# Data Processor — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/verwerker
> Sources are cited per item. Verify against the official texts before relying on them.

The entity that processes personal data on behalf of the controller

## Overview

## Legal Framework

Article 28 GDPR establishes the core legal regime for data processors. A controller may only engage a processor that provides sufficient guarantees of implementing appropriate technical and organisational measures. The relationship must be governed by a written contract—or other legally binding act—that mandatorily addresses the subject matter, duration, nature and purpose of processing, the type of personal data, the categories of data subjects, and the obligations and rights of the controller. Article 28(3) enumerates specific contractual clauses required, including instructions-only processing, confidentiality obligations, security measures under Article 32, restrictions on engaging sub-processors without prior authorisation, assistance obligations for data subject rights and breach notification, and deletion or return of data at termination.

Article 29 GDPR reinforces the chain of command: both the processor and any person acting under the authority of the controller or processor who has access to personal data may process them only on instructions, unless legally compelled otherwise. Article 44 GDPR extends the regime to international transfers: both controllers and processors must comply with Chapter V safeguards when transferring data to third countries, including when sub-processors are located outside the EU.

The sub-processor regime under Article 28(2) and (4) is particularly relevant in cloud computing contexts, where service providers routinely outsource hosting or shared server capacity to third parties. Processors must flow down equivalent data protection obligations to each sub-processor.

## Key Developments

The Court of Justice's Schrems II ruling invalidated the Privacy Shield framework, directly impacting processors relying on third-country sub-processors. Processors must now implement supplementary transfer impact assessments and adopt appropriate safeguards, typically Standard Contractual Clauses, for any onward transfer outside the EU.

Dutch courts have clarified the enforcement expectations around processor agreements. In a case before the Dutch judiciary involving ActiveCampaign, a data subject argued that the absence of a valid processor agreement and Standard Contractual Clauses constituted independent violations warranting supervisory authority action. The court held that while the AP must investigate complaints appropriately, its investigative duty does not extend to proving the absence of violations—but the existence of a valid Article 28 agreement and transfer safeguards remains a distinct compliance obligation.

The Polish DPA's €2.68 million fine against DPD Polska demonstrates that deficient processing agreements carry substantial financial risk. The Italian Garante's fine against the Ministry of Enterprises further confirms that inadequate processing arrangements are enforceable across both private and public sector processors.

The EDPB has also issued recommendations on processor binding corporate rules, expanding the available transfer mechanisms for processor-led international data flows.

## Practical Guidance

- Execute a written Article 28(3) agreement before any processing begins; verbal arrangements or generic terms of service without the mandatory enumerated clauses are insufficient and independently sanctionable.
- Obtain the controller's prior specific or general written authorisation before engaging any sub-processor; where general authorisation is used, notify the controller of intended changes and provide an objection mechanism.
- Conduct transfer impact assessments for all sub-processors located outside the EU, implement Standard Contractual Clauses, and add supplementary measures where local law undermines the safeguards.
- Bind all personnel with access to personal data under enforceable confidentiality obligations, as required by Article 28(3)(b) and reinforced by Article 29.
- Establish documented procedures for assisting the controller with data subject rights requests, breach notification under Article 33, and data deletion or return at contract termination.

## Case law

### HvJ EU: Privacy Shield ongeldig verklaard (Schrems II)

*Source: Hof van Justitie EU, 2020-07-16 — https://overview.legal/posts/1 — original: https://eur-lex.europa.eu/legal-content/NL/TXT/?uri=CELEX:62018CJ0311*

Het Hof van Justitie verklaart het Privacy Shield-akkoord ongeldig wegens onvoldoende waarborgen voor Europese burgers tegen toegang door Amerikaanse inlichtingendiensten.

### VG München - M 26a K 25.5210

*Source: Administrative Court Munich, 2026-05-18 — https://overview.legal/posts/108991 — original: https://gdprhub.eu/index.php?title=VG_München_-_M_26a_K_25.5210*

Facts — The data subject had been liable to pay broadcasting contributions to the Controller, a German regional public broadcasting authority, since 2007. Following objections to several contribution assessment notices, the data subject submitted a request under Article 15 GDPR seeking a copy of all personal data processed about him by the Controller. The Controller responded by providing the categories of personal data and related information specified under § 11(8) of the German Broadcasting Contribution Treaty (RBStV), which governs data subject access requests relating to broadcasting contribution records, together with general privacy information. The data subject argued that the response was incomplete because it did not include copies of all documents containing his personal data, including correspondence with him and third parties. The Controller maintained that it had fully complied with its obligations under the RBStV. After the Controller declined to provide additional information, the data subject brought proceedings seeking disclosure of all personal data concerning him processed by the Controller. Holding — The Court held that § 11(8) of the German Broadcasting Contribution Treaty (RBStV) constituted a lawful restriction of the broader right of access under Article 15 GDPR pursuant to Article 23(1)(e) GDPR. It found that the national provision was a valid legislative measure, respected the essence of the fundamental right to data protection, and pursued an important public interest by ensuring the effective financing and administration of the public broadcasting system. The Court further held that the restriction was necessary and proportionate, noting that requiring the Controller to comply with the full scope of Article 15 GDPR across more than 44 million broadcasting contribution accounts would impose a disproportionate administrative and financial burden capable of undermining that public interest. The Court also held that § 11(8) RBStV satisfied the safeguards required under Article 23(2) GDPR by specifying the purposes of processing, categories of personal data, scope of the restriction, safeguards against misuse and unlawful access, the identity of the Controller, applicable storage periods and other statutory protections. Accordingly, while the Controller was required to disclose the categories of information specified under § 11(8) RBStV, it was not required to provide a copy of all personal data processed under Article 15(3) GDPR. As the Controller had already provided all information required under the national provision, the court dismissed the action.

### Data Protection Commissioner v Facebook Ireland and Maximillian Schrems

*Source: CJEU, C-311/18, 2020-07-16 — https://overview.legal/posts/51470 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0311&ref=51470*

Invalidated Privacy Shield adequacy decision and upheld validity of Standard Contractual Clauses with additional safeguards required.

### Unabhängiges Landeszentrum für Datenschutz v Wirtschaftsakademie Schleswig-Holstein

*Source: CJEU, C-210/16, 2018-06-05 — https://overview.legal/posts/51477 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62016CJ0210&ref=51477*

Facebook fan page administrators are joint controllers with Facebook.

