Showing posts with label GDPR. Show all posts
Showing posts with label GDPR. Show all posts

Monday, 27 July 2026

Reconciling data protection and ‘new media’: The judgment in Legal Newsdesk Sweden (Case C-199/24)

 


 

Lorna Woods, Professor Emerita, University of Essex

 

Photo credit: Océanos y dados, via Wikimedia commons

 

Introduction

This case deals with one of the perennial questions that has faced legal regimes which recognise special treatment for journalism and new media since the advent of “new media”, that is, how far are such exceptions and preferential treatment extended? While a question for individual States to balance the freedom of expression concerns with other rights and societal interests, for the EU there is also the fact that Member States seemingly take very different approaches.  The Swedish rules, the subject of this case, provide broad protections and exemptions from data protection rules; but are they compatible with the GDPR?

 

The Facts

The case originated when ND, who had been convicted a criminal offence, sought to have details of that offence removed from the database provided, for a fee, by Legal Newsdesk Sweden.  The database allows individuals and businesses to search for those who have been subject to criminal prosecution before a Swedish court. ND’s request for erasure of the data was not met and ND sought damages for failure to comply with data protection rules. Legal Newsdesk Sweden relied on a Swedish law exempting journalism from the GDPR, and the fact that the relevant authority had granted Legal Newsdesk Sweden a certificate confirming the protection applied (utgivningsbevis). Further this meant that the only remedies available to ND against Legal Newsdesk Sweden would be criminal prosecution or civil claims for defamation.

 

The Questions

The case revolved around the Swedish law’s compatibility with the GDPR and specifically whether the rules fell within the space created by Article 85. Article 85 provides:

 

(1) Member States shall by law reconcile the right to the protection of personal data pursuant to this Regulation with the right to freedom of expression and information, including processing for journalistic purposes and the purposes of academic, artistic or literary expression.

 

(2) For processing carried out for journalistic purposes or the purpose of academic artistic or literary expression, Member States shall provide for exemptions or derogations from Chapter II (principles), Chapter III (rights of the data subject), Chapter IV (controller and processor), Chapter V (transfer of personal data to third countries or international organisations), Chapter VI (independent supervisory authorities), Chapter VII (cooperation and consistency) and Chapter IX (specific data processing situations) if they are necessary to reconcile the right to the protection of personal data with the freedom of expression and information.

 

The national court referred three questions around the scope of Article 85(1) and (2) and their relationship to one another:

 

Is the list in Article 85(2) exhaustive or does Article 85(1) allow member States to adopt legislative measures in relation to further categories of activity?

 

Does the Swedish approach of limiting the remedies available to a person to criminal proceedings or defamation find an appropriate balance between freedom of expression and data protection?

Can the making available of information based on public documents in a database for a fee  without any processing or editing constitute processing of personal data for the purposes identified in Article 85(2) (specifically journalistic purposes)?

 

Judgment

As regards the first question, the Court held that the right to derogation from data protection rules applies only in relation to the categories enumerated in Article 85(2). The Court noted that Article 85(1) establishes a general rule about reconciliation of freedom of expression and GDPR requirements, but Article 85(2) operationalises it.  Although the term "including" confirms that journalistic, academic, artistic, and literary processing are only part of that reconciliation, paragraph 1 in itself does not grant independent exemption authority; that is the role of Article 85(2). The requirement to provide exceptions only applies to those exceptions listed. Exceptions are interpreted narrowly, and taking this approach provides a “fair balance”, as required by the principle of proportionality, between Charter rights.

 

As regards the second question, Article 85(2) lists the rights that may be limited, and that list does not include the rights to remedies provided for in the GDPR.  While there is Member State procedural autonomy, the GDPR confers directly effective rights and they can only be limited by conditions found in the GDPR. This means limitations such as those found in the Swedish law are not compatible with the GDPR.

 

The third question concerned whether the provision of the database constituted processing of personal data for journalistic purposes.  The Court confirmed, first, that the making available of documents to the public constituted processing. That exemptions were to be provided if necessary to provide the balance specified in Article 85(1). Moreover, the definition of journalism from Article 9 Directive 95/46 was in principle transposable to inform the concept of journalistic purposes, which was not otherwise defined, for the GDPR.  The Court referred to the definition in Satskunnan Markkinaporsii and Satamedia (Case C-73/07):

 

“disclosure to the public of information, opinions or ideas, irrespective of the medium which is used to transmit them”.

 

The Court also referred to Recital 153 GDPR which emphasises that the term should be interpreted broadly. The Court, however, continued to say it

 

“cannot cover all forms of expression but must be understood in a way that takes into account what differentiates, from the point of view of the manner in which they are created, journalistic expression from other forms of expression” [para 64]

 

The Court then referred to the case law of the European Court of Human Rights on protection of journalism within freedom of expression (Article 10 ECHR). From this body of jurisprudence, the CJEU identified three aspects:

  • carrying out the role of editing or adapting material, or publishing according to an editorial line or policy;
  • verification of factual claims for reliability; and
  • compliance with journalistic ethics.

 

The Court suggested that a service that simply makes criminal convictions available to anyone willing to pay, without editorial review or processing, is unlikely to satisfy those requirements.  The Court did emphasise that when the protections apply, they apply also to prior research as to publication.  So convictions can be useful raw material for journalists, but the processing is for  journalistic purposes only if those documents are used exclusively for such activity.

 

Commentary

This judgment is a strong defence of data protection and the coherence of the GDPR regime.  The main point of interest in this judgment is the Court’s approach to journalistic purposes. Before discussing that, it is also worth noting that in the Court’s approach to the relationship between Article 85(1) and 85(2), it has taken an approach with favours maximum harmonisation rather than allowing too much space for Member States to go their separate ways.  This re-emphasises the supremacy of EU law, and the narrowness of exceptions thereto, even when States’ individual constitutions are in issue. It is arguably a narrow interpretation of Article 85.  There is a question of how the balance that the Court has struck in Article 85(1) might impact other forms of data processing that impact the public information sphere – what for example, about search engines (already the subject of some jurisprudence: Case C-136/17 GC et al and Case C-460/20 TU and RE v Google), social media and – increasingly – chatbots?

 

Rights are a theme throughout this judgment but it is interesting to note that while the rights which the Swedish rules sought to limit were those relating to remedies, the Court did not rely on the right to a remedy as a fundamental right to support its argument. Rather, it relied on the fact that these were directly effective rights derived from the GDPR. The concern was the priority of EU legislative objectives over national concerns.

 

The main significance is the establishment of a three stage test for “journalistic purposes” which had hitherto been undefined.  The previous position had been established in Satamedia, and further elaborated in Google Spain (Case C-131/12) and Buivids (Case C-345/17), all of which seemed to be orientated towards elaborating the idea of informing the public which is the base of the definition in Satamedia.  It is arguable, that Legal Newsdesk Sweden’s activities might not fall within the scope of this definition anyway – though the position was certainly unclear. In identifying further criteria, however, the Court has provided more clarity and likely narrowed the scope of the journalistic purposes exception.  It is interesting to note that the Court has taken cases about the level or protection awarded to journalists within the ECHR jurisprudence to identify qualifying criteria for being a journalist (of carrying out journalistic purposes) in the GDPR context- a shift from assessing how to identifying who. Whether this shift is significant in practical terms is rather uncertain – both Courts seem to be asking if the person is behaving according to relevant standards to gain the benefits of extra protection (and neither require institutional affiliation as a precondition of receiving the status).

