# Processing — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/verwerking
> Sources are cited per item. Verify against the official texts before relying on them.

Any operation performed on personal data

## Overview

## Legal Framework

Article 4(2) GDPR defines processing as any operation or set of operations performed on personal data, whether or not by automated means. The definition is deliberately broad, encompassing collection, recording, storage, alteration, retrieval, disclosure, alignment, restriction, erasure, and destruction. Article 2(1) and (2) establishes the material scope: the Regulation applies to processing wholly or partly by automated means, and to non-automated processing of data forming part of a filing system. This expansive formulation ensures that virtually any interaction with personal data falls within the GDPR's reach.

Article 29 GDPR imposes a fundamental constraint on processing operations: processors and any person acting under the authority of the controller or processor may process personal data only on the controller's instructions, unless bound by Union or Member State law. This provision operationalizes the controller's responsibility for determining purposes and means, as defined in Article 4(7). Article 30 requires both controllers and processors to maintain records of processing activities, creating an auditable trail that supervisory authorities can inspect.

The rationale is structural: by defining processing broadly and anchoring accountability to the controller concept, the GDPR ensures that no data manipulation escapes regulatory oversight, regardless of the technical method employed.

## Key Developments

In *Schrems II* (C-311/18), the Court of Justice confirmed that supervisory authorities bear responsibility for monitoring whether processing operations—including transfers to third countries—comply with EU rules, reinforcing that processing accountability cannot be displaced by adequacy decisions alone. The Court's reasoning in paragraphs 8 through 10 underscores that technological scale and globalization have intensified the need for processing oversight.

In *Fashion ID* (C-210/16), the Court established a critical limitation on information duties tied to processing: operators must provide information to data subjects only regarding the specific operations for which that operator actually determines purposes and means. This narrows the scope of Article 13 obligations for joint controllers and clarifies that processing accountability is operation-specific rather than blanket-based.

Enforcement confirms that deficient processing foundations attract significant penalties. The Norwegian DPA's €1.82 million fine against Elkjøp AS targeted insufficient legal basis for processing, while Romania's ANSPDCP fined Poșta Română €5,000 for inadequate technical safeguards during processing operations. These decisions signal that authorities examine both the legal basis and the technical conditions under which processing occurs.

## Practical Guidance

- Map every processing operation against Article 4(2)'s enumerated activities—collection, storage, alteration, disclosure, erasure—and confirm each has a valid legal basis under Article 6 before operations begin.
- Ensure Article 29 compliance by contractually binding all subprocessors and internal personnel to process data solely on documented controller instructions, with no independent purpose determination permitted.
- Maintain Article 30 records that identify each processing operation, its purpose, legal basis, data categories, recipients, retention periods, and technical safeguards—these records are the primary instrument authorities use to assess compliance.
- Apply the *Fashion ID* principle when multiple parties are involved: delineate precisely which processing operations each party controls, and limit transparency obligations to those specific operations rather than assuming joint responsibility for the entire processing chain.
- Before any international transfer as part of processing operations, conduct a transfer impact assessment consistent with *Schrems II* requirements, evaluating whether the third country's surveillance framework undermines the adequacy of protection for the processing at issue.

## Legislation (full text of key provisions)

### Records of processing activities

*Source: GDPR, gdpr-art-30-en, 2016-04-27 — https://overview.legal/posts/90594*

### Processing of personal data relating to criminal convictions and offences

*Source: GDPR, gdpr-art-10-en, 2016-04-27 — https://overview.legal/posts/90322*

Processing of personal data relating to criminal convictions and offences or related security measures based on Article 6(1) shall be carried out only under the control of official authority or when the processing is authorised by Union or Member State law providing for appropriate safeguards for the rights and freedoms of data subjects. Any comprehensive register of criminal convictions shall be kept only under the control of official authority.

### Principles relating to processing of personal data

*Source: GDPR, gdpr-art-5-en, 2016-04-27 — https://overview.legal/posts/90243*

### Further processing of personal data for developing certain AI systems in the public interest in the AI regulatory sandbox

*Source: AI Act, aiact-art-59-en, 2024-06-12 — https://overview.legal/posts/92939*

### Article 39

*Source: EU, eu-art-39-38432, 2012-10-26 — https://overview.legal/posts/38433*

In accordance with Article 16 of the Treaty on the Functioning of the European Union and by way of derogation from paragraph 2 thereof, the Council shall adopt a decision laying down the rules relating to the protection of individuals with regard to the processing of personal data by the Member States when carrying out activities which fall within the scope of this Chapter, and the rules relating to the free movement of such data. Compliance with these rules shall be subject to the control of independent authorities.

### Services concerned

*Source: ePrivacy, eprivacy-art-3-en, 2002-07-12 — https://overview.legal/posts/132170*

Services concernedThis Directive shall apply to the processing of personal data in connection with the provision of publicly available electronic communications services in public communications networks in the Community, including public communications networks supporting data collection and identification devices.

### Recital 50 — compatible further processing of personal data

*Source: GDPR, gdpr-rec-50-en, 2016-04-27 — https://overview.legal/posts/91615*

The processing of personal data for purposes other than those for which the personal data were initially collected should be allowed only where the processing is compatible with the purposes for which the personal data were initially collected. In such a case, no legal basis separate from that which allowed the collection of the personal data is required. If the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, Union or Member State law may determine and specify the tasks and purposes for which the further processing should be regarded as compatible and lawful. Further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes should be considered to be compatible lawful processing operations. The legal basis provided by Union or Member State law for the processing of personal data may also provide a legal basis for further processing. In order to ascertain whether a purpose of further processing is compatible with the purpose for which the personal data are initially collected, the controller, after having met all the requirements for the lawfulness of the original processing, should take into account, inter alia: any link between those purposes and the purposes of the intended further processing; the context in which the personal data have been collected, in particular the reasonable expectations of data subjects based on their relationship with the controller as to their further use; the nature of the personal data; the consequences of the intended further processing for data subjects; and the existence of appropriate safeguards in both the original and intended further processing operations. Where the data subject has given consent or the processing is based on Union or Member State law which constitutes a necessary and proportionate measure in a democratic society to safeguard, in particular, important objectives of general public interest, the controller should be allowed to further process the personal data irrespective of the compatibility of the purposes. In any case, the application of the principles set out in this Regulation and in particular the information of the data subject on those other purposes and on his or her rights including the right to object, should be ensured. Indicating possible criminal acts or threats to public security by the controller and transmitting the relevant personal data in individual cases or in several cases relating to the same criminal act or threats to public security to a competent authority should be regarded as being in the legitimate interest pursued by the controller. However, such transmission in the legitimate interest of the controller or further processing of personal data should be prohibited if the processing is not compatible with a legal, professional or other binding obligation of secrecy.

### Recital 82 — records of processing activities

*Source: GDPR, gdpr-rec-82-en, 2016-04-27 — https://overview.legal/posts/91679*

In order to demonstrate compliance with this Regulation, the controller or processor should maintain records of processing activities under its responsibility. Each controller and processor should be obliged to cooperate with the supervisory authority and make those records, on request, available to it, so that it might serve for monitoring those processing operations.

### Recital 162 — statistical processing of personal data

*Source: GDPR, gdpr-rec-162-en, 2016-04-27 — https://overview.legal/posts/91839*

Where personal data are processed for statistical purposes, this Regulation should apply to that processing. Union or Member State law should, within the limits of this Regulation, determine statistical content, control of access, specifications for the processing of personal data for statistical purposes and appropriate measures to safeguard the rights and freedoms of the data subject and for ensuring statistical confidentiality. Statistical purposes mean any operation of collection and the processing of personal data necessary for statistical surveys or for the production of statistical results. Those statistical results may further be used for different purposes, including a scientific research purpose. The statistical purpose implies that the result of processing for statistical purposes is not personal data, but aggregate data, and that this result or the personal data are not used in support of measures or decisions regarding any particular natural person.

### Recital 74 — controller responsibility liability and compliance measures

*Source: GDPR, gdpr-rec-74-en, 2016-04-27 — https://overview.legal/posts/91663*

The responsibility and liability of the controller for any processing of personal data carried out by the controller or on the controller's behalf should be established. In particular, the controller should be obliged to implement appropriate and effective measures and be able to demonstrate the compliance of processing activities with this Regulation, including the effectiveness of the measures. Those measures should take into account the nature, scope, context and purposes of the processing and the risk to the rights and freedoms of natural persons.

## Case law

### CJEU - C‑769/22 - European Commission v Hungary

*Source: GDPRhub, 2026-07-24 — https://overview.legal/posts/158432 — original: https://gdprhub.eu/index.php?title=CJEU_-_C‑769/22_-_European_Commission_v_Hungary*

Facts — The background In 2021 Hungary adopted "Law LXXIX of 2021 adopting stricter measures against persons convicted of paedophilia and amending certain laws for the protection of children" ("the amending law"). The law introduced a number of rules to restrict the access of minors to content portraying or promoting gender identities that do not correspond to the sex assigned at birth, sex reassignment or homosexuality. The law also introduced new rules for access to public documents, requiring public bodies to allow broad access to information about individuals convicted of sexual offences against children. The alleged purpose of the law was to protect minors. In 2021 the Commission sent a formal letter to Hungary contesting the amending law's compliance with EU law. After some unproductive back-and-forth, the Commission escalated the case to the CJEU, requesting the CJEU to declare the amending law incompatible with EU law. The European Commission filed four pleas, claiming that Hungary violated of a long list of provisions from primary and secondary EU law . Only the Commission's fourth plea invokes data protection law- specifically, Article 8(2) of the EU Charter of Fundamental Rights (CFR) ("Protection of personal data") and Article 10 GDPR ("Processing of personal data relating to criminal convictions and offences"). The fourth plea: Article 10 GDPR The alleged violation of the GDPR relates to the amended law's rules on access to information about individuals convicted of sexual offences against children. The law amended the "Law on the criminal record system" and made documents about sexual offences accessible to a broad audience. Under the new rules, any adult who is either a relative or a guardian of a minor ("authorised person"), has the right to access and share information about individuals convicted of sexual offences against children (the data subjects) from bodies with access to registered data. The Commission claimed that the amended law failed to specify with sufficient clarity who is authorised to submit a data request and, therefore, did not provide sufficient guarantees for the rights and freedoms of data subjects regarding the conditions of access to their personal data. On these grounds, the Commission claimed that the amended law infringed Article 10 of the GDPR (as well as Art. 8(2) CFR). In its defense, Hungary argued that the law accurately identified "authorised persons" when read in light of the definition of "relatives" in the Hungarian civil code. Additionally, Hungary claimed that there were two additional criteria access to personal data under Hungarian law: the authorised person must consider the relevant data to be probably necessary, and it must be disproportionately difficult for them to access the subjects' data if they are not disclosed. In other words, Hungary argued that when interpreted correctly, Hungarian law provided for three cumulative criteria for the disclosure of data about convictions for sex offences against children: (i) the disclosure was requested by an authorized person (i.e. "any adult who is either a relative of, or educates, supervises or cares for, a person who has not attained 18 years of age"- where "relative" was to be understood in the well-defined sense of Hungarian civil law); (ii) the disclosure was probably necessary to keep the minor safe; (iii) it was disproportionately difficult for the authorized person to access the data otherwise. Hungary claimed that these criteria were clearly defined and provided sufficient safeguards for data subjects. On this basis, Hungary argued that the amended law complied with Article 10 GDPR and 8(2) CFR. Advocate General Opinion — AG Cápeta clarified that, according to CJEU case law, the GDPR did not impose an absolute ban on the disclosure of personal data from public authorities. The GDPR did, however, require a balancing between the purpose of such disclosures, and the rights and freedoms of data subjects. In particular, the disclosure of personal data regarding criminal convictions, required strict justification and clear legal safeguards, because of the sensitive nature of such data. In the case at hand, the AG conceded that the data disclosure pursued an important public interest (the protection of minors). So, the question was whether the amending law correctly balanced this interest against the right to data protection. The AG opined that the amending law failed to do so and exceeded what was strictly necessary to protect minors, for two reasons. First, the AG agreed with the Commission that the notion of "authorised persons" was too broad and unclearly defined under the amending law, even when the amending law was interpreted in light of domestic civil law. In this regard, the AG pointed to the CJEU case law on the access to personal data from national authorities: in order to satisfy the requirement of proportionality, national law that allowed for such access "must lay down clear and precise rules governing the scope and application of the measure in question and imposing minimum safeguards". The AG further opined that such criteria would also apply to access from private citizens, as in the case at hand. Second, the AG considered that requirements (ii) and (iii) (i.e.: the probable necessity of the disclosure, and the difficulty of otherwise accessing the data) were overly generic and were to be assessed by the authorized person themselves. The AG argued that such a self-declaratoty regime lent itself to abuse and deprived the disclosing body of any control over the necessity and proportionality of the disclosure. For this reason, the AG opined that the amending law failed to provide the required safeguards for data subjects. On these grounds, the AG opined that the amended law was disproportionate and violated Article 10 GDPR as well as Article 8(2) CFR. Holding — The court first noted that one of the objectives of the GDPR is to ensure a high level of protection of data subjects’ fundamental rights and freedoms, in accordance with Article 1 GDPR and Article 8(1) CFR. Therefore, any processing of personal data must be lawful, in accordance with Articles 5(1)(a) and 6(1) GDPR. In addition, any legal basis other than consent (Article 6(1)(a) GDPR) must be interpreted restrictively. The court then assessed whether the processing was lawful under Article 6(1)(e) and 86 GDPR. Article 6(1)(e) GDPR provides for a legal basis based on public interest or in the exercise of official authority vested in the controller. In the case of disclosing this data, Article 86 GDPR states that this may be done to reconcile public access to official documents with the right to the protection of personal data. The court stated that, in principle, the processing of data related to criminal convictions (including its disclosure) could be lawful under Article 6(1)(e) and 10 GDPR. However, Article 10 GDPR makes the processing subject to additional restrictions (for example, the processing must provide for appropriate safeguards). In addition, limits to the fundamental rights to privacy and data protection must respect the essence of the fundamental right and be proportionate, in accordance with Article 52(1) CFR. This is especially relevant in this case, as data related to criminal convictions is particularly sensitive and its processing can be a particularly serious interference with data subjects’ fundamental rights. The court followed the reasoning of the AG in stating that the protection of minors was an important public interest. However, the court considered the amending law incompatible with Article 10 GDPR. The law was not sufficiently precise, particularly in defining the concept of “authorised person”. The court considered that the processing was not limited to what is strictly necessary, as the circle of persons potentially entitled to submit a request was too broad. Finally, the court concurred with the AG, and stated that the amending law was not proportionate. This is because it relied on the person requesting the data to justify the need to access it. Therefore, the amending law did not provide for appropriate safeguards by relying on the self-declaration regarding the necessity and proportionality of accessing the data. The court concluded that the amending law did not meet the requirements under Article 10 GDPR, meaning it could not justify its processing under Article 6(1)(e) GDPR. With this, Hungary had failed to fulfil its obligations under Article 10 GDPR and Article 8(2) CFR.

