Friday, 31 July 2026

The effectiveness of the Cloud and AI Development Act regarding data centres


 


Annelieke Mooij, Assistant Professor, Tilburg Law School

Photo: Facebook Clonee (Ireland) data centre

Photo credit: Thomas Nugent, via Wikimedia commons

 

1.    Introduction

The debate about sovereignty and specifically digital sovereignty is fierce. Member States, struggle to achieve digital sovereignty which impacts the continuity and safety of the digital services. To speed up the realization of the sovereign cloud the Commission has proposed a new act the Cloud and AI Development Act (CADA). The act covers three important facets: AI, Cloud and Data centres. This contribution is limited to the proposed rules regarding data centres and analyze their effectiveness. The proposed Regulation should not be considered a stand-alone Regulation but rather forms part of the European Union’s broader strategy to strengthen digital sovereignty. The EU aims to reduce dependence on foreign digital service providers and expand Europe’s cloud and data centre capacity. At its core, the proposed Regulation seeks to create the conditions necessary for a sovereign European cloud ecosystem. A system that can support economic growth, innovation, and public-sector resilience.

The pursuit of cloud sovereignty, however, depends on more than software, governance frameworks, or industrial policy. Cloud services, AI and other digital services ultimately rely on physical infrastructure. Data centres provide storage, computing power, and connectivity upon which cloud services and AI applications depend. Without sufficient data centre capacity, ambitions for European technological autonomy cannot be achieved. The Commission aims to stimulate the increase of the data centre capacity through the CADA. The CADA therefore introduces a regulatory framework aimed at accelerating the development of data centres.  The Commission aims for the EU capacity to have tripled by 2030, and by 2035, all critical infrastructure will be hosted in EU data centres. These objectives are ambitious but there are good reasons for the Commission to emphasize digital sovereignty.

2. Why Digital Sovereignty Is Necessary & Difficult

Before delving into the CADA, it is important to understand why digital sovereignty is important to the EU. Cloud computing provides its users with remote access to data storage, software, and computing resources hosted on external servers. By outsourcing storage and computing functions to the cloud, organizations can reduce the need to maintain their own IT infrastructure. Whilst benefiting from greater scalability and operational flexibility. Public authorities increasingly rely on cloud services for precisely these reasons.

At present, however, the European cloud market is heavily concentrated. American providers dominate the sector, with Amazon Web Services and Microsoft accounting for approximately 75% of the European market. The largest European provider holds only a marginal 2% share. This concentration creates a structural dependency on foreign companies for critical digital infrastructure. One of the principal objectives of CADA is therefore to reduce this dependency and strengthen Europe’s technological autonomy.

The strategic rationale for reducing dependence on non-European providers extends beyond concerns about market concentration. Control over cloud infrastructure increasingly translates into geopolitical influence. A recent example is that of the latest AI-model created by Anthropic. The US government prohibited Anthropic from releasing its newest and most powerful model to its European customers. The official reason was due to considered possibilities of jailbreaks. The possibility of this happening was strongly denied by Anthropic. The EU Commission, however, stressed the possible negative impact on EU cybersecurity and cyberdefense.  It has been illustrative of how the US can cut-off new technologies to the EU, without serious repercussions. These incidents have not remained limited to simply limiting foreign accessibility but also to demonstrate power to individuals and institutions. Illustrative of this is the disruption of e-mail communications involving the International Criminal Court. The ICC’s email was cut-off after President Trump disagreed with actions from its main prosecutor. The case illustrated how political pressure exerted through private technology providers, without court permission, may affect the continuity of essential digital services. This dependence can be dangerous for Europe as it includes technology that is necessary for military purposes.

To achieve the desired increased EU cloud and AI capacity, physical infrastructure (or hardware) is necessary. Cloud and AI systems require data centres to operate on. The CADA therefore introduces a framework to create the necessary infrastructure.

3. The CADA’s rules on achieving data centre capacity.  

3.1. Specific Objectives

The CADA seeks to establish what the Commission describes as a coordinated and integrated ecosystem approach to cloud computing and artificial intelligence. According to the Commission, divergent national approaches to data centre permitting barriers to the efficient functioning of the internal market and hinder the development of a competitive European cloud ecosystem.

Against this background, the Regulation aims to create the conditions necessary for the large-scale deployment of cloud and AI infrastructure throughout the Union. In addition to reducing regulatory fragmentation, the proposal seeks to strengthen technological sovereignty, improve operational resilience, and support public-order objectives. The Commission further presents the Regulation as an instrument for promoting innovation and sustainability in Europe's digital infrastructure.

Regarding data centres specifically, the proposal seeks to address perceived shortages in computing and storage capacity through a combination of harmonisation measures and accelerated deployment procedures. This should lead to a specific result namely; triple the data centre capacity by 2030 and have sufficient EU data centre capacity for critical infrastructure by 2035.

3.2 Role of the Commission

The responsibility for achieving the operational objectives established by the CADA rests primarily with the European Commission. To achieve its goals, the proposal relies heavily on existing and future funding programmes intended to stimulate the development of cloud and AI technologies. These programmes seek, among other things, to improve the efficiency with which computing resources are used.