### Rb. Den Haag - C/09/689833

*Source: District Court Den Haag, 2026-05-27 — https://overview.legal/posts/53095 — original: https://gdprhub.eu/index.php?title=Rb._Den_Haag_-_C/09/689833*

Facts — Kindred Group PLC and Risepoint Limited (the controllers) are companies that provide online gambling products. Several companies within Kindred Group PLC (Risepoint was initially in this group) offered online gambling products before a national law requiring a license entered into force. In response, several lawsuits were filed before courts regarding the validity of the gambling agreements between players and unlicensed online gambling providers. Several data subjects later requested access (Article 15 GDPR, or in the alternative, the right to portability under Article 20 GDPR) to the controller to receive information on specific transaction data and the types of games they participated in. The data subjects did not receive access and brought a claim to the court. The data subjects requested the court to hold both companies liable (jointly or separately) The court initially dismissed the claim based on the code of civil procedure, but allowed the data subjects to amend their arguments regarding the GDPR. Both companies argued that they were not controllers, and that the requests made by the data subjects were abusive. According to the companies, the data subjects requested access for the sole purpose of bringing legal actions against them. Finally, the companies argued that they did not have the obligation to comply with the requests under Article 15(4) GDPR. Holding — The court first clarified that both Kindred Group PLC and Risepoint Limited were controllers. Kindred Group PLC argued that it did not exercise any decisive influence over the purpose and means of processing. The court took into consideration the functional definition of “controller” under Article 4(7) GDPR and CJEU case law, rather than a formal definition. The court found that Kindred Group PLC was a controller for access made between May and October 2024, but not for requests made after October 2024. This is because Kindred had a unified privacy policy for companies under its group, and answered the access request from an email address containing its name. However, after October 2024, Risepoint was no longer a part of the group, and the data from Kindred had been transferred to Risepoint. The court then dismissed the controllers’ arguments, and stated that the access requests were not abusive under Article 12(5) GDPR. Under Article 12(5) GDPR, a controller may refuse a request for access if it is manifestly unfounded or excessive. However, the CJEU has clarified that a data subject does not need to justify an access request, and a controller cannot refuse a request for access on the sole ground that it serves a purpose other than obtaining information about the processing of personal data and verifying its lawfulness. In any case, the court stated that the controller bears the burden in proving that a request is manifestly unfounded or excessive. Similarly, the controllers could not rely on Article 15(4) GDPR to refuse the data subjects’ requests. The court stated that the controllers’ interest in not granting information that data subjects could use against them in court is not recognised under EU law as a basis to refuse access. While the GDPR allows for national law to restrict specific rights under Article 23 GDPR, the court stated that the restriction must be necessary and proportionate. This, however, does not apply for hypothetical situations. The court upheld the data subjects’ claim, and ordered the controllers to provide them with a copy of their transaction data. The court specified that the controllers had the obligation to provide a complete copy, in accordance with CJEU case law.

### VB v Natsionalna agentsia za prihodite

*Source: CJEU, C-340/21, 2023-12-14 — https://overview.legal/posts/51485 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0340*

Data breach alone does not establish inadequate security measures. Burden on controller to prove adequacy.

### Meta Platforms v noyb

*Source: CJEU, C-252/21, 2023-01-12 — https://overview.legal/posts/51484 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0252*

GDPR consent requirements and lead supervisory authority mechanism.

### LG Rostock - 3 O 762/19

*Source: LG Rostock, 2020-09-15 — https://overview.legal/posts/122848 — original: https://gdprhub.eu/index.php?title=LG_Rostock_-_3_O_762/19*

Facts — The German consumer organisation Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband e.V. (vzbv, the claimant) filed a lawsuit against advocado GmbH (advocado, the defendant), a German-based company that runs an online platform where attorneys can offer their services. The defendant's website had used a cookie banner with pre-ticked boxes for the use of marketing and analytics cookies. This included the use of tools such as Google Analytics that entail a data transfer to third countries. The claimant argued that the data processing in connection with the placed cookies was unlawful under Article 6(1) GDPR: A user's consent under Article 6(1)(a) GDPR could not be considered valid under Articles 4(11) and 7 GDPR, especially since the boxes were pre-ticked. Moreover, the claimant claimed that the defendant had violated Articles 5(1)(a), 13/14, 26 and 44 et seqq. GDPR as it had failed to properly inform users of the scope of intended processing activities, joint controllers and international data transfers in connection with the use of cookies. The defendant stated that it had based the use of cookies on legitimate interests under Article 6(1)(f) GDPR until the CJEU issued its decision C-673/17 on 01.10.2019 ("Planet 49"). Afterwards, the defandent argued that they changed the legal basis for processing to consent under Article 6(1)(a) GDPR, which it considered valid under Articles 4(11) and 7 GDPR. The defendant also stated that it was the sole controller for the processing activities - there were no joint controllers involved, only processors. (Furthermore, the claimant had also argued that some provisions in the defendant's general terms and conditions were unlawful from a civil law / consumer protection law perspective. This will not be discussed further in this summary.) Dispute — Was it necessary to ask for the users' consent under Article 6(1)(a) GDPR or could the processing activities in connection with the use of marketing and analytics cookies be based on legitimate interest under Artilce 6(1)(f)? Was the consent given by users' when interacting with the defendant's cookie banner valid under Articles 6(1)(a), 4(11) and 7 GDPR? Did the defendant violate GDPR provisions on transparency? Was the defendant the sole controller regarding the processing activities in connection with the use of marketing and analytics cookies or were there any joint controllers? Holding — Legal basis and validity of consent — The court held that the marketing and analytics cookies used by the defendant c an only be placed with the users' consent under Article 6(1)(a) GDPR : § 15(3) Telemediengesetz that deals with such cookies must be interpreted in light of Article 5(3) e-Privacy Directive, which requires consent for cookies not strictly necessary for technical reasons. Taking into consideration the design of the cookie banner and the lack of information provided to a website user, the court held that consent given could not be considered valid under Articles 6(1)(a), 4(11) and 7 GDPR. The banner featured pre-ticked boxes and a big "OK" button. The option "use only necessary cookies" was designed to not look like an interactive button but rather a link. Consent could therefore not be considered "freely given" and was invalid. Transparency — The court further held that the defendant violated Article 13 GDPR by mentioning an incorrect transfer mechanism under Articles 44 et seqq. GDPR for data transfers in connection with the use of cookies. Sole or joint controllership when using Google Analytics? — Lastly, the court held that the use of Google Analytics results in joint controllership of the website provider using this tool and Google . Google does not qualify as the website provider's processor under Article 4(7). This is because Google does not process the data solely for the purpose of use by the website provider. Rather, Google, like other third-party providers, expressly reserves the right to process the data for its own purposes as well. The fact that the defendant and Google entered into a data processing agreement under Article 28 GDPR does not change this assessment. The court's legal view is in line with the official opinion of the "Datenschutzkonferenz", a gathering of all German DPAs.

