[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fQucgu2AnGv3d-z9anJ2wcWTS4x1AQhXQLh7okY4tux4":3},{"article":4,"iocs":43},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":21,"category":22,"article_tags":26},"e9c7a734-126d-4446-89c3-57270672efcc","CJEU - C-458\u002F25","cjeu-c-458-25-cd116e","← Older revision Revision as of 09:23, 23 September 2026 (One intermediate revision by the same user not shown) Line 5: Line 5: |Opinion_Link=https:\u002F\u002Finfocuria.curia.europa.eu\u002Ftabs\u002Fdocument\u002FC\u002F2025\u002FC-0458-25-00000000RP-01-P-01\u002FCONCL\u002F326396-EN-1-html |Opinion_Link=https:\u002F\u002Finfocuria.curia.europa.eu\u002Ftabs\u002Fdocument\u002FC\u002F2025\u002FC-0458-25-00000000RP-01-P-01\u002FCONCL\u002F326396-EN-1-html |Judgement_Link=https:\u002F\u002Finfocuria.curia.europa.eu\u002Ftabs\u002Fjurisprudence?lang=en&sort=DOC_DATE-DESC&searchTerm=2016%252F679 |Judgement_Link= |Date_Decided=10.09.2026 |Date_Decided=10.09.2026 Line 66: Line 66: }} }} The Advocate General opined that [[Article 83 GDPR|Article 83(7) GDPR]] precludes exempting a private-law entity providing publicly subsidised education from administrative fines merely because it performs a public-interest task. The Advocate General opined that while [[Article 83 GDPR|Article 83(7) GDPR]] allows national law to exempt public authorities from administrative fines, national law may not exempt private-law entities from fines – even if they provide tasks in the public interest such as publicly subsidised education. ==English Summary== ==English Summary== Line 76: Line 76: On 16 June 2020, the DPA found that the controller infringed [[Article 6 GDPR|Article 6(1) GDPR]], [[Article 8 GDPR]], the data minimisation principle under [[Article 5 GDPR|Article 5(1)(c) GDPR]] and the transparency principle under [[Article 5 GDPR|Article 5(1)(a) GDPR]] in conjunction with [[Article 12 GDPR|Articles 12(1)]] and [[Article 13 GDPR|13 GDPR]]. The DPA ordered the controller to bring the processing into compliance and imposed a €2,000 administrative fine. On 16 June 2020, the DPA found that the controller infringed [[Article 6 GDPR|Article 6(1) GDPR]], [[Article 8 GDPR]], the data minimisation principle under [[Article 5 GDPR|Article 5(1)(c) GDPR]] and the transparency principle under [[Article 5 GDPR|Article 5(1)(a) GDPR]] in conjunction with [[Article 12 GDPR|Articles 12(1)]] and [[Article 13 GDPR|13 GDPR]]. The DPA ordered the controller to bring the processing into compliance and imposed a €2,000 administrative fine. [[Article 83 GDPR|Article 83(7) GDPR]] allows Member States to determine whether and to what extent administrative fines may be imposed on public authorities and bodies established in that Member State. Belgium made use of this possibility in [https:\u002F\u002Fwww.belgium.be\u002Fen\u002Fpersonal_data Article 221(2) of its Data Protection Law], which excludes the application of [[Article 83 GDPR]] to public authorities and their employees or agents, except for legal persons governed by public law that offer goods or services on a market. The dispute therefore concerned whether the controller, despite being a legal person governed by private law, could fall within that exemption because it provided publicly subsidised education. The controller appealed. A court held that the DPA had not sufficiently justified whether the controller benefited from the exemption from administrative fines provided under [https:\u002F\u002Fwww.belgium.be\u002Fen\u002Fpersonal_data Article 221(2) of the Belgian Data Protection Law]. The DPA subsequently adopted a new decision and imposed a €1,000 fine, reasoning that, although the controller could qualify as a public authority under national law, it was not a public authority for the purposes of [[Article 83 GDPR|Article 83(7) GDPR]]. The controller appealed. A court held that the DPA had not sufficiently justified whether the controller benefited from the exemption from administrative fines provided under [https:\u002F\u002Fwww.belgium.be\u002Fen\u002Fpersonal_data Article 221(2) of the Belgian Data Protection Law]. The DPA subsequently adopted a new decision and imposed a €1,000 fine, reasoning that, although the controller could qualify as a public authority under national law, it was not a public authority for the purposes of [[Article 83 GDPR|Article 83(7) GDPR]].","The Advocate General has opined that Article 83(7) of the GDPR does not permit national laws to exempt private-law entities from administrative fines, even if they perform public-interest tasks like providing publicly subsidized education. This ruling clarifies that