Data Protection Insider, Issue 159

Digital data and privacy in the context of EU data protection law

Table of Contents:

 

In the present edition, we inform our readers of one CJEU judgment and two AG Opinions. The CJEU judgment concerns the proportionality of disclosures of shareholder information. The AG Opinions concern data retention and whether private education establishments can qualify as public authorities and bodies, and the consequences of this for the possibility of DPAs to issue administrative fines to them. Finally, we highlight new EDPS Opinions in the sphere of law enforcement reform proposals.

1. CJEU Considers the Proportionality of Disclosures of Shareholder Information

On 3rd September the CJEU passed down its judgment in the case of A and Others v Latvijas Republikas Saeima.[1] In terms of the facts, the case essentially concerned a constitutional complaint made by several natural persons related to an instrument of national legislation, according to which, “certain information relating to the shareholders of public limited liability companies is to be made available to the public. If such a shareholder is a natural person, that information is to include the surname, first name, personal identification number or, in the absence of such a number, the date of birth, the number and date of issue of an identity document, the country and issuing authority, and the address at which the shareholder can be contacted. In addition, and regardless of whether the shareholder is a natural person, that information is also to include the shareholder’s email address, where the shareholder has requested that it be used by the company in which it holds shares to communicate with them, the class, number and nominal value of their shares, as well as the number of votes attaching to them. The same information is to be available online and may be downloaded in bulk, including by any unidentified user”. The applicants argue that “the Latvian legislature neither examined nor justified the need to disclose the information concerned to the public, it being noted that, once disclosed, it is no longer possible to place any restrictions on its subsequent use and there is a high risk of it being used for dishonest purposes. They contend that, in any event, in the light of the judgment of…Luxembourg Business Registers…the disclosure of that information is unjustified and disproportionate, in view of the fact that the applicants in the main proceedings are neither the beneficial owners of the company concerned nor members of its management bodies, and that they have neither the right nor the option to exercise control over” the company. In this regard, with relevance to EU data protection law, the CJEU considered the following significant question: do Articles 5 and 6 of the GDPR, in the light of Articles 7 and 8 of the CFREU, preclude “national legislation which requires personal data relating to all shareholders” such as listed above “including minority shareholders, of public limited liability companies…to be made available to the public in order to ensure a transparent business environment so as to protect the interests of third parties, prevent money laundering and the financing of terrorism and the proliferation of weapons of mass destruction, and provide the information necessary for the implementation of national, international and EU sanctions, where access to such data is not subject to any conditions, such as demonstrating a legitimate interest”? The CJEU asserted that the relevant basis for processing was Article 6(1)(c) and thus went on to consider the proportionality of the law under consideration. The Court concluded, essentially, that the national legislation such as that at issue would not be proportionate “where access to such data is not subject to any conditions, such as demonstrating a legitimate interest”. The analysis and conclusion in the case is relatively straightforward. The case is nevertheless interesting and worthy of reading for a number of reasons, including the presence of a number of statements in the decision with relevance to deeper doctrinal debates. The Court states, for example – albeit without further clarification – on the possibility to process personal data without consent, that: “In the absence of…consent, or where that consent is not freely given, specific, informed and unambiguous, within the meaning of Article 4(11) of the GDPR, such processing is nevertheless justified where it meets one of the requirements of necessity mentioned in points (b) to (f) of the first subparagraph of Article 6(1) of the GDPR”.

Notes: [1]

https://infocuria.curia.europa.eu/tabs/document/C/2024/C-0798-24-00000000RP-01-P-01/ARRET/325972-EN-1-html

 

2. AG Campos Sánchez-Bordona on the Concept of “Public Authorities and Bodies” in Education

On 10th September, AG Campos Sánchez-Bordona delivered their Opinion in the case of Gegevensbeschermingsautoriteit v Onderwijsgroep Zusters der Christelijke Scholen Zuid-Kempen VZW. In terms of the facts, the case essentially concerned the imposition of a fine, by the Belgian DPA, “on the owner of a subsidised educational establishment”. The establishment appealed the fine, on the basis that it falls under the scope of the term “public authority” and, under Belgian national law, DPAs may not impose “administrative fines on public authorities, except where they are legal persons governed by public law offering goods or services in a market”. In this regard, the following question was posed to the Court: does Article 83(7) of the GDPR, “in conjunction with recitals 38 and 58 and Article 6(1)(f), Article 8 and Article 57(1)(b)…preclude national legislation under which the supervisory authority cannot impose administrative fines on legal persons constituted under private law which provide subsidised independent education?” The AG considered that “the notion of ‘public authorities and bodies’ contained in Article 83(7) of the GDPR constitutes an autonomous concept of EU law, which it is not for the national law of the Member States to define”.
Accordingly, the AG proceeded to engage in a careful examination of the concepts in question – i.e. “public authorities and bodies” – deciding that the plaintiff did not necessarily fulfil the requisite criteria, in particular relating to “the exercise of prerogatives of powers conferred by public law”.[2] The AG proceeded to observe that “supervisory authorities should not, categorically, be deprived of the ability to impose administrative fines on an entity governed by private law, simply because that entity carries out teaching tasks in the general interest and receives public subsidies. Such an interpretation would substantially reduce the ability of supervisory authorities to ensure compliance with the GDPR and the protection of natural persons”. Accordingly, the AG considered that Article 83(7) of the GDPR should be interpreted as meaning that “it precludes national legislation under which the supervisory authority cannot impose administrative fines on legal persons constituted under private law which provide independent education and, for that purpose, receive subsidies from public funds”.