### Data Protection Commissioner v. Facebook Ireland Ltd, and Maximillian Schrems

*Source: CJEU, 2020-07-16 — https://overview.legal/posts/6120 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0311&ref=6120*

“[…] the standard data protection clauses adopted by the Commission on the basis of Article 46(2)(c) of the GDPR are solely intended to provide contractual guarantees that apply uniformly in all third countries to controllers and processors established in the European Union and, consequently, independently of the level of protection guaranteed in each third country. In so far as those standard data protection clauses cannot, having regard to their very nature, provide guarantees beyond a contrac

### GHARL - 200.256.426

*Source: GHARL, 2019-11-05 — https://overview.legal/posts/122859 — original: https://gdprhub.eu/index.php?title=GHARL_-_200.256.426*

Facts — DFW (a Dutch movie distributor) applies a protocol to its processing of personal data which was approved by the Dutch DPA before the GDPR came into force. DFW asked Ziggo (an internet service provider) to provide IP addresses of customers who according to DFW shared movies illegally. Ziggo refused to provide this information. Dispute — Τhe Court had to assess whose interests prevail in this case: DFW's interest in the protection of its intellectual property rights or Ziggo's interest in the protection of the personal data of its customers. Holding — The Court found that any processing needed to be based on legitimate interests according to Article 6(1)(f) GDPR and that Ziggo had to comply with Article 6(4)(d) GDPR. The Court found that DFW had a legitimate interest and that the processing was necessary. However, the Court pursued a balancing exercise between the interests of DFW and the interests of the data subjects and found that the approved protocol was not transparent enough. Thus, the possible consequences for the data subjects of providing their data to DFW could not be estimated. DFW failed to make clear which action it would take, under which circumstances and in which manner it would inform the data subjects of their rights. The Court is of the opinion that the interests of Ziggo's customers are still insufficiently safeguarded, and it, therefore, rejected DFW’s claims confirming the ruling of the Court of First Instance. The Court based its ruling on the national civil code, Articles 4(2) and 6 GDPR, Articles 17 and 47 of the Charter of Fundamental Rights (CFR), and Articles 8 and 13 ECHR.

### SG Nürnberg - S 5 SF 65/24 DS

*Source: Social Court Nuremberg, 2026-06-10 — https://overview.legal/posts/122874 — original: https://gdprhub.eu/index.php?title=SG_Nürnberg_-_S_5_SF_65/24_DS*

Facts — The data subject (a child born in 2018), represented by her parents, was insured with the controller (a statutory health insurance provider) and participated in its digital bonus programme. The bonus programme was managed via an app. To handle the information technology operations of this programme, the controller hired the processor (an IT service provider), establishing a data processing agreement under Article 28 GDPR alongside specific information security guidelines. To provide these services, the processor utilised "MOVEit Transfer," a market-leading file transfer software developed by Progress Software Corp. On 31 May 2023, the software developer publicly announced a critical, previously unknown "zero-day" vulnerability in the software (later assigned CVE-2023-34362). At that exact moment, no security patch was available. On the very same day, 31 May 2023, the processor – alongside thousands of other companies worldwide – became the victim of a global cyberattack carried out by the hacker group "Clop." The hackers exploited this zero-day vulnerability to install a "web-shell" backdoor (typically named human2.aspx), bypassing authentication to exfiltrate database records. The compromised data included the data subject's first and last name, health insurance number, bonus points balance, and a bank account number (IBAN) belonging to her mother. No medical, health, or social security data was exfiltrated. On 1 June 2023, the developer released a security patch, which the processor installed immediately. On 2 June 2023, the German Federal Office for Information Security (BSI) issued a formal IT security warning (No. 2023-240133-1100, Version 1.1). The BSI classified the IT threat level as "3 / Orange" (business-critical), confirming active exploitation with data exfiltration. The BSI recommended immediately blocking all HTTP and HTTPS traffic to MOVEit environments, checking for specific Indicators of Compromise (IoCs) in the web server directories, and applying the newly released patch before reconnecting systems to the network. On 16 June 2023, the processor informed the controller about the incident. On 17 June 2023, the controller issued a public press release confirming that its external service provider for the bonus programme had been targeted on 31 May 2023. The release stated that the security vulnerability had been closed, that there was never any connection to the controller's internal IT systems, and that relevant supervisory authorities had been notified. The controller subsequently notified the data subject's parents. On 27 March 2024, the data subject, via legal counsel, sent a formal warning letter to the controller demanding an injunction, a declaration of liability for all potential future damages, and non-material damages of at least €3,000. Following the controller's refusal, the data subject filed a lawsuit with the Nuremberg Social Court (Sozialgericht Nürnberg), later expanding the claim to the processor as a joint defendant. Holding — The Court dismissed the lawsuit as partly inadmissible and otherwise unfounded, establishing the following legal principles: First, the Court held that a successful third-party cyberattack does not establish an irrebuttable presumption that a controller or processor failed to implement appropriate security measures under Article 32(1) GDPR and Article 5(1)(f) GDPR. To escape liability under Article 82(3) GDPR, an operator must prove they implemented robust baseline security controls (such as multi-factor authentication, encryption, and lockout policies) and applied a security patch immediately upon its release by the vendor, even if this occurred before formal alerts were issued by national IT security authorities. Second, the Court held that a claim for non-material damages under Article 82(1) GDPR based on the fear or distress of future data misuse cannot be established if the data subject is a minor who has no subjective knowledge or cognitive awareness of the data breach. Furthermore, if the compromised financial data (such as an IBAN) does not belong to the data subject personally, there is no direct risk of financial harm to them, rendering the alleged fear of financial damage unfounded. Third, the Court held that an injunction claim is inadmissible due to a lack of specificity if it merely demands that a controller stop making personal data accessible to third parties without implementing "state-of-the-art" security measures, without specifying the concrete technical or organisational measures the controller is required to take. Fourth, the Court held that a declaratory claim for potential future material damages is inadmissible under national procedural law (§ 55(1) SGG) if there is no realistic probability of future financial harm, particularly because the compromised bank account belonged to a third party (the mother) and the software vulnerability was immediately patched.