while Member States can exempt public authorities, this exemption does not extend to private entities acting in the public interest. The case involved a Belgian DPA's decision to fine an educational institution, highlighting the distinction between public authorities and private entities for GDPR fine applicability.","Advocate General opines private entities providing public services can be fined under GDPR.","Help CJEU - C-458\u002F25: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 14:28, 22 September 2026 view sourceBms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators332 editsTag: Visual edit← Older edit Latest revision as of 09:23, 23 September 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators332 editsTag: Visual edit (One intermediate revision by the same user not shown)Line 5: Line 5: |Opinion_Link=https:\u002F\u002Finfocuria.curia.europa.eu\u002Ftabs\u002Fdocument\u002FC\u002F2025\u002FC-0458-25-00000000RP-01-P-01\u002FCONCL\u002F326396-EN-1-html|Opinion_Link=https:\u002F\u002Finfocuria.curia.europa.eu\u002Ftabs\u002Fdocument\u002FC\u002F2025\u002FC-0458-25-00000000RP-01-P-01\u002FCONCL\u002F326396-EN-1-html |Judgement_Link=https:\u002F\u002Finfocuria.curia.europa.eu\u002Ftabs\u002Fjurisprudence?lang=en&sort=DOC_DATE-DESC&searchTerm=2016%252F679|Judgement_Link= |Date_Decided=10.09.2026|Date_Decided=10.09.2026 Line 66: Line 66: }}}} The Advocate General opined that [[Article 83 GDPR|Article 83(7) GDPR]] precludes exempting a private-law entity providing publicly subsidised education from administrative fines merely because it performs a public-interest task.The Advocate General opined that while [[Article 83 GDPR|Article 83(7) GDPR]] allows national law to exempt public authorities from administrative fines, national law may not exempt private-law entities from fines – even if they provide tasks in the public interest such as publicly subsidised education. ==English Summary====English Summary== Line 76: Line 76: On 16 June 2020, the DPA found that the controller infringed [[Article 6 GDPR|Article 6(1) GDPR]], [[Article 8 GDPR]], the data minimisation principle under [[Article 5 GDPR|Article 5(1)(c) GDPR]] and the transparency principle under [[Article 5 GDPR|Article 5(1)(a) GDPR]] in conjunction with [[Article 12 GDPR|Articles 12(1)]] and [[Article 13 GDPR|13 GDPR]]. The DPA ordered the controller to bring the processing into compliance and imposed a €2,000 administrative fine.On 16 June 2020, the DPA found that the controller infringed [[Article 6 GDPR|Article 6(1) GDPR]], [[Article 8 GDPR]], the data minimisation principle under [[Article 5 GDPR|Article 5(1)(c) GDPR]] and the transparency principle under [[Article 5 GDPR|Article 5(1)(a) GDPR]] in conjunction with [[Article 12 GDPR|Articles 12(1)]] and [[Article 13 GDPR|13 GDPR]]. The DPA ordered the controller to bring the processing into compliance and imposed a €2,000 administrative fine. [[Article 83 GDPR|Article 83(7) GDPR]] allows Member States to determine whether and to what extent administrative fines may be imposed on public authorities and bodies established in that Member State. Belgium made use of this possibility in [https:\u002F\u002Fwww.belgium.be\u002Fen\u002Fpersonal_data Article 221(2) of its Data Protection Law], which excludes the application of [[Article 83 GDPR]] to public authorities and their employees or agents, except for legal persons governed by public law that offer goods or services on a market. The dispute therefore concerned whether the controller, despite being a legal person governed by private law, could fall within that exemption because it provided publicly subsidised education. The controller appealed. A court held that the DPA had not sufficiently justified whether the controller benefited from the exemption from administrative fines provided under [https:\u002F\u002Fwww.belgium.be\u002Fen\u002Fpersonal_data Article 221(2) of the Belgian Data Protection Law]. The DPA subsequently adopted a new decision and imposed a €1,000 fine, reasoning that, although the controller could qualify as a public authority under national law, it was not a public authority for the purposes of [[Article 83 GDPR|Article 83(7) GDPR]].The controller appealed. A court held that the DPA had not sufficiently justified whether the controller benefited from the exemption from administrative fines provided under [https:\u002F\u002Fwww.belgium.be\u002Fen\u002Fpersonal_data Article 221(2) of the Belgian Data Protection Law]. The DPA subsequently adopted a new decision and imposed a €1,000 fine, reasoning that, although the controller could qualify as a public