Particular emphasis is placed on technological innovation. High Performance Computing (HPC), for example, may increase the amount of computing output generated from a given level of infrastructure. More efficient use of computing resources can reduce the relative amount of storage and processing capacity required to achieve a particular outcome. Nevertheless, such efficiency gains do not eliminate the need for physical infrastructure. High-performance computing still depends on data centres and therefore remains subject to the same underlying constraints relating to energy, water, and spatial planning.

The effectiveness of this strategy consequently depends largely on the success of research and innovation projects supported through European funding programmes. There is ample reason to believe these strategies can be successful, economic literature has long recognised that research subsidies can stimulate innovation by reducing investment costs and encouraging experimentation. The chance of success, however, depends on the knowledge of the subsidy provider. In the past EU subsidies have proven a successful strategy. It is to be expected that the aim of development through subsidies will be successful again.

3.3. Data centre Acceleration Zones

To facilitate the expansion of data centre capacity, the CADA introduces so-called Data Centre Acceleration Areas (article 10). Each Member State is required to designate at least one such area for the accelerated development of data centre infrastructure, within six months of the Regulation entering into force.

When identifying acceleration areas, Member States must consider existing and future infrastructure capacity, energy availability, and broader sustainability considerations. The proposal further requires national authorities responsible for spatial planning to consider future data centre development and the necessary supporting infrastructure in those zones.

A developer wishing to develop a data centre in such an acceleration zone, will have the right to be assisted by a single point of information (article 11). This single point of information can assist the developer by sharing and coordinating the necessary permits and environmental and habitat assessments. The latter will be a sped-up procedure in accordance with Regulation 2026/XXXX on speeding-up environmental assessments. This Regulation was proposed in December 2025 with the aim to simplify environmental assessments. These rules aim to ensure that new projects have completed the permitting procedures within a year. The latter is the maximum that permitting procedures are allowed to last.

Taken together, these measures are intended to reduce administrative burdens and increase legal certainty for developers. The underlying assumption is that lengthy and fragmented permitting procedures constitute a significant obstacle to data centre deployment. To the extent that regulatory complexity delays investment, the proposed measures may indeed facilitate development. It is, however, questionable whether regulatory procedures are the primary challenge. The extent to which these objectives can be achieved in practice is, however, less clear. The realization of data centres come with significant challenges. When in operation, data centres become increasingly hot. With temperatures rising to 70 degrees in an hour. To continue their operations data centres need to cool. The cooling process requires high amounts of energy and clean water. E.g. data centres in the Netherlands constituted for approximately 5% of electricity demand in 2024. Recently a data centre by Microsoft made headlines that it uses 1% of the total national energy in the Netherlands. This whilst on the other hand there are significant shortages in energy supply for new housing and net congestion is increasing. Thereby creating serious debates on whether power should be diverted to data centres. On an EU level the targets for energy consumption are not yet met. The reduction target is approximately 18% away from its 2030 target. In 2024 the EU was 17% from renewable energy targets for 2030. In 2024 data centres consumed roughly 3% of the EU’s energy. Tripling this number and increasing it further till there is sufficient capacity for digital sovereignty creates a significant challenge.

These concerns are not limited to energy, the Netherlands is estimated to have a drinking water shortage by 2030. This whilst the data centres require approximately 3.7 million tonnes of drinking water per year, roughly 0.3% of Dutch tap water consumption, in the EU it is estimated to total 5.747.764.000 (nearly 6 billion liters). The CADA does not provide solutions to these underlying constraints. Instead, it requires Member States to create data centre acceleration zones and take infrastructure into account when designating these zones. Within these zones permitting procedures must be conducted within 12 months. While this may improve planning and coordination, it does not generate additional electricity capacity, alleviate network congestion, or increase the availability of water resources. The permits may become a hollow factor. A good example of the potential irony is that of the data centre in the Netherlands. The data centre had the required planning permits but were put on a waiting list for their energy connection.

The requirements created by the CADA may seem with a large margin of discretion as it uses language such as “take into consideration”. This language does not exert pressure on Member States. The CADA, however, also includes the earlier mentioned hard objective to triple the data centre capacity by 2030. Here lies another difficulty with the proposed framework. The CADA does not introduce a division key for how much capacity must be realized by each individual Member State. There are, however, big gaps between Member States in the current capacity.

Hungary for example only has 7.3MW of total capacity whereas Germany has 2.6GW of IT power. Arguably the capacity can be divided equally over all Member States, using the GDP as percentage divider. GDP is an indication of how much IT power is consumed in the economy. Generally, the higher the GDP the higher the IT consumption is. There is, however, little data on the demand for critical infrastructure in the EU. This is likely to change as article 15 of the CADA charges the EU Commission with obtaining that data. From an environmental perspective it is, however, ineffective to simply divide along GDP. Countries with cold climates and large coastal areas can build new more efficient data centres as the can use ocean water or outside air to cool. A submerged data centre on the coast is more sustainable than a data centre in a desert. In theory, the incentive to build data centre capacity by these countries is profit. Countries with favorable circumstances can build capacity cheaper than others and sell the capacity for profit. This theory of absolute advantage seems undermined by the next section of the CADA; the introduction of the European Cloud Federation.

 

4. The European Cloud Federation

In addition to measures aimed at expanding data centre capacity, in articles 34 and 35 the CADA introduces the proposed EuroCloud Federation. Participation in the Federation is voluntary and open to EU institutions and public-sector bodies. The purpose of the Federation is to facilitate the sharing of public cloud and data centre resources among participating members.