### French Supreme Court upholds €8M CNIL fine against Apple for App Store ad tracking

*Source: Supreme Administrative Court, 2025-10-10 — https://overview.legal/posts/122852 — original: https://gdprhub.eu/index.php?title=CE_-_473833*

Facts — The DPA imposed an €8 million administrative fine on Apple (the controller) in 2022 (CNIL - SAN-2022-025). The DPA found that Apple used identifiers stored on users’ devices to enable personalized advertising in the App Store without first obtaining valid user consent, as required by Article 82 of the French Data Protection Act, which implements Article 5(3) of the ePrivacy Directive. Apple challenged the sanction before the Supreme Administrative Court (Conseil d’État), arguing that the DPA lacked jurisdiction, that the investigation violated Apple’s procedural rights, that the advertising-related processing did not fall within the scope of Article 82, and that the case should be referred to the Court of Justice of the EU. Apple also claimed that the fine was disproportionate. Holding — The court held that reading identifiers stored on user devices for the purpose of delivering personalised advertising constitutes access to information under Article 5(3) of the ePrivacy Directive, requiring the controller to obtain the user’s prior consent. It reasoned that since this operation was to implement personalized advertising it could not fall within the exemptions to the consent requirement. The court found that the national authority was competent because the controller’s establishment within the country contributed to the advertising operations in question. It did so by marketing devices pre-equipped with the App Store where personalized advertising appears and by providing Search Ads Specialists who helped monetize and optimize that advertising space. It also rejected the controller’s claim that the authority had violated its procedural rights, finding that the right to remain silent did not apply during CNIL investigations and that the authority had lawfully carried out the investigation providing sufficient opportunity for the controller to respond. Additionally, the court rejected Apple's request to reference the case to the Court of Justice of the EU stating that there wasn't any reasonable doubt Finally, it held that the €8 million fine was proportionate, noting the scale of the processing, the number of affected users, and the economic significance of the advertising activity.

## Guidance

### Translations proofread by EDPB Members. This language version has not yet been proofread.

*Source: EDPB, edpb-van-de-tekst-in-de-afbeeldingen-in-de-bijlage, 2025-11-21 — https://overview.legal/posts/38114 — original: https://www.edpb.europa.eu/system/files/2023-12/edpb_guidelines_05-2021_translations-of-visual-examples-in-annex_nl.pdf*

The European Data Protection Board (EDPB) published a Dutch language translation table for key GDPR terminology used in its guidance documents, including terms such as "controller" (verwerkingsverantwoordelijke), "processor" (verwerker), and "data transfer" (gegevensdoorgifte). The document is explicitly marked as a translation that has not yet been proofread by EDPB Members, indicating it is a draft or provisional language version. This translation resource serves to support consistent Dutch-language usage of GDPR concepts across EDPB guidance materials.

### Opinion 22/2024 on certain obligations following from the reliance on processor(s) and sub-processor(s)

*Source: EDPB, opinion-222024-on-certain-obligations-following-from-the-en, 2024-10-09 — https://overview.legal/posts/125715 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-222024-on-certain-obligations-following-from-the_en*

A dopted 1 Opinion 22/2024 on certain obligations following from the reliance on processor(s) and sub - processor(s) Adopted on 7 October 2024 Adopted 2 Executive summary The Danish SA requested the EDPB to issue an opinion on matters of general application pursuant to Article 64(2) GDPR. The opinion contributes to a harmonised interpretation by the national supervisory authorities of certain aspects of Article 28 GDPR, whe re appropriate in conjunction with Chapter V GDPR. In particular, the…

### Opinion 14/2019 on the draft Standard Contractual Clauses submitted by the DK SA (Article 28(8) GDPR)

*Source: EDPB, opinion-142019-on-the-draft-standard-contractual-clauses-en, 2019-07-12 — https://overview.legal/posts/126212 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-142019-on-the-draft-standard-contractual-clauses_en*

Adopted 1 Opinion 14/2019 on the draft Standard Contractual Clauses sub mitted by the DK SA (Article 28( 8 ) GDPR) Adopted on 9 July 2019 Adopted 2 1 CONTENTS 2 Summary of the Facts ................................ ................................ ................................ .................... 4 3 Assessment ................................ ................................ ................................ ................................ .... 5 3.1 General reasoning of the Board…

### Guidelines 02/2022 on the application of Article 60 GDPR

*Source: EDPB, edpb-guidelines-on-the-application-of-article-60-gdpr, 2022-03-14 — https://overview.legal/posts/38066 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-022022-on-the-application-of-article-60-gdpr_en*

With the introduction of the GDPR, the concept of the one-stop shop was established as one of the main innovations. In cross-border processing cases, the supervisory authority in the Member State of the controller's or processor's main establishment is the authority leading the  enforcement of the GDPR for the respective cross-border processing activities, in cooperation with all the authorities which may face the effects of the processing activities at stake: be it  through  the establishments ...

### Guidelines 07/2020 on the concepts of controller and processor in the GDPR

*Source: EDPB, edpb-guidelines-on-the-concepts-of-controller-and-processor-in-the-gdpr, 2021-07-07 — https://overview.legal/posts/38069 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-072020-on-the-concepts-of-controller-and-processor-in-the-gdpr_en*

The concepts of controller, joint controller and processor play a crucial role in the application of the General Data Protection Regulation 2016/679 (GDPR), since they determine who shall be responsible for compliance with different data protection rules, and how data subjects can exercise their rights in practice. The precise meaning of these concepts and the criteria for their correct interpretation must be sufficiently clear and consistent throughout the European Economic Area (EEA). The conc...

