Back to all lessons
Awareness Lessons
4 months ago

CJEU Rules Courts May Process Unlawfully Obtained Personal Data as Evidence Under GDPR

The CJEU's ruling in C-484/24 clarifies a critical tension between judicial proceedings and GDPR's right to erasure: courts may process personal data as evidence even when that data was initially collected unlawfully, provided national law establishes clear conditions and processing remains proportionate. This matters because organizations and individuals cannot assume that unlawfully obtained data will be automatically excluded from legal proceedings simply by invoking Article 17 erasure rights. The ruling underscores that GDPR's legal obligation basis (Article 6(1)(c)) can override erasure requests in judicial contexts, but this does not grant carte blanche — data minimization principles still apply. Security and compliance teams must understand that GDPR protections have nuanced exceptions in litigation scenarios, making lawful data collection practices even more critical to avoid data being used against an organization in court.

Tactical Insight

Immediate actions

  • Review your organization's data collection practices to ensure all personal data is obtained lawfully, reducing exposure in potential litigation scenarios.
  • Audit current data subject erasure requests to identify any cases that may intersect with ongoing or anticipated legal proceedings.

Long-term improvements

  • Establish a documented legal hold policy that aligns GDPR data minimization requirements with national procedural law obligations.
  • Train legal, compliance, and security teams on how GDPR Article 6(1)(c) interacts with judicial processes so evidence-handling decisions are informed and defensible.
  • Embed privacy-by-design principles into all data collection workflows to minimize the risk of unlawfully obtained data entering your data estate.

Detection & governance measures

  • Implement data lineage tracking so the origin and lawfulness of all personal data can be audited and demonstrated in legal or regulatory proceedings.
  • Establish a cross-functional privacy committee to assess the proportionality and necessity of data processing activities against evolving CJEU and national court interpretations.