# Data Protection Hub

A collection of knowledge on data protection law in Germany, in particular the GDPR and the German Federal Data Protection Act (BDSG).

> Quelle: https://www.thomashelbing.com/en/wissen/dsgvo-hub
> Sprache: en



Contains a collection of knowledge on data protection law in Germany, in particular the GDPR and the BDSG.

## 1.1 Statutory text [#11-statutory-text]

The complete text of the GDPR and of the BDSG, subdivided into chapters, sections and individual provisions.

[→ To the statutory text](/docs/dsgvo-hub/gesetzestext)

## 1.2 Concepts and definitions [#12-concepts-and-definitions]

Central concepts of data protection law that are referred to again and again. The legal definitions of Article 4 GDPR, each as a separate reference entry.

[→ To the concepts](/docs/dsgvo-hub/begriffe-und-definitionen)

* [1.2.1 Personal Data](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.1-personenbezogene-daten): Article 4(1) GDPR: the threshold that triggers data protection law; identifiability, data relating to objects, synthetic data, and the distinction from anonymous data.
* [1.2.2 Processing](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.2-verarbeitung): Article 4(2) GDPR: a comprehensive catch-all concept for any handling of data.
* [1.2.3 Restriction of Processing](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.3-einschraenkung-der-verarbeitung): Article 4(3) GDPR: the marking of data to limit their future processing (formerly "blocking").
* [1.2.4 Profiling](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.4-profiling): Article 4(4) GDPR: the automated evaluation of personal aspects; the relationship with scoring.
* [1.2.5 Pseudonymization](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.5-pseudonymisierung): Article 4(5) GDPR: separating data from identity; the distinction from anonymization.
* [1.2.6 Filing System](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.6-dateisystem): Article 4(6) GDPR: a structured set that also covers manual files.
* [1.2.7 Controller](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.7-verantwortlicher): Article 4(7) GDPR: whoever determines the purposes and means; the addressee of the GDPR's obligations.
* [1.2.8 Processor](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.8-auftragsverarbeiter): Article 4(8) GDPR: processing on behalf of a controller, with its own obligations and liability.
* [1.2.9 Recipient](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.9-empfaenger): Article 4(9) GDPR: any body to which data are disclosed.
* [1.2.10 Third Party](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.10-dritter): Article 4(10) GDPR: a body outside the controller's organization; there is no group privilege.
* [1.2.11 Consent](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.11-einwilligung): Article 4(11) GDPR: a freely given, informed indication of wishes serving as a legal basis.
* [1.2.12 Personal Data Breach](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.12-verletzung-des-schutzes-personenbezogener-daten): Article 4(12) GDPR: a breach of security that triggers the notification obligations.
* [1.2.13 Genetic Data](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.13-genetische-daten): Article 4(13) GDPR: data resulting from the analysis of a biological sample.
* [1.2.14 Biometric Data](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.14-biometrische-daten): Article 4(14) GDPR: data obtained through technical processing for unique identification.
* [1.2.15 Data Concerning Health](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.15-gesundheitsdaten): Article 4(15) GDPR: data on a person's physical or mental state of health.

## 1.3 Individual topics [#13-individual-topics]

Individual topics of the GDPR.

[→ To the individual topics overview](/docs/dsgvo-hub/einzelthemen)

### 1.3.1 Scope of application of the GDPR [#131-scope-of-application-of-the-gdpr]

Material and territorial scope of the GDPR, the existence of personal data, processing, Articles 2 and 3 GDPR.

[→ To the scope of application overview](/docs/dsgvo-hub/einzelthemen/anwendungsbereich-der-dsgvo)

* [1.3.1.1 Material Scope (Article 2 GDPR)](/docs/dsgvo-hub/einzelthemen/anwendungsbereich-der-dsgvo/1.3.1.1-sachlicher-anwendungsbereich): The forms of processing covered (automated and filing-system-based), exclusions from the material scope (national security, criminal law enforcement and the Law Enforcement Directive, the household exemption), the public and the non-public sector, and the media and employment privileges.
* [1.3.1.2 Territorial Scope (Article 3 GDPR)](/docs/dsgvo-hub/einzelthemen/anwendungsbereich-der-dsgvo/1.3.1.2-raeumlicher-anwendungsbereich): The establishment criterion, the targeting criterion and the monitoring of behavior, flag and diplomatic mission scenarios; Union citizenship is not a connecting factor.

### 1.3.2 Legal bases for processing [#132-legal-bases-for-processing]

The structure and system of Article 6 GDPR: the general prohibition subject to permission, the exhaustive catalog of grounds for lawful processing, the necessity requirement, and the relationship with the opening clauses and with the purpose limitation principle.