### Opinion 30/2025 on the draft decision of the Dutch Supervisory Authority regarding the Processor Binding Corporate Rules of the Illumina Group

*Source: EDPB, edpb-opinion302025-bcr-p-illumina-en, 2025-12-02 — https://overview.legal/posts/51412 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-302025-on-the-draft-decision-of-the-dutch-supervisory_en*

Opinion 30 / 2025 on the draft decision of the Dutch Supervisory Authority regarding the Processor Binding Corporate Rules of the Illumina Group Adopted on 02 December 2025 1 | 2 | The European Data Protection Board Having regard to Article 63, Article 64(1)(f) and Article 47 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and…

### Opinion 33/2025 on the draft decision of the Irish Supervisory Authority regarding the Processor Binding Corporate Rules of the CSG Group

*Source: EDPB, edpb-opinion-332025-bcr-p-csg-group-en, 2025-12-02 — https://overview.legal/posts/51415 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-332025-on-the-draft-decision-of-the-irish-supervisory_en*

Opinion 33/2025 on the draft decision of the Irish Supervisory Authority regarding the Processor Binding Corporate Rules of the CSG Group Adopted on 02 December 2025 1 | 2 | The European Data Protection Board Having regard to Article 63, Article 64(1)(f) and Article 47 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and…

### Opinion 25/2025 on the decision of the Polish Supervisory Authority regarding the Processor Binding Corporate Rules of the BOX Group

*Source: EDPB, opinion-252025-on-the-decision-of-the-polish-supervisory-en, 2025-10-07 — https://overview.legal/posts/125693 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-252025-on-the-decision-of-the-polish-supervisory_en*

Opinion 25/2025 on the decision of the Polish Supervisory Authority regarding the Processor Binding Corporate Rules of the BOX Group Adopted on 07 October 2025 1 | 2 | The European Data Protection Board Having regard to Article 63, Article 64(1)(f) and Article 47 of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing…

## Enforcement decisions

### AKI (Estonia) - No. 2.1-1/24/397-890-38

*Source: AKI (Estonia), 2026-04-16 — https://overview.legal/posts/53882 — original: https://gdprhub.eu/index.php?title=AKI_(Estonia)_-_No._2.1-1/24/397-890-38*

Facts — OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic. On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had failed to provide all personal data requested. The controller only partially complied after several requests from the DPA. Although the DPA closed the part of the case concerning the access request, it continued investigating the controller’s processing of patients’ personal data when providing Invisalign treatment. The service required the controller to collect and transfer patients’ health data to Align Technology, Inc. However, the contractual documents did not clearly establish whether Align Technology acted as a processor, an independent controller or a joint controller. The controller stated that Align Technology largely determined the conditions of the service, including the consent form and the processing arrangements, and that individual clinics could not unilaterally amend these conditions. The DPA also found that the information provided to patients was incomplete and fragmented. The consent form and privacy information did not clearly explain the legal basis and purposes of processing, the parties involved, data recipients, retention periods, transfers outside the European Union or the safeguards applied to such transfers. Parts of the information were only available in English on external websites. Holding — The DPA held that the controller had failed to demonstrate that the processing carried out in connection with the Invisalign service was lawful and transparent under Articles 5(1)(a) and 5(2) GDPR. First, the DPA found that the parties’ roles had not been properly determined. Under Article 4(7) GDPR, the assessment had to be based on which party actually determined the purposes and means of processing, rather than solely on the contractual description of the relationship. The controller decided whether Invisalign treatment was suitable for a patient and collected the relevant health data. It therefore acted as a controller in relation to the treatment. However, Align Technology exercised significant control over the subsequent processing, including the data collected, the recipients, retention arrangements, the use of other service providers and transfers outside the European Union. The DPA therefore considered that Align Technology could not simply be regarded as a processor acting only on documented instructions under Article 28(3)(a) GDPR. On the available evidence, it was at least a joint controller under Article 26 GDPR. The DPA ordered the controller to review the contractual relationship. If Align Technology acted as a processor, the agreement had to comply with Article 28 GDPR, including the requirements concerning subprocessors under Article 28(2). If the parties were joint controllers, they had to allocate their respective responsibilities under Article 26 GDPR. Second, the DPA found that the consent obtained from patients was invalid. The consent form did not provide sufficient information for patients to understand the processing and therefore did not meet Articles 4(11), 6(1)(a), 7 and 9(2)(a) GDPR. The DPA also noted that healthcare processing may, depending on the operation concerned, rely on Article 6(1)(b) GDPR together with Article 9(2)(h) GDPR. However, the controller had not clearly identified the applicable legal bases for the different processing activities. The privacy information also failed to comply with Articles 12, 13 and 14 GDPR. Patients were required to consult several documents and external websites, some of which contained incomplete or inconsistent information. The controller had therefore not ensured that the information was easily accessible, understandable and available in Estonian. The DPA further referred to Article 25 GDPR when emphasising that the controller had to ensure that the processing arrangements and safeguards complied with the GDPR. Under Article 58(2)(d) GDPR and § 56(1) of the Estonian Personal Data Protection Act, the DPA ordered the controller to clarify the parties’ roles, conclude an Article 26 arrangement or Article 28 agreement, amend the consent form and privacy policy, and publish the required information in Estonian. No administrative fine was imposed. However, failure to comply could result in a penalty payment of €1,000 for each unfulfilled point or subpoint of the order, imposed repeatedly until compliance.

### Datatilsynet (Denmark) - 2020-431-0061 (Helsingor decision no. 4)

*Source: Datatilsynet (Denmark), 2022-09-28 — https://overview.legal/posts/6313 — original: https://gdprhub.eu/index.php?title=Datatilsynet_(Denmark)_-_2020-431-0061_(Helsingor_decision_no._4)*

Facts — This is the Danish DPA's fourth decision in the case relating to Helsingor municipality's processing of personal data in primary and lower secondary school. Helsingor municipality, the controller, has been using Google Chromebooks and Workspace for Education in violation of several GDPR requirements, as detailed in the first decision of September 2021, the second decision of 14 July 2022 and the third decision of 18 August 2022. Following the third decision, the municipality submitted more documentation and also requested a consultation with the DPA as per Article 36 GDPR. Holding — The DPA temporarily suspended its processing ban against Helsingor municipality until 5 November 2022, and also ordered the municipality to: Change the data processing agreement with Google so that the DPA's remarks in their 14 July and 18 August decisions, are implemented. This includes, at a minimum, a clarification of where and if Google acts as a sole controller and any uncertainties that may entail that Google acts beyond their role as a processor, see Article 28(3)(a) GDPR. Document that all transfers of personal data to insecure third countries, are in line with the GDPR. Describe all data flows and identify the personal data that are shared with the vendor, and clarify when the vendor acts as a sole or joint controller. This documentation must include the whole technology stack used by the municipality (for this processing activity). Update their data protection impact assessment based on all identified risks. Consult the DPA if the DPIA shows any high risks the municipality is not able to mitigate. If any processing activities are still not in line with the GDPR before the DPA's deadline 3 November 2022, present a final plan for bringing them in line with the GDPR.

