Skip to main content
Back to knowledge base
Legal

GDPR case law: key rulings EU, NL and BE

The GDPR is shaped not only by the legal text, but also by rulings from the Court of Justice of the European Union and national courts. These rulings determine how the GDPR is applied in practice. This overview covers the most important cases for organisations managing data processing agreements and data processing.

28 March 202610 min read

European case law (CJEU)

Transfers to third countries (C-311/18, 2020)

The Court ruled that the EU-US Privacy Shield was invalid because the US did not provide adequate protection against surveillance. Organisations transferring personal data outside the EEA must assess the protection level per transfer, even when using SCCs. A Transfer Impact Assessment (TIA) is required.

Practical impact: Check all sub-processors outside the EEA. Prepare a TIA per transfer. Document supplementary measures in the DPA.

Material scope (C-25/17, 2018)

The Court ruled that a religious community collecting personal data during door-to-door visits was a joint controller, even without formal instructions. The concept of controller must be interpreted broadly.

Right to be forgotten and search engines (C-131/12, 2014)

The Court ruled that search engine operators are controllers and can be required to remove search results at the request of data subjects.

Compensation and non-material damage (C-300/21, 2023)

The Court ruled that Art. 82 GDPR grants the right to compensation for non-material damage without a minimum threshold. The mere unlawful processing is insufficient — the data subject must demonstrate actual harm, but the threshold is low.

Practical impact: Organisations face financial risk for any unlawful processing, even without data theft or breaches.

Joint controllership with social media (C-210/16, 2018)

The Court ruled that a fan page administrator on a social media platform is a joint controller with the platform, even without access to the raw personal data.

Processing by employers and consent (C-34/21, 2023)

The Court confirmed that consent in an employment relationship is rarely freely given due to the power imbalance. Employers should rely on another legal basis.

Dutch case law

Fine for missing DPA (Dutch DPA, 2022)

The Dutch Data Protection Authority fined an organisation that systematically failed to conclude DPAs with processors accessing medical personal data. Art. 28 is not discretionary: a DPA is mandatory for every processing by a third party.

Right of access and scope (Supreme Court, 2023)

The Supreme Court ruled that the right of access (Art. 15) extends beyond the data itself to include: the source of the data, retention periods and categories of recipients.

Retention periods and proportionality (Amsterdam District Court, 2024)

The court ruled that retaining CCTV footage beyond 4 weeks without a specific reason violated the storage limitation principle (Art. 5(1)(e)).

Belgian case law

Data Protection Authority: cookies and consent (GBA, 2022)

The GBA ruled that a cookie consent banner with non-essential cookies pre-checked was invalid. Consent must be active, specific and informed.

Right to erasure and archiving (Brussels Market Court, 2023)

The court confirmed that the right to erasure (Art. 17) is not absolute: legal retention obligations take precedence. However, organisations must demonstrate which specific legal obligation applies.

Fine for inadequate security (GBA, 2023)

The GBA fined an organisation for failing to implement adequate technical measures after a data breach. Art. 32 is an ongoing obligation, not a one-time measure.

Common threads and practical lessons

  • DPAs are mandatory — case law confirms strict enforcement of Art. 28
  • Non-EEA transfers require a TIA — SCCs alone are insufficient
  • Joint controllership is broader than many organisations assume
  • Non-material damage gives rise to compensation claims
  • Retention periods must be proportional, documented and verifiable
  • Security is an ongoing obligation — not just at setup but also upon changes and incidents
  • Consent in employment is rarely a valid legal basis

GDPR compliance informed by case law?

DPAkit helps you manage DPAs, transfers and sub-processors in line with the latest rulings.

Start for free