CJEU, judgment of 4 May 2023, C-60/22, Bundesrepublik Deutschland (BAMF)
Infringements of Article 26 GDPR (joint controllership) and Article 30 GDPR (records of processing activities) do not in themselves render the processing unlawful; no erasure or restriction of processing on the ground of purely documentary infringements.
1 Overview
An asylum seeker brought proceedings before the Wiesbaden Administrative Court (VG Wiesbaden) against the Federal Republic of Germany because the German Federal Office for Migration and Refugees (BAMF) had kept his asylum file electronically and had transmitted extracts from it to the court without being able to produce a complete record of processing activities under Article 30 GDPR or an arrangement on joint controllership under Article 26 GDPR. The VG Wiesbaden referred to the CJEU the question whether such infringements render the processing unlawful and whether the data subject has a right to erasure (Article 17 GDPR) or to restriction of processing (Article 18 GDPR).
2 Headnotes
A breach of the obligation to conclude an arrangement on joint controllership under Article 26 GDPR and of the obligation to maintain a record of processing activities under Article 30 GDPR does not constitute a case of unlawful processing within the meaning of Article 17(1)(d) and Article 18(1)(b) GDPR (paras. 60-62, operative part).
What is decisive for the lawfulness of the processing is solely the principles laid down in Article 5 GDPR and the existence of a legal basis under Article 6 GDPR. By contrast, the documentation and organizational obligations under Articles 26 and 30 GDPR constitute self-standing obligations, breaches of which are penalized through the regulatory and administrative fine sanctions of the GDPR, without "infecting" the underlying processing itself.
3 Significance
The decision draws a clean distinction between formal documentation obligations and substantive lawfulness. It takes away from practice the argument that a missing or incomplete record of processing activities (or a missing arrangement on joint controllership) is automatically a lever for claims to erasure or restriction. Conversely, the obligation to maintain proper documentation under Article 30 GDPR remains subject to administrative fines in its own right (Article 83(4)(a) GDPR); it is simply not a benchmark under Article 6 GDPR.
That finding can be transferred to other accompanying obligations: the absence of a data protection impact assessment (Article 35 GDPR) or of proper information to data subjects (Articles 13 and 14 GDPR) likewise does not render otherwise lawful processing unlawful retroactively, although it does make it liable to an administrative fine.
About the author
About the author
This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.
Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.
According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.
Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.
His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.
For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.
CJEU, judgment of 7 December 2023, C-26/22 and C-64/22, SCHUFA Holding (Libération de reliquat de dette)
Three-stage test under Article 6(1)(f) GDPR for the storage by credit information agencies of information from public insolvency registers; necessity, proportionality and the relationship to the right to object and the right to erasure.
CJEU, judgment of 12 January 2023, C-154/21, RW/Österreichische Post
Access to information on the recipients of personal data under Article 15(1)(c) GDPR: in principle an obligation to name the specific recipients; limitation to categories only by way of exception.