### SENDING TRANSPORTE Y COMUNICACIÓN, S.A.: Onvoldoende overeenkomst met betrekking tot gegevensverwerking.

*Source: Spanish Data Protection Authority (aepd), 2025-10-22 — https://overview.legal/posts/52014*

De Spaanse gegevensbeschermingsautoriteit (DPA) heeft een boete van 80.000 euro opgelegd aan SENDING TRANSPORTE Y COMUNICACIÓN, S.A. Het bedrijf dat beboet is, is een verwerker voor de verantwoordelijke partij. Het heeft een andere onderaannemer ingehuurd zonder daarvoor toestemming te hebben, en daarbij een ongeschikte DPA (gegevensbeschermingsautoriteit) gebruikt.

### UODO (Poland) - DKN.5131.7.2022

*Source: UODO (Poland), 2026-04-13 — https://overview.legal/posts/53109 — original: https://gdprhub.eu/index.php?title=UODO_(Poland)_-_DKN.5131.7.2022*

Facts — An electricity sales company (the controller) had outsourced some of its operations to two processors and one sub-processor. Employees of the sub-processor had used a smartphone application between July 2020 and March 2021 to send pictures of customer contracts containing the personal data of individuals residing at addresses visited during door-to-door sales (the data subjects). The controller had not authorised this practice, and former employees of the sub-processor could still access the personal data through the app. The controller identified the use of the app as a data breach and notified the supervisory authority about it in April 2021. The DPA initiated administrative proceedings in March 2022. Holding — First, the DPA held that the controller had violated the principles of integrity and confidentiality enshrined in Article 5(1)(f) and the principle of accountability laid down in Article 5(2) GDPR. It had also violated Articles 24(1), 25(1), 28(1), 32(1) and 32(2) GDPR, which specify these principles. The DPA issued the controller a reprimand. The DPA found the controller had failed to implement appropriate technical and organisational measures itself and also failed to properly verify whether the (sub-)processors had provided sufficient guarantees that they had implemented such measures. The data protection agreements required in Article 28(1) GDPR were very general in nature, and none of the parties in the chain of contracts had conducted a risk analysis to select appropriate security measures. In addition, the controller had not continuously monitored the processing activities. Second, the DPA held that the two processor and the sub-processor had violated Articles 32(1) and 32(2) GDPR read in conjunction with Article 28(4) GDPR. They had all failed to implement appropriate technical and organisational measures to ensure the security of personal data processing. The sub-processor was largely held responsible for the data breach – it had started using the app to process customers’ personal data without authorisation from the controller or the processors. Furthermore, the DPA pointed out the sub-processor should have verified whether the application would allow access to the personal data through it even after the termination of the employment relationship. The DPA reprimanded the processors and fined the sub-processor €2,415.

### Datatilsynet (Denmark) - 2020-422-0026

*Source: Datatilsynet (Denmark), 2022-09-28 — https://overview.legal/posts/6312 — original: https://gdprhub.eu/index.php?title=Datatilsynet_(Denmark)_-_2020-422-0026*

Facts — The Danish DPA had decided to investigate three research projects of Region Syddanmark (the controller) with regards to its processing activities, the use of processors, data processing agreements and processor audit practices. Holding — The DPA first held that, based on the information provided by the controller, there were no indications that the controller's assessment of the legal bases for the processing were incorrect. The DPA then held that the use of processors had been lawful and that the relevant data processing agreements satisfied the requirements of Article 28 GDPR. However, the DPA reprimanded the controller, partly for its lack of clear auditing procedures, and partly for not actually conducting audits in line with the routines that did exist. The DPA held that the accountability principle in Article 5 GDPR entails an obligation for the controller to oversee the security of the data processing operations performed by a processor. The DPA highlighted that entering into a data processing agreement that contains security obligations is not sufficient, and that the controller must also oversee that the processor actually adheres to the agreement. The fact that the controller had auditing procedures in place was not good enough if these auditing procedures were not being followed in practice.

### EDPS - 2020-1013

*Source: EDPS, 2022-01-05 — https://overview.legal/posts/122849 — original: https://gdprhub.eu/index.php?title=EDPS_-_2020-1013*

