Showing posts with label data protection law. Show all posts
Showing posts with label data protection law. Show all posts

Saturday, 21 June 2025

Must cases be unfounded to qualify as SLAPPs? What unfoundedness means for GDPR-based SLAPPs

 


 

Léna Perczel, Legal Officer, Political Freedoms Program, Hungarian Civil Liberties Union

 

Photo credit: Dirk Beyer, via Wikimedia commons

 

Countering SLAPPs (Strategic Lawsuits Against Public Participation) has been at the forefront of political, legal and academic discourse over the past two years. The most significant legislative development has been the European Union’s Anti-SLAPP Directive (Directive), backed by a soft law instrument, the Council of Europe’s Anti-SLAPP Recommendation (CoE Recommendation).

But what exactly qualifies as a SLAPP? The Directive, which is limited to cases with cross-border elements, defines the term and treats unfoundedness as a key criterion. In contrast, the CoE Recommendation treats it as just one of several indicators for identifying such lawsuits. While both instruments acknowledge it as a factor, Hungary’s example for General Data Protection Regulation (GDPR) based SLAPP cases suggest it is not necessarily a defining feature. 

In this blog post, I aim to explore—through the lens of this Hungarian case group—whether assessing the SLAPP nature of a case based on unfoundedness could render legal efforts to combat SLAPPs ultimately ineffective. This issue is particularly pressing in Hungary, especially in cases where the press is required to comply with GDPR obligations—yet no benchmark has been established by the European Court of Human Rights (ECtHR, the Court) to date.

 

The GDPR’s burden on the press in Hungary

 

The SLAPP phenomenon gained attention in Hungary when individuals with economic power repeatedly attempted to erase their names and wealth from the media, invoking rights enshrined in the GDPR. This conduct demonstrated that the GDPR can become a powerful tool for SLAPPs when interpreted in a strictly formal manner. By placing the responsibility on data controllers, the GDPR established a rigid procedural framework, obliging them to comply with extensive administrative safeguards. The press becomes a data controller simply by gathering and storing someone’s name, even without publishing it. As a result, a journalist must begin preparing extensive documentation from the moment they start investigating an individual. Unlike commonly used legal remedies against the press, such as press rectification procedures or defamation claims, violations of the GDPR can stand regardless of whether the article is false or reputationally harmful, thus regardless of the journalist’s ethical conduct. Adhering to such duties makes reporting on public matters increasingly difficult. In fact, beyond the administrative burden itself, informing data subjects about articles in preparation can entirely undermine investigative journalism. Data subjects may resort to dismissing evidence or objecting to the data processing, effectively blocking the publication of articles. 

Despite Article 85  of the GDPR, the Hungarian government has not reconciled the GDPR with the freedom of the press, which could have led to exemptions from certain GDPR obligations (such as the strict notification obligations imposed on data controllers, explained below). This lack of reconciliation has created a constitutional loophole: a legal grey zone that reflects the state's failure to fulfil its positive obligation to protect the press. In the absence of clear legal provisions, and due to this unresolved tension, the responsibility has fallen on those applying the law to balance the competing rights of freedom of expression and data protection. 

The Hungarian National Authority for Data Protection and Freedom of Information (DPA) was the first forum in Hungary to detail these obligations, requiring data controllers to inform each data subject preliminarily, proactively, and individually about the data being processed and its legal basis—recognizing only legitimate interest under Article 6(f) of the GDPR as a valid ground for processing. This was despite Forbes’ argument that publishing on public matters falls within the constitutional duty of the press, thus the ground for processing should be public interest (Article 6(e) of the GDPR). This means that journalists, whose work consists primarily of processing personal data, must notify each data subject in advance while conducting their reporting, including during initial research. Compliance is required regardless of whether the data subject has initiated any procedure, making this an even more effective SLAPP tool. In its decision, the DPA entirely failed to consider how such a disproportionate workload could stifle the press. Had public interest been accepted as a legal basis for processing, these notification obligations would not have been imposed on journalists.

 

The manifestation of GDPR-based SLAPPs through legal proceedings against Forbes

 

In 2019, the owners of a Hungarian energy drink company—a family business that gained prominence partly through public funding—initiated proceedings after Forbes included them in its annual wealth rankings. Their inclusion prompted GDPR-based claims.

First, they argued that the press lacked a legal basis for publishing their personal data, and that the data processing therefore constituted a violation of their rights (primary claims). Second, they contended that even if legitimate interest were accepted as the legal basis, the press had failed to meet its procedural obligations—such as informing the data subjects about the legitimate interest assessment (ancillary claims).

Both GDPR-based claims proceeded in parallel before the civil court and the DPA. Initiating multiple proceedings simultaneously by the same claimant is a typical characteristic of SLAPPs, intended to increase pressure on the target. 

In this blog post, I will focus on the DPA case. However, it is important to illustrate the SLAPP nature of these proceedings by noting that, in the civil case, the claimants requested a preliminary injunctionwhich the court granted (The Metropolitan Court ordered the interim measure in its decision no. 25.Pk.23.297/2019/17-I. The Appellate Court and the Supreme Court upheld the decision in their decisions 2.Pkf.25.030/2020/2. and Pfv.IV.20.395/2020/4 respectively. The decision of the Supreme Court is currently before the EctHR).

