and has powers to collect data relating to their assets and liabilities to be indefinitely extended after the constitutionally stipulated term of office of that body comes to an end? If such an extension is permissible, under what conditions is that the case? (2) Must Article 2(2)(a) of [the GDPR] be interpreted as meaning that the disclosure of data covered by banking secrecy for the purposes of verifying assets and liabilities of judges and public prosecutors which are subsequently made public constitutes an activity which falls outside the scope of [EU] law? Is the answer different where that activity also includes the disclosure of data relating to family members of those judges and public prosecutors who are not judges or public prosecutors themselves? (3) If the answer to the second question is that [EU] law is applicable, must Article 4(7) of [the GDPR] be interpreted as meaning that a judicial authority which allows another State authority to access data concerning the account balances of judges and public prosecutors and their family members determines the purposes or means of the processing of personal data and is therefore a “controller” for the purposes of the processing of personal data? (4) If the answer to the second question is that [EU] law is applicable and the third question is answered in the negative, must Article 51 of [the GDPR] be interpreted as meaning that a judicial authority which allows another State authority to access data concerning the account balances of judges and public prosecutors and their family members is responsible for monitoring the application of that regulation and must therefore be classified as a “supervisory authority” in relation to those data? (5) If the answer to the second question is that [EU] law is applicable and either the third or the fourth questions are answered in the affirmative, must Article 32(1)(b) of [the GDPR] and Article 57(1)(a) of that regulation be interpreted as meaning that a judicial authority which allows another State authority to access data concerning the account balances of judges and public prosecutors and their families, is obliged, in the presence of [information] concerning a personal data breach committed in the past by the authority to which such access is to be granted, to obtain information on the data protection measures taken and to take into account the appropriateness of those measures in its decision to permit access? (6) If the answer to the second question is that [EU] law is applicable, and irrespective of the answers to the third and fourth questions, must Article 79(1) of [the GDPR], read in conjunction with Article 47 of [the Charter], be interpreted as meaning that, where the national law of a Member State provides that certain categories of data may be disclosed only after permission to do so has been granted by a court, the court so competent must of its own motion grant legal protection to the persons whose data are to be disclosed, by requiring the authority which has applied for access to the data in question and which is known to have committed a personal data breach in the past to provide information on the measures taken pursuant to Article 33(3)(d) of [the GDPR] and their effective application? Holding — Question 1: The Court ruled that that Article 19(1) TEU, read in light of Article 47 of the Charter must be interpreted as meaning that the principle of judicial independence precludes a Member State’s allowing the office holders of judicial body authorised to scrutinize the activities of judges, magistrates and public prosecutors to continue to perform their functions beyond their term where such extension does not have an explicit basis in national law which governs the exercise of such authority and where the extension is not limited in time. Question 2: The Court held that Article 2 of the GDPR must be interpreted as meaning that disclosures to judicial bodies of personal data concerning judges, public prosecutors and investigating magistrates, as well as their family members, with the view of verifying submitted declarations and are published constitutes processing within the material scope of the GDPR. The Court noted that it had previously found (Commission v Poland C-204/21) that neither the fact that information which is the subject of national provisions relates to judges nor the fact that information might have certain links with the performance of their duties is, in itself, sufficient to remove those national provisions from the scope of the GDPR. Although the proper administration of justice and rules relating to the performance and conduct of judges come within the competence of Member States, the processing in question does not fall within that category, nor is it an activity intended to safeguard national security, the Court found. Accordingly, the Court held that the processing in question comes under the material scope of the GDPR. Question 3: The Court held that Article 4(7) of the GDPR must be interpreted as meaning that a court competent to authorise disclosure by a bank to a judicial authority data relating to the bank accounts of judges, public prosecutors and magistrates, and their family members, cannot be classified as a controller under that provision. The Court reasoned that the national legislation determines the scope of such processing, the purpose of the processing and designates the body which is competent to carry it out. The national court, the Court found, confines itself to considering whether the conditions laid down in the national law are met. As such, the Court concluded that the national court determines neither the purposes nor the means and thus cannot be regarded as the controller under the GDPR. It is the designated body, in this case the Inspectorate, which is the controller. Question 4 The Court held that Article 51 of the GDPR must be interpreted as meaning that a court competent to authorise disclosure of personal data to another judicial body does not constitute a supervisory authority in the meaning of that provision. The Court reasoned that the national court has not been designated under Bulgarian law as a supervisory authority, as envisaged in Article 51(1) GDPR. Member States are also obliged to notify the Commission of such provisions adopted or amended pursuant to Chapter VI GDPR. No such notification had been made as to the designation of the national court as supervisory authority. Question 5: As the Court answered both questions 2 & 3 in the negative, no response to question 5 was necessary. Question 6: The Court held that Article 79(1) GDPR, read in light of Article 47 of the Charter, must be interpreted as meaning that a court competent to authorise disclosure of personal data to another judicial body is not required to ensure, of its own volition, the security of the personal data to be disclosed in accordance with the GDPR. This is the case even where the receiving body has, in the past, infringed those provisions of the GDPR. In reaching this conclusion, the Court highlighted the difference between supervisory authorities and their powers under the GDPR and the position of national courts. The Court also highlighted that it is the obligation of the Member State to ensure that practical arrangements have been made for the exercise of the remedies in Articles 77(1), 78(1) & 79(1).

