Ruling
Meta v Bundeskartellamt: competition authority may find a GDPR breach, strict conditions for legal bases behind personalised advertising
- Date
- Status
- final
- Body
- Hof van Justitie van de EU (Grote kamer), Meta Platforms Inc., Meta Platforms Ireland Ltd en Facebook Deutschland GmbH tegen Bundeskartellamt
- Reference
- C-252/21, ECLI:EU:C:2023:537
What it is about
Question: may the German competition authority, when examining an abuse of a dominant position, assess whether Facebook complies with the GDPR, and on what legal basis may Meta link data from other group services and from third-party websites and apps to the Facebook account? Ruling: a competition authority may find a GDPR infringement where that is necessary to establish an abuse. It must cooperate sincerely with the data protection authorities and cannot depart from their earlier decision on the same or similar terms. Collecting and linking visit data from websites and apps touching special categories is processing of special category data where it allows such information to be revealed. Merely visiting such a site is not manifestly making the data public. Reliance on the contract (Article 6(1)(b)) is possible only where the processing is objectively indispensable to the main subject matter of the contract. Reliance on legitimate interest (Article 6(1)(f)) requires that the user was informed of that interest, that the processing is strictly necessary and that a balancing of interests favours the controller. For personalised advertising without consent, the Court held that the user's interests prevail. Legal obligation, vital interests and public interest are also of limited use. Dominance does not as such rule out valid consent, but it is an important factor in assessing whether consent was freely given.
What this means in practice
If you combine data from several services or third parties for profiling or advertising, you can rely on the contract only where the processing is genuinely indispensable to the service you provide. For personalised advertising based on such combined data, legitimate interest without consent is in practice not tenable. If you rely on legitimate interest, name that interest to the user in advance, limit processing to what is strictly necessary and document the balancing test. Processing that can reveal sensitive information falls under Article 9, even where that information is inferred from browsing behaviour. If you hold a strong market position, you must be able to show that consent was freely given. Expect that competition authorities can also review your GDPR compliance.
The GDPR articles concerned
- Article 4: Definitions
- Article 5: Principles relating to processing of personal data
- Article 6: Lawfulness of processing
- Article 7: Conditions for consent
- Article 9: Processing of special categories of personal data
- Article 51: Supervisory authority
- Article 56: Competence of the lead supervisory authority
Source: EUR-Lex, arrest C-252/21checked on 15 September 2026
Summary and practical reading by Praxikon. Not legal advice; the source prevails.
Connections
What connects to this development
Themes where this returns
The counterpart in the other law
- Article 2 AI Act: Scope
via Using special categories of personal data to detect bias
- Article 3 AI Act: Definitions
- Article 5 AI Act: Prohibited AI practices
- Article 6 AI Act: Classification rules for high-risk AI systems
- Article 10 AI Act: Data and data governance
- Article 11 AI Act: Technical documentation
via Keeping records: record of processing, technical documentation and logs
- Article 12 AI Act: Record-keeping
via Keeping records: record of processing, technical documentation and logs
- Article 16 AI Act: Obligations of providers of high-risk AI systems
- Article 18 AI Act: Documentation keeping
via Keeping records: record of processing, technical documentation and logs
- Article 19 AI Act: Automatically generated logs
via Keeping records: record of processing, technical documentation and logs
- Article 25 AI Act: Responsibilities along the AI value chain
- Article 26 AI Act: Obligations of deployers of high-risk AI systems
- Article 50 AI Act: Transparency obligations for providers and deployers of certain AI systems
- Article 70 AI Act: Designation of national competent authorities and single points of contact
- Article 74 AI Act: Market surveillance and control of AI systems in the Union market
- Article 99 AI Act: Penalties
Case law8 of 14
- Council of State: 600,000 euro fine for wifi tracking in Enschede stays annulled
