# Transparency — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/transparantie
> Sources are cited per item. Verify against the official texts before relying on them.

Openness about data processing activities

## Overview

## Legal Framework

Transparency is established as a foundational data protection principle under [Article 5(1)(a) GDPR](/laws/gdpr/art-5), requiring that personal data be:

This principle operates not in isolation but as an enabling condition: without transparent information provision, other GDPR rights — including consent withdrawal and access — become functionally inaccessible. The EDPB has framed this in stark terms:

> "If the controller does not provide accessible information, user control becomes illusory and consent will be an invalid basis for processing."
> — [EDPB Guidelines 05/2020 §62](/posts/38053#seg-62)

In the employment context, [Article 88(2) GDPR](/laws/gdpr/art-88#par-2) requires member states to adopt specific measures safeguarding the transparency of processing alongside data transfers and workplace monitoring — recognizing that power imbalances in employment demand heightened transparency obligations.

The AI Act extends transparency obligations beyond traditional data protection. [Article 1(2)(d)](/laws/ai-act/art-1#par-2-pnt-d) establishes "harmonised transparency rules for certain AI systems," while [Article 112(2)(b)](/laws/ai-act/art-112#par-2-pnt-b) provides for periodic review of which AI systems require additional transparency measures under Article 50 of the AI Act.

## Key Developments

The CJEU's jurisprudence reveals that transparency is not an absolute value but must be balanced against competing fundamental rights. In *Client Earth v. EFSA*, the Court established a critical baseline:

> "no automatic priority can be conferred on the objective of transparency over the right to protection of personal data"
> — [Client Earth ¶51](/posts/5958#seg-51)

Yet the same case affirmed transparency's democratic function:

> "The transparency of the process followed by a public authority for the adoption of a measure of that nature contributes to that authority acquiring greater legitimacy"
> — [Client Earth ¶56](/posts/5958#seg-56)

The *Schrems* litigation exposed how transparency deficits in international transfer frameworks — specifically "structural shortcomings related to transparency and enforcement" — can invalidate entire adequacy mechanisms. The *Schecke* ruling grounded transparency obligations in the European Transparency Initiative, linking public fund disclosure to sound financial management.

Italian DPA enforcement illustrates practical failure modes: the Garante fined a health authority €20,000 for publishing personal data in a resolution, and €50,000 against an agency whose remote work policy lacked adequate transparency.

## Status of the Debate

This topic is actively contested in court. The core tension — transparency versus data protection — has been addressed at the principle level in *Client Earth*, but operational boundaries remain unresolved. Courts diverge on how to weigh transparency interests when disclosure would expose personal data, particularly in institutional decision-making involving expert advisors with vested interests. No definitive court split is on record, but the balancing test lacks granular criteria. Resolution will likely require further CJEU guidance on proportionality assessment — specifically, whether the necessity test for transparency disclosure should require consideration of anonymization alternatives before raw personal data is exposed.

## Practical Guidance

- **Implement layered information architecture**: EDPB guidance endorses "layered and granular information" to reconcile completeness with accessibility — provide concise summaries with drill-down capability for full details.
- **Conduct transparency-by-design assessments**: For each processing activity, document what information is provided, when, and through what channel, mapping directly to [Article 5(1)(a)](/laws/gdpr/art-5#par-1-pnt-a) requirements.
- **Apply heightened transparency in employment contexts**: Under [Article 88(2)](/laws/gdpr/art-88#par-2), implement specific measures addressing workplace monitoring, data transfers within corporate groups, and employee dignity — go beyond generic privacy notices.
- **Assess AI system transparency obligations early**: With the AI Act's harmonised transparency rules under [Article 1(2)(d)](/laws/ai-act/art-1#par-2-pnt-d) and periodic review under [Article 112(2)(b)](/laws/ai-act/art-112#par-2-pnt-b), classify AI systems proactively and prepare disclosure mechanisms for affected individuals.
- **Document the transparency–privacy balance**: When transparency obligations intersect with personal data protection, record the proportionality analysis — including consideration of anonymization or partial disclosure — to demonstrate compliance with the *Client Earth* balancing standard.

## Legislation (full text of key provisions)

### Transparency obligations for providers and deployers of certain AI systems

*Source: AI Act, aiact-art-50-en, 2024-06-12 — https://overview.legal/posts/92746*

### Transparency and provision of information to deployers

*Source: AI Act, aiact-art-13-en, 2024-06-12 — https://overview.legal/posts/92180*

### Transparency reporting obligations for providers of online platforms

*Source: DSA, dsa-art-24-en, 2022-10-19 — https://overview.legal/posts/94410*

### Transparency reporting obligations

*Source: DSA, dsa-art-42-en, 2022-10-19 — https://overview.legal/posts/94760*

### Recommender system transparency

*Source: DSA, dsa-art-27-en, 2022-10-19 — https://overview.legal/posts/94451*

### Additional online advertising transparency

*Source: DSA, dsa-art-39-en, 2022-10-19 — https://overview.legal/posts/94672*

### Transparency reporting obligations for providers of intermediary services

*Source: DSA, dsa-art-15-en, 2022-10-19 — https://overview.legal/posts/94226*

### Recital 134 — deep fake transparency labelling obligations

*Source: AI Act, aiact-rec-134-en, 2024-06-12 — https://overview.legal/posts/93950*

Further to the technical solutions employed by the providers of the AI system, deployers who use an AI system to generate or manipulate image, audio or video content that appreciably resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful (deep fakes), should also clearly and distinguishably disclose that the content has been artificially created or manipulated by labelling the AI output accordingly and disclosing its artificial origin. Compliance with this transparency obligation should not be interpreted as indicating that the use of the AI system or its output impedes the right to freedom of expression and the right to freedom of the arts and sciences guaranteed in the Charter, in particular where the content is part of an evidently creative, satirical, artistic, fictional or analogous work or programme, subject to appropriate safeguards for the rights and freedoms of third parties. In those cases, the transparency obligation for deep fakes set out in this Regulation is limited to disclosure of the existence of such generated or manipulated content in an appropriate manner that does not hamper the display or enjoyment of the work, including its normal exploitation and use, while maintaining the utility and quality of the work. In addition, it is also appropriate to envisage a similar disclosure obligation in relation to AI-generated or manipulated text to the extent it is published with the purpose of informing the public on matters of public interest unless the AI-generated content has undergone a process of human review or editorial control and a natural or legal person holds editorial responsibility for the publication of the content.

### Recital 137 — transparency compliance not implying lawfulness

*Source: AI Act, aiact-rec-137-en, 2024-06-12 — https://overview.legal/posts/93956*

Compliance with the transparency obligations for the AI systems covered by this Regulation should not be interpreted as indicating that the use of the AI system or its output is lawful under this Regulation or other Union and Member State law and should be without prejudice to other transparency obligations for deployers of AI systems laid down in Union or national law.

### Recital 101 — General-purpose AI model provider transparency obligations

*Source: AI Act, aiact-rec-101-en, 2024-06-12 — https://overview.legal/posts/93884*

Providers of general-purpose AI models have a particular role and responsibility along the AI value chain, as the models they provide may form the basis for a range of downstream systems, often provided by downstream providers that necessitate a good understanding of the models and their capabilities, both to enable the integration of such models into their products, and to fulfil their obligations under this or other regulations. Therefore, proportionate transparency measures should be laid down, including the drawing up and keeping up to date of documentation, and the provision of information on the general-purpose AI model for its usage by the downstream providers. Technical documentation should be prepared and kept up to date by the general-purpose AI model provider for the purpose of making it available, upon request, to the AI Office and the national competent authorities. The minimal set of elements to be included in such documentation should be set out in specific annexes to this Regulation. The Commission should be empowered to amend those annexes by means of delegated acts in light of evolving technological developments.

## Case law

### Order of the Vice-President of the Court of 25 February 2025.#WebGroup Czech Republic a.s. v European Commission.#Appeal – Interim relief – Approximation of laws – Regulation (EU) 2022/2065 – Single market for digital services – Article 33(4) – Designation as a very large online platform – Article 39 – Additional online advertising transparency – Action for annulment – Weighing up of interests.#Case C-620/24 P(R).

