GDPR case law
Rulings that shape the GDPR in practice
The Court of Justice interprets the GDPR; national courts review fines. Per ruling: the key question, the holding, what changes in practice and the articles concerned. Only rulings read on curia.europa.eu or rechtspraak.nl.
Reference date of this layer: 15 September 2026. Every item was checked against its source; the date per item is shown. Anything after the reference date is not yet here.
- finalRaad van State, Afdeling bestuursrechtspraakECLI:NL:RVS:2026:4403, zaaknummer 202401622/1/A3€600,000
Council of State: 600,000 euro fine for wifi tracking in Enschede stays annulled
From 25 May 2018 to 30 April 2020 the municipality of Enschede counted city centre visitors with at least ten sensors capturing (pseudonymised) phone MAC addresses. On 11 March 2021 the DPA fined it 600,000 euros for processing personal data without a legal basis. On 2 February 2024 the Overijssel District Court annulled the fine because the DPA had not proven the data were personal data. On appeal the DPA conceded that the three identification routes in its decision did not meet the standard of proof. Its new position, that people were directly identified by counting unique visitors, had not been taken in the decision. The Council of State disregards it: the decisive evidence must be provided at the decision stage. The DPA's appeal is unfounded.
What this means: The DPA must fully prove at the decision stage that personal data and a breach are involved; evidence or new reasoning first raised in court does not count. This is no licence for wifi tracking: the court did not say MAC addresses are not personal data and did not assess on the merits the position on direct identification through unique counts. Anyone deploying sensors must still justify necessity, legal basis and anonymisation.
- finalHof van Justitie van de EU (Vijfde kamer), ND tegen Legal Newsdesk Sweden AB (voorheen Garrapatica AB)C-199/24, ECLI:EU:C:2026:564
Legal Newsdesk Sweden: paid online publication of criminal convictions is in principle not journalism, national exemptions may not switch off the GDPR
Question: may a Member State, under the freedom of expression exemption (Article 85), place a paid searchable database of criminal convictions (Lexbase, holding a Swedish constitutional publishing certificate) outside the GDPR so that the convicted person is left only with criminal defamation proceedings or an action for compensation? Ruling: no. Member States may not, on the basis of Article 85(1), introduce derogations going beyond Article 85(2) for processing that has no journalistic, academic, artistic or literary purpose, and they may not limit the data subject's remedies to those two options. Processing is journalistic only if it aims at disclosure to the public of information, opinions or ideas, in compliance with the ethical rules of the journalistic profession, after editing or at least in accordance with an editorial policy, and after verification of the facts.
What this means: Providers of data about people, such as screening, background checks, registers or case law databases, cannot simply invoke the press exemption; without a genuine editorial process all GDPR rules apply, including the right to erasure and compensation. Check whether your retention and deletion policy for criminal data (Article 10) holds up. In the Netherlands too, the application of the journalistic exemption in the national implementing act must be measured against this standard.
- finalHof van Justitie van de EU (Vierde kamer), Brillen Rottler GmbH & Co. KG tegen TCC-526/24, ECLI:EU:C:2026:216
Brillen Rottler: even a first access request can be abusive if made solely to claim compensation
Question: may a controller refuse a first access request as excessive where the requester evidently makes it only to claim compensation afterwards, and does the requester have a right to compensation when access is refused? Ruling: a first request can be excessive and thus abusive where the controller shows it was made not to know and verify the processing but to artificially create a claim; a publicly known pattern of many requests followed by claims may be taken into account. Breach of the right of access does give a right to compensation for damage actually suffered, even without any processing and including loss of control or uncertainty, but not where the data subject's own conduct is the determining cause.
What this means: You may not refuse an access request lightly, but you now have a concrete defence against claim farmers, provided you substantiate the abuse with facts. Record in your access procedure how you assess and document indications of abuse, and keep handling ordinary requests within one month. Remain careful: an unjustified refusal remains an infringement that can lead to compensation.
