[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fCWzUP1BpB5PH6qUCsXnRUEOheliRMZplbs8zAbizlRI":3},{"article":4,"iocs":43},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":21,"category":22,"article_tags":26},"4b6e64e1-facf-4c7a-b165-4fb67b0b7eb6","CJEU - C-458\u002F25","cjeu-c-458-25-3056e6","← Older revision Revision as of 14:14, 22 September 2026 Line 75: Line 75: The complaint concerned a survey on pupils' well-being which was distributed to pupils through a digital platform. According to the complaint, the controller had not informed the parents beforehand, had not obtained their consent, had collected more personal data than necessary and had failed to comply with its obligations regarding the processing of the pupils' personal data. The complaint concerned a survey on pupils' well-being which was distributed to pupils through a digital platform. According to the complaint, the controller had not informed the parents beforehand, had not obtained their consent, had collected more personal data than necessary and had failed to comply with its obligations regarding the processing of the pupils' personal data. On 16 June 2020, the DPA found that the controller infringed [[Article 6 GDPR|Article 6(1) GDPR]], [[Article 8 GDPR|Article 8 GDPR]], the data minimisation principle under [[Article 5 GDPR|Article 5(1)(c) GDPR]] and the transparency principle under [[Article 5 GDPR|Article 5(1)(a) GDPR]] in conjunction with Articles 12(1) and 13 GDPR. The DPA ordered the controller to bring the processing into compliance and imposed a €2,000 administrative fine. On 16 June 2020, the DPA found that the controller infringed [[Article 6 GDPR|Article 6(1) GDPR]], [[Article 8 GDPR]], the data minimisation principle under [[Article 5 GDPR|Article 5(1)(c) GDPR]] and the transparency principle under [[Article 5 GDPR|Article 5(1)(a) GDPR]] in conjunction with Articles 12(1) and 13 GDPR. The DPA ordered the controller to bring the processing into compliance and imposed a €2,000 administrative fine. The controller appealed. A court held that the DPA had not sufficiently justified whether the controller benefited from the exemption from administrative fines provided under Article 221(2) of the Belgian Data Protection Law. The DPA subsequently adopted a new decision and imposed a €1,000 fine, reasoning that, although the controller could qualify as a public authority under national law, it was not a public authority for the purposes of [[Article 83 GDPR|Article 83(7) GDPR]]. The controller appealed. A court held that the DPA had not sufficiently justified whether the controller benefited from the exemption from administrative fines provided under Article 221(2) of the Belgian Data Protection Law. The DPA subsequently adopted a new decision and imposed a €1,000 fine, reasoning that, although the controller could qualify as a public authority under national law, it was not a public authority for the purposes of [[Article 83 GDPR|Article 83(7) GDPR]]. Following further proceedings, a court annulled the fine. After an appeal and remittal, a court again held on 27 February 2024 that the DPA could not impose an administrative fine on the controller. The DPA appealed to the high court, which referred the matter to the CJEU for a preliminary ruling. It essentially asked whether [[Article 83 GDPR|Article 83(7) GDPR]] precludes national legislation under which a private-law entity providing subsidised independent education cannot be subject to administrative fines. Following further proceedings, a court annulled the fine. After an appeal and remittal, a court again held on 27 February 2024 that the DPA could not impose an administrative fine on the controller. The DPA appealed to the high court, which referred the matter to the CJEU for a preliminary ruling. It essentially asked whether [[Article 83 GDPR|Article 83(7) GDPR]] precludes national legislation under which a private-law entity providing subsidised independent education cannot be subject to administrative fines. === Advocate General Opinion === === Advocate General Opinion === The Advocate General (hereinafter, the AG) first considered that the concepts of \"public authorities and bodies\" in [[Article 83 GDPR|Article 83(7) GDPR]] constitute autonomous concepts of EU law. [[Article 83 GDPR|Article 83(7) GDPR]] allows Member States to determine whether and to what extent administrative fines can be imposed on public authorities and bodies, but it does not allow Member States themselves to determine which entities fall within those concepts. The Advocate General (hereinafter, the AG) first considered that the concepts of \"public authorities and bodies\" in [[Article 83 GDPR|Article 83(7) GDPR]] constitute autonomous concepts of EU law. [[Article 83 GDPR|Article 83(7) GDPR]] allows Member States to determine whether and to what extent administrative fines can be imposed on public authorities and bodies, but it does not allow Member States themselves to determine