European Union
CJEU caselaw
C-101/01 (6 November 2003) - Bodil Lindqvist
1. The act of referring, on an internet page, to various persons and identifying them by name or by other means, for instance by giving their telephone number or information regarding their working conditions and hobbies, constitutes the processing of personal data wholly or partly by automatic means within the meaning of Article 3(1) of Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data.
2. Such processing of personal data is not covered by any of the exceptions in Article 3(2) of Directive 95/46.
3. Reference to the fact that an individual has injured her foot and is on half-time on medical grounds constitutes personal data concerning health within the meaning of Article 8(1) of Directive 95/46.
4. There is no transfer [of data] to a third country within the meaning of Article 25 of Directive 95/46 where an individual in a Member State loads personal data onto an internet page which is stored on an internet site on which the page can be consulted and which is hosted by a natural or legal person who is established in that State or in another Member State, thereby making those data accessible to anyone who connects to the internet, including people in a third country.
5. The provisions of Directive 95/46 do not, in themselves, bring about a restriction which conflicts with the general principles of freedom of expression or other freedoms and rights, which are applicable within the European Union and are enshrined inter alia in Article 10 of the European Convention for the Protection of Human Rights and Fundamental Freedoms signed at Rome on 4 November 1950. It is for the national authorities and courts responsible for applying the national legislation implementing Directive 95/46 to ensure a fair balance between the rights and interests in question, including the fundamental rights protected by the Community legal order.
6. Measures taken by the Member States to ensure the protection of personal data must be consistent both with the provisions of Directive 95/46 and with its objective of maintaining a balance between freedom of movement of personal data and the protection of private life. However, nothing prevents a Member State from extending the scope of the national legislation implementing the provisions of Directive 95/46 to areas not included in the scope thereof provided that no other provision of Community law precludes it.
Link
C-342/12 (30 May 2013) - Worten
1. Article 2(a) of Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data is to be interpreted as meaning that a record of working time, such as that at issue in the main proceedings, which indicates, in relation to each worker, the times when working hours begin and end, as well as the corresponding breaks and intervals, is included within the concept of ‘personal data’, within the meaning of that provision.
2. Article 6(1)(b) and (c) and Article 7(c) and (e) of Directive 95/46 do not preclude national legislation, such as that at issue in the main proceedings, which requires an employer to make the record of working time available to the national authority responsible for monitoring working conditions so as to allow its immediate consultation, provided that this obligation is necessary for the purposes of the performance by that authority of its task of monitoring the application of the legislation relating to working conditions, in particular as regards working time.
Judgment of the Court
C-131/12 (13 May 2014) - Google Spain et Google
1. Article 2(b) and (d) of Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data are to be interpreted as meaning that, first, the activity of a search engine consisting in finding information published or placed on the internet by third parties, indexing it automatically, storing it temporarily and, finally, making it available to internet users according to a particular order of preference must be classified as ‘processing of personal data’ within the meaning of Article 2(b) when that information contains personal data and, second, the operator of the search engine must be regarded as the ‘controller’ in respect of that processing, within the meaning of Article 2(d).
2. Article 4(1)(a) of Directive 95/46 is to be interpreted as meaning that processing of personal data is carried out in the context of the activities of an establishment of the controller on the territory of a Member State, within the meaning of that provision, when the operator of a search engine sets up in a Member State a branch or subsidiary which is intended to promote and sell advertising space offered by that engine and which orientates its activity towards the inhabitants of that Member State.
3. Article 12(b) and subparagraph (a) of the first paragraph of Article 14 of Directive 95/46 are to be interpreted as meaning that, in order to comply with the rights laid down in those provisions and in so far as the conditions laid down by those provisions are in fact satisfied, the operator of a search engine is obliged to remove from the list of results displayed following a search made on the basis of a person’s name links to web pages, published by third parties and containing information relating to that person, also in a case where that name or information is not erased beforehand or simultaneously from those web pages, and even, as the case may be, when its publication in itself on those pages is lawful.
