CJEU, judgment of 4 October 2024, C-621/22, Koninklijke Nederlandse Lawn Tennisbond
Commercial interest as a legitimate interest within the meaning of Article 6(1)(f) GDPR; lawfulness of the interest; balancing in the case of transmission of members' data to third parties.
1 Overview
The Netherlands tennis association transmitted personal data of its members, for consideration, to two sponsors, one of them a gambling operator, which then sent advertising to the members. The Netherlands data protection authority imposed a fine. The association relied, among other things, on Article 6(1)(f) GDPR. The Amsterdam District Court referred to the CJEU the question whether a purely commercial interest can be a legitimate interest within the meaning of that provision.
2 Headnotes
A commercial interest of the controller may in principle be a legitimate interest within the meaning of Article 6(1)(f) GDPR, provided that it is not unlawful. What is decisive is an assessment in the individual case which takes account of the applicable legal environment (paras. 40, 49).
Necessity is to be assessed narrowly: the processing is necessary only where the interest cannot reasonably be achieved by less intrusive means (paras. 42 et seq., 51 et seq.).
The balancing exercise must take into account not only the immediate effects but also possible wider risks, for example where the data are transmitted to a gambling operator and this may entail risks of gambling addiction for the data subjects (para. 56).
3 Significance
The decision makes clear that a purely economic motive may qualify as a legitimate interest, while at the same time remaining bound by the strict standard of necessity and balancing established in the case law of the CJEU. It is also a practical example of the fact that secondary consequential harm (here, health risks arising from gambling advertising) must likewise be factored into the balancing exercise.
About the author
About the author
This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.
Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.
According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.
Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.
His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.
For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.
CJEU, judgment of 7 December 2023, C-634/21, SCHUFA Holding (Scoring)
Automated decisions and profiling under Article 22 GDPR; limits of Member State implementation under Article 22(2)(b) GDPR; the balancing of interests must not be pre-empted.
CJEU, judgment of 17 June 2021, C-597/19, M.I.C.M.
Legitimate interest of third parties in the identification of IP addresses in order to pursue copyright infringements under Article 6(1)(f) GDPR.