 

While the focus in the case was just about resale of public information without any amendment, contextualisation or commentary (and possibly data brokerage generally including digital archives, research platforms, aggregators, and people-search services), the implications go further and impact “citizen journalists”, bloggers, gossip sites and other public communicators who might have assumed that they would benefit from protections, even though they might also not have bothered with fact checking and ethical considerations around news-gathering and publication. While they might have argued that they contributed to informing society, now there are more specific and arguably less vague requirements to satisfy – those around verification and ethics. Although this is a narrowing of their protections, it does not mean such speakers are off air – it means that they have to pay more attention to how they acquire and retell stories.  It is also important to note that the Court has not as a point of principle excluded private actors (rather than those earning a living from journalist) from the scope of state protections, and nor does the fact that such activities are done for money affect the assessment of whether they are done for journalistic purposes or not. And, of course, traditional journalism and media are not affected by this ruling.

 

One final point is also clear: the Swedish system will require significant overhaul if it is to comply with GDPR requirements.

Monday, 30 March 2026

Clash between gender data vs Hungarian personal data register: Can an existing Hungarian registry system prevent the enforcement of trans rights based on the GDPR?


 

Attila Szabó, PhD

Head of Legal Aid Service, Hungarian Civil Liberties Union

 

*The author assisted the lawyer representing the person concerned as an advisor in the Hungarian case analyzed in the text.  The author also used artificial intelligence to prepare the English version of the text.

 

Photo credit: Jorge Franganillo, via Wikimedia commons

 

In recent years, the Court of Justice of the European Union has increasingly engaged with trans rights. European constitutional community has followed this development. 

It appears that despite the consolidation of a GDPR interpretation aligned with trans rights, and thus with human dignity, Hungarian courts fail to understand that gender identity is not only a matter of self-determination, but also one of data accuracy. If someone presents and lives as a woman, then from the perspective of data accuracy she must also be treated as a woman, since this is the accurate data. The highest Hungarian court, however, sees this differently, and with its decision on the matter, it violates EU law.

Between 2024 and 2025, the Court of Justice of the European Union (CJEU) reshaped the landscape of trans rights in the EU through a remarkable line of cases: Mirin, Mousse, Deldits and Shipov. Taken together, these rulings reveal a structural shift in the CJEU’s approach. The Court increasingly speaks the language of “gender identity” rather than “gender reassignment,” signalling a move away from medicalised understandings of trans status and opening space for non-binary recognition. It integrates ECtHR standards as a constitutional floor while embedding trans rights across multiple doctrinal pillars: EU citizenship, free movement, privacy, equality, and data protection. What emerges is not a single breakthrough, but a coherent jurisprudential arc. One that justifies speaking of a significant doctrinal shift of trans rights in EU law.

Summary of the Hungarian Kúria’s Decision 

The claimant requested the rectification of the “sex” entry in the Hungarian personal data and address register from “male” (as recorded in the civil registry at birth) to “female,” relying primarily on Article 16 GDPR (right to rectification) and explicitly invoking the CJEU’s judgment in Deldits. The claimant argued that the register in question records “sex”, not “sex at birth,” and therefore should reflect lived (social) gender identity. Since her appearance and social relations objectively correspond to a female identity, the currently recorded data were inaccurate within the meaning of Article 5 (1) d) and Article 16 of GDPR. She maintained that the data protection authority should assess whether the recorded data correspond to reality as experienced and perceived, and that EU law requires rectification even if domestic civil registry law remains unchanged.

Both the first-instance court and, on review, the Kúria (Hungarian Supreme Court) rejected the claim. (The decisions have not yet been made public; this blog post provides the first summary of them.) The decisive reasoning was structural: the personal data and address register is a secondary, derivative register whose “sex” entry is based directly on the birth registry. Under Hungarian law, the birth registry records “sex at birth,” defined biologically. Since the personal data register derives this data from the civil registry, it cannot diverge from it without undermining legal certainty and the authenticity of public registers. The Kúria held that the register does not record “lived gender identity” at all; therefore, the data cannot be considered inaccurate merely because the claimant’s current gender identity differs from the birth record. In its reading of Deldits, the GDPR right to rectification applies only to data that are inaccurate within the meaning and function of the specific register concerned. Article 16 GDPR cannot be interpreted as obliging an authority to insert new categories of data (e.g. lived gender identity) without explicit statutory authorisation, nor to assign a different substantive meaning to an existing category (“sex at birth”). The Court therefore concluded that no inaccuracy existed and that rectification was not required.

Mistakes in the decision

The conceptual distinction between “sex at birth” and “sex” undermines the exclusivity claim. The birth registry records a historical biological fact at the time of birth. By contrast, the personal data and address register functions as an operational identification database used for everyday legal and administrative interactions. Accuracy in this context serves identification and legal certainty in present-day relations. If the data recorded there do not reflect the individual’s lived and socially recognised gender, they may fail the accuracy requirement precisely because they hinder reliable identification. The fact that one dataset originates historically from another does not transform the original entry into an immutable legal truth for all future processing contexts.

Secondly, Hungarian law itself does not establish that the civil registry is the sole permissible source of “sex” data in all registers. If it would have been so it would be absolutely unchangeable. However it is not, since the statutory framework governing the personal data and address register allows updates based on legally valid rectification requests. It is fully in line with GDPR. Moreover, even Hungarian constitutional jurisprudence has recognised that legal acknowledgment of gender identity, at least outside the civil registry context, may be compatible with the Hungarian Fundamental Law. This demonstrates that the legal system does not treat the birth entry as metaphysically definitive, but as one administrative record among others.

Finally, the “hierarchy of registers” argument reverses the logic of legal certainty. Legal certainty is not preserved by maintaining inter-database consistency at the price of factual inaccuracy. Rather, certainty requires that state records correspond to verifiable social and legal reality. If necessary, consistency between registers can be achieved by differentiating between “sex at birth” (retained in the birth registry) and current “sex” or gender identity (reflected in identification databases). EU law does not require uniformity of terminology across all databases; it requires accuracy, proportionality, and effective protection of fundamental rights. Therefore, the proposition that only the birth registry may serve as the lawful source of sex-related data is neither compelled by domestic law nor compatible with the GDPR as interpreted by the Court of Justice.

The Decision in the Context of European Law

This ruling stands in notable tension with the emerging CJEU jurisprudence represented by the Deldits, Mirin, Mousse and Shipov cases. In Deldits, the CJEU held that where a register contains personal data relating to gender identity, that data must be rectified if inaccurate, and that Member States may not impose disproportionate evidentiary burdens (such as proof of surgery). The Hungarian Kúria distinguished Deldits on the basis that the asylum register there functioned as a primary identity register, whereas the Hungarian personal data register merely mirrors the civil registry’s birth-sex entry. The core of Kúria's reasoning is therefore ontological: if a register is designed to record biological sex at birth, then a divergence from lived gender identity does not render it “inaccurate.”

This is, of course, a misconception: the personal data register, which is distinct from the civil (birth) registry, exists precisely to record the data necessary for identification. In most cases, those data derive from the civil registry; however, in the case of trans persons, they do not necessarily follow from the birth registry but from factual circumstances that, through a rectification procedure, could also become officially documented facts. This state database can record birth sex data and accurate, actual data too, in parallel. Kúria argues that the registry only processes data relating to "sex" and cannot process data relating to birth gender and current gender without a change in legislation. This is true, of course, but the data controller can, in such cases, process only data relating to current gender in the registry that exists alongside the birth registry system.

Nor is Kúria's argument persuasive that it cannot order the processing of “new” data. The personal data register can, within the existing legal framework, be modified technically and administratively if in its current form it does not comply with the requirements flowing from the GDPR and EU law. The Kúria therefore did not give effect to EU law, but rather to domestic practical constraints: it effectively treated a functional system as if it were a legal norm, even though in reality such a system should adapt to legal norms, not prevent their enforcement.