### NSA - III OSK 5037/21

*Source: Supreme Administrative Court, 2025-04-29 — https://overview.legal/posts/125644 — original: https://gdprhub.eu/index.php?title=NSA_-_III_OSK_5037/21*

Facts — In March 2020, the Ombudsman requested the DPA to initiate proceedings regarding several laws that introduced an obligation for judges and prosecutors to declare their membership in an association, which would then be included in a Public Information Bulletin. The declarations of membership included associations to churches, religions, political parties, and functions similar to trade unions. The Ombudsman argued that the law was unconstitutional. In addition, the Ombudsman requested that the DPA issue an order restricting the processing of this data, specifically to prohibit the publication in the bulletin until proceedings were complete. The DPA dismissed the case in April 2020. The DPA stated that Article 6(1) GDPR provided a legal basis for the processing based on a legal obligation (Article 6(1)(c) GDPR) and necessity for the public interest (Article 6(1)(e) GDPR). Finally, the DPA stated that it did not have the competence under Article 57 GDPR to decide on the issue of constitutionality; this was a matter the Ombudsman should have taken to the Constitutional Court. The Ombudsman appealed the decision to the Court of First Instance, arguing that the DPA should have also considered whether the law fulfilled the requirements of public interest and proportionality under Article 6(3) GDPR. The Court upheld the reasoning of the DPA, stating that law has a legal basis in accordance with the GDPR. According to the Court, GDPR does not give the DPA broader powers, since the this was not foreseen by the EU legislator or provided by national law. The Ombudsman appealed the case to the Provincial Administrative Court, who dismissed the case. The Ombudsman requested the Court to reconsider, or alternatively, the Supreme Administrative Court. In addition, the Ombudsman requested the Supreme Administrative Court to refer a preliminary question to the EU Court of Justice (CJEU). The Provincial Administrative Court referred the case to the Supreme Administrative Court. In its complaint, the Ombudsman argued there was a violation of EU and national law due to the DPA’s and Court’s failure to act, as well as the law restricting the judges and prosecutor’s freedom of religion and assembly. The Ombudsman cited CJEU Case C-204/21 (European Commission v. Republic of Poland). In this case, the CJEU found that national legislation requiring judges to submit written declarations of membership in a political party violated Article 7 CFR and Article 8 CFR, as well as Article 6(1)(c) GDPR and Article 6(3) GDPR. In addition, the CJEU stated that it was insufficient for a national law to meet the formal criteria (e.g. by specifying the data processed and the storage period), it also needed to meet the qualitative criteria (public interest purpose and proportionality). Holding — The Supreme Administrative Court first dismissed the request of the Ombudsman to refer a preliminary question to the CJEU, on the basis that the case C-204/21 made the question irrelevant. Nonetheless, the Court stated that it had the obligation to take the CJEU case into account in assessing whether a national law is compatible with EU law, regardless of the issues raised in the appeal. Article 260(1) TFEU obliges the Court to take measures to ensure the implementation of a CJEU judgment stating that a Member State has not complied with its obligations under the Treaties. The Court considered that the Court of First Instance had misinterpreted Article 6(1)(c) GDPR and Article 6(1)(e) GDPR by limiting its interpretation to national laws. According to the Court, the decision did not consider the Constitution or the CFREU (Article 8 CFR and Article 10(1) CFR) and the European Convention of Human Rights (ECHR) (Article 8 ECHR and Article 9(1) ECHR and Article 9(2) ECHR ). The Court followed the reasoning of the CJEU in Case C-204/21 and concluded that the Polish law requiring judges and prosecutors to disclose their affiliation with religious, trade union and political organisations was a serious interference of their rights under the CFREU. The Polish law also violated Article 6(1)(c) GDPR and Article 6(1)(e) GDPR and Article 6(3) GDPR. The Court referred to the CJEU's reasoning in stating that the processing and publishing of judges' and prosecutors' personal data is likely to reveal their worldview and religious beliefs. This data belongs to the special category of personal data that has additional protections in accordance with Article 9(1) GDPR. The Court overturned the decision by the lower courts and the DPA.

