[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fLOng9ho3UZZHX2BtkDAhY9CAHxIk_ohTxhA7PFhl5R4":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":43},"de857e35-59b7-408c-a6b0-911a4545713e","cjeu-rules-individuals-can-demand-erasure-from-church-baptismal-records-under-gdpr","b6b15f1e-28f8-4d0b-9141-a2710c9d12bc","CJEU Rules Individuals Can Demand Erasure from Church Baptismal Records Under GDPR","The CJEU Advocate General's opinion in case C-12\u002F25 affirms that Article 17 GDPR's 'right to erasure' extends to religious organizations maintaining baptismal registers, when continued data processing causes emotional distress to individuals who have left the faith. This ruling highlights that no organization — including religious institutions — is categorically exempt from GDPR obligations simply by virtue of their historical record-keeping traditions. The burden falls on the data controller (the Diocese) to demonstrate overriding legitimate grounds for retention, such as archiving or historical research, rather than assuming perpetual lawfulness of processing. Failure to honor valid erasure requests without documented justification exposes organizations to regulatory enforcement and reputational harm.","**Immediate actions:**\n- Audit all personal data held in legacy or traditional records (including physical registers) to assess GDPR applicability and legal basis for processing.\n- Establish a documented process for receiving, logging, and responding to Data Subject Requests (DSRs), including erasure requests, within the statutory 30-day window.\n\n**Policy & Legal Alignment:**\n- Review and update data retention policies to explicitly address when archiving or historical research exemptions under Article 17(3) GDPR legitimately override erasure requests.\n- Engage legal counsel to map all data processing activities against lawful bases and document legitimate interests assessments (LIAs) for long-term record retention.\n- Ensure privacy notices accurately reflect the types of data held, the purposes of processing, and individuals' rights under GDPR.\n\n**Long-term improvements:**\n- Train staff responsible for record management on GDPR rights, particularly Articles 17 and 21, so erasure and objection requests are handled correctly and escalated appropriately.\n- Implement a formal Data Protection Impact Assessment (DPIA) process for any data processing that may cause emotional, reputational, or psychological harm to data subjects.\n- Appoint or verify a designated Data Protection Officer (DPO) to provide ongoing compliance oversight across all data processing activities, including those rooted in tradition or canon law.",[12,13,14,15,16,17,18,19,20,21,22],"GDPR Article 17 (Right to Erasure \u002F Right to be Forgotten)","GDPR Article 17(3) (Exemptions to Erasure)","GDPR Article 21 (Right to Object)","GDPR Article 6 (Lawful Basis for Processing)","GDPR Article 37-39 (Data Protection Officer Requirements)","GDPR Article 35 (Data Protection Impact Assessment)","NIST SP 800-53 IP-3 (Information Management and Retention)","NIST Privacy Framework PR.DS-P (Data Processing Policies)","CIS Control 3 (Data Protection)","ISO\u002FIEC 27701:2019 (Privacy Information Management)","ITIL Service Management — Request Fulfilment (DSR handling)","published","2026-10-06T16:21:43.187982+00:00","2026-10-06T16:21:42.897+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=CJEU_-_C-12\u002F25&diff=53308&oldid=53294","cjeu-c-12-25-94c1e9","CJEU - C-12\u002F25",[31,37],{"id":32,"name":33,"slug":34,"description":35,"color":36},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":38,"name":39,"slug":40,"description":41,"color":42},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]