From an EU law perspective, however, this formalistic register-based distinction raises deeper questions. The recent CJEU trend has emphasised substance over classification: Mirin prioritised the practical effectiveness of EU citizenship and identity coherence across registers; Mousse treated gender-related data as protected personal data subject to strict necessity and proportionality review; and Deldits framed gender identity as a legally relevant dimension of accuracy under the GDPR. Against this background, the Hungarian decision represents a restrictive reading of Article 16 GDPR, confining rectification to internal consistency within a nationally defined registry hierarchy.

In this case, we will still turn to the Hungarian Constitutional Court. However, if that body also fails to restore the possibility of effective legal enforcement under the Hungarian Fundamental Law and the binding EU law applicable on that basis, then, besides applying to the European Court of Human Rights, the only remaining option will be for the European Commission to initiate infringement proceedings and thereby compel Hungary to comply with the binding requirements of the GDPR and the Charter of Fundamental Rights. And yes, if necessary, let them add another field to the personal data register system.

Following the very recent Shipov decision, the situation is even clearer: the position of the Hungarian Supreme Court is completely untenable. In that case, the court ruled that it violates the right to free movement if a person is unable to identify themselves in another Member State with an identity document corresponding to their true gender. The current Hungarian case highlights that this violates not only the right to free movement but also the GDPR’s data accuracy rules. After all, inaccuracy is not only a problem when someone travels to another Member State. The two cases are thus based on different legal arguments, but they point to the same thing: inaccuracy causes privacy difficulties that violate the right to private life protected by the Charter of Fundamental Rights.

 

 

 

Wednesday, 10 December 2025

Image Rights and False Claims, Data Protection and Intermediary Immunity: the case of Russmedia

 


 

Lorna Woods, Professor Emerita, University of Essex

 

Image credit: US Department of Defense

 

This Grand Chamber judgment of the Court of Justice in X v Russmedia Digital and Inform Media Press (Case C-492/23) handed down on 2 December 2025 concerns the scope of data protection rights and intermediary immunity in the context of the non-consensual use of someone’s image.  The judgment identifies:

- when someone has responsibilities under the GDPR,

- the relationship between those regulatory obligations and intermediary immunity, and

- the steps an data controller could take to satisfy those GDPR obligations.

 

It has been described as reshaping the obligations of online operators in the EU, while others have questioned how far the points in the judgments may be generalised to other situations.

 

Judgment

 

The Facts

 

Russmedia owns an online marketplace on which advertisements may be published. An unidentified user posted an advertisement falsely representing X as offering sexual services. The advert included X’s photographs (though there is no suggestion that these were intimate images) and phone number, all without her consent. Once notified, Russmedia removed the advert within an hour but the advertisement had been shared across several third party websites and remained accessible. X sued in the national courts in respect of her image rights, rights to reputation and data protection rights. The Romanian courts struggled with the question of whether Russmedia could claim the benefit of intermediary immunity (under the e-Commerce Directive (Directive 2000/31), provisions now replaced by the Digital Services Act (DSA)) and the extent of the obligations under the GDPR.

 

Is Russmedia subject to Obligations under the GDPR?

 

Obligations under GDPR arise when (1) personal data are (2) processed by (3) a data controller.

 

The CJEU commenced its analysis by noting the the information contained in the advert about X was personal data for the purposes of the GDPR and moreover that claims about a person’s sex life (implied in the advert) constituted “sensitive” personal data as protected by Article 9 GDPR, and that remained the case whether or not the claim was true.  Classification of the data as special category data means that there is a higher threshold to show lawful processing of those data. 

 

The Court further noted that “the operation of loading personal data on a webpage constitutes processing” for the purposes of the GDPR (para 54) and therefore covered the publication of the advert.

 

While this puts the advert within the scope of the GDPR, its obligations apply to data controllers and processors, so the question was whether, given Russmedia had no control over the content of the advert, was it a controller or joint controller? The Court reiterated previous jurisprudence to say (para 58) that:

 

any natural or legal person who exerts influence over the processing of such data, for his or her own purposes, and who participates, as a result, in the determination of the purposes and means of that processing, may be regarded as a controller in respect of such processing.

 

It noted also that there may be more than one entity which is a controller in respect of processing – this is the idea of joint controllers, although they may not have equal responsibility depending on the facts (para 63).  Joint decision making is not necessary for there to be joint controllers.

 

While the test for “controller” requires that the person processing the data does so for their own purposes, the Court added that this could include the situation “where the operator of an online marketplace publishes the personal data concerned for commercial or advertising purposes which go beyond the mere provision of a service which he or she provides to the user advertiser”  (para 66).  The Court in this case pointed to the fact that the terms of use give Russmedia “considerable freedom to exploit the information  published on that marketplace” including “the right to use published content, distribute it, transmit it, reproduce it, modify it, translate it, transfer it to partners and remove it at any time” (para 67). Russmedia is therefore not publishing solely on behalf of the user placing the advert. The Court also noted that Russmedia make the data in the advert accessible, allows the placing of anonymous adverts and sets the parameters for the dissemination of adverts (likely to contain personal data).

 

As a result of finding that the advert publishing platform was a joint controller the GDPR obligations bite in relation to the advert and must be able to demonstrate that the advert is published lawfully, which includes the requirement for consent for sensitive data (para 84 and 93) and the requirement for accuracy.  The CJEU notes that once published online and accessible to any Internet user, such data may be copied and reproduced on other websites, so that it may be difficult, if not impossible, for the data subject to obtain their effective deletion from the Internet.  The adds to the seriousness of the risks facing the data subject.

 

The GDPR also requires the implementation of technical and organisational measures – and this should be considered in the design of the service so that such data controllers can identify adverts containing sensitive data before they are published and to verify that such sensitive data is published in compliance with the principles of the GDPR (para 106).  Further, the controller must ensure that there are safety measures in place so that adverts containing sensitive data and not copied and unlawfully published elsewhere (para 122).

 

Are the GDPR Obligations Affected by Intermediary Immunity?

 

While the immunity provisions in the e-Commerce Directive are far-reaching, the e-Commerce Directive specified that it was not to apply to the Data Protection Directive (the legislation in  force at the time the e-Commerce Directive was drafted) and that included the immunities; the Court concluded that this meant the e-Commerce Directive could not interfere with the GDPR. It also specified that GDPR requirements here cannot be classified as general monitoring (which is prohibited by the e-Commerce Directive (and now the DSA)).

 

 

Conclusions, Implications and Questions

 

The ruling in this case does not match existing industry practice. It is not a bolt out of the blue, however, but builds on existing jurisprudence (eg Fashion ID (Case C-40/17)).  While the obligations required of Russmedia in this case may indicate, to some, a landmark shift in the Court’s approach, the judgment does rely on the specific facts in the case and, specifically, the point that “sensitive” data, which effectively requires explicit consent, is in issue. In principle, this could be relevant to other forms of sensitive content, notably non-consensual intimate images (NCII). Certainly, it re-emphasises data protection as a route for victims’ redress, if not preventing harm in the first place.

 

The ruling clarifies that a range of activities typically carried out by platforms - structuring, categorizing, and monetizing user content, can amount to determining “the purposes and means of processing personal data”, the test for responsibility as a controller under the GDPR (article 4 GDPR). In taking this approach, it differed from the Opinion of its Advocate-General (AG’s Opinion, para 120).  The Court noted that the definition of controller in the GDPR is broad – and this is to support the protection of individuals’ fundamental rights to privacy and data protection. Once a body is a controller, that body must be able to demonstrate compliance with the data protection principles, and take appropriate technical and organisational measures to ensure data processing is carried out in accordance with the GDPR. 