*Source: Court of Justice of the European Union, C-620/24, 2025-02-25 — https://overview.legal/posts/132148 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62024CO0620*

In Case C-620/24 P(R), WebGroup Czech Republic a.s., the operator of the adult content platform XVideos, appealed to the Court of Justice seeking to set aside a General Court order that denied interim suspension of a European Commission decision designating XVideos as a very large online platform (VLOP) under the Digital Services Act. WebGroup sought to suspend the Article 39 obligation to make publicly available an advertising transparency repository, arguing that compliance would jeopardize the platform's advertising-based business model and financial viability. The Vice-President of the Court dismissed the appeal, upholding the General Court's finding that while prima facie case and urgency conditions were met, the interests defended by the EU legislature in protecting online advertising transparency prevailed over the appellant's interests.

### Judgment of the Court (Fourth Chamber) of 11 July 2024.#Meta Platforms Ireland Limited v Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband e.V.#Request for a preliminary ruling from the Bundesgerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – First sentence of Article 12(1) – Transparency of information – Article 13(1)(c) and (e) – Obligation o

*Source: Court of Justice of the European Union, C-757/22, 2024-07-11 — https://overview.legal/posts/132250 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0757*

In a preliminary ruling requested by the German Federal Court of Justice (Bundesgerichtshof), the Court of Justice of the European Union interpreted Article 80(2) GDPR in the context of proceedings between Meta Platforms Ireland Ltd and the Bundesverband der Verbraucherzentralen und Verbraucherverbände (Consumer Association). The core issue is whether a consumer protection association may bring a representative action under Article 80(2) GDPR without a mandate from specific data subjects and independently of an actual infringement of a data subject's rights, based on a controller's alleged violation of its transparency obligations under Articles 12(1) and 13(1)(c) and (e). The Court held that such an action is permissible, finding that an infringement of the controller's information obligations constitutes an "infringement of the rights of data subjects as a result of the processing" within the meaning of Article 80(2), and that Member States may allow representative actions without requiring a specific data subject's mandate or an actual infringement of individual rights.

### Order of the Vice-President of the Court of 6 September 2024.#Aylo Freesites LTD v European Commission.#Appeal – Interim relief – Approximation of laws – Regulation (EU) 2022/2065 – Single market for digital services – Additional online advertising transparency – Decision to designate as a very large online platform – Action for annulment – Balancing of competing interests.#Case C-511/24 P(R).

*Source: Court of Justice of the European Union, C-511/24, 2024-09-06 — https://overview.legal/posts/132247 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62024CO0511*

### Order of the Vice-President of the Court of 27 March 2024.#European Commission v Amazon Services Europe Sàrl.#Appeal – Interim relief – Approximation of laws – Regulation (EU) 2022/2065 – Single market for digital services – Additional online advertising transparency – Decision to designate a very large online platform – Action for annulment.#Case C-639/23 P(R).

*Source: Court of Justice of the European Union, C-639/23, 2024-03-27 — https://overview.legal/posts/132264 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CO0639(01)*

### BVwG - W256 2227693-1

*Source: Federal Administrative Court, 2023-09-28 — https://overview.legal/posts/125664 — original: https://gdprhub.eu/index.php?title=BVwG_-_W256_2227693-1*

Facts — On 05.09.2019, the Austrian DPA (DSB) notified the controller of a customer loyalty program that they were initiating an ex officio investigation. The controller responded by answering the provided questionnaire and submitting further documents. On 23.10.2019, the DPA ruled that the investigation was justified and that the declaration of consent for profiling using certain registration methods (website, app, partner company store, flyer) did not comply with the requirements of Article 4(11) GDPR and Article 7 GDPR, nor were they provided in an intelligible way. If a contract covers several aspects, the declaration of consent must be clearly distinguishable. Regarding the website and flyer, the following was found: The website says 'Enjoy your personal benefits' without providing clear information that 'personal benefits' involves profiling. In an embedded box, the relevant points were merely referred to. Information regarding profiling was only accessible by scrolling down further. Concerning the flyer, the following information was provided under the signature field: 'This signature only applies to the declaration of consent and is voluntary. Your registration [...] is also valid without a signature.' Thus, it conveyed the impression that a signature was required to confirm the registration. Consequently, the controller was required to amend the declaration and to cease using any obtained consents for the purpose of profiling prior to 01.05.2020. The controller lodged a complaint. In addition to other information, the controller stated that the data processing was in accordance with Article 6(1)(a) GDPR, and that they had a legitimate interest under Article 6(1)(f) GDPR. The DPA ruled a preliminary decision on the complaint, thereby changing the ruling that the website and flyer did not meet the requirements under Article 6(1)(a) GDPR, and thus, the processing of personal data, collected in that cases, was forbidden. The other methods ensured that the consent was clearly separated from the rest of the registration process. The controller then filed a request for referral to the court, arguing that the DPA had exceeded their corrective powers by prohibiting the processing of the data. Furthermore, the data processing for profiling would be used to manage customer memberships under Article 6(1)(b) GDPR. Following their view, processing under Article 6(4) GDPR was applicable. Additionally, the controller denied the DPA's view that a violation of the principle of good faith would foreclose a weighing of interests under Article 6(1)(f) GDPR. The court quashed the preliminary decision as the DPA had not examined the other grounds of justification for data processing under Article 6(1) GDPR in their initial decision. The DPA then lodged an appeal to the Austrian Supreme Administrative Court (Verwaltungsgerichtshof), which overturned the court's ruling (VwGH 08.02.2022, Ro 2021/04/0033). It was the court's responsibility to examine the potential legal bases, rather than overturning the DPA's decision. Therefore, the case was returned to the court. In the meantime, the controller complied with the preliminary decision by deleting the affected personal data in 2021 and changing their registration process in 2020. Holding — First, the court found that they had to formally rule on whether the DPA's decision was lawful at the time it was ruled. It is not to be considered that the controller complied with the administrative decision and fulfilled the required steps (VwGH 28.04.2022, Ra 2022/06/0056). Second, the court held that the controller did not comply with the transparency requirements regarding the layout of their declaration of consent under Article 7(2) GDPR in both cases (website, flyer). Third, the court ruled that they could not agree with DPA's view, that an invalid declaration of consent always constitutes unlawful data processing and that a review of other grounds of justification would not be necessary (CLEU in 'Meta Platforms and Others' (C-252/21) ECLI:EU:C:2023:537). Further on, the Supreme Administrative Court ruled that both, the DPA and the court are required to examine the presence of other grounds (VwGH 08.02.2022, Ro 2021/04/0033). Fourth, the court held that the controller could not base their appeal on Article 6(4) GDPR as the data processing did not satisfy the grounds of justification, nor were other grounds apparent. Inter alia, following the CLEU's preliminary ruling in 'Meta Platforms and Others' (C-252/21) ECLI:EU:C:2023:537, three cumulative requirements must be met for data processing under Article 6(1)(f) GDPR: (1) The controller or a third party must have a legitimate interest, (2) which requires the processing of that personal data, (3) and 'the fundamental rights and freedoms of the data subject' must not outweigh those interests. There were no doubts about the controller's legitimate interest in processing the personal data in question for targeted marketing purposes, as this was both necessary and reasonable. However, the data subject should have been notified about profiling. The wording 'only if the member consents' did not constitute such a notification, and therefore the data subjects were not to be expected that their personal data was used for profiling purposes. Furthermore, the controller explicitly excluded it in their general terms and conditions. Hence, the data subject's right to secrecy overrode the controller's legitimate interest. In summary, the court dismissed the controller's complaint. Last, the court held that an appeal to the Supreme Administrative Court was admissible under Article 133(4) B-VG, as no prevailing case law concerning the implementation of a declaration of consent existed. Hence, the decision relied on a legal question of fundamental importance.