- status not establishedRechtbank Den Haag, voorzieningenrechterECLI:NL:RBDHA:2026:4248; C/09/697042 / KG ZA 26/2
Reddit's summary proceedings against the DPA over a penalty order and legal privilege dismissed
Since March 2025 the DPA, as lead authority, has investigated whether Reddit lawfully makes users' public content available through its API to AI model developers. Because Reddit refused access to internal systems (Jira, Google Vault, SWAT Tables), on 26 January 2026 the DPA imposed an order subject to a penalty for breach of the duty to cooperate (Articles 31 and 58(1) GDPR with Articles 5:16, 5:17 and 5:20 of the General Administrative Law Act). Reddit sought, among other things, safeguards for legal privilege in summary proceedings. The court refused the relief because objections to the order and to the DPA's handling of privileged material can be reviewed by the administrative court. Reddit bears the costs.
What this means: The DPA can demand access to your internal systems during an investigation and enforce it with an order subject to a penalty. If you dispute such an order and the DPA's handling of privileged material, the route is in principle objection and appeal before the administrative court; civil summary proceedings offer no way around that. Before an investigation starts, record which documents are privileged and how you flag them.
- finalHof van Justitie van de EU (Grote kamer), WhatsApp Ireland Ltd tegen Europees Comité voor gegevensbescherming (EDPB)C-97/23 P, ECLI:EU:C:2026:81
WhatsApp v EDPB: a binding EDPB dispute resolution decision can be challenged directly before the EU courts
Question: can a company directly challenge before the General Court a binding EDPB decision (Article 65) that settled a dispute between supervisory authorities and required the Irish authority to increase the fine (ultimately EUR 225 million)? Ruling: yes. Such a decision emanates from an EU body, is intended to produce legal effects for third parties and is of direct concern to WhatsApp. The General Court's order declaring the action inadmissible is set aside and the case referred back for a decision on the merits.
What this means: For organisations under the one-stop-shop mechanism there is an extra route: besides appealing the national final decision you can challenge the binding EDPB decision itself before the General Court. Watch the two month time limit after notification or publication of such a decision. This makes the EDPB's role in cross-border enforcement subject to judicial review and may affect the outcome of pending fine cases.
- finalHof van Justitie van de EU (Grote kamer), X tegen Russmedia Digital SRL en Inform Media Press SRLC-492/23, ECLI:EU:C:2025:935
Russmedia: an online marketplace operator is controller for personal data in adverts and must check before publication
Question: is the operator of a classified ads site the controller for personal data in adverts placed by users, and can it rely on the intermediary liability exemptions of the e-Commerce Directive? Ruling: the operator is controller and must, before publication and through technical and organisational measures, identify adverts containing special category data, verify that the advertiser is the data subject and otherwise refuse publication, unless explicit consent or another Article 9(2) exception is demonstrated. It must also take security measures against copying of such adverts to other sites. The e-Commerce Directive exemptions do not apply to these GDPR obligations.
What this means: Platforms, marketplaces and forums where users can post content with other people's personal data must build in a pre-publication check for sensitive content, with identity verification of the poster and a refusal mechanism. Technical measures against scraping and republication are also part of the security duty. The defence that you are merely a neutral conduit does not work under the GDPR.
- finalRaad van State, Afdeling bestuursrechtspraakECLI:NL:RVS:2025:4562 (zaaknummer 202305954/1/A3; eerste aanleg ECLI:NL:RBAMS:2023:5074)€262,500
Council of State: DPA could fine DPG Media for routinely demanding ID copies, fine halved to 262,500 euros
DPG Media routinely required a copy of an ID document up front from subscribers requesting access or erasure outside its online login environment, without first checking whether a less intrusive method, such as a customer number or email verification, would do. The DPA imposed a 525,000 euro fine in January 2022. In 2023 the Amsterdam District Court found a breach of Article 12(2) GDPR but annulled the fine entirely. The Council of State held that the DPA was entitled to fine, because this was structural policy at a large media company rather than an incident. However, the DPA failed to address the mitigation grounds raised, breaching the duty to give reasons. The Council itself reduced the fine by 50 percent to 262,500 euros, citing among other things the relatively small number of cases, the destruction of copies within a month and the policy change well before the enforcement notice.