4. Article 12(b) and subparagraph (a) of the first paragraph of Article 14 of Directive 95/46 are to be interpreted as meaning that, when appraising the conditions for the application of those provisions, it should inter alia be examined whether the data subject has a right that the information in question relating to him personally should, at this point in time, no longer be linked to his name by a list of results displayed following a search made on the basis of his name, without it being necessary in order to find such a right that the inclusion of the information in question in that list causes prejudice to the data subject. As the data subject may, in the light of his fundamental rights under Articles 7 and 8 of the Charter, request that the information in question no longer be made available to the general public on account of its inclusion in such a list of results, those rights override, as a rule, not only the economic interest of the operator of the search engine but also the interest of the general public in having access to that information upon a search relating to the data subject’s name. However, that would not be the case if it appeared, for particular reasons, such as the role played by the data subject in public life, that the interference with his fundamental rights is justified by the preponderant interest of the general public in having, on account of its inclusion in the list of results, access to the information in question.
Opinion of Advocate general
Judgment of the Court
C-683/13 (19 June 2014) - Pharmacontinente - Saúde e Higiene e.a.
1. Article 2(a) of Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data is to be interpreted as meaning that a record of working time, such as that at issue in the main proceedings, which indicates, in relation to each worker, the times when working hours begin and end, as well as the corresponding breaks and intervals, is covered by the concept of ‘personal data’ as referred to in that provision.
2. Article 6(1)(b) and (c) and Article 7(c) and (e) of Directive 95/46 must be interpreted as not precluding national legislation, such as that at issue in the main proceedings, which requires an employer to make the record of working time available to the national authority responsible for monitoring working conditions so as to allow its immediate consultation, provided that this obligation is necessary for the purposes of the performance by that authority of its task of monitoring the application of the legislation relating to working conditions, in particular as regards working time.
3. It is for the referring court to determine whether the employer’s obligation to provide the national authority responsible for monitoring working conditions access to the record of working time so as to allow its immediate consultation may be considered necessary for the purposes of the performance by that authority of its monitoring task, by contributing to the more effective application of the legislation relating to working conditions, in particular as regards working time, and, if so, whether the penalties imposed with a view to ensuring the effective application of the requirements laid down by Directive 2003/88/EC of the European Parliament and of the Council of 4 November 2003, concerning certain aspects of the organisation of working time, are consistent with the principle of proportionality.
Judgment of the Court
C-434/16 ( 20 December 2017) - Nowak
Article 2(a) of Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data must be interpreted as meaning that, in circumstances such as those of the main proceedings, the written answers submitted by a candidate at a professional examination and any comments made by an examiner with respect to those answers constitute personal data, within the meaning of that provision.
Opinion of advocate general
Judgment of the court
C-210/16 (5 June 2018) - Wirtschaftsakademie Schleswig-Holstein
Article 2(d) of Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data must be interpreted as meaning that the concept of ‘controller’ within the meaning of that provision encompasses the administrator of a fan page hosted on a social network.
Opinion of Advocate general
Judgment of court
C-25/17 (10 July 2018) - Jehovan todistajat
1. Article 2(c) of Directive 95/46 must be interpreted as meaning that the concept of a ‘filing system’, referred to by that provision, covers a set of personal data collected in the course of door-to-door preaching, consisting of the names and addresses and other information concerning the persons contacted, if those data are structured according to specific criteria which, in practice, enable them to be easily retrieved for subsequent use. In order for such a set of data to fall within that concept, it is not necessary that they include data sheets, specific lists or other search methods.
2. Article 2(d) of Directive 95/46, read in the light of Article 10(1) of the Charter of Fundamental Rights, must be interpreted as meaning that it supports the finding that a religious community is a controller, jointly with its members who engage in preaching, for the processing of personal data carried out by the latter in the context of door-to-door preaching organised, coordinated and encouraged by that community, without it being necessary that the community has access to those data, or to establish that that community has given its members written guidelines or instructions in relation to the data processing.