As a result, until the court ruled on the merits of the case whether Forbes had a legal basis for processing the data, the magazine was prohibited from publishing any information about the family members—amounting to de facto censorship for more than four years (The interim measure was repealed by the first-instance court’s non-final decision, decision no. 25.P.21.067/2023/21).

It was in the DPA procedure initiated by this claimant that the authority first established a formal interpretation of the GDPR, as explained above. Although the DPA’s decision was challenged in the administrative courts—emphasizing the claimants’ economic position and the press’s constitutional duty—the Supreme Court, while acknowledging that “it is of particular importance to inform the public about the use of public funds for the development of private enterprises,” and that such reporting falls under the press’s watchdog role, nevertheless found no grounds for exempting the press. It affirmed that the press is required to fulfill notification obligations when relying on legitimate interest as a legal basis for data processing.

 

The definitions’ cornerstone: unfoundedness

 

Effectively countering SLAPPs requires clear definitions. This section examines those offered by the Directive and the CoE Recommendation, which both include unfoundedness. Unfoundedness has been central to debates over the Directive’s initial draft. Many still argue that it imposes an unnecessary limitation on what constitutes a SLAPP, potentially hindering the effectiveness of action.

The CoE Recommendation describes unfoundedness as one of several indicators that could help in recognizing SLAPPs, allowing a broader margin of appreciation for legal interpreters. In contrast, the Directive’s scope is limited to unfounded claims.

According to its title, the Directive operates within a dichotomy, providing safeguards against (a) manifestly unfounded claims or (b) abusive court proceedings. While it does not define “manifestly unfounded” or “unfounded”, it expands the definition of “abusive court proceedings against public participation.”

According to the definition, “‘abusive court proceedings against public participation’ mean court proceedings which are not brought to genuinely assert or exercise a right, but have as their main purpose the prevention, restriction or penalisation of public participation, frequently exploiting an imbalance of power between the parties, and which pursue unfounded claims”. Although the title and scope of the Directive suggests (a) and (b) as alternating categories (as indicated by the conjunction “or”), the definition of abusive court proceedings introduces “and,” requiring unfoundedness as part of both categories. This raises the question of whether the two are truly alternatives. (Note: most interpretations suggest that (a) and (b) are indeed alternatives, however, that contradicts the grammatical interpretation.)

One understanding could be that the Directive places “manifestly unfounded” claims and “abusive court proceedings” on a spectrum—with “manifestly unfounded”, as ab ovo unfounded at one end and “abusive” cases, potentially less clearly unfounded, further along that continuum. However, this interpretation creates additional uncertainty for courts in determining where to position a given case on that spectrum.

An interpretation aligned with paragraph 29 of the Directive’s preamble—which provides context for its operative definitions—suggests that only proceedings that are either fully or partially unfounded can be classified as abusive. If this is accepted, the Directive effectively collapses its own dichotomy, making unfoundedness the sole defining element and rendering the distinction between the two categories functionally meaningless. 

This distinction becomes most relevant when determining the appropriate safeguards. Defendants facing manifestly unfounded claims benefit from an early dismissal mechanism, whereas those facing abusive court proceedings—though still partially unfounded—must endure the full process and may only seek reparation after proceedings conclude. The legal uncertainty leaves the court’s decisions subject to accusations of cherry-picking. 

Despite earlier debates over elements of the definition and criticism of the distinction between manifestly unfounded claims and abusive court proceedings in terms of available remedies, this differentiation has persisted, along with the ambiguity surrounding 'unfoundedness.' The lack of a clear definition has left stakeholders in a state of legal uncertainty.

 

Unfoundedness in the context of GDPR-based SLAPPs

 

When examining what unfoundedness means for GDPR-based SLAPPs in Hungary, it is essential to continue distinguishing between the primary claim and the ancillary claims.

As discussed previously, the family members raised two distinct claims: the primary claim, namely the lack of legal basis for processing personal data, and the ancillary claims, concerning the failure to adhere to its procedural obligations.

First, let us examine the primary claim. The family argued that, in the absence of a legal basis, Forbes had no right to publish their personal data. The courts ultimately held that the press had a legitimate interest in reporting on the family members, given their receipt of public funds. However, as the GDPR was a relatively new legal instrument and no relevant precedent existed at the time, the legal question was considered unsettled until a final judgment had been delivered. Consequently, until then, the possibility of classifying such claims as unfounded could not have been seriously contemplated.

And although this decision enabled the press to report on the family in these circumstances, the publication of the family members’ personal data in other contexts will likely continue to be assessed on a case-by-case basis, meaning such claims may not be considered ab ovo (manifestly) unfounded. The case illustrates that unsettled legal questions are inherently difficult to classify as unfounded, allowing SLAPP proceedings to persist and continue imposing a burden on the press.