### OLG Köln - 15 W 55/26

*Source: Higher Regional Court Cologne, 2026-06-12 — https://overview.legal/posts/53657 — original: https://gdprhub.eu/index.php?title=OLG_Köln_-_15_W_55/26*

Facts — The data subject, a doctor, sought an injunction against the Controller, the operator of an online review platform, requiring the removal of, and prohibiting the future publication of, a notice stating that between six and ten reviews concerning his medical practice had been removed during the previous year following complaints relating to defamation under German law. The Regional Court of Cologne dismissed the application, following which the data subject lodged an immediate appeal before the Higher Regional Court of Cologne. The data subject argued that the notice was inaccurate because the reviews had been challenged on the basis that no genuine patient relationship existed, rather than on the ground of defamation. He submitted that the notice therefore created the false impression that he had complained of defamatory reviews, rendering the processing of his personal data unlawful. The Controller argued that complaints alleging the absence of a genuine customer or patient relationship fell within its internal category of complaints concerning defamation under German law and that publishing the number of removed reviews promoted transparency regarding its review moderation process. Holding — The court held that where a data subject seeks not only the erasure of personal data but also an injunction preventing its future publication, Article 17(1) GDPR provides a basis for both forms of relief. It further held that the journalistic exemption under Article 85(2) GDPR did not apply because the Controller's review platform, including the automated notices relating to removed reviews, did not process data for journalistic purposes. The court also held that the displayed number of removed reviews constituted personal data within the meaning of Article 4(1) GDPR because it related to an identified natural person. By storing and disclosing that information, the Controller processed personal data within the meaning of Article 4(2) GDPR. In assessing the accuracy of the notice under Article 5(1)(d) GDPR, the court considered how an average user would understand the information. It held that a prominently linked information page entitled "Defamation under German law" explained that the platform categorised not only false or reputation-damaging reviews, but also complaints alleging that the reviewer was not a genuine customer, as complaints concerning defamation. As the data subject did not dispute that he had successfully requested the removal of between six and ten reviews on the basis that the reviewers had not been genuine patients, the court concluded that users could readily understand the platform's use of the term and that the notice was factually accurate. The court also rejected the data subject's reliance on the Festzins Plus judgment (BGH, judgment of 21 September 2017 – I ZR 53/16), distinguishing that case because the corrective information there appeared only at the end of a lengthy and unclear text, whereas the notice in the present case contained a clearly highlighted hyperlink directing users to explanatory information specifically addressing the platform's categorisation of review removals. The court held that the Controller had legitimate interests in promoting transparency regarding its handling of review-removal requests and that publication of the notice was necessary for that purpose. These interests outweighed the data subject's rights because the notice related only to his professional activity, was presented in a factual manner, contained no criticism of his behavior and was not prominently displayed, appearing only after users selected the "Reviews" tab. Accordingly, the court concluded that the processing was lawful under Article 6(1)(f) GDPR and that the data subject was not entitled to erasure or an injunction preventing the future publication of the notice under Article 17(1) GDPR.

### Judgment of the Court (First Chamber) of 27 February 2025.#CK v Magistrat der Stadt Wien.#Request for a preliminary ruling from the Verwaltungsgericht Wien.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 15(1)(h) – Automated decision-making, including profiling – Scoring – Assessment of the creditworthiness of a natural person – Access to meaningful information about the logic involved in profiling – Verification of the accuracy of the infor

*Source: Court of Justice of the European Union, C-203/22, 2025-02-27 — https://overview.legal/posts/132146 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0203*

In Case C-203/22, the Court of Justice of the European Union interpreted Article 15(1)(h) of the GDPR in response to a preliminary ruling from the Verwaltungsgericht Wien concerning an individual's request for meaningful information about the logic of creditworthiness scoring conducted by Dun & Bradstreet Austria GmbH. The Court held that data subjects must receive sufficiently detailed explanations of the logic involved in automated profiling to understand how the decision was reached, while controllers may withhold information protected by trade secrets under Directive (EU) 2016/943 only insofar as such withholding does not render the information provided meaningless. The Court further clarified that data subjects may not use access rights to obtain personal data of third parties or to verify the absolute accuracy of the underlying information processed.

### Order of the General Court (Fourth Chamber, Extended Composition) of 7 December 2022.#WhatsApp Ireland Ltd v European Data Protection Board.#Action for annulment – Protection of personal data – Draft decision of the lead supervisory authority – Resolution of disputes between supervisory authorities by the European Data Protection Board – Binding decision – Article 60(4) and Article 65(1)(a) of Regulation (EU) 2016/679 – Act not open to challenge – Preparatory act – Lack of individual concern.#Ca

*Source: General Court, T-709/21, 2022-12-07 — https://overview.legal/posts/132302 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021TO0709*

WhatsApp Ireland Ltd sought annulment of EDPB Binding Decision 1/2021, which resolved disputes among supervisory authorities regarding the Irish DPC's draft decision on WhatsApp's compliance with GDPR transparency obligations. The General Court dismissed the action, finding that the EDPB's binding decision under Article 65(1)(a) GDPR was not a challengeable act against which WhatsApp could bring annulment proceedings, as WhatsApp lacked individual concern and the decision was a preparatory act in the GDPR cooperation mechanism. The underlying Irish DPC final decision, adopted pursuant to the EDPB's binding decision, had found WhatsApp in breach of multiple GDPR transparency provisions and imposed corrective measures including a reprimand and compliance orders.

### LG Rostock - 3 O 762/19

*Source: LG Rostock, 2020-09-15 — https://overview.legal/posts/122848 — original: https://gdprhub.eu/index.php?title=LG_Rostock_-_3_O_762/19*

Facts — The German consumer organisation Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband e.V. (vzbv, the claimant) filed a lawsuit against advocado GmbH (advocado, the defendant), a German-based company that runs an online platform where attorneys can offer their services. The defendant's website had used a cookie banner with pre-ticked boxes for the use of marketing and analytics cookies. This included the use of tools such as Google Analytics that entail a data transfer to third countries. The claimant argued that the data processing in connection with the placed cookies was unlawful under Article 6(1) GDPR: A user's consent under Article 6(1)(a) GDPR could not be considered valid under Articles 4(11) and 7 GDPR, especially since the boxes were pre-ticked. Moreover, the claimant claimed that the defendant had violated Articles 5(1)(a), 13/14, 26 and 44 et seqq. GDPR as it had failed to properly inform users of the scope of intended processing activities, joint controllers and international data transfers in connection with the use of cookies. The defendant stated that it had based the use of cookies on legitimate interests under Article 6(1)(f) GDPR until the CJEU issued its decision C-673/17 on 01.10.2019 ("Planet 49"). Afterwards, the defandent argued that they changed the legal basis for processing to consent under Article 6(1)(a) GDPR, which it considered valid under Articles 4(11) and 7 GDPR. The defendant also stated that it was the sole controller for the processing activities - there were no joint controllers involved, only processors. (Furthermore, the claimant had also argued that some provisions in the defendant's general terms and conditions were unlawful from a civil law / consumer protection law perspective. This will not be discussed further in this summary.) Dispute — Was it necessary to ask for the users' consent under Article 6(1)(a) GDPR or could the processing activities in connection with the use of marketing and analytics cookies be based on legitimate interest under Artilce 6(1)(f)? Was the consent given by users' when interacting with the defendant's cookie banner valid under Articles 6(1)(a), 4(11) and 7 GDPR? Did the defendant violate GDPR provisions on transparency? Was the defendant the sole controller regarding the processing activities in connection with the use of marketing and analytics cookies or were there any joint controllers? Holding — Legal basis and validity of consent — The court held that the marketing and analytics cookies used by the defendant c an only be placed with the users' consent under Article 6(1)(a) GDPR : § 15(3) Telemediengesetz that deals with such cookies must be interpreted in light of Article 5(3) e-Privacy Directive, which requires consent for cookies not strictly necessary for technical reasons. Taking into consideration the design of the cookie banner and the lack of information provided to a website user, the court held that consent given could not be considered valid under Articles 6(1)(a), 4(11) and 7 GDPR. The banner featured pre-ticked boxes and a big "OK" button. The option "use only necessary cookies" was designed to not look like an interactive button but rather a link. Consent could therefore not be considered "freely given" and was invalid. Transparency — The court further held that the defendant violated Article 13 GDPR by mentioning an incorrect transfer mechanism under Articles 44 et seqq. GDPR for data transfers in connection with the use of cookies. Sole or joint controllership when using Google Analytics? — Lastly, the court held that the use of Google Analytics results in joint controllership of the website provider using this tool and Google . Google does not qualify as the website provider's processor under Article 4(7). This is because Google does not process the data solely for the purpose of use by the website provider. Rather, Google, like other third-party providers, expressly reserves the right to process the data for its own purposes as well. The fact that the defendant and Google entered into a data processing agreement under Article 28 GDPR does not change this assessment. The court's legal view is in line with the official opinion of the "Datenschutzkonferenz", a gathering of all German DPAs.