* [1.3.2.1 Consent](/docs/dsgvo-hub/einzelthemen/rechtsgrundlagen-der-verarbeitung/1.3.2.1-einwilligung): Consent under Article 6(1)(a) GDPR: significance, conditions for validity, and the relationship with the statutory grounds for lawful processing and with contractual declarations of assent.
* [1.3.2.2 Contract and Pre-Contractual Steps](/docs/dsgvo-hub/einzelthemen/rechtsgrundlagen-der-verarbeitung/1.3.2.2-vertrag-und-vorvertragliche-massnahmen): Lawfulness under Article 6(1)(b) GDPR: performance of a contract and pre-contractual steps, the EU law concept of necessity, the distinction from consent and terms of use, and typical categories of cases in the online context.
* [1.3.2.3 Legal Obligation](/docs/dsgvo-hub/einzelthemen/rechtsgrundlagen-der-verarbeitung/1.3.2.3-rechtliche-verpflichtung): Lawfulness under Article 6(1)(c) GDPR: a legal obligation to which the controller is subject, and the requirements for the Union or Member State legal basis under Article 6(3) GDPR.
* [1.3.2.4 Vital Interests](/docs/dsgvo-hub/einzelthemen/rechtsgrundlagen-der-verarbeitung/1.3.2.4-lebenswichtige-interessen): Lawfulness under Article 6(1)(d) GDPR: protection of vital interests, subsidiarity, and the relationship with the right to self-determination.
* [1.3.2.5 Public Interest and Official Authority](/docs/dsgvo-hub/einzelthemen/rechtsgrundlagen-der-verarbeitung/1.3.2.5-oeffentliches-interesse-und-oeffentliche-gewalt): Lawfulness under Article 6(1)(e) GDPR: performance of a task carried out in the public interest or in the exercise of official authority.
* [1.3.2.6 Legitimate Interests](/docs/dsgvo-hub/einzelthemen/rechtsgrundlagen-der-verarbeitung/1.3.2.6-berechtigte-interessen): Lawfulness under Article 6(1)(f) GDPR: the three-stage test (interest, necessity, balancing), the exclusion of public authorities, and categories of cases.
* [1.3.2.7 Change of Purpose](/docs/dsgvo-hub/einzelthemen/rechtsgrundlagen-der-verarbeitung/1.3.2.7-zweckaenderung): Change of purpose under Article 6(4) GDPR: function and legal nature, the compatibility test, and the special case of archiving, research and statistical purposes.
* [1.3.2.8 Opening Clauses and National Law](/docs/dsgvo-hub/einzelthemen/rechtsgrundlagen-der-verarbeitung/1.3.2.8-oeffnungsklauseln-und-nationales-recht): The opening clauses in Article 6(2) and (3) GDPR and how they are filled out by national law: the BDSG, the data protection acts of the German federal states, and the German Telecommunications Digital Services Data Protection Act (TDDDG).

### 1.3.3 Principles relating to processing [#133-principles-relating-to-processing]

Principles relating to the processing of personal data under Article 5 GDPR. Classification, legal nature, relationship with Article 6 GDPR, addressees, exceptions under Articles 23 and 85 GDPR, and liability to administrative fines.

* [1.3.3.1 Lawfulness](/docs/dsgvo-hub/einzelthemen/grundsaetze-der-verarbeitung/1.3.3.1-rechtmaessigkeit): The principle of lawful processing under Article 5(1)(a) GDPR as a reference to the requirement of a legal basis under Article 6 GDPR.
* [1.3.3.2 Fairness](/docs/dsgvo-hub/einzelthemen/grundsaetze-der-verarbeitung/1.3.3.2-treu-und-glauben): The fairness principle under Article 5(1)(a) GDPR: the duty of consideration, the prohibition of manipulation (including dark patterns), and protection against unclear and covert processing.
* [1.3.3.3 Transparency](/docs/dsgvo-hub/einzelthemen/grundsaetze-der-verarbeitung/1.3.3.3-transparenz): The transparency principle under Article 5(1)(a) GDPR: retrospective and prospective comprehensibility, and the substantive requirements for informing data subjects.
* [1.3.3.4 Purpose Limitation](/docs/dsgvo-hub/einzelthemen/grundsaetze-der-verarbeitung/1.3.3.4-zweckbindung): Purpose limitation under Article 5(1)(b) GDPR: the obligation to specify the purpose and the prohibition of further processing for incompatible purposes.
* [1.3.3.5 Data Minimization](/docs/dsgvo-hub/einzelthemen/grundsaetze-der-verarbeitung/1.3.3.5-datenminimierung): Data minimization under Article 5(1)(c) GDPR: relevance, necessity and adequacy of the data processed.
* [1.3.3.6 Accuracy](/docs/dsgvo-hub/einzelthemen/grundsaetze-der-verarbeitung/1.3.3.6-richtigkeit): Accuracy under Article 5(1)(d) GDPR: the obligation to ensure accuracy and to keep data up to date, including profiling, value judgments and automated decisions.
* [1.3.3.7 Storage Limitation](/docs/dsgvo-hub/einzelthemen/grundsaetze-der-verarbeitung/1.3.3.7-speicherbegrenzung): Storage limitation under Article 5(1)(e) GDPR: the time limits on storage and the obligations to erase and to review.
* [1.3.3.8 Integrity and Confidentiality](/docs/dsgvo-hub/einzelthemen/grundsaetze-der-verarbeitung/1.3.3.8-integritaet-und-vertraulichkeit): Integrity and confidentiality under Article 5(1)(f) GDPR: protection against unauthorized processing, loss, destruction and damage by means of technical and organizational measures.
* [1.3.3.9 Accountability](/docs/dsgvo-hub/einzelthemen/grundsaetze-der-verarbeitung/1.3.3.9-rechenschaftspflicht): Accountability under Article 5(2) GDPR: the obligation to comply with the principles set out in paragraph 1 and to demonstrate compliance with them.

### 1.3.4 Rights of the data subject [#134-rights-of-the-data-subject]

Rights of data subjects under Articles 12 and 15 to 23 GDPR (including access, rectification, erasure, restriction, data portability and objection).