The underlying rationale is straightforward. Public authorities do not always utilize their available computing resources at full capacity. By enabling participating organisations to share infrastructure, the Federation seeks to improve the utilisation of existing resources and reduce unnecessary duplication of investments. In principle, such an approach may contribute to a more efficient use of public infrastructure.

To facilitate this objective, the proposal establishes a framework governing access to and sharing of infrastructure within the Federation. A notable feature of this framework is the limitation placed on financial compensation. Under Article 35(5), members providing infrastructure may recover their costs but are not permitted to generate profit from sharing their capacity with other participants.

From the perspective of short-term efficiency, this approach is understandable. Allowing access at cost price reduces barriers for participating entities and may encourage greater use of available infrastructure. The arrangement may therefore improve the allocation of existing capacity within the public sector.

The longer-term effects are less clear. The development of additional infrastructure requires significant investment and involves financial and operational risks. Where providers are unable to obtain any return beyond cost recovery, but cost recovery is not guaranteed, the incentive to create surplus capacity that can later be shared within the Federation may be reduced. Public entities may conclude that it is more attractive to rely on the capacity of other participants than to invest in additional infrastructure themselves.

 

5. Conclusion: a failed attempt?

The aim of the CADA is to increase the total EU data centre capacity. The CADA, however, does not create a division key. This is a fundamental gap within the regulation, it is too easy to state that all Member States should triple their data centre capacity equally. At present there are high differences in capacity between the different Member States.

The proposed Cloud and AI Development Act represents an ambitious attempt to strengthen European digital sovereignty through the expansion of cloud and AI infrastructure. Central to this ambition is the objective of significantly increasing data centre capacity across the European Union. To facilitate this development, the Regulation requires Member States to designate acceleration areas, develop national cloud and AI strategies, and participate in a broader framework intended to support the growth of sovereign digital infrastructure.

The proposal therefore sends a clear political signal. Data centres are no longer regarded as purely commercial infrastructure but as strategic assets that are essential for economic competitiveness, public administration, and technological autonomy. In that respect, the CADA forms part of a broader shift in European policy towards reducing strategic dependencies in critical digital technologies. Nevertheless, the CADA does not solve issues regarding natural resources. The introduction of the EU Cloud Federation furthermore has the potential to undermine a sustainable and economically efficient capacity division.  

 

Wednesday, 29 July 2026

Who Reviews the Conditions of Union Power? The Kövesi Litigation and a Blind Spot in the Judicial Review of Hybrid EU Governance

 




Joanna Demopoulou holds a PhD in International Affairs and is a former Executive in Residence at the Geneva Centre for Security Policy (GCSP). Her research examines the legal and institutional architecture of public authority and governance, focusing on how law structures, distributes, and constrains public authority across European and international institutions.

 

Photo: Laura Kövesi, by AGERPRES, cropped by Ionutzmovie, via Wikimedia Commons

 

EU law can examine almost any exercise of public power. Where it struggles is with the decision, taken a step earlier, about whether that power may exist at all. The Kövesi litigation is where the gap becomes visible.

 

On 24 June 2026 the Administrative Plenum of the Greek Court of Cassation dismissed, as inadmissible, an application brought by the European Chief Prosecutor, Laura Kövesi. She had challenged a Greek decision renewing three European Delegated Prosecutors (EDPs) for two years, where the College of the European Public Prosecutor's Office had wanted five. The vote was seventy-two to ten. Reported as news, the case looks like a routine standing problem: a supranational official has no locus, under domestic law, to contest a Member State's handling of its own judicial officers, and national procedure ran its course. That reading is not wrong. It is just incomplete.

 

What the dismissal actually protects is worth stating plainly. European prosecutorial independence was shielded here not according to what it does, but according to who signed the act that curtailed it. Nobody designed things to work this way, which is rather the trouble.

 

The case in brief

 

The College favoured a five-year renewal for three prosecutors in the Greek national section. The Supreme Judicial Council, the organ of national judicial self-government, granted two. Kövesi sought annulment. The Plenum found she lacked standing. Under Greek law on the service status of judicial officers, recourse lies only with the affected officers themselves, and only where the underlying Council decision carried a dissent of at least two members. This renewal had been unanimous.

 

The consequence is what matters. The problem was not that the wrong applicant had turned up. On these facts, no applicant could have brought a challenge at all. A minority of ten judges would have referred the underlying question, who fixes the duration of an EDP's mandate, to Luxembourg; the majority made no reference. And the forum matters: this was the Administrative Plenum in closed session, the Court acting in its self-governing rather than its adjudicative capacity. A national body, applying national rules, set a term that would bound the independence of a Union prosecutor.

 

EU law reviews the exercise of power well

 

The EPPO Regulation shows how far Union law has come in policing how European Union power is used. Operational acts, meaning the procedural steps of an investigation that can affect third parties, are reviewable under Article 42(1). Administrative acts of the Office fall to the Court of Justice under Article 42(8). And that Court has read these provisions generously. In EPPO v I.R.O. and F.J.L.R. (C-292/23), decided by the Grand Chamber on 8 April 2025 on a reference from a Spanish court, it insisted on effective review even of a witness summons issued by a European Delegated Prosecutor, looking past the formal label of the act to its effect on a legal position. The Regulation itself reveals an asymmetry: Article 42(8) expressly provides review for decisions dismissing EDPs under Article 17(3), but says nothing about national decisions shortening the office on which the Union mandate depends. Where European Union power is exercised, in short, a court can generally be found to look at it.

