CJEU, judgment of 6 November 2003, C-101/01, Lindqvist
Publication of personal data on a website is processing that falls within the scope of data protection law; the household exemption does not apply.
1. Overview
A person working in a voluntary capacity posted on private web pages information about herself and about several members of her parish, including names, contact details, activities and, in part, information on their state of health. The Court had to clarify whether that publication falls within the scope of data protection law.
Reference: CJEU, judgment of 6 November 2003, C-101/01, Lindqvist
2. Publication as automated processing
Loading personal data onto a website constitutes processing that is at least partly automated. As soon as persons are made identifiable by name or by other means, the material scope of data protection law is engaged.
3. Limits of the household exemption
The exemption for purely personal or household activities does not apply where data are disclosed on the internet to an indefinite number of persons. A publication that is accessible to an unlimited public leaves the protected personal sphere. That reasoning can be transposed to the household exemption under Article 2(2)(c) GDPR. The Court has since confirmed that line, among other things for notes and publications made in the course of door-to-door preaching and for the dissemination of video recordings (CJEU, judgment of 10 July 2018, C-25/17, Jehovah's Witnesses).
4. Narrow interpretation of the exclusions from the material scope
The decision also stands for the narrow interpretation of the exclusions from the material scope. Only the activities expressly named, or activities of the same kind, are excluded; that benchmark continues to shape the interpretation of Article 2(2) GDPR to this day.
5. Latitude of national law
It also follows from the decision that the harmonizing effect of European data protection law does not extend beyond its scope of application. In areas not covered by Union law, the Member States may adopt rules of their own, provided that no other provision of Union law precludes this. On that basis, the national legislature may, for instance, also make purely manual processing without a filing system subject to data protection law.
About the author
About the author
This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.
Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.
According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.
Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.
His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.
For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.
CJEU, judgment of 1 October 2015, C-230/14, Weltimmo
Broad interpretation of the concept of an establishment for the purposes of the territorial scope: a stable arrangement with minimal but real activity suffices.
CJEU, judgment of 16 January 2024, C-33/22, Committee of Inquiry
The GDPR applies in principle also to a parliamentary committee of inquiry; an activity does not fall outside Union law merely because of its connection with parliament.