Data Protection HubCase Law

CJEU, judgment of 17 June 2021, C-597/19, M.I.C.M.

Legitimate interest of third parties in the identification of IP addresses in order to pursue copyright infringements under Article 6(1)(f) GDPR.

1 Overview

M.I.C.M. Mediarex Enterprises pursued copyright infringements committed via peer-to-peer networks. In order to identify the infringing users, it needed the IP addresses to be resolved. That required the internet service provider to disclose data. A Belgian court referred questions to the CJEU concerning the compatibility of the processing with the GDPR.

2 Headnotes

The systematic collection of IP addresses for the purpose of identifying persons who make works protected by copyright available to the public via peer-to-peer networks is in principle processing of personal data that may be based on a legitimate interest within the meaning of Article 6(1)(f) GDPR (para. 108).

The interest of a third party in establishing or defending legal claims on account of copyright infringements may constitute a legitimate interest. The processing is, however, permissible only to the extent of what is strictly necessary and must withstand scrutiny in the light of the fundamental rights of the data subjects.

3 Significance

The decision confirms the line of case law established in Rīgas satiksme: the interest of third parties in identifying a wrongdoer in order to enforce their own claims may constitute a legitimate interest. It is at the same time an example of how third-party interests may be taken into account under point (f), even where they serve the private enforcement of rights.

About the author

About the author

This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.

Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.

Follow me on LinkedIn