Opinion of Advocate general
Judgment of the court
C-345/17 (14 février 2019) - Buivids
1. Article 3 of Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data must be interpreted as meaning that the recording of a video of police officers in a police station, while a statement is being made, and the publication of that video on a video website, on which users can send, watch and share videos, are matters which come within the scope of that directive.
2. Article 9 of Directive 95/46 must be interpreted as meaning that factual circumstances such as those of the case in the main proceedings, that is to say, the video recording of police officers in a police station, while a statement is being made, and the publication of that recorded video on a video website, on which users can send, watch and share videos, may constitute a processing of personal data solely for journalistic purposes, within the meaning of that provision, in so far as it is apparent from that video that the sole object of that recording and publication thereof is the disclosure of information, opinions or ideas to the public, this being a matter which it is for the referring court to determine.
Link
C-272/19 (9 July 2020) - VQ v. Land Hessen
Article 4(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) must be interpreted as meaning that, in so far as a Petitions Committee of the parliament of a Federated State of a Member State determines, alone or with others, the purposes and means of the processing of personal data, that committee must be categorised as a ‘controller’, within the meaning of that provision, and consequently the processing of personal data carried out by that committee falls within the scope of that regulation and, in particular, of Article 15 thereof.
Judgment of the court
C-61/19 (11 November 2020) - Orange Romania SA
Article 2(h) and Article 7(a) of Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data and Article 4(11) and Article 6(1)(a) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), must be interpreted as meaning that it is for the data controller to demonstrate that the data subject has, by active behaviour, given his or her consent to the processing of his or her personal data and that he or she has obtained, beforehand, information relating to all the circumstances surrounding that processing, in an intelligible and easily accessible form, using clear and plain language, allowing that person easily to understand the consequences of that consent, so that it is given with full knowledge of the facts. A contract for the provision of telecommunications services which contains a clause stating that the data subject has been informed of, and has consented to, the collection and storage of a copy of his or her identity document for identification purposes is not such as to demonstrate that that person has validly given his or her consent, as provided for in those provisions, to that collection and storage, where
- the box referring to that clause has been ticked by the data controller before the contract was signed, or where;
- the terms of that contract are capable of misleading the data subject as to the possibility of concluding the contract in question even if he or she refuses to consent to the processing of his or her data, or where;
- the freedom to choose to object to that collection and storage is unduly affected by that controller, in requiring that the data subject, in order to refuse consent, must complete an additional form setting out that refusal.
Judgment of the court
C-659/22, RK. V. Ministerstvo Zdravotnictvi, (5 October 2023)
The concept of ‘processing’ personal data referred to in Article 4(2) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
must be interpreted as including the verification, using a national mobile application, of the validity of interoperable COVID-19 vaccination, test and recovery certificates issued pursuant to Regulation (EU) 2021/953 of the European Parliament and of the Council of 14 June 2021 on a framework for the issuance, verification and acceptance of interoperable COVID-19 vaccination, test and recovery certificates (EU Digital COVID Certificate) to facilitate free movement during the COVID-19 pandemic, and used by a Member State for national purposes.
Judgment of the court
C-683/21, Nacionalinis visuomenės sveikatos centras prie Sveikatos apsaugos ministerijos v. Valstybinė duomenų apsaugos inspekcija, (5 Décember 2023)
1. Article 4(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation),
must be interpreted as meaning that an entity which has entrusted an undertaking with the development of a mobile IT application and which has, in that context, participated in the determination of the purposes and means of the processing of personal data carried out through that application may be regarded as a controller, within the meaning of that provision, even if that entity has not itself performed any processing operations in respect of such data, has not expressly agreed to the performance of specific operations for such processing or to that mobile application being made available to the public, and has not acquired the abovementioned mobile application, unless, prior to that application being made available to the public, that entity expressly objected to such making available and to the resulting processing of personal data.