Second, when examining the ancillary claims, defining "unfoundedness" becomes even more ambiguous. Article 85 of the GDPR states: “Member States shall by law reconcile the right to the protection of personal data pursuant to this Regulation with the right to freedom of expression and information.” From a legal positivist perspective, the absence of implementing legislation under Article 85 of the GDPR has significant consequences. Since no national laws have been adopted to clearly define the boundaries of such reconciliation (for example, by exempting the press from the obligation to preliminarily, individually, and proactively inform data subjects, that is required of other data controllers like big companies), individuals may lawfully invoke GDPR provisions even in ways that restrict journalistic activities or the freedom of the press. As a result, legal claims based on alleged violations of GDPR obligations by the press cannot automatically be deemed unfounded. Therefore, under the Directive’s definition, such claims cannot be classified as SLAPPs.

However, the legal positivist approach is problematic, as it completely disregards context and fundamental rights aspects. From a fundamental rights perspective, it is contrary to freedom of the press to require full compliance with all GDPR-based duties, as it significantly hinders the press’s constitutional role. The lack of reconciliation in Hungary therefore constitutes a constitutional loophole, and exploiting such a loophole should never constitute a well-founded claim: applying the law in a way that contradicts the state’s positive obligations to protect the press and disproportionately hinders its operation is inherently problematic. It also disregards the state’s obligations stemming from the GDPR itself, as it uses mandatory language.

Furthermore, at the European level, the varying degrees of reconciliation between freedom of the press and data protection under Article 85 make it increasingly difficult and uncertain to draw a consistent line around unfoundedness.

 

The European interest

 

While the lawsuits against Forbes will most likely fall outside the Directive’s scope—due to their domestic nature and the fact that the procedure based on the DPA’s decision is administrative—interpreting the Directive’s definition remains relevant, particularly for future cross-border cases that do fall within its scope. Furthermore, the Directive sets only a minimum standard, meaning that national transpositions can expand its scope to include domestic cases, where unfoundedness would still be a determining criterion. Additionally, early-dismissed cases will likely reach the ECtHR, whether brought by the press or the claimant—ultimately forcing the Court to engage with the Directive’s interpretation. The relevance of interpreting the definition of the Directive extends beyond GDPR-based SLAPPs, as other claims that lack precedent or exploit constitutional loopholes can fall outside the scope of the Directive due to the definition. 

As the CoE Recommendation’s scope is not limited to cross-border claims, assessing the current cases from its perspective is highly relevant. In fact, since the ECtHR was established by the Council of Europe, the CoE Recommendation remains an important interpretive source when the Court rules on SLAPP-related cases.

These GDPR-based cases highlighted that the prolonged proceedings and ongoing legal uncertainty drain press resources and have already created a chilling effect. However, within the Directive’s framework, GDPR-based SLAPPs may not even fit the definition of “abusive court proceedings”. Even if they do, it is unlikely they would qualify as “manifestly unfounded,” placing them outside the scope of the early dismissal mechanism. As a result, the Directive might fail to effectively combat SLAPPs, especially the ones emerging in legal grey zones—even when defendants (the press) ultimately win. To put it more bluntly, the narrow definition could completely thwart the objective of the Directive and jeopardize its long-term legitimacy.

While broadening the definition of manifestly unfounded claims carries risks, it is unlikely that the drafters intended early dismissal to apply only in rare cases. The CoE Recommendation’s approach appears to offer a more suitable reference point for identifying SLAPPs. But let us wait and see what the ECtHR has to say. Until then, legal uncertainty continues to shield SLAPPs under the guise of procedural compliance. 

 

Acknowledgements: I would like to sincerely thank Beatrix Vissy and Tivadar Hüttl for their valuable insights and contributions.


Monday, 16 December 2024

As long as the system of remedies and the objectives are not undermined: The Court of Justice on GDPR enforcement (Case C-21/23, Lindenapotheke)

 

 


 

Alessandra Fratini and Giorgia Lo Tauro, Fratini Vergano European lawyers

Photo credit: via Wikimedia Commons


Introduction

On 4 October 2024, the Grand Chamber of the Court of Justice of the European Union issued its judgment in Lindenapotheke (Case C-21/23), a case concerning the online sale of pharmacy-only medicinal products and its implications as regards GDPR compliance. In its request for a preliminary ruling, the German Federal Court of Justice (Bundesgerichtshof) raised two questions on the interpretation of the GDPR. While acknowledging the importance of the second question on the meaning of ‘data concerning health’, this post focuses on the first one, concerning the compatibility of the system of remedies established in Chapter VIII GDPR with other remedies under national law. The paragraphs below, after a short overview of the facts of the case and the preliminary questions, review the main findings of the Advocate General and of the Court of Justice on the first question and conclude by placing the judgment within the rising trend of addressing the challenges of digital markets through a broader enforcement of EU digital regulation.

 

Facts of the case and questions referred

The main proceedings involved two competitors operating pharmacies in Germany, ND and DR. ND, which operates a pharmacy under the trade name ‘Lindenapotheke’, has been selling pharmacy-only medicinal products via the ‘Amazon-Marketplace’ online platform since 2017.