authority under national law, it was not a public authority for the purposes of [[Article 83 GDPR|Article 83(7) GDPR]]. Latest revision as of 09:23, 23 September 2026 CJEU - C-458\u002F25 Court: CJEU Jurisdiction: European Union Relevant Law: Article 83(7) GDPR Decided: 10.09.2026 Parties: Onderwijsgroep Zusters der Christelijke Scholen Zuid-Kempen VZW Gegevensbeschermingsautoriteit Case Number\u002FName: C-458\u002F25 European Case Law Identifier: Reference from: Hof van Cassatie (Court of Cassation) Language: 24 EU Languages Original Source: AG Opinion Initial Contributor: bms The Advocate General opined that while Article 83(7) GDPR allows national law to exempt public authorities from administrative fines, national law may not exempt private-law entities from fines – even if they provide tasks in the public interest such as publicly subsidised education. Contents 1 English Summary 1.1 Facts 1.2 Advocate General Opinion 1.3 Holding 2 Comment 3 Further Resources English Summary Facts In July 2019, the father of a pupil filed a complaint with the Dutch DPA, against Onderwijsgroep Zusters der Christelijke Scholen Zuid-Kempen VZW (OZCS), the controller, a non-profit organisation operating a subsidised independent educational establishment. The complaint concerned a survey on pupils' well-being which was distributed to pupils through a digital platform. According to the complaint, the controller had not informed the parents beforehand, had not obtained their consent, had collected more personal data than necessary and had failed to comply with its obligations regarding the processing of the pupils' personal data. On 16 June 2020, the DPA found that the controller infringed Article 6(1) GDPR, Article 8 GDPR, the data minimisation principle under Article 5(1)(c) GDPR and the transparency principle under Article 5(1)(a) GDPR in conjunction with Articles 12(1) and 13 GDPR. The DPA ordered the controller to bring the processing into compliance and imposed a €2,000 administrative fine. Article 83(7) GDPR allows Member States to determine whether and to what extent administrative fines may be imposed on public authorities and bodies established in that Member State. Belgium made use of this possibility in Article 221(2) of its Data Protection Law, which excludes the application of Article 83 GDPR to public authorities and their employees or agents, except for legal persons governed by public law that offer goods or services on a market. The dispute therefore concerned whether the controller, despite being a legal person governed by private law, could fall within that exemption because it provided publicly subsidised education. The controller appealed. A court held that the DPA had not sufficiently justified whether the controller benefited from the exemption from administrative fines provided under Article 221(2) of the Belgian Data Protection Law. The DPA subsequently adopted a new decision and imposed a €1,000 fine, reasoning that, although the controller could qualify as a public authority under national law, it was not a public authority for the purposes of Article 83(7) GDPR. Following further proceedings, a court annulled the fine. After an appeal and remittal, a court again held on 27 February 2024 that the DPA could not impose an administrative fine on the controller. The DPA appealed to the high court, which referred the matter to the CJEU for a preliminary ruling. It essentially asked whether Article 83(7) GDPR precludes national legislation under which a private-law entity providing subsidised independent education cannot be subject to administrative fines. Advocate General Opinion The Advocate General (hereinafter, the AG) first considered that the concepts of \"public authorities and bodies\" in Article 83(7) GDPR constitute autonomous concepts of EU l","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=CJEU_-_C-458\u002F25&diff=53181&oldid=53156","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002F8\u002F87\u002FCjeulogo.png","2026-09-23T09:23:27+00:00","2026-09-23T10:00:28.225131+00:00",7,[18],{"name":19,"type":20},"GDPR","product","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":21,"icon":23,"name":24,"slug":25},null,"Policy","policy",[27,31,36,38],{"category":28},{"id":29,"icon":23,"name":19,"slug":30},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","gdpr",{"category":32},{"id":33,"icon":23,"name":34,"slug":35},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":37},{"id":21,"icon":23,"name":24,"slug":25},{"category":39},{"id":40,"icon":23,"name":41,"slug":42},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]