 

The Greek renewal decision is not that kind of act. It exercises no Union power and administers no Union office. What it does is change the duration of the national judicial status a person must hold in order to serve as an EDP at all (Recitals 32–33). Article 17, which entrusts appointment and dismissal to the College, treats that status as a standing precondition of the Union mandate, not as the thing the mandate acts upon. The act does not use the prosecutor's independence and it does not formally end it; it determines whether that independence can go on being held at all. What is being decided, in other words, is a precondition of the Union mandate rather than anything the mandate does, and preconditions of that sort are where EU judicial review is thinnest.

 

Why it falls between the regimes

 

The Regulation's review architecture sorts acts along two axes: institutional origin (an act of the EPPO, or of a Member State) and character (operational or administrative). A decision of the kind at issue here fits none of the resulting boxes. Because it is national in origin, the national track applies and Article 42 does not. Because it is neither operational nor administrative in the Regulation's sense, no Union regime claims it either. It is left to ordinary national service-status litigation.

And in Greece that litigation led nowhere. The unanimity bar, anchored in Article 90(3) of the Greek Constitution (whose compatibility with the right to effective judicial protection is itself already contested), meant that no review was available to anyone. The independence of a Union prosecutor was capped by a national hand, and no court, Greek or European, was in a position to examine the cap.

 

The obvious objection

 

The natural response is that this is simply a national act, and that dressing it up as anything else misreads the bargain on which the EPPO was built. The Office was designed to stay embedded in national structures. Article 42 was written for the Office's operational output, not for Member States' decisions about their own judges.

 

Take that objection at its strongest and it still runs into the facts. To succeed, it has to treat the decision's effect on a Union status as carrying no independent legal weight, the two-year cap as, in Union terms, simply invisible. But the College's five-year act and the Council's two-year act, pulling in opposite directions over the same office, put exactly that in doubt. If national tenure can quietly cap the Union mandate, a formally national act is shaping a condition of Union authority with no Union-level review; if it cannot, the act was never purely national in effect. Either way the binary the architecture relies on does not hold, and incorporation of the national status into the Union scheme, even if one grants it, says nothing about who may review a decision that shortens the incorporated condition.

 

The argument does not turn on how Kövesi ends

 

It is worth being precise about what this is not. There is a substantial literature on judicial review in composite or integrated procedures, where national and Union authorities each contribute to a single act and review fractures because each court sees only its own segment. The Greek renewal is a different animal: not a national input into a composite Union act, but a self-standing national decision that governs a precondition the Union scheme takes as given. The composite-procedures problem is who reviews which part of a joint act. The problem here is that the review architecture offers no settled framework for a decision about whether the Union mandate can subsist at all.

 

None of this denies that EU law has built review doctrines in adjacent terrain. Article 19(1) TEU, in the line running from the Portuguese Judges case, obliges Member States to uphold the independence of national courts that may rule on Union law. But that doctrine asks whether independence is protected; it does not supply a route for reviewing a national decision that fixes the tenure on which a Union mandate depends. The guarantee runs to independence as a value, not to the reviewability of the act that conditions the office.

 

Suppose the Court of Justice were eventually to hold, here or in a later case, that a renewal of this kind is purely national and beyond Union reach. That would not defeat the point; it would illustrate it. The claim is not that such decisions must become Union acts and be reviewed in Luxembourg. It is narrower and more awkward: EU law currently reads such decisions through the origin of the act, so that their bearing on Union power does no independent work. A ruling that an act of this kind is 'purely national' would be the clearest demonstration of that reflex. The thesis is about the criterion of review, not the disposition of this dispute, which is why it survives whichever way the dispute is resolved.

 

Beyond the EPPO

 

European Union constitutional law has grown confident at reviewing how public power is exercised. Whether it has built anything equally coherent for reviewing the legal conditions on which that power rests is far less clear, and those conditions multiply as Union governance turns hybrid, its authorities European but their underpinnings national.

 

So Kövesi is not really a story about three prosecutors in Athens. It is the point at which the standard question of judicial review, who exercised this power, starts to miss something. EU law has developed an answer to the first question. It has not yet developed one to the second, who set the conditions under which the power could be exercised at all.

 

*A note on sources. At the time of writing the full reasoning of the Administrative Plenum was not publicly available. This post relies on the EPPO Regulation (Council Regulation (EU) 2017/1939) and CJEU case law as primary materials, and on contemporaneous reporting for the Greek proceedings. The characterisation of the majority and minority positions should be checked against the official text once it is released.

 


Monday, 27 July 2026

Reconciling data protection and ‘new media’: The judgment in Legal Newsdesk Sweden (Case C-199/24)

 


 

Lorna Woods, Professor Emerita, University of Essex

 

Photo credit: Océanos y dados, via Wikimedia commons

 

Introduction

This case deals with one of the perennial questions that has faced legal regimes which recognise special treatment for journalism and new media since the advent of “new media”, that is, how far are such exceptions and preferential treatment extended? While a question for individual States to balance the freedom of expression concerns with other rights and societal interests, for the EU there is also the fact that Member States seemingly take very different approaches.  The Swedish rules, the subject of this case, provide broad protections and exemptions from data protection rules; but are they compatible with the GDPR?