### Judgment of the General Court (Tenth Chamber, Extended Composition) of 29 January 2025 (Extracts).#Data Protection Commission v European Data Protection Board.#Protection of personal data – Article 65(1)(a) of Regulation (EU) 2016/679 – Binding decision instructing a lead supervisory authority to broaden the scope of its investigation and issue a new draft decision – Competence of the European Data Protection Board.#Joined Cases T-70/23, T-84/23 and T-111/23.

*Source: General Court, T-70/23, 2025-01-29 — https://overview.legal/posts/132152 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023TJ0070*

The Irish Data Protection Commission (DPC) challenged provisions of EDPB Binding Decisions 3/2022, 4/2022, and 5/2022, arguing the EDPB exceeded its competence under Article 65(1)(a) GDPR by requiring the DPC to broaden its investigation into Facebook, Instagram, and WhatsApp and issue new draft decisions. The core legal issue was whether the EDPB, in the consistency mechanism context, can compel a lead supervisory authority to conduct additional investigations and produce new draft decisions beyond addressing the specific relevant and reasoned objections raised by concerned supervisory authorities. The General Court dismissed the DPC's actions, upholding the EDPB's authority to issue binding decisions instructing the lead supervisory authority to carry out further investigation and issue new draft decisions.

### Judgment of the Court (First Chamber) of 9 January 2025.#Österreichische Datenschutzbehörde v F R.#Request for a preliminary ruling from the Verwaltungsgerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 57(1)(f) and Article 57(4) – Tasks of the supervisory authority – Concepts of a ‘request’ and ‘excessive requests’ – Charging of a reasonable fee or refusal to act on requests in the e

*Source: Court of Justice of the European Union, C-416/23, 2025-01-09 — https://overview.legal/posts/132153 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0416*

In Case C-416/23, the Court of Justice of the European Union (First Chamber) ruled on a preliminary reference from the Austrian Supreme Administrative Court concerning the Austrian Data Protection Authority's (DSB) refusal to act on a complaint from individual F R regarding an alleged infringement of his right of access. The Court interpreted Article 57(4) and Article 77(1) of the GDPR, addressing the concepts of a "request" and "excessive requests" and the criteria guiding a supervisory authority's choice between charging a reasonable fee or refusing to act on manifestly unfounded or excessive requests. No fine was imposed, as the ruling solely provides interpretive guidance on the supervisory authority's tasks and obligations under the GDPR.

### Judgment of the Court (Third Chamber) of 28 November 2024.#Nemzeti Adatvédelmi és Információszabadság Hatóság v UC.#Request for a preliminary ruling from the Kúria.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data and the free movement of such data – Regulation (EU) 2016/679 – Data processed when drawing up a COVID-19 certificate – Data not collected from the data subject – Information to be provided – Exception to the obligation t

*Source: Court of Justice of the European Union, C-169/23, 2024-11-28 — https://overview.legal/posts/132158 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0169*

In Case C-169/23, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Kúria (Hungary) concerning whether the Budapest Metropolitan Government Office, as controller issuing COVID-19 immunity certificates, was required to provide information to data subjects under Article 14 GDPR where the personal data was not collected directly from them. The Court held that data generated by the controller in the context of its own processes falls within the Article 14(5)(c) exemption from the obligation to provide information, provided that Member State law ensures appropriate measures to protect the data subject's legitimate interests, including data security measures under Article 32. The Court also confirmed that supervisory authorities retain competence to handle complaints under Article 77(1) even where the Article 14(5)(c) exemption applies.