2026-07-29 · final, Raad van State, Afdeling bestuursrechtspraak
- Overijssel District Court revokes DPA fine for wifi tracking in Enschede
2024-02-02 · final, Rechtbank Overijssel
- Noord-Nederland District Court upholds DPA fine for village livestream, reduces it to 375 euros
2025-01-09 · status not established, Rechtbank Noord-Nederland
- Schrems v Meta: no unlimited retention and aggregation of data for targeted advertising
2024-10-04 · final, Hof van Justitie van de EU (Vierde kamer), Maximilian Schrems tegen Meta Platforms Ireland Limited
- Gelderland District Court: bankruptcy trustee is controller, DPA fine for unsecured hard drive cut to 58,125 euros
2025-08-07 · status not established, Rechtbank Gelderland
- Mousse: asking for Mr or Ms when selling a train ticket is not necessary
2025-01-09 · final, Hof van Justitie van de EU (Eerste kamer), Mousse tegen Commission nationale de l'informatique et des libertés (CNIL) en SNCF Connect
- Interim relief judge: DPA must redact fine amount when giving an enforcement decision to complainants
2024-05-31 · status not established, Rechtbank Den Haag, voorzieningenrechter (kort geding, team handel)
- EU Court of Justice in KNLTB: a purely commercial interest can be a legitimate interest
2024-10-04 · final, Hof van Justitie van de Europese Unie
Guidelines8 of 13
- Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models
2024-12-17 · final, European Data Protection Board (EDPB)
- Guidelines 05/2020 on consent under Regulation 2016/679
2020-05-04 · final, European Data Protection Board (EDPB)
- Guidelines 03/2026 on web scraping in the context of generative AI
2026-07-07 · under consultation, European Data Protection Board (EDPB)
- Guidelines 02/2026 on Anonymisation
2026-07-07 · under consultation, European Data Protection Board (EDPB)
- Guidelines 1/2024 on processing of personal data based on Article 6(1)(f) GDPR (legitimate interest)
2024-10-08 · adopted, European Data Protection Board (EDPB)
- Dutch DPA (AP) publishes position paper on the Digital Omnibus and the AI Omnibus
2026-01-13 · final, Autoriteit Persoonsgegevens
- Guidelines 01/2025 on Pseudonymisation
2025-01-16 · adopted, European Data Protection Board (EDPB)
- Guidelines 1/2026 on processing of personal data for scientific research purposes
2026-04-15 · adopted, European Data Protection Board (EDPB)
Enforcement and fines8 of 11
- Ten municipalities fined a total of 250,000 euros for unlawful files on Muslim residents
2026-02-03 · final, Autoriteit Persoonsgegevens
- Coolblue fined 40,000 euros on objection for cookies without consent
2024-12-23 · status not established, Autoriteit Persoonsgegevens
- Dutch DPA and tennis federation KNLTB end litigation: fine cut from 525,000 to at most 250,000 euros
2025-10-18 · status not established, Autoriteit Persoonsgegevens
- 600,000 euro fine for AS Watson (Kruidvat) over tracking cookies without consent
2024-05-02 · annulled, Autoriteit Persoonsgegevens
- 500 euro fine and penalty order for Stichting Oud Lemmer over webcam livestream
2021-07-09 · status not established, Autoriteit Persoonsgegevens
- DPA cuts Kruidvat fine to 50,000 euros on objection
2025-05-27 · status not established, Autoriteit Persoonsgegevens
- Experian Netherlands fined 2.7 million euros for credit scoring without legal basis or information
2025-10-16 · final, Autoriteit Persoonsgegevens
- Clearview AI: 30.5 million euro fine and penalty orders for illegal facial database
2024-05-16 · final, Autoriteit Persoonsgegevens
Legislation in motion6 of 12
- Council: Irish Presidency continues with a revised compromise, Antici Group 11 September 2026
2026-09-11 · under negotiation, Raad van de Europese Unie, Iers voorzitterschap
- Proposal: cookie rules move from ePrivacy to the GDPR, with new exceptions and a six-month rule (new Article 88a GDPR and Article 5(3) ePrivacy)
2025-11-19 · under negotiation, Europese Commissie
- Proposal: exception for biometric verification under the data subject's sole control (Article 9(2)(l) GDPR)
2025-11-19 · proposal, Europese Commissie
- Proposal: definition of scientific research, purpose limitation and information duty for research (Article 4(38), 5(1)(b) and 13(5) GDPR)
2025-11-19 · under negotiation, Europese Commissie
- Proposal: exception for incidental special category data in AI development (Article 9(2)(k) and 9(5) GDPR)
2025-11-19 · proposal, Europese Commissie
- Proposal: relative definition of personal data (Article 4(1) GDPR)
2025-11-19 · proposal, Europese Commissie