which entities fall within those concepts. Line 97: Line 94: Consequently, the AG proposed that [[Article 83 GDPR|Article 83(7) GDPR]] be interpreted as precluding national legislation under which the DPA cannot impose administrative fines on legal persons governed by private law solely because they provide independent education financed through public subsidies. Consequently, the AG proposed that [[Article 83 GDPR|Article 83(7) GDPR]] be interpreted as precluding national legislation under which the DPA cannot impose administrative fines on legal persons governed by private law solely because they provide independent education financed through public subsidies. === Holding === === Holding === TBD TBD","The Advocate General (AG) in CJEU case C-458\u002F25 provided an opinion on whether national legislation can exempt private-law entities providing subsidized independent education from administrative fines under GDPR. The case originated from a complaint about a digital survey on pupil well-being, where the controller allegedly violated GDPR principles. Belgian DPAs initially imposed fines, but courts repeatedly annulled them, leading to a referral to the CJEU.","CJEU case C-458\u002F25: AG opinion on GDPR fines for private entities providing subsidized education.","Help CJEU - C-458\u002F25: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 15:21, 21 September 2026 view sourceBms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators326 edits Tag: Decisions [1.0] Revision as of 14:14, 22 September 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators326 editsTag: Visual editNewer edit → Line 75: Line 75: The complaint concerned a survey on pupils' well-being which was distributed to pupils through a digital platform. According to the complaint, the controller had not informed the parents beforehand, had not obtained their consent, had collected more personal data than necessary and had failed to comply with its obligations regarding the processing of the pupils' personal data.The complaint concerned a survey on pupils' well-being which was distributed to pupils through a digital platform. According to the complaint, the controller had not informed the parents beforehand, had not obtained their consent, had collected more personal data than necessary and had failed to comply with its obligations regarding the processing of the pupils' personal data. On 16 June 2020, the DPA found that the controller infringed [[Article 6 GDPR|Article 6(1) GDPR]], [[Article 8 GDPR|Article 8 GDPR]], the data minimisation principle under [[Article 5 GDPR|Article 5(1)(c) GDPR]] and the transparency principle under [[Article 5 GDPR|Article 5(1)(a) GDPR]] in conjunction with Articles 12(1) and 13 GDPR. The DPA ordered the controller to bring the processing into compliance and imposed a €2,000 administrative fine.On 16 June 2020, the DPA found that the controller infringed [[Article 6 GDPR|Article 6(1) GDPR]], [[Article 8 GDPR]], the data minimisation principle under [[Article 5 GDPR|Article 5(1)(c) GDPR]] and the transparency principle under [[Article 5 GDPR|Article 5(1)(a) GDPR]] in conjunction with Articles 12(1) and 13 GDPR. The DPA ordered the controller to bring the processing into compliance and imposed a €2,000 administrative fine. The controller appealed. A court held that the DPA had not sufficiently justified whether the controller benefited from the exemption from administrative fines provided under Article 221(2) of the Belgian Data Protection Law. The DPA subsequently adopted a new decision and imposed a €1,000 fine, reasoning that, although the controller could qualify as a public authority under national law, it was not a public authority for the purposes of [[Article 83 GDPR|Article 83(7) GDPR]].The controller appealed. A court held that the DPA had not sufficiently justified whether the controller benefited from the exemption from administrative fines provided under Article 221(2) of the Belgian Data Protection Law. The DPA subsequently adopted a new decision and imposed a €1,000 fine, reasoning that, although the controller could qualify as a public authority under national law, it was not a public authority for the purposes of [[Article 83 GDPR|Article 83(7) GDPR]]. Following further proceedings, a court annulled the fine. After an appeal and remittal, a court again held on 27 February 2024 that the DPA could not impose an administrative fine on the controller. The DPA appealed to the high court, which referred the matter to the CJEU for a preliminary ruling. It essentially asked whether [[Article 83 GDPR|Article 83(7) GDPR]] precludes national legislation under which a private-law entity providing subsidised independent education cannot be subject to administrative fines.Following further proceedings, a court annulled the fine. After an appeal and remittal, a court again held on 27 February 2024 that the DPA could not impose an administrative fine on the controller. The DPA appealed