### 1.3.5 Transparency obligations [#135-transparency-obligations]

Information and transparency obligations of the controller under Articles 12 to 14 GDPR: content and design of the privacy policy.

[→ To the transparency obligations overview](/docs/dsgvo-hub/einzelthemen/transparenzpflichten)

* [1.3.5.1 General Requirements (Article 12 GDPR)](/docs/dsgvo-hub/einzelthemen/transparenzpflichten/1.3.5.1-allgemeine-anforderungen): Presentation and form requirements for the information: concise, transparent, intelligible and easily accessible, clear and plain language, form, icons, timing, and the legal consequences of an infringement.
* [1.3.5.2 Content Where Data Are Collected from the Data Subject (Article 13 GDPR)](/docs/dsgvo-hub/einzelthemen/transparenzpflichten/1.3.5.2-inhalt-bei-direkterhebung): Mandatory information where data are collected from the data subject (paragraphs 1 and 2), information in the event of a change of purpose (paragraph 3), and the exception where the information is already available (paragraph 4).
* [1.3.5.3 Content Where Data Are Collected from Third Parties (Article 14 GDPR)](/docs/dsgvo-hub/einzelthemen/transparenzpflichten/1.3.5.3-inhalt-bei-dritterhebung): Additional information (categories of data, source), the timing of the information (paragraph 3), change of purpose, and the four exceptions in paragraph 5.
* [1.3.5.4 Design and Practice](/docs/dsgvo-hub/einzelthemen/transparenzpflichten/1.3.5.4-gestaltung-und-praxis): Structure, the layered approach, the level of detail for each item of information, ways of providing the information, typical mistakes, updating and a checklist.

### 1.3.6 Controllers and processors [#136-controllers-and-processors]

The data protection roles under the GDPR, how they are distinguished according to purposes and means, and the allocation of obligations and liability.

[→ To the controllers and processors overview](/docs/dsgvo-hub/einzelthemen/verantwortliche-und-auftragsverarbeiter)

* [1.3.6.2 Controller](/docs/dsgvo-hub/einzelthemen/verantwortliche-und-auftragsverarbeiter/1.3.6.2-verantwortliche): The concept and its broad interpretation under Article 4(7) GDPR, the obligations under Article 24 GDPR, and persons acting under the authority of the controller under Article 29 GDPR.
* [1.3.6.3 Joint Controllers](/docs/dsgvo-hub/einzelthemen/verantwortliche-und-auftragsverarbeiter/1.3.6.3-gemeinsam-verantwortliche): The existence of joint controllership, criteria and categories of cases, and the arrangement on the allocation of obligations under Article 26 GDPR.
* [1.3.6.4 Processor](/docs/dsgvo-hub/einzelthemen/verantwortliche-und-auftragsverarbeiter/1.3.6.4-auftragsverarbeiter): The existence of processing on behalf of a controller (categories of cases and assessment framework) and the data processing agreement under Article 28 GDPR.

### 1.3.7 Records of processing activities [#137-records-of-processing-activities]

The obligation to maintain records of processing activities under Article 30 GDPR.

* [1.3.7 Records of Processing Activities](/docs/dsgvo-hub/einzelthemen/1.3.7-verzeichnis-von-verarbeitungstaetigkeiten): Mandatory content for controllers and processors, form, the obligation to make the records available, the SME exemption under paragraph 5, and reform proposal COM(2025) 501.

### 1.3.8 Data protection officer [#138-data-protection-officer]

Designation, position and tasks of the data protection officer, Articles 37 to 39 GDPR, § 38 BDSG.

* [1.3.8 Data Protection Officer (Overview)](/docs/dsgvo-hub/einzelthemen/datenschutzbeauftragter): Function as an instrument of self-monitoring, classification of the areas regulated.
* [1.3.8.1 Designation](/docs/dsgvo-hub/einzelthemen/datenschutzbeauftragter/1.3.8.1-benennung): The obligation under Article 37(1) GDPR and § 38 BDSG, voluntary designation, qualifications, formalities, the licensing requirement for external data protection officers under the German Legal Services Act (RDG), termination, and the contract with an external data protection officer.
* [1.3.8.2 Position](/docs/dsgvo-hub/einzelthemen/datenschutzbeauftragter/1.3.8.2-stellung): Involvement, resources, freedom from instructions, the prohibition on penalization and removal from office, the reporting line, the right of data subjects to contact the officer, and conflicts of interest under Article 38 GDPR.
* [1.3.8.3 Tasks](/docs/dsgvo-hub/einzelthemen/datenschutzbeauftragter/1.3.8.3-aufgaben): Informing and advising, monitoring compliance, advice on the data protection impact assessment, cooperation with the supervisory authority, and the risk-based approach under Article 39 GDPR.
* [1.3.8.4 Liability](/docs/dsgvo-hub/einzelthemen/datenschutzbeauftragter/1.3.8.4-haftung): No compensation under Article 82 GDPR, tort liability towards data subjects, internal liability of the internal and the external data protection officer, and responsibility under criminal and administrative fine law.

### 1.3.9 Data security [#139-data-security]

Technical and organizational measures to protect personal data, Article 32 GDPR.

### 1.3.10 Data protection impact assessment [#1310-data-protection-impact-assessment]

Requirements, performance and documentation of the data protection impact assessment, Articles 35 and 36 GDPR.

