[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2SwqPdgHYDPUn6CtMxlWDM8dKH8137sanE6V-UOcksM":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"421a005e-395b-42af-8b08-17cc954f7504","german-court-forces-jehovahs-witnesses-to-honor-gdpr-data-access-rights","221d6205-53ec-4949-9a78-acda39b80865","German Court Forces Jehovah's Witnesses to Honor GDPR Data Access Rights","A Berlin court ruled that a Jehovah's Witnesses congregation unlawfully withheld personal data from a former member by citing religious confidentiality as justification. The ruling underscores that EU law — specifically GDPR Article 15 (Right of Access) — supersedes domestic religious privilege claims in most data access scenarios. Organizations, including religious bodies, cannot selectively apply GDPR exemptions without a clear, proportionate legal basis. This matters because individuals have a fundamental right to know what personal data is held about them and how it is being used, regardless of the type of organization processing it.","**Immediate actions:**\n- Conduct an audit of all personal data held on former members or clients to ensure it is catalogued and retrievable upon request.\n- Establish a formal Subject Access Request (SAR) intake process with documented response timelines aligned to GDPR's 30-day requirement.\n\n**Policy & Governance improvements:**\n- Review and update any internal confidentiality or data-sharing policies to ensure they do not conflict with GDPR obligations, seeking legal counsel where exemptions are claimed.\n- Train staff and leadership on the limits of religious or professional privilege exemptions under GDPR, clarifying that EU law takes primacy.\n- Designate a Data Protection Officer (DPO) or equivalent responsible for handling data subject rights requests and regulatory correspondence.\n\n**Detection & Accountability measures:**\n- Implement logging of all data subject rights requests (access, erasure, rectification) to create an auditable trail of compliance activity.\n- Schedule annual GDPR compliance reviews to identify gaps between internal data-handling practices and evolving regulatory interpretations.",[12,13,14,15,16,17,18,19,20],"GDPR Article 15 – Right of Access","GDPR Article 17 – Right to Erasure","GDPR Article 85 – Processing and Freedom of Expression (religious exemption limits)","GDPR Recital 165 – Religious organisations and data processing","NIST SP 800-53 IP-1 (Individual Access)","NIST SP 800-53 AR-1 (Governance and Privacy Policies)","CIS Control 3 – Data Protection","ISO\u002FIEC 27701 – Privacy Information Management (PIMS)","ITIL Service Management – Request Fulfilment (for SAR handling processes)","published","2026-08-12T10:21:12.97333+00:00","2026-08-12T10:21:12.861+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=VG_Berlin_-_42_K_25\u002F25&diff=52680&oldid=52675","vg-berlin-42-k-25-25-ad6f12","VG Berlin - 42 K 25\u002F25",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":36,"name":37,"slug":38,"description":39,"color":40},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":42,"name":43,"slug":44,"description":45,"color":46},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]