### CJEU - C‑209/23 - RRC Sports

*Source: GDPRhub, 2026-07-16 — https://overview.legal/posts/144028 — original: https://gdprhub.eu/index.php?title=CJEU_-_C‑209/23_-_RRC_Sports*

Facts — Fédération internationale de football association (FIFA) is a Switzerland-based non-profit that acts as the global governing body for football. A large number of football clubs and national football associations are member of FIFA and bound by its regulations. In January FIFA published the FIFA Football Agent Regulations (FFAR). FFAR regulated the conduct of player’s agents. In particular, FFAR provided maximum limits to agents’ remuneration and prohibited specific types of contractual arrangements between clubs, agents, and agencies. In order to ensure compliance with these rules, Article 12 FFAR required agents to disclose certain information to FIFA. In particular, agents had to disclose: Information about any agreement with a client, other than a representation agreement; Information on any arrangement between agents to cooperate in the provision of their services, or to share the revenue or profits of their services; Information about their relationship with agencies, including the names of all of the agency’s employees. Additionally, FIFA would make the information available to a number of stakeholders including agents, players, and football clubs. Three applicants (an agent, a company acting as a players’ agent, and the Vice-President of a players’ agents’ associations) challenged FFAR in the Regional Court of Mainz (Germany). The Court referred four questions to the CJEU for a preliminary ruling. In essence, the Court asked the CJEU whether the FFAR was compatible with Articles 101 TFEU (prohibition on cartels), 102 TFEU (prohibition on abuse of a dominant position), 56 TFEU (freedom to provide services), and 6 GDPR (legal bases for processing personal data). With regards to Article 6 GDPR specifically, the referring court essentially asked whether there was a lawful basis under the GDPR for a collection of personal data, such as required under the FFAR’s mandatory disclosure rules. Advocate General Opinion — The referring question did not specify what legal basis had to be examined in order to assess the compatibility of FFAR disclosures with the GDPR. However, the AG opined that interest under Article 6(1)(f) was the relevant legal basis, based on the nature of the FFAR rules and on other information on the order for reference. Therefore, the AG focused on the legal basis of legitimate interest exclusively. The AG recalled that the mandatory disclosure under FFAR were compatible with the GDPR if they met three cumulative requirements: They genuinely pursued an interest worthy of protection; They were limited to what was strictly necessary to that end; They did not place an intolerable burden on the data subjects as regards their right to privacy and their financial interests. The AG opined that in the case at hand, the processing of personal data pursued an interest worthy of protection (that is, FIFA’s interest in ensuring that the conduct of agents was consistent with the core objective of the football transfer systems, and other objectives related to the good functioning of the player market). However, the AG was more cautious about the other two requirements. With regards to the requirement of necessity, the AG noted that FFAR required the collection of a substantial amount of personal data, including delicate data about agents’ remuneration and contractual agreements. Additionally, FIFA would not only receive the data but also make it available to stakeholders such as clubs, players, and player’s agents. The AG opined that such a broad collection and disclosure of personal data could, to some extent, exceed what was strictly necessary to pursue FIFA’s legitimate interest. In that regard, the AG stressed that FIFA should explain to the referring court why the collection and disclosure of the data were necessary, in relation to each type of information. With regards to the balancing of interests, the AG opined that agents operate within a regulatory framework and, therefore, have a reasonable expectation that FIFA would process their data as a regulatory body. In the AG’s view, this expectation could weight favorably on the balancing of legitimate interest. At the same time, the AG opined that the availability of agents’ personal data to both competitors and potential clients, could financially harm agents and erode trust in agent-client relationships. Holding — The CJEU held that processing based on Article 6(1)(f) GDPR is lawful only where three cumulative conditions are met. First, the controller or a third party must pursue a legitimate interest. Second, the processing must be necessary for that interest. Third, the interests or fundamental rights and freedoms of the data subject must not override the legitimate interest pursued. Regarding the information agents were required to submit through the controller’s digital platform under Article 16 FFAR, the Court considered that ensuring compliance with the regulatory framework governing football agents could constitute a legitimate interest. This was conditional on the underlying obligations being compatible with EU and national law. The Court found that the information required under Article 16 FFAR appeared capable of identifying attempts to circumvent rules on representation, remuneration and conflicts of interest. The processing could therefore be adequate, relevant and limited to what was necessary. However, the referring court had to determine whether equally effective but less intrusive measures were available and assess any additional information requested through the platform whose precise scope was not defined in the regulations. The processing under Article 16 FFAR could therefore be compatible with Article 6(1)(f) GDPR, subject to verification by the referring court. Regarding Article 19 FFAR, the Court distinguished between the different categories of information disclosed by the controller. The publication of agents’ names and contact details, the identity of their clients, the duration and exclusivity of representation agreements and the services provided could pursue legitimate interests such as establishing professional and ethical standards, protecting clients from unethical conduct and improving transparency. Since the information concerned professional activities within a regulatory framework known to the persons involved, this processing could satisfy the balancing test under Article 6(1)(f) GDPR. By contrast, publishing detailed information about every transaction involving an agent, including the service fees paid, was not limited sufficiently. The Court held that agents and clients did not need access to detailed information about all transactions involving their competitors to comply with the regulations. The indiscriminate disclosure of this information therefore infringed the data minimisation principle under Article 5(1)(c) GDPR and was not necessary under Article 6(1)(f) GDPR. The Court also examined the publication of sanctions imposed on agents and clients. It accepted that publication could, in certain circumstances, deter misconduct, restore confidence in the market and allow persons harmed by an infringement to become aware of it. Nevertheless, Article 19 FFAR required the publication of every sanction without considering its seriousness, the harm caused, its relevance to market confidence or the time elapsed since the infringement. The regulation also did not provide for the information to cease being available after a defined period. The blanket publication obligation therefore did not appropriately balance the controller’s interests against the data subjects’ rights under Articles 7 and 8 CFR. Moreover, where a sanction contained personal data relating to criminal convictions or offences, Article 10 GDPR applied. In the absence of authorisation under EU or Member State law and supervision by a public authority, the controller could not process such data. The Court consequently held that Article 6(1)(f) GDPR precluded regulations adopted by an international sports federation insofar as they required the disclosure and publication of: every sanction imposed on agents or their clients; and detailed information concerning all transactions involving agents. The Court did not impose a fine or order any specific corrective measure. It provided an interpretation of EU law for the referring court, which remained responsible for resolving the underlying dispute and verifying the relevant factual and legal conditions.

### Amsterdam District Court: consumers seek access to ING–Google Pay data agreements

*Source: District Court Amsterdam, 2026-07-16 — https://overview.legal/posts/144027 — original: https://gdprhub.eu/index.php?title=Rb._Amsterdam_-_781904*

Facts — ING Bank (the controller) is a bank. One of the services the controller offers is to make contactless payments using an Android phone. This was initially done through its own app, however, the controller later discontinued this and offered the contactless payment through Google Pay. To activate Google Pay, data subjects have to create an account with Google. When making a payment, the controller shares data related to the payment and store to Google. Two Dutch consumer’s organisations (the “Benadeelden in Actie” Foundation, or SBIA and Consumer Union) demanded that the controller discontinue Google Pay, and requested it to share its data. The controller stated that it had reached agreements with Google regarding data processing for contactless payments, but it refused to disclose those agreements. The consumer organisations therefore filed a case with the court, requesting it to order the controller to provide access to the agreements. The organisations also requested access to additional documentation, such as (draft) decisions and research data. They argued that they questioned the lawfulness of the processing of personal data in relation to contactless payments, and needed access in order to verify whether this processing was lawful. The controller, on the other hand, argued that the argument was unsubstantiated because the processing was lawful. The organisations argued that ING and Google acted as joint controllers in accordance with Article 26 GDPR. ING disputed this, and argued that it was only a joint controller with Google for the activation of tokens when making a payment. Holding — The court also clarified that ING Bank and Google were joint controllers, in accordance with Article 26 GDPR. The court dismissed the argument that ING and Google were joint controllers only in a specific instance (activating tokens). The court stated that both companies aimed at enabling data subjects to make contact payments with their phones using Google Pay. The court considered this a jointly defined purpose. Furthermore, the companies do not limit their data exchange to tokens; for example, Google stored the payment data to generate payment summaries. In terms of further processing of the personal data by Google (e.g. for advertising purposes), the court held that the ING may have a certain duty of care. This means that ING may have the obligation to implement safeguards to prevent the processing of data for contactless payments for any other purpose. The court also stated that the data subjects can hold ING liable for a breach of this duty of care. In terms of access, the court assessed whether the organisations had this right under the code of civil procedure rather than the GDPR. The court first stated that the request for access applied to ING Bank and not ING Group (the entity the organisations had initially brought the case against). This is because the parent group ING Group did not have a banking license. The court stated that the organisations have a legitimate interest in reviewing the agreements to assess whether they are sufficient and whether the companies are processing the data lawfully. Finally, the court noted that the organisations may determine the relationship (i.e. whether a joint controllership existed) between the companies based on this access request. The court ordered the controller to provide the organisations with access to the agreements between ING and Google. This includes how data subjects’ data will be processed (business sensitive information could be redacted. However, the controller did not have to grant access to the other requested data (e.g. research data or internal correspondence).

