[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1BKb9ZISMYfCJJzLChfhs14Lbhz-vfuxFwfqptmVQ5g":3},{"article":4,"iocs":44},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":23,"category":24,"article_tags":28},"b7c9d919-6086-4010-bcac-98c2477bf6c5","CJEU - C‑769\u002F22 - European Commission v Hungary","cjeu-c-769-22-european-commission-v-hungary-528487","GDPRhub EU cleanup ← Older revision Revision as of 13:13, 24 July 2026 Line 17: Line 17: |GDPR_Article_Link_3= |GDPR_Article_Link_3= |EU_Law_Name_1=Art. 8(2) CFREU |EU_Law_Name_1=Art. 8(2) CFR |EU_Law_Link_1=https:\u002F\u002Fwww.europarl.europa.eu\u002Fcharter\u002Fpdf\u002Ftext_en.pdf |EU_Law_Link_1=https:\u002F\u002Fwww.europarl.europa.eu\u002Fcharter\u002Fpdf\u002Ftext_en.pdf |EU_Law_Name_2= |EU_Law_Name_2= Line 52: Line 52: In 2021 the Commission sent a formal letter to Hungary contesting the amending law's compliance with EU law. After some unproductive back-and-forth, the Commission escalated the case to the CJEU, requesting the CJEU to declare the amending law incompatible with EU law. In 2021 the Commission sent a formal letter to Hungary contesting the amending law's compliance with EU law. After some unproductive back-and-forth, the Commission escalated the case to the CJEU, requesting the CJEU to declare the amending law incompatible with EU law. The European Commission filed four pleas, claiming that Hungary violated of a long list of provisions from primary and secondary EU law The Commission alleged the violation of Articles 1, 7, 8(2), 11 and 21 CFREU; Article 2 TEU; Article 56 TFEU; Article 3(2) of the Directive on electronic commerce; Articles 16 and 19 of the Services Directive, Article 9(1)(c)(ii) of the AVMS Directive; and [[Article 10 GDPR]]. . Only the Commission's fourth plea invokes data protection law- specifically, [https:\u002F\u002Fwww.europarl.europa.eu\u002Fcharter\u002Fpdf\u002Ftext_en.pdf Article 8(2) of the EU Charter of Fundamental Rights (CFREU)] (\"Protection of personal data\") and [[Article 10 GDPR]] (\"Processing of personal data relating to criminal convictions and offences\"). The European Commission filed four pleas, claiming that Hungary violated of a long list of provisions from primary and secondary EU law The Commission alleged the violation of Articles 1, 7, 8(2), 11 and 21 CFREU; Article 2 TEU; Article 56 TFEU; Article 3(2) of the Directive on electronic commerce; Articles 16 and 19 of the Services Directive, Article 9(1)(c)(ii) of the AVMS Directive; and [[Article 10 GDPR]]. . Only the Commission's fourth plea invokes data protection law- specifically, [https:\u002F\u002Fwww.europarl.europa.eu\u002Fcharter\u002Fpdf\u002Ftext_en.pdf Article 8(2) of the EU Charter of Fundamental Rights (CFR)] (\"Protection of personal data\") and [[Article 10 GDPR]] (\"Processing of personal data relating to criminal convictions and offences\"). '''The fourth plea: [[Article 10 GDPR]]''' '''The fourth plea: [[Article 10 GDPR]]''' Line 58: Line 58: The alleged violation of the GDPR relates to the amended law's rules on access to information about individuals convicted of sexual offences against children. The law amended the ''\"Law on the criminal record system\"'' and made documents about sexual offences accessible to a broad audience. Under the new rules, any adult who is either a relative or a guardian of a minor (\"authorised person\"), has the right to access and share information about individuals convicted of sexual offences against children (the data subjects) from bodies with access to registered data. The alleged violation of the GDPR relates to the amended law's rules on access to information about individuals convicted of sexual offences against children. The law amended the ''\"Law on the criminal record system\"'' and made documents about sexual offences accessible to a broad audience. Under the new rules, any adult who is either a relative or a guardian of a minor (\"authorised person\"), has the right to access and share information about individuals convicted of sexual offences against children (the data subjects) from bodies with access to registered data. The Commission claimed that the amended law failed to specify with sufficient clarity who is authorised to submit a data request and, therefore, did not provide sufficient guarantees for