Data Protection Insider, Issue 160

Data Protection Insider, Issue 160 - DPI Issue 160

Table of Contents:

 

In the present edition, we inform our readers of one AG Opinions and two new documents published by the EDPB. In the AG Opinion, AG Spielmann analysed the requirements on consent for direct marketing purposes when a controller indirectly collects the data. The EDPS published new documents on the interplay between the DSA and the GDPR and on administrative fines.

On 17th September, AG Spielmann advised the CJEU to rule that when controllers receive personal data from another controller for direct marketing purposes, they need to obtain a “fresh” consent where the first controller did not mention the identity of the receiving controllers in Groupe Canal + SAS. As to the facts of the case, the applicant in the main proceedings (Groupe Canal +) appealed against a CNIL decision, imposing a fine on it for not having obtained consent, under Article 13 e-Privacy Directive (as transposed in national law) and Article 7(1) GDPR, for direct marketing purposes. In fact, the data subjects had given their consent to two ISPs to which they subscribed to transmit their data to undefined third “partners” for direct marketing purposes. The CNIL decided that this does not fulfil the requirements on consent. Thus, the preliminary ruling question raised by the referring court seeks guidance on “the conditions under which an operation involving the subsequent processing of personal data by a different controller may be based on the initial consent given at the time those data were collected” for direct marketing purposes in the framework of the e-Privacy Directive. AG Spielmann started his analysis by examining the requirements on consent in Article 4(11) GDPR, combined with the right to information as anchored in Articles 13 GDPR (when data are directly collected by the controller, in casu the ISPs) and Article 14 GDPR (when data are indirectly collected, in casu by Groupe Canal +). He concluded that because the concerned individuals did not know the identity of the new controllers, they were not effectively informed about the processing, which also makes the processing unfair and non-transparent under Article 5(1)(a) GDPR. Thus, he concluded that “the data subject’s consent given to a primary collector for his or her data to be used by a category of recipients who are designated as the primary collector’s ‘partners’, but whose identity was not known to the data subject at the time consent was given to the primary collector, cannot be regarded as informed consent permitting any person belonging to that category of recipients to carry out commercial marketing activities by electronic means without first obtaining fresh consent from the data subjects before carrying out such commercial marketing activities in relation to them”. AG Spielmann proposed two more approaches in case the Court disagrees with his reasoning and conclusion: (1) “to consider that there is no link between, on the one hand, whether consent is sufficiently informed and, on the other hand, the degree of precision of the concept of a ‘category’ of recipients”, in which case it should be considered the Groupe Canal + had obtained lawful consent, and (2) the preferred approach by AG Spielmann, according to which “even in the absence of information regarding the specific identity of the data controller responsible for the direct marketing activity, it would still be necessary to be able to identify that party in order to carry out direct marketing without obtaining fresh consent. The degree of precision of the concept of ‘category of recipients’ could therefore be significant”. Following that approach, in casu, a “fresh” consent would still be needed. [1]

EDPB Releases New Opinions

Over the past couple of weeks, the EDPB published the following significant documents:

  • “Guidelines 3/2025 on the interplay between the DSA and the GDPR” (Version 2.0); [2]
  • “Guidelines 04/2026 on the application of the power to impose administrative fines in relation to other corrective powers under the GDPR”. [3]

 

Notes:

[1] https://infocuria.curia.europa.eu/tabs/document/C/2025/C-0317-25-00000000RP-01-P-01/CONCL/326756-EN-1-html

[2] https://www.edpb.europa.eu/documents/guideline/guidelines-32025-on-the-interplay-between-the-dsa-and-the-gdpr_en

[3] https://www.edpb.europa.eu/documents/guideline/guidelines-042026-on-the-application-of-the-power-to-impose-administrative_en

About

DPI Editorial Team


Dara Hallinan, Editor: Legal academic working at FIZ Karlsruhe. His specific focus is on the interaction between law, new technologies – particularly ICT and biotech – and society. He studied law in the UK and Germany, completed a Master’s in Human Rights and Democracy in Italy and Estonia and wrote his PhD at the Vrije Universiteit Brussel on the better regulation of genetic privacy in biobanks and genomic research through data protection law. He is also programme director for the annual Computers, Privacy and Data Protection conference.


Diana Dimitrova, Editor: Researcher at FIZ Karlsruhe. Focus on privacy and data protection, especially on rights of data subjects in the Area of Freedom, Security and Justice. Completed her PhD at the VUB on the topic of ‘Data Subject Rights: The rights of access and rectification in the AFSJ’. Previously, legal researcher at KU Leuven and trainee at EDPS. Holds LL.M. in European Law from Leiden University.

Leave a Reply