[→ To the data protection impact assessment overview](/docs/dsgvo-hub/einzelthemen/datenschutz-folgenabschaetzung)

* [1.3.10.1 Necessity](/docs/dsgvo-hub/einzelthemen/datenschutz-folgenabschaetzung/1.3.10.1-erforderlichkeit): Threshold analysis under Article 35 GDPR, the statutory examples in paragraph 3, the positive and negative lists of the supervisory authorities, the nine criteria of the risk forecast, the mandatory list and case examples, and the exceptions under paragraphs 5 and 10.
* [1.3.10.2 Carrying It Out](/docs/dsgvo-hub/einzelthemen/datenschutz-folgenabschaetzung/1.3.10.2-durchfuehrung): The six steps under Article 35(7) GDPR, risk assessment with severity, likelihood and risk matrices, the report and templates, review under paragraph 11, and consultation of the supervisory authority under Article 36 GDPR.
* [1.3.10.3 Internal Organization](/docs/dsgvo-hub/einzelthemen/datenschutz-folgenabschaetzung/1.3.10.3-unternehmensinterne-organisation): Roles and responsibilities of the business unit, the data protection officer, the units involved, data subjects and processors, as well as a proposal for an internal procedure.

### 1.3.11 Administrative fines [#1311-administrative-fines]

Administrative fines and penalties under the GDPR, Articles 83 and 84 GDPR.

### 1.3.12 Special categories of personal data (Article 9 GDPR) [#1312-special-categories-of-personal-data-article-9-gdpr]

Processing of special ("sensitive") categories of personal data under Article 9 GDPR: the general prohibition of processing, the grounds for lawful processing, the relationship with Article 6 GDPR, and opening clauses for Member State law.

* [1.3.12.1 Sensitive Data Categories (Article 9(1) GDPR)](/docs/dsgvo-hub/einzelthemen/besondere-kategorien-personenbezogener-daten/1.3.12.1-sensible-datenkategorien): The nine categories of sensitive data and the general prohibition of processing; the two-part structure, the processing context as the point of reference, and questions of delimitation.
* [1.3.12.2 Grounds for Lawful Processing (Article 9(2) and (3) GDPR)](/docs/dsgvo-hub/einzelthemen/besondere-kategorien-personenbezogener-daten/1.3.12.2-zulaessigkeitstatbestaende): The ten exceptions in paragraph 2, points (a) to (j), and the personal restriction in paragraph 3; the relationship with Article 6 GDPR, opening clauses, appropriate safeguards.
* [1.3.12.3 Opening Clause for Member State Law (Article 9(4) GDPR)](/docs/dsgvo-hub/einzelthemen/besondere-kategorien-personenbezogener-daten/1.3.12.3-oeffnungsklausel-fuer-mitgliedstaatliches-recht): Additional national conditions and limitations for genetic data, biometric data and data concerning health; implementation in the BDSG and in sector-specific German law: the Genetic Diagnostics Act (GenDG), the Social Code (SGB), the Infection Protection Act (IfSG), the Transplantation Act (TPG), the Identity Cards Act (PAuswG).

### 1.3.13 Transfers to third countries (data export) [#1313-transfers-to-third-countries-data-export]

Transfer of personal data to unsafe third countries under Chapter V of the GDPR (Articles 44 to 49 GDPR): when a data export exists, the assessment framework and the instruments for establishing an adequate level of protection.

[→ To the transfers to third countries overview](/docs/dsgvo-hub/einzelthemen/drittlandsuebermittlung)

* [1.3.13.1 Derogations under Article 49 GDPR](/docs/dsgvo-hub/einzelthemen/drittlandsuebermittlung/1.3.13.1-ausnahmen-art-49): When data may be transferred without appropriate safeguards (consent, performance of a contract, legal claims, public interest); narrow interpretation, occasional transfers only, documentation obligation.
* [1.3.13.2 EU Standard Contractual Clauses and Transfer Impact Assessment](/docs/dsgvo-hub/einzelthemen/drittlandsuebermittlung/1.3.13.2-eu-standardvertragsklauseln): The four modules, the constellations, the delegation model and the conclusion of the standard contractual clauses, as well as the three-stage transfer impact assessment with risk-based considerations and the treatment of the processing chain.
* [1.3.13.3 EU-US Data Privacy Framework](/docs/dsgvo-hub/einzelthemen/drittlandsuebermittlung/1.3.13.3-data-privacy-framework): Adequacy decision for certified US recipients; checking the certification and its scope, no transfer impact assessment, contractual safeguards.
* [1.3.13.4 Binding Corporate Rules](/docs/dsgvo-hub/einzelthemen/drittlandsuebermittlung/1.3.13.4-binding-corporate-rules): Binding internal data protection rules for intra-group transfers (controller BCR and processor BCR); scope and limits.
* [1.3.13.5 Intra-Group Transfers](/docs/dsgvo-hub/einzelthemen/drittlandsuebermittlung/1.3.13.5-konzerninterne-uebermittlungen): A framework agreement (Data Transfer Agreement) with an allocation clause and a Data Transfer Directory that bundles processing on behalf of a controller, joint controllership, separate controllers and transfers to third countries for a group of undertakings.

### 1.3.14 Automated individual decision-making (Article 22 GDPR) [#1314-automated-individual-decision-making-article-22-gdpr]

General prohibition of decisions based solely on automated processing under Article 22 GDPR: the statutory criteria, profiling and scoring, the exceptions, the safeguards, sensitive data, and the relationship with the AI Act.