### BUNDESVERBAND DER VERBRAUCHERZENTRALEN UND VERBRAUCHERVERBANDE —BERBRAUCHERZENTRALE BUNDESVERBAND V. PLANET49 GmbH (“PLANET49”)

*Source: CJEU, 2019-10-01 — https://overview.legal/posts/5946 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62017CJ0673*

The information that service provider must give to a website user includes “the duration of the operation of cookies and whether or not third parties may have access to those cookies.” (¶80)

### CJEU - C‑209/23 - RRC Sports

*Source: GDPRhub, 2026-07-16 — https://overview.legal/posts/144028 — original: https://gdprhub.eu/index.php?title=CJEU_-_C‑209/23_-_RRC_Sports*

Facts — Fédération internationale de football association (FIFA) is a Switzerland-based non-profit that acts as the global governing body for football. A large number of football clubs and national football associations are member of FIFA and bound by its regulations. In January FIFA published the FIFA Football Agent Regulations (FFAR). FFAR regulated the conduct of player’s agents. In particular, FFAR provided maximum limits to agents’ remuneration and prohibited specific types of contractual arrangements between clubs, agents, and agencies. In order to ensure compliance with these rules, Article 12 FFAR required agents to disclose certain information to FIFA. In particular, agents had to disclose: Information about any agreement with a client, other than a representation agreement; Information on any arrangement between agents to cooperate in the provision of their services, or to share the revenue or profits of their services; Information about their relationship with agencies, including the names of all of the agency’s employees. Additionally, FIFA would make the information available to a number of stakeholders including agents, players, and football clubs. Three applicants (an agent, a company acting as a players’ agent, and the Vice-President of a players’ agents’ associations) challenged FFAR in the Regional Court of Mainz (Germany). The Court referred four questions to the CJEU for a preliminary ruling. In essence, the Court asked the CJEU whether the FFAR was compatible with Articles 101 TFEU (prohibition on cartels), 102 TFEU (prohibition on abuse of a dominant position), 56 TFEU (freedom to provide services), and 6 GDPR (legal bases for processing personal data). With regards to Article 6 GDPR specifically, the referring court essentially asked whether there was a lawful basis under the GDPR for a collection of personal data, such as required under the FFAR’s mandatory disclosure rules. Advocate General Opinion — The referring question did not specify what legal basis had to be examined in order to assess the compatibility of FFAR disclosures with the GDPR. However, the AG opined that interest under Article 6(1)(f) was the relevant legal basis, based on the nature of the FFAR rules and on other information on the order for reference. Therefore, the AG focused on the legal basis of legitimate interest exclusively. The AG recalled that the mandatory disclosure under FFAR were compatible with the GDPR if they met three cumulative requirements: They genuinely pursued an interest worthy of protection; They were limited to what was strictly necessary to that end; They did not place an intolerable burden on the data subjects as regards their right to privacy and their financial interests. The AG opined that in the case at hand, the processing of personal data pursued an interest worthy of protection (that is, FIFA’s interest in ensuring that the conduct of agents was consistent with the core objective of the football transfer systems, and other objectives related to the good functioning of the player market). However, the AG was more cautious about the other two requirements. With regards to the requirement of necessity, the AG noted that FFAR required the collection of a substantial amount of personal data, including delicate data about agents’ remuneration and contractual agreements. Additionally, FIFA would not only receive the data but also make it available to stakeholders such as clubs, players, and player’s agents. The AG opined that such a broad collection and disclosure of personal data could, to some extent, exceed what was strictly necessary to pursue FIFA’s legitimate interest. In that regard, the AG stressed that FIFA should explain to the referring court why the collection and disclosure of the data were necessary, in relation to each type of information. With regards to the balancing of interests, the AG opined that agents operate within a regulatory framework and, therefore, have a reasonable expectation that FIFA would process their data as a regulatory body. In the AG’s view, this expectation could weight favorably on the balancing of legitimate interest. At the same time, the AG opined that the availability of agents’ personal data to both competitors and potential clients, could financially harm agents and erode trust in agent-client relationships. Holding — The CJEU held that processing based on Article 6(1)(f) GDPR is lawful only where three cumulative conditions are met. First, the controller or a third party must pursue a legitimate interest. Second, the processing must be necessary for that interest. Third, the interests or fundamental rights and freedoms of the data subject must not override the legitimate interest pursued. Regarding the information agents were required to submit through the controller’s digital platform under Article 16 FFAR, the Court considered that ensuring compliance with the regulatory framework governing football agents could constitute a legitimate interest. This was conditional on the underlying obligations being compatible with EU and national law. The Court found that the information required under Article 16 FFAR appeared capable of identifying attempts to circumvent rules on representation, remuneration and conflicts of interest. The processing could therefore be adequate, relevant and limited to what was necessary. However, the referring court had to determine whether equally effective but less intrusive measures were available and assess any additional information requested through the platform whose precise scope was not defined in the regulations. The processing under Article 16 FFAR could therefore be compatible with Article 6(1)(f) GDPR, subject to verification by the referring court. Regarding Article 19 FFAR, the Court distinguished between the different categories of information disclosed by the controller. The publication of agents’ names and contact details, the identity of their clients, the duration and exclusivity of representation agreements and the services provided could pursue legitimate interests such as establishing professional and ethical standards, protecting clients from unethical conduct and improving transparency. Since the information concerned professional activities within a regulatory framework known to the persons involved, this processing could satisfy the balancing test under Article 6(1)(f) GDPR. By contrast, publishing detailed information about every transaction involving an agent, including the service fees paid, was not limited sufficiently. The Court held that agents and clients did not need access to detailed information about all transactions involving their competitors to comply with the regulations. The indiscriminate disclosure of this information therefore infringed the data minimisation principle under Article 5(1)(c) GDPR and was not necessary under Article 6(1)(f) GDPR. The Court also examined the publication of sanctions imposed on agents and clients. It accepted that publication could, in certain circumstances, deter misconduct, restore confidence in the market and allow persons harmed by an infringement to become aware of it. Nevertheless, Article 19 FFAR required the publication of every sanction without considering its seriousness, the harm caused, its relevance to market confidence or the time elapsed since the infringement. The regulation also did not provide for the information to cease being available after a defined period. The blanket publication obligation therefore did not appropriately balance the controller’s interests against the data subjects’ rights under Articles 7 and 8 CFR. Moreover, where a sanction contained personal data relating to criminal convictions or offences, Article 10 GDPR applied. In the absence of authorisation under EU or Member State law and supervision by a public authority, the controller could not process such data. The Court consequently held that Article 6(1)(f) GDPR precluded regulations adopted by an international sports federation insofar as they required the disclosure and publication of: every sanction imposed on agents or their clients; and detailed information concerning all transactions involving agents. The Court did not impose a fine or order any specific corrective measure. It provided an interpretation of EU law for the referring court, which remained responsible for resolving the underlying dispute and verifying the relevant factual and legal conditions.

### VG München - M 26a K 25.5210

*Source: Administrative Court Munich, 2026-05-18 — https://overview.legal/posts/108991 — original: https://gdprhub.eu/index.php?title=VG_München_-_M_26a_K_25.5210*

Facts — The data subject had been liable to pay broadcasting contributions to the Controller, a German regional public broadcasting authority, since 2007. Following objections to several contribution assessment notices, the data subject submitted a request under Article 15 GDPR seeking a copy of all personal data processed about him by the Controller. The Controller responded by providing the categories of personal data and related information specified under § 11(8) of the German Broadcasting Contribution Treaty (RBStV), which governs data subject access requests relating to broadcasting contribution records, together with general privacy information. The data subject argued that the response was incomplete because it did not include copies of all documents containing his personal data, including correspondence with him and third parties. The Controller maintained that it had fully complied with its obligations under the RBStV. After the Controller declined to provide additional information, the data subject brought proceedings seeking disclosure of all personal data concerning him processed by the Controller. Holding — The Court held that § 11(8) of the German Broadcasting Contribution Treaty (RBStV) constituted a lawful restriction of the broader right of access under Article 15 GDPR pursuant to Article 23(1)(e) GDPR. It found that the national provision was a valid legislative measure, respected the essence of the fundamental right to data protection, and pursued an important public interest by ensuring the effective financing and administration of the public broadcasting system. The Court further held that the restriction was necessary and proportionate, noting that requiring the Controller to comply with the full scope of Article 15 GDPR across more than 44 million broadcasting contribution accounts would impose a disproportionate administrative and financial burden capable of undermining that public interest. The Court also held that § 11(8) RBStV satisfied the safeguards required under Article 23(2) GDPR by specifying the purposes of processing, categories of personal data, scope of the restriction, safeguards against misuse and unlawful access, the identity of the Controller, applicable storage periods and other statutory protections. Accordingly, while the Controller was required to disclose the categories of information specified under § 11(8) RBStV, it was not required to provide a copy of all personal data processed under Article 15(3) GDPR. As the Controller had already provided all information required under the national provision, the court dismissed the action.