### Judgment of the Court (First Chamber) of 26 September 2024.#TR v Land Hessen.#Request for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 57(1)(a) and (f) – Tasks of the supervisory authority – Article 58(2) – Corrective powers – Administrative fine – Discretion of the supervisory authority – Limits.#Case C-768/21.

*Source: Court of Justice of the European Union, C-768/21, 2024-09-26 — https://overview.legal/posts/132245 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0768*

In Case C-768/21, the Court of Justice of the European Union (First Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden concerning TR's challenge of the Hessischer Beauftragte für Datenschutz und Informationsfreiheit (HBDI) for declining to exercise corrective powers against Sparkasse X following a personal data breach complaint. The Court clarified the limits of supervisory authorities' discretion under GDPR Articles 57(1) and 58(2), holding that while authorities retain discretion in selecting corrective measures, they are legally obliged to exercise those powers when an infringement is established, and complainants have a right to an effective remedy under Article 77 even where no enforcement action was taken. No fine was imposed in this proceeding, as the ruling addressed the supervisory authority's enforcement obligations rather than penalizing a controller.

### Judgment of the Court (Fourth Chamber) of 11 July 2024.#Meta Platforms Ireland Limited v Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband e.V.#Request for a preliminary ruling from the Bundesgerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – First sentence of Article 12(1) – Transparency of information – Article 13(1)(c) and (e) – Obligation o

*Source: Court of Justice of the European Union, C-757/22, 2024-07-11 — https://overview.legal/posts/132250 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0757*

In a preliminary ruling requested by the German Federal Court of Justice (Bundesgerichtshof), the Court of Justice of the European Union interpreted Article 80(2) GDPR in the context of proceedings between Meta Platforms Ireland Ltd and the Bundesverband der Verbraucherzentralen und Verbraucherverbände (Consumer Association). The core issue is whether a consumer protection association may bring a representative action under Article 80(2) GDPR without a mandate from specific data subjects and independently of an actual infringement of a data subject's rights, based on a controller's alleged violation of its transparency obligations under Articles 12(1) and 13(1)(c) and (e). The Court held that such an action is permissible, finding that an infringement of the controller's information obligations constitutes an "infringement of the rights of data subjects as a result of the processing" within the meaning of Article 80(2), and that Member States may allow representative actions without requiring a specific data subject's mandate or an actual infringement of individual rights.

## Guidance

### Guidelines 02/2022 on the application of Article 60 GDPR

*Source: EDPB, edpb-guidelines-on-the-application-of-article-60-gdpr, 2022-03-14 — https://overview.legal/posts/38066 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-022022-on-the-application-of-article-60-gdpr_en*

With the introduction of the GDPR, the concept of the one-stop shop was established as one of the main innovations. In cross-border processing cases, the supervisory authority in the Member State of the controller's or processor's main establishment is the authority leading the  enforcement of the GDPR for the respective cross-border processing activities, in cooperation with all the authorities which may face the effects of the processing activities at stake: be it  through  the establishments ...

### Guidelines 06/2022 on the practical implementation of amicable settlements

*Source: EDPB, edpb-guidelines-on-the-practical-implementation-of-amicable-settlements, 2022-05-12 — https://overview.legal/posts/38072 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-062022-on-the-practical-implementation-of-amicable-settlements_en*

The EDPB adopted Guidelines 06/2022 to provide practical guidance on the implementation of amicable settlements between supervisory authorities and controllers or processors under the GDPR. The guidelines address the scope and definition of amicable settlements, the legal basis for this power, and its procedural operation within the one-stop-shop mechanism, including the roles of the complaint-receiving competent supervisory authority and the lead supervisory authority. No fines are imposed as this is a guidance document rather than an enforcement decision.