Notes: [2]

https://infocuria.curia.europa.eu/tabs/document/C/2025/C-0458-25-00000000RP-01-P-01/CONCL/326396-EN-1-html

 

3. AG Szpunar: New Solution for Data Retention?

On 3rd September, AG Szpunar delivered his Opinion in the case of Academie Fiscale and Others, concerning the compatibility with Article 15(1) e-Privacy Directive and the CFREU of the new Belgian legal framework on data retention – which had been amended after the Quadrature du Net II judgment. With the preliminary ruling questions, the Court is asked to develop its data retention case law, especially as concerns the retention of traffic and location data by telecommunications providers for the purposes of “establishing fraud or malicious use of the network or service or identifying its perpetrator and origin”. In his Opinion, AG Szpunar started by providing a detailed overview of the existing CJEU case law on data retention and assessed the pending questions in light of this case law. He paid special attention to the principle of proportionality, which includes two aspects: (1) clear rules on the data retention regime, accompanied by appropriate safeguards against abuse (strict necessity) and (2) proportionality between the seriousness of the interference and the pursued public interest objective, in which case national security interests could justify more serious interference with privacy and data protection rights. He then recalled the Quadrature du Net II judgment, in which the Court refined its data retention case law in relation to crime committed exclusively online. It (1) accepted that an indiscriminate retention of all IP addresses for fighting crime in general could be compatible with EU law if IP addresses are technically separated from other data in order to prevent concrete conclusions about individuals’ private lives being made and (2) concluded that retaining the IP addresses of all users might be the only means of identifying criminals online (strict necessity). From a combined reading of all the relevant cases, AG Szpunar concluded that (1) whereas the Court requires that telecommunication providers implement technical measures to store different personal data separately in order to fight crime in general, it does not impose this requirement for national security purposes, which leads to the storage of the same data on two different files and enables their easier access for law enforcement purposes by declaring a national security purpose for their access; and (2) the seriousness of the interference with private life depends on the subsequent access and further processing of the data.
On that basis, he advised the Court to rule that the general and indiscriminate retention of traffic and location data as established in Quadrature du Net II should be extended to all traffic and location data, provided that “those data are retained in conditions and in accordance with technical arrangements which ensure that the possibility that that retention might allow precise conclusions to be drawn about the private life of users is ruled out, which may be accomplished, in particular, by imposing on providers of electronic communications services an obligation to retain the various categories of personal data in such a way as to ensure a genuinely watertight separation of those different categories of data, thereby preventing, at the retention stage, any combined use of those different categories of data – and for a period not exceeding what is strictly necessary”. In addition, adequate safeguards should be anchored in law to prevent abuse. [3] Lastly, AG Szpunar applied the above new model to the 2022 Belgian legal framework and advised the Court to rule that the said legislation is not compatible with Article 15 e-Privacy Regulation and the CFREU, because it does not require the separate technical storage of traffic and location data in a way which prevents private life conclusions to be made from such data; neither does national aw define sufficiently precisely the data categories to be stored and the storage periods. Finally, AG Szpunar opined that, should the Court declare the national provisions incompatible with EU law, the national court may not conclude these remain in force, contrary to the EU ruling.

Notes: [3]

https://infocuria.curia.europa.eu/tabs/document/C/2024/C-0661-24-00000000RP-01-P-01/CONCL/325978-EN-1-html

 

4. EDPS Releases New Opinions

In the course of August, the EDPS published four Opinions related to proposed amendments, or recasts, of five instruments in the sphere of judicial and law enforcement cooperation [4]:

  • “EDPS Opinion 17/2026 on the Proposal for a Regulation amending Regulation (EU) 2018/1725 on the protection of natural persons with regard to the processing of personal data by the EU institutions, bodies, offices and agencies”;
  • “EDPS Opinion 18/2026 on the Proposal for a Regulation on Europol repealing Regulation (EU) 2016/794”;
  • “EDPS Opinion 19/2026 on the Proposal for the Regulation on the establishment of Eurojust and repealing Regulation (EU) 2018/1727”; and
  • “EDPS Opinion 16/2026 on the Proposal for a Directive regarding the European Investigation Order in criminal matters and the European Remote Participation Order (recast)”.

Notes: [4]

https://www.edps.europa.eu/data-protection/our-work/publications/opinions/2026-08-11-edps-opinion-192026-regulation-establishment-eurojust-and-repealing-regulation-eu-20181727_en

https://www.edps.europa.eu/data-protection/our-work/publications/opinions/2026-08-11-edps-opinion-172026-regulation-amending-regulation-eu-20181725-protection-natural-persons-regard-processing-personal-data-eu-institutions_en

https://www.edps.europa.eu/data-protection/our-work/publications/opinions/2026-08-11-edps-opinion-182026-regulation-europol-repealing-regulation-eu-2016794_en

https://www.edps.europa.eu/data-protection/our-work/publications/opinions/2026-08-10-edps-opinion-162026-directive-regarding-european-investigation-order-criminal-matters-and-european-remote-participation-order-recast_en

 

About

DPI Editorial Team


Dara Hallinan, Editor: Legal academic working at FIZ Karlsruhe. His specific focus is on the interaction between law, new technologies – particularly ICT and biotech – and society. He studied law in the UK and Germany, completed a Master’s in Human Rights and Democracy in Italy and Estonia and wrote his PhD at the Vrije Universiteit Brussel on the better regulation of genetic privacy in biobanks and genomic research through data protection law. He is also programme director for the annual Computers, Privacy and Data Protection conference.


Diana Dimitrova, Editor: Researcher at FIZ Karlsruhe. Focus on privacy and data protection, especially on rights of data subjects in the Area of Freedom, Security and Justice. Completed her PhD at the VUB on the topic of ‘Data Subject Rights: The rights of access and rectification in the AFSJ’. Previously, legal researcher at KU Leuven and trainee at EDPS. Holds LL.M. in European Law from Leiden University.

Leave a Reply