DR brought an action before the German Regional Court seeking an order for ND to cease selling pharmacy-only medicinal products via the online marketplace on the basis that such marketing constituted an unfair commercial practice in so far as it was pursued in breach of Article 9 GDPR, which requires that the data subject’s prior explicit consent be obtained for the processing of data concerning health. According to the German law against unfair competition, in fact, “anyone who infringes a statutory provision intended, inter alia, to regulate market conduct in the interest of market players acts unfairly where that infringement is capable of having an appreciable adverse effect on consumers, other market players or competitors”; such an infringement constitutes a prohibited unfair commercial practice enabling any competitor to claim an injunctive relief (paras. 21-23 of the judgment). The Regional Court upheld the action and the subsequent appeal brought by ND was dismissed by the Higher Regional Court, which held that such an online marketing was contrary to the national law against unfair competition. ND lodged an appeal on a point of law before the German Federal Court of Justice, which raised a request for a preliminary ruling on the interpretation of Chapter VIII and Article 9(1) GDPR, but also Article 8(1) of Directive 95/46 (the previous data protection Directive) before the Court of Justice.

Question 1

With its first question, the referring court asked the Court of Justice whether a competitor, who is not a data subject within the meaning of Article 4(1) GDPR, has standing to bring an action before the civil courts against the alleged infringer of the GDPR, on the basis that the alleged infringement falls within the prohibition of unfair commercial practices. The referring court noted that the provisions of Chapter VIII GDPR do not mention, nor do they explicitly exclude, the possibility for competitors to bring an action against an undertaking, where the infringement of data protection law constitutes an unfair commercial practice (para. 35). The referring court underlined the uncertainty of the situation and highlighted both the risks of recognising such a possibility for competitors, in terms of potential encroaching on the powers of the supervisory authorities and ensuing divergences, and its potential benefits in terms of ‘effet utile’ to ensure the highest level of data protection (paras. 36-39).

Question 2

With its second question, the referring court asked the Court of Justice to clarify whether the data which customers must enter on the online sales platform when ordering medicinal products (such as name, delivery address and information required for individualising the medicinal products ordered) constitute ‘data concerning health’ within the meaning of Article 8(1) of Directive 95/46 and Article 9(1) GDPR. In particular, the doubts of the referring court concerned non-prescription medicinal products, since these may be intended not necessarily for the customers but for third parties, who may not be identifiable (para. 41).

In the opinion of the referring court, the questions of a competitor’s standing to bring proceedings (para. 39) and of the notion of ‘special categories of personal data’ (para. 43) had not been clarified by the case-law of the Court of Justice and warranted its request for a preliminary ruling.

 

The Opinion

In his Opinion, Advocate General Szpunar first changed the order of the proposed questions, as he considered that if the answer to the second one were to be negative, there would be no need to answer the first one (para. 31 of the Opinion). Addressing the second question at the outset, the AG suggested to answer that “the data of the customers of a pharmacist which are transmitted when an order is placed on an online sales platform for pharmacy-only but non-prescription medicines do not constitute ‘data concerning health’ within the meaning of Article 4(15) and Article 9 of the GDPR, in so far as only hypothetical or imprecise conclusions as to the health status of the person placing the online order may be drawn, which it is for the referring court to verify” (para. 54).

In the light of that proposed negative answer, the first question was dealt with in the Opinion only for the sake of completeness. Having acknowledged that the GDPR confers no rights on undertakings and their competitors, as that regulation grants rights only to data subjects (paras. 79-81), the AG assessed whether the GDPR system of remedies has to be seen as an exhaustive system, in the sense that it precludes undertakings from relying on a GDPR infringement in the context of other remedies provided for by national law (paras. 82-89).

First, he noted that the action at issue in the main proceedings was not based on a GDPR infringement, but took such an infringement into account in an incidental manner. The Court already accepted, in its judgment in Meta Platforms and others (2023), that data may be taken into account in an incidental manner and that an infringement of the GDPR may constitute an infringement of competition law (paras. 90-91), and the AG considered that was applicable to the present case (para. 91). Second, as regards the interaction between national actions in which the GDPR can be invoked incidentally and the GDPR system of remedies, the AG observed that the former should be accepted only on condition that they do not undermine the GDPR system of remedies or the attainment of its objectives (para. 95). In the present case, since an action brought by an undertaking against a competitor is not intended to ensure respect for the data subjects’ rights but pursues another objective, the actions made available to data subjects by the GDPR system of remedies are preserved and may still be exercised in those circumstances (paras. 100-101). Furthermore, in the AG’s view, the objectives pursued by the GDPR, such as the high level of protection of natural persons and the consistent and homogenous application of the data protection rules (recital 10), are not threatened (but, as for the high level of protection, actually strengthened) by the possibility afforded to an undertaking to bring an action for an injunction against a competitor based on the prohibition of acts of unfair competition, in reliance on a GDPR infringement by that competitor (paras. 103-104). Finally, the AG noted that, far from being undermined, the effectiveness of the GDPR would be reinforced by the fact that compliance with its provisions may also be enforced in judicial proceedings distinct from those within its system of remedies. Accordingly, he concluded that such national remedies may exist alongside the system established by the GDPR (paras. 105-108).

 

The Judgment

The Court of Justice considered the questions in the order they were raised by the referring court and departed from the Opinion with regard to the answer to the second question.

