Ruling
Lindenapotheke: competitors may sue over GDPR breaches and pharmacy order data are health data
- Date
- Status
- final
- Body
- Hof van Justitie van de EU (Grote kamer), ND tegen DR (twee Duitse apothekers)
- Reference
- C-21/23, ECLI:EU:C:2024:846
What it is about
Question: may national law allow a competitor to challenge a GDPR infringement before the civil courts as an unfair commercial practice? And are the data customers enter when ordering non-prescription pharmacy-only products online health data? Ruling: the remedies provisions in Chapter VIII of the GDPR do not preclude such actions by competitors. These actions exist alongside supervisory powers and data subject remedies. Name, delivery address and product details entered when ordering pharmacy-only medicines online are health data under Article 9(1). This holds even without a prescription and even if it is not certain the customer is the person who will use the product. Processing is then only allowed under an Article 9(2) exception, such as explicit consent given after accurate, comprehensive and easily understandable information. The Court's press release summarises this as a requirement of explicit consent.
What this means in practice
GDPR compliance also becomes a competition risk: a competitor can take you to court and seek an injunction, independently of the authority. Web shops and platforms selling products from which someone's health can be inferred must treat that ordering process as processing of special category data. That requires a valid Article 9(2) exception, in practice usually explicit prior consent with clear information. Check your product categories for similar sensitive information that can be inferred from orders.
The GDPR articles concerned
- Article 4: Definitions
- Article 9: Processing of special categories of personal data
- Article 77: Right to lodge a complaint with a supervisory authority
- Article 78: Right to an effective judicial remedy against a supervisory authority
- Article 79: Right to an effective judicial remedy against a controller or processor
- Article 80: Representation of data subjects
- Article 84: Penalties
Source: EUR-Lex, arrest C-21/23checked on 15 September 2026
Summary and practical reading by Praxikon. Not legal advice; the source prevails.
Connections
What connects to this development
Themes where this returns
The counterpart in the other law
- Article 2 AI Act: Scope
via Using special categories of personal data to detect bias
- Article 3 AI Act: Definitions
- Article 5 AI Act: Prohibited AI practices
- Article 6 AI Act: Classification rules for high-risk AI systems
- Article 10 AI Act: Data and data governance
- Article 16 AI Act: Obligations of providers of high-risk AI systems
- Article 25 AI Act: Responsibilities along the AI value chain
- Article 26 AI Act: Obligations of deployers of high-risk AI systems
- Article 50 AI Act: Transparency obligations for providers and deployers of certain AI systems
Case law8 of 13
- Schrems v Meta: no unlimited retention and aggregation of data for targeted advertising
2024-10-04 · final, Hof van Justitie van de EU (Vierde kamer), Maximilian Schrems tegen Meta Platforms Ireland Limited
- IAB Europe: the TC String is personal data and the industry body is a joint controller
2024-03-07 · final, Hof van Justitie van de EU (Vierde kamer), IAB Europe tegen Gegevensbeschermingsautoriteit (België)
- Council of State: 600,000 euro fine for wifi tracking in Enschede stays annulled
2026-07-29 · final, Raad van State, Afdeling bestuursrechtspraak
- EDPS v SRB: pseudonymised data are not always personal data for everyone, but the information duty applies from collection
2025-09-04 · final, Hof van Justitie van de EU (Eerste kamer), Europese Toezichthouder voor gegevensbescherming (EDPS) tegen Gemeenschappelijke Afwikkelingsraad (SRB)
- Gelderland District Court: bankruptcy trustee is controller, DPA fine for unsecured hard drive cut to 58,125 euros
2025-08-07 · status not established, Rechtbank Gelderland
- Overijssel District Court revokes DPA fine for wifi tracking in Enschede
2024-02-02 · final, Rechtbank Overijssel
- Deutsche Wohnen: a fine on a legal person needs no identified natural person, but does require fault
2023-12-05 · final, Hof van Justitie van de EU (Grote kamer), Deutsche Wohnen SE tegen Staatsanwaltschaft Berlin
- WhatsApp v EDPB: a binding EDPB dispute resolution decision can be challenged directly before the EU courts
2026-02-10 · final, Hof van Justitie van de EU (Grote kamer), WhatsApp Ireland Ltd tegen Europees Comité voor gegevensbescherming (EDPB)
Guidelines8 of 10
- Guidelines 05/2020 on consent under Regulation 2016/679
2020-05-04 · final, European Data Protection Board (EDPB)
- Guidelines 02/2026 on Anonymisation
2026-07-07 · under consultation, European Data Protection Board (EDPB)
- Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models
2024-12-17 · final, European Data Protection Board (EDPB)
- Guidelines 07/2020 on the concepts of controller and processor in the GDPR
2021-07-07 · final, European Data Protection Board (EDPB)
- Guidelines 03/2026 on web scraping in the context of generative AI
2026-07-07 · under consultation, European Data Protection Board (EDPB)
- Dutch DPA (AP) publishes position paper on the Digital Omnibus and the AI Omnibus
2026-01-13 · final, Autoriteit Persoonsgegevens
- Guidelines 01/2025 on Pseudonymisation
2025-01-16 · adopted, European Data Protection Board (EDPB)
- Guidelines on Automated individual decision-making and Profiling for the purposes of Regulation 2016/679
2018-05-25 · final, Article 29 Working Party, bekrachtigd door de European Data Protection Board (EDPB)
Enforcement and fines
- Ten municipalities fined a total of 250,000 euros for unlawful files on Muslim residents
2026-02-03 · final, Autoriteit Persoonsgegevens
- Coolblue fined 40,000 euros on objection for cookies without consent
2024-12-23 · status not established, Autoriteit Persoonsgegevens
- Formal warning to the Dutch Minister of Education, Culture and Science not to put the CABR war archive online and searchable
2024-11-26 · final, Autoriteit Persoonsgegevens
- Clearview AI: 30.5 million euro fine and penalty orders for illegal facial database
2024-05-16 · final, Autoriteit Persoonsgegevens
Legislation in motion6 of 10
- Council: Irish Presidency continues with a revised compromise, Antici Group 11 September 2026
2026-09-11 · under negotiation, Raad van de Europese Unie, Iers voorzitterschap
- Proposal: exception for incidental special category data in AI development (Article 9(2)(k) and 9(5) GDPR)
2025-11-19 · proposal, Europese Commissie
- Proposal: relative definition of personal data (Article 4(1) GDPR)
2025-11-19 · proposal, Europese Commissie
- European Parliament: joint ITRE-LIBE draft report, amendments tabled, no committee vote yet
2026-06-22 · under negotiation, Europees Parlement, commissies ITRE en LIBE (gezamenlijke commissie)
- Proposal: exception for biometric verification under the data subject's sole control (Article 9(2)(l) GDPR)
2025-11-19 · proposal, Europese Commissie
- Proposal: implementing acts on when pseudonymised data ceases to be personal data (new Article 41a GDPR)
2025-11-19 · proposal, Europese Commissie