Data Protection HubCase Law

CJEU, judgment of 9 January 2025, C-394/23, Mousse

Necessity under Article 6(1)(f) GDPR; the right to object under Article 21 GDPR is not to be taken into account in the assessment of necessity; relationship with the transparency obligation.

1 Overview

The French railway company SNCF required customers buying tickets online to state a title of address ("Monsieur" or "Madame"). The non-governmental organization Mousse challenged that practice before the French data protection supervisory authority. The Conseil d'État referred questions to the Court of Justice concerning the interpretation of the requirement of necessity under Article 6(1)(b) and (f) GDPR.

2 Headnotes

Processing is necessary within the meaning of Article 6(1)(f) GDPR only where the legitimate interest cannot reasonably be achieved by other means that are less intrusive upon the fundamental rights and freedoms of the data subject, in particular upon the rights under Articles 7 and 8 of the Charter of Fundamental Rights of the European Union (paras. 49 et seq.).

In the assessment of necessity it is irrelevant whether the data subject has a right to object under Article 21 GDPR. The existence or non-existence of a right to object is not a criterion capable of mitigating or replacing the necessity of a processing operation (paras. 65 et seq.).

The title of address "Mr" or "Ms" is not objectively indispensable for the issue of a transport ticket. Personalized commercial communication is an interest that as a rule does not fall within the scope of point (b). Where the controller bases the processing on point (f), it must in addition carry out, at stage 3, a balancing of interests into which the transparency obligations also feed.

Where the processing is based on legitimate interests, the interest pursued must be communicated to the data subject at the time of collection (Article 13(1)(d) GDPR); if that information is missing, the processing cannot be based on Article 6(1)(f) GDPR (paras. 46, 52). The communication of the legitimate interest is therefore not a mere formality but a condition of lawfulness; the legal basis cannot be supplied after the event.

3 Significance

The decision sharpens the assessment of necessity under Article 6(1)(f) GDPR. It makes clear that the existence of the right to object does not mitigate the requirements of necessity: a controller cannot rely on the argument that the data subject "can stop the processing anyway". At the same time, the Court of Justice underlines that even apparently harmless data (such as a title of address) may be processed only where they are objectively indispensable for the specific purpose.

About the author

About the author

This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.

Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.

Follow me on LinkedIn