* [1.3.14 Automated Individual Decision-Making (Article 22 GDPR)](/docs/dsgvo-hub/einzelthemen/1.3.14-automatisierte-einzelentscheidung): The statutory criteria (decision, exclusively automated processing, legal or significant effect, being subject to the decision), profiling and scoring, the exceptions under paragraph 2 (contract, legal provision, consent), the safeguards under paragraph 3, the counter-exception for sensitive data under paragraph 4, information and access rights, and the relationship with the AI Act.

### 1.3.15 Personal data breach (data breach) [#1315-personal-data-breach-data-breach]

Handling a personal data breach under Articles 4(12), 33 and 34 GDPR: the concept, the internal process, the three-stage risk assessment, notification to the supervisory authority and communication to the data subjects.

[→ To the personal data breach overview](/docs/dsgvo-hub/einzelthemen/datenschutzverletzung)

* [1.3.15.1 First Steps and Internal Procedure](/docs/dsgvo-hub/einzelthemen/datenschutzverletzung/1.3.15.1-erste-schritte-und-interner-ablauf): Detection and containment, internal reporting, preliminary assessment, from when the breach is deemed known and the 72-hour period begins, attribution of awareness within the organization, and the obligations of processors and joint controllers.
* [1.3.15.2 Risk Assessment](/docs/dsgvo-hub/einzelthemen/datenschutzverletzung/1.3.15.2-risikobewertung): The three-stage risk model and its legal consequences, obtaining the basis for the assessment, risk analysis based on severity and likelihood of occurrence, the risk matrix, case examples, and special cases such as encryption and a trusted recipient.
* [1.3.15.3 Notification to the Supervisory Authority (Article 33 GDPR)](/docs/dsgvo-hub/einzelthemen/datenschutzverletzung/1.3.15.3-meldung-an-die-aufsichtsbehoerde): When notification is required, the deadline (without undue delay, where feasible within 72 hours of becoming aware) and how it is calculated, the competent and the lead supervisory authority, the minimum content under Article 33(3) GDPR, phased and bundled notification, and the documentation obligation under paragraph 5.
* [1.3.15.4 Communication to Data Subjects (Article 34 GDPR)](/docs/dsgvo-hub/einzelthemen/datenschutzverletzung/1.3.15.4-benachrichtigung-der-betroffenen): When communication is required in the case of a high risk, content and form in clear and plain language, the deadline, the exceptions under Article 34(3) GDPR, and the supervisory authority's power to issue an order.

## 1.4 Case law [#14-case-law]

Judgments on data protection law, for example of the CJEU, the General Court, the German Federal Court of Justice (BGH) and other German courts.

[→ To the case law overview](/docs/dsgvo-hub/rechtsprechung)

