# CJEU, Judgment of 30 March 2023, C-34/21, Hauptpersonalrat der Lehrerinnen und Lehrer

Limits of specific national rules on employee data protection: requirements for § 23 of the Hesse Data Protection and Freedom of Information Act (HDSIG) and § 26 of the German Federal Data Protection Act (BDSG) measured against Article 88 GDPR.

> Quelle: https://www.thomashelbing.com/en/wissen/dsgvo-hub/rechtsprechung/1.4.17-eugh-hauptpersonalrat
> Sprache: en



## 1 Overview [#1-overview]

The proceedings concerned the rules of the German federal state of Hesse on the live streaming of school lessons by videoconference without the consent of the teachers concerned. The CJEU addressed the limits of specific Member State rules in the field of employee data protection.

Reference: [CJEU, judgment of 30 March 2023, C-34/21, Hauptpersonalrat der Lehrerinnen und Lehrer](https://curia.europa.eu/juris/liste.jsf?num=C-34/21\&language=de)

## 2 Exhaustive character of Article 6(1) GDPR [#2-exhaustive-character-of-article-61-gdpr]

The Court confirms that Article 6(1) GDPR contains an exhaustive list of the permissible legal bases. Special Member State rules (including those adopted on the basis of Article 88 GDPR) must fit within that list and may not alter the scope of the individual grounds.

## 3 Requirements under Article 88 GDPR [#3-requirements-under-article-88-gdpr]

National rules in the employment context must, pursuant to Article 88(2) GDPR, include specific measures to safeguard the human dignity, legitimate interests and fundamental rights of the employees concerned. Broadly framed general clauses that confine themselves to repeating the GDPR do not satisfy that requirement.

## 4 Significance for § 26 BDSG [#4-significance-for--26-bdsg]

The decision has considerable implications for § 26 BDSG, which is designed as a specific rule for the processing of employee data pursuant to Article 88 GDPR. In so far as that provision does not contain specific protective measures, it is contrary to EU law and must be left unapplied; Article 6(1) GDPR then applies directly in its place.


---

## About the author

This article was written by [Dr. Thomas Helbing, specialist lawyer for IT law in Munich](https://www.thomashelbing.com/en).

Since 2020 and continuously through today (2026), Handelsblatt has [recognized](https://www.thomashelbing.com/en#auszeichnungen) Dr. Helbing as one of **"Germany's Best Lawyers"** in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the **leading lawyers for data protection and IT law** and is listed among the **top 100 lawyers in Germany (2024/25)**. Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has **many years of advisory experience in data protection and IT law** and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His [professional background](https://www.thomashelbing.com/en#stationen) covers the **full spectrum of IT and technology law practice**. He began his career at a major international law firm, then gained **in-house experience at a DAX-listed company**, and is himself an **entrepreneur and founder of several digital ventures**. He also has **hands-on programming experience**, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his [clients](https://www.thomashelbing.com/en#referenzen) have included **technology companies and SaaS providers**, leading **German research institutions** and a **systemically important German bank**. His advisory focus lies in particular on **GDPR compliance, the data economy, SaaS, AI regulation and IT contract law**.