### Statement on the ePrivacy Regulation and the future role of Supervisory Authorities and the EDPB

*Source: EDPB, statement-on-the-eprivacy-regulation-and-the-future-role-en, 2020-11-19 — https://overview.legal/posts/126113 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-on-the-eprivacy-regulation-and-the-future-role_en*

1 Statement on the ePrivacy Regulation and the future role of Supervisory Authorities and the EDPB Adopted on 19 November 2020 The European Data Protection Board has adopted the following statement: Firstly, the EDPB wants to stress that this statement is without prejudice to its previous positions , including s tatement 3/2019 1 and its statement of 25 May 2018 2 . The ePrivacy Regulation must under no circumstances lower the level of protection offered by the curren t ePrivacy Directive…

### Article 65 FAQ

*Source: EDPB, article-65-faq-en, 2020-11-10 — https://overview.legal/posts/126115 — original: https://www.edpb.europa.eu/documents/other-guidance/article-65-faq_en*

Article 65 FAQ How does cross - border cooperation work under the GDPR? The G eneral D ata P rotection R egulation (GDPR) requires the Supervisory Authorities (SAs) of the European Economic Area (EEA) to cooperate closely - under the umbrella of the European Data Protection Board (EDPB) - to ensure the consistent application of the GDPR and the protection of individuals’ data protection rights across the EEA. One of their tasks is to coordinate decision - making in cross - border data…

### Opinion 10/2020 on the draft decision of the competent supervisory authorities of Germany regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR

*Source: EDPB, opinion-102020-on-the-draft-decision-of-the-competent-en, 2020-05-25 — https://overview.legal/posts/126147 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-102020-on-the-draft-decision-of-the-competent_en*

1 Adopted Opinion 10 /2020 on the draft decision of the competent supervisory authorities of Germany regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR Adopted on 25 May 2020 2 Adopted 3 Adopted The European Data Protection Board Having regard to Article 63, Article 64 (1)(c), (3) - (8) and Article 41 (3) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of…

### EDPB Annual Report 2019

*Source: EDPB, edpb-annual-report-2019-en, 2020-05-18 — https://overview.legal/posts/126163 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-annual-report-2019_en*

EDPB Annual Report 2019 1 EDPB Annual Report 2019 1 European Data Protection Board 2019 Annual Report WORKING TOGETHER FOR STRONGER RIGHTS An Executive Summary of this report, which provides an overview of key EDPB activities in 2019, is also available. Further details about the EDPB can be found on our website at edpb.europa.eu. EDPB Annual Report 2019 EDPB Annual Report 2019 2 3 FOREWORD 1 4 MISSION STATEMENT, TASKS AND PRINCIPLES 2 5 Tasks and duties Guiding principles 5 6 2.1. 2.2 . ABOUT…

### EDPB LIBE report on the implementation of GDPR

*Source: EDPB, edpb-libe-report-on-the-implementation-of-gdpr-en, 2019-02-26 — https://overview.legal/posts/126238 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-libe-report-on-the-implementation-of-gdpr_en*

1 First overview on the implementation of the GDPR and the roles and means of the national supervisory authorities Executive Summary This document sets out an overview of the implementation and enforcement of the General Data Protection Regulation (GDPR) covering both the cooperation mechanism and the consistency findings . In comparison with the EC Directive 95/46/EC , where Supervisory Authorities (SAs) were working separately even on cross - border cases , the GDPR created a duty for the SAs…

### Opinion 4/2019 on the draft AA between EEA and non-EEA Financial Supervisory Authorities

*Source: EDPB, opinion-42019-on-the-draft-aa-between-eea-and-non-eea-en, 2019-02-12 — https://overview.legal/posts/126248 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-42019-on-the-draft-aa-between-eea-and-non-eea_en*

adopted 1 Opinion 4 / 2019 on the draft Administrative Arrangement for the transfer of personal data between European Economic Area (“EEA”) Financial Supervisory Authorities and non - EEA Financial Supervisory Authorities Adopted on 12 February 2019 adopted 2 4 Final remarks ................................ ................................ ................................ ................................ ... 8 adopted 3 The European Data Protection Board Having regard to Article 63, Article 64…