the rights and freedoms of data subjects regarding the conditions of access to their personal data. On these grounds, the Commission claimed that the amended law infringed Article 10 of the GDPR (as well as [https:\u002F\u002Fwww.europarl.europa.eu\u002Fcharter\u002Fpdf\u002Ftext_en.pdf Art. 8(2) CFREU]). The Commission claimed that the amended law failed to specify with sufficient clarity who is authorised to submit a data request and, therefore, did not provide sufficient guarantees for the rights and freedoms of data subjects regarding the conditions of access to their personal data. On these grounds, the Commission claimed that the amended law infringed Article 10 of the GDPR (as well as [https:\u002F\u002Fwww.europarl.europa.eu\u002Fcharter\u002Fpdf\u002Ftext_en.pdf Art. 8(2) CFR]). In its defense, Hungary argued that the law accurately identified \"authorised persons\" when read in light of the definition of \"relatives\" in the Hungarian civil code. Additionally, Hungary claimed that there were two additional criteria access to personal data under Hungarian law: the authorised person must consider the relevant data to be probably necessary, and it must be disproportionately difficult for them to access the subjects' data if they are not disclosed. In its defense, Hungary argued that the law accurately identified \"authorised persons\" when read in light of the definition of \"relatives\" in the Hungarian civil code. Additionally, Hungary claimed that there were two additional criteria access to personal data under Hungarian law: the authorised person must consider the relevant data to be probably necessary, and it must be disproportionately difficult for them to access the subjects' data if they are not disclosed. Line 68: Line 68: * (iii) it was disproportionately difficult for the authorized person to access the data otherwise. * (iii) it was disproportionately difficult for the authorized person to access the data otherwise. Hungary claimed that these criteria were clearly defined and provided sufficient safeguards for data subjects. On this basis, Hungary argued that the amended law complied with [[Article 10 GDPR]] and [https:\u002F\u002Fwww.europarl.europa.eu\u002Fcharter\u002Fpdf\u002Ftext_en.pdf 8(2) CFREU]. Hungary claimed that these criteria were clearly defined and provided sufficient safeguards for data subjects. On this basis, Hungary argued that the amended law complied with [[Article 10 GDPR]] and [https:\u002F\u002Fwww.europarl.europa.eu\u002Fcharter\u002Fpdf\u002Ftext_en.pdf 8(2) CFR]. === Advocate General Opinion === === Advocate General Opinion === Line 81: Line 81: Second, the AG considered that requirements (ii) and (iii) (''i.e.'': the probable necessity of the disclosure, and the difficulty of otherwise accessing the data) were overly generic and were to be assessed by the authorized person themselves. The AG argued that such a self-declaratoty regime lent itself to abuse and deprived the disclosing body of any control over the necessity and proportionality of the disclosure. For this reason, the AG opined that the amending law failed to provide the required safeguards for data subjects. Second, the AG considered that requirements (ii) and (iii) (''i.e.'': the probable necessity of the disclosure, and the difficulty of otherwise accessing the data) were overly generic and were to be assessed by the authorized person themselves. The AG argued that such a self-declaratoty regime lent itself to abuse and deprived the disclosing body of any control over the necessity and proportionality of the disclosure. For this reason, the AG opined that the amending law failed to provide the required safeguards for data subjects. On these grounds, the AG opined that the amended law was disproportionate and violated [[Article 10 GDPR]] as well as [https:\u002F\u002Fwww.europarl.europa.eu\u002Fcharter\u002Fpdf\u002Ftext_en.pdf Article 8(2) CFREU]. On these grounds, the AG opined that the amended law was disproportionate and violated [[Article 10 GDPR]] as well as [https:\u002F\u002Fwww.europarl.europa.eu\u002Fcharter\u002Fpdf\u002Ftext_en.pdf Article 8(2) CFR]. === Holding === === Holding === The court first noted that one of the objectives of the GDPR is to ensure a high level of protection of data subjects’ fundamental rights and