# CJEU, judgment of 27 October 2022, C-129/21, Proximus

Objection to direct marketing under Article 21 GDPR and further use of publicly accessible data in telephone directories.

> Quelle: https://www.thomashelbing.com/en/wissen/dsgvo-hub/rechtsprechung/1.4.24-eugh-proximus
> Sprache: en



## 1 Overview [#1-overview]

The proceedings concerned the processing of personal data for the purpose of producing telephone directories and directory inquiry services in Belgium. The CJEU addressed the requirements for consent and the obligations that arise where the data subject objects.

Reference: [CJEU, judgment of 27 October 2022, C-129/21, Proximus](https://curia.europa.eu/juris/liste.jsf?num=C-129/21\&language=de)

## 2 Consent in the case of multiple use [#2-consent-in-the-case-of-multiple-use]

The consent given for the initial measure (inclusion in a telephone directory) also covers the disclosure of the data to other directory inquiry services, provided that the purpose remains the same. The data subject must, however, be informed in a transparent manner that their data are disclosed to third parties.

## 3 Obligations where the data subject objects [#3-obligations-where-the-data-subject-objects]

Where the data subject objects to the processing, the original controller is subject to far-reaching obligations to inform and to erase: it must not only cease its own processing but also inform the recipients of the objection so that they, in turn, can cease processing. The CJEU thereby creates a kind of "chain reaction" for objections in the context of telephone directories and directory inquiry services.

## 4 Significance [#4-significance]

The decision strengthens the right to object under Article 21 GDPR and shows that the controller remains responsible for its disclosures of data even after those disclosures have been completed. In practice, controllers must provide for processes by which objections can be passed on to all recipients.


---

## About the author

This article was written by [Dr. Thomas Helbing, specialist lawyer for IT law in Munich](https://www.thomashelbing.com/en).

Since 2020 and continuously through today (2026), Handelsblatt has [recognized](https://www.thomashelbing.com/en#auszeichnungen) Dr. Helbing as one of **"Germany's Best Lawyers"** in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the **leading lawyers for data protection and IT law** and is listed among the **top 100 lawyers in Germany (2024/25)**. Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has **many years of advisory experience in data protection and IT law** and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His [professional background](https://www.thomashelbing.com/en#stationen) covers the **full spectrum of IT and technology law practice**. He began his career at a major international law firm, then gained **in-house experience at a DAX-listed company**, and is himself an **entrepreneur and founder of several digital ventures**. He also has **hands-on programming experience**, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his [clients](https://www.thomashelbing.com/en#referenzen) have included **technology companies and SaaS providers**, leading **German research institutions** and a **systemically important German bank**. His advisory focus lies in particular on **GDPR compliance, the data economy, SaaS, AI regulation and IT contract law**.