To address the first question, the Court interpreted the relevant provisions of Chapter VIII GDPR by relying on their wording, the context and the objectives pursued by the GDPR (para. 52 of the judgment). As to the wording, the Court noted that not only the provisions of Chapter VIII do not expressly rule out the possibility for additional national remedies, but the rights provided for by Article 77(1), Article 78(1) and Article 79(1) are ‘without prejudice’ to any other administrative, judicial or non-judicial remedy (para. 53). When it comes to the context, while it agreed with the AG that only data subjects are beneficiaries of the GDPR protection, the Court noted in addition that the infringement of its substantive provisions is also liable to adversely affect third parties (in this sense, it referred to the right to compensation provided for by Article 82(1); para. 55). The Court recalled that it had already held that the infringement of data protection rules may at the same time give rise to an infringement of rules on consumer protection or unfair commercial practices (judgment in Meta Platforms Ireland, 2022, para. 78) and may be “a vital clue” in the assessment of an abuse of a dominant position (judgment in Meta Platforms and others, 2023, para. 47) (para. 55). It also noted the importance of access to personal data and the ability to process such data, which “have become a significant parameter of competition between undertakings in the digital economy”, so that it may be necessary to consider rules on data protection when enforcing competition law and the rules on unfair commercial practices (para. 56).

Interestingly, while the above would have been sufficient to interpret Chapter VIII in the light of the context, the Court went further to consider the margin of discretion enjoyed by Member States in the implementation of the GDPR. In this respect, even though the GDPR “seeks to ensure the harmonisation of national legislation on the protection of personal data which is, in principle, full, the fact remains that several provisions of that regulation expressly make it possible for Member States to lay down additional, stricter or derogating national rules, which leave them a margin of discretion as to the manner in which those provisions may be implemented (‘opening clauses’)”(para. 57). After referring to its judgment in Meta Platforms Ireland (2022, para. 57), which concerned a provision of the GDPR (Article 80) expressly containing an opening clause, the Court added: “It is true that the provisions of Chapter VIII of the GDPR do not specifically provide for such an opening clause which would expressly allow Member States to make it possible for a competitor of an undertaking which allegedly infringes the substantive provisions of that regulation to bring an action in order to put an end to that infringement. However, it follows from the wording and context of the provisions of Chapter VIII (…) that, by adopting that regulation, the EU legislature did not intend to bring about an exhaustive harmonisation of the remedies available in respect of infringements of the provisions of the GDPR and, in particular, did not wish to rule out the availability of such remedies to competitors of the person allegedly responsible for an infringement of the laws protecting personal data, on the basis of national law relating to the prohibition of unfair commercial practices” (paras. 59-60, emphasis added).

In the Court’s view, that interpretation was corroborated by the GDPR objectives (i.e., ensuring a consistent and high level of protection of natural persons with regard to the processing of personal data and removing obstacles to the flow of such data within the EU; strengthening of the rights of data subjects and of the obligations of those who process and determine the processing of data, as well as equivalent powers for monitoring and ensuring compliance with the rules for the protection of personal data and equivalent sanctions for infringements in the Member States; providing natural persons in all Member States with the same level of legally enforceable rights and obligations and responsibilities for data controllers and processors, and ensuring consistent monitoring of the processing of personal data, and equivalent sanctions in all Member States) (para. 61). It found therefore that the possibility of national remedies like those at stake does not undermine those objectives but actually enhances the effectiveness of the GDPR provisions (para. 62). These national remedies are in addition to those of Chapter VIII and pursue an objective (fair competition) which is different from those pursued by the GDPR. In this context, as the German government observed, the uniform interpretation of the GDPR remains ensured by the preliminary ruling procedure under Article 267 TFEU (paras. 65-67). Furthermore, the Court held that national remedies aimed at ensuring fair competition undoubtedly contribute to compliance with the GDPR and, therefore, to strengthening the rights of data subjects: an application for injunctive relief filed by a competitor may also prove particularly effective in so far as it may prevent a large number of infringements of data subjects’ rights (paras. 69-70).

In the light of the above, the Court concluded that Chapter VIII does not preclude national legislation providing for such remedies to the benefit of competitors, while leaving to the referring court the assessment of whether the alleged infringement of the GDPR, in so far as it is established, also constitutes a breach of the prohibition of unfair commercial practices under the relevant national law (paras. 71-72).

As to the second question, suffice it to say that the Court, unlike the AG, found that the information which customers enter when ordering online pharmacy-only medicinal products, the sale of which does not require a prescription, does constitute ‘data concerning health’ even where it is “only with a certain degree of probability, and not with absolute certainty, that those medicinal products are intended for those customers” (para. 90). This, however, does not preclude it from being processed, in specific contexts, if the conditions for exemptions are met (para. 92), i.e. does not mean automatically that the processing is in breach of the GDPR.