 

The Facts

The case originated when ND, who had been convicted a criminal offence, sought to have details of that offence removed from the database provided, for a fee, by Legal Newsdesk Sweden.  The database allows individuals and businesses to search for those who have been subject to criminal prosecution before a Swedish court. ND’s request for erasure of the data was not met and ND sought damages for failure to comply with data protection rules. Legal Newsdesk Sweden relied on a Swedish law exempting journalism from the GDPR, and the fact that the relevant authority had granted Legal Newsdesk Sweden a certificate confirming the protection applied (utgivningsbevis). Further this meant that the only remedies available to ND against Legal Newsdesk Sweden would be criminal prosecution or civil claims for defamation.

 

The Questions

The case revolved around the Swedish law’s compatibility with the GDPR and specifically whether the rules fell within the space created by Article 85. Article 85 provides:

 

(1) Member States shall by law reconcile the right to the protection of personal data pursuant to this Regulation with the right to freedom of expression and information, including processing for journalistic purposes and the purposes of academic, artistic or literary expression.

 

(2) For processing carried out for journalistic purposes or the purpose of academic artistic or literary expression, Member States shall provide for exemptions or derogations from Chapter II (principles), Chapter III (rights of the data subject), Chapter IV (controller and processor), Chapter V (transfer of personal data to third countries or international organisations), Chapter VI (independent supervisory authorities), Chapter VII (cooperation and consistency) and Chapter IX (specific data processing situations) if they are necessary to reconcile the right to the protection of personal data with the freedom of expression and information.

 

The national court referred three questions around the scope of Article 85(1) and (2) and their relationship to one another:

 

Is the list in Article 85(2) exhaustive or does Article 85(1) allow member States to adopt legislative measures in relation to further categories of activity?

 

Does the Swedish approach of limiting the remedies available to a person to criminal proceedings or defamation find an appropriate balance between freedom of expression and data protection?

Can the making available of information based on public documents in a database for a fee  without any processing or editing constitute processing of personal data for the purposes identified in Article 85(2) (specifically journalistic purposes)?

 

Judgment

As regards the first question, the Court held that the right to derogation from data protection rules applies only in relation to the categories enumerated in Article 85(2). The Court noted that Article 85(1) establishes a general rule about reconciliation of freedom of expression and GDPR requirements, but Article 85(2) operationalises it.  Although the term "including" confirms that journalistic, academic, artistic, and literary processing are only part of that reconciliation, paragraph 1 in itself does not grant independent exemption authority; that is the role of Article 85(2). The requirement to provide exceptions only applies to those exceptions listed. Exceptions are interpreted narrowly, and taking this approach provides a “fair balance”, as required by the principle of proportionality, between Charter rights.

 

As regards the second question, Article 85(2) lists the rights that may be limited, and that list does not include the rights to remedies provided for in the GDPR.  While there is Member State procedural autonomy, the GDPR confers directly effective rights and they can only be limited by conditions found in the GDPR. This means limitations such as those found in the Swedish law are not compatible with the GDPR.

 

The third question concerned whether the provision of the database constituted processing of personal data for journalistic purposes.  The Court confirmed, first, that the making available of documents to the public constituted processing. That exemptions were to be provided if necessary to provide the balance specified in Article 85(1). Moreover, the definition of journalism from Article 9 Directive 95/46 was in principle transposable to inform the concept of journalistic purposes, which was not otherwise defined, for the GDPR.  The Court referred to the definition in Satskunnan Markkinaporsii and Satamedia (Case C-73/07):

 

“disclosure to the public of information, opinions or ideas, irrespective of the medium which is used to transmit them”.

 

The Court also referred to Recital 153 GDPR which emphasises that the term should be interpreted broadly. The Court, however, continued to say it

 

“cannot cover all forms of expression but must be understood in a way that takes into account what differentiates, from the point of view of the manner in which they are created, journalistic expression from other forms of expression” [para 64]

 

The Court then referred to the case law of the European Court of Human Rights on protection of journalism within freedom of expression (Article 10 ECHR). From this body of jurisprudence, the CJEU identified three aspects:

  • carrying out the role of editing or adapting material, or publishing according to an editorial line or policy;
  • verification of factual claims for reliability; and
  • compliance with journalistic ethics.

 

The Court suggested that a service that simply makes criminal convictions available to anyone willing to pay, without editorial review or processing, is unlikely to satisfy those requirements.  The Court did emphasise that when the protections apply, they apply also to prior research as to publication.  So convictions can be useful raw material for journalists, but the processing is for  journalistic purposes only if those documents are used exclusively for such activity.

 

Commentary

This judgment is a strong defence of data protection and the coherence of the GDPR regime.  The main point of interest in this judgment is the Court’s approach to journalistic purposes. Before discussing that, it is also worth noting that in the Court’s approach to the relationship between Article 85(1) and 85(2), it has taken an approach with favours maximum harmonisation rather than allowing too much space for Member States to go their separate ways.  This re-emphasises the supremacy of EU law, and the narrowness of exceptions thereto, even when States’ individual constitutions are in issue. It is arguably a narrow interpretation of Article 85.  There is a question of how the balance that the Court has struck in Article 85(1) might impact other forms of data processing that impact the public information sphere – what for example, about search engines (already the subject of some jurisprudence: Case C-136/17 GC et al and Case C-460/20 TU and RE v Google), social media and – increasingly – chatbots?