What this means: Ask for an ID copy only where you reasonably doubt identity and a lighter method (customer number, email verification, other known data) will not do; a blanket rule of always demanding a copy up front breaches Article 12(2) and the data minimisation principle. State in the request itself that a masked copy is enough and destroy copies quickly. If you raise mitigation grounds, the DPA must address them with reasons; if it does not, the court can reduce the fine itself.
- finalHof van Justitie van de EU (Eerste kamer), Europese Toezichthouder voor gegevensbescherming (EDPS) tegen Gemeenschappelijke Afwikkelingsraad (SRB)C-413/23 P, ECLI:EU:C:2025:645
EDPS v SRB: pseudonymised data are not always personal data for everyone, but the information duty applies from collection
Question: were the pseudonymised shareholder comments the SRB passed to Deloitte personal data, and from whose perspective must identifiability be assessed? Ruling: the General Court wrongly required the EDPS to examine the content, purpose or effect of opinions; a personal opinion is by nature closely linked to its author. Pseudonymised data may be non-personal for a recipient without the key, but only where the technical and organisational measures actually prevent that recipient from identifying data subjects; if the recipient has reasonable means to identify them, for example by cross-checking with other data, they remain personal data. The controller's duty to inform about recipients is assessed at the time of collection and from the controller's own perspective, regardless of whether the data remain personal data for the recipient after pseudonymisation. The General Court's judgment is set aside and Case T-557/20 is referred back to the General Court.
What this means: Pseudonymisation can genuinely change the position of a recipient such as a research firm or analytics vendor, but it does not relieve you as controller of the information duty: you must inform data subjects at collection about transfers to such recipients. Assess per recipient whether re-identification by reasonable means is possible and record it. This judgment interprets Regulation 2018/1725 for EU institutions, but the definitions and the information duty mirror the GDPR (Article 4 and Article 13(1)(e)).
- status not establishedRechtbank GelderlandECLI:NL:RBGEL:2025:6547 (zaaknummer ARN 22/4633)€58,125
Gelderland District Court: bankruptcy trustee is controller, DPA fine for unsecured hard drive cut to 58,125 euros
At the auction of a bankrupt healthcare foundation's estate, the trustee sold a server whose hard drive held large amounts of (special category) personal data on clients and staff, including citizen service numbers, salary and medical data. On 9 December 2021 the DPA fined the trustee 310,000 euros for breaching Article 5(1)(f) with Article 32(1) and (2) GDPR, and on objection reduced the fine to 148,750 euros on 25 August 2022. The court held that the trustee in that capacity is the controller because he could reasonably access the data, and that the fine was justified. It reduced the fine to 58,125 euros for reduced culpability and excessive length of proceedings.
What this means: Whoever gains actual control over data carriers, such as a bankruptcy trustee, becomes the controller and must arrange security, including when selling hardware. Inventory all data carriers and wipe or destroy them verifiably before equipment leaves. Instructing an auction house to remove drives is not enough without checking. Fines for security failures are reduced for lower culpability, not removed.
- finalHof van Justitie van de EU (Eerste kamer), CK tegen Magistrat der Stadt Wien, met Dun & Bradstreet Austria GmbH als andere partijC-203/22, ECLI:EU:C:2025:117
Dun & Bradstreet: right to an intelligible explanation of an automated decision, trade secrets are no absolute ground for refusal
Question: what does the right to meaningful information about the logic of automated decision-making involve, and may a controller refuse it by invoking trade secrets? Ruling: the controller must describe, concisely, transparently and intelligibly, the procedure and principles actually applied so the data subject understands which data were used and how. Merely handing over an algorithm is insufficient; explaining how a different input would have changed the result may be appropriate. Where trade secrets or third party data are involved, the controller must provide the information to the authority or court, which balances the interests. A national rule excluding access as a rule where trade secrets are at stake is not permitted.