## Enforcement decisions

### EDPB - Binding Decision 1/2026

*Source: EDPB, 2026-05-28 — https://overview.legal/posts/144037 — original: https://gdprhub.eu/index.php?title=EDPB_-_Binding_Decision_1/2026*

Facts — On 10 August 2021, a data subject represented by noyb lodged a complaint with the Austrian DPA against Vlaamse Radio- en Televisieomroeporganisatie (VRT), the controller. The complaint concerned the controller’s cookie banner and alleged infringements of Articles 5(1)(a), 6(1)(a), 12(1), 12(2) and 13(1)(c) GDPR, as well as Article 5(3) ePrivacy Directive. It formed part of a wider project involving similar cookie banner complaints submitted by noyb across the EEA. The Austrian DPA transferred the complaint to the Belgian DPA, which acted as the lead supervisory authority. In its draft decision, the DPA proposed dismissing the complaint without examining its merits. It considered that the data subject and noyb had abused the rights provided under Articles 77 and 80(1) GDPR. The DPA relied on factors including the standardised and partly automated preparation of the complaints, noyb’s role in selecting the targeted controllers, the relationship between the data subject and noyb, and the broader strategic objectives pursued by the organisation. It considered that both the objective and subjective elements required to establish an abuse of rights were present. The Austrian DPA raised a relevant and reasoned objection under Article 60(4) GDPR. It argued that the circumstances did not demonstrate an abuse of rights and requested that the complaint be examined on its merits in accordance with Article 57(1)(f) GDPR. As the DPA did not follow the objection, it referred the dispute to the EDPB under Article 65(1)(a) GDPR. Holding — The EDPB first held that it was competent to decide the dispute. Its powers under Article 65(1)(a) GDPR are not limited to determining whether a controller infringed the GDPR. They also cover disputes concerning whether an action envisaged by a supervisory authority, including the dismissal of a complaint, complies with the GDPR. The EDPB found that the Austrian DPA’s objection met the requirements of Article 4(24) GDPR. The objection was directly connected to the draft decision, proposed a different outcome and sufficiently demonstrated the risks that the dismissal would create for data subjects’ rights and the consistent application of the GDPR. On the merits, the EDPB recalled that the prohibition of abuse of rights must be interpreted strictly, particularly where its application may restrict the fundamental right to data protection and the rights provided by Articles 77 and 80(1) GDPR. The supervisory authority alleging abuse bears the burden of establishing both its objective and subjective elements on the basis of sufficient evidence. Regarding the objective element, the EDPB acknowledged that noyb had organised a project involving predefined selection criteria, standardised complaints and automated tools. However, the data subject had validly mandated noyb under Article 80(1) GDPR and had lodged a complaint concerning an alleged infringement of their own data protection rights. Consequently, the objectives of Articles 77 and 80(1) GDPR had been fulfilled rather than circumvented. Regarding the subjective element, the EDPB found no evidence that the complaint had been submitted to obtain an undue advantage unrelated to the purposes of the GDPR. The objectives pursued by noyb could not be separated from those of the data subject merely because the organisation had played a leading role in preparing the complaint. Nor was there evidence that the data subject or noyb had sought compensation or another financial benefit. The EDPB therefore concluded that the data subject had not abused the right to lodge a complaint under Article 77 GDPR or the right to be represented under Article 80(1) GDPR. It instructed the DPA not to dismiss the complaint on that basis, to assess it on its merits and to submit a new draft decision to the supervisory authorities concerned under Article 60(3) GDPR.

### FUENSANTA S.L.: Insufficient cooperation with supervisory authority

*Source: Spanish Data Protection Authority (aepd), 2021-11-23 — https://overview.legal/posts/47028 — original: https://www.enforcementtracker.com/ETid-913*

The controller failed to provide information requested by the Spanish DPA (AEPD) for investigative purposes.