freedoms, in accordance with [[Article 1 GDPR]] and [https:\u002F\u002Fwww.europarl.europa.eu\u002Fcharter\u002Fpdf\u002Ftext_en.pdf Article 8(1) CFREU]. See ''Mousse'', C‑394\u002F23, margin 21, https:\u002F\u002Finfocuria.curia.europa.eu\u002Ftabs\u002Fdocument?source=document&text=&docid=294110&pageIndex=0&doclang=en&mode=lst&dir=&occ=first&part=1&cid=14235898 Therefore, any processing of personal data must be lawful, in accordance with [[Article 5 GDPR|Articles 5(1)(a)]] and [[Article 6 GDPR|6(1) GDPR]]. In addition, any legal basis other than consent ([[Article 6 GDPR|Article 6(1)(a) GDPR]]) must be interpreted restrictively. See ''Mousse'', C‑394\u002F23, margin 27, https:\u002F\u002Finfocuria.curia.europa.eu\u002Ftabs\u002Fdocument?source=document&text=&docid=294110&pageIndex=0&doclang=en&mode=lst&dir=&occ=first&part=1&cid=14235898 The court first noted that one of the objectives of the GDPR is to ensure a high level of protection of data subjects’ fundamental rights and freedoms, in accordance with [[Article 1 GDPR]] and [https:\u002F\u002Fwww.europarl.europa.eu\u002Fcharter\u002Fpdf\u002Ftext_en.pdf Article 8(1) CFR]. See ''Mousse'', C‑394\u002F23, margin 21, https:\u002F\u002Finfocuria.curia.europa.eu\u002Ftabs\u002Fdocument?source=document&text=&docid=294110&pageIndex=0&doclang=en&mode=lst&dir=&occ=first&part=1&cid=14235898 Therefore, any processing of personal data must be lawful, in accordance with [[Article 5 GDPR|Articles 5(1)(a)]] and [[Article 6 GDPR|6(1) GDPR]]. In addition, any legal basis other than consent ([[Article 6 GDPR|Article 6(1)(a) GDPR]]) must be interpreted restrictively. See ''Mousse'', C‑394\u002F23, margin 27, https:\u002F\u002Finfocuria.curia.europa.eu\u002Ftabs\u002Fdocument?source=document&text=&docid=294110&pageIndex=0&doclang=en&mode=lst&dir=&occ=first&part=1&cid=14235898 The court then assessed whether the processing was lawful under [[Article 6 GDPR|Article 6(1)(e)]] and [[Article 86 GDPR|86 GDPR]]. [[Article 6 GDPR|Article 6(1)(e) GDPR]] provides for a legal basis based on public interest or in the exercise of official authority vested in the controller. In the case of disclosing this data, [[Article 86 GDPR]] states that this may be done to reconcile public access to official documents with the right to the protection of personal data. The court stated that, in principle, the processing of data related to criminal convictions (including its disclosure) could be lawful under [[Article 6 GDPR|Article 6(1)(e)]] and [[Article 10 GDPR|10 GDPR]]. However, [[Article 10 GDPR]] makes the processing subject to additional restrictions (for example, the processing must provide for appropriate safeguards). In addition, limits to the fundamental rights to privacy and data protection must respect the essence of the fundamental right and be proportionate, in accordance with [https:\u002F\u002Fwww.europarl.europa.eu\u002Fcharter\u002Fpdf\u002Ftext_en.pdf Article 52(1) CFREU]. See ''Endemol Shine Finland'', C‑740\u002F22, margin 52, https:\u002F\u002Feur-lex.europa.eu\u002Flegal-content\u002FEN\u002FTXT\u002FPDF\u002F?uri=CELEX:62022CJ0740 This is especially relevant in this case, as data related to criminal convictions is particularly sensitive and its processing can be a particularly serious interference with data subjects’ fundamental rights. See ''Endemol Shine Finland'', C‑740\u002F22, margin 54, https:\u002F\u002Feur-lex.europa.eu\u002Flegal-content\u002FEN\u002FTXT\u002FPDF\u002F?uri=CELEX:62022CJ0740 The court then assessed whether the processing was lawful under [[Article 6 GDPR|Article 6(1)(e)]] and [[Article 86 GDPR|86 GDPR]]. [[Article 6 GDPR|Article 6(1)(e) GDPR]] provides for a legal basis based on public interest or in the exercise of official authority vested in the controller. In the case of disclosing this data, [[Article 86 GDPR]] states that this may be done to reconcile public access to official documents with the right to the protection of personal data. The court stated that, in principle, the processing of data related to criminal convictions (including its disclosure) could be lawful under [[Article 6 GDPR|Article 6(1)(e)]] and [[Article 10 GDPR|10 GDPR]]. However, [[Article 10 GDPR]] makes the processing subject to additional restrictions (for example, the processing must provide for appropriate