What this means: If you use automated decisions or scores, you must be able to give a plain language explanation per decision: which data, which rules and what weight. Build this in when choosing models and vendors, because a model you cannot explain produces a request you cannot answer. Trade secrecy is no free pass; prepare to share the sensitive details with the authority or court.
- finalHof van Justitie van de EU (Eerste kamer), Mousse tegen Commission nationale de l'informatique et des libertés (CNIL) en SNCF ConnectC-394/23, ECLI:EU:C:2025:2
Mousse: asking for Mr or Ms when selling a train ticket is not necessary
Question: may a transport company require customers to state their title (Mr or Ms) to personalise commercial communication, and is that compatible with data minimisation? Ruling: that processing is not objectively indispensable for performance of the transport contract. It can rest on legitimate interest only if customers were informed of that interest at collection, the processing is strictly necessary and customers' rights, including the risk of discrimination on gender identity, do not override it. The existence of a right to object does not count in assessing necessity.
What this means: Review every mandatory field in your forms: only what is genuinely needed for the service may be mandatory. Title, gender or date of birth for personalised salutation usually are not; make them optional or drop them. If you want to process such data on legitimate interest, that interest must already appear in your privacy information at collection and you must be able to explain why it is strictly necessary.
- status not establishedRechtbank Noord-NederlandECLI:NL:RBNNE:2025:83 (zaaknummer LEE 22/3460)€375
Noord-Nederland District Court upholds DPA fine for village livestream, reduces it to 375 euros
The court held that the DPA rightly found the livestream processed personal data without a legal basis. Only interests actually pursued and known to data subjects at the time of processing count in the legitimate interest test; interests raised later do not. The processing was not necessary and residents' interests prevailed. Because proceedings took four years and five months, the fine was cut from 500 to 375 euros. The penalty order stands.
What this means: Record and communicate your legitimate interest before you start processing; interests first raised in court do not count. For cameras in public space you must show with concrete data that the purpose cannot be achieved by less intrusive means. Excessively long proceedings reduce the fine, they do not erase the infringement.
- status not establishedRechtbank Den HaagECLI:NL:RBDHA:2024:16324; zaaknummer SGR 23/8425€30,000
The Hague District Court cuts DPA fine on police for mobile camera cars without completed DPIA to 30,000 euros
At the start of the pandemic mobile camera cars were deployed in Rotterdam while the police had not yet completed the data protection impact assessment (DPIA). The DPA fined the police 50,000 euros under the Police Data Act. The court finds that police data were processed on 20 and 29 May 2020, but only 20 May is a breach, because the DPIA was completed after 26 May. The court considers the breach serious and culpable and rejects force majeure. Because the breach lasted only one day and repetition is very unlikely, the court sets the fine at 30,000 euros.
What this means: A deployment framework or preliminary DPIA does not replace a full impact assessment with risk analysis and measures; it must be finished before the camera is switched on. Processing starts only when the camera is actually on, which determines the duration of the breach and thus the fine. Acting fast in a crisis can lower the fine but does not justify the breach. For the DPIA duty under the Police Data Act the court follows the interpretation of GDPR article 35 and the EDPB guidelines.
- finalHof van Justitie van de EU (Vierde kamer), Maximilian Schrems tegen Meta Platforms Ireland LimitedC-446/21, ECLI:EU:C:2024:834
Schrems v Meta: no unlimited retention and aggregation of data for targeted advertising
Question: may a social network use all data it collects about a user, on and off the platform, without time limit and without distinction by type, for personalised advertising, and may it use sexual orientation data after the person spoke publicly about it? Ruling: the data minimisation principle precludes aggregating, analysing and processing data for targeted advertising without restriction as to time and without distinction as to type. A public statement about one's own orientation does not allow the platform to process other data about that orientation, collected via third parties, for advertising.