### Bulgarian SAC upholds DPA finding on neighbour's CCTV covering adjacent property

*Source: Supreme Administrative Court of Bulgaria‎, 2026-07-13 — https://overview.legal/posts/184723 — original: https://gdprhub.eu/index.php?title=BAC_(Bulgaria)_-_7890/2026*

Facts — A data subject lodged a complaint with the Bulgarian DPA (CPDP), alleging that her neighbour (the controller) was unlawfully monitoring her property through CCTV. She claimed that a camera had been mounted on a metal structure on a third-floor terrace of the neighbouring building and installed in a manner that extended into the space above her property. According to the data subject, the camera had the technical capacity to identify individuals and objects throughout her property. The controller did not deny installing the camera but argued that it was directed towards the fence and an outbuilding on his own property. He also stated that a second camera had been installed on the western façade of the building. The controller claimed that both cameras were used solely to monitor his own property and the processing was lawful under the GDPR. The DPA carried out an on-site investigation and found that the CCTV system consisted of two independent cameras operated through separate software applications. Both cameras could be rotated in all directions and could use an automatic tracking function. The recordings were stored on memory cards for approximately 15 days before being automatically deleted, and only the controller had access to the system. The DPA noted that Camera 1 recorded the northern part of the controller’s yard, his house and the fence bordering the data subject’s property and Camera 2 recorded the roof of the controller’s house and a small part of the data subject’s yard. The DPA reviewed the oldest available footage and noticed that Camera 2 had recorded the data subject’s house and yard. The inspection report stated that the system could process personal data relating to individuals on both properties, but did not allow the identification of individuals or facial recognition. The DPA pointed out that warning stickers informing individuals of the video surveillance were displayed at the property. It found the complaint well founded in relation to Camera 1 and established a violation of Article 5(1)(c) GDPR, for which it issued an official warning to the controller. However, it found the complaint unfounded in relation to Camera 2, considering that the surveillance was permissible on the basis of the controller’s legitimate interest in protecting his property. The data subject appealed the part of the decision concerning Camera 2. The court of first instance annulled that part of the DPA’s decision and remitted the case to the DPA for reconsideration. It found that the DPA had relied entirely on the findings of the inspection team without carrying out a thorough, objective and independent examination of the relevant facts. Both the DPA and the controller appealed that judgment before the Bulgarian Supreme Administrative Court. Holding — The Supreme Administrative Court rejected the appeals and upheld the judgment of the court of first instance. The court noted that Camera 2 recorded the roof of the controller’s building and part of the data subject’s yard. It further pointed out that the DPA had found that, due to their technical characteristics, both cameras could alter their surveillance coverage and process personal data relating to individuals on both properties, while the CCTV system allowed individuals to be identified. Moreover, the court agreed with the first-instance court that the DPA had failed to provide adequate reasons for treating the two cameras differently. In particular, the DPA had not explained how the partial recording of the data subject’s yard contributed to the protection of the controller’s legitimate interest in safeguarding his property. It determined that it had also failed to establish whether adjusting the field of view of Camera 2 could expand its recording perimeter and allow it to capture a larger part of the data subject’s property.

### Audiencia Nacional upholds €2M AEPD fine against Amazon Flex for criminal-record checks

*Source: National Court, 2026-07-08 — https://overview.legal/posts/184679 — original: https://gdprhub.eu/index.php?title=AN_-_SAN_2996/2026*

Facts — Unión General de Trabajadores (UGT), a trade union, lodged a complaint with the DPA (AEPD) against Amazon Road Transport Spain, S.L., the controller. Applicants wishing to work within the Amazon Flex delivery programme were required to provide a certificate confirming that they had no criminal record. The certificates and other application documents were processed by external processors responsible for the preliminary screening of candidates. The controller considered this requirement necessary to protect its customers and ensure the security of the programme. Delivery drivers transported packages directly to private residences and had access to customers’ addresses, telephone numbers and information that could reveal aspects of their habits. They could also be entrusted with packages of significant value. On 10 February 2022, the DPA imposed a €2 million fine on the controller for an infringement of Article 6(1), in conjunction with Article 10 GDPR, as well as Articles 10 and 71 LOPDGDD. The DPA considered that a certificate showing the absence of criminal convictions still constituted personal data relating to criminal convictions and offences. Consequently, it held that candidates’ consent could not legitimise the processing without a specific authorisation under Union or national law. The controller appealed the decision before the Audiencia Nacional, the appeal court. It argued that a certificate confirming the absence of criminal records did not fall within Article 10 GDPR and referred to previous cases in which the DPA had accepted similar requirements for certain professional activities. Holding — The Court granted the appeal and annulled the DPA’s decision and the €2 million fine. First, the Court held that Article 10 GDPR must be interpreted strictly, particularly in administrative sanctioning proceedings, which are governed by the principle of minimum intervention and the prohibition of extensive interpretations against the alleged infringer. The Court distinguished between processing information concerning existing criminal convictions or offences and processing a certificate confirming that the person has no criminal record. In its view, Article 10 GDPR expressly covers personal data relating to criminal convictions and offences, but not information concerning their absence. The Court considered that a negative criminal record certificate contains favourable information regarding a person’s conduct. Therefore, processing such a certificate does not amount to processing specially protected criminal-offence data under Article 10 GDPR. As a result, the consent provided by candidates was not invalid merely because no Union or national law specifically authorised the processing under that provision. The Court distinguished the case from situations involving direct access to criminal-record databases or the creation of files containing adverse information. It also distinguished previous employment-law judgments concerning employers requesting criminal records. Although requiring such certificates could be unlawful or abusive under employment law, this did not necessarily mean that the conduct was sanctionable under data protection law. Nevertheless, the Court clarified that processing negative criminal record certificates remained subject to the general GDPR requirements, particularly the principles under Article 5 GDPR and the need for a valid legal basis under Article 6(1) GDPR. In this regard, the Court found the controller’s reasons sufficient to consider the processing legitimate. Amazon Flex drivers delivered packages to private homes and had access to customers’ contact details and information capable of revealing their habits. The Court therefore accepted that verifying candidates’ good standing served the security of the recruitment process and the protection of customers. Accordingly, the Court concluded that the processing was legitimate, granted the controller’s appeal and annulled the DPA’s decision without awarding costs.

### OLG München - 36 U 1054/25 e

*Source: Higher Regional Court Munich, 2026-06-26 — https://overview.legal/posts/184545 — original: https://gdprhub.eu/index.php?title=OLG_München_-_36_U_1054/25_e*

Facts — The data subject had used a social media platform operated by the controller, an Irish company, since 2013. The controller provided “Business Tools” to third-party website operators and app providers. These tools enabled the controller to obtain data concerning how users interacted with third-party websites and apps, including information about page visits, purchases and advertisements clicked. In November 2023, the data subject requested that the controller recognize that the processing of his personal data was contrary to the parties’ contract, erase or anonymize the personal data, provide access to the personal data and pay compensation. The data subject subsequently brought an action before the Regional Court of Munich II, seeking a declaration that the parties’ user contract did not permit the processing, cessation of the processing of personal data collected through the Business Tools on third-party websites and apps, restriction of further processing, erasure or anonymization of previously collected data and at least €5,000 in non-material damages. The relevant data included direct and indirect identifiers, such as his name, contact details, IP address and internal identifiers, as well as website URLs, visit times, app names and information about his interactions with websites and apps. The Regional Court of Munich II dismissed the action, holding that the declaratory and erasure or anonymization claims were inadmissible, the cessation claims were legally unavailable and the damages claim had not been sufficiently substantiated. In relation to the damages claim, it found that the data subject had not identified specific third-party websites or apps through which his personal data had been processed. The data subject accordingly appealed to the Higher Regional Court of Munich. Holding — The Higher Regional Court of Munich partially upheld the appeal. First, the court held that the Controller processed the data subject’s personal data under Articles 4(1) and 4(2) GDPR by receiving data transmitted through its Business Tools, associating it with a user account and storing it. The data subject was not required to identify every website, app or individual transmission because the relevant information was principally within the controller’s knowledge and it was sufficiently probable that he had been affected. Second, referring to CJEU C‑40/17 concerning the broad interpretation of “controller”, the court held that the controller was a joint controller under Articles 4(7) and 26 GDPR for the collection and transmission of the personal data. It controlled the programming of the Business Tools and participated in determining the purposes and means of processing. Allocating certain obligations to third-party website and app operators did not remove its responsibility. Third, referring to CJEU C‑252/21, the court held that the controller had not established a lawful basis for the processing of the personal data. The processing was not justified by consent under Article 6(1)(a), contractual necessity under Article 6(1)(b), a legal obligation under Article 6(1)(c), a public-interest task under Article 6(1)(e), or legitimate interests under Article 6(1)(f) GDPR. Accordingly, the court held that the controller's processing infringed Articles 5(1)(a), 5(1)(b), 5(1)(c) and 6 GDPR. Relying on CJEU C‑655/23, the court granted an injunction against future unlawful processing under German law. It also ordered restriction pending erasure under Article 18(1)(b) and erasure under Article 17(1)(d) GDPR. The court upheld the dismissal of the separate declaratory claim and also rejected anonymization of the website and app interaction data. Finally, relying on BGH VI ZR 10/24, the court awarded €1,500 in non-material damages under Article 82(1) GDPR for the data subject’s loss of control over his personal data.

### VwGH - VwGH Ro 2025/04/0007-7

*Source: Austrian Administrative Supreme Court, 2026-06-24 — https://overview.legal/posts/184547 — original: https://gdprhub.eu/index.php?title=VwGH_-_VwGH_Ro_2025/04/0007-7*

Facts — The controller was an address publisher and direct advertising company that operated a data application to provide advertisers with personal data for targeted marketing measures. In 2019, following media reports concerning the alleged sale of personal data, particularly information about natural persons’ political party affinity, the Austrian DPA (DSB) initiated an ex officio investigation against the controller. Based on its investigation, the DPA found that the controller had unlawfully processed political party affinity data and unlawfully further processed parcel-frequency data, and had infringed its obligations concerning the DPIA and record of processing activities. It consequently imposed a fine of €18,000,000. The controller appealed to the Federal Administrative Court (BVwG), arguing that the commission of an infringement by a legal person was not, in itself, sufficient for a fine to be imposed under the GDPR. It claimed that since a legal person could not act on its own, the culpable conduct of a natural person had to be identified and attributed to it. The controller argued that the DPA had failed to establish such attribution. The court agreed and, on 26 November 2020, annulled the fine. It found that the DPA had failed to establish that natural persons acting on behalf of the controller had engaged in culpable conduct. The DPA filed an extraordinary official appeal against this judgment with the Austrian Supreme Administrative Court (VwGH). The court stayed the proceedings pending the CJEU’s preliminary ruling in Case C-807/21 (Deutsche Wohnen SE), as the questions referred in that case were also relevant to the appeal proceedings. The CJEU published its judgement on this matter on 5 December 2023. The CJEU held that a fine under Article 83(4) GDPR, Article 83(5) GDPR and Article 83(6) GDPR may be imposed on anyone who qualifies as a controller where it is established that the controller committed the relevant infringement intentionally or negligently. A controller may be sanctioned where it could not have been unaware of the infringing nature of its conduct, regardless of whether it knew that its conduct infringed the GDPR. The CJEU further clarified that, where the controller is a legal person, the application of Article 83 GDPR does not require any action or knowledge on the part of its governing body. Member States may not impose additional substantive requirements for the imposition of fines beyond those laid down in Article 83 GDPR. For the determination of the fine, the controller may also constitute an undertaking within the meaning of EU competition law, with the turnover of the relevant economic unit being taken into account. Following the CJEU judgment, the Supreme Administrative Court annulled the Federal Administrative Court’s judgment on 1 February 2024. The Federal Administrative Court issued a new judgment on 27 December 2024, largely upholding the infringements but reducing the fine to €16,000,000. The controller appealed this decision before the Supreme Administrative Court. Holding — The court found that the controller gathered information concerning the political party affinity of the Austrian population based on anonymous surveys conducted by commissioned polling institutes. These surveys included specific questions concerning interest in election advertising, together with sociodemographic information such as age, level of education and income, place of residence and interest in advertising from political parties. Marketing groups were subsequently formed based on the sociodemographic data and place of residence. For each group, calculations were made to determine the likelihood that an individual with particular sociodemographic characteristics and religious affiliation would be interested in advertising from the political parties concerned. By assigning an identifiable individual to a particular marketing group, the controller linked that person to the probability values calculated for the group and the resulting political party affinity. The court held that the controller did not obtain consent from the data subjects to whom these probability scores were assigned. In total, political party affinity was attributed to approximately 2,200,000 individuals. The court reiterated that political party affinity scores attributed to identifiable individuals constituted personal data revealing political opinions within the meaning of Article 9(1) GDPR. It therefore upheld the finding that the controller had infringed Article 5(1)(a) GDPR in conjunction with Article 9(1) GDPR. In assessing the controller’s culpability, the court relied heavily on the CJEU’s judgment in Deutsche Wohnen SE. It held that the fact that the controller believed it had complied with the GDPR because it had established a quality-assured organisation was not decisive. It pointed out that under GDPR, a legal person’s fault does not require knowledge or awareness on the part of the management body. The establishment of a data protection compliance system, like the obtaining of legal advice, did not in itself exculpate the controller. It stated that the decisive question was whether the controller could have been aware of the unlawfulness of the processing of political party affinity data during the relevant period. The court ruled that the controller had incorrectly assessed that political party affinity scores did not constitute personal data and that it had consequently failed to examine whether they constituted special categories of personal data under Article 9 GDPR. The court rejected the controller’s argument that political party affinity was processed only in relation to groups rather than in relation to specific identifiable individuals. It also rejected the argument that marketing classifications used for political advertising posed no risk to data subjects. The court concluded that given the controller’s resources and its ability to examine the applicable legal position, that legal assessment amounted to gross negligence concerning the infringement of Article 5(1)(a) GDPR in conjunction with Article 9(1) GDPR. Furthermore, the court ruled that the controller’s incorrect assessment that political party affinity scores did not constitute personal data or special categories of personal data also led it to conclude in its Data Protection Impact Assessment (DPIA) that the processing did not pose a high risk and that the scope of Article 35(3)(a) GDPR was therefore not applicable. The court held that the DPIA-related infringement was therefore absorbed from the infringement of Article 5(1)(a) GDPR in conjunction with Article 9(1) GDPR. It found no separate element of wrongdoing. The court additionally ruled that the same incorrect legal assessment resulted in the controller’s failure to include political party affinity as a separate category of personal data in its record of processing activities under Article 30(1)(c) GDPR. The court similarly found that these documentation failures did not contain a separate element of wrongdoing beyond that already covered by the infringement of Article 5(1)(a) GDPR and Article 9(1) GDPR. The court therefore discontinued the proceedings concerning the separate DPIA and record-of-processing infringements. It further held that, where a controller commits multiple GDPR infringements, a single aggregate fine must be imposed under Article 83(3) GDPR, the total amount of which may not exceed the amount applicable to the most serious infringement. The court reassessed the penalty and reduced it to €13,000,000, because the DPIA and record of processing infringements were no longer to be taken into account in determining the fine.