 

Here, some of the points that the Court relied on to determine that Russmedia was a joint controller could well be relevant to other services and not just online marketplaces. For example, many sites have broad terms of service similar to those the Court highlighted here; other services also allow anonymous posting and a key feature of many services is the making available of that content for advertising revenue purposes, as well as controlling how content is promoted. (Note the decision of the court in YouTube and Cyanado (Joined Cases C-682/18 and C-683/18), which suggested that automated content curation did not mean that a service is not neutral, is not directly relevant here as it relates to the conditions for maintaining intermediary immunity – and see Russmedia, AG’s Opinion, para 155)  It is unclear how many of these criteria need to be present for a service to constitute a controller in relation to the personal data in third party content it publishes (though the Court seems to list them as alternatives, suggesting any of them would suffice), or whether less far-reaching terms of service may be sufficient to stop a platform being a joint controller.  Where these conditions are satisfied, its impact need not be limited to advertising but to organic content containing third party personal data too.

 

The Court’s confirmation that the clear wording of the e-Commerce Directive, excluding the Data Protection Directive (the predecessor legislation to the GDPR) from its scope, meant that an intermediary cannot escape its own data protection responsibilities does not affect immunity from liability in respect of unlawful content.  Note that this decision was based on the wording of the e-Commerce Directive. This language has not been carried over to the DSA, which is expressed to operate without prejudice to, inter alia, the GDPR. It is not clear if or how this would change the Court’s interpretation. Immunity provisions from the e-Commerce Directive have been carried across to the DSA (albeit with a “carve out” in respect of consumer law in Article 6(3) DSA). While the EDPB has published guidance on the interplay of the GDPR and the DSA, it has looked at the question of the impact of the DSA requirements on data protection rather than the impact of data protection on the DSA.

 

The judgment suggests that services should design checks into their services to ensure compliance with the data protection obligations including pre-publication checks as to whether sensitive data is included and to check the identity of the person posting the material. Of course, while some sorts of posts (eg NCII) clearly constitute sensitive personal data, the outer edges of this category might not be clear cut. The Court here noted that the category should be interpreted broadly (para 52). It could be that some of the obligations could be passed on to the user uploading the advert through terms of service, though this might be capable of being abused by some users.  Further, the CJEU expects the site to prevent third party scraping so far as is possible – the judgment does not introduce strict liability in this regard.  What technical measures would be sufficient in practice remains uncertain.   This is very different from the reactive response required to maintain immunity under the e-Commerce Directive – and which has been the dominant framing until now. Assuming the position on immunity does not change, services may have to implement new systems, probably including automated tools and may ultimately affect choice of business model for some services.

 

There are questions about how this ruling impacts the DSA. How does a pre-check system differ from general monitoring. General monitoring is prohibited under Article 8 DSA (though specific monitoring is not)? The CJEU stated that systems to ensure GDPR compliance could not be classified as “general monitoring” (para 132) – but did not explain this statement any further. There is an argument to say that all content will need to be scanned to identify that which contains sensitive personal data – and by contrast to checking against a database of known CSAM images, for example, which might be considered specific monitoring, this is a more open ended obligation. It is unclear whether there are other routes to pre-check which do not involve content scanning.  The requirements to check whether the person posting the personal data is the person to which the data relates (or is otherwise lawfully processing) may make, for example, anonymity difficult to maintain and it is unclear what level of identity verification would be acceptable.  There are also questions about how this system of pre-checks affects the neutrality of the platform and consequently the possibility for the platform to claim immunity (in respect of other claims relating to the content) under Article 6 DSA.

 

The position in the UK may be slightly different, however. Section 6(1) European Union (Withdrawal) Act provides that decisions of the CJEU post-dating 31 December 2020 do not bind UK courts although they may have regard to such judgments. The provisions which would have had the effect of removing the status of binding precedent from decisions of the CJEU made on or before that date have now not been brought into force (but they remain on the statute book), as the Labour Government revoked the relevant commencement regulations.  Furthermore, old case law from the Northern Irish courts (pre-dating Brexit), CG v. Facebook, suggested the the e-Commerce Directive (the relevant law at the time) could apply to data protection claims.

Tuesday, 7 October 2025

The General Court of the European Union upholds the Data Privacy Framework

 


 

Dr Samira Allioui, Research fellow, Centre d'études internationales et européennes, Université de Strasbourg

Photo credit: Ibrahim Rustanov, via Wikimedia Commons

French Member of Parliament Philippe Latombe, who also sits on the board of the French data protection authority, the Commission Nationale de l’Informatique et des Libertés, brought an action, in his personal capacity, in the General Court of the European Union calling for the annulment of the Data Privacy Framework. On Wednesday, September 3, the General Court of the European Union dismissed MP Philippe Latombe's appeal against the Data Privacy Framework adequacy decision, the agreement governing data transfers between the EU and the United States, at the heart of a long legal saga. Since Latombe's case was brought as an action for annulment and not as a preliminary question by a national court, he not only had to prove that the deal was substantively wrong, but also that he was directly affected in order to be entitled to bring an action at all.

The DPF is the successor to the EU-U.S. Privacy Shield (the Privacy Shield), after the adequacy decision on the EU side adopted in light of the Privacy Shield was declared invalid in 2020 by the CJEU following litigation by privacy advocate Maximilian Schrems, acting through not-for-profit NOYB (none of your business), in the landmark case of Schrems II. The Privacy Shield was the successor to the EU-U.S. Safe Harbor Framework, which was declared invalid in 2015 in Schrems I. In response, the United States established the Data Protection Review Court (DPRC). The European Commission approved the DPF in July 2023.

Personal data transferred from the European Union to third countries is no longer subject to the GDPR in those countries. This requires compliance with certain safeguards prior to transfer, with the aim of ensuring adequate data protection in the destination country. An adequacy decision is one of the mechanisms for ensuring this protection, and the GDPR provides for a Commission decision recognizing, after a thorough examination, that the law of a third country offers guarantees deemed adequate.

It is clear that even though American law has since evolved towards greater oversight of intelligence services, one particular issue has long been a problem in US-EU relations: access to effective remedies in the United States, allowing Europeans affected by transatlantic transfers to challenge the processing of their data. This issue was already the subject of progress in 2022 with Executive Order 14086, which paved the way for a challenge mechanism. This allowed the European Commission to adopt a new adequacy decision in 2023, the very one that is being challenged in the Latombe case.

The new ruling

This new ruling is therefore part of a series of developments relating to transatlantic transfers. The fundamental issue is the adequacy of the safeguards provided abroad, and therefore the degree of requirement that the European Union must have vis-à-vis the states to which data are transferred. However, on this point, the reasoning followed by the General Court of the European Union contrasts sharply with the rulings handed down by the Court of Justice of the European Union in the Schrems I and II cases. In the Schrems II ruling, the Court insisted that "the third country must offer guarantees to ensure an adequate level of protection essentially equivalent to that guaranteed in the European Union," while also using the terms "essential equivalence" and "substantial equivalence" interchangeably. Only the latter expression—"substantial equivalent"—is adopted by the General Court, although it gives it a scope that appears to be weakened.

In its assessment of the adequacy of American law, the Court appears to be less demanding than the Court of Justice. In recent years, the latter has initiated a particularly demanding jurisprudential movement in matters of personal data protection, giving rise to numerous tensions with Member States, which themselves struggle to comply with the requirements of the Court of Justice. While the Schrems I and II judgments were perfectly in line with this trend, the Court's judgment seems to propose another direction, perhaps more favorable to national security issues.

In any case, in its analysis of the conditions to be met to conclude that foreign law is adequate, the Court draws its inspiration primarily from the ECtHR case of Big Brother Watch v. United Kingdom. On the contrary, the major decisions of the CJEU – we are thinking in particular of the La Quadrature du Net I case – dealing with the activities of intelligence services are not considered relevant by the Court. The latter were particularly demanding, where the ECtHR recognizes certain margins of appreciation for States, in particular due to the very sensitive nature of intelligence and national security issues.

The next developments?