2. Article 4(7) and Article 26(1) of Regulation 2016/679
must be interpreted as meaning that the classification of two entities as joint controllers does not require that there be an arrangement between those entities regarding the determination of the purposes and means of the processing of personal data in question; nor does it require that there be an arrangement laying down the terms of the joint control.
3. Article 4(2) of Regulation 2016/679
must be interpreted as meaning that the use of personal data for the purposes of the IT testing of a mobile application constitutes ‘processing’, within the meaning of that provision, unless such data have been rendered anonymous in such a manner that the subject of those data is not or is no longer identifiable, or unless it involves fictitious data which do not relate to an existing natural person.
4. Article 83 of Regulation 2016/679
must be interpreted as meaning that (i) an administrative fine may be imposed pursuant to that provision only where it is established that the controller has intentionally or negligently committed an infringement referred to in paragraphs 4 to 6 of that article, and (ii) such a fine may be imposed on a controller in respect of personal data processing operations performed by a processor on behalf of that controller, unless, in the context of those operations, that processor has carried out processing for its own purposes or has processed such data in a manner incompatible with the framework of, or detailed arrangements for, the processing as determined by the controller, or in such a manner that it cannot reasonably be considered that that controller consented to such processing.
Opinion of Advocate general
Judgment of the court
C‑231/22, État belge contre Autorité de protection des données (11 janvier 2024)
1. Point 7 of Article 4 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation),
must be interpreted as meaning that the agency or body responsible for the official journal of a Member State, which is inter alia required, under the law of that State, to publish as they stand official acts and documents that have been prepared by third parties under their own responsibility in compliance with the applicable rules, then lodged with a judicial authority that sends them to it for publication, may, notwithstanding its lack of legal personality, be classified as a ‘controller’ of the personal data contained in those acts and documents, where the national law concerned determines the purposes and means of the processing of personal data performed by that official journal.
2. Article 5(2) of Regulation 2016/679, read in conjunction with point 7 of Article 4 and Article 26(1) thereof,
must be interpreted as meaning that the agency or body responsible for the official journal of a Member State, classified as a ‘controller’ within the meaning of point 7 of Article 4 of that regulation, is solely responsible for compliance with the principles set out in Article 5(1) thereof as regards the personal data processing operations that it is required to perform under national law, unless joint responsibility with other entities in respect of those operations arises under that law.
Décision of the Court
Opinion of Advocate General
C-604/22 (7 March 2024) - IAB Europe
1. Article 4(1) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
must be interpreted as meaning that a string composed of a combination of letters and characters, such as the TC String (Transparency and Consent String), containing the preferences of a user of the internet or of an application relating to that user’s consent to the processing of personal data concerning him or her by website or application providers as well as by brokers of such data and by advertising platforms constitutes personal data within the meaning of that provision in so far as, where those data may, by reasonable means, be associated with an identifier, such as, inter alia, the IP address of that user’s device, they allow the data subject to be identified. In such circumstances, the fact that, without an external contribution, a sectoral organisation holding that string can neither access the data that are processed by its members under the rules which that organisation has established nor combine that string with other factors does not preclude that string from constituting personal data within the meaning of that provision.
2. Article 4(7) and Article 26(1) of Regulation 2016/679
must be interpreted as meaning that:
– first, a sectoral organisation, in so far as it proposes to its members a framework of rules that it has established relating to consent to the processing of personal data, which contains not only binding technical rules but also rules setting out in detail the arrangements for storing and disseminating personal data relating to such consent, must be classified as a ‘joint controller’ for the purpose of those provisions where, in the light of the particular circumstances of the individual case, it exerts influence over the personal data processing at issue, for its own purposes, and determines, as a result, jointly with its members, the purposes and means of such processing. The fact that such a sectoral organisation does not itself have direct access to the personal data processed by its members under those rules does not preclude it from holding the status of joint controller for the purpose of those provisions;
– second, the joint controllership of that sectoral organisation does not extend automatically to the subsequent processing of personal data carried out by third parties, such as website or application providers, with regard to users’ preferences for the purposes of targeted online advertising.