to the high court, which referred the matter to the CJEU for a preliminary ruling. It essentially asked whether [[Article 83 GDPR|Article 83(7) GDPR]] precludes national legislation under which a private-law entity providing subsidised independent education cannot be subject to administrative fines. === Advocate General Opinion ====== Advocate General Opinion === The Advocate General (hereinafter, the AG) first considered that the concepts of \"public authorities and bodies\" in [[Article 83 GDPR|Article 83(7) GDPR]] constitute autonomous concepts of EU law. [[Article 83 GDPR|Article 83(7) GDPR]] allows Member States to determine whether and to what extent administrative fines can be imposed on public authorities and bodies, but it does not allow Member States themselves to determine which entities fall within those concepts.The Advocate General (hereinafter, the AG) first considered that the concepts of \"public authorities and bodies\" in [[Article 83 GDPR|Article 83(7) GDPR]] constitute autonomous concepts of EU law. [[Article 83 GDPR|Article 83(7) GDPR]] allows Member States to determine whether and to what extent administrative fines can be imposed on public authorities and bodies, but it does not allow Member States themselves to determine which entities fall within those concepts. Line 97: Line 94: Consequently, the AG proposed that [[Article 83 GDPR|Article 83(7) GDPR]] be interpreted as precluding national legislation under which the DPA cannot impose administrative fines on legal persons governed by private law solely because they provide independent education financed through public subsidies.Consequently, the AG proposed that [[Article 83 GDPR|Article 83(7) GDPR]] be interpreted as precluding national legislation under which the DPA cannot impose administrative fines on legal persons governed by private law solely because they provide independent education financed through public subsidies. === Holding ====== Holding === TBDTBD Revision as of 14:14, 22 September 2026 CJEU - C-458\u002F25 Court: CJEU Jurisdiction: European Union Relevant Law: Article 83(7) GDPR Decided: 10.09.2026 Parties: Onderwijsgroep Zusters der Christelijke Scholen Zuid-Kempen VZW Gegevensbeschermingsautoriteit Case Number\u002FName: C-458\u002F25 European Case Law Identifier: Reference from: Hof van Cassatie (Court of Cassation) Language: 24 EU Languages Original Source: AG OpinionJudgement Initial Contributor: bms The Advocate General opined that Article 83(7) GDPR precludes exempting a private-law entity providing publicly subsidised education from administrative fines merely because it performs a public-interest task. Contents 1 English Summary 1.1 Facts 1.2 Advocate General Opinion 1.3 Holding 2 Comment 3 Further Resources English Summary Facts In July 2019, the father of a pupil filed a complaint with the Dutch DPA, against Onderwijsgroep Zusters der Christelijke Scholen Zuid-Kempen VZW (OZCS), the controller, a non-profit organisation operating a subsidised independent educational establishment. The complaint concerned a survey on pupils' well-being which was distributed to pupils through a digital platform. According to the complaint, the controller had not informed the parents beforehand, had not obtained their consent, had collected more personal data than necessary and had failed to comply with its obligations regarding the processing of the pupils' personal data. On 16 June 2020, the DPA found that the controller infringed Article 6(1) GDPR, Article 8 GDPR, the data minimisation principle under Article 5(1)(c) GDPR and the transparency principle under Article 5(1)(a) GDPR in conjunction with Articles 12(1) and 13 GDPR. The DPA ordered the controller to bring the processing into compliance and imposed a €2,000 administrative fine. The controller appealed. A court held that the DPA had not sufficiently justified whether the controller benefited from the exemption from administrative fines provided under Article 221(2) of the Belgian Data Protection Law. The DPA subsequently adopted a new decision and imposed a €1,000 fine, reasoning that, although the controller could qualify as a public authority under nation","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=CJEU_-_C-458\u002F25&diff=53154&oldid=53123","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002F8\u002F87\u002FCjeulogo.png","2026-09-22T14:14:58+00:00","2026-09-22T16:00:38.482678+00:00",7,[18],{"name":19,"type":20},"GDPR","product","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":21,"icon":23,"name":24,"slug":25},null,"Policy","policy",[27,31,36,38],{"category":28},{"id":29,"icon":23,"name":19,"slug":30},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","gdpr",{"category":32},{"id":33,"icon":23,"name":34,"slug":35},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":37},{"id":21,"icon":23,"name":24,"slug":25},{"category":39},{"id":40,"icon":23,"name":41,"slug":42},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]