 

Concluding remarks

The judgment in Lindenapotheke, as far as the first question is concerned, provides an interpretation of the GDPR system of remedies aimed at enhancing the effectiveness of data protection. The remarkable point of the reasoning is the emphasis placed on the margin of discretion recognised to Member States in implementing the GDPR, with a view to enhancing the protection afforded by it. While in Meta Platforms Ireland (2022) the Court could rely on the wording of the provision concerned (para. 59: “(…) Article 80(2) of the GDPR, which leaves the Member States a discretion with regard to its implementation. (…) Member States must make use of the option made available to them by that provision to provide in their national law for that mode of representation of data subjects”), in Lindenapotheke it admitted that Chapter VIII does not expressly provide for any opening clause allowing Member States to make available further remedies for actors other than data subjects invoking a GDPR infringement. However, by relying on the wording and context of Chapter VIII, as well as on the legislator’s intention and the GDPR objectives, it came to the conclusion that Member States can make available such remedies to competitors of the person allegedly responsible for an infringement of the laws protecting personal data, since such a possibility is not being ruled out by the GDPR system of remedies and its objectives (paras. 60-61). The Court’s interpretation actually seems to encourage Member States to make additional remedies available under national laws, insofar as they enhance the effectiveness of data protection (paras. 62 and 69).

From this perspective, the Court’s conclusion is significantly relevant when placed in the context of the ongoing debate on the GDPR (under) enforcement (Gentile-Lynskey, 2022), the shortcomings of its composite enforcement system (Hofmann-Mustert, 2024) and the Commission’s Proposal for a Regulation laying down additional procedural rules relating to the enforcement of the GDPR (2023). When it comes to the handling of complaints and the role of complainants, it has been observed that these vary significantly among Member States, which in turn results in a limitation of individual procedural rights (Hofmann-Mustert, 2024). Against this background, some rightly fear, by comparing this judgment with previous case law, that its “implications have the potential to be more disruptive” as regards the consistent enforcement of the GDPR and introduce “greater potential risks of interference between administrative and judicial enforcement” (van den Poel, 2024).

However, the implications of the judgment are less daunting when considering the GDPR enforcement in the broader context of digital legislation. The Commission Second Report on the application of the GDPR, published on 25 July 2024, makes it clear that “the development of digital regulations raises the need for close cooperation across regulatory fields. Such cooperation is all the more necessary since data protection issues increasingly intersect with questions of, for example, competition law, consumer law, digital markets rules, electronic communications regulation and cybersecurity. (…) data protection authorities are taking steps to ensure their actions are complementary and coherent with other regulatory fields”. In its statement of 3 December 2024 on the Commission Second Report, the EDPB also recognised that it “would support a holistic methodological approach for the next evaluation of the GDPR that explores the interplay between the GDPR and other EU digital legislation”.

The judgment fits into this context of growing institutional awareness of the need for a holistic and coordinated approach for the effective protection of personal data, in line with the “more ‘collaborative approach’” proposed by scholars for the enforcement of data protection, competition law and unfair competition law (Vandendriessche, 2024). The Court insists on the likely enhanced effective enforcement of the GDPR via national remedies aiming at other objectives (Holtz, 2024), by proposing an interpretation where the GDPR as such calls upon the Member States for its effective enforcement (again, paras. 60-61). By stating that “such an application for injunctive relief brought by a competitor may prove, like that brought by a consumer protection association, to be particularly effective in ensuring such protection, in so far as it is capable of preventing a large number of infringements of the rights of data subjects by the processing of their personal data” (para. 70), the Court recognises the preventive effect of a potential “private enforcement” (Opinion, para. 93) through remedies allowed under national laws, which has been read as an ‘incentive’ for market players to contribute to GDPR compliance (Vandendriessche, 2024). In this sense, the judgment embraces an emerging approach in the EU regulation of the digital environment, which is aimed at involving in the enforcement multiple actors of society as a whole. This approach is evident when it comes to making the online world safer and fairer, namely with the DSA: for example, as far as institutional actors are concerned, in the cooperation required between the Commission and the Digital Services Coordinators with regard to systemic risk mitigation measures (Peukert, 2024); even more, as far as non-institutional actors are concerned, in the mechanisms required to allow any user - individual or entity - to notify illegal content online, or in the required cooperation with “trusted flaggers” (Articles 16, 22, 35 DSA) (in this sense, see also Commission’s dialogue with Civil Society Organisations for implementing the DSA).

It remains to be seen whether such an approach succeeds in becoming consolidated through greater coordination of EU institutions and national authorities and greater awareness of society at large, alongside the required adjustments for the effective implementation of the remedies the GDPR grants to data subjects.

Sunday, 13 October 2024

Latest Updates on The Legitimate Interest Ground for Processing Personal Data (Article 6(1)(f) of GDPR): the latest CJEU Case and EDPB New Guidelines

 

 




 

Aolan Li*

*The author is a third-year PhD candidate in Law at Queen Mary University of London. Her ongoing doctoral thesis research delves into the application of Article 6(1)(f) of GDPR from a comparative perspective. Email: aolan.li@qmul.ac.uk

Photo credit: TheDigitalArtist, via Wikipedia Commons

 

A positive spirit has spread among business-side stakeholders across the EU since the Court of Justice of the European Union (CJEU) published its preliminary ruling in the Koninklijke Nederlandse Lawn Tennisbond case (C-621/22) on 4 October 2024, where the court confirms a purely commercial interest could constitute a legitimate interest for processing personal data under Article 6(1)(f) of GDPR. Commentators go as far as to say - “what this means is that under the GDPR, your data can be used without your consent solely for a company’s commercial interests.”

The preceding saying is a total misunderstanding. The positive spirit should have been dampened as, on 9 October 2024, the European Data Protection Board (EDPB) published its new guidelines on Article 6(1)(f) for public consultation (hereafter as the new EDPB guidelines).