## Guidance

### Art. 29 WP Guidelines on GDPR transparency requirements (WP260 rev.01)

*Source: EDPB, edpb-guidelines-on-transparency, 2025-11-21 — https://overview.legal/posts/38076 — original: https://www.edpb.europa.eu/system/files/2023-09/wp260rev01_en.pdf*

The Article 29 Data Protection Working Party issued these guidelines (WP260 rev.01), adopted on 29 November 2017 and last revised on 11 April 2018, to provide interpretive and practical guidance on the transparency requirements under the GDPR (Articles 12–14). The document addresses the form, timing, content, and modalities of information provided to data subjects, including issues such as plain language, layered privacy notices, information for children, and exceptions to the obligation to provide information. No fines or enforcement actions are imposed, as this is a guidance document rather than an enforcement decision.

### Article 29 Working Party - Guidelines on transparency under Regulation 2016/679

*Source: EDPB, article-29-working-party-guidelines-on-transparency-under-regulation-2016679-en, 2018-04-11 — https://overview.legal/posts/126340 — original: https://www.edpb.europa.eu/documents/guideline/article-29-working-party-guidelines-on-transparency-under-regulation-2016679_en*

ARTICLE 29 DATA PROTECTION WORKING PARTY This Working Party was set up under Article 29 of Directive 95/46/EC. It is an independent European advisory body on data protection and privacy. Its tasks are descr bed in Article 30 of Directive 95/46/EC and Article 15 of Directive 2002/58/EC. The secretariat is provided by Directorate C (Fundamental Rights and Union Citizenship) of the Europe an Commission, Directorate General Justice, B - 1049 Brussels, Belgium, Office No MO - 59 02/013. Website:…

### Transparency

*Source: EDPB, transparency-en, 2018-05-25 — https://overview.legal/posts/126323 — original: https://www.edpb.europa.eu/documents/guideline/transparency_en*

### Guidelines 8/2020 on the targeting of social media users

*Source: EDPB, edpb-guidelines-on-the-targeting-of-social-media-users, 2021-04-13 — https://overview.legal/posts/38073 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-82020-on-the-targeting-of-social-media-users_en*

The EDPB adopted Guidelines 8/2020 on the targeting of social media users to clarify the roles, responsibilities, and legal obligations of the various actors involved in social media targeting, including social media providers, targeters, and users. The guidelines analyze different targeting mechanisms—based on provided, observed, and inferred data—and address controller determinations, legal bases, transparency requirements, DPIAs, and the processing of special categories of data. No fines are imposed, as this is interpretive guidance intended to assist stakeholders in achieving GDPR compliance.

### Report on stakeholder event on processing of personal data to target or deliver political advertisements

*Source: EDPB, report-on-stakeholder-event-on-processing-of-personal-data-en, 2026-03-27 — https://overview.legal/posts/125684 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/report-on-stakeholder-event-on-processing-of-personal-data_en*

Report on stakeholder event on processing of personal data to target or deliver political advertisements 27 March 2026 1. Background The EDPB organised an online stakeholder event on 27 March 2026 to collect stakeholders’ input on processing of personal data to target or deliver political advertisements. The objective was to engage with stakeholders at an early stage of drafting the EDPB Guidelines on the processing of personal data to target or deliver political advertisements (Chapter III of…

### Opinion 17/2021 on the draft decision of the French Supervisory Authority regarding the European code of conduct submitted by the Cloud Infrastructure Service Providers (CISPE)

*Source: EDPB, opinion-172021-on-the-draft-decision-of-the-french-en, 2021-05-19 — https://overview.legal/posts/126026 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-172021-on-the-draft-decision-of-the-french_en*

Adopted Opinion 17/2021 on the draft decision of the French Supervisory Authority regarding the European code of conduct submitted by the Cloud Infrastructure Service Providers (CISPE) Adopted on 19 May 2021 2 Adopted 3 Adopted The European Data Protection Board Having regard to Article 63, Article 64(1)( b ) and Article 4 0 of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal…

### Opinion 16/2021 on the draft decision of the Belgian Supervisory Authority regarding the “EU Data Protection Code of Conduct for Cloud Service Providers” submitted by Scope Europe

*Source: EDPB, opinion-162021-on-the-draft-decision-of-the-belgian-en, 2021-05-19 — https://overview.legal/posts/126028 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-162021-on-the-draft-decision-of-the-belgian_en*

Adopted Opinion 16/2021 on the draft decision of th e Belgian Supervisory Authority regarding the “EU Data Protection Code of Conduct for Cloud Service Providers” submitted by Scope Europe Adopted on 19 May 2021 2 Adopted 3 Adopted The European Data Protection Board Having regard to Article 63, Article 64(1) ( b ) and Article 4 0 of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of…

### Guidelines 5/2019 on the criteria of the Right to be Forgotten in the search engines cases under the GDPR (part 1)

*Source: EDPB, edpb-guidelines-on-the-criteria-of-the-right-to-be-forgotten-in-the-search-engines-cases-under-th, 2020-07-07 — https://overview.legal/posts/38070 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-52019-on-the-criteria-of-the-right-to-be-forgotten-in-the-search_en*

The European Data Protection Board (EDPB) issued these guidelines to clarify the criteria and grounds for exercising the right to erasure (right to be forgotten) specifically in the context of search engine cases under the GDPR. The document details the six grounds under Article 17(1) that allow data subjects to request delisting, alongside the relevant exceptions, such as the right to freedom of expression and information. As a guidance instrument, it does not impose administrative fines but instead aims to harmonize how search engine providers handle and balance delisting requests across the EU.

## Enforcement decisions

### NAIH fines online store HUF 15M for transparency and Article 12(1) GDPR violations

*Source: NAIH (Hungary), 2026-05-12 — https://overview.legal/posts/184727 — original: https://gdprhub.eu/index.php?title=NAIH_(Hungary)_-_NAIH-450-7-2026*

Facts — The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The period under review extended from January 2020 to November 2025. During this time, the company had multiple privacy notices in force, as well as other documents that contained relevant information on the processing of personal data. Holding — The DPA found the controller guilty of multiple GDPR violations and issued it a fine of HUF 15,000,000 (€41,500). In addition, it ordered the controller to bring its processing operations in compliance with the GDPR by amending the information system used on its website, in particular the data processing provisions of the general terms and conditions and the data processing notices related to prize contests. First, the DPA held that the controller had violated the principle of transparency laid down in Article 5(1)(a) GDPR: several separate documents contained partially conflicting, irrelevant, and incomplete information regarding the processing of personal data. The information was not organised within a uniform, transparent system. Second, the DPA determined that the controller had failed to provide concise, transparent, and intelligible information regarding the purposes and the legal basis for each processing activity and therefore infringed Article 12(1) GDPR. Finally, the DPA found infringements of Articles 13(1) and 13(2) GDPR – the controller had not provided the data subjects all information necessary when personal data is collected from data subjects. In particular, the controller had failed to adequately distinguish the purposes and the legal bases for each processing operation, recipients of personal data, and retention periods. The controller’s website also contained contradictory information on whether or not personal data was transferred to the United States.

### NAIH fines online store HUF 10M for missing and inadequate privacy notice

*Source: NAIH (Hungary), 2026-04-30 — https://overview.legal/posts/262255 — original: https://gdprhub.eu/index.php?title=NAIH_(Hungary)_-_NAIH-4462-5-2026*

Facts — The DPA initiated an investigation into the processing of the personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The controller’s main business activity was the wholesale distribution of beverages. The personal data of the data subjects was processed on the website of the online store for registration, placing orders, billing, communication, delivery, creation of user accounts, and newsletter subscription. During the period under review, i.e. between January 2020 and October 2025, no standalone privacy notice was available on the website. The previously archived privacy notice and the data processing section included in the general terms and conditions described the processing operations in a rather brief and general manner. The controller argued that the inaccessibility of the privacy notice followed from a technical error that was corrected upon discovery. Holding — The DPA found that the controller had violated Articles 5(1)(a), 5(2), 12(1), 13(1)(a), (c), and (e) as well as 13(2)(a)–(e) GDPR and issued it a fine of HUF 10,000,000 (€27,300). When issuing the fine, the DPA took into account that the identified infringements followed from systemic inadequacies of the privacy notice and were of continuous nature. In addition, the DPA ordered the controller to develop and publish a uniformly structured privacy notice that is aligned with its actual processing operations. First, the DPA identified a violation of the principle of transparency laid down in Article 5(1)(a) GDPR: the information provided to data subjects about the processing of their personal data was either incomplete or completely absent, and changes could not be tracked. Second, the DPA held that the controller had violated the principle of accountability set forth in Article 5(2) GDPR, as it had failed to submit appropriate documentation covering the period under review. In addition, the controller’s data processing practices could not be continuously monitored or subsequently verified based on the documentation it had provided. Finally, the DPA confirmed that the controller had not complied with the requirements laid down in Articles 12(1), 13(1)(a), (c) and (e), and 13(2)(a)–(e) GDPR. Due to the lack of a privacy notice, the controller could not demonstrate that it had provided data subjects with the information required under Article 13 GDPR apart from brief, general statements in the archived privacy notice and the general terms and conditions. The controller had thus failed to provide the data subjects clear and differentiated information regarding the purpose and legal basis for each processing operation. Furthermore, the controller had not adequately identified the recipients or the storage period of personal data or information on the data subjects' rights. Due to the form and scope of the information provided, the controller had also infringed Article 12(1) GDPR.