 

Rights are a theme throughout this judgment but it is interesting to note that while the rights which the Swedish rules sought to limit were those relating to remedies, the Court did not rely on the right to a remedy as a fundamental right to support its argument. Rather, it relied on the fact that these were directly effective rights derived from the GDPR. The concern was the priority of EU legislative objectives over national concerns.

 

The main significance is the establishment of a three stage test for “journalistic purposes” which had hitherto been undefined.  The previous position had been established in Satamedia, and further elaborated in Google Spain (Case C-131/12) and Buivids (Case C-345/17), all of which seemed to be orientated towards elaborating the idea of informing the public which is the base of the definition in Satamedia.  It is arguable, that Legal Newsdesk Sweden’s activities might not fall within the scope of this definition anyway – though the position was certainly unclear. In identifying further criteria, however, the Court has provided more clarity and likely narrowed the scope of the journalistic purposes exception.  It is interesting to note that the Court has taken cases about the level or protection awarded to journalists within the ECHR jurisprudence to identify qualifying criteria for being a journalist (of carrying out journalistic purposes) in the GDPR context- a shift from assessing how to identifying who. Whether this shift is significant in practical terms is rather uncertain – both Courts seem to be asking if the person is behaving according to relevant standards to gain the benefits of extra protection (and neither require institutional affiliation as a precondition of receiving the status).

 

While the focus in the case was just about resale of public information without any amendment, contextualisation or commentary (and possibly data brokerage generally including digital archives, research platforms, aggregators, and people-search services), the implications go further and impact “citizen journalists”, bloggers, gossip sites and other public communicators who might have assumed that they would benefit from protections, even though they might also not have bothered with fact checking and ethical considerations around news-gathering and publication. While they might have argued that they contributed to informing society, now there are more specific and arguably less vague requirements to satisfy – those around verification and ethics. Although this is a narrowing of their protections, it does not mean such speakers are off air – it means that they have to pay more attention to how they acquire and retell stories.  It is also important to note that the Court has not as a point of principle excluded private actors (rather than those earning a living from journalist) from the scope of state protections, and nor does the fact that such activities are done for money affect the assessment of whether they are done for journalistic purposes or not. And, of course, traditional journalism and media are not affected by this ruling.

 

One final point is also clear: the Swedish system will require significant overhaul if it is to comply with GDPR requirements.

From recognition to positive obligations: the ECJ’s judgment in Shipov (C-43/24)

 


 

By Marzia Genovese, Postdoctoral Lecturer and Researcher in Public Law at the European Documentation and Research Centre of the University of Pau (France).

Photo: Bulgaria Palace of Justice; photo credit Bim in Garten via Wikimedia Commons

      I.         Introduction

In K.M.H. v Obshtina Stara Zagora (Shipov, C-43/24), the Grand Chamber of the Court of Justice of the European Union (ECJ) held that Article 21 TFEU and Article 4(3) of Directive 2004/38, read in the light of Article 7 of the Charter of Fundamental Rights of the EU, preclude national legislation that does not permit a transgender Union citizen to amend certain data recorded in civil-status registers. The judgment builds upon the Court’s recent decision in Mirin and forms part of a broader line of case law concerning the relationship between free movement rights, personal status and gender identity.

The decision will likely be welcomed as a further step in the protection of transgender Union citizens exercising their free movement rights, yet the lines of reasoning adopted by both the Court and the Advocate General (AG) raise a number of conceptual and constitutional questions that remain insufficiently explored.

This contribution argues that Shipov marks a significant development in the evolution of Article 21 TFEU. Unlike Mirin, the case did not involve the recognition of a legal status previously acquired in another Member State. Instead, the Court used Article 21 TFEU to impose a positive obligation affecting the organisation of national civil-status law itself. At the same time, it does so through reasoning that leaves several conceptual and constitutional questions unresolved. In particular, the Court employs notions such as sex, gender and gender identity, without clearly identifying the legal category that Member States are required to recognise or modify. Additionally, the Court’s reasoning raises broader questions regarding the practical scope of Member State autonomy in matters of civil status.

The discussion proceeds in four steps. It first examines the conceptual uncertainty underlying the judgment. It then considers the shift from mutual recognition to self-standing positive obligations under Article 21 TFEU, before analysing the limitations of the AG’s reasoning as well. Finally, it reflects on the implications of Shipov for the relationship between Union citizenship and national competence in matters of civil status.

II. Conceptual ambiguity: what exactly must be changed?

One of the most striking features of Shipov is the conceptual ambiguity underlying the Court’s judgment. Throughout the proceedings, a number of distinct notions appear interchangeably, such as sex, gender and gender identity. Yet neither the Court nor the Advocate General clearly explain the legal relationship between these concepts or identify with precision which of them forms the object of the obligation imposed on Member States.

Such an obligation necessarily presupposes the identification of the legal category to be modified. Is EU law requiring the recognition of a person’s gender identity, the amendment of legal gender or the modification of civil-status records relating to sex? The judgment offers no clear answer.

The ambiguity culminates in the operative part of the judgment, where the Court refers to “data relating to gender, such as sex” (paras 36 and 56). This formulation is difficult to reconcile with a coherent conceptual framework. If sex and gender are distinct categories, as the Court itself appears to assume throughout the proceedings and it is also scientifically established, the judgment fails to explain why they can be treated as interchangeable for the purposes of civil-status registration. Conversely, if the two concepts are understood as functionally equivalent, the Court never justifies the use of separate terminology throughout its reasoning and moves fluidly between references to sex, gender identity and personal appearance without clarifying the legal significance of each concept.

