Back to Feed
PolicyOct 6, 2026

CJEU - C-12/25

CJEU Advocate General opinion on GDPR applicability to church baptismal registers.

Summary

The CJEU Advocate General has opined that a church's baptismal register, even if a physical book, constitutes a filing system under GDPR. This means the regulation applies to manual processing of personal data within such registers. The opinion also addresses the right to erasure, considering exceptions for archiving and historical research, and clarifies what constitutes 'erasure' in this context.

Full text

Help CJEU - C-12/25: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 07:37, 6 October 2026 view sourceLh (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators106 edits Tag: Decisions [1.0] Latest revision as of 07:41, 6 October 2026 view source Lh (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators106 editsmTag: Visual edit Line 92: Line 92: === Facts ====== Facts === The data subject was baptised as a minor. The name, date and place of birth and place of baptism were recorded in the baptismal register with the Bisdom Gent (Diocese of Ghent, controller). The baptismal register is a physical book that indicates the date of birth and the place of baptism. It is kept in a safeguarded storage (for example in a locked safe or dedicated room) that only a limited amount of persons affiliated with the Diocese have access to.The data subject was baptised as a minor. The name, date and place of birth and place of baptism were recorded in the baptismal register with the Bisdom Gent (Diocese of Ghent, controller). The baptismal register is a physical book that indicates the date of birth and the place of baptism. It is kept in a safeguarded storage (for example in a locked safe or dedicated room) that only a limited amount of persons affiliated with the Diocese have access to. After the data subject departed from the Church, they requested the controller to erase their personal data from the registry. The controller recorded the departure of the data subject from the church with an annotation in the baptismal register. Upon the request, the controller stroke through the personal data of the data subject from the registry, however, it remained legible.After the data subject departed from the Church, they requested the controller to erase their personal data from the registry. The controller recorded the departure of the data subject from the church with an annotation in the baptismal register. Upon the request, the controller stroke through the personal data of the data subject from the registry, however, it remained legible. The data subject complained with the DPA. The DPA found an infringement of the GDPR. The controller appealed the decision with the Court of Appeal of Brussels.The data subject complained with the DPA. The DPA found an infringement of the GDPR. The controller appealed the decision with the Court of Appeal of Brussels. Line 99: Line 102: === Advocate General Opinion ====== Advocate General Opinion === 1. Filing system Firstly, according to the Advocate General Medina, the baptismal register is to be considered a filing system under [[Article 4 GDPR|Article 4(6) GDPR]]. Therefore, the GDPR is applicable despite the manual processing of the data. The personal data in the register is arranged according to a particular logic and the information therein can be easily retrieved. The register is structured on the basis of a geographical criterion (the location of the parish) and a chronological criterion (the date of celebration). It is immaterial that the criteria employed to structure the filing system do not directly concern the data subjects who were baptised. Neither is it relevant that the register is only available to a limited number of persons. The Advocate General clarified that the GDPR is also applicable in its personal scope to entities such as churches or religious communities. 2. Right to erasure under [[Article 17 GDPR|Article 17(1)(d) GDPR]]# Filing system Firstly, according to the Advocate General Medina, the baptismal register is to be considered a filing system under [[Article 4 GDPR|Article 4(6) GDPR]]. Therefore, the GDPR is applicable despite the manual processing of the data. The personal data in the register is arranged according to a particular logic and the information therein can be easily retrieved. The register is structured on the basis of a geographical criterion (the location of the parish) and a chronological criterion (the date of celebration). It is immaterial that the criteria employed to structure the filing system do not directly concern the data subjects who were baptised. Neither is it relevant that the register is only available to a limited number of persons. The Advocate General clarified that the GDPR is also applicable in its personal scope to entities such as churches or religious communities. 2. Right to erasure under [[Article 17 GDPR|Article 17(1)(d) GDPR]] The data subject can request the erasure of their personal data under [[Article 17 GDPR|Article 17(1)(d) GDPR]] when the processing was unlawful.The data subject can request the erasure of their personal data under [[Article 17 GDPR|Article 17(1)(d) GDPR]] when the processing was unlawful. The processing of the data subject’s personal data in the baptismal register is to be considered special categories of personal data pursuant to [[Article 9 GDPR|Article 9(1) GDPR]], namely data on the religious belief. The conditions of [[Article 9 GDPR|Article 9(2)(d) GDPR]] are met because the data is processed by a religious entity and the register is safeguarded.The processing of the data subject’s personal data in the baptismal register is to be considered special categories of personal data pursuant to [[Article 9 GDPR|Article 9(1) GDPR]], namely data on the religious belief. The conditions of [[Article 9 GDPR|Article 9(2)(d) GDPR]] are met because the data is processed by a religious entity and the register is safeguarded. Moreover, the controller can rely on the legal basis of [[Article 6 GDPR|Article 6(1)(f) GDPR]] for the processing of the data because the controller pursues the interest of ensuring a proper administration of the sacraments. It is necessary to keep a record of all baptisms in order to prevent believers from being baptised twice. The sacraments are of utmost importance to the Church. Moreover, the controller can rely on the legal basis of [[Article 6 GDPR|Article 6(1)(f) GDPR]] for the processing of the data because the controller pursues the interest of ensuring a proper administration of the sacraments. It is necessary to keep a record of all baptisms in order to prevent believers from being baptised twice. The sacraments are of utmost importance to the Church. When balancing the interest of the controller with the rights and interests of the data subject under [[Article 6 GDPR|Article 6(1)(f) GDPR]], the Advocate General took into account the fact that the data subject was unable to consent to the data processing because they were a child at the time of the baptism. When balancing the interest of the controller with the rights and interests of the data subject under [[Article 6 GDPR|Article 6(1)(f) GDPR]], the Advocate General took into account the fact that the data subject was unable to consent to the data processing because they were a child at the time of the baptism. On the other hand, the Advocate General considered that only a limited number of people have access to the register, which is a mitigating factor. Moreover, the register also serves the interests of individuals who need to provide proof of their baptism in order to receive other sacraments such as religious marriage. On the other hand, the Advocate General considered that only a limited number of people have access to the register, which is a mitigating factor. Moreover, the register also serves the interests of individuals who need to provide proof of their baptism in order to receive other sacraments such as religious marriage. According to the Advocate General, whether the processing could be based on [[Article 6 GDPR|Article 6(1)(f) GDPR]] is ultimately for the referring court to decide. In case of the affirmative, the data subject could not request the erasure pursuant to [[Article 17 GDPR|Article 17(1)(d) GDPR]] before the controller was informed about the data subject’s objection to the processing.According to the Advocate Gener

Entities

Bisdom Gent (vendor)GDPR (technology)