Data Protection HubCase Law

CJEU, judgment of 8 December 2022, C-180/21, Inspectoratul General pentru Imigrări

Processing of personal data by public authorities in judicial proceedings; delimitation between Article 6(1)(c) and (e) GDPR and in relation to Directive (EU) 2016/680.

1 Overview

The request for a preliminary ruling concerned the processing of personal data by a Romanian administrative authority in the context of civil proceedings. The CJEU delimits the scope of application of the GDPR and of Directive (EU) 2016/680 (the Law Enforcement Directive) and assesses the legal bases for processing by public authorities.

Reference: CJEU, judgment of 8 December 2022, C-180/21, Inspectoratul General pentru Imigrări

2 Scope of application of the GDPR

Where a public authority does not act for the purposes of the prevention, investigation, detection or prosecution of criminal offenses, but in other proceedings (for example as a party to civil proceedings or in the context of a disciplinary measure), the GDPR remains applicable. Directive (EU) 2016/680 cannot be extended to such processing operations.

3 Legal basis under Article 6(1)(c) or (e) GDPR

The processing carried out by the authority is based either on a legal obligation (point (c)) or on the performance of a task carried out in the public interest or in the exercise of official authority (point (e)). The Court makes clear that it is irrelevant whether, in the specific proceedings, the authority appears on an equal footing with the other parties involved or acts in the exercise of public powers: the classification as the performance of a public task is preserved.

4 Change of purpose

Where the authority processes data collected for a particular administrative purpose for a new (judicial) purpose, Article 6(4) GDPR must be observed. Further processing is permissible only where it is compatible or rests on an appropriate legal basis.

About the author

About the author

This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.

Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.

Follow me on LinkedIn