This ambiguity is not merely semantic. It has direct implications for legal certainty. Member States remain, in principle, competent in matters of civil status. If EU law nevertheless requires them to modify certain entries contained in civil-status records, they must be able to determine with reasonable clarity and certainty which legal category is affected and what precisely must be recognised. By treating distinct dimensions as largely interchangeable, the Court risks obscuring the precise basis of the obligation imposed on Member States.

Moreover, the Court’s treatment of intersex and transgender persons illustrates the conceptual difficulties underlying the judgment (para 22). In assessing the Bulgarian legal framework, the Court appears to rely on the fact that national law permits the amendment of civil-status records in certain situations involving intersex persons whilst excluding such amendments for transgender persons. Yet the comparability of those situations is largely assumed rather than demonstrated.

This omission is significant. Intersex variations and transgender identity raise distinct legal and factual questions. The former concern biological conditions that may affect the classification of sex at the time of birth and, consequently, the accuracy of the original civil-status registration. The latter concern the recognition of a gender identity emerging after birth and whose legal implications are conceptually different from the correction of an allegedly inaccurate birth record. The Court does not explain why these situations should be treated as comparable for the purposes of civil-status registration, nor why legal solutions developed in one context should necessarily apply in the other.

Whether the situations ought ultimately to be treated alike is therefore not the central issue. The difficulty lies in the absence of a clear comparability analysis. By moving between different categories without defining the legal relevance of each of them, the judgment further reinforces the conceptual ambiguity already present elsewhere in its reasoning.

This difficulty is compounded by a second and arguably more fundamental question: does Shipov fit within the logic of the Court’s earlier citizenship case law at all?

III. From recognition to self-standing positive obligations

The Court presents Shipov as part of a broader line of case law concerning the exercise of free movement rights by Union citizens. Yet a closer examination reveals that the judgment departs in a significant respect from the logic underlying the Court’s earlier decisions on civil status.

Cases such as Grunkin-Paul, Coman and, more recently, Mirin were all built around a common premise: a legal status had already been lawfully acquired in one Member State and another Member State refused to recognise it. The obstacle to free movement arose from the coexistence of conflicting legal situations within the Union. In those circumstances, the Court relied on Article 21 TFEU to prevent Union citizens from suffering disadvantages resulting from the exercise of their right to move and reside in another Member State.

In Mirin, for example, the applicant had obtained legal recognition of his gender identity in the United Kingdom and sought recognition of that status in Romania. The Court’s intervention therefore remained rooted in a logic of mutual recognition. Romania was not required to create a new legal status; it was required to recognise one already validly established elsewhere in the Union.

Shipov presents a fundamentally different situation. The applicant had not obtained legal recognition of her gender identity in Italy or in any other Member State. No foreign administrative act, judicial decision or civil-status record existed that could serve as the object of recognition. The case therefore lacked the transnational legal element that had justified the Court’s intervention in previous cases. This distinction is not merely factual. It alters the very nature of the obligation imposed by EU law.

In the absence of any status acquired elsewhere, Bulgaria was not asked to recognise an existing legal situation. Rather, it was required to provide a mechanism through which a new legal status could be established under Bulgarian law itself. Article 21 TFEU thus ceases to operate as a principle of recognition and becomes a source of self-standing positive obligations affecting the organisation of national civil-status systems.

The significance of this shift should not be underestimated. Mutual recognition has traditionally allowed the Court to balance free movement rights with Member State autonomy. Whilst Member States remained free to determine the substantive conditions governing civil status within their own legal systems, they could not disregard legal situations lawfully established elsewhere. This logic preserved a degree of constitutional pluralism by distinguishing between the creation of legal status and its recognition.

In Shipov, however, that distinction becomes increasingly difficult to maintain. Once Article 21 TFEU is capable of generating obligations independently of any foreign status requiring recognition, the Court’s review is no longer confined to ensuring the continuity of legal situations across borders. It extends to the substantive content of national rules governing civil status. The competence formally remains national, but the outcome is increasingly shaped by EU law.

IV. The Advocate General’s ‘functional’ solution and its limits

 

If Shipov cannot be really explained through the logic of mutual recognition, a different justification is required. The AG sought to provide one by focusing on the functional role of identity documents in facilitating the exercise of free movement rights. Since identity documents play a crucial role in enabling Union citizens to move and reside freely within the Union, the Member State of nationality could not, in his view, maintain a system that prevented such documents from reflecting a person's lived gender identity.

The most problematic aspect of the Opinion, however, lies elsewhere. In paragraph 94, the AG expressly states that the original indication of the applicant’s sex should not be regarded as erroneous and should not be treated as a mistake requiring rectification. Two paragraphs later, moreover, he recalls the ECtHR’s recognition of the “historical nature” of birth records and of the continuing relevance of the sex assigned at birth for establishing facts predating gender reassignment. Yet the solution advocated by the Opinion ultimately requires the creation of a legal mechanism through which the same birth certificates may be amended in order to reflect a subsequently recognised gender identity.

The resulting tension is difficult to ignore. If the original registration was accurate and birth certificates serve, at least in part, a historical function, the Opinion never adequately explains why EU law nevertheless requires their amendment.