### Privacy Appeals Board: Datatilsynet may demand information from OpenX under GDPR Art.

*Source: Datatilsynet (Norway), 2020-09-07 — https://overview.legal/posts/122844 — original: https://gdprhub.eu/index.php?title=Datatilsynet_(Norway)-_20/02254*

Facts — The Norwegian Consumer Council (Forbrukerrådet) filed three complaints against the gay/bi dating app Grindr and five adtech companies that received personal data through the app. Subsequently, Datatilsynet sent a request for more information from one of the adtech companies; OpenX. OpenX refused to respond on the basis that Datatilsynet does not have legal grounds to impose such a request on them, because, in their opinion, the issue relates to the Electronic Communications Act § 2(7)(b) (cf. Article 5(3) ePrivacy Directive 2002/58/EC), where the Norwegian Communications Authority is the right supervisory authority (and not Datatilsynet), and filed a complaint to the Privacy Appeals Board. Dispute — Does the Datatilsynet have the legal grounds (as a supervisory authority) to impose a request for information on OpenX? Holding — The Privacy Appeals Board rejected OpenX's complaint as they concluded that Datatilsynet has legal grounds to impose such requests for information as per Article 58(1) GDPR.

### Globus Score SRL: Insufficient cooperation with supervisory authority

*Source: Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), 2019-12-16 — https://overview.legal/posts/46260 — original: https://www.enforcementtracker.com/ETid-145*

The company did not comply with measures ordered by the National Supervisory Authority.

### Modern Barber: Insufficient cooperation with supervisory authority

*Source: Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), 2019-11-26 — https://overview.legal/posts/46263 — original: https://www.enforcementtracker.com/ETid-148*

The company did not comply with measures ordered by the National Supervisory Authority.

### Housing Association: Insufficient cooperation with supervisory authority

*Source: Spanish Data Protection Authority (aepd), 2026-03-13 — https://overview.legal/posts/53582 — original: https://www.enforcementtracker.com/ETid-3131*

Spanish Data Protection Authority (aepd) fined Housing Association €450 on 2026-03-13 for: Insufficient cooperation with supervisory authority.

### SPAIN DPA: Insufficient cooperation with supervisory authority

*Source: Spanish Data Protection Authority (aepd), 2025-12-20 — https://overview.legal/posts/51497 — original: https://www.enforcementtracker.com/ETid-2986*

The Spanish DPA has imposed a fine of EUR 300 on an unkonwn person/entity. The controller failed to react to requests made by the DPA.

### Entrepreneur: Insufficient cooperation with supervisory authority

*Source: Polish National Personal Data Protection Office (UODO), 2025-07-28 — https://overview.legal/posts/48879 — original: https://www.enforcementtracker.com/ETid-2764*

The Polish DPA has imposed a fine of EUR 4,400 on an Entrepreneur. The controller failed to adequatly react to a request from the DPA.

## Recent developments

### UODO (Poland) - DKE.561.1.2026

*Source: GDPRhub, 2026-08-18 — https://overview.legal/posts/291290 — original: https://gdprhub.eu/index.php?title=UODO_(Poland)_-_DKE.561.1.2026*

The DPA reprimanded a company for refusing to cooperate with the supervisory authority: the controller had failed to provide information on the processing of personal data in two pending cases against it. English Summary. Facts. The DPA received two complaints against the same company (the controller) due to the unauthorised access to the data subjects’ personal data. The first complaint concerned processing that had taken place in January 2025, while the events giving rise to the second complai

### EDPB calls for legal basis for cross-regulatory information sharing

*Source: European Data Protection Board, 2026-07-17 — https://overview.legal/posts/125636 — original: https://www.edpb.europa.eu/news/edpb-calls-for-legal-basis-for-cross-regulatory-information-sharing_en*

Dublin, 17 July– At a high-level meeting in Dublin on 16 and 17 July 2026, the European Data Protection Board (EDPB) called for a clear legal basis for the sharing of information among regulators with different competences. The Board also discussed how to further expand efforts to support a consistent application of the General Data Protection Regulation (GDPR), including through more intense cooperation between Data Protection Authorities (DPAs).A clear legal basis for efficient cross-regulator

### EDPB requires Belgian DPA to handle the merits of NOYB cookie banner complaint

*Source: European Data Protection Board, 2026-07-14 — https://overview.legal/posts/96831 — original: https://www.edpb.europa.eu/news/edpb-requires-belgian-dpa-to-handle-the-merits-of-noyb-cookie-banner-complaint_en*

