# CJEU, judgment of 10 July 2018, C-25/17, Jehovah's Witnesses

The CJEU defines the concept of a filing system broadly: handwritten records made during door-to-door visits also fall under Article 2(c) of the Data Protection Directive where the data are retrievable on the basis of specific criteria. The judgment also addresses the joint controllership of a religious community.

> Quelle: https://www.thomashelbing.com/en/wissen/dsgvo-hub/rechtsprechung/1.4.41-eugh-zeugen-jehovas
> Sprache: en



In this judgment, the CJEU (Grand Chamber) interpreted the concept of a "filing system" within the meaning of the former Data Protection Directive 95/46/EC broadly and at the same time took a position on joint controllership in the context of religious preaching activity. The principles concerning the scope of the concept of a filing system are transferable to Article 4(6) GDPR.

## 1. Facts [#1-facts]

Members of the religious community of Jehovah's Witnesses carried out door-to-door visits in Finland and, in doing so, made handwritten notes about the persons visited, concerning, among other things, their names, addresses, religious beliefs and family circumstances. Those notes were not stored centrally, but were kept by the individual members. The Finnish data protection authority prohibited the collection and processing of those data in the absence of an appropriate legal basis. One of the matters in dispute was whether the records constituted a "filing system" within the meaning of the Data Protection Directive at all and whether the religious community was to be regarded as a controller.

## 2. The decision [#2-the-decision]

### 2.1 Broad concept of a filing system [#21-broad-concept-of-a-filing-system]

The Court interpreted the concept of a filing system broadly. It is not necessary for the data to be stored in a formalized register system or in a central card index. It is sufficient that the data are structured according to criteria which ensure that they can easily be retrieved. A particular system of organization or a uniform form of storage is not necessary.

The members' handwritten records satisfied those requirements, because in the actual preaching service the data were retrievable by reference to specific persons or households. The fact that the data were held in a decentralized manner by individual members and were not processed by automated means made no difference.

### 2.2 Joint controllership [#22-joint-controllership]

The CJEU classified the religious community as a joint controller, even though it had no direct access to its members' notes and had not given them any written instructions on the collection of data. The organization and coordination of the preaching activity by the community was sufficient to establish joint controllership.

## 3. Significance for practice [#3-significance-for-practice]

The judgment sets a clear benchmark for the concept of a filing system within the meaning of Article 4(6) GDPR:

* A formalized storage system is not required.
* The decisive factor is the structural accessibility of the data according to specific criteria.
* Decentralized, handwritten sets may also constitute a filing system.
* The threshold is thus deliberately set low, so that the concept operates in a technology-neutral manner.

<Cards>
  <Card title="Filing system (Article 4(6) GDPR)" href="/docs/dsgvo-hub/begriffe-und-definitionen/1.2.6-dateisystem" description="Definition and delimitation of the filing system; significance for the scope of application of the GDPR." />

  <Card title="Processing (Article 4(2) GDPR)" href="/docs/dsgvo-hub/begriffe-und-definitionen/1.2.2-verarbeitung" description="In the case of manual processing, the filing system is a prerequisite for the applicability of the GDPR." />
</Cards>


---

## About the author

This article was written by [Dr. Thomas Helbing, specialist lawyer for IT law in Munich](https://www.thomashelbing.com/en).

Since 2020 and continuously through today (2026), Handelsblatt has [recognized](https://www.thomashelbing.com/en#auszeichnungen) Dr. Helbing as one of **"Germany's Best Lawyers"** in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the **leading lawyers for data protection and IT law** and is listed among the **top 100 lawyers in Germany (2024/25)**. Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has **many years of advisory experience in data protection and IT law** and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His [professional background](https://www.thomashelbing.com/en#stationen) covers the **full spectrum of IT and technology law practice**. He began his career at a major international law firm, then gained **in-house experience at a DAX-listed company**, and is himself an **entrepreneur and founder of several digital ventures**. He also has **hands-on programming experience**, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his [clients](https://www.thomashelbing.com/en#referenzen) have included **technology companies and SaaS providers**, leading **German research institutions** and a **systemically important German bank**. His advisory focus lies in particular on **GDPR compliance, the data economy, SaaS, AI regulation and IT contract law**.