safeguards). In addition, limits to the fundamental rights to privacy and data protection must respect the essence of the fundamental right and be proportionate, in accordance with [https:\u002F\u002Fwww.europarl.europa.eu\u002Fcharter\u002Fpdf\u002Ftext_en.pdf Article 52(1) CFR]. See ''Endemol Shine Finland'', C‑740\u002F22, margin 52, https:\u002F\u002Feur-lex.europa.eu\u002Flegal-content\u002FEN\u002FTXT\u002FPDF\u002F?uri=CELEX:62022CJ0740 This is especially relevant in this case, as data related to criminal convictions is particularly sensitive and its processing can be a particularly serious interference with data subjects’ fundamental rights. See ''Endemol Shine Finland'', C‑740\u002F22, margin 54, https:\u002F\u002Feur-lex.europa.eu\u002Flegal-content\u002FEN\u002FTXT\u002FPDF\u002F?uri=CELEX:62022CJ0740 The court followed the reasoning of the AG in stating that the protection of minors was an important public interest. However, the court considered the amending law incompatible with [[Article 10 GDPR]]. The law was not sufficiently precise, particularly in defining the concept of “authorised person”. The court considered that the processing was not limited to what is strictly necessary, as the circle of persons potentially entitled to submit a request was too broad. Finally, the court concurred with the AG, and stated that the amending law was not proportionate. This is because it relied on the person requesting the data to justify the need to access it. Therefore, the amending law did not provide for appropriate safeguards by relying on the self-declaration regarding the necessity and proportionality of accessing the data. The court followed the reasoning of the AG in stating that the protection of minors was an important public interest. However, the court considered the amending law incompatible with [[Article 10 GDPR]]. The law was not sufficiently precise, particularly in defining the concept of “authorised person”. The court considered that the processing was not limited to what is strictly necessary, as the circle of persons potentially entitled to submit a request was too broad. Finally, the court concurred with the AG, and stated that the amending law was not proportionate. This is because it relied on the person requesting the data to justify the need to access it. Therefore, the amending law did not provide for appropriate safeguards by relying on the self-declaration regarding the necessity and proportionality of accessing the data. The court concluded that the amending law did not meet the requirements under [[Article 10 GDPR]], meaning it could not justify its processing under [[Article 6 GDPR|Article 6(1)(e) GDPR]]. With this, Hungary had failed to fulfil its obligations under [[Article 10 GDPR]] and [https:\u002F\u002Fwww.europarl.europa.eu\u002Fcharter\u002Fpdf\u002Ftext_en.pdf Article 8(2) CFREU]. The court concluded that the amending law did not meet the requirements under [[Article 10 GDPR]], meaning it could not justify its processing under [[Article 6 GDPR|Article 6(1)(e) GDPR]]. With this, Hungary had failed to fulfil its obligations under [[Article 10 GDPR]] and [https:\u002F\u002Fwww.europarl.europa.eu\u002Fcharter\u002Fpdf\u002Ftext_en.pdf Article 8(2) CFR]. == Comment == == Comment ==","The Court of Justice of the European Union (CJEU) found that Hungary's amended law on criminal records violated GDPR Article 10 by allowing overly broad access to information about individuals convicted of sexual offences against children. The law permitted any adult relative or guardian of a minor to request and share such sensitive data without sufficient safeguards, precision, or proportionality controls. The court concluded Hungary failed to meet GDPR requirements for processing criminal conviction data and breached the fundamental right to data protection under the EU Charter.","CJEU rules Hungary's law allowing broad access to sexual offender records violates GDPR Article 10.","Help CJEU - C‑769\u002F22 - European Commission v Hungary: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 09:50, 22 April 2026 view sourceAp (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators754 editsmTag: Visual edit← Older edit Latest revision as of 13:13, 24 July 2026 view source Ap (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators754 