What this means: For profiling and advertising you must set retention periods and decide per data type whether use is needed; a data lake where everything is kept and combined forever is not permitted. Special category data that a person made public somewhere may not for that reason be compiled from other sources. Reflect this in your retention policy and in the configuration of marketing and analytics tools. This judgment is from 2024 and therefore also counts among the recent rulings.
- finalHof van Justitie van de EU (Grote kamer), ND tegen DR (twee Duitse apothekers)C-21/23, ECLI:EU:C:2024:846
Lindenapotheke: competitors may sue over GDPR breaches and pharmacy order data are health data
Question: may national law allow a competitor to challenge a GDPR infringement before the civil courts as an unfair commercial practice? And are the data customers enter when ordering non-prescription pharmacy-only products online health data? Ruling: the remedies provisions in Chapter VIII of the GDPR do not preclude such actions by competitors. These actions exist alongside supervisory powers and data subject remedies. Name, delivery address and product details entered when ordering pharmacy-only medicines online are health data under Article 9(1). This holds even without a prescription and even if it is not certain the customer is the person who will use the product. Processing is then only allowed under an Article 9(2) exception, such as explicit consent given after accurate, comprehensive and easily understandable information. The Court's press release summarises this as a requirement of explicit consent.
What this means: GDPR compliance also becomes a competition risk: a competitor can take you to court and seek an injunction, independently of the authority. Web shops and platforms selling products from which someone's health can be inferred must treat that ordering process as processing of special category data. That requires a valid Article 9(2) exception, in practice usually explicit prior consent with clear information. Check your product categories for similar sensitive information that can be inferred from orders.
- finalHof van Justitie van de Europese UnieC-621/22, ECLI:EU:C:2024:858
EU Court of Justice in KNLTB: a purely commercial interest can be a legitimate interest
On questions from the Amsterdam District Court in the KNLTB fine case (disclosure of members' data to sponsors for payment), the Court held that a controller's commercial interest can be a legitimate interest under Article 6(1)(f) GDPR, provided it is not contrary to law. The interest need not be laid down in law but must be lawful. The processing must also be strictly necessary and the data subjects' interests and fundamental rights must not override it in light of all circumstances. The Court thereby rejected the Dutch DPA's view that a legitimate interest must be enshrined in law.
What this means: You cannot simply rely on legitimate interest for marketing or data sales, but it is not excluded up front either. Document the three step test: which interest, why strictly necessary, and why data subjects' interests do not override it. Without that record and clear information to data subjects the basis will not hold.
- finalHof van Justitie van de EU (Eerste kamer), TR tegen Land HessenC-768/21, ECLI:EU:C:2024:785
Land Hessen: the supervisory authority need not always fine where the organisation already remedied the breach
Question: must a supervisory authority, after an established breach (a bank employee looked at customer data without reason), always take corrective action and impose a fine when a data subject asks for it? Ruling: no. The authority need not adopt a corrective measure or a fine where that is not appropriate, necessary or proportionate to remedy the shortcoming and ensure full compliance, for instance because the controller immediately took measures to prevent recurrence. Its discretion is limited by the need for a high and consistent level of protection.
What this means: Fast and demonstrable self-correction after an incident pays off: it can prevent a fine. Have an incident procedure in which you remove the cause, prevent recurrence, document disciplinary or technical measures and substantiate the notification to the authority. Data subjects have no right to have the offender fined; they can have the authority's decision reviewed.