Judgment of the Court
C-740/22 (7 March 2024) - Endemol Shine Finland
1. Article 2(1) and Article 4(2) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
must be interpreted as meaning that the oral disclosure of information on possible ongoing or completed criminal proceedings to which a natural person has been subject constitutes processing of personal data, within the meaning of Article 4(2) of that regulation, and comes within the material scope of that regulation where that information forms part of a filing system or is intended to form part of a filing system.
2. The provisions of Regulation 2016/679, in particular Article 6(1)(e) and Article 10 thereof,
must be interpreted as precluding data relating to criminal convictions of a natural person contained in a court’s filing system from being disclosed orally to any person for the purpose of ensuring public access to official documents, without the person requesting the disclosure of those data having to establish a specific interest in obtaining those data, it being irrelevant in that regard whether that person is a commercial company or a private individual.
Judgment of the Court
C-461/22 (11 July 2024) - MK (Curateur professionnel)
On those grounds, the Court (Ninth Chamber) hereby rules:
Article 4(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation),
must be interpreted as meaning that a former guardian who performed his or her duties in a professional capacity in respect of a person placed under his or her guardianship must be classified as a ‘controller’, within the meaning of that provision, of personal data in his or her possession concerning that person and that such processing must comply with all the provisions of that regulation, including Article 15 thereof.
Judgment of the Court
C-200/23 (4 October 2024) - Agentsia po vpisvaniyata
1. Article 21(2) of Directive (EU) 2017/1132 of the European Parliament and of the Council of 14 June 2017 relating to certain aspects of company law
must be interpreted as not imposing on a Member State an obligation to permit the disclosure, in the commercial register, of a company’s constitutive instrument subject to compulsory disclosure under that directive and containing personal data, other than the minimum personal data required, disclosure of which is not required by the law of that Member State.
2. Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), in particular Article 4(7) and (9) thereof
must be interpreted as meaning that the authority responsible for maintaining the commercial register of a Member State which publishes, in that register, the personal data contained in a company’s constitutive instrument, which is subject to compulsory disclosure under Directive 2017/1132 and was transmitted to it in an application for registration of the company concerned in that register, is both a ‘recipient’ of those data and, particularly in so far as it makes them available to the public, a ‘controller’ of those data, within the meaning of that provision, even where that instrument contains personal data not required by that directive or by the law of that Member State.
3. Directive 2017/1132, in particular Article 16 thereof, and Article 17 of Regulation 2016/679
must be interpreted as precluding a Member State’s legislation or practice which leads the authority responsible for maintaining the commercial register of that Member State to refuse any request for erasure of personal data not required by that directive or by the law of that Member State, contained in a company’s constitutive instrument published in that register, where a copy of that instrument in which those data have been redacted has not been provided to that authority, contrary to the procedural rules laid down by that legislation.
4. Article 4(1) of Regulation 2016/679
must be interpreted as meaning that the handwritten signature of a natural person is covered by the concept of ‘personal data’ within the meaning of that provision.
5. Article 82(1) of Regulation 2016/679
must be interpreted as meaning that a loss of control, for a limited period, by the data subject over his or her personal data, on account of those data being made available online to the public, in the commercial register of a Member State, may suffice to cause ‘non-material damage’, provided that that data subject demonstrates that he or she has actually suffered such damage, however minimal, without that concept of ‘non-material damage’ requiring that the existence of additional tangible adverse consequences be demonstrated.