editsm Tag: Visual edit Line 17: Line 17: |GDPR_Article_Link_3=|GDPR_Article_Link_3= |EU_Law_Name_1=Art. 8(2) CFREU|EU_Law_Name_1=Art. 8(2) CFR |EU_Law_Link_1=https:\u002F\u002Fwww.europarl.europa.eu\u002Fcharter\u002Fpdf\u002Ftext_en.pdf|EU_Law_Link_1=https:\u002F\u002Fwww.europarl.europa.eu\u002Fcharter\u002Fpdf\u002Ftext_en.pdf |EU_Law_Name_2=|EU_Law_Name_2= Line 52: Line 52: In 2021 the Commission sent a formal letter to Hungary contesting the amending law's compliance with EU law. After some unproductive back-and-forth, the Commission escalated the case to the CJEU, requesting the CJEU to declare the amending law incompatible with EU law.In 2021 the Commission sent a formal letter to Hungary contesting the amending law's compliance with EU law. After some unproductive back-and-forth, the Commission escalated the case to the CJEU, requesting the CJEU to declare the amending law incompatible with EU law. The European Commission filed four pleas, claiming that Hungary violated of a long list of provisions from primary and secondary EU law\u003Cref>The Commission alleged the violation of Articles 1, 7, 8(2), 11 and 21 CFREU; Article 2 TEU; Article 56 TFEU; Article 3(2) of the Directive on electronic commerce; Articles 16 and 19 of the Services Directive, Article 9(1)(c)(ii) of the AVMS Directive; and [[Article 10 GDPR]].\u003C\u002Fref>. Only the Commission's fourth plea invokes data protection law- specifically, [https:\u002F\u002Fwww.europarl.europa.eu\u002Fcharter\u002Fpdf\u002Ftext_en.pdf Article 8(2) of the EU Charter of Fundamental Rights (CFREU)] (\"Protection of personal data\") and [[Article 10 GDPR]] (\"Processing of personal data relating to criminal convictions and offences\").The European Commission filed four pleas, claiming that Hungary violated of a long list of provisions from primary and secondary EU law\u003Cref>The Commission alleged the violation of Articles 1, 7, 8(2), 11 and 21 CFREU; Article 2 TEU; Article 56 TFEU; Article 3(2) of the Directive on electronic commerce; Articles 16 and 19 of the Services Directive, Article 9(1)(c)(ii) of the AVMS Directive; and [[Article 10 GDPR]].\u003C\u002Fref>. Only the Commission's fourth plea invokes data protection law- specifically, [https:\u002F\u002Fwww.europarl.europa.eu\u002Fcharter\u002Fpdf\u002Ftext_en.pdf Article 8(2) of the EU Charter of Fundamental Rights (CFR)] (\"Protection of personal data\") and [[Article 10 GDPR]] (\"Processing of personal data relating to criminal convictions and offences\"). '''The fourth plea: [[Article 10 GDPR]]''''''The fourth plea: [[Article 10 GDPR]]''' Line 58: Line 58: The alleged violation of the GDPR relates to the amended law's rules on access to information about individuals convicted of sexual offences against children. The law amended the ''\"Law on the criminal record system\"'' and made documents about sexual offences accessible to a broad audience. Under the new rules, any adult who is either a relative or a guardian of a minor (\"authorised person\"), has the right to access and share information about individuals convicted of sexual offences against children (the data subjects) from bodies with access to registered data.The alleged violation of the GDPR relates to the amended law's rules on access to information about individuals convicted of sexual offences against children. The law amended the ''\"Law on the criminal record system\"'' and made documents about sexual offences accessible to a broad audience. Under the new rules, any adult who is either a relative or a guardian of a minor (\"authorised person\"), has the right to access and share information about individuals convicted of sexual offences against children (the data subjects) from bodies with access to registered data. The Commission claimed that the amended law failed to specify with sufficient clarity who is authorised to submit a data request and, therefore, did not provide sufficient guarantees for the rights and freedoms of data subjects regarding the conditions of access to their personal data. On these grounds, the Commission claimed that the amended law infringed Article 10 of the GDPR (as well as [https:\u002F\u002Fwww.europarl.europa.eu\u002Fcharter\u002Fpdf\u002Ftext_en.pdf Art. 8(2) CFREU]).The Commission claimed that the amended law failed