- status not establishedRechtbank Den Haag, voorzieningenrechter (kort geding, team handel)ECLI:NL:RBDHA:2024:17249; C/09/663620 / KG ZA 24-273
Interim relief judge: DPA must redact fine amount when giving an enforcement decision to complainants
On 6 December 2023 the Dutch DPA imposed two administrative fines and two orders subject to penalty payments on an anonymised provider of a financial service, for breaching Article 5(1)(a) with Article 6(1) GDPR and Article 12(1) with Article 14(1) and (2) GDPR. The DPA intended to send the full decision, including the fine amount, to the two complainants. The civil interim relief judge accepted that the complainants are interested parties, but ordered the DPA to redact the fine amount and the parts on its calculation and prohibited the DPA from informing the complainants of them. The fine is substantial, disclosure before judicial review could cause serious reputational harm, and the complainants have no concrete interest in the exact amount. A general ban on disclosure to third parties was refused.
What this means: Complainants are entitled to know that and how the DPA enforces, but not automatically to the exact fine amount and its calculation while the decision has not yet been reviewed by a court. If you are fined after complaints, you can ask the DPA to redact the amount and calculation in the copy for complainants, and if needed start interim relief proceedings. An objection against the announced sending does not work, because that is a factual act (ECLI:NL:RBDHA:2024:3754). This route does not give a general ban on publishing the fine; that runs through the separate view on publication.
- finalRaad van State, Afdeling bestuursrechtspraakECLI:NL:RVS:2024:2221, zaaknr. 202401169/1/A3 (bevestigt ECLI:NL:RBAMS:2024:1214)€6,000
Council of State upholds 6,000 euro DPA fine for recruitment firm
The Division tested the fine against the EU law principle of proportionality, also in light of Article 83(1) GDPR, and found 6,000 euros not disproportionate. The DPA had already cut the base fine of 310,000 euros sharply. The company did not actually follow the instructions in its own GDPR handbook and ignored repeated erasure requests from data subjects (Article 17(1) read with Article 12(3) GDPR). The fact that the DPA's fines vary widely in practice does not make this one disproportionate. The Amsterdam District Court ruling of 15 January 2024 is upheld.
What this means: The highest administrative court accepts that the DPA may depart substantially downwards from its fining policy where circumstances require, without the fine becoming arbitrary. Pointing at other cases helps little; the court looks at your own culpability. Make sure your GDPR handbook is actually followed, since its mere existence is no defence.
- finalRechtbank Midden-Nederland, voorzieningenrechter (zittingsplaats Utrecht)ECLI:NL:RBMNE:2024:1804; zaaknummer UTR 24/885
Interim judge suspends DPA penalty order against Northwave: exhaust powers against the hosting provider first
A large hosting provider reported a data breach in August 2023 and hired Northwave to investigate. The DPA demanded the investigation report from the provider, which in the DPA's view did not fully comply. The DPA then demanded the information from Northwave itself and imposed a penalty order in February 2024. The interim judge held that under Article 58(1)(a) GDPR the DPA must first address the party the obligation applies to, here the hosting provider. The DPA had not exhausted its powers against the provider and never imposed the penalty order it had threatened. Demanding information from a third party outside the DPA's supervision was therefore not reasonably necessary (Article 5:13 of the Dutch General Administrative Law Act, subsidiarity). The order was suspended until two weeks after the decision on the objection; the DPA must reimburse court fees and legal costs.
What this means: The DPA must first seek information from the controller or processor itself and exhaust its powers there before using enforcement tools against a supplier or adviser. Incident response and forensic firms can challenge an information demand if the DPA has not yet used its powers against the supervised organisation. This is a provisional view, and the controller itself must still hand over investigation reports when demanded. Agree contractually who reports to the DPA and how investigation reports are handled.
- finalHof van Justitie van de EU (Vierde kamer), IAB Europe tegen Gegevensbeschermingsautoriteit (België)C-604/22, ECLI:EU:C:2024:214
IAB Europe: the TC String is personal data and the industry body is a joint controller
Question: is the encoded consent string (TC String) from the Transparency and Consent Framework for online ad auctions personal data, and is IAB Europe as author of that framework a (joint) controller? Ruling: the TC String is personal data once it can, by reasonable means, be linked to an identifier such as an IP address, even if IAB Europe itself cannot access that link. IAB Europe is a joint controller for recording and disseminating the preferences because the framework co-determines purposes and means; that responsibility does not automatically extend to later processing by websites and advertisers.