Bearing in mind the optimistic bubbles in the market, this writing articulates the EDPB’s stringent stance on the application of Article 6(1)(f) of GDPR, focusing on what has changed compared to the Article 29 Data Protection Working Party’s opinion on the legitimate interest ground under Directive 95/46/EC (hereafter as the WP29 Opinion).

General remark

The newly published EDPB guidelines align with the WP29 Opinion in some basic stances. First and foremost, the recognition of a legitimate interest is not itself sufficient to rely on Article 6(1)(f) of GDPR as a legal basis (this is why the saying is misleading) as there are three cumulative conditions for its application. Secondly, Article 6(1)(f) of GDPR should not be used “by default” nor as a “last resort”. The open-ended nature of Article 6(1)(f) has a unique role in the EU data protection law.

Not surprisingly, the new EDPB guidelines also substantially update the WP29 Opinion.

The update is partially attributed to judgments of CJEU issued after the adoption of the WP29 Opinion, including Rīgas (Case C-13/16), Fashion ID (C-40/17), TK (C-708/18), MICM (C-597/19), Meta v Bundeskartellamt (C-252/21), SCHUFA Holding (Joined Cases C-26/22 and C-64/22), and the latest Koninklijke Nederlandse Lawn Tennisbond (C-621/22). Many practical examples in the new guidelines mirror scenarios disputed in the abovementioned cases. For example, example 4 is analogous to Rīgas.

Building upon more detailed case law, the new EDPB guidelines are more logical and clearly articulated. Unlike the WP29 Opinion, the new guidelines make effects to draw a clearer line between the six grounds for legitimising data processing under Article 6(1) of GDPR. Also, the new guidelines follow the now well-accepted three-step approach to applying Article 6(1)(f), which was established by the CJEU in its judgment in Rīgas.

The update also corresponds to the evolvement of the law itself (GDPR vs Data Protection Directive). GDPR has strengthened data subject rights. It is worth noting the improvement of the right to object - a specific right for the processing based on Article 6(1)(e) and (f) of GDPR - as the burden of proof has been reversed on the controller. Also, GDPR and CJEU case law have escalated the reasonable expectation of data subjects to a more significant position in determining the application of Article 6(1)(f) of GDPR. Therefore, the new guidelines are observed to enhance the position of data subjects accordingly.

Besides being consistent with legislative developments and the CJEU’s case law, the EDPB is observed to add its unique understanding to narrow down the scope of Article 6(1)(f) of GDPR; here’s why I said the EDPB takes a stringent stance. The next part provides more discussions.

Overall, the new guidelines have been compiled from rich and up-to-date sources and provide much more nuanced interpretations of Article 6(1)(f) of GDPR. However, one might lament that Part IV of the new guidelines hesitates to touch on the application of Article 6(1)(f) of GDPR in more complicated and controversial contexts. For example, its application in the credit scoring industry seems like a real-world need, as demonstrated in SCHUFA Holding. Let alone its silence on applying Article 6(1)(f) of GDPR in AI-related scenarios.

The writing below touches on the substantial content of Article 6(1)(f) of GDPR. However, it does not intend to sketch the 37-page guidelines reductively. Instead, it aims to highlight the stringent stance of the new guidelines, read together with the Koninklijke Nederlandse Lawn Tennisbond case.

The Three Steps Approach

As mentioned above, three cumulative conditions must be fulfilled to rely on Article 6(1)(f) of GDPR as a legal basis, called the three steps approach, which are 1) the pursuit of a legitimate interest by the controller or by a third party; 2) the need to process personal data for the purposes of the legitimate interest(s) pursued; 3) the interests or fundamental freedoms and rights of the concerned data subjects do not take precedence over the legitimate interest(s) of the controller or of a third party (the new EDPB guidelines, p 2).

For the first step, the new guidelines narrow down the scope of interests with respect to the controller’s own interests and disentangle the third party’s interests from wider public interests.

As the information circulated, the qualifier “legitimate” is interpreted broadly, covering any interests that are not contrary to the law (Koninklijke Nederlandse Lawn Tennisbond, para 49).

However, sourced to the CJEU judgment in Meta v. Bundeskartellamt, the new guidelines confine that “as a general rule, the interest pursued by the controller should be related to the actual activities of the controller.” (the new EDPB guidelines, para 19) It means that, within the meaning of Article 6(1)(f) of GDPR, a controller whose activity is economic and commercial in nature is only allowed to pursue economic and commercial-related interests.

Other legitimate but non-economic/commercial interests might fall within the scope of interest(s) pursued by a third party. The new guidelines clarify that the controller needs to demonstrate the legitimate interest(s) are pursued by one or more specific third parties (para 20-25) and should not be confused with broader public interests despite the fact they can overlap, as seen in SCHUFA Holding.

Remarkably, the new EDPB guidelines indicate that relying on the interest(s) pursued by a third party in the first step is generally more challenging to pass the latter two steps (the necessity and balance test) than relying on the controller's own interests. (para 30)

For the second step, the processing involved should be necessary for the purposes of that interest identified in the first step, called the necessity test. The concept of necessity has its own free-standing meaning in EU law. The controller must demonstrate that there are no other reasonable, just as effective, but less intrusive alternatives to achieve the pursued legitimate interests.