Since this is a General Court ruling, it is likely that there will be an appeal to the CJEU. Let us assume, however, that the Court upholds the existing adequacy decision. Another fundamental question would inevitably arise. The General Court is not taking into account recent developments in US law, particularly since the return of President Donald Trump. However, some of the guarantees applicable in US law, highlighted by the General Court, already appear to be weakened. Let us give an example: the Privacy and Civil Liberties Oversight Board (PCLOB) which role is fundamental, particularly because it is involved in the appointment of members of the Data Protection Review Court, whose independence and impartiality are discussed at length in the General Court's ruling. However, President Donald Trump has terminated the terms of several PCLOB members, preventing it from functioning. The impact this could have on transatlantic data transfers has already been the subject of debate in the European Parliament and the United States. The saga surrounding transatlantic data transfers could thus, despite the Court's ruling, be the subject of new twists and turns.

Today, more than 2,800 US companies are DPF-certified, allowing them to continue relying on the adequacy decision (Article 45 of the GDPR) as the legal basis for their transatlantic transfers Data Privacy Framework. However, while this prevents massive disruptions to data flows, the stability of the framework is not guaranteed. It must be actively monitored, given regulatory or judicial events that may disrupt it.

Plus, if Mr. Latombe can still appeal the General Court's decision to the CJEU, it is uncertain whether the CJEU would follow the General Court's reasoning. It should be recalled here that the CJEU has in the past held that adequacy decisions must be assessed on the basis of the legal and factual situation at the time of the appeal, while in Latombe, the General Court departed from this standard and stated that decisions must be assessed on the basis of the situation at the time of their adoption (i.e., under the previous administration). Finally, the European Commission could, in theory, decide to suspend or repeal the DPF if it considers in the future that US law no longer provides sufficient protection for European Economic Area personal data.

Saturday, 21 June 2025

Must cases be unfounded to qualify as SLAPPs? What unfoundedness means for GDPR-based SLAPPs

 


 

Léna Perczel, Legal Officer, Political Freedoms Program, Hungarian Civil Liberties Union

 

Photo credit: Dirk Beyer, via Wikimedia commons

 

Countering SLAPPs (Strategic Lawsuits Against Public Participation) has been at the forefront of political, legal and academic discourse over the past two years. The most significant legislative development has been the European Union’s Anti-SLAPP Directive (Directive), backed by a soft law instrument, the Council of Europe’s Anti-SLAPP Recommendation (CoE Recommendation).

But what exactly qualifies as a SLAPP? The Directive, which is limited to cases with cross-border elements, defines the term and treats unfoundedness as a key criterion. In contrast, the CoE Recommendation treats it as just one of several indicators for identifying such lawsuits. While both instruments acknowledge it as a factor, Hungary’s example for General Data Protection Regulation (GDPR) based SLAPP cases suggest it is not necessarily a defining feature. 

In this blog post, I aim to explore—through the lens of this Hungarian case group—whether assessing the SLAPP nature of a case based on unfoundedness could render legal efforts to combat SLAPPs ultimately ineffective. This issue is particularly pressing in Hungary, especially in cases where the press is required to comply with GDPR obligations—yet no benchmark has been established by the European Court of Human Rights (ECtHR, the Court) to date.

 

The GDPR’s burden on the press in Hungary

 

The SLAPP phenomenon gained attention in Hungary when individuals with economic power repeatedly attempted to erase their names and wealth from the media, invoking rights enshrined in the GDPR. This conduct demonstrated that the GDPR can become a powerful tool for SLAPPs when interpreted in a strictly formal manner. By placing the responsibility on data controllers, the GDPR established a rigid procedural framework, obliging them to comply with extensive administrative safeguards. The press becomes a data controller simply by gathering and storing someone’s name, even without publishing it. As a result, a journalist must begin preparing extensive documentation from the moment they start investigating an individual. Unlike commonly used legal remedies against the press, such as press rectification procedures or defamation claims, violations of the GDPR can stand regardless of whether the article is false or reputationally harmful, thus regardless of the journalist’s ethical conduct. Adhering to such duties makes reporting on public matters increasingly difficult. In fact, beyond the administrative burden itself, informing data subjects about articles in preparation can entirely undermine investigative journalism. Data subjects may resort to dismissing evidence or objecting to the data processing, effectively blocking the publication of articles. 

Despite Article 85  of the GDPR, the Hungarian government has not reconciled the GDPR with the freedom of the press, which could have led to exemptions from certain GDPR obligations (such as the strict notification obligations imposed on data controllers, explained below). This lack of reconciliation has created a constitutional loophole: a legal grey zone that reflects the state's failure to fulfil its positive obligation to protect the press. In the absence of clear legal provisions, and due to this unresolved tension, the responsibility has fallen on those applying the law to balance the competing rights of freedom of expression and data protection. 

The Hungarian National Authority for Data Protection and Freedom of Information (DPA) was the first forum in Hungary to detail these obligations, requiring data controllers to inform each data subject preliminarily, proactively, and individually about the data being processed and its legal basis—recognizing only legitimate interest under Article 6(f) of the GDPR as a valid ground for processing. This was despite Forbes’ argument that publishing on public matters falls within the constitutional duty of the press, thus the ground for processing should be public interest (Article 6(e) of the GDPR). This means that journalists, whose work consists primarily of processing personal data, must notify each data subject in advance while conducting their reporting, including during initial research. Compliance is required regardless of whether the data subject has initiated any procedure, making this an even more effective SLAPP tool. In its decision, the DPA entirely failed to consider how such a disproportionate workload could stifle the press. Had public interest been accepted as a legal basis for processing, these notification obligations would not have been imposed on journalists.

 

The manifestation of GDPR-based SLAPPs through legal proceedings against Forbes

 

In 2019, the owners of a Hungarian energy drink company—a family business that gained prominence partly through public funding—initiated proceedings after Forbes included them in its annual wealth rankings. Their inclusion prompted GDPR-based claims.

First, they argued that the press lacked a legal basis for publishing their personal data, and that the data processing therefore constituted a violation of their rights (primary claims). Second, they contended that even if legitimate interest were accepted as the legal basis, the press had failed to meet its procedural obligations—such as informing the data subjects about the legitimate interest assessment (ancillary claims).

Both GDPR-based claims proceeded in parallel before the civil court and the DPA. Initiating multiple proceedings simultaneously by the same claimant is a typical characteristic of SLAPPs, intended to increase pressure on the target. 

In this blog post, I will focus on the DPA case. However, it is important to illustrate the SLAPP nature of these proceedings by noting that, in the civil case, the claimants requested a preliminary injunctionwhich the court granted (The Metropolitan Court ordered the interim measure in its decision no. 25.Pk.23.297/2019/17-I. The Appellate Court and the Supreme Court upheld the decision in their decisions 2.Pkf.25.030/2020/2. and Pfv.IV.20.395/2020/4 respectively. The decision of the Supreme Court is currently before the EctHR).

As a result, until the court ruled on the merits of the case whether Forbes had a legal basis for processing the data, the magazine was prohibited from publishing any information about the family members—amounting to de facto censorship for more than four years (The interim measure was repealed by the first-instance court’s non-final decision, decision no. 25.P.21.067/2023/21).

It was in the DPA procedure initiated by this claimant that the authority first established a formal interpretation of the GDPR, as explained above. Although the DPA’s decision was challenged in the administrative courts—emphasizing the claimants’ economic position and the press’s constitutional duty—the Supreme Court, while acknowledging that “it is of particular importance to inform the public about the use of public funds for the development of private enterprises,” and that such reporting falls under the press’s watchdog role, nevertheless found no grounds for exempting the press. It affirmed that the press is required to fulfill notification obligations when relying on legitimate interest as a legal basis for data processing.

 

The definitions’ cornerstone: unfoundedness

 

Effectively countering SLAPPs requires clear definitions. This section examines those offered by the Directive and the CoE Recommendation, which both include unfoundedness. Unfoundedness has been central to debates over the Directive’s initial draft. Many still argue that it imposes an unnecessary limitation on what constitutes a SLAPP, potentially hindering the effectiveness of action.