* [1.4.1 German Federal Constitutional Court (BVerfG), judgment of 15 December 1983, 1 BvR 209/83 and others, Census](/docs/dsgvo-hub/rechtsprechung/1.4.1-bverfg-volkszaehlung): Landmark decision of the BVerfG on the right to informational self-determination; basis for the principles of transparency and accuracy under the GDPR.
* [1.4.2 CJEU, judgment of 20 May 2003, C-465/00 and others, Österreichischer Rundfunk](/docs/dsgvo-hub/rechtsprechung/1.4.2-eugh-oesterreichischer-rundfunk): Publication of income data of public-sector employees; requirements as to the clarity and precision of the legal basis.
* [1.4.3 CJEU, judgment of 16 December 2008, C-524/06, Huber](/docs/dsgvo-hub/rechtsprechung/1.4.3-eugh-huber): Necessity of the data processing in a central register of foreign nationals; proactive obligation to erase and to rectify.
* [1.4.4 CJEU, judgment of 7 May 2009, C-553/07, Rijkeboer](/docs/dsgvo-hub/rechtsprechung/1.4.4-eugh-rijkeboer): Duration of the storage of recipients of a data transmission; interpretation of the principles with regard to rights of access.
* [1.4.5 CJEU, judgment of 8 April 2014, C-293/12 and others, Digital Rights Ireland](/docs/dsgvo-hub/rechtsprechung/1.4.5-eugh-digital-rights-ireland): Data retention; requirements for clear and precise legal bases and for data security.
* [1.4.6 CJEU, judgment of 13 May 2014, C-131/12, Google Spain](/docs/dsgvo-hub/rechtsprechung/1.4.6-eugh-google-spain): Derivation of the "right to be forgotten" from the principles of data processing; obligation to erase where the data lose their relevance to the purpose.
* [1.4.7 CJEU, judgment of 1 October 2015, C-201/14, Bara](/docs/dsgvo-hub/rechtsprechung/1.4.7-eugh-bara): Transparency requirements for transmissions of personal data between public authorities.
* [1.4.8 CJEU, judgment of 20 December 2017, C-434/16, Nowak](/docs/dsgvo-hub/rechtsprechung/1.4.8-eugh-nowak): Examination answers and examiner's comments as personal data; limits of the right to rectification in the case of time-related data.
* [1.4.9 CJEU, judgment of 24 November 2011, C-468/10 and C-469/10, ASNEF](/docs/dsgvo-hub/rechtsprechung/1.4.9-eugh-asnef): Exhaustive character of the list of grounds for lawful processing and balancing of interests under the Data Protection Directive; decisive for Article 6(1)(f) GDPR.
* [1.4.10 CJEU, judgment of 1 October 2019, C-673/17, Planet49](/docs/dsgvo-hub/rechtsprechung/1.4.10-eugh-planet49): Requirements for valid consent in the online context (active conduct, no pre-ticked boxes).
* [1.4.11 CJEU, judgment of 11 December 2019, C-708/18, Asociaţia de Proprietari](/docs/dsgvo-hub/rechtsprechung/1.4.11-eugh-asociatia-de-proprietari): Video surveillance in an apartment building; three-stage test under Article 6(1)(f) GDPR and restrictive interpretation of necessity.
* [1.4.12 CJEU, judgment of 4 May 2017, C-13/16, Rīgas satiksme](/docs/dsgvo-hub/rechtsprechung/1.4.12-eugh-rigas-satiksme): Interpretation of Article 7(f) of the Data Protection Directive (predecessor provision to Article 6(1)(f) GDPR); three-stage test and necessity.
* [1.4.13 CJEU, judgment of 29 July 2019, C-40/17, Fashion ID](/docs/dsgvo-hub/rechtsprechung/1.4.13-eugh-fashion-id): Lawfulness of embedding social plugins; legitimate interests in the case of joint controllership under Article 26 GDPR.
* [1.4.14 CJEU, judgment of 24 September 2019, C-136/17, GC and Others/CNIL](/docs/dsgvo-hub/rechtsprechung/1.4.14-eugh-gc-cnil): De-listing requests against search engine operators; normative precedence of data protection and privacy in the case of name-based searches.
* [1.4.15 CJEU, judgment of 1 August 2022, C-184/20, Vyriausioji tarnybinės etikos komisija](/docs/dsgvo-hub/rechtsprechung/1.4.15-eugh-vyriausioji): The list of grounds for lawful processing in Article 6(1) GDPR is exhaustive; publication of declarations of interests on the internet and special categories under Article 9 GDPR.
* [1.4.16 CJEU, judgment of 4 July 2023, C-252/21, Meta Platforms/Bundeskartellamt](/docs/dsgvo-hub/rechtsprechung/1.4.16-eugh-meta-bundeskartellamt): Scope of the necessity criterion under Article 6(1)(b) and (f) GDPR; "objectively indispensable" rather than merely "useful"; interaction with Article 9 GDPR.
* [1.4.17 CJEU, judgment of 30 March 2023, C-34/21, Hauptpersonalrat der Lehrerinnen und Lehrer](/docs/dsgvo-hub/rechtsprechung/1.4.17-eugh-hauptpersonalrat): Scope of specific national rules on employee data protection (§ 23 of the Hesse Data Protection and Freedom of Information Act (HDSIG), § 26 BDSG) and limits of the opening clauses.
* [1.4.18 CJEU, judgment of 2 March 2023, C-268/21, Norra Stockholm Bygg](/docs/dsgvo-hub/rechtsprechung/1.4.18-eugh-norra-stockholm-bygg): Further processing for new purposes and Article 6(4) GDPR; requirements of necessity and proportionality.
* [1.4.19 CJEU, judgment of 8 December 2022, C-180/21, Inspectoratul General pentru Imigrări](/docs/dsgvo-hub/rechtsprechung/1.4.19-eugh-inspectoratul-general): Processing by public authorities in judicial proceedings; delimitation between Article 6(1)(c) and Article 6(1)(e) GDPR.
* [1.4.20 CJEU, judgment of 11 December 2014, C-212/13, Ryneš](/docs/dsgvo-hub/rechtsprechung/1.4.20-eugh-rynes): Private video surveillance and purely personal or household activity under Article 2(2)(c) GDPR (at the time the Data Protection Directive).
* [1.4.21 German Federal Administrative Court (BVerwG), judgment of 27 September 2018, 7 C 5/17](/docs/dsgvo-hub/rechtsprechung/1.4.21-bverwg-7-c-5-17): Requirements for national legal bases for data processing in the public sector; limits of general catch-all clauses.
* [1.4.22 BVerwG, judgment of 27 March 2019, 6 C 2/18](/docs/dsgvo-hub/rechtsprechung/1.4.22-bverwg-6-c-2-18): Article 6(1)(e) GDPR does not apply to private parties in the absence of an act conferring public authority; requirements for the national legal basis.