to specify with sufficient clarity who is authorised to submit a data request and, therefore, did not provide sufficient guarantees for the rights and freedoms of data subjects regarding the conditions of access to their personal data. On these grounds, the Commission claimed that the amended law infringed Article 10 of the GDPR (as well as [https:\u002F\u002Fwww.europarl.europa.eu\u002Fcharter\u002Fpdf\u002Ftext_en.pdf Art. 8(2) CFR]). In its defense, Hungary argued that the law accurately identified \"authorised persons\" when read in light of the definition of \"relatives\" in the Hungarian civil code. Additionally, Hungary claimed that there were two additional criteria access to personal data under Hungarian law: the authorised person must consider the relevant data to be probably necessary, and it must be disproportionately difficult for them to access the subjects' data if they are not disclosed.In its defense, Hungary argued that the law accurately identified \"authorised persons\" when read in light of the definition of \"relatives\" in the Hungarian civil code. Additionally, Hungary claimed that there were two additional criteria access to personal data under Hungarian law: the authorised person must consider the relevant data to be probably necessary, and it must be disproportionately difficult for them to access the subjects' data if they are not disclosed. Line 68: Line 68: * (iii) it was disproportionately difficult for the authorized person to access the data otherwise.* (iii) it was disproportionately difficult for the authorized person to access the data otherwise. Hungary claimed that these criteria were clearly defined and provided sufficient safeguards for data subjects. On this basis, Hungary argued that the amended law complied with [[Article 10 GDPR]] and [https:\u002F\u002Fwww.europarl.europa.eu\u002Fcharter\u002Fpdf\u002Ftext_en.pdf 8(2) CFREU].Hungary claimed that these criteria were clearly defined and provided sufficient safeguards for data subjects. On this basis, Hungary argued that the amended law complied with [[Article 10 GDPR]] and [https:\u002F\u002Fwww.europarl.europa.eu\u002Fcharter\u002Fpdf\u002Ftext_en.pdf 8(2) CFR]. === Advocate General Opinion ====== Advocate General Opinion === Line 81: Line 81: Second, the AG considered that requirements (ii) and (iii) (''i.e.'': the probable necessity of the disclosure, and the difficulty of otherwise accessing the data) were overly generic and were to be assessed by the authorized person themselves. The AG argued that such a self-declaratoty regime lent itself to abuse and deprived the disclosing body of any control over the necessity and proportionality of the disclosure. For this reason, the AG opined that the amending law failed to provide the required safeguards for data subjects.Second, the AG considered that requirements (ii) and (iii) (''i.e.'': the probable necessity of the disclosure, and the difficulty of otherwise accessing the data) were overly generic and were to be assessed by the authorized person themselves. The AG argued that such a self-declaratoty regime lent itself to abuse and deprived the disclosing body of any control over the necessity and proportionality of the disclosure. For this reason, the AG opined that the amending law failed to provide the required safeguards for data subjects. On these grounds, the AG opined that the amended law was disproportionate and violated [[Article 10 GDPR]] as we","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=CJEU_-_C%E2%80%91769\u002F22_-_European_Commission_v_Hungary&diff=52487&oldid=51443","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002F8\u002F87\u002FCjeulogo.png","2026-07-24T13:13:33+00:00","2026-07-24T14:00:15.38986+00:00",7,[18,21],{"name":19,"type":20},"European Commission","vendor",{"name":22,"type":20},"Court of Justice of the European Union (CJEU)","3f0f8451-91df-4b6c-9a73-ef3b2509b7f1",{"id":23,"icon":25,"name":26,"slug":27},null,"GDPR","gdpr",[29,34,39],{"category":30},{"id":31,"icon":25,"name":32,"slug":33},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":35},{"id":36,"icon":25,"name":37,"slug":38},"614132b8-5837-4952-b8b5-c6c9a32a1d85","Privacy","privacy",{"category":40},{"id":41,"icon":25,"name":42,"slug":43},"c5c77cdb-f7d7-4990-9436-c81dcbff1163","Policy","policy",[]]