### Rotterdam Court: DPA did not err in finding ING contactless chip payments GDPR-compliant

*Source: District Court Rotterdam, 2026-06-24 — https://overview.legal/posts/96826 — original: https://gdprhub.eu/index.php?title=Rb._Rotterdam_-_ROT_25/7371*

Facts — ING Bank N.V. (the controller) is a bank. In 2022, several data subjects brought a complaint to the DPA regarding the controller’s contactless payments. The data subjects requested the controller to issue debit cards without a chip that would enable contactless payments. The controller stated that this was not possible, however, the contactless payment feature could be disabled on the data subjects’ cards. The data subjects later filed a complaint because the debit cards contained the chips even if the contactless feature was disabled. The DPA dismissed the complaint in 2024, on the grounds that further investigation would be needed to determine whether the controller violated the GDPR or not. The DPA stated that it had limited capacity and such an investigation would place a heavy burden on it. The data subjects appealed this decision to the court, who determined that the DPA had wrongfully failed to hear the data subjects during the objection phase. The DPA issued a new decision in 2025 and concluded that the controller had not violated the GDPR. The data subjects appealed this decision, arguing that the DPA had again not investigated the case sufficiently. In addition, the data subjects argued that the controller processed personal data through the debit card chip without a valid legal basis. This is because the chip allowed payments made with blocked or expired cards, meaning Article 6(1)(b) GDPR did not apply. The controller could also not rely on consent (Article 6(1)(a) GDPR) to process the data. The DPA argued that the GDPR does not require controllers to completely eliminate a risk. In addition, disabling contactless payments or blocking cards were related to the contract between the data subject and the controller; the DPA argued that this did not remove the basis to process personal data. Holding — The court found that the DPA investigated the complaint to an appropriate extent and was not required to conduct a further investigation. According to the court, the data subjects did not provide sufficient evidence that the controller’s statements were incorrect or that the DPA lacked the technical knowledge during its investigations. The court upheld the DPA’s reasoning that Article 32 GDPR does not require a security risk to be completely eliminated, and concluded that the DPA could reasonably decide that there was no violation of the GDPR. Similarly, the court upheld the DPA’s reasoning and concluded that the controller had a valid legal basis to process the data subjects’ personal data. The court saw no need to assess potential violations of other laws (e.g. fraud or forgery) or consumer law issues, on the grounds that the DPA’s investigation is limited to compliance with the GDPR. The DPA is also not required to coordinate or refer the case to other competent authorities. The court dismissed the appeal.

### Supreme Court upholds €300,000 fine against INPS for GDPR violations in COVID bonus data

*Source: Supreme Court, 2026-05-21 — https://overview.legal/posts/53097 — original: https://gdprhub.eu/index.php?title=Cass.Civ._-_15625/2026*

Facts — Istituto nazionale della previdenza sociale (INPS, the controller) is the Italian National Institute for Social Security. In 2021, the DPA fined the controller €300,000 for its data processing activities linked to a subsidy given during the pandemic (also called “the COVID bonus”). The DPA found that the controller had postponed its second screening of verifying the eligibility of data subjects to a later stage, on the grounds that there was a need to immediately pay the subsidy. The controller considered that politicians did not fall under the scope of eligible data subjects, as they were already enrolled in a mandatory social security scheme. The controller processed their personal data from databases to cross reference them with data subjects who had applied for the subsidy. The DPA found a violation of several GDPR principles: the principle of lawfulness (Article 5(1)(a) GDPR), data minimisation (Article 5(1)(c) GDPR), accuracy (Article 5(1)(d) GDPR) and accountability (Articles 5(2) and 24 GDPR). According to the DPA, the controller had not limited the cross referencing to data subjects that had received the allowance, but to those whose applications had already been rejected. In addition, the DPA found a violation of Articles 25 and 35 GDPR, as the controller failed to conduct a data protection impact assessment (DPIA). The DPA ordered the controller to erase all personal data that had been processed unlawfully and to carry out a DPIA before resuming its processing activities. The controller appealed the decision to the Court of Rome, and argued that the DPA’s decision was unfounded. The court upheld the appeal and dismissed the DPA’s decision. The court considered that the controller had processed data subjects’ data lawfully, as it had limited the amount of data to what was necessary to verify data subjects’ eligibility. The court also considered that the processing posed a low risk for data subjects’ rights, as the data subjects’ names were not disclosed. The DPA appealed this decision to the court. Holding — The court dismissed the appeal. The court first stated that the controller processed the data lawfully under Article 6(1)(e) GDPR (public interest) and Article 6(3)(b) GDPR. While the controller processed data of specific data subjects (politicians), the court stated that national law allowed the controller to check the eligibility of all data subjects applying for the subsidy. The controller had also obtained the personal data through public databases provided by the Chambers of Parliament and Ministry of the Interior. The court also dismissed the DPA’s arguments on data minimisation (Article 5(1)(c) GDPR). The court stated that the principle of data minimisation is not absolute, and must be balanced with other interests at stake. The court took into consideration the fact that the data was publicly available and the need to quickly verify a high number of applications during a state of emergency. According to the court, there was also no other way to check applications still under review, and concluded that there was an overriding public interest in carrying out the verification process quickly. Finally, the court considered that the controller complied with Article 25 GDPR, as it processed data lawfully and in compliance with Article 5(1)(c) GDPR. In terms of data accuracy (Article 5(1)(d) GDPR), the court dismissed the DPA’s argument that the controller’s system did not eliminate the risk of “homocodes” (identical tax numbers between two or more people). The court considered that the data collected by the Chambers of Parliament and Ministry of Interior were presumed to be accurate. The court also noted that national law foresees the risk of “homocodes” and sets specific procedures in such cases, and that no actual inaccuracies were found in the controller’s verification process. Finally, the court did not find a violation of Article 35 GDPR. The court stated that the controller did not have the obligation to conduct a DPIA, as it did not meet all the necessary criteria. According to the court, the DPA failed to explain the potential high risks of large scale processing that would have justified the need for a DPIA. Given the previous dismissed arguments, the court considered that the controller had also complied with the principle of accountability (Articles 5(2) and 24 GDPR).

### French Supreme Admin Court partly upholds challenge to graduated response IP data decree

*Source: Supreme Administrative Court, 2026-04-30 — https://overview.legal/posts/122869 — original: https://gdprhub.eu/index.php?title=CE_-_N._433539*

Facts — Several digital rights organisations asked the Prime Minister to repeal Decree No. 2010-236 of 5 March 2010. The decree regulated an automated personal data processing system used by the French authority for freedom of communications (ARCOM, hereinafter the French authority) for France’s online copyright enforcement mechanism, known as the graduated response procedure. Under this system, the French authority could receive IP addresses linked to alleged copyright infringements and request the corresponding subscriber identity data from electronic communications operators. This data could then be used to send warnings to subscribers and, in repeated cases, refer the matter to the public prosecutor. The applicants argued that the decree allowed the French authority to access personal data linked to IP addresses without sufficient safeguards under EU law. The court had previously referred questions to the CJEU, which ruled in Case C-470/21 that such access may be allowed, but only under strict conditions. Following the CJEU judgment, the court reviewed whether the French decree complied with EU law. Holding — The court partly upheld the action. First, the court held that EU law allows the general and indiscriminate retention of IP addresses for combating criminal offences in general only where serious interference with private life is effectively excluded. This requires strict separation between different categories of retained data, secure technical safeguards and regular monitoring by an independent public authority. The court found that French law did not require electronic communications operators to retain subscriber identity data and IP-related data under these conditions. Therefore, the decree was unlawful insofar as it allowed the French authority to process data that had not necessarily been retained in compliance with EU-law safeguards. Second, the court held that the French authority may access subscriber identity data linked to IP addresses in order to identify persons suspected of online copyright infringements and send the first two warnings under the graduated response procedure. However, the court distinguished the third access to such data. At that stage, the authority is no longer dealing with an isolated identification request: it has already linked the same person’s identity twice with alleged unlawful online activity and with the protected works concerned. A third access therefore allows the authority to build a more detailed picture of the person’s conduct and may reveal sensitive aspects of their private life. It also marks a more serious procedural stage, since it may lead to a registered letter and ultimately to referral to the public prosecutor. For that reason, EU law requires prior authorisation by a court or an independent administrative body before this third access takes place. The decree did not provide for such prior review, so the court held that it was unlawful to that extent. For this third access, EU law requires prior authorisation by a court or an independent administrative body. The decree did not provide for such prior review. The court therefore held that the decree was unlawful to that extent. The court annulled the Prime Minister’s refusal to repeal the unlawful parts of the decree and ordered their repeal. It also held that the French authority must stop applying the unlawful provisions. However, the French authority may still access identity data for the first and second warnings, and may request access in serious copyright offence cases under the conditions set out in the judgment.