What this means: Anyone who sets up a standard, protocol or platform for data exchange and sets its rules can be a joint controller without seeing the data itself. That requires an Article 26 arrangement with participants and your own accountability. For websites and advertisers using the TCF, consent signals themselves are personal data and thus subject to all GDPR principles, including security and transparency.
- finalRechtbank OverijsselECLI:NL:RBOVE:2024:594 (zaaknummer ZWO 22/775)€600,000
Overijssel District Court revokes DPA fine for wifi tracking in Enschede
The court upheld the municipality of Enschede's appeal, annulled the objection decision of 6 April 2022 and revoked the fine decision of 11 March 2021 (a fine of 600,000 euros for processing without a legal basis, Article 5(1)(a) read with Article 6(1) GDPR). The DPA had not sufficiently investigated or proven that natural persons were identifiable through hashed and truncated MAC addresses combined with location data, as recital 26 GDPR requires. The Council of State confirmed this ruling on 29 July 2026 (ECLI:NL:RVS:2026:4403).
What this means: Whether pseudonymised or hashed identifiers are personal data depends on concrete evidence of identifiability in your setting, assessed against the means reasonably likely to be used under recital 26 GDPR; for a fine, the regulator must deliver that evidence in the decision itself. Record yourself which steps you take to rule out identification. The Council of State left open whether counting unique visitors via MAC addresses is in itself direct identification, so counting with MAC addresses remains risky.
- finalHof van Justitie van de EU (Eerste kamer), OQ tegen Land Hessen, met SCHUFA Holding AG als interveniëntC-634/21, ECLI:EU:C:2023:957
SCHUFA: a credit score on which third parties draw strongly is automated decision-making
Question: is the automated calculation of a credit score by a credit reference agency already an automated individual decision under Article 22, even though a bank or shop takes the actual decision? Ruling: yes, where the third party receiving the score draws strongly on it to establish, implement or terminate a contract. The score is then itself the decision with legal or similarly significant effects, and the prohibition in Article 22(1) applies unless an exception in Article 22(2) is met.
What this means: If you supply scores, risk indicators or rankings that customers adopt almost automatically, you yourself must meet the requirements of Article 22: a valid exception (law, contract or explicit consent), suitable safeguards, human intervention and information on the logic used. Recipients of such scores must check whether their decision process in fact relies on the score and adjust their information and objection processes accordingly. This also affects AI models that compute risk scores about people.
- finalHof van Justitie van de EU (Grote kamer), Deutsche Wohnen SE tegen Staatsanwaltschaft BerlinC-807/21, ECLI:EU:C:2023:950
Deutsche Wohnen: a fine on a legal person needs no identified natural person, but does require fault
Question: may a Member State allow a GDPR fine on a company only where the infringement has first been attributed to a specific manager or employee, and is a fine possible without intent or negligence? Ruling: national rules making a fine on a legal person conditional on attribution to an identified natural person are contrary to Article 58(2)(i) and Article 83 GDPR. A fine may however be imposed only where it is established that the controller committed the infringement intentionally or negligently. That is the case where the controller could not be unaware of the infringing nature of its conduct, whether or not it was aware that it was infringing the GDPR. For the maximum fine the total worldwide annual turnover of the undertaking in the competition law sense (Articles 101 and 102 TFEU) counts.
What this means: Your organisation can be fined directly as a legal person; the defence that no employee is personally responsible does not work. The authority must however establish intent or negligence, but ignorance of the GDPR is no defence where you could not have been unaware that your conduct was infringing. A well documented compliance programme and demonstrable diligence strengthen your position. For corporate groups the maximum fine is set by reference to the turnover of the whole economic unit, not just that of the subsidiary that made the error.