6. Article 82(3) of Regulation 2016/679
must be interpreted as meaning that an opinion of the supervisory authority of a Member State, issued on the basis of Article 58(3)(b) of that regulation, is not sufficient to exempt from liability, under Article 82(2) of that regulation, the authority responsible for maintaining the commercial register of that Member State which has the status of ‘controller’, within the meaning of Article 4(7) of that regulation
Opinion of Advocate general
Judgement of the Court
C-638/23 (27 February 2025) - Amt der Tiroler Landesregierung
Article 4(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
must be interpreted as not precluding national legislation which designates, as controller, an auxiliary administrative entity lacking legal personality and legal capacity of its own, without specifying, in a precise manner, the specific processing operations of personal data for which that entity is responsible or the purpose of those operations in so far as, first, such an entity is able to fulfil, in accordance with that national legislation, the obligations on a controller towards data subjects with respect to the protection of personal data and, second, that national legislation determines, explicitly or at least implicitly, the scope of the processing of personal data for which that entity is responsible.
Judgment of the Court
C-492/23 (2 December 2025) - Russmedia Digital and Inform Media Press
1. Article 5(2) and Articles 24 to 26 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation),
must be interpreted as meaning that the operator of an online marketplace, as controller, within the meaning of Article 4(7) of that regulation, of the personal data contained in advertisements published on its online marketplace, is required, before the publication of the advertisements and by means of appropriate technical and organisational measures,
– to identify the advertisements that contain sensitive data in terms of Article 9(1) of that regulation,
– to verify whether the user advertiser preparing to place such an advertisement is the person whose sensitive data appear in that advertisement and, if this is not the case,
– to refuse publication of that advertisement, unless that user advertiser can demonstrate that the data subject has given his or her explicit consent to the data in question being published on that online marketplace, within the meaning of Article 9(2)(a), or that one of the other exceptions provided for in Article 9(2)(b) to (j) is satisfied.
Opinion of the Advocate General
Judgment of the Court
Retour au sommaire
Netherlands
Door: Nelisa de Bruin
Hoge Raad 16 maart 2018, ECLI:NL:HR:2018:365 (Geen verstrekking medische analyse want geen persoonsgegevens)
NB: Wet bescherming persoonsgegevens (vervallen per 25 mei 2018)
De zaak betreft een vordering tot inzage in een notitie met bevindingen van een radioloog, nadat de eisende partij de verwerende partijen aansprakelijk heeft gesteld voor een bij de keizersnede van eisende partij gemaakte beroepsfout.
De Hoge Raad overweegt dat er geen sprake is van een vordering van inzage in medische gegevens, maar inzage in een medische analyse. Het hof heeft dit geval terecht gelijkgesteld met het geval van het arrest van het HvJEU van 17 juli 2014, gevoegde zaken C-141/12 en C-372/12, ECLI:EU:C:2014:2081. De vordering is gericht op verkrijging van informatie ten behoeve van de procedure en niet op het doel waartoe Richtlijn 95/46/EG strekt. De Hoge Raad oordeelt dat het dus niet gaat om persoonsgegevens, zodat het hof terecht heeft geoordeeld dat eiseres aan de Wbp niet een recht op verstrekking van de medische analyse kan ontlenen.
Raad van State 30 juli 2025, ECLI:NL:RVS:2025:3561 (vermelding locatieaanduiding voor een boom in de openbare ruimte ter hoogte van adres [appellante sub 1] in overzicht Meldingen is geen persoonsgegeven)
Op 8 oktober 2022 heeft [appellant sub 1] de burgemeester van Eindhoven op grond van de Woo verzocht om informatie over een vermeend buurtonderzoek aan de Lorrainelaan in Eindhoven. Een medewerker heeft het overzicht Meldingen verstrekt, waarbij gegevens die herleidbaar zijn naar de melder(s) zijn geanonimiseerd. Volgens [appellant sub 1] is het adres van een object, in dit geval ter aanduiding van een dorre boom op openbare weg, een persoonsgegeven en de vermelding daarvan in het overzicht Meldingen in strijd met de AVG. De rechtbank stelt [appellant sub 1] in het gelijk.