### AKI (Estonia) - No. 2.1-1/24/397-890-38

*Source: AKI (Estonia), 2026-04-16 — https://overview.legal/posts/53882 — original: https://gdprhub.eu/index.php?title=AKI_(Estonia)_-_No._2.1-1/24/397-890-38*

Facts — OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic. On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had failed to provide all personal data requested. The controller only partially complied after several requests from the DPA. Although the DPA closed the part of the case concerning the access request, it continued investigating the controller’s processing of patients’ personal data when providing Invisalign treatment. The service required the controller to collect and transfer patients’ health data to Align Technology, Inc. However, the contractual documents did not clearly establish whether Align Technology acted as a processor, an independent controller or a joint controller. The controller stated that Align Technology largely determined the conditions of the service, including the consent form and the processing arrangements, and that individual clinics could not unilaterally amend these conditions. The DPA also found that the information provided to patients was incomplete and fragmented. The consent form and privacy information did not clearly explain the legal basis and purposes of processing, the parties involved, data recipients, retention periods, transfers outside the European Union or the safeguards applied to such transfers. Parts of the information were only available in English on external websites. Holding — The DPA held that the controller had failed to demonstrate that the processing carried out in connection with the Invisalign service was lawful and transparent under Articles 5(1)(a) and 5(2) GDPR. First, the DPA found that the parties’ roles had not been properly determined. Under Article 4(7) GDPR, the assessment had to be based on which party actually determined the purposes and means of processing, rather than solely on the contractual description of the relationship. The controller decided whether Invisalign treatment was suitable for a patient and collected the relevant health data. It therefore acted as a controller in relation to the treatment. However, Align Technology exercised significant control over the subsequent processing, including the data collected, the recipients, retention arrangements, the use of other service providers and transfers outside the European Union. The DPA therefore considered that Align Technology could not simply be regarded as a processor acting only on documented instructions under Article 28(3)(a) GDPR. On the available evidence, it was at least a joint controller under Article 26 GDPR. The DPA ordered the controller to review the contractual relationship. If Align Technology acted as a processor, the agreement had to comply with Article 28 GDPR, including the requirements concerning subprocessors under Article 28(2). If the parties were joint controllers, they had to allocate their respective responsibilities under Article 26 GDPR. Second, the DPA found that the consent obtained from patients was invalid. The consent form did not provide sufficient information for patients to understand the processing and therefore did not meet Articles 4(11), 6(1)(a), 7 and 9(2)(a) GDPR. The DPA also noted that healthcare processing may, depending on the operation concerned, rely on Article 6(1)(b) GDPR together with Article 9(2)(h) GDPR. However, the controller had not clearly identified the applicable legal bases for the different processing activities. The privacy information also failed to comply with Articles 12, 13 and 14 GDPR. Patients were required to consult several documents and external websites, some of which contained incomplete or inconsistent information. The controller had therefore not ensured that the information was easily accessible, understandable and available in Estonian. The DPA further referred to Article 25 GDPR when emphasising that the controller had to ensure that the processing arrangements and safeguards complied with the GDPR. Under Article 58(2)(d) GDPR and § 56(1) of the Estonian Personal Data Protection Act, the DPA ordered the controller to clarify the parties’ roles, conclude an Article 26 arrangement or Article 28 agreement, amend the consent form and privacy policy, and publish the required information in Estonian. No administrative fine was imposed. However, failure to comply could result in a penalty payment of €1,000 for each unfulfilled point or subpoint of the order, imposed repeatedly until compliance.

### EDPS - 2019-0878

*Source: EDPS, 2021-05-03 — https://overview.legal/posts/122870 — original: https://gdprhub.eu/index.php?title=EDPS_-_2019-0878*

Facts — A data subject complained around cookies and similar technologies used in connection to audiovisual material on the website of the Court of Justice of the European Union (CJEU), as well as websites displaying the Court's branding that the Court linked to (two firms, Companywebcast and Connectedviews, to host a conference recording), claiming that they did not correctly inform the user or obtain required consent before data processing or storage of information on a terminal device. Dispute — The complaint was decided under the data protection regime applying to EU institutions, rather than the GDPR (Regulation (EU) 2018/1725). The dispute concerned: - did the laying of cookies by the CJEU violate Article 37 of the Regulation, implementing the requirements of the e-Privacy Directive? - did the laying of cookies and the lack of transparent information on a third party website, with CJEU branding, linked to by the CJEU to provide it with services, breach the transparency (art 14) and consent (art 7) requirements of Regulation (EU) 2018/1725? - were the conditions for consent met by the CJEU? Holding — The EDPS held that there had been violations by the CJEU, on its own webpages of several provisions of Regulation (EU) 2018/1725. - Article 37 (accessing and storage of information on a terminal device), on the basis that the CJEU did not inform the user about the potential for YouTube cookies to be set if they accepted, nor did they provide a mechanism to refuse all cookies on the website. - Article 7 (conditions for consent), "as the CJEU did not provide its website users with a way to withdraw their consent regarding the use of cookies as easily as giving it - such as a ‘reject’ button displayed in the same place and in the same manner as the ‘accept’ button. Instead, in order to reject cookies, users had to click on the button ‘more information’ and go almost to the bottom of the page to withdraw their consent." It held that there were partial violations of - Article 14 (transparency), in relation to the CJEU's website's own YouTube cookies. In relation to the third party websites, Fashion ID applied, as the CJEU had no obligation to inform users of cookies laid by a website linked to by that website, regardless of whether it was a service the CJEU were using to deliver material or the branding on the site. The CJEU rectified all breaches following the complaint, in co-operation with the EDPS. As a result, the EDPS did not use any of its corrective powers. The EDPS also used the complaint to deploy its Website Evidence Collector (WEC). In relation to linked pages of third party services that the CJEU used to host branded conference videos, which laid Google and DoubleClick cookies without information or a possibility to reject, these were in breach of the law but did not fall within EDPS jurisdiction, and the CJEU had no obligation to provide information on cookies on pages it linked to (Fashion ID applied). This case clarified and confirmed that a withdraw button is needed to be placed as clearly as an accept button in order for consent to be valid to cookies and similar technologies. The EDPS took no formal action as the CJEU engaged rapidly with the organisation and rectified all breaches following the complaint.

### NAIH fines online store HUF 2M for unclear and incomplete privacy notice

*Source: NAIH (Hungary), 2026-07-22 — https://overview.legal/posts/156361 — original: https://gdprhub.eu/index.php?title=NAIH_(Hungary)_-_NAIH-11443-3/2026*

Facts — The DPA initiated an investigation into the GDPR compliance of an online store (the controller) processing the data of its customers (the data subjects) in April 2025. The processing activities in question included, inter alia, cookies, registration, billing, shipping, consumer complaint, and processing of orders. The privacy notice of the company operating the online store had been in force unchanged from May 2018 to May 2025, and the period under investigation extended from 1 January 2020 to 27 June 2025. Holding — The DPA held that the controller had violated Articles 12(1), 13(1)(c), (d) and (f), and 13(2)(a) GDPR and issued the controller a fine of HUF 2,000,000 (€5,500). In addition, the DPA ordered the controller to bring its data processing operations into compliance with the GDPR and to amend the content of its privacy notice. First, the DPA found an infringement of Article 12(1) GDPR: the structure of the privacy notice was confusing and difficult to follow. The privacy notice also contained incomplete, incorrect, and unnecessary information as well as repetitive details. Based on this, the DPA concluded that the controller had failed to provide data subjects with information regarding the processing of personal data that was sufficiently concise, transparent, intelligible and easily accessible. Second, the DPA held that the controller had also violated Articles 13(1)(c), (d) and (f) GDPR by failing to specify a legal basis for certain processing operations such as the use of cookies, not specifying its legitimate interests when relying on Article 6(1)(f) GDPR as a legal basis, and not providing detailed information regarding the safeguards ensuring the lawfulness of data transfers to the United States. Finally, the DPA found a violation of Article 13(2)(a) GDPR as the controller had also failed to provide the data subjects information on the period for which the personal data processed would be stored.

