CJEU, judgment of 4 October 2024, C-446/21, Schrems/Meta
Scope of the concept of sensitive data under Article 9 GDPR in the context of advertising on social networks; restrictive interpretation of Article 9(2)(e) and obligation to impose a time limit on the processing.
1 Overview
The judgment concerns a dispute between the Austrian data protection activist Maximilian Schrems and Meta Platforms Ireland and gives concrete shape to the protective regime of Article 9 GDPR in the context of advertising-financed social networks. The Court tightens the requirements of purpose limitation and data minimization in the case of personalized advertising and interprets the exception for data "manifestly made public" (Article 9(2)(e) GDPR) restrictively.
Reference: CJEU, judgment of 4 October 2024, C-446/21, Schrems/Meta Platforms Ireland
2 Facts
Meta processes user data for the purposes of personalized advertising and in doing so combines data from different sources, both on-site (within the Facebook services) and off-site (from other websites and apps). At a public panel discussion, Schrems had given indications as to his sexual orientation. It fell to be clarified under what conditions Meta may use such data for personalized advertising.
3 Decision
3.1 Data minimization and limitation in time
The Court emphasizes the principle of data minimization (Article 5(1)(c) GDPR) as an independent limit: processing of personal data for advertising purposes without any limitation in time and without distinction is impermissible even where the data were lawfully collected. The controller must align the duration of storage and processing with the purpose and must continuously minimize the volume of data held.
3.2 Restrictive interpretation of Article 9(2)(e) GDPR
For the exception covering data manifestly made public, the Court requires that the data subject intended, by an explicit and clear affirmative action, to make the data accessible to the general public. A blanket release of all data subsequently accessible does not follow from a public self-disclosure.
Even where a person's sexual orientation becomes known in a public format (for example a live-streamed panel discussion), this does not justify further processing for the purposes of aggregation and analysis in the context of personalized advertising. Purpose limitation and proportionality restrict the reach of the exception even where its conditions are met.
3.3 Implications for personalized advertising
The principles of purpose limitation and data minimization give rise to specific obligations for advertising-financed platforms:
- differentiation between data collected on-site and off-site when assessing the purpose,
- limitation of the processing of sensitive data to what is strictly necessary for the specific purpose,
- continuous review of the storage period and of the obligations to erase,
- a clear separation between the exception under Article 9(2) GDPR and compliance with the general principles of Articles 5 and 6 GDPR.
4 Significance
The judgment strengthens the position of the data protection principles as against the grounds for lawful processing. It makes clear that Article 9(2)(e) GDPR does not leave data that have become public "without protection" and that the principle of data minimization remains an independent and continuing obligation of the controller. Business models that rest on permanent collection of data going beyond the purpose must demonstrate that they ensure limitation in terms of time and purpose.
About the author
About the author
This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.
Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.
According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.
Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.
His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.
For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.
CJEU, judgment of 9 January 2025, C-394/23, Mousse
Necessity under Article 6(1)(f) GDPR; the right to object under Article 21 GDPR is not to be taken into account in the assessment of necessity; relationship with the transparency obligation.
CJEU, judgment of 4 October 2024, C-21/23, Lindenapotheke
Order data relating to pharmacy-only medicinal products are data concerning health within the meaning of Article 9(1) GDPR; admissibility of national rules conferring standing on competitors under unfair competition law.