* [1.4.23 BGH, judgment of 20 February 2018, VI ZR 30/17, Ärztebewertung III (Jameda)](/docs/dsgvo-hub/rechtsprechung/1.4.23-bgh-jameda-aerztebewertung-iii): Balancing of interests in the case of rating portals; reassessment as a result of changed business models.
* [1.4.24 CJEU, judgment of 27 October 2022, C-129/21, Proximus](/docs/dsgvo-hub/rechtsprechung/1.4.24-eugh-proximus): Objection to direct marketing and further use of publicly accessible data.
* [1.4.25 CJEU, judgment of 11 November 2020, C-61/19, Orange România](/docs/dsgvo-hub/rechtsprechung/1.4.25-eugh-orange-romania): Requirements for a pre-formulated declaration of consent; clear distinction from other contractual matters, burden of proof on the controller.
* [1.4.26 CJEU, judgment of 22 June 2021, C-439/19, Latvijas Republikas Saeima ("B")](/docs/dsgvo-hub/rechtsprechung/1.4.26-eugh-b-latvijas-saeima): Improvement of road safety as a public interest within the meaning of Article 6(1)(e) GDPR; classification of road traffic offenses as criminal offenses within the meaning of Article 10 GDPR.
* [1.4.27 CJEU, judgment of 12 September 2024, C-17/22 and C-18/22, HTB Neunte Immobilien Portfolio and Ökorenta](/docs/dsgvo-hub/rechtsprechung/1.4.27-eugh-htb-oekorenta): Judge-made law as a legal obligation within the meaning of Article 6(1)(c) GDPR; requirements of clarity, foreseeability and proportionality.
* [1.4.28 BGH, order of 18 August 2020, 5 StR 175/20](/docs/dsgvo-hub/rechtsprechung/1.4.28-bgh-5-str-175-20): Admissibility of unlawfully obtained video recordings in criminal proceedings despite an infringement of the GDPR; balancing in the individual case.
* [1.4.29 CJEU, judgment of 9 January 2025, C-394/23, Mousse](/docs/dsgvo-hub/rechtsprechung/1.4.29-eugh-mousse): Necessity under Article 6(1)(f) GDPR; the right to object under Article 21 GDPR is not to be taken into account in the assessment of necessity.
* [1.4.30 CJEU, judgment of 4 October 2024, C-446/21, Schrems/Meta](/docs/dsgvo-hub/rechtsprechung/1.4.30-eugh-schrems-meta): Scope of the concept of sensitive data under Article 9(1) GDPR in the context of advertising on social networks; interpretation of the exception for data "manifestly made public" and obligation to impose a time limit.
* [1.4.30 CJEU, judgment of 19 October 2016, C-582/14, Breyer](/docs/dsgvo-hub/rechtsprechung/1.4.37-eugh-breyer): Dynamic IP addresses as personal data; processing to ensure the functionality of a publicly accessible website as a legitimate interest under Article 7(f) of the Data Protection Directive.
* [1.4.31 CJEU, judgment of 4 October 2024, C-21/23, Lindenapotheke](/docs/dsgvo-hub/rechtsprechung/1.4.31-eugh-lindenapotheke): Ordering medicinal products that are pharmacy-only but not subject to prescription generates data concerning health within the meaning of Article 9(1) GDPR; pursuit of data protection infringements by competitors under unfair competition law.
* [1.4.31 CJEU, judgment of 7 December 2023, C-26/22 and C-64/22, SCHUFA Holding (Libération de reliquat de dette)](/docs/dsgvo-hub/rechtsprechung/1.4.38-eugh-schufa-liberation): Three-stage test under Article 6(1)(f) GDPR for the storage of information from public registers by credit information agencies; relationship to the right to object and the right to erasure.
* [1.4.32 CJEU, judgment of 7 December 2023, C-634/21, SCHUFA Holding (Scoring)](/docs/dsgvo-hub/rechtsprechung/1.4.32-eugh-schufa-scoring): Automated decision-making and profiling under Article 22 GDPR; limits of Member State implementation; the balancing exercise must not be pre-empted.
* [1.4.33 CJEU, judgment of 4 October 2024, C-621/22, Koninklijke Nederlandse Lawn Tennisbond](/docs/dsgvo-hub/rechtsprechung/1.4.33-eugh-koninklijke-nederlandse-lawn-tennisbond): Commercial interest as a legitimate interest within the meaning of Article 6(1)(f) GDPR; balancing in the case of transmission of members' data to third parties offering gambling.
* [1.4.34 CJEU, judgment of 17 June 2021, C-597/19, M.I.C.M.](/docs/dsgvo-hub/rechtsprechung/1.4.34-eugh-m-i-c-m): Legitimate interest of third parties in the identification of IP addresses in order to pursue copyright infringements; interpretation of Article 6(1)(f) GDPR.
* [1.4.35 CJEU, judgment of 25 November 2021, C-102/20, StWL Städtische Werke Lauf a.d. Pegnitz](/docs/dsgvo-hub/rechtsprechung/1.4.35-eugh-stwl-pegnitz): Concept of direct marketing under the ePrivacy Directive; advertising displayed in an email inbox in the guise of messages constitutes direct marketing and requires consent.
* [1.4.36 BGH, order of 23 June 2020, KVR 69/19, Facebook (antitrust proceedings)](/docs/dsgvo-hub/rechtsprechung/1.4.36-bgh-facebook-kvr-69-19): Interim antitrust proceedings with knock-on effects for data protection law: narrow interpretation of the performance characteristic of the contract in the context of Article 6(1)(b) GDPR.
* [1.4.39 CJEU, judgment of 4 May 2023, C-60/22, Bundesrepublik Deutschland (BAMF)](/docs/dsgvo-hub/rechtsprechung/1.4.39-eugh-c-60-22-bamf): Infringements of Article 26 GDPR and Article 30 GDPR do not render the processing unlawful; separation of the formal documentation obligation from substantive lawfulness.
* [1.4.40 CJEU, judgment of 12 January 2023, C-154/21, RW/Österreichische Post](/docs/dsgvo-hub/rechtsprechung/1.4.40-eugh-c-154-21-oesterreichische-post): Right of access under Article 15(1)(c) GDPR: the controller must in principle name the specific recipients; limitation to categories only as a narrowly defined exception.