### Italian DPA: Vasto municipality breached transparency duties over traffic cameras

*Source: Garante per la protezione dei dati personali (Italy), 2026-06-18 — https://overview.legal/posts/144036 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_457/2026*

Facts — The Municipality of Vasto (the controller) implemented a dedicated photo and video system for the purpose of detecting violations of the national provisions on traffic safety. A data subject filed a complaint against the controller after being fined for running a red light. The data subject argued that there were no signs or warnings near the cameras installed to detect violations, and that the controller did not obscure the windows to make data subjects unrecognisable. The controller argued that it provided warning signs of the presence of cameras. In addition, the cameras only capture data subjects’ license plates to comply with the principle of data minimisation (Article 5(1)(c) GDPR), and that the case of the data subject was a technical error. Holding — The DPA first noted that, in principle, a public entity can process this data if it is necessary to fulfil a legal obligation or for the public interest (Article 6(1)(c) and (e) GDPR). However, the controller still has the obligation to provide information to data subjects regarding the processing, in accordance with the principle of transparency (Article 5(1)(a) GDPR). The DPA found that, at the time of the complaint, the controller had not included any information near the cameras. In addition, the first level privacy policy did not comply with the requirements of Article 13 GDPR and were not provided in concise and transparent manner. Therefore, the DPA found a violation of Articles 5(1)(a), 12(1) and 13 GDPR. The DPA also found a violation of Article 5(1)(c) GDPR, as the controller failed to comply with the principle of data minimisation. The DPA stated that the controller had failed to ensure that the cameras only captured the vehicles’ license plates, and had therefore processed more data than necessary. Finally, the DPA found a violation of Article 35 GDPR, as the controller had prepared a data protection impact assessment (DPIA) only after the processing activities began. The DPA noted that the DPIA was also not specific enough. The DPA fined the controller €5,000. In addition, the DPA ordered the controller to adopt appropriate measures to provide data subjects with adequate information and update its DPIA.

### EDPS - 2020-1013

*Source: EDPS, 2022-01-05 — https://overview.legal/posts/122849 — original: https://gdprhub.eu/index.php?title=EDPS_-_2020-1013*

Facts — In January 2021, noyb filed a complaint against the European Parliament on behalf of six Members of the European Parliament over an internal coronavirus testing website. The issues raised were: confusing and unclear cookie banners, vague and unclear data protection notices, and the illegal transfer of data to the US. Holding — On data controllership — According to the EDPS, the processor may enjoy a considerable degree of autonomy in providing its services and may identify the ‘non-essential’ elements of the processing operation. Furthermore, the processor may advise or propose certain measures in this respect, but it is up to the controller to decide whether to accept such advice or proposals. The analysis of the EDPS shows that the European Parliament (EP) delegated some aspects on the setting up and functioning of the website to Ecolog. The EDPS considers the EP acts as the sole data controller for the processing in question (i.e. the operation of the Parliament’s dedicated website) whereas Ecolog acts as a processor. After having assessed the instructions given by the EP to the processor, the EDPS concluded that the EP did not show the necessary diligence required from a data controller and, ultimately, failed to comply with the Regulation on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data 2018/1725 (hereafter Regulation 2018/1725), in particular with Articles 26(1) and 29(1). Moreover, the EDPS considered that the EP failed to provide the necessary detailed instructions to Ecolog for the setting up of the website, including the drafting of the data protection notice. The absence of documented instructions is therefore in violation of Article 29(3) Regulation 2018/1725. Transparency and information requirements — The EDPS confirmed that the data protection notice published at the time of the complaint did not reflect the processing done by the EP, since it merely consisted of a copy of the testing center of Zaventem's airport. Moreover, the reference made in the document to Article 6(1)(f) GDPR was wrong since it stems from the same error. The EDPS confirmed that the EP did not meet its transparency requirements. The EDPS also analysed the updated version of the data protection notice during the procedure and raised several remaining -and even new- inconsistencies and issues. Among other things, the following problems persisted after the data protection notice was updated: a mere reference to Article 15 and 16 Regulation 2018/1725 is misleading as it should apply in its entirety; the reference to the processing of health data is not correct since no such data are processed in the case at hand; the retention period mentioned is not precise enough; the sections of the data protection notices relating to the recipients of the personal data fail to make any reference to the processor; inconsistencies between the different linguistic versions of the data protection notices were still observed: The English and German versions refer to Ecolog and the Laboratory van Poucke as processors under Article 29 Regulation 2018/1725, whereas the French version refers to them as controllers (‘responsables du traitement’). Moreover, the DPO’s contact details on the website refer to Ecolog in all three linguistic versions of the website, when they should be referring to the Parliament Cookies and transfers of personal data to the US — The EDPS confirmed that tracking cookies, such as the Stripe and the Google analytics cookies, are considered personal data, even if the traditional identity parameters of the tracked users are unknown or have been deleted by the tracker after collection. In the same vein, the EDPS rejected the EP's argument and confirmed that upon installation on a device, a cookie cannot be considered ‘inactive’. Every time a user visited Ecolog’s website, personal data was transferred to Stripe through the Stripe cookie, which contained an identifier. The EDPS reached the conclusion that a transfer of data was taking place to the US, via the use of Google and Stripe cookies, since Google Analytics is hosted in the US and the data protection notice referred to a Standard Contractual Clause (SCC) for the transfer of data outside of the EU. However, the Parliament provided no documentation, evidence or other information regarding the contractual, technical or organisational measures in place to ensure an essentially equivalent level of protection to the personal data transferred to the US in the context of the use of cookies on the website. Cookie banner on the Parliament’s dedicated website — The EDPS reminded that: before setting cookies or any other technology falling within the scope of Article 5(3) ePrivacy Directive 2002/58/EC (hereafter ePrivacy Directive), the EU institution must provide the user with adequate information on what is accessed or stored on the user’s terminal equipment, on the purposes of this action and the means for expressing their consent; no action may be performed before the consent is collected. In addition, users must be enabled to withdraw their consent at any time; ‘cookie walls’ are not in line with Regulation 2018/1725, meaning that for consent to be freely given, access to the website’s service and functionalities should not depend on the users’ consent for cookies that are not strictly necessary in the sense described above; in case personal data collected through the cookies are shared with third parties such as analytics partners, the cookie banner should draw the user's attention to it. The EDPS reached the conclusion that the cookie banners in all three languages were not in line with the definition of consent under Article 3(15) Regulation 2018/1725, nor did they meet the requirements of Article 37 Regulation 2018/1725 and Article 5(3) ePrivacy Directive. The cookie banner further failed to provide transparent information regarding the processing of personal data in relation to the cookies on the website. Request for access to personal data — The Parliament was aware that the complainants’ personal data had been processed through the cookies, which were present on the website for the period between 30 September to 4 November 2020, since transfers of personal data had taken place. Consequently, and especially following the EDPS’ inquiry on the matter, the Parliament should have replied to the complainants’ access to personal data request. The Parliament should have provided the relevant information even if it was aware that the processing of the personal data in question was unlawful, as the main purpose of the right of access under Article 15 GDPR is precisely to enable data subjects to become aware of the processing and verify the lawfulness thereof, or exercise other data subject rights. Conclusion — The EDPS concludes that the Parliament has infringed the following articles of Regulation 2018/1725: Articles 26(1) and 29(1) due to its failure to fulfil its responsibilities as controller and use a processor providing sufficient guarantees to implement appropriate technical and organisational measures; Article 29(3) due to its failure to provide documentation relating to the detailed instructions given to the processor for the setting up and functioning of the website; Articles 4(1)(a) and 14, 4(2), and 15 due to its failure to respect the principle of transparency, accountability and the data subjects’ right to information because of the inaccurate data protection notice and cookie banner on the dedicated website; Article 46 and Article 48(2)(b) of the Regulation, due to its reliance on the Standard Contractual Clauses in the absence of a demonstration that data subjects’ personal data transferred to the US were provided an essential equivalent level of protection; Article 37 read in the light of Article 5(3) of the ePrivacy Directive, due to its failure to protect information (the cookies) transmitted to, stored in, related to, processed by and collected from the users’ terminal equipment; Articles 17 and 14(4) due to its failure to reply to the data subjects’ request for access to their personal data. On the basis of the above, the EDPS decides: to issue a reprimand to the Parliament in accordance with Article 58(2)(b) Regulation 2018/1725 for the above infringements; to order the Parliament, pursuant to Article 58(2)(b) Regulation 2018/1725:, to update its data protection notices in the dedicated website in order to provide all relevant information relating to the processing of personal data. The Parliament should address this order within one month from the date of the decision.