The CoE Recommendation describes unfoundedness as one of several indicators that could help in recognizing SLAPPs, allowing a broader margin of appreciation for legal interpreters. In contrast, the Directive’s scope is limited to unfounded claims.

According to its title, the Directive operates within a dichotomy, providing safeguards against (a) manifestly unfounded claims or (b) abusive court proceedings. While it does not define “manifestly unfounded” or “unfounded”, it expands the definition of “abusive court proceedings against public participation.”

According to the definition, “‘abusive court proceedings against public participation’ mean court proceedings which are not brought to genuinely assert or exercise a right, but have as their main purpose the prevention, restriction or penalisation of public participation, frequently exploiting an imbalance of power between the parties, and which pursue unfounded claims”. Although the title and scope of the Directive suggests (a) and (b) as alternating categories (as indicated by the conjunction “or”), the definition of abusive court proceedings introduces “and,” requiring unfoundedness as part of both categories. This raises the question of whether the two are truly alternatives. (Note: most interpretations suggest that (a) and (b) are indeed alternatives, however, that contradicts the grammatical interpretation.)

One understanding could be that the Directive places “manifestly unfounded” claims and “abusive court proceedings” on a spectrum—with “manifestly unfounded”, as ab ovo unfounded at one end and “abusive” cases, potentially less clearly unfounded, further along that continuum. However, this interpretation creates additional uncertainty for courts in determining where to position a given case on that spectrum.

An interpretation aligned with paragraph 29 of the Directive’s preamble—which provides context for its operative definitions—suggests that only proceedings that are either fully or partially unfounded can be classified as abusive. If this is accepted, the Directive effectively collapses its own dichotomy, making unfoundedness the sole defining element and rendering the distinction between the two categories functionally meaningless. 

This distinction becomes most relevant when determining the appropriate safeguards. Defendants facing manifestly unfounded claims benefit from an early dismissal mechanism, whereas those facing abusive court proceedings—though still partially unfounded—must endure the full process and may only seek reparation after proceedings conclude. The legal uncertainty leaves the court’s decisions subject to accusations of cherry-picking. 

Despite earlier debates over elements of the definition and criticism of the distinction between manifestly unfounded claims and abusive court proceedings in terms of available remedies, this differentiation has persisted, along with the ambiguity surrounding 'unfoundedness.' The lack of a clear definition has left stakeholders in a state of legal uncertainty.

 

Unfoundedness in the context of GDPR-based SLAPPs

 

When examining what unfoundedness means for GDPR-based SLAPPs in Hungary, it is essential to continue distinguishing between the primary claim and the ancillary claims.

As discussed previously, the family members raised two distinct claims: the primary claim, namely the lack of legal basis for processing personal data, and the ancillary claims, concerning the failure to adhere to its procedural obligations.

First, let us examine the primary claim. The family argued that, in the absence of a legal basis, Forbes had no right to publish their personal data. The courts ultimately held that the press had a legitimate interest in reporting on the family members, given their receipt of public funds. However, as the GDPR was a relatively new legal instrument and no relevant precedent existed at the time, the legal question was considered unsettled until a final judgment had been delivered. Consequently, until then, the possibility of classifying such claims as unfounded could not have been seriously contemplated.

And although this decision enabled the press to report on the family in these circumstances, the publication of the family members’ personal data in other contexts will likely continue to be assessed on a case-by-case basis, meaning such claims may not be considered ab ovo (manifestly) unfounded. The case illustrates that unsettled legal questions are inherently difficult to classify as unfounded, allowing SLAPP proceedings to persist and continue imposing a burden on the press.

Second, when examining the ancillary claims, defining "unfoundedness" becomes even more ambiguous. Article 85 of the GDPR states: “Member States shall by law reconcile the right to the protection of personal data pursuant to this Regulation with the right to freedom of expression and information.” From a legal positivist perspective, the absence of implementing legislation under Article 85 of the GDPR has significant consequences. Since no national laws have been adopted to clearly define the boundaries of such reconciliation (for example, by exempting the press from the obligation to preliminarily, individually, and proactively inform data subjects, that is required of other data controllers like big companies), individuals may lawfully invoke GDPR provisions even in ways that restrict journalistic activities or the freedom of the press. As a result, legal claims based on alleged violations of GDPR obligations by the press cannot automatically be deemed unfounded. Therefore, under the Directive’s definition, such claims cannot be classified as SLAPPs.

However, the legal positivist approach is problematic, as it completely disregards context and fundamental rights aspects. From a fundamental rights perspective, it is contrary to freedom of the press to require full compliance with all GDPR-based duties, as it significantly hinders the press’s constitutional role. The lack of reconciliation in Hungary therefore constitutes a constitutional loophole, and exploiting such a loophole should never constitute a well-founded claim: applying the law in a way that contradicts the state’s positive obligations to protect the press and disproportionately hinders its operation is inherently problematic. It also disregards the state’s obligations stemming from the GDPR itself, as it uses mandatory language.

Furthermore, at the European level, the varying degrees of reconciliation between freedom of the press and data protection under Article 85 make it increasingly difficult and uncertain to draw a consistent line around unfoundedness.

 

The European interest

 

While the lawsuits against Forbes will most likely fall outside the Directive’s scope—due to their domestic nature and the fact that the procedure based on the DPA’s decision is administrative—interpreting the Directive’s definition remains relevant, particularly for future cross-border cases that do fall within its scope. Furthermore, the Directive sets only a minimum standard, meaning that national transpositions can expand its scope to include domestic cases, where unfoundedness would still be a determining criterion. Additionally, early-dismissed cases will likely reach the ECtHR, whether brought by the press or the claimant—ultimately forcing the Court to engage with the Directive’s interpretation. The relevance of interpreting the definition of the Directive extends beyond GDPR-based SLAPPs, as other claims that lack precedent or exploit constitutional loopholes can fall outside the scope of the Directive due to the definition. 

As the CoE Recommendation’s scope is not limited to cross-border claims, assessing the current cases from its perspective is highly relevant. In fact, since the ECtHR was established by the Council of Europe, the CoE Recommendation remains an important interpretive source when the Court rules on SLAPP-related cases.

These GDPR-based cases highlighted that the prolonged proceedings and ongoing legal uncertainty drain press resources and have already created a chilling effect. However, within the Directive’s framework, GDPR-based SLAPPs may not even fit the definition of “abusive court proceedings”. Even if they do, it is unlikely they would qualify as “manifestly unfounded,” placing them outside the scope of the early dismissal mechanism. As a result, the Directive might fail to effectively combat SLAPPs, especially the ones emerging in legal grey zones—even when defendants (the press) ultimately win. To put it more bluntly, the narrow definition could completely thwart the objective of the Directive and jeopardize its long-term legitimacy.

While broadening the definition of manifestly unfounded claims carries risks, it is unlikely that the drafters intended early dismissal to apply only in rare cases. The CoE Recommendation’s approach appears to offer a more suitable reference point for identifying SLAPPs. But let us wait and see what the ECtHR has to say. Until then, legal uncertainty continues to shield SLAPPs under the guise of procedural compliance. 

 

Acknowledgements: I would like to sincerely thank Beatrix Vissy and Tivadar Hüttl for their valuable insights and contributions.


