# CJEU, Judgment of 8 April 2014, C-293/12 and others, Digital Rights Ireland

CJEU decision on the invalidity of the Data Retention Directive: requirements for clear and precise legal bases and for data security.

> Quelle: https://www.thomashelbing.com/en/wissen/dsgvo-hub/rechtsprechung/1.4.5-eugh-digital-rights-ireland
> Sprache: en



## 1 Overview [#1-overview]

In the joined cases, the CJEU declared Directive 2006/24/EC on the retention of data generated by electronic communications invalid in its entirety. The directive interfered with the right to private life and the right to the protection of personal data under Articles 7 and 8 of the Charter of Fundamental Rights of the European Union (CFR) without providing for sufficient substantive and procedural safeguards.

Reference: [CJEU, judgment of 8 April 2014, C-293/12, C-594/12, Digital Rights Ireland](https://curia.europa.eu/juris/document/document.jsf?docid=150642\&doclang=DE)

## 2 Significance for the principles of the GDPR [#2-significance-for-the-principles-of-the-gdpr]

The judgment has two strands that continue to have effect today in Article 5 GDPR:

* Interferences with the right to the protection of personal data require a **clear and precise** legal basis governing the scope and application of the processing (para. 54). That requirement underlies the principle of lawfulness (Article 5(1)(a) GDPR).
* The legal basis must also provide for **safeguards** to protect the stored data (paras. 54 et seq.). That proposition has an effect on the principle of integrity and confidentiality (Article 5(1)(f) GDPR) and on the obligations giving it concrete form under Article 32 GDPR.


---

## About the author

This article was written by [Dr. Thomas Helbing, specialist lawyer for IT law in Munich](https://www.thomashelbing.com/en).

Since 2020 and continuously through today (2026), Handelsblatt has [recognized](https://www.thomashelbing.com/en#auszeichnungen) Dr. Helbing as one of **"Germany's Best Lawyers"** in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the **leading lawyers for data protection and IT law** and is listed among the **top 100 lawyers in Germany (2024/25)**. Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has **many years of advisory experience in data protection and IT law** and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His [professional background](https://www.thomashelbing.com/en#stationen) covers the **full spectrum of IT and technology law practice**. He began his career at a major international law firm, then gained **in-house experience at a DAX-listed company**, and is himself an **entrepreneur and founder of several digital ventures**. He also has **hands-on programming experience**, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his [clients](https://www.thomashelbing.com/en#referenzen) have included **technology companies and SaaS providers**, leading **German research institutions** and a **systemically important German bank**. His advisory focus lies in particular on **GDPR compliance, the data economy, SaaS, AI regulation and IT contract law**.