# CJEU, judgment of 4 October 2024, C-446/21, Schrems/Meta

Scope of the concept of sensitive data under Article 9 GDPR in the context of advertising on social networks; restrictive interpretation of Article 9(2)(e) and obligation to impose a time limit on the processing.

> Quelle: https://www.thomashelbing.com/en/wissen/dsgvo-hub/rechtsprechung/1.4.30-eugh-schrems-meta
> Sprache: en



## 1 Overview [#1-overview]

The judgment concerns a dispute between the Austrian data protection activist Maximilian Schrems and Meta Platforms Ireland and gives concrete shape to the protective regime of Article 9 GDPR in the context of advertising-financed social networks. The Court tightens the requirements of purpose limitation and data minimization in the case of personalized advertising and interprets the exception for data "manifestly made public" (Article 9(2)(e) GDPR) restrictively.

Reference: [CJEU, judgment of 4 October 2024, C-446/21, Schrems/Meta Platforms Ireland](https://eur-lex.europa.eu/legal-content/DE/TXT/?uri=CELEX:62021CJ0446)

## 2 Facts [#2-facts]

Meta processes user data for the purposes of personalized advertising and in doing so combines data from different sources, both on-site (within the Facebook services) and off-site (from other websites and apps). At a public panel discussion, Schrems had given indications as to his sexual orientation. It fell to be clarified under what conditions Meta may use such data for personalized advertising.

## 3 Decision [#3-decision]

### 3.1 Data minimization and limitation in time [#31-data-minimization-and-limitation-in-time]

The Court emphasizes the principle of data minimization (Article 5(1)(c) GDPR) as an independent limit: processing of personal data for advertising purposes without any limitation in time and without distinction is impermissible even where the data were lawfully collected. The controller must align the duration of storage and processing with the purpose and must continuously minimize the volume of data held.

### 3.2 Restrictive interpretation of Article 9(2)(e) GDPR [#32-restrictive-interpretation-of-article-92e-gdpr]

For the exception covering data manifestly made public, the Court requires that the data subject intended, by an **explicit and clear affirmative action**, to make the data accessible to the general public. A blanket release of all data subsequently accessible does not follow from a public self-disclosure.

Even where a person's sexual orientation becomes known in a public format (for example a live-streamed panel discussion), this does not justify further processing for the purposes of aggregation and analysis in the context of personalized advertising. Purpose limitation and proportionality restrict the reach of the exception even where its conditions are met.

### 3.3 Implications for personalized advertising [#33-implications-for-personalized-advertising]

The principles of purpose limitation and data minimization give rise to specific obligations for advertising-financed platforms:

* differentiation between data collected on-site and off-site when assessing the purpose,
* limitation of the processing of sensitive data to what is strictly necessary for the specific purpose,
* continuous review of the storage period and of the obligations to erase,
* a clear separation between the exception under Article 9(2) GDPR and compliance with the general principles of Articles 5 and 6 GDPR.

## 4 Significance [#4-significance]

The judgment strengthens the position of the data protection principles as against the grounds for lawful processing. It makes clear that Article 9(2)(e) GDPR does not leave data that have become public "without protection" and that the principle of data minimization remains an independent and continuing obligation of the controller. Business models that rest on permanent collection of data going beyond the purpose must demonstrate that they ensure limitation in terms of time and purpose.


---

## About the author

This article was written by [Dr. Thomas Helbing, specialist lawyer for IT law in Munich](https://www.thomashelbing.com/en).

Since 2020 and continuously through today (2026), Handelsblatt has [recognized](https://www.thomashelbing.com/en#auszeichnungen) Dr. Helbing as one of **"Germany's Best Lawyers"** in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the **leading lawyers for data protection and IT law** and is listed among the **top 100 lawyers in Germany (2024/25)**. Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has **many years of advisory experience in data protection and IT law** and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His [professional background](https://www.thomashelbing.com/en#stationen) covers the **full spectrum of IT and technology law practice**. He began his career at a major international law firm, then gained **in-house experience at a DAX-listed company**, and is himself an **entrepreneur and founder of several digital ventures**. He also has **hands-on programming experience**, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his [clients](https://www.thomashelbing.com/en#referenzen) have included **technology companies and SaaS providers**, leading **German research institutions** and a **systemically important German bank**. His advisory focus lies in particular on **GDPR compliance, the data economy, SaaS, AI regulation and IT contract law**.