Monday, 16 December 2024

As long as the system of remedies and the objectives are not undermined: The Court of Justice on GDPR enforcement (Case C-21/23, Lindenapotheke)

 

 


 

Alessandra Fratini and Giorgia Lo Tauro, Fratini Vergano European lawyers

Photo credit: via Wikimedia Commons


Introduction

On 4 October 2024, the Grand Chamber of the Court of Justice of the European Union issued its judgment in Lindenapotheke (Case C-21/23), a case concerning the online sale of pharmacy-only medicinal products and its implications as regards GDPR compliance. In its request for a preliminary ruling, the German Federal Court of Justice (Bundesgerichtshof) raised two questions on the interpretation of the GDPR. While acknowledging the importance of the second question on the meaning of ‘data concerning health’, this post focuses on the first one, concerning the compatibility of the system of remedies established in Chapter VIII GDPR with other remedies under national law. The paragraphs below, after a short overview of the facts of the case and the preliminary questions, review the main findings of the Advocate General and of the Court of Justice on the first question and conclude by placing the judgment within the rising trend of addressing the challenges of digital markets through a broader enforcement of EU digital regulation.

 

Facts of the case and questions referred

The main proceedings involved two competitors operating pharmacies in Germany, ND and DR. ND, which operates a pharmacy under the trade name ‘Lindenapotheke’, has been selling pharmacy-only medicinal products via the ‘Amazon-Marketplace’ online platform since 2017.

DR brought an action before the German Regional Court seeking an order for ND to cease selling pharmacy-only medicinal products via the online marketplace on the basis that such marketing constituted an unfair commercial practice in so far as it was pursued in breach of Article 9 GDPR, which requires that the data subject’s prior explicit consent be obtained for the processing of data concerning health. According to the German law against unfair competition, in fact, “anyone who infringes a statutory provision intended, inter alia, to regulate market conduct in the interest of market players acts unfairly where that infringement is capable of having an appreciable adverse effect on consumers, other market players or competitors”; such an infringement constitutes a prohibited unfair commercial practice enabling any competitor to claim an injunctive relief (paras. 21-23 of the judgment). The Regional Court upheld the action and the subsequent appeal brought by ND was dismissed by the Higher Regional Court, which held that such an online marketing was contrary to the national law against unfair competition. ND lodged an appeal on a point of law before the German Federal Court of Justice, which raised a request for a preliminary ruling on the interpretation of Chapter VIII and Article 9(1) GDPR, but also Article 8(1) of Directive 95/46 (the previous data protection Directive) before the Court of Justice.

Question 1

With its first question, the referring court asked the Court of Justice whether a competitor, who is not a data subject within the meaning of Article 4(1) GDPR, has standing to bring an action before the civil courts against the alleged infringer of the GDPR, on the basis that the alleged infringement falls within the prohibition of unfair commercial practices. The referring court noted that the provisions of Chapter VIII GDPR do not mention, nor do they explicitly exclude, the possibility for competitors to bring an action against an undertaking, where the infringement of data protection law constitutes an unfair commercial practice (para. 35). The referring court underlined the uncertainty of the situation and highlighted both the risks of recognising such a possibility for competitors, in terms of potential encroaching on the powers of the supervisory authorities and ensuing divergences, and its potential benefits in terms of ‘effet utile’ to ensure the highest level of data protection (paras. 36-39).

Question 2

With its second question, the referring court asked the Court of Justice to clarify whether the data which customers must enter on the online sales platform when ordering medicinal products (such as name, delivery address and information required for individualising the medicinal products ordered) constitute ‘data concerning health’ within the meaning of Article 8(1) of Directive 95/46 and Article 9(1) GDPR. In particular, the doubts of the referring court concerned non-prescription medicinal products, since these may be intended not necessarily for the customers but for third parties, who may not be identifiable (para. 41).

In the opinion of the referring court, the questions of a competitor’s standing to bring proceedings (para. 39) and of the notion of ‘special categories of personal data’ (para. 43) had not been clarified by the case-law of the Court of Justice and warranted its request for a preliminary ruling.

 

The Opinion

In his Opinion, Advocate General Szpunar first changed the order of the proposed questions, as he considered that if the answer to the second one were to be negative, there would be no need to answer the first one (para. 31 of the Opinion). Addressing the second question at the outset, the AG suggested to answer that “the data of the customers of a pharmacist which are transmitted when an order is placed on an online sales platform for pharmacy-only but non-prescription medicines do not constitute ‘data concerning health’ within the meaning of Article 4(15) and Article 9 of the GDPR, in so far as only hypothetical or imprecise conclusions as to the health status of the person placing the online order may be drawn, which it is for the referring court to verify” (para. 54).

In the light of that proposed negative answer, the first question was dealt with in the Opinion only for the sake of completeness. Having acknowledged that the GDPR confers no rights on undertakings and their competitors, as that regulation grants rights only to data subjects (paras. 79-81), the AG assessed whether the GDPR system of remedies has to be seen as an exhaustive system, in the sense that it precludes undertakings from relying on a GDPR infringement in the context of other remedies provided for by national law (paras. 82-89).

First, he noted that the action at issue in the main proceedings was not based on a GDPR infringement, but took such an infringement into account in an incidental manner. The Court already accepted, in its judgment in Meta Platforms and others (2023), that data may be taken into account in an incidental manner and that an infringement of the GDPR may constitute an infringement of competition law (paras. 90-91), and the AG considered that was applicable to the present case (para. 91). Second, as regards the interaction between national actions in which the GDPR can be invoked incidentally and the GDPR system of remedies, the AG observed that the former should be accepted only on condition that they do not undermine the GDPR system of remedies or the attainment of its objectives (para. 95). In the present case, since an action brought by an undertaking against a competitor is not intended to ensure respect for the data subjects’ rights but pursues another objective, the actions made available to data subjects by the GDPR system of remedies are preserved and may still be exercised in those circumstances (paras. 100-101). Furthermore, in the AG’s view, the objectives pursued by the GDPR, such as the high level of protection of natural persons and the consistent and homogenous application of the data protection rules (recital 10), are not threatened (but, as for the high level of protection, actually strengthened) by the possibility afforded to an undertaking to bring an action for an injunction against a competitor based on the prohibition of acts of unfair competition, in reliance on a GDPR infringement by that competitor (paras. 103-104). Finally, the AG noted that, far from being undermined, the effectiveness of the GDPR would be reinforced by the fact that compliance with its provisions may also be enforced in judicial proceedings distinct from those within its system of remedies. Accordingly, he concluded that such national remedies may exist alongside the system established by the GDPR (paras. 105-108).

 

The Judgment

The Court of Justice considered the questions in the order they were raised by the referring court and departed from the Opinion with regard to the answer to the second question.

To address the first question, the Court interpreted the relevant provisions of Chapter VIII GDPR by relying on their wording, the context and the objectives pursued by the GDPR (para. 52 of the judgment). As to the wording, the Court noted that not only the provisions of Chapter VIII do not expressly rule out the possibility for additional national remedies, but the rights provided for by Article 77(1), Article 78(1) and Article 79(1) are ‘without prejudice’ to any other administrative, judicial or non-judicial remedy (para. 53). When it comes to the context, while it agreed with the AG that only data subjects are beneficiaries of the GDPR protection, the Court noted in addition that the infringement of its substantive provisions is also liable to adversely affect third parties (in this sense, it referred to the right to compensation provided for by Article 82(1); para. 55). The Court recalled that it had already held that the infringement of data protection rules may at the same time give rise to an infringement of rules on consumer protection or unfair commercial practices (judgment in Meta Platforms Ireland, 2022, para. 78) and may be “a vital clue” in the assessment of an abuse of a dominant position (judgment in Meta Platforms and others, 2023, para. 47) (para. 55). It also noted the importance of access to personal data and the ability to process such data, which “have become a significant parameter of competition between undertakings in the digital economy”, so that it may be necessary to consider rules on data protection when enforcing competition law and the rules on unfair commercial practices (para. 56).