### BVwG - W254 2321912-1

*Source: Federal Administrative Court, 2026-04-14 — https://overview.legal/posts/125597 — original: https://gdprhub.eu/index.php?title=BVwG_-_W254_2321912-1*

Facts — The data subject, an Austrian citizen residing in Vienna, was enrolled in a distance-learning programme at a German university (the controller). When the data subject enrolled, the controller registered them under the official name shown on their identity document. The data subject experienced gender dysphoria and had chosen a gender-neutral name for themselves which was a different to their legal name. They requested the controller to rectify and replace their official name with their chosen name. They stated that the chosen name reflected better their gender identity. The controller refused the change because the data subject had not provided either an official document proving a legal name change or a dgti supplementary ID card. This is a German supplementary identity document issued by Deutsche Gesellschaft für Trans*- und Inter*geschlechtlichkeit e.V. (dgti e.V.), a German association supporting trans and intersex persons, which may certify, among other things, a chosen first name, pronouns, gender and a current photo. The controller claimed that such a document would allow it to record changes concerning pronouns and first name in its administrative system. On 6 May 2024 the data subject lodged a complaint with the Austrian DPA. They argued that the controller failed to comply with their rectification request under Article 16 GDPR. The data subject also relied on the CJEU’s judgement in Deldits case(C-247/23), which concerned the rectification of gender identity data under Article 16 GDPR. As the controller was established in Germany, the Austrian DPA considered that the Thuringian DPA was the lead supervisory authority for the cross-border processing. The Thuringian DPA held that the controller had not violated Article 16 GDPR. Because the complaint had been lodged with the Austrian DPA and the outcome was a dismissal of the complaint, Article 60(8) GDPR required the supervisory authority with which the complaint had been lodged to adopt the decision and notify the data subject. The data subject then appealed that decision before the Austrian Federal Administrative Court. They argued that the continued use of the official name resulted in misidentification and systematic misgendering. They also stated that the prerequisite to submit further documents proving the name change was excessive and disproportionate. Moreover, the data subject requested that the chosen name should at least be used in non-legally binding university systems, such as the learning platform, email address, campus card and attendance lists. The controller noted that it was legally obligated to identify students and process their data based on official identification documents. This applied, on the one hand, to the transcripts addressed in the administrative proceedings, but also to other academic achievements by students, such as individual coursework, seminar work, or work within interdisciplinary study teams. Holding — The court first confirmed that the cooperation procedure under Article 56 GDPR and Article 60 GDPR had been correctly applied. The Thuringian DPA acted as the lead supervisory authority because the controller was established in Germany. However, since the complaint was dismissed, the Austrian DPA, as the authority with which the complaint had been lodged, adopted the rejection decision pursuant to Article 60(8) GDPR. The court held that there was no violation of Article 16 GDPR. It emphasised that the accuracy of personal data must be assessed in relation to the purpose of the processing. The controller processed the official name in order to identify the student, administer the study programme, issue certificates and academic degrees that aim to be recognized outside the university and certify the student's completion of the program to third parties. The court held that in light of these processing purposes, the processed data of the data subject should be regarded as accurate within the meaning of Article 16 GDPR. Since the data subject had not officially changed their name and had not submitted any official document, the court found that the official name was not inaccurate for the controller’s stated processing purposes. It further stated that the requirement to provide proof of a name change or to present a supplementary identification document was proportionate. The court acknowledged that gender identity is protected as part of private life under Article 8 ECHR. However, it distinguished the case from Deldits. In Deldits, the issue concerned the rectification of gender data in a public register and CJEU held that a data subject requesting the correction of gender identity data may be required to provide relevant and sufficient evidence, taking into account the circumstances of the individual case, in order to establish the inaccuracy of such data. By contrast, this case concerned university administration and academic documents whose effects extend beyond the university and there was no official change of the data subject’s name. Therefore, the court maintained that the controller could continue to use the official name unless the data subject provided official proof of name change. The court further noted that the request to use the chosen name only in non-legally binding systems went beyond the original complaint.

### CJEU - C‑371/24 - Comdribus

*Source: GDPRhub, 2026-03-19 — https://overview.legal/posts/125595 — original: https://gdprhub.eu/index.php?title=CJEU_-_C‑371/24_-_Comdribus*

Facts — In 2020, law enforcement officers arrested several people from a climate protest. One of the individuals detained (the data subject) provided their identity, but refused to be fingerprinted and photographed, as well as to provide the code to their phone (or unlock it themselves). The data subject was later accused before the Paris Criminal Court of unlawfully organising a protest, as well as refusing to provide their data for identification and investigation purposes in accordance with national law . The court found them guilty of not providing their biometric data and fined the data subject €300. Both the data subject and Public Prosecutor appealed the decision to the Paris Court of Appeal. The court requested a preliminary ruling from the CJEU, regarding the compatibility of national law with provisions of the Law Enforcement Directive (LED), taking into consideration previous case law . Specifically, the court had questions regarding the systematic processing of biometric data of a data subject reasonably suspected of having committed or attempted to commit an offense in the context of an investigation, when the data subject has not necessarily been accused of committing an offense. The court referred the following questions: 1. Does the Law Enforcement Directive 2016/680 preclude national legislation from systematically processing identification data from data subjects who are suspected of having committed or attempted to commit an offense? 2. Does the Law Enforcement Directive 2016/680 require national legislation to oblige a competent authority to sufficiently explain why it is strictly necessary to process this data on an individual basis? 3. Does the Law Enforcement Directive 2016/680 preclude national legislation from allowing data subjects to be prosecuted on the basis of refusing to provide identification data, even if they are not prosecuted for or convicted of the offense under which said data was processed? The French Government argued that the national law complies with the strict necessity requirements of the LED. For example, the wording of the law leaves the competent authority the discretion to process non-sensitive data for the purposes of the investigation. In addition, national law provisions strictly limit the processing of biometric data for investigation purposes. Finally, the government questioned the admissibility of the second and third questions, arguing that both concerned matters outside the scope of EU law. Holding — Question 1: systematic collection of biometric data under national law — The court first noted that Article 10 Law Enforcement Directive 2016/680 aims to ensure a higher level of protection for personal data that is considered sensitive by nature (e.g. biometric data), as its processing can create significant risks for data subjects’ fundamental rights. Under Article 10 Law Enforcement Directive 2016/680, processing activities allowed under national law must also be strictly necessary in relation to the purposes of processing this data. This also requires the purposes to be sufficiently precise, and the processing activities to be relevant and respects the principle of data minimisation (Article 4(1)(c) Law Enforcement Directive 2016/680). Therefore, Member States must either delegate the responsibility of complying with these requirements to a competent authority, or include assessment criteria in national law for authorities to follow. In this case, the court found that national law is not compatible with the LED in terms of collecting biometric data in an indiscriminate and generalised manner. This is because it provided for the systematic collection of biometric and genetic data of any person accused of an intentional offense with the purpose of entering them in a record, without also obliging competent authorities to demonstrate first that this data processing is strictly necessary. The court stated that the scope of processing biometric data was particularly broad, as it concerned all data subjects reasonably suspected of having committed or attempted to commit a criminal offense. The court took into consideration the possible interferences with data subjects’ fundamental rights . The court concluded that it was for the referring court to determine whether national law required the police authority to carry out a systematic collection of biometric data, and to verify the data subject’s claim of an automated database containing the fingerprints of 6.5 million data subjects. Question 2: obligation of a competent authority to explain the necessity of the data processing — The court first stated that this question was admissible, as it concerned the obligations of a national competent authority in relation to EU law (Article 10 of the LED). The court then noted that the obligation to implement appropriate safeguards when processing biometric data is connected to data subjects’ fundamental right to an effective judicial remedy (Article 47 CFR). Therefore, a competent authority must provide data subjects with information on why it is “strictly necessary” to process their biometric data to allow them to exercise this right. The court stated that this information could be succinct in order to not compromise the investigation. However, the information must also be sufficiently clear. Furthermore, this obligation was essential in ensuring that a competent authority carries a case by case assessment on whether it is “strictly necessary” to process a data subject’s biometric data, as well as allowing national courts to review the competent authority’s decision. This is especially relevant in relation to the competent authority’s obligation to demonstrate compliance with Articles 4(1)(a) to (c) Law Enforcement Directive 2016/680, as it acts as a controller in accordance with Article 3(8) Law Enforcement Directive 2016/680. In any event, this judicial review cannot compensate for cases where the competent authority is not obliged to state the reasons why the data processing is strictly necessary. Finally, the court noted that this obligation is not an excessive burden for the authority, since it was clear that it may not systematically process biometric data of data subjects reasonably suspected of having committed or attempted to commit an offense. Question 3: refusal to provide biometric data as an offense — The court first stated that this question was admissible, as it was not obvious that the facts in dispute bear no relation to EU law. The court clarified that the LED was also applicable to situations in which a competent authority attempts to process personal data. Therefore, if national law imposes a criminal penalty for refusing to provide this data, this penalty is lawful if it complies with the LED (in essence, the processing must meet the conditions of strict necessity in accordance with Article 10 Law Enforcement Directive 2016/680 and Articles 4(1)(a) to (c) Law Enforcement Directive 2016/680 and 8 Law Enforcement Directive 2016/680). The court stated that the LED does not preclude national law allowing data subjects to be prosecuted on the basis of refusing to provide identification data, even if they are not prosecuted for or convicted of the offense under which said data was processed. However, national law must meet the strict necessity requirement under Article 10 Law Enforcement Directive 2016/680, and the criminal penalty must be proportionate. The court noted that fact that a data subject is reasonably suspected of committing an offense or attempted to commit an offense is not in itself decisive to determine whether the data processing is strictly necessary. In addition, the criminal penalty must be proportionate to the offense, and take into account the individual circumstances of each case. The court concluded that it was for the referring court having jurisdiction to impose a criminal penalty to take into consideration the individual circumstances of the case.

## Guidance

### Translations proofread by EDPB Members. This language version has not yet been proofread.

*Source: EDPB, edpb-van-de-tekst-in-de-afbeeldingen-in-de-bijlage, 2025-11-21 — https://overview.legal/posts/38114 — original: https://www.edpb.europa.eu/system/files/2023-12/edpb_guidelines_05-2021_translations-of-visual-examples-in-annex_nl.pdf*

The European Data Protection Board (EDPB) published a Dutch language translation table for key GDPR terminology used in its guidance documents, including terms such as "controller" (verwerkingsverantwoordelijke), "processor" (verwerker), and "data transfer" (gegevensdoorgifte). The document is explicitly marked as a translation that has not yet been proofread by EDPB Members, indicating it is a draft or provisional language version. This translation resource serves to support consistent Dutch-language usage of GDPR concepts across EDPB guidance materials.

### Opinion 18/2021 on the draft Standard Contractual Clauses submitted by the LT SA (Article 28(8) GDPR)

*Source: EDPB, opinion-182021-on-the-draft-standard-contractual-clauses-en, 2021-05-19 — https://overview.legal/posts/126032 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-182021-on-the-draft-standard-contractual-clauses_en*

1 Adopted Opinion 18 /2021 on the draft Standard Contractual Clauses sub mitted by the LT SA (Article 28( 8 ) GDPR) Adopted on 19 May 2021 2 Adopted 3 Adopted The European Data Protection Board Having rega rd to Article 28(8), Article 63 and Article 64(1 ) (d), (3) - (8) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repe…

### Opinion 16/2021 on the draft decision of the Belgian Supervisory Authority regarding the “EU Data Protection Code of Conduct for Cloud Service Providers” submitted by Scope Europe

*Source: EDPB, opinion-162021-on-the-draft-decision-of-the-belgian-en, 2021-05-19 — https://overview.legal/posts/126028 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-162021-on-the-draft-decision-of-the-belgian_en*

Adopted Opinion 16/2021 on the draft decision of th e Belgian Supervisory Authority regarding the “EU Data Protection Code of Conduct for Cloud Service Providers” submitted by Scope Europe Adopted on 19 May 2021 2 Adopted 3 Adopted The European Data Protection Board Having regard to Article 63, Article 64(1) ( b ) and Article 4 0 of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of…

### Opinion 17/2020 on the draft Standard Contractual Clauses submitted by the SI SA (Article 28(8) GDPR)

*Source: EDPB, opinion-172020-on-the-draft-standard-contractual-clauses-en, 2020-05-19 — https://overview.legal/posts/126161 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-172020-on-the-draft-standard-contractual-clauses_en*

1 Adopted Opinion 17 /2020 on the draft Standard Contractual Clauses sub mitted by the SI SA (Article 28( 8 ) GDPR) Adopted on 19 May 2020 2 Adopted 4 Final Remarks ................................ ................................ ................................ ................................ .. 9 3 Adopted The European Data Protection Board Having rega rd to Article 28(8), Article 63 and Article 64(1 ) (d), (3) - (8) of the Regulation 2016/679/EU of the European Parliament and of the…

### Opinion 19/2026 on the draft decision of the Dutch Supervisory Authority regarding the Processor Binding Corporate Rules of the Rubrik Group

*Source: EDPB, opinion-192026-on-the-draft-decision-of-the-dutch-supervisory-en, 2026-06-08 — https://overview.legal/posts/125672 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-192026-on-the-draft-decision-of-the-dutch-supervisory_en*

Opinion 19/2026 on the draft decision of the Dutch Supervisory Authority regarding the Processor Binding Corporate Rules of the Rubrik Group Adopted on 08 June 2026 1 | Adopted 2 | Adopted The European Data Protection Board Having regard to Article 63, Article 64(1)(f) and Article 47 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such…

### Opinion 04/2024 on the notion of main establishment of a controller in the Union under Art. 4.16(a) GDPR

*Source: EDPB, opinion-042024-on-the-notion-of-main-establishment-of-a-en, 2024-02-13 — https://overview.legal/posts/125773 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-042024-on-the-notion-of-main-establishment-of-a_en*

Opinion 04/2024 on the notion of main establishment of a controller in the Union under Article 4(16)(a) GDPR Adopted on 13 February 2024 Executive summary The French Supervisory Authority requested the European Data Protection Board to issue an opinion on the notion of main establishment of a controller under Article 4(16)(a) GDPR, and on the criteria for the application of the one-stop-shop mechanism, in particular regarding the notion of controller’s “place of central administration” in the…

### Guidelines 07/2020 on the concepts of controller and processor in the GDPR

*Source: EDPB, edpb-guidelines-on-the-concepts-of-controller-and-processor-in-the-gdpr, 2021-07-07 — https://overview.legal/posts/38069 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-072020-on-the-concepts-of-controller-and-processor-in-the-gdpr_en*

The concepts of controller, joint controller and processor play a crucial role in the application of the General Data Protection Regulation 2016/679 (GDPR), since they determine who shall be responsible for compliance with different data protection rules, and how data subjects can exercise their rights in practice. The precise meaning of these concepts and the criteria for their correct interpretation must be sufficiently clear and consistent throughout the European Economic Area (EEA). The conc...

