Data Protection HubCase Law

CJEU, Judgment of 24 September 2019, C-136/17, GC and Others/CNIL

De-listing requests against search engine operators; normative precedence of data protection and privacy in the case of name-based searches, particular requirements in the case of sensitive data.

1 Overview

The proceedings concerned de-listing requests brought by several data subjects against Google. The French data protection authority (CNIL) had ordered Google to remove certain links from name-based search results. The CJEU sets out in greater detail the conditions governing the so-called right to be forgotten and the legal basis for search engines.

Reference: CJEU, judgment of 24 September 2019, C-136/17, GC and Others/CNIL

2 Normative precedence of data protection in the case of name-based searches

For name-based searches, the Court derives from Articles 7 and 8 of the Charter of Fundamental Rights of the European Union (CFR) a precedence in principle of personality rights and data protection rights. That precedence applies not only vis-à-vis the economic interest of the search engine operator, but also vis-à-vis the interest of the general public in obtaining information.

3 Sensitive data (Article 9 GDPR)

Where a data subject seeks the de-listing of links to content containing sensitive data, the search engine operator must examine whether the inclusion of the link is strictly necessary in order to protect the freedom of information of internet users. The mere accessibility of the data by way of a search engine does not meet that standard.

4 Significance for Article 6(1)(f) GDPR

The decision shapes the balancing of interests for search engine operators and for online providers engaged in comparable activities. The "rule-exception mechanism" of the Google Spain decision is carried forward under the GDPR and tightened further for sensitive data.

About the author

About the author

This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.

Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.

Follow me on LinkedIn