Brussels, 14 July–The EDPB has published its binding decision of 28 May 2026 under Art.65(1)(a) GDPR*. The decision concerns a dispute submitted by the Belgian Data Protection Authority (DPA) about a complaint against Vlaamse Radio-en Televisieomroeporganisatie (VRT) – a public broadcasting company based in Belgium.The complaint was lodged with the Austrian DPA by the Austrian-based NGO Noyb on behalf of an individual. It concerns the use of cookie banners on the website of VRT.The Belgian DPA,

### Toezichthouders: versnel de overgang naar meer digitale autonomie

*Source: Autoriteit Persoonsgegevens, 2026-07-10 — https://overview.legal/posts/83498 — original: https://autoriteitpersoonsgegevens.nl/actueel/toezichthouders-versnel-de-overgang-naar-meer-digitale-autonomie*

Bedrijven kunnen vaker gezamenlijk optrekken wanneer zij contracten afsluiten met IT-leveranciers. Dat is belangrijk om hun digitale autonomie te versterken. En overheden en bedrijven zouden digitale autonomie nadrukkelijk moeten meewegen bij de inkoop van IT-diensten. Zo kunnen zij optreden als aanjager van Europese digitale diensten.

### Supporting GDPR consistency: EDPB launches dedicated form

*Source: European Data Protection Board, 2026-06-24 — https://overview.legal/posts/53056 — original: https://www.edpb.europa.eu/news/supporting-gdpr-consistency-edpb-launches-dedicated-form_en*

Brussels, 24 June – The EDPB has launched a dedicated contact form for stakeholders to report possible inconsistencies in how the GDPR is interpreted across Europe. This initiative reflects the commitments set out in the EDPB Helsinki Statement on enhanced clarity, support and engagement, aimed at strengthening the dialogue with stakeholders and ensuring consistent GDPR enforcement across Europe.The new tool enables stakeholders to report alleged divergences between national positions, as well a

## Literature

### Complete Independence of national Data Protection Supervisory Authorities: About persons, czars and data governance in Belgian debates

*Source: European Law Blog, 2021-12-24 — https://overview.legal/posts/132495 — original: https://doi.org/10.21428/9885764c.7197cf15*

### `Data Protection, Privacy Regulators and Supervisory Authorities` by Jacob Kornbeck

*Source: Journal of Data Protection Privacy, 2021-03-01 — https://overview.legal/posts/132492 — original: https://doi.org/10.69554/jyow6251*

### The independence requirement for national data protection supervisory authorities.

*Source: PinG Privacy in Germany, 2019-04-26 — https://overview.legal/posts/132494 — original: https://doi.org/10.37307/j.2196-9817.2019.03.07*

### The Wirtschaftsakademie Fan Page Decision: A Landmark on Joint Controllership – A Challenge for Supervisory Authorities Competences

*Source: European Data Protection Law Review, 2018-01-01 — https://overview.legal/posts/132499 — original: https://doi.org/10.21552/edpl/2018/4/21*

### European Union ∙ EDPB Opinion on the Draft Lists of Competent Supervisory Authorities Regarding the Processing Operations Subject to DPIAs

*Source: European Data Protection Law Review, 2018-01-01 — https://overview.legal/posts/132500 — original: https://doi.org/10.21552/edpl/2018/4/13*

## Tools

### GDPR Enforcement Tracker (fines and penalties database)

*Source: CMS, 2026-07-17 — https://overview.legal/posts/125626 — original: https://www.enforcementtracker.com/*

Continuously updated database by CMS of thousands of GDPR fines and penalties across all member states: authority, amount, date, sector, violated articles and a summary per decision, with filtering and statistics. The de-facto reference for fine benchmarking.

## Related topics

- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Data Controller** — https://overview.legal/topics/verwerkingsverantwoordelijke
  The entity that determines purposes and means of processing personal data
- **Monitoring** — https://overview.legal/topics/monitoring
  Systematic observation and tracking of individuals

---
Generated by overview.legal · https://overview.legal/topics/toezicht · 2026-08-22