### Opinion 17/2021 on the draft decision of the French Supervisory Authority regarding the European code of conduct submitted by the Cloud Infrastructure Service Providers (CISPE)

*Source: EDPB, opinion-172021-on-the-draft-decision-of-the-french-en, 2021-05-19 — https://overview.legal/posts/126026 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-172021-on-the-draft-decision-of-the-french_en*

Adopted Opinion 17/2021 on the draft decision of the French Supervisory Authority regarding the European code of conduct submitted by the Cloud Infrastructure Service Providers (CISPE) Adopted on 19 May 2021 2 Adopted 3 Adopted The European Data Protection Board Having regard to Article 63, Article 64(1)( b ) and Article 4 0 of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal…

## Enforcement decisions

### Datatilsynet (Denmark) - 2020-422-0026

*Source: Datatilsynet (Denmark), 2022-09-28 — https://overview.legal/posts/6312 — original: https://gdprhub.eu/index.php?title=Datatilsynet_(Denmark)_-_2020-422-0026*

Facts — The Danish DPA had decided to investigate three research projects of Region Syddanmark (the controller) with regards to its processing activities, the use of processors, data processing agreements and processor audit practices. Holding — The DPA first held that, based on the information provided by the controller, there were no indications that the controller's assessment of the legal bases for the processing were incorrect. The DPA then held that the use of processors had been lawful and that the relevant data processing agreements satisfied the requirements of Article 28 GDPR. However, the DPA reprimanded the controller, partly for its lack of clear auditing procedures, and partly for not actually conducting audits in line with the routines that did exist. The DPA held that the accountability principle in Article 5 GDPR entails an obligation for the controller to oversee the security of the data processing operations performed by a processor. The DPA highlighted that entering into a data processing agreement that contains security obligations is not sufficient, and that the controller must also oversee that the processor actually adheres to the agreement. The fact that the controller had auditing procedures in place was not good enough if these auditing procedures were not being followed in practice.

### CNPD (Portugal) - Deliberação 2019/494

*Source: CNPD (Portugal), 2019-09-03 — https://overview.legal/posts/122872 — original: https://gdprhub.eu/index.php?title=CNPD_(Portugal)_-_Deliberação_2019/494*

Facts — In its Opinion 20/2018 concerning the draft of Law 58/2019 which ensures the implementation of the GDPR in the portuguese national legal framework, the DPA drew the attention of the national legislator to a set of provisions that could potentially violate EU law, particularly the GDPR. The DPA emphasized the primacy of EU law as outlined in the EU treaties, particularly reflecting on Article 288 of the Treaty on the Functioning of the European Union (TFEU) and reinforced by the jurisprudence of the CJEU, which has consistently stated that national laws cannot obstruct the direct applicability of EU regulations and must comply with EU law to ensure uniform implementation across the Member States. However, Law 58/2019 came into force without incorporating all of the DPA's recommendations. The DPA explains that the decision to not apply some of its provisions aims to ensure legal certainty, reinforcing the importance of consistent GDPR application without being hindered by conflicting national rules. Holding — The DPA has decided to disapply the following provisions of Law 58/2019, in cases of personal data processing under its review due to their conflict with the GDPR: Article 2(1)(2): This article broadens the territorial scope of the GDPR to encompass all personal data processing within national territory and processing linked to national establishments outside the territory. The DPA believes this contradicts Article 3 and Article 56 of the GDPR, which outlines the applicable law in cross-border situations. Additionally, it undermines the one-stop-shop mechanism and fails to address instances where the GDPR applies, such as in Portuguese embassies, consulates, ships, and aircraft. Article 20(1): This article states that the right to be informed and the right of access cannot be exercised when a duty of secrecy is imposed on the data controller/processor. In the view of the DPA, this article lacks legal relevance in relation to the GDPR, as it merely repeats provisions already present in the GDPR, particularly concerning the possibility of restricting the data subject's right to information in cases where data collection is indirect and a legal duty of confidentiality exists. Regarding the possibility of restricting the right to information when collecting data directly from the data subject, this right can only be restricted under the provisions of Article 23 GDPR, and Law58/2019 does not meet the requirements therein, thus contradicting the norms of the GDPR and the Charter of Fundamental Rights. Article 23: This article allows public authorities to reuse personal data for any public interest without ensuring compliance with principles of purpose limitation and data minimization (Article 5 GDPR) and could lead to potential misuse of personal data and a violation of individuals’ rights, as it does not ensure that the reuse of data serves the original purpose for which it was collected nor respecting the requirements imposed in Article 23 GDPR. Article 28(3)(a): The employee's consent cannot be the legal basis if the processing results in a legal or economic advantage for the employee. The Portuguese DPA considers it to be a contraction of the doctrine established by European institutions, which accepts employee consent in situations where the act of giving or refusing consent does not, in itself, have negative consequences for the employee. The DPA therefore believes that this provision does not protect the dignity, fundamental rights, and legitimate interests of employees, and thus fails to meet the requirements set forth in Article 9 (2) (b) and Article 88 GDPR. Regime of Administrative Offenses – Articles 37, 38, and 39: The DPA notes that some of the violations outlined in the law contradict the exhaustive list provided in the GDPR (Article 83). The DPA also criticizes the distinction in sanctioning frameworks based on the size of companies and the collective or individual nature of the entities conducting data processing, as the impact on personal data does not depend on those characteristics but rather on the nature of the activity being carried out. Article 61(2) states that "if the expiration of consent is the reason for terminating a contract in which the data subject is a party, the processing of data is lawful until this occurs." The DPA notes that this provision is incongruent, conflating two types of legal basis: consent and contract execution. The contract in which the data subject is a party is sufficient to justify the processing of the data necessary for its execution. Regarding the reasons that led to publish this decision, the Portuguese DPA clarifies that it did so in order to ensure the transparency of its future decision-making processes and, in this regard, contribute to legal certainty and security. It also clarifies that the non-application, in future specific cases, of the legal provisions listed above results in the direct application of the GDPR provisions that were manifestly restricted, contradicted, or compromised in their useful effect.

### NAIH fines online store HUF 2M for unclear and incomplete privacy notice

*Source: NAIH (Hungary), 2026-07-22 — https://overview.legal/posts/156361 — original: https://gdprhub.eu/index.php?title=NAIH_(Hungary)_-_NAIH-11443-3/2026*

Facts — The DPA initiated an investigation into the GDPR compliance of an online store (the controller) processing the data of its customers (the data subjects) in April 2025. The processing activities in question included, inter alia, cookies, registration, billing, shipping, consumer complaint, and processing of orders. The privacy notice of the company operating the online store had been in force unchanged from May 2018 to May 2025, and the period under investigation extended from 1 January 2020 to 27 June 2025. Holding — The DPA held that the controller had violated Articles 12(1), 13(1)(c), (d) and (f), and 13(2)(a) GDPR and issued the controller a fine of HUF 2,000,000 (€5,500). In addition, the DPA ordered the controller to bring its data processing operations into compliance with the GDPR and to amend the content of its privacy notice. First, the DPA found an infringement of Article 12(1) GDPR: the structure of the privacy notice was confusing and difficult to follow. The privacy notice also contained incomplete, incorrect, and unnecessary information as well as repetitive details. Based on this, the DPA concluded that the controller had failed to provide data subjects with information regarding the processing of personal data that was sufficiently concise, transparent, intelligible and easily accessible. Second, the DPA held that the controller had also violated Articles 13(1)(c), (d) and (f) GDPR by failing to specify a legal basis for certain processing operations such as the use of cookies, not specifying its legitimate interests when relying on Article 6(1)(f) GDPR as a legal basis, and not providing detailed information regarding the safeguards ensuring the lawfulness of data transfers to the United States. Finally, the DPA found a violation of Article 13(2)(a) GDPR as the controller had also failed to provide the data subjects information on the period for which the personal data processed would be stored.

### Italian DPA sanctions Lusha Systems for processing contact data without consent in B2B

*Source: Garante per la protezione dei dati personali (Italy), 2026-07-14 — https://overview.legal/posts/184678 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_542/2026*

