CJEU, judgment of 16 January 2024, C-33/22, Committee of Inquiry
The GDPR applies in principle also to a parliamentary committee of inquiry; an activity does not fall outside Union law merely because of its connection with parliament.
1. Overview
A parliamentary committee of inquiry examined political influence exerted on a security authority. A person who had been deployed as an undercover investigator and who had been questioned by the committee requested the anonymization of their data. The Court had to clarify whether the activity of such a committee falls within the scope of the GDPR.
Reference: CJEU, judgment of 16 January 2024, C-33/22, Committee of Inquiry
2. No exclusion on account of the connection with parliament
An activity does not fall outside the scope of Union law merely because it is carried out by a committee of inquiry set up by the parliament of a Member State in the exercise of its power to scrutinize the executive. The GDPR therefore applies in principle also to the data processing carried out by a parliamentary committee of inquiry.
3. Reach of the "national security" exception
The exclusion from the material scope under Article 2(2)(a) GDPR applies only in so far as an activity serves to protect national security. The investigation of political influence exerted on a public authority does not as such serve national security and is therefore not excluded.
4. Significance for Article 2(2) GDPR
The decision confirms the narrow interpretation of the exclusions from the material scope in Article 2(2) GDPR (material scope). It fits into the line of case law according to which data processing in the context of parliamentary activity is also in principle subject to European data protection law. The scope of the Regulation thus extends into the parliamentary sphere, unless national security is exceptionally affected.
About the author
About the author
This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.
Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.
According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.
Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.
His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.
For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.
CJEU, judgment of 6 November 2003, C-101/01, Lindqvist
Publication of personal data on a website is processing that falls within the scope of data protection law; the household exemption does not apply.
CJEU, judgment of 22 June 2022, C-534/20, Leistritz
The stricter German special protection against dismissal for data protection officers (§ 6(4) BDSG) is compatible with the prohibition on removal from office under Article 38(3), second sentence, GDPR, provided that the objectives of the GDPR are not undermined.