De RvS is van oordeel dat de vermelding van de locatie geen persoonsgegevens is in de zin van artikel 4 lid 1 AVG en dus ook geen strijd met de AVG. De RvS overweegt dat: “[locatie] is slechts in het systeem van de burgemeester verwerkt als een locatieaanduiding voor een boom in de openbare ruimte vanwege een melding over problemen met de boom in de openbare ruimte ter hoogte van dit adres. Naar aanleiding van het Woo-verzoek van [appellant sub 1] over een buurtonderzoek aan de Lorrainelaan en meldingen over haar door bewoners van de Lorrainelaan is uit het systeem een overzicht gegenereerd van alle meldingen gerelateerd aan [locatie]. Het is ongelukkig dat op het overzicht Meldingen ook de melding over de locatieaanduiding van de boom is opgenomen in een overzicht met als titel "Meldingen woonoverlast", aangezien deze melding niet gaat over persoonlijke overlast door [appellant sub 1] en het strikt genomen ook niet valt onder haar Woo-verzoek. Dit alleen maakt echter niet dat de burgemeester met de locatieaanduiding van de boom in zijn systeem, en de opname daarvan in het overzicht Meldingen, toch een persoonsgegeven van [appellant sub 1] heeft verwerkt.”
Hoge Raad 13 maart 2026, ECLI:NL:HR:2026:392 (Vastleggen of opslaan foto met gezichtsafbeelding geen verwerking van biometrische gegevens; prejudiciële vragen over verhouding Wwft en AVG)
Tussenarrest van ECLI:NL:HR:2026:921
Het gaat in deze zaak om het opslaan van een kopie van een identificatiebewijs met foto als onderdeel van de door ICS gehanteerde methoden van identificatie. Voor wat betreft de AVG, gaat het in de kern om de volgende vragen: “In de eerste plaats is dat de vraag of het vastleggen of opslaan van een (pas)foto door ICS kan worden aangemerkt als verwerking van biometrische gegevens met het oog op de unieke identificatie van een persoon, hetgeen op grond van art. 9 lid 1 Algemene verordening gegevensbescherming (hierna: AVG)1 in beginsel verboden is. Daarnaast is de vraag aan de orde of art. 33 Wwft, waarin uitvoering is gegeven aan art. 40 van de (gewijzigde) Europese vierde anti-witwasrichtlijn2, een verplichting bevat voor het opslaan en bewaren van (pas)foto’s door ICS en, zo ja, hoe deze zich verhoudt tot de AVG.”
De Hoge Raad oordeelt als volgt. Het (enkele) vastleggen of opslaan van een foto met een gezichtsafbeelding impliceert geen verwerking van biometrische gegevens als bedoeld in art. 4, aanhef en onder 14, AVG. Daarbij is relevant dat uit punt 51 van de considerans blijkt dat “de verwerking van een foto met een gezichtsafbeelding van een persoon slechts een verwerking van biometrische gegevens is, indien de foto voorwerp is van een specifieke technische verwerking met betrekking tot de fysieke, fysiologische of gedragsgerelateerde kenmerken van een natuurlijke persoon op grond waarvan eenduidige identificatie van die natuurlijke persoon mogelijk is of wordt bevestigd.”
Ten aanzien van de tweede vraag stelt de Hoge Raad prejudiciële vragen, aangezien daarover nog geen sprake is van een acte clair of acte éclairé:
“3. Kunnen foto’s waarop een persoon herkenbaar is afgebeeld, worden beschouwd als persoonsgegevens waaruit ras of etnische afkomst blijken als bedoeld in art. 9 lid 1 AVG, en zo ja, onder welke voorwaarden?
a. Is in dat verband van belang of de desbetreffende foto wordt verwerkt met het doel of oogmerk om onderscheid te maken naar ras of etnische afkomst?
b. Is in dit verband van belang of informatie over ras of etnische afkomst met een voldoende mate van zekerheid uit de desbetreffende foto kan worden afgeleid?”