Facts — Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database. It was an US company wholly owned by Lusha Systems Ltd. In April 2025, the Italian DPA (Garante) initiated an investigation after media reports revealed that telephone numbers of senior Italian officials were available on the platform. The DPA later received one complaint and one report from data subjects who had received unsolicited advertising communications. The data subjects further stated that after requesting information about the source of their contact details, they discovered that their data were available on the controller’s platform without their consent. The controller explained that, for a subscription fee, it provided its Clients with a Business Contact Card for each Contact. The controller further distinguished between “Clients”, namely customers who used the platform and accessed its B2B database, and “Contacts”, namely the individuals whose personal data were included in that database, regardless of whether they used or were aware of the platform. Clients received Contact Cards containing information such as names, professional email addresses, telephone numbers, job titles, roles and locations, which could be used for sales, marketing, recruitment, business intelligence and fraud prevention. The DPA limited its investigation to the processing of Contacts’ personal data. The controller stated that it collected and combined data from publicly available sources, specialised providers, affiliated companies and commercial partners. It also inferred missing professional email addresses through algorithms that identified standard company email patterns. Through its Community Program and integrations with email, calendar and CRM services, it could also obtain information from Clients’ professional networks and communications. The data were cross-referenced, enriched and regularly updated to reflect changes in Contacts’ professional circumstances. The controller argued that the GDPR did not apply because it was established outside the EU and provided services only to businesses. It additionally claimed that the weekly updating of Contact Cards ensured accuracy rather than constituting monitoring or profiling. The controller maintained that the collection and disclosure of the data were necessary for its own economic interest in providing accurate professional contact information and for its Clients’ interests, including fraud prevention. According to the controller, it processed only a limited range of information concerning the Contacts’ professional lives. It further claimed that individuals who made professional information publicly available, particularly through services such as LinkedIn, could reasonably expect that the information might be reused and that they could be contacted regarding professional opportunities. Regarding transparency, the controller stated that its Personal Information Notice was sent to each Contact before their information became available in the database. It explained that it notified Contacts that they had a seven-day period during which they could opt out before their information became available to Clients. The controller also maintained that excluding public officials and public figures from the database was not a requirement under the GDPR. It attributed the presence of certain public officials to technical limitations in its filtering system. It also argued that public figures had a lower expectation of privacy. After the proceedings began, the controller removed profiles connected with Italian public bodies and officials, strengthened its filters and customer-verification measures, discontinued the Community Program in Italy and extended the opt-out period to fourteen days. Holding — Regarding the territorial scope of the GDPR, the DPA acknowledged that Article 3(2)(a) GDPR could apply to the processing of Clients’ data, but not to Contacts, since they were not recipients of the service. However, it held that Article 3(2)(b) GDPR applied because the controller systematically combined, enriched and updated Contacts’ professional information in order to assess their circumstances and determine whether and how they would appear in the database. Referring to Recital 24 and Recital 30, the DPA held that monitoring did not require profiling. It noted that the systematic observation of online traces and changes in a person’s professional situation was sufficient. The fact that the processing also served data accuracy did not alter that conclusion. It emphasised that the fact that the controller also updated the information to ensure its accuracy did not prevent the processing from constituting monitoring. Regarding transparency, the DPA found that the information concerning the collection of the Contacts’ data, the purposes of the processing and the legal basis relied upon was scattered across several documents. Also, the relevant information was not easily accessible from the controller’s homepage, while the Personal Information Notice could not be located directly through the website without prior knowledge of its existence. It further pointed out that the documents were provided in English rather than in the language of the affected data subjects. The DPA held that presenting the information in this manner did not satisfy the requirement that information be concise, transparent, intelligible and easily accessible. It therefore found an infringement of Article 5(1)(a) GDPR and Article 12 GDPR. Moreover, the DPA assessed whether Article 6(1)(f) GDPR provided a valid legal basis for the processing. It examined the controller’s Legitimate Interest Assessment and considered it essentially non-existent, as it contained only generic statements on necessity and proportionality and no genuine balancing assessment. The DPA then applied the three-part test under Article 6(1)(f) GDPR. It held that making the Contacts’ data available to Clients for their own marketing and sales activities could not constitute a legitimate interest, since the disclosure of contact information to third parties for their independent advertising purposes required prior consent under the applicable national and ePrivacy framework . However, it acknowledged that the controller’s interest in fraud prevention could be considered legitimate. The DPA nevertheless found that the processing was not necessary for the purposes pursued. It held that the controller collected information extending beyond ordinary professional contact details, including third-party data contained in CRM databases, email headers and subject lines, information about calendar meetings, and browsing data collected through browser extensions or other software integrations used by Clients. It pointed out that much of this information was not publicly available but was extracted from private interpersonal communications, disclosed by Clients, obtained through integrations with information systems or acquired from third-party providers. The DPA held that the collection and combination of such extensive information was neither strictly necessary nor proportionate for creating professional Contact Cards. Furthermore, it stressed that fraud prevention could also have been achieved through less intrusive means. The DPA therefore concluded that the necessity requirement and the principle of data minimisation were not met. Regarding the balancing test, the DPA emphasised that there was no prior relationship between the controller and the Contacts. Creating a professional profile on LinkedIn or another professional platform did not create a reasonable expectation that unpublished contact details would be collected from multiple sources, continuously updated and disclosed to an unspecified number of paying customers. It further noted that the processing could expose Contacts to communications from unknown third parties for purposes they could not reasonably anticipate. The DPA concluded that the Contacts’ interests, rights and freedoms prevailed over the controller’s economic interests and that the safeguards adopted by the controller could not change this outcome. Therefore, the DPA held that Article 6(1)(f) GDPR did not provide an appropriate legal basis and found that the controller infringed Article 5(1)(a) GDPR, Article 5(1)(c) GDPR, and Article 6 GDPR. Regarding public officials, the DPA held that their status did not reduce their entitlement to data protection and that no public interest justified disclosing their direct contact details for commercial purposes. The DPA further found that the controller had been aware of the risk that public officials could be included in its database but had failed to implement sufficiently effective technical and organisational measures. Its filters recognised general titles such as “President” but failed to exclude more specific titles such as “President of the Italian Republic” and “Vice Prime Minister”. The DPA therefore found an infringement of the principle of data minimisation under Article 5(1)(c) GDPR and the obligation of data protection by design and by default under Article 25 GDPR. The DPA imposed a fine of €2,000,000. Furthermore, it prohibited any further processing of personal data of data subjects located in Italy that had been collected without an adequate legal basis and ordered their deletion.

### AKI (Estonia) - No. 2.1-1/24/397-890-38

*Source: AKI (Estonia), 2026-04-16 — https://overview.legal/posts/53882 — original: https://gdprhub.eu/index.php?title=AKI_(Estonia)_-_No._2.1-1/24/397-890-38*

Facts — OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic. On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had failed to provide all personal data requested. The controller only partially complied after several requests from the DPA. Although the DPA closed the part of the case concerning the access request, it continued investigating the controller’s processing of patients’ personal data when providing Invisalign treatment. The service required the controller to collect and transfer patients’ health data to Align Technology, Inc. However, the contractual documents did not clearly establish whether Align Technology acted as a processor, an independent controller or a joint controller. The controller stated that Align Technology largely determined the conditions of the service, including the consent form and the processing arrangements, and that individual clinics could not unilaterally amend these conditions. The DPA also found that the information provided to patients was incomplete and fragmented. The consent form and privacy information did not clearly explain the legal basis and purposes of processing, the parties involved, data recipients, retention periods, transfers outside the European Union or the safeguards applied to such transfers. Parts of the information were only available in English on external websites. Holding — The DPA held that the controller had failed to demonstrate that the processing carried out in connection with the Invisalign service was lawful and transparent under Articles 5(1)(a) and 5(2) GDPR. First, the DPA found that the parties’ roles had not been properly determined. Under Article 4(7) GDPR, the assessment had to be based on which party actually determined the purposes and means of processing, rather than solely on the contractual description of the relationship. The controller decided whether Invisalign treatment was suitable for a patient and collected the relevant health data. It therefore acted as a controller in relation to the treatment. However, Align Technology exercised significant control over the subsequent processing, including the data collected, the recipients, retention arrangements, the use of other service providers and transfers outside the European Union. The DPA therefore considered that Align Technology could not simply be regarded as a processor acting only on documented instructions under Article 28(3)(a) GDPR. On the available evidence, it was at least a joint controller under Article 26 GDPR. The DPA ordered the controller to review the contractual relationship. If Align Technology acted as a processor, the agreement had to comply with Article 28 GDPR, including the requirements concerning subprocessors under Article 28(2). If the parties were joint controllers, they had to allocate their respective responsibilities under Article 26 GDPR. Second, the DPA found that the consent obtained from patients was invalid. The consent form did not provide sufficient information for patients to understand the processing and therefore did not meet Articles 4(11), 6(1)(a), 7 and 9(2)(a) GDPR. The DPA also noted that healthcare processing may, depending on the operation concerned, rely on Article 6(1)(b) GDPR together with Article 9(2)(h) GDPR. However, the controller had not clearly identified the applicable legal bases for the different processing activities. The privacy information also failed to comply with Articles 12, 13 and 14 GDPR. Patients were required to consult several documents and external websites, some of which contained incomplete or inconsistent information. The controller had therefore not ensured that the information was easily accessible, understandable and available in Estonian. The DPA further referred to Article 25 GDPR when emphasising that the controller had to ensure that the processing arrangements and safeguards complied with the GDPR. Under Article 58(2)(d) GDPR and § 56(1) of the Estonian Personal Data Protection Act, the DPA ordered the controller to clarify the parties’ roles, conclude an Article 26 arrangement or Article 28 agreement, amend the consent form and privacy policy, and publish the required information in Estonian. No administrative fine was imposed. However, failure to comply could result in a penalty payment of €1,000 for each unfulfilled point or subpoint of the order, imposed repeatedly until compliance.

### Datatilsynet (Denmark) - 2020-431-0061 (Helsingor decision no. 4)

*Source: Datatilsynet (Denmark), 2022-09-28 — https://overview.legal/posts/6313 — original: https://gdprhub.eu/index.php?title=Datatilsynet_(Denmark)_-_2020-431-0061_(Helsingor_decision_no._4)*

Facts — This is the Danish DPA's fourth decision in the case relating to Helsingor municipality's processing of personal data in primary and lower secondary school. Helsingor municipality, the controller, has been using Google Chromebooks and Workspace for Education in violation of several GDPR requirements, as detailed in the first decision of September 2021, the second decision of 14 July 2022 and the third decision of 18 August 2022. Following the third decision, the municipality submitted more documentation and also requested a consultation with the DPA as per Article 36 GDPR. Holding — The DPA temporarily suspended its processing ban against Helsingor municipality until 5 November 2022, and also ordered the municipality to: Change the data processing agreement with Google so that the DPA's remarks in their 14 July and 18 August decisions, are implemented. This includes, at a minimum, a clarification of where and if Google acts as a sole controller and any uncertainties that may entail that Google acts beyond their role as a processor, see Article 28(3)(a) GDPR. Document that all transfers of personal data to insecure third countries, are in line with the GDPR. Describe all data flows and identify the personal data that are shared with the vendor, and clarify when the vendor acts as a sole or joint controller. This documentation must include the whole technology stack used by the municipality (for this processing activity). Update their data protection impact assessment based on all identified risks. Consult the DPA if the DPIA shows any high risks the municipality is not able to mitigate. If any processing activities are still not in line with the GDPR before the DPA's deadline 3 November 2022, present a final plan for bringing them in line with the GDPR.

### EDPS - 2020-1013

*Source: EDPS, 2022-01-05 — https://overview.legal/posts/122849 — original: https://gdprhub.eu/index.php?title=EDPS_-_2020-1013*

Facts — In January 2021, noyb filed a complaint against the European Parliament on behalf of six Members of the European Parliament over an internal coronavirus testing website. The issues raised were: confusing and unclear cookie banners, vague and unclear data protection notices, and the illegal transfer of data to the US. Holding — On data controllership — According to the EDPS, the processor may enjoy a considerable degree of autonomy in providing its services and may identify the ‘non-essential’ elements of the processing operation. Furthermore, the processor may advise or propose certain measures in this respect, but it is up to the controller to decide whether to accept such advice or proposals. The analysis of the EDPS shows that the European Parliament (EP) delegated some aspects on the setting up and functioning of the website to Ecolog. The EDPS considers the EP acts as the sole data controller for the processing in question (i.e. the operation of the Parliament’s dedicated website) whereas Ecolog acts as a processor. After having assessed the instructions given by the EP to the processor, the EDPS concluded that the EP did not show the necessary diligence required from a data controller and, ultimately, failed to comply with the Regulation on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data 2018/1725 (hereafter Regulation 2018/1725), in particular with Articles 26(1) and 29(1). Moreover, the EDPS considered that the EP failed to provide the necessary detailed instructions to Ecolog for the setting up of the website, including the drafting of the data protection notice. The absence of documented instructions is therefore in violation of Article 29(3) Regulation 2018/1725. Transparency and information requirements — The EDPS confirmed that the data protection notice published at the time of the complaint did not reflect the processing done by the EP, since it merely consisted of a copy of the testing center of Zaventem's airport. Moreover, the reference made in the document to Article 6(1)(f) GDPR was wrong since it stems from the same error. The EDPS confirmed that the EP did not meet its transparency requirements. The EDPS also analysed the updated version of the data protection notice during the procedure and raised several remaining -and even new- inconsistencies and issues. Among other things, the following problems persisted after the data protection notice was updated: a mere reference to Article 15 and 16 Regulation 2018/1725 is misleading as it should apply in its entirety; the reference to the processing of health data is not correct since no such data are processed in the case at hand; the retention period mentioned is not precise enough; the sections of the data protection notices relating to the recipients of the personal data fail to make any reference to the processor; inconsistencies between the different linguistic versions of the data protection notices were still observed: The English and German versions refer to Ecolog and the Laboratory van Poucke as processors under Article 29 Regulation 2018/1725, whereas the French version refers to them as controllers (‘responsables du traitement’). Moreover, the DPO’s contact details on the website refer to Ecolog in all three linguistic versions of the website, when they should be referring to the Parliament Cookies and transfers of personal data to the US — The EDPS confirmed that tracking cookies, such as the Stripe and the Google analytics cookies, are considered personal data, even if the traditional identity parameters of the tracked users are unknown or have been deleted by the tracker after collection. In the same vein, the EDPS rejected the EP's argument and confirmed that upon installation on a device, a cookie cannot be considered ‘inactive’. Every time a user visited Ecolog’s website, personal data was transferred to Stripe through the Stripe cookie, which contained an identifier. The EDPS reached the conclusion that a transfer of data was taking place to the US, via the use of Google and Stripe cookies, since Google Analytics is hosted in the US and the data protection notice referred to a Standard Contractual Clause (SCC) for the transfer of data outside of the EU. However, the Parliament provided no documentation, evidence or other information regarding the contractual, technical or organisational measures in place to ensure an essentially equivalent level of protection to the personal data transferred to the US in the context of the use of cookies on the website. Cookie banner on the Parliament’s dedicated website — The EDPS reminded that: before setting cookies or any other technology falling within the scope of Article 5(3) ePrivacy Directive 2002/58/EC (hereafter ePrivacy Directive), the EU institution must provide the user with adequate information on what is accessed or stored on the user’s terminal equipment, on the purposes of this action and the means for expressing their consent; no action may be performed before the consent is collected. In addition, users must be enabled to withdraw their consent at any time; ‘cookie walls’ are not in line with Regulation 2018/1725, meaning that for consent to be freely given, access to the website’s service and functionalities should not depend on the users’ consent for cookies that are not strictly necessary in the sense described above; in case personal data collected through the cookies are shared with third parties such as analytics partners, the cookie banner should draw the user's attention to it. The EDPS reached the conclusion that the cookie banners in all three languages were not in line with the definition of consent under Article 3(15) Regulation 2018/1725, nor did they meet the requirements of Article 37 Regulation 2018/1725 and Article 5(3) ePrivacy Directive. The cookie banner further failed to provide transparent information regarding the processing of personal data in relation to the cookies on the website. Request for access to personal data — The Parliament was aware that the complainants’ personal data had been processed through the cookies, which were present on the website for the period between 30 September to 4 November 2020, since transfers of personal data had taken place. Consequently, and especially following the EDPS’ inquiry on the matter, the Parliament should have replied to the complainants’ access to personal data request. The Parliament should have provided the relevant information even if it was aware that the processing of the personal data in question was unlawful, as the main purpose of the right of access under Article 15 GDPR is precisely to enable data subjects to become aware of the processing and verify the lawfulness thereof, or exercise other data subject rights. Conclusion — The EDPS concludes that the Parliament has infringed the following articles of Regulation 2018/1725: Articles 26(1) and 29(1) due to its failure to fulfil its responsibilities as controller and use a processor providing sufficient guarantees to implement appropriate technical and organisational measures; Article 29(3) due to its failure to provide documentation relating to the detailed instructions given to the processor for the setting up and functioning of the website; Articles 4(1)(a) and 14, 4(2), and 15 due to its failure to respect the principle of transparency, accountability and the data subjects’ right to information because of the inaccurate data protection notice and cookie banner on the dedicated website; Article 46 and Article 48(2)(b) of the Regulation, due to its reliance on the Standard Contractual Clauses in the absence of a demonstration that data subjects’ personal data transferred to the US were provided an essential equivalent level of protection; Article 37 read in the light of Article 5(3) of the ePrivacy Directive, due to its failure to protect information (the cookies) transmitted to, stored in, related to, processed by and collected from the users’ terminal equipment; Articles 17 and 14(4) due to its failure to reply to the data subjects’ request for access to their personal data. On the basis of the above, the EDPS decides: to issue a reprimand to the Parliament in accordance with Article 58(2)(b) Regulation 2018/1725 for the above infringements; to order the Parliament, pursuant to Article 58(2)(b) Regulation 2018/1725:, to update its data protection notices in the dedicated website in order to provide all relevant information relating to the processing of personal data. The Parliament should address this order within one month from the date of the decision.