Despite no given example in the new EDPB guidelines, the CJEU judgment in Koninklijke Nederlandse Lawn Tennisbond provides a least intrusive scenario in the direct marketing context. To be brief, without asking for consent, a Netherlands sports federation (KNLTB) sold its members’ personal data to its sponsors for the latter’s marketing purposes. The court considers it possible for KNLTB “to inform its members beforehand and to ask them whether they want their data to transmitted to those third parties for advertising or marketing purposes.” (para 51) The court deems a procedure as such may involve the least intrusion of data subjects’ rights and compliance with data minimisation principles. As will be explained below, the proposed approach resonates with the right to object and controllers’ notification obligations.

For the third step, the balance test entails a balancing of the controller side's rights and interests against those of the data subject side. The controller needs to ascertain, on a case-by-case basis, that the processing at issue would not disproportionately impact the data subject’s rights and interests.

One can observe the improved position of data subjects directly from the structures of exercising the balance test in the new EDPB guidelines and the WP29 Opinion. (See table below)

Methodology for the balancing test under new EDPB guidelines

Methodology for the balancing test under the WP29 opinion

 

The data subjects’ interests, fundamental rights and freedoms.

 

 

Assessing the controller’s legitimate interest. -      Exercise of a fundamental right;

-          Public interests/the interests of the wider community;

-          Other legitimate interests;

-          Legal and cultural/societal recognition of the legitimacy of the interests.

 

 

 

The impact of the processing on data subjects, including

-          The nature of the data to be processed;

-          The context of the processing;

-          Any further consequences of the processing.

 

 

 

Impact on the data subjects

-          Assessment of impact;

-          Nature of the data;

-          The way data are being processed;

-          Reasonable expectations of the data subject;

-          Status of the data controller and data subject.

 

 

 

The reasonable expectations of the data subject.

 

 

Provisional balance.

 

 

The final balancing of opposing rights and interests, including the possibility of further mitigating measures.

 

 

Additional safeguards applied by the controller to prevent any undue impact on the data subjects.

 

Despite most of the content continuing to work, some remarkable points exist.

Firstly, the reasonable expectation of the data subject has been escalated to an independent element. It goes beyond the controller’s notification obligation and highlights the data subject’s genuine understanding; as the new EDPB guidelines put it, more than the mere fulfilment of Articles 12, 13, and 14 is needed to consider that the data subject can reasonably expect the said processing. (para 53)

Secondly, the mitigating measures, be it technical and organisational, within the meaning of Article 6(1)(f) of GDPR must go beyond existing principles and obligations set out in the GDPR. In this sense, the new EDPB guidelines encourage controllers who intend to rely on Article 6(1)(f) of GDPR to pursue a higher level of personal data protection than legal obligations.

Data subject rights

A comprehensive review of the enhanced data subject rights under the GDPR goes beyond the subject matter of this writing. Calling back to the least intrusive approach proposed in Koninklijke Nederlandse Lawn Tennisbond, this part of the writing articulates the significance of controllers’ notification obligations and data subjects’ right to object in the context of Article 6(1)(f) of GDPR.

The court considers that KNLTB can inform its members beforehand. KNLTB’s notification obligations are set out in Articles 13 and 14 of GDPR. Its members (data subjects) should be informed about, among other things, the legal basis of processing, the specific legitimate interests pursued by KNLTB or its sponsors, and data subject rights. According to Article 13(3), KNLTB should inform its member concerned prior to further processing.

The court also considers it good practice for KNLTB to ask members concerned whether they want their data transmitted to third parties for advertising or marketing purposes. One might feel at odds with the reintroduction of “consent” in assessing Article 6(1)(f) of GDPR. Actually, it is better to understand the “ask” as informing its members concerned about their right to object under Article 21 of GDPR.

The objection to direct marketing based on Article 6(1)(f) of GDPR is absolute. In other cases, however, the controller might have compelling legitimate grounds to disapprove the right. Here, it involves another balancing test to determine whether the controller has a compelling legitimate ground. Unlike Directive 95/46, the burden of proof is on the controller.

The new EDPB guidelines promote the idea that the controller’s compelling legitimate grounds can only be recognised in exceptional cases. The controller cannot circumvent the right to object by merely showing that the processing would be beneficial to the controller. Rather, the concept of compelling is understood as essential to the controller.

From the preceding standpoint, the right to object has been improved in favour of the data subject, and it is not much inferior to the right to withdraw consent.

Concluding remarks

In conclusion, while the CJEU’s preliminary ruling in the Koninklijke Nederlandse Lawn Tennisbond case initially sparked optimism among business stakeholders by holding that purely commercial interests could qualify as legitimate under Article 6(1)(f) of the GDPR, this enthusiasm is misplaced. The ongoing EDPB’s new guidelines underscore a more restrictive interpretation of the legitimate interest ground than the earlier WP29 Opinion, reinforcing the need for careful application and a balanced approach to personal data protection. This writing calls for a self-reassessment of GDPR compliance, in particular for controllers relying on legitimate interest as a main legal basis.