Facts — In January 2021, noyb filed a complaint against the European Parliament on behalf of six Members of the European Parliament over an internal coronavirus testing website. The issues raised were: confusing and unclear cookie banners, vague and unclear data protection notices, and the illegal transfer of data to the US. Holding — On data controllership — According to the EDPS, the processor may enjoy a considerable degree of autonomy in providing its services and may identify the ‘non-essential’ elements of the processing operation. Furthermore, the processor may advise or propose certain measures in this respect, but it is up to the controller to decide whether to accept such advice or proposals. The analysis of the EDPS shows that the European Parliament (EP) delegated some aspects on the setting up and functioning of the website to Ecolog. The EDPS considers the EP acts as the sole data controller for the processing in question (i.e. the operation of the Parliament’s dedicated website) whereas Ecolog acts as a processor. After having assessed the instructions given by the EP to the processor, the EDPS concluded that the EP did not show the necessary diligence required from a data controller and, ultimately, failed to comply with the Regulation on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data 2018/1725 (hereafter Regulation 2018/1725), in particular with Articles 26(1) and 29(1). Moreover, the EDPS considered that the EP failed to provide the necessary detailed instructions to Ecolog for the setting up of the website, including the drafting of the data protection notice. The absence of documented instructions is therefore in violation of Article 29(3) Regulation 2018/1725. Transparency and information requirements — The EDPS confirmed that the data protection notice published at the time of the complaint did not reflect the processing done by the EP, since it merely consisted of a copy of the testing center of Zaventem's airport. Moreover, the reference made in the document to Article 6(1)(f) GDPR was wrong since it stems from the same error. The EDPS confirmed that the EP did not meet its transparency requirements. The EDPS also analysed the updated version of the data protection notice during the procedure and raised several remaining -and even new- inconsistencies and issues. Among other things, the following problems persisted after the data protection notice was updated: a mere reference to Article 15 and 16 Regulation 2018/1725 is misleading as it should apply in its entirety; the reference to the processing of health data is not correct since no such data are processed in the case at hand; the retention period mentioned is not precise enough; the sections of the data protection notices relating to the recipients of the personal data fail to make any reference to the processor; inconsistencies between the different linguistic versions of the data protection notices were still observed: The English and German versions refer to Ecolog and the Laboratory van Poucke as processors under Article 29 Regulation 2018/1725, whereas the French version refers to them as controllers (‘responsables du traitement’). Moreover, the DPO’s contact details on the website refer to Ecolog in all three linguistic versions of the website, when they should be referring to the Parliament Cookies and transfers of personal data to the US — The EDPS confirmed that tracking cookies, such as the Stripe and the Google analytics cookies, are considered personal data, even if the traditional identity parameters of the tracked users are unknown or have been deleted by the tracker after collection. In the same vein, the EDPS rejected the EP's argument and confirmed that upon installation on a device, a cookie cannot be considered ‘inactive’. Every time a user visited Ecolog’s website, personal data was transferred to Stripe through the Stripe cookie, which contained an identifier. The EDPS reached the conclusion that a transfer of data was taking place to the US, via the use of Google and Stripe cookies, since Google Analytics is hosted in the US and the data protection notice referred to a Standard Contractual Clause (SCC) for the transfer of data outside of the EU. However, the Parliament provided no documentation, evidence or other information regarding the contractual, technical or organisational measures in place to ensure an essentially equivalent level of protection to the personal data transferred to the US in the context of the use of cookies on the website. Cookie banner on the Parliament’s dedicated website — The EDPS reminded that: before setting cookies or any other technology falling within the scope of Article 5(3) ePrivacy Directive 2002/58/EC (hereafter ePrivacy Directive), the EU institution must provide the user with adequate information on what is accessed or stored on the user’s terminal equipment, on the purposes of this action and the means for expressing their consent; no action may be performed before the consent is collected. In addition, users must be enabled to withdraw their consent at any time; ‘cookie walls’ are not in line with Regulation 2018/1725, meaning that for consent to be freely given, access to the website’s service and functionalities should not depend on the users’ consent for cookies that are not strictly necessary in the sense described above; in case personal data collected through the cookies are shared with third parties such as analytics partners, the cookie banner should draw the user's attention to it. The EDPS reached the conclusion that the cookie banners in all three languages were not in line with the definition of consent under Article 3(15) Regulation 2018/1725, nor did they meet the requirements of Article 37 Regulation 2018/1725 and Article 5(3) ePrivacy Directive. The cookie banner further failed to provide transparent information regarding the processing of personal data in relation to the cookies on the website. Request for access to personal data — The Parliament was aware that the complainants’ personal data had been processed through the cookies, which were present on the website for the period between 30 September to 4 November 2020, since transfers of personal data had taken place. Consequently, and especially following the EDPS’ inquiry on the matter, the Parliament should have replied to the complainants’ access to personal data request. The Parliament should have provided the relevant information even if it was aware that the processing of the personal data in question was unlawful, as the main purpose of the right of access under Article 15 GDPR is precisely to enable data subjects to become aware of the processing and verify the lawfulness thereof, or exercise other data subject rights. Conclusion — The EDPS concludes that the Parliament has infringed the following articles of Regulation 2018/1725: Articles 26(1) and 29(1) due to its failure to fulfil its responsibilities as controller and use a processor providing sufficient guarantees to implement appropriate technical and organisational measures; Article 29(3) due to its failure to provide documentation relating to the detailed instructions given to the processor for the setting up and functioning of the website; Articles 4(1)(a) and 14, 4(2), and 15 due to its failure to respect the principle of transparency, accountability and the data subjects’ right to information because of the inaccurate data protection notice and cookie banner on the dedicated website; Article 46 and Article 48(2)(b) of the Regulation, due to its reliance on the Standard Contractual Clauses in the absence of a demonstration that data subjects’ personal data transferred to the US were provided an essential equivalent level of protection; Article 37 read in the light of Article 5(3) of the ePrivacy Directive, due to its failure to protect information (the cookies) transmitted to, stored in, related to, processed by and collected from the users’ terminal equipment; Articles 17 and 14(4) due to its failure to reply to the data subjects’ request for access to their personal data. On the basis of the above, the EDPS decides: to issue a reprimand to the Parliament in accordance with Article 58(2)(b) Regulation 2018/1725 for the above infringements; to order the Parliament, pursuant to Article 58(2)(b) Regulation 2018/1725:, to update its data protection notices in the dedicated website in order to provide all relevant information relating to the processing of personal data. The Parliament should address this order within one month from the date of the decision.

### Telecommunicatiebedrijf (exploitant van elektronische communicatienetwerken en -diensten): Overtreding van de algemene principes van gegevensverwerking.

*Source: Croatian Data Protection Authority (azop), 2025-11-24 — https://overview.legal/posts/51939*

Na een onderzoek door de autoriteit, heeft AZOP een telecombedrijf een boete van 4,5 miljoen euro opgelegd vanwege meerdere overtredingen van de AVG. De verantwoordelijke partij heeft klantgegevens overgedragen aan een verwerker in de Republiek Servië (een dochteronderneming die software onderhoudt). Deze overdrachten vonden plaats op basis van standaardcontractuele clausules (SCC's) vanaf 16 april 2020 tot uiterlijk 27 december 2022; daarna zijn de overdrachten doorgegaan zonder SCC's of equivalente waarborgen, ondanks dat Servië niet als voldoende beschermd land wordt beschouwd.

### FT Solutions S.r.l.: Niet-naleving van algemene principes voor gegevensverwerking.

*Source: Italian Data Protection Authority (Garante), 2025-10-09 — https://overview.legal/posts/52037*

De Italiaanse autoriteit voor gegevensbescherming (DPA) heeft een boete van 5.000 euro opgelegd aan FT Solutions S.r.l. Het bedrijf, dat actief was in direct marketing als verwerker van gegevens, heeft persoonsgegevens gebruikt voor dit doel zonder voldoende juridische basis. Deze gegevens waren verkregen van een derde partij, die de gegevens ook verzamelde in strijd met de principes van gegevensbescherming. Bovendien heeft de verwerker de betrokkenen niet geïnformeerd over de verwerking en geen adequate maatregelen genomen om de gegevens te beschermen.