### Italian DPA: AgID's automatic transfer of PEC addresses to INAD index unlawful

*Source: Garante per la protezione dei dati personali (Italy), 2026-05-28 — https://overview.legal/posts/122875 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_419/2026*

Facts — The data controller for the case is a government body called the Agency for Digital Italy (AgID). AgID is tasked with driving the adoption of digital technologies in both government and the private sector. Additionally, AgID is Italy’s soon-to-be notification authority for the AI Act. The case revolves around two public online indexes of certified email addresses: the INI-PEC and the INAD. INI-PEC is the older of the two indexes and includes, among others, the email addressess of professionals (the data subjects). INAD was created by AgID in 2023 as provided by Italian law and functions as an index of “digital domiciles” (where data subjects are supposed to get certain important communications) for both professionals and other owners of a digital email address. Shortly after setting up the INAD index, AgID automatically included the addresses of professionals from the old INI-PEC index. As a result, the addresses automatically became the digital domicile for communications not related to the professional lives of the data subjects. Data subjects were given the option to opt-out of the inclusion in the INAD index. Some data subjects complained that this processing severely infringed on their privacy. As the DPA’s decision explains, it is not uncommon for professionals to give co-workers access to their professional email addresses, on the assumption that they will only be used for strictly professional communications. When the addressess became digital domiciles, third parties (such as public bodies) started using them for communications unrelated to the data subjects' personal lives - which occasionally led to unintended data disclosures. The data subjects also claimed that the controller had not informed them about the processing, which prevented them from opting out in a timely fashion. Holding — The investigation — On the duty of information — First of all, the DPA clarified that by including email addresses in the INAD index, the controller further processed personal data for a new purpose, incompatible with the original purpose of the processing (i.e.: the inclusion of email addresses in the older index). With regards to the duty of information, the controller pointed out that it contacted professional orders to inform them about the creation of the INAD index. In the context of these communications, the controller asked professional orders to inform the data subjects about this processing of personal data and about their right to opt out. The controller stated that it did not directly contact the data subjects via their email addresses, as it feared that its emails would have been mistaken as phishing or scams . The controller later launched a more effective information campaign with the help of other government bodies; however, this campaign only took place in 2025 - two years after addresses where included in the INAD index. On the controller’s identity — The DPA’s investigation also focused on a second issue, relative to the authentication procedure for digital domiciles: for a long time, a company (InfoCamere S.c.p.a.) was erroneously listed as a service provider for the INAD index. During the investigation, the controller confirmed that InfoCamere had no role in the processing of personal data. The controller also stated that it had contacted the actual service provider in order to correct the error and that the provider had done so with great delay. The DPA's conclusion — The DPA held that until 2025, the controller had failed to inform the data subjects about the inclusion of their email address in the INAD index, in violation of Articles 5(1)(a), 5(1)(b), 5(2), 12, 14 and 25 GDPR. On these grounds, the DPA fined the controller €55,000. With regards to the erroneous indication of the service provider in the authentication screen, the DPA found that the mistake was isolated and that overall, the information provided during the procedure was still sufficient to clarify that AgID was the controller. On these grounds, the DPA found that the mistake did not, in and of itself, constitute a violation of the GDPR.

## Recent developments

### DPC (Ireland) - IN-19-9-4

*Source: GDPRhub, 2026-08-18 — https://overview.legal/posts/291263 — original: https://gdprhub.eu/index.php?title=DPC_(Ireland)_-_IN-19-9-4*

The DPA fined the HSE €300,000 for inadequate security measures which enabled a ransomware attack affecting health data of 84,000 people, alongside violations of Articles 28, 30 and 34 GDPR.The DPA fined the HSE €300,000 for inadequate security measures which enabled a ransomware attack affecting health data of 84,000 people, alongside violations of Articles 28, 30 and 34 GDPR. English Summary. English Summary On 8 October 2019, the DPA initiated an own-volition inquiry to determine whether the

### UODO (Poland) - DKE.561.1.2026

*Source: GDPRhub, 2026-08-18 — https://overview.legal/posts/291290 — original: https://gdprhub.eu/index.php?title=UODO_(Poland)_-_DKE.561.1.2026*

The DPA reprimanded a company for refusing to cooperate with the supervisory authority: the controller had failed to provide information on the processing of personal data in two pending cases against it. English Summary. Facts. The DPA received two complaints against the same company (the controller) due to the unauthorised access to the data subjects’ personal data. The first complaint concerned processing that had taken place in January 2025, while the events giving rise to the second complai

### EDPB sheds light on anonymisation and web scraping for generative AI and adopts final version of guidelines on blockchain

*Source: European Data Protection Board, 2026-07-08 — https://overview.legal/posts/53905 — original: https://www.edpb.europa.eu/news/edpb-sheds-light-on-anonymisation-and-web-scraping-for-generative-ai-and-adopts-final-version_en*

Brussels, 8 July– During its latest plenary, the EDPB has adopted guidelines on anonymisation and guidelines on web scraping in the context of generative AI. In addition, the Board has adopted the final version of its guidelines on the processing of personal data through blockchain technologies.Understanding anonymous dataThe new EDPB guidelines bring clarity to the notion of anonymous data, taking also into account the ruling of the Court of Justice of the EU in the case C-413/23 P EDPS v SRB o

### Coordinated Supervision Committee extends scope to include Eurodac

*Source: European Data Protection Board, 2026-06-12 — https://overview.legal/posts/53058 — original: https://www.edpb.europa.eu/news/coordinated-supervision-committee-extends-scope-to-include-eurodac_en*

Brussels, 12 June – As of today, coordinated supervision of the European Union’s asylum and migration database (Eurodac) will be carried out by the Coordinated Supervision Committee (CSC). Eurodac is an information system initially designed to compare the fingerprints of asylum applicants and irregular migrants, which has evolved into a full asylum and migration management system. It plays a key role in implementing the Dublin III Regulation, which aims at determining the Member State responsibl

### EU-Hof: een belastingautoriteit die bij een marktaanbieder van  internetdiensten gegevens opvraagt moet de AVG in acht nemen

*Source: NL EU Court Expert, 2022-03-02 — https://overview.legal/posts/6309 — original: https://ecer.minbuza.nl/-/eu-hof-een-belastingautoriteit-die-bij-een-marktaanbieder-van-internetdiensten-gegevens-opvraagt-moet-de-avg-in-acht-nemen?redirect=%2Fecer%2Fnieuws%3Fq%3Dprivacy%2520OR%2520avg%26f%3D%26t%3D#entry-308*

The collection by the tax authority of a Member State of personal data concerning the advertisements for the sale of vehicles placed on the website of an economic operator falls within the material scope of the General Data Protection Regulation (AVG). Thus, that authority will also have to comply with the principles on the processing of personal data laid down in the AVG. However, a tax authority can derogate from the AVG in certain cases, even if the right to derogate is not granted by nationa

## Literature

### Data Controller, Processor or a Joint Controller: Towards Reaching GDPR Compliance in the Data and Technology Driven World

*Source: SSRN Electronic Journal, 2020-01-01 — https://overview.legal/posts/132509 — original: https://doi.org/10.2139/ssrn.3584207*

### Grounds for Lawful Processing of Personal Data in GDPR and Personal Data Protection Bill 2018, India (PDPB): Section – III: Legal Obligation.

*Source: SSRN Electronic Journal, 2019-01-01 — https://overview.legal/posts/132468 — original: https://doi.org/10.2139/ssrn.3720422*

### Grounds for Lawful Processing of Personal Data in GDPR and Personal Data Protection Bill 2018, India (PDPB): Section – IV: Vital Interests.

*Source: SSRN Electronic Journal, 2019-01-01 — https://overview.legal/posts/132471 — original: https://doi.org/10.2139/ssrn.3743565*

### Grounds for Lawful Processing of Personal Data in GDPR and Personal Data Protection Bill 2018, India (PDPB): Section – V: Public Interests amp; Exercise of Official Authority.

*Source: SSRN Electronic Journal, 2019-01-01 — https://overview.legal/posts/132516 — original: https://doi.org/10.2139/ssrn.3743566*

### Civil Liability for Processing of Personal Data in the GDPR

*Source: European Data Protection Law Review, 2019-01-01 — https://overview.legal/posts/132465 — original: https://doi.org/10.21552/edpl/2019/4/7*

## Tools

### CNIL record of processing activities template

*Source: CNIL, 2026-07-17 — https://overview.legal/posts/125621 — original: https://www.cnil.fr/en/record-processing-activities*

The French DPA's explanation of the Article 30 record-keeping obligation with a simplified downloadable register template aimed at SMEs: one sheet per processing activity covering purposes, data categories, recipients, transfers, retention and security measures.

### ICO documentation templates (records of processing, Article 30)

*Source: ICO, 2026-07-17 — https://overview.legal/posts/125620 — original: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/documentation/*

Guidance plus downloadable controller and processor documentation templates for the Article 30 record of processing activities: what must be recorded, who is exempt, and spreadsheet templates organisations can adopt directly.

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Data Controller** — https://overview.legal/topics/verwerkingsverantwoordelijke
  The entity that determines purposes and means of processing personal data
- **Processing Agreement** — https://overview.legal/topics/verwerkersovereenkomst
  Contract between controller and processor defining processing terms
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities

---
Generated by overview.legal · https://overview.legal/topics/verwerking · 2026-08-22