Interestingly, while the above would have been sufficient to interpret Chapter VIII in the light of the context, the Court went further to consider the margin of discretion enjoyed by Member States in the implementation of the GDPR. In this respect, even though the GDPR “seeks to ensure the harmonisation of national legislation on the protection of personal data which is, in principle, full, the fact remains that several provisions of that regulation expressly make it possible for Member States to lay down additional, stricter or derogating national rules, which leave them a margin of discretion as to the manner in which those provisions may be implemented (‘opening clauses’)”(para. 57). After referring to its judgment in Meta Platforms Ireland (2022, para. 57), which concerned a provision of the GDPR (Article 80) expressly containing an opening clause, the Court added: “It is true that the provisions of Chapter VIII of the GDPR do not specifically provide for such an opening clause which would expressly allow Member States to make it possible for a competitor of an undertaking which allegedly infringes the substantive provisions of that regulation to bring an action in order to put an end to that infringement. However, it follows from the wording and context of the provisions of Chapter VIII (…) that, by adopting that regulation, the EU legislature did not intend to bring about an exhaustive harmonisation of the remedies available in respect of infringements of the provisions of the GDPR and, in particular, did not wish to rule out the availability of such remedies to competitors of the person allegedly responsible for an infringement of the laws protecting personal data, on the basis of national law relating to the prohibition of unfair commercial practices” (paras. 59-60, emphasis added).

In the Court’s view, that interpretation was corroborated by the GDPR objectives (i.e., ensuring a consistent and high level of protection of natural persons with regard to the processing of personal data and removing obstacles to the flow of such data within the EU; strengthening of the rights of data subjects and of the obligations of those who process and determine the processing of data, as well as equivalent powers for monitoring and ensuring compliance with the rules for the protection of personal data and equivalent sanctions for infringements in the Member States; providing natural persons in all Member States with the same level of legally enforceable rights and obligations and responsibilities for data controllers and processors, and ensuring consistent monitoring of the processing of personal data, and equivalent sanctions in all Member States) (para. 61). It found therefore that the possibility of national remedies like those at stake does not undermine those objectives but actually enhances the effectiveness of the GDPR provisions (para. 62). These national remedies are in addition to those of Chapter VIII and pursue an objective (fair competition) which is different from those pursued by the GDPR. In this context, as the German government observed, the uniform interpretation of the GDPR remains ensured by the preliminary ruling procedure under Article 267 TFEU (paras. 65-67). Furthermore, the Court held that national remedies aimed at ensuring fair competition undoubtedly contribute to compliance with the GDPR and, therefore, to strengthening the rights of data subjects: an application for injunctive relief filed by a competitor may also prove particularly effective in so far as it may prevent a large number of infringements of data subjects’ rights (paras. 69-70).

In the light of the above, the Court concluded that Chapter VIII does not preclude national legislation providing for such remedies to the benefit of competitors, while leaving to the referring court the assessment of whether the alleged infringement of the GDPR, in so far as it is established, also constitutes a breach of the prohibition of unfair commercial practices under the relevant national law (paras. 71-72).

As to the second question, suffice it to say that the Court, unlike the AG, found that the information which customers enter when ordering online pharmacy-only medicinal products, the sale of which does not require a prescription, does constitute ‘data concerning health’ even where it is “only with a certain degree of probability, and not with absolute certainty, that those medicinal products are intended for those customers” (para. 90). This, however, does not preclude it from being processed, in specific contexts, if the conditions for exemptions are met (para. 92), i.e. does not mean automatically that the processing is in breach of the GDPR.

 

Concluding remarks

The judgment in Lindenapotheke, as far as the first question is concerned, provides an interpretation of the GDPR system of remedies aimed at enhancing the effectiveness of data protection. The remarkable point of the reasoning is the emphasis placed on the margin of discretion recognised to Member States in implementing the GDPR, with a view to enhancing the protection afforded by it. While in Meta Platforms Ireland (2022) the Court could rely on the wording of the provision concerned (para. 59: “(…) Article 80(2) of the GDPR, which leaves the Member States a discretion with regard to its implementation. (…) Member States must make use of the option made available to them by that provision to provide in their national law for that mode of representation of data subjects”), in Lindenapotheke it admitted that Chapter VIII does not expressly provide for any opening clause allowing Member States to make available further remedies for actors other than data subjects invoking a GDPR infringement. However, by relying on the wording and context of Chapter VIII, as well as on the legislator’s intention and the GDPR objectives, it came to the conclusion that Member States can make available such remedies to competitors of the person allegedly responsible for an infringement of the laws protecting personal data, since such a possibility is not being ruled out by the GDPR system of remedies and its objectives (paras. 60-61). The Court’s interpretation actually seems to encourage Member States to make additional remedies available under national laws, insofar as they enhance the effectiveness of data protection (paras. 62 and 69).

From this perspective, the Court’s conclusion is significantly relevant when placed in the context of the ongoing debate on the GDPR (under) enforcement (Gentile-Lynskey, 2022), the shortcomings of its composite enforcement system (Hofmann-Mustert, 2024) and the Commission’s Proposal for a Regulation laying down additional procedural rules relating to the enforcement of the GDPR (2023). When it comes to the handling of complaints and the role of complainants, it has been observed that these vary significantly among Member States, which in turn results in a limitation of individual procedural rights (Hofmann-Mustert, 2024). Against this background, some rightly fear, by comparing this judgment with previous case law, that its “implications have the potential to be more disruptive” as regards the consistent enforcement of the GDPR and introduce “greater potential risks of interference between administrative and judicial enforcement” (van den Poel, 2024).

However, the implications of the judgment are less daunting when considering the GDPR enforcement in the broader context of digital legislation. The Commission Second Report on the application of the GDPR, published on 25 July 2024, makes it clear that “the development of digital regulations raises the need for close cooperation across regulatory fields. Such cooperation is all the more necessary since data protection issues increasingly intersect with questions of, for example, competition law, consumer law, digital markets rules, electronic communications regulation and cybersecurity. (…) data protection authorities are taking steps to ensure their actions are complementary and coherent with other regulatory fields”. In its statement of 3 December 2024 on the Commission Second Report, the EDPB also recognised that it “would support a holistic methodological approach for the next evaluation of the GDPR that explores the interplay between the GDPR and other EU digital legislation”.

The judgment fits into this context of growing institutional awareness of the need for a holistic and coordinated approach for the effective protection of personal data, in line with the “more ‘collaborative approach’” proposed by scholars for the enforcement of data protection, competition law and unfair competition law (Vandendriessche, 2024). The Court insists on the likely enhanced effective enforcement of the GDPR via national remedies aiming at other objectives (Holtz, 2024), by proposing an interpretation where the GDPR as such calls upon the Member States for its effective enforcement (again, paras. 60-61). By stating that “such an application for injunctive relief brought by a competitor may prove, like that brought by a consumer protection association, to be particularly effective in ensuring such protection, in so far as it is capable of preventing a large number of infringements of the rights of data subjects by the processing of their personal data” (para. 70), the Court recognises the preventive effect of a potential “private enforcement” (Opinion, para. 93) through remedies allowed under national laws, which has been read as an ‘incentive’ for market players to contribute to GDPR compliance (Vandendriessche, 2024). In this sense, the judgment embraces an emerging approach in the EU regulation of the digital environment, which is aimed at involving in the enforcement multiple actors of society as a whole. This approach is evident when it comes to making the online world safer and fairer, namely with the DSA: for example, as far as institutional actors are concerned, in the cooperation required between the Commission and the Digital Services Coordinators with regard to systemic risk mitigation measures (Peukert, 2024); even more, as far as non-institutional actors are concerned, in the mechanisms required to allow any user - individual or entity - to notify illegal content online, or in the required cooperation with “trusted flaggers” (Articles 16, 22, 35 DSA) (in this sense, see also Commission’s dialogue with Civil Society Organisations for implementing the DSA).

It remains to be seen whether such an approach succeeds in becoming consolidated through greater coordination of EU institutions and national authorities and greater awareness of society at large, alongside the required adjustments for the effective implementation of the remedies the GDPR grants to data subjects.