## Recent developments

### Artikel 40 van de AVG (Algemene Verordening Gegevensbescherming).

*Source: GDPRhub, 2026-01-05 — https://overview.legal/posts/51680*

Commentaar: Codes van Gedrag (CoC) zijn vrijwillige instrumenten die specifieke regels voor gegevensbescherming vaststellen voor bepaalde categorieën van verantwoordelijken en verwerkers. Met andere woorden, een CoC kan een handleiding vormen voor een groep verantwoordelijken en verwerkers, waarin beschreven staat hoe een verwerking die voldoet aan de AVG er in een specifieke verwerkingssituatie uitziet. <ref>EDPB, ‘Richtlijnen 1/2019 over Codes van Gedrag en Toezichthoudende Instanties onder Verordening 2016/679’, 4 juni 2019 (versie 2.0), voetnoot 7 (beschikbaar op [https://ww

### De Deense toezichthouder (SA) heeft de regio Syddanmark berispt omdat de procedures voor het controleren van verwerkingsactiviteiten niet voldoende duidelijk waren.

*Source: GDPRhub, 2022-09-28 — https://overview.legal/posts/51809*

De gegevensbeschermingsautoriteit (DPA) benadrukte dat het afsluiten van een overeenkomst voor gegevensverwerking die beveiligingseisen bevat, niet voldoende is. De verantwoordelijke partij moet er ook op toezien dat de verwerker daadwerkelijk aan de overeenkomst voldoet. Het feit dat de verantwoordelijke partij controleprocedures had, was niet voldoende als deze procedures in de praktijk niet werden nageleefd. https://www.datatilsynet.dk/afgoerelser/afgoerelser/2022/jul/tilsyn-med-region-syddanmarks-brug-af-personoplysninger-til-forskn

### De Deense beschermingsautoriteit (SA) heeft verklaard dat het gebruik van Google Analytics onrechtmatig is zonder aanvullende maatregelen.

*Source: Datatilsynet, 2022-09-21 — https://overview.legal/posts/51817*

De Deense Autoriteit voor Persoonsgegevens heeft onderzoek gedaan naar het instrument Google Analytics en de bijbehorende instellingen, evenals de voorwaarden waaronder het instrument wordt aangeboden. Op basis van dit onderzoek concludeert de Deense Autoriteit voor Persoonsgegevens dat het instrument, zonder aanvullende maatregelen, niet op een wettelijke manier kan worden gebruikt. Wettelijk gebruik vereist de implementatie van aanvullende maatregelen, naast de instellingen die door Google worden aangeboden.

### VDAI (Litouwen) - Besluit nr. 3R-1700.

*Source: GDPRhub, 2026-01-07 — https://overview.legal/posts/51672*

Feiten: De gegevensbeschermingsautoriteit (DPA) oordeelde dat een aanbieder van kansspelen gegevens op rechtmatige wijze heeft overgedragen aan een verwerker voor het versturen van uitnodigingen voor sportevenementen, maar vond dat de verantwoordelijke partij haar transparantieplicht had geschonden doordat ze de betrokkene niet had geïnformeerd over de categorieën van ontvangers van de gegevens. De DPA oordeelde dat de exploitant van een kansspelwebsite gegevens op rechtmatige wijze heeft overgedragen aan een verwerker voor het versturen van uitnodigingen voor sportevenementen, aangezien het inschakelen van een verwerker geen aparte juridische basis vereist. Echter, het gerecht...

### An analysis of Dutch case law: what factors play a role in awarding (or not) and determining the extent of damages under the GDPR?

*Source: News, 2022-11-17 — https://overview.legal/posts/6245 — original: https://www.vast-online.nl/art/4442/een-analyse-van-de-nederlandse-rechtspraak-welke-factoren-spelen-een-rol-bij-het-al-dan-niet-toekennen-en-vaststellen-van-de-omvang-van-een-schadevergoeding-op-grond-van-de-avg#entry-1349*

Since May 2018, the GDPR has been directly applicable in the European Economic Area, including the member states of the European Union, Liechtenstein, Norway, and Iceland. Four years later, awarding damages for GDPR violations is still not a common practice in the Netherlands, despite the fact that news reports regularly mention data breaches and other GDPR violations. This article analyzes Dutch case law over the past four years to see what factors may influence the awarding of damages under th

## Literature

### GDPR Implementation Series ∙ Netherlands: The GDPR Implementation Act

*Source: European Data Protection Law Review, 2018-01-01 — https://overview.legal/posts/132478 — original: https://doi.org/10.21552/edpl/2018/3/15*

### HOW GDPR TREATS AUTOMATED DECISION-MAKING

*Source: Journal Scientific and Applied Research, 2025-11-14 — https://overview.legal/posts/132599 — original: https://doi.org/10.46687/jsar.v28i1.435*

This article examines how the General Data Protection Regulation (GDPR) regulates automated decision-making, including profiling, in the context of personal data processing. It analyzes the main provisions of Article 22 of the Regulation, as well as the conditions under which fully automated decisions that produce legal effects or significantly affect data subjects are permitted. The article highlights the rights of data subjects – the right to human intervention, the right to express their poin

### GDPR Implementation Series ∙ Malta: An Overview of the GDPR Implementation

*Source: European Data Protection Law Review, 2020-01-01 — https://overview.legal/posts/132480 — original: https://doi.org/10.21552/edpl/2020/4/15*

### GDPR Implementation Series ∙ Portugal: A Brief Overview of the GDPR Implementation

*Source: European Data Protection Law Review, 2019-01-01 — https://overview.legal/posts/132482 — original: https://doi.org/10.21552/edpl/2019/4/12*

### GDPR Implementation Series ∙ Romania: Overview of the GDPR Implementation

*Source: European Data Protection Law Review, 2018-01-01 — https://overview.legal/posts/132479 — original: https://doi.org/10.21552/edpl/2018/3/16*

## Related topics

- **Processors** — https://overview.legal/topics/processors
  Entities that process data on behalf of controllers
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Data Controller** — https://overview.legal/topics/verwerkingsverantwoordelijke
  The entity that determines purposes and means of processing personal data
- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers

---
Generated by overview.legal · https://overview.legal/topics/verwerker · 2026-08-22