* [1.4.41 CJEU, judgment of 10 July 2018, C-25/17, Jehovah's Witnesses](/docs/dsgvo-hub/rechtsprechung/1.4.41-eugh-zeugen-jehovas): Broad concept of a filing system: handwritten records kept in a decentralized manner fall within the concept of a filing system where the data are easily retrievable on the basis of criteria; joint controllership of a religious community.
* [1.4.42 CJEU, judgment of 1 October 2015, C-230/14, Weltimmo](/docs/dsgvo-hub/rechtsprechung/1.4.42-eugh-weltimmo): Broad interpretation of the concept of an establishment for the purposes of the territorial scope (Article 3(1) GDPR); a stable arrangement with minimal but real activity suffices; limits of the power of national supervisory authorities to impose penalties.
* [1.4.43 CJEU, judgment of 6 November 2003, C-101/01, Lindqvist](/docs/dsgvo-hub/rechtsprechung/1.4.43-eugh-lindqvist): Publication of personal data on a website is processing that falls within the scope of application; the household exemption does not apply where data are disclosed to an indefinite number of persons; narrow interpretation of the exclusions from the material scope.
* [1.4.44 CJEU, judgment of 16 January 2024, C-33/22, Committee of Inquiry](/docs/dsgvo-hub/rechtsprechung/1.4.44-eugh-untersuchungsausschuss): The GDPR applies in principle also to a parliamentary committee of inquiry; exception only for activities in the field of national security (Article 2(2)(a) GDPR).
* [1.4.45 CJEU, judgment of 22 June 2022, C-534/20, Leistritz](/docs/dsgvo-hub/rechtsprechung/1.4.45-eugh-leistritz): The stricter German special protection against dismissal for data protection officers (§ 6(4) BDSG) is compatible with the prohibition on removal from office under Article 38(3), second sentence, GDPR, provided that the objectives of the GDPR are not undermined.
* [1.4.46 CJEU, judgment of 9 February 2023, C-453/21, X-FAB](/docs/dsgvo-hub/rechtsprechung/1.4.46-eugh-x-fab): Conflict of interests under Article 38(6) GDPR where tasks are assigned that determine the purposes and means of the processing; assessment in the individual case; stricter national rules on removal from office permissible.
* [1.4.47 Bar Court of Appeal for North Rhine-Westphalia (AGH NRW), judgment of 12 March 2021, 1 AGH 9/19](/docs/dsgvo-hub/rechtsprechung/1.4.47-agh-nrw-1-agh-9-19): The legal advisory tasks of the data protection officer under Article 39 GDPR constitute a legal service permitted by statute (§ 1(3) RDG); licensing requirement for external data protection officers under the RDG.
* [1.4.48 German Regional Labor Court of Hamm (LAG Hamm), judgment of 6 October 2022, 18 Sa 271/22](/docs/dsgvo-hub/rechtsprechung/1.4.48-lag-hamm-18-sa-271-22): Payroll accounting and personnel administration for around 80 employees do not constitute a core activity within the meaning of Article 37(1)(b) GDPR; voluntarily designated data protection officer without special protection against dismissal under § 6(4) BDSG.
* [1.4.49 CJEU, judgment of 5 June 2018, C-210/16, Wirtschaftsakademie Schleswig-Holstein](/docs/dsgvo-hub/rechtsprechung/1.4.49-eugh-wirtschaftsakademie): The operator of a Facebook fan page is jointly responsible with the network; landmark decision on the broad interpretation of joint controllership under Article 26 GDPR (no equivalent participation, no access to the data required).
* [1.4.50 CJEU, judgment of 16 July 2020, C-311/18, Schrems II](/docs/dsgvo-hub/rechtsprechung/1.4.50-eugh-schrems-ii): The EU-US Privacy Shield is invalid; the standard contractual clauses are tenable only with a supplementary assessment of the level of protection in the third country in the individual case. Basis of the obligation to carry out a transfer impact assessment.
* [1.4.51 CJEU, judgment of 6 October 2015, C-362/14, Schrems (Safe Harbor)](/docs/dsgvo-hub/rechtsprechung/1.4.51-eugh-schrems-i): The Safe Harbor arrangement is invalid; the national supervisory authorities may examine transfers independently notwithstanding an adequacy decision. The opening of the chain of US adequacy decisions.
* [1.4.52 CJEU, judgment of 27 February 2025, C-203/22, Dun & Bradstreet Austria](/docs/dsgvo-hub/rechtsprechung/1.4.52-eugh-dun-bradstreet): Scope of the right of access to the logic involved in an automated decision under Article 15(1)(h) GDPR; explanation of the procedure and principles instead of disclosure of the algorithm; in camera proceedings where trade secrets stand in the way.


---

## About the author

This article was written by [Dr. Thomas Helbing, specialist lawyer for IT law in Munich](https://www.thomashelbing.com/en).

Since 2020 and continuously through today (2026), Handelsblatt has [recognized](https://www.thomashelbing.com/en#auszeichnungen) Dr. Helbing as one of **"Germany's Best Lawyers"** in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the **leading lawyers for data protection and IT law** and is listed among the **top 100 lawyers in Germany (2024/25)**. Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has **many years of advisory experience in data protection and IT law** and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His [professional background](https://www.thomashelbing.com/en#stationen) covers the **full spectrum of IT and technology law practice**. He began his career at a major international law firm, then gained **in-house experience at a DAX-listed company**, and is himself an **entrepreneur and founder of several digital ventures**. He also has **hands-on programming experience**, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his [clients](https://www.thomashelbing.com/en#referenzen) have included **technology companies and SaaS providers**, leading **German research institutions** and a **systemically important German bank**. His advisory focus lies in particular on **GDPR compliance, the data economy, SaaS, AI regulation and IT contract law**.