### Italian DPA fines butcher €1,500 for unlawful video surveillance lacking information signs

*Source: Garante per la protezione dei dati personali (Italy), 2026-01-16 — https://overview.legal/posts/52452 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_10214411*

Facts — The Local Territorial Agency for Residential Housing (Azienda territoriale per l’edilizia residenziale) submitted a complaint to the DPA regarding the installation of security cameras by the business “Macelleria La Costata s.r.l.s.”, a local butcher . The data controller installed the cameras (three, of which one was not functioning), positioned in two external areas of the business, without signs informing about the presence of the aforementioned cameras. The Local Territorial Agency for Residential Housing requested further investigations by the Local Police command, that was able to confirm violations of the Regulation. The Agency then submitted a complaint to the DPA. Despite being asked to submit written defenses in relation to the disciplinary proceedings against him, the data controller did not send any response to the Authority. Holding — The DPA found the data controller in breach of GDPR for the data processing being unlawful, and imposed a fine of €1,500. The DPA confirmed that the data processing through the video surveillance system did not comply with Article 5(1)(a) GDPR and violated the principle of transparency for not being equipped with suitable information signs. The controller also was found in breach of disclosure obligations, even in simplified form, specifically provided for by Article 13 of the Regulation. In fact, the data controller did not provide data subjects with all information relating to the essential characteristics of the processing performed. Furthermore, the processing was considered unlawful, as it violated Article 6 of GDPR, for lacking legal basis. The cameras were capable of recording areas other than those under the exclusive ownership (specifically, the public parking area in front of and to the side of the business entrance and part of the public road), as the initial local police report confirmed as well. In light of these considerations, the DPA fined data controller for €1,500, and ordered to provide information on processing and to stop the filming of public spaces.

## Recent developments

### Digital Omnibus - First Legal Analysis

*Source: noyb - European Center for Digital Rights, 2025-11-22 — https://overview.legal/posts/49181 — original: https://noyb.eu/en/digital-omnibus-first-legal-analysis*

GDPR Policy This week the "Digital Omnibus" came out. noyb is right now working on an in-dept written analysis that we hope to publish the next days. As a preview, we brought together team members that worked on the various aspects of the Omnibus proposal by the European Commission in a video, to go into more details on select topics (the new personal data definition, the new research exemption, limitations on transparency rules and the new rules on access to the terminal equipment). We hope thi

### noyb WIN: Austrian authority forbids unlawful credit scoring by KSV1870

*Source: noyb - European Center for Digital Rights, 2025-09-26 — https://overview.legal/posts/53136 — original: https://noyb.eu/en/noyb-win-austrian-authority-forbids-unlawful-credit-scoring-ksv1870*

Credit Scoring noyb has scored a win in its complaint proceedings against the Austrian credit information agency KSV1870 and the energy provider Unsere Wasserkraft. The Austrian Data Protection Authority has found KSV1870's fully automated credit rating – which prevented the complainant from concluding an energy supply contract – to be unlawful. The DSB has also prohibited KSV1870 from carrying out such credit checks in future without the complainant's consent. Last but not least, the authority

### noyb takes Swedish tax authority to court for selling people’s personal data

*Source: noyb - European Center for Digital Rights, 2025-04-03 — https://overview.legal/posts/53158 — original: https://noyb.eu/en/noyb-takes-swedish-tax-authority-court-selling-peoples-personal-data*

Data Subject Rights In most countries, the government knows when you were born, your social security number, where you live, how much you earn and how much your house is worth. Sweden is a bit different though. There, the tax authority doesn’t just use this information for administrative purposes – but sells it to data brokers who publish it online. This is a violation of EU law. Earlier this year, a Swedish data subject asked the country’s tax authority to stop selling his data. The country’s S

### Swedbank refuses transparency in automatic interest calculation

*Source: noyb - European Center for Digital Rights, 2025-02-27 — https://overview.legal/posts/53160 — original: https://noyb.eu/en/swedbank-refuses-transparency-automatic-interest-calculation*

Data Subject Rights Nowadays, more and more banks set their interest rates automatically, and without any human intervention. But even the smallest inaccuracies can cost consumers thousands of additional euros. While EU law allows the use of such an automatic system in certain circumstances, companies must follow strict rules to protect people’s fundamental right to privacy. Banks, for example, would need to provide their customers with “meaningful information about the logic involved” in calcul

### Transparantie-eisen AI gelden vanaf 2 augustus: AP adviseert praktijkcode te ondertekenen

*Source: Autoriteit Persoonsgegevens, 2026-07-09 — https://overview.legal/posts/83468 — original: https://autoriteitpersoonsgegevens.nl/actueel/transparantie-eisen-ai-gelden-vanaf-2-augustus-ap-adviseert-praktijkcode-te-ondertekenen*

Vanaf 2 augustus 2026 zijn aanbieders en gebruikers van AI-systemen verplicht duidelijk te maken wanneer mensen met artificiële intelligentie (AI) te maken hebben. De Europese Commissie heeft op 10 juni een praktijkcode gepubliceerd waarin een deel van deze transparantieverplichtingen verder is uitgewerkt. De Autoriteit Persoonsgegevens (AP) adviseert organisaties die onder deze verplichtingen vallen zich te verdiepen in de praktijkcode en (onderdelen ervan) te ondertekenen. Organisaties die voo

## Literature

### Transparency Discourse on Digital Platforms: A Comparative Textual Analysis of Platform Reports and Regulatory Texts in the EU and Türkiye

*Source: Lectio Socialis, 2026-07-16 — https://overview.legal/posts/132111 — original: https://doi.org/10.47478/lectio.1921434*

This study examines transparency reporting in digital platform governance through a comparative analysis of platform reports, the European Union’s Digital Services Act (DSA), and Türkiye’s Law No. 7253. Drawing on surveillance capitalism, disciplinary power, and critical platform studies, the research employs systematic qualitative content analysis using MAXQDA software. The analysis covers 65 transparency reports and two regulatory texts published by Meta, X (formerly Twitter), YouTube, and Tik

### When GDPR-Principles Blind Each Other: Accountability, Not Transparency, at the Heart of Algorithmic Governance

*Source: European Data Protection Law Review, 2022-01-01 — https://overview.legal/posts/132535 — original: https://doi.org/10.21552/edpl/2022/1/7*

### Automating the Design and Development of Usable, GDPR-Aware Web Forms

*Source: SN Computer Science, 2026-07-14 — https://overview.legal/posts/132119 — original: https://doi.org/10.1007/s42979-026-05219-7*

Abstract Personal data collection in web applications should follow mandated legislative frameworks such as the EU General Data Protection Regulation (GDPR) principles. Among others, web data collection forms should provide clear and transparent explanations regarding the purposes of the collection. At the same time, for users’ ease, such forms should follow standard usability principles. There have been works studying the merging of usability principles and privacy standards. Building on this l

### ARTIFICIAL INTELLIGENCE, DATA PROTECTION AND TRANSPARENCY: A COMPARATIVE STUDY OF GDPR AND CCPA

*Source: SSRN Electronic Journal, 2025-01-01 — https://overview.legal/posts/132537 — original: https://doi.org/10.2139/ssrn.5216910*

### Spain ∙ GDPR ‘Glasnost’: The Spanish AEPD Raises the Transparency Bar and Sanctions Two Banks

*Source: European Data Protection Law Review, 2021-01-01 — https://overview.legal/posts/132534 — original: https://doi.org/10.21552/edpl/2021/2/14*

## Tools

### DSA Transparency Database (statements of reasons)

*Source: European Commission, 2026-07-17 — https://overview.legal/posts/125631 — original: https://transparency.dsa.ec.europa.eu/*

The European Commission's database of statements of reasons that online platforms must submit under Article 17 DSA for every content moderation decision — searchable and downloadable, with dashboards on moderation practices across platforms.

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Monitoring** — https://overview.legal/topics/monitoring
  Systematic observation and tracking of individuals

---
Generated by overview.legal · https://overview.legal/topics/transparantie · 2026-08-22
