CJEU Rules GDPR Complaint Rights Independent of Judicial Remedies
The CJEU clarified that data subjects retain the right to file complaints with supervisory authorities (such as a Data Protection Authority) even when they have already pursued judicial remedies against a controller or processor. Organizations that assumed parallel proceedings would neutralize regulatory scrutiny were operating under a flawed legal assumption. This ruling reinforces that GDPR provides layered, independent enforcement pathways — supervisory, judicial, and civil — that cannot be used to obstruct one another. Failing to recognize this distinction exposes organizations to simultaneous regulatory investigations and court actions, compounding legal and reputational risk.
Tactical Insight
Immediate actions
- Review your organization's complaint-handling procedures to ensure they account for concurrent supervisory and judicial proceedings under GDPR.
- Brief your legal and compliance teams on the CJEU ruling to prevent incorrect assumptions about complaint admissibility blocking regulatory exposure.
Organizational policy improvements
- Update your Data Subject Rights (DSR) response policy to explicitly recognize that complaints to a DPA and court actions are parallel, independent rights.
- Establish clear escalation paths so that any incoming DPA complaint is treated as active regardless of ongoing litigation involving the same data subject.
- Train customer-facing and legal staff on GDPR Articles 77, 78, and 79 to ensure accurate communication with data subjects about their available remedies.
Long-term compliance improvements
- Conduct a periodic GDPR enforcement landscape review to incorporate key CJEU rulings into your compliance framework.
- Implement a centralized case management system to track simultaneous supervisory and judicial actions involving the same matter or data subject.
- Engage external Data Protection counsel annually to audit your complaint-handling processes against current EU case law.