- finalHof van Justitie van de EU (Grote kamer), Meta Platforms Inc., Meta Platforms Ireland Ltd en Facebook Deutschland GmbH tegen BundeskartellamtC-252/21, ECLI:EU:C:2023:537
Meta v Bundeskartellamt: competition authority may find a GDPR breach, strict conditions for legal bases behind personalised advertising
Question: may the German competition authority, when examining an abuse of a dominant position, assess whether Facebook complies with the GDPR, and on what legal basis may Meta link data from other group services and from third-party websites and apps to the Facebook account? Ruling: a competition authority may find a GDPR infringement where that is necessary to establish an abuse. It must cooperate sincerely with the data protection authorities and cannot depart from their earlier decision on the same or similar terms. Collecting and linking visit data from websites and apps touching special categories is processing of special category data where it allows such information to be revealed. Merely visiting such a site is not manifestly making the data public. Reliance on the contract (Article 6(1)(b)) is possible only where the processing is objectively indispensable to the main subject matter of the contract. Reliance on legitimate interest (Article 6(1)(f)) requires that the user was informed of that interest, that the processing is strictly necessary and that a balancing of interests favours the controller. For personalised advertising without consent, the Court held that the user's interests prevail. Legal obligation, vital interests and public interest are also of limited use. Dominance does not as such rule out valid consent, but it is an important factor in assessing whether consent was freely given.
What this means: If you combine data from several services or third parties for profiling or advertising, you can rely on the contract only where the processing is genuinely indispensable to the service you provide. For personalised advertising based on such combined data, legitimate interest without consent is in practice not tenable. If you rely on legitimate interest, name that interest to the user in advance, limit processing to what is strictly necessary and document the balancing test. Processing that can reveal sensitive information falls under Article 9, even where that information is inferred from browsing behaviour. If you hold a strong market position, you must be able to show that consent was freely given. Expect that competition authorities can also review your GDPR compliance.
- finalHof van Justitie van de EU (Derde kamer), UI tegen Österreichische Post AGC-300/21, ECLI:EU:C:2023:370
Österreichische Post: no compensation without damage, but no seriousness threshold for non-material damage
Question: does every GDPR infringement give a right to compensation, and may national law require non-material damage to reach a certain seriousness? Ruling: a mere infringement is not enough; there must be damage caused by the infringement. National law may not, however, require non-material damage to reach a seriousness threshold. The amount of compensation is set by national rules, provided equivalence and effectiveness are respected.
What this means: Expect claims for non-material damage after data breaches and other infringements, including for relatively minor effects such as anxiety or loss of control; the argument that the harm is simply too minor to count does not work on its own. The claimant must still prove actual damage and a causal link. Therefore document incidents and your response carefully so you can contest damage and causation where that is justified.
- finalHof van Justitie van de EU (Grote kamer), Data Protection Commissioner tegen Facebook Ireland Ltd en Maximillian SchremsC-311/18, ECLI:EU:C:2020:559
Schrems II: Privacy Shield invalid, transfers under standard clauses only with essentially equivalent protection
Question: may personal data be transferred to the United States under the Privacy Shield or under standard contractual clauses while US intelligence services have broad access? Ruling: the Privacy Shield decision (2016/1250) is invalid. The standard contractual clauses (Decision 2010/87) remain valid. However, the controller or processor in the EU must verify case by case, where appropriate together with the recipient, whether the law of the third country provides a level of protection essentially equivalent to that in the EU. If not, it must add supplementary measures or suspend or end the transfer. Where there is no valid adequacy decision and the controller or processor has not stopped the transfer itself, the supervisory authority must suspend or prohibit the transfer if that protection cannot be ensured by other means.
What this means: For every transfer outside the EU under standard contractual clauses you must carry out and document an assessment of the law of the receiving country (transfer impact assessment). Where that law goes too far, you must add supplementary measures such as encryption with keys kept away from the recipient, or stop the transfer. For the US, the EU-US Data Privacy Framework (Implementing Decision 2023/1795) has served as the successor for certified organisations since July 2023, but the test from this judgment remains the standard for all other countries and for vendors not covered by that framework.