Hoge Raad 12 juni 2026, ECLI:NL:HR:2026:921 (Vastleggen of opslaan foto met gezichtsafbeelding geen verwerking van biometrische gegevens; prejudiciële vragen over verhouding Wwft en AVG)
De zaak ziet in cassatie op twee vragen naar aanleiding van een geschil tussen een creditcardhouder en International Card Services B.V. (ICS). De creditcardhouder weigerde mee te werken aan de identificatieplicht, waarbij een foto van een identiteitsbewijs en een foto van haarzelf moest worden aangeleverd.
De eerste vraag is of het vastleggen of opslaan van een (pas)foto door ICS kan worden aangemerkt als verwerking van biometrische gegevens met het oog op de unieke identificatie van een persoon. De tweede vraag is of art. 33 Wwft, waarin uitvoering is gegeven aan art. 40 van de (gewijzigde) Europese vierde anti-witwasrichtlijn, een verplichting bevat voor het opslaan en bewaren van (pas)foto’s door ICS en, zo ja, hoe deze zich verhoudt tot de AVG.
De Hoge Raad oordeelt dat het (enkele) vastleggen of opslaan van een foto met een gezichtsafbeelding geen verwerking van biometrische gegevens impliceert als bedoeld in art. 4, aanhef en onder 14, AVG, en verwijst daarbij naar punt 51 van de considerans waaruit volgt dat er sprake moet zijn van een “specifieke technische verwerking met betrekking tot de fysieke, fysiologische of gedragsgerelateerde kenmerken van een natuurlijke persoon op grond waarvan eenduidige identificatie van die natuurlijke persoon mogelijk is of wordt bevestigd”.
Ten aanzien van de tweede vraag overweegt de Hoge Raad dat het HvJ EU zich nog niet uitgelaten over de vraag of art. 40 lid 1, aanhef en onder a, van de (gewijzigde) vierde anti-witwasrichtlijn, bezien in verhouding tot de hiervoor vermelde bepalingen van de AVG, en dus worden de volgende prejudiciële vragen gesteld:
“1. Kan het vastleggen en opslaan van een foto met een gezichtsafbeelding van een persoon met het doel om deze voor identificatie te gebruiken, worden beschouwd als de verwerking van een biometrisch gegeven in de zin van art. 9 lid 1 van Verordening (EU) 2016/679 (Algemene verordening gegevensbescherming, AVG) in verbinding met art. 4, aanhef en onder 14 AVG, en, zo ja, onder welke voorwaarden?
2. Dient art. 40 lid 1, aanhef en onder a, van Richtlijn (EU) 2015/849 van 20 mei 2015 (de (gewijzigde) Europese vierde anti-witwasrichtlijn), mede bezien in verhouding tot art. 6 lid 3 AVG, het in art. 5 lid 1, aanhef en onder c, AVG vervatte beginsel van minimale gegevensverwerking, art. 7, 8 en 52 van het Handvest van de grondrechten van de Europese Unie, en art. 8 van het Europees Verdrag voor de Rechten van de Mens aldus te worden uitgelegd dat de lidstaten meldingsplichtige entiteiten dienen te verplichten tot het bewaren van een afschrift van het identiteitsbewijs dat is gebruikt bij de verificatie van de identiteit van een cliënt in het kader van een cliëntenonderzoek?
3. Indien vraag 2 bevestigend moet worden beantwoord: omvat de door de lidstaten te implementeren bewaarplicht van de meldingsplichtige entiteiten dan een volledig afschrift van de relevante pagina’s van een identiteitsbewijs, met inbegrip van de op het identiteitsbewijs aangebrachte foto?
4. Kunnen foto’s waarop een persoon herkenbaar is afgebeeld, worden beschouwd als persoonsgegevens waaruit ras of etnische afkomst blijkt als bedoeld in art. 9 lid 1 AVG, en zo ja, onder welke voorwaarden?
a. Is in dat verband van belang of de desbetreffende foto wordt verwerkt met het doel of oogmerk om onderscheid te maken naar ras of etnische afkomst?
b. Is in dit verband van belang of informatie over ras of etnische afkomst met een voldoende mate van zekerheid uit de desbetreffende foto kan worden afgeleid?”
Retour au sommaire