CJEU, Judgment of 29 July 2019, C-40/17, Fashion ID
Joint controllership where social plugins are embedded; legal basis under Article 7(f) of the Data Protection Directive (today Article 6(1)(f) GDPR).
1 Overview
The decision concerned the embedding of a Facebook Like button on the website of an online retailer. The Court addressed two central questions: joint controllership under Article 26 GDPR and the legal basis for the disclosure of data to the provider of the plugin.
Reference: CJEU, judgment of 29 July 2019, C-40/17, Fashion ID
2 Joint controllership
The operator of a website that embeds a Facebook Like button is jointly responsible with Facebook for the collection and transmission of the users' data. That responsibility is, however, limited to the phase of the processing in which the website operator is actually able to influence the means and purposes.
3 Legal basis
The Court states that, in the case of joint controllership, each controller must be able to show a legitimate interest in respect of its own contribution. Consent is required for processing operations that take place before or during the user's interaction with the plugin; for subsequent processing carried out by Facebook itself, the website operator does not remain responsible.
About the author
About the author
This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.
Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.
According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.
Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.
His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.
For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.
CJEU, Judgment of 4 May 2017, C-13/16, Rīgas satiksme
Interpretation of the balancing-of-interests clause in Article 7(f) of the Data Protection Directive; three-stage test and the standard of necessity.
CJEU, Judgment of 24 September 2019, C-136/17, GC and Others/CNIL
De-listing requests against search engine operators; normative precedence of data protection and privacy in the case of name-based searches, particular requirements in the case of sensitive data.