# CJEU, judgment of 22 June 2021, C-439/19, Latvijas Republikas Saeima ("B")

Improvement of road safety as a public interest within the meaning of Article 6(1)(e) GDPR; classification of road traffic offenses as criminal offenses within the meaning of Article 10 GDPR.

> Quelle: https://www.thomashelbing.com/en/wissen/dsgvo-hub/rechtsprechung/1.4.26-eugh-b-latvijas-saeima
> Sprache: en



## 1 Overview [#1-overview]

Latvia maintained a publicly accessible register in which penalty points for road traffic infringements were stored. Any person could obtain the current number of points by supplying a driver's national identification number; in addition, the data were passed on to commercial re-users. An applicant ("B") challenged that publication; in the preliminary ruling proceedings the Court of Justice examined the interpretation of Articles 5, 6 and 10 GDPR.

## 2 Headnotes [#2-headnotes]

The improvement of road safety is an objective of general interest recognized by the Union and therefore a task carried out in the public interest within the meaning of Article 6(1)(e) GDPR (para. 108).

The processing of data on penalty points arising from road traffic offenses constitutes processing of personal data relating to criminal convictions and offenses within the meaning of Article 10 GDPR. Where infringements are classified under national law as regulatory (administrative) offenses, it must likewise be examined whether, by reason of their nature, their purpose and the severity of the penalty they attract, they are "criminal offenses" within the meaning of EU law.

Making a national register containing data on road traffic infringements publicly accessible without the individual person making the request having a specific legitimate interest goes beyond what is necessary in order to attain the objective of road safety and is incompatible with the principle of necessity.

## 3 Significance [#3-significance]

The decision is one of the landmark decisions on the scope of the public interest under Article 6(1)(e) GDPR. It shows two things: first, weighty objectives of general welfare are recognized as legitimate public interests; second, the necessity test places narrow limits on the disclosure of sensitive data to the public. At the same time, the Court of Justice clarifies the autonomous EU law concept of a "criminal offense" within the meaning of Article 10 GDPR.

<Cards>
  <Card title="Public interest and official authority" href="/docs/dsgvo-hub/einzelthemen/rechtsgrundlagen-der-verarbeitung/1.3.2.5-oeffentliches-interesse-und-oeffentliche-gewalt" description="Article 6(1)(e) GDPR." />

  <Card title="CJEU Vyriausioji" href="/docs/dsgvo-hub/rechtsprechung/1.4.15-eugh-vyriausioji" description="Strict necessity in the case of publication." />
</Cards>


---

## About the author

This article was written by [Dr. Thomas Helbing, specialist lawyer for IT law in Munich](https://www.thomashelbing.com/en).

Since 2020 and continuously through today (2026), Handelsblatt has [recognized](https://www.thomashelbing.com/en#auszeichnungen) Dr. Helbing as one of **"Germany's Best Lawyers"** in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the **leading lawyers for data protection and IT law** and is listed among the **top 100 lawyers in Germany (2024/25)**. Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has **many years of advisory experience in data protection and IT law** and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His [professional background](https://www.thomashelbing.com/en#stationen) covers the **full spectrum of IT and technology law practice**. He began his career at a major international law firm, then gained **in-house experience at a DAX-listed company**, and is himself an **entrepreneur and founder of several digital ventures**. He also has **hands-on programming experience**, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his [clients](https://www.thomashelbing.com/en#referenzen) have included **technology companies and SaaS providers**, leading **German research institutions** and a **systemically important German bank**. His advisory focus lies in particular on **GDPR compliance, the data economy, SaaS, AI regulation and IT contract law**.