This tension is reinforced by the AG’s own discussion of Article 3(2) of Regulation 2025/1208. There, he acknowledges that EU law does not require Member States to include a reference to sex or gender on national identity cards and permits them to omit such information altogether, unlike the International Civil Aviation Organisation (ICAO) standards applicable to passports and other travel documents (all Member States, but not the EU, are parties to the Convention establishing the ICAO). If the objective pursued is the removal of obstacles to free movement, the necessity of amending birth certificates becomes considerably less obvious. The Opinion does not explain why that objective cannot be achieved through less intrusive means. As paragraph 82 of the Opinion makes clear, the perceived necessity of amending the birth certificate stems largely from the fact that Bulgarian identity documents are based upon that record, yet this approach risks extending the reach of Article 21 TFEU into matters that traditionally fall within Member State competence.

The AG’s functional approach thus succeeds in identifying a practical difficulty faced by the applicant, but it never convincingly explains why a birth certificate whose original entries are acknowledged to be accurate must nevertheless be altered in order to comply with EU law.

V. EU citizenship and national autonomy in matters of civil status

The preceding discussion ultimately points towards a broader constitutional issue. If Article 21 TFEU (which sets out EU citizens’ rights to move and reside freely in the EU) can require the amendment of civil-status records in the absence of any foreign status requiring recognition, what remains of Member State autonomy in matters of civil status?

The Court has consistently recognised that matters such as civil status, family status, names and personal identity fall, in principle, within the competence of the Member States (e.g., Runevič-Vardyn). At the same time, however, it has repeatedly held that those competences must be exercised consistently with EU law whenever the exercise of free movement rights is affected. The tension between these two propositions lies at the heart of Shipov.

Here, the Court expressly acknowledges that the issuing of identity documents falls within the competence of the Member State of nationality (para 47), yet it immediately adds that such documents serve to enable the exercise of the rights conferred by Article 21 TFEU. Once that connection is established, national rules governing civil-status registration become subject to review in light of both free movement and the fundamental rights guaranteed by the Charter, such as Article 7 (respect for private and family life).

This dynamic is further illustrated by the ECJ’s treatment of the Bulgarian Constitutional Court’s reasoning. The latter had previously interpreted the concept of sex contained in the Bulgarian Constitution as referring exclusively to biological sex and justified its interpretative decision in light of broader moral and religious rules and principles “prevailing over the interests of transgender persons” (paras 21 and 46). The ECJ rejected those arguments as potential justifications for the restriction of free movement and ultimately reaffirmed that neither the Member State’s competence in matters of civil status nor moral and religious considerations could justify the obstacles encountered by the applicant (paras 47-48). This logic culminates in paragraph 60 of the judgment, where the ECJ reiterates that rules of national law, even of constitutional rank, cannot undermine the effectiveness of EU law.

From the perspective of EU law, this result is hardly surprising. The principle of primacy would be significantly weakened if Member States could rely upon domestic constitutional concepts to avoid obligations flowing from Union law. Nevertheless, Shipov illustrates how the progressive expansion of Article 21 TFEU may affect the practical scope of Member State autonomy in areas that formally remain within national competence. This point is particularly significant when considered alongside the preceding sections.

To raise this concern is not to suggest that constitutional autonomy should operate as a shield against Union law. Nor is it to deny the legitimacy of protecting Union citizens against discrimination and/or unjustified obstacles to free movement. However, the broader the concept of an obstacle to free movement becomes, the greater the potential reach of EU law into areas that the Treaties continue formally to reserve to the Member States.

In this respect, Shipov may ultimately prove significant not only for legal gender recognition, but also for the constitutional development of Union citizenship itself. The judgment suggests that once a matter can be connected, even indirectly, to the exercise of free movement rights, the scope for maintaining distinct national approaches becomes increasingly narrow. Whether that development represents a natural consequence of Union citizenship or a more profound transformation of the relationship between EU law and national competences remains open to debate.

VI. Conclusion

Shipov is likely to be remembered as an important step in the Court’s case law on the rights of transgender Union citizens, yet its significance extends beyond the specific context of legal gender recognition.

The judgment suffers from a degree of conceptual ambiguity that is difficult to ignore. Throughout its reasoning, the Court moves between references to sex, gender and gender identity without clearly identifying the precise legal category that Member States are required to recognise or modify. This uncertainty is compounded by the Court’s equal treatment of intersex and transgender situations, whose comparability is largely assumed rather than demonstrated.

More fundamentally, Shipov marks an important step beyond the logic that characterised previous case law. Unlike earlier cases, no foreign legal status required recognition here. In this instance, article 21 TFEU was used not to ensure the continuity of a legal situation already established elsewhere in the Union, but to generate a positive obligation affecting the organisation of national civil-status law in circumstances where the transnational element appeared particularly weak. The AG’s attempt to justify that result through the functional role of identity documents is ultimately unpersuasive, not least because it fails to explain why birth certificates whose original entries are acknowledged to be accurate must nevertheless be amended in order to facilitate free movement.

Ultimately, the most significant issue raised by Shipov may not concern legal gender recognition at all, but the limits of Article 21 TFEU itself. Once the latter is capable of generating substantive obligations in areas formally falling within Member State competence, the distinction between the recognition of legal status and its creation becomes increasingly difficult to maintain. Whether the Court has provided a sufficiently clear and principled justification for that evolution remains an open question.