General Data Protection Regulation

Article 5

Principles relating to processing of personal data

1. Personal data shall be:

2. The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1 ('accountability').

Holdings

/
C-474/2414 Jul 2026

AR and Others v Österreichische Datenschutzbehörde and Others

3. Article 5(1)(a) and (c) and the second subparagraph of Article 6(3) of Regulation 2016/679

must be interpreted as not precluding national legislation which imposes on national anti-doping bodies an obligation to publish on the internet personal data concerning all athletes sanctioned for infringing anti-doping rules, such as the names of the athletes concerned, the duration of the ban imposed on them and the reasons for it, with the exception of recreational athletes, particularly vulnerable persons and whistleblowers, provided that that legislation allows controllers, apart from those exceptions and prior to such publication, to carry out an individual balancing exercise weighing up the interests involved in order to ensure that that publication is made in a manner consistent with that regulation.

C-484/2418 Jun 2026

NTH Haustechnik GmbH v EM

2. Article 17(3)(e) of Regulation 2016/679

must be interpreted as meaning that that provision does not formulate an alternative lawfulness condition which processing could satisfy in order to comply with Article 5(1)(a) of that regulation and which is distinct from any of those listed in the first subparagraph of Article 6(1) of that regulation.

C-484/2418 Jun 2026

NTH Haustechnik GmbH v EM

3. Article 5(1)(c) of Regulation 2016/679, read in conjunction with the second sentence of Article 52(1) of the Charter of Fundamental Rights,

must be interpreted as meaning that the principle of 'data minimisation' does not require a court to ensure, for each processing of personal data it undertakes, that the principle of proportionality is observed, by ensuring that the data processed on that occasion are such as to enable the objective pursued by that processing to be achieved and are strictly necessary for achieving it, and that the seriousness of the interference with fundamental rights entailed by taking such data into account in order to undertake that processing is proportionate to the interest which that court has in using those data in order to undertake that processing, provided that the conditions laid down in Article 5(1)(c) of Regulation 2016/679 are met.

C-484/2418 Jun 2026

NTH Haustechnik GmbH v EM

4. Articles 7 and 8 of the Charter of Fundamental Rights, Article 5(1) of Regulation 2016/679, point (c) of the first subparagraph of Article 6(1) of that regulation, read in conjunction with Article 6(3) thereof, and the principle of 'data minimisation'

must be interpreted as not precluding a national court from using evidence containing personal data obtained in breach of the right to privacy and the right to the protection of personal data by the party which transmitted such data to that court, where that party's legitimate interest in such processing does not outweigh the interest in simply adducing the facts on which it relies. By contrast, before disclosing those data to the parties or third parties, that court must verify that such data are limited to what is necessary in relation to the purposes for which such disclosure is made and, as appropriate, take certain measures to minimise the impediment to the right to the protection of personal data which such disclosure is likely to entail.

C-492/232 Dec 2025

X v Russmedia Digital SRL and Inform Media Press SRL

An online marketplace operator that is the controller of the personal data in advertisements published on its marketplace cannot rely on Articles 12 to 15 of Directive 2000/31 on the liability of intermediary providers in relation to an infringement of its obligations under Article 5(2), Articles 24 to 26, and Article 32 of Regulation 2016/679.

C-247/2313 Mar 2025

VP v Országos Idegenrendészeti Főigazgatóság

A national authority responsible for keeping a public register must rectify personal data on a natural person's gender identity where those data are inaccurate within the meaning of Article 5(1)(d) of Regulation 2016/679.

C-394/239 Jan 2025

Mousse v Commission nationale de l'informatique et des libertés (CNIL) and SNCF Connect

Processing customers' title data by a transport undertaking in order to personalise commercial communications based on gender identity does not appear to be objectively indispensable or essential to the proper performance of a contract and therefore cannot be regarded as necessary for performing that contract. The same processing cannot be regarded as necessary for the legitimate interests pursued by the controller or by a third party where those customers were not informed of the legitimate interest pursued when the data were collected. The same processing cannot be so regarded where it is not carried out only in so far as is strictly necessary to attain that legitimate interest. The same processing cannot be so regarded where, in the light of all the relevant circumstances, those customers' fundamental freedoms and rights prevail over that legitimate interest, in particular because of a risk of discrimination on grounds of gender identity.

C-65/2319 Dec 2024

MK v K GmbH

Under Article 88(1) and (2) of Regulation 2016/679, a national-law provision on the processing of personal data for the purposes of employment relationships that was adopted pursuant to Article 88(1) must require its addressees to comply not only with Article 88(2), but also with Article 5, Article 6(1), and Article 9(1) and (2).

C-65/2319 Dec 2024

MK v K GmbH

Where a collective agreement falls within Article 88(1) of Regulation 2016/679, the parties' discretion to decide whether processing is 'necessary' under Articles 5, 6(1) and 9(1) and (2) does not prevent the national court from carrying out a full judicial review of that question.

C-446/214 Oct 2024

Maximilian Schrems v Meta Platforms Ireland Limited

The data minimisation principle in Article 5(1)(c) of Regulation 2016/679 bars a controller, such as the operator of an online social network platform, from aggregating, analysing and processing for targeted advertising any personal data obtained from the data subject or from third parties and collected on or outside that platform, without any time limit and without distinguishing by type of data.

C-231/2211 Jan 2024

État belge v Autorité de protection des données

An agency or body responsible for a Member State's official journal that qualifies as a controller is solely responsible for compliance with the Article 5(1) principles for the processing operations it must carry out under national law, unless that law makes it jointly responsible with other entities for those operations.

C-667/2121 Dec 2023

ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, Körperschaft des öffentlichen Rechts

Article 9(3) of Regulation 2016/679 does not itself require a controller processing health data on the basis of Article 9(2)(h) to ensure that no colleague of the data subject can access the data. That obligation may nonetheless arise under national rules adopted under Article 9(4) or under the integrity and confidentiality principles in Article 5(1)(f), as defined in Article 32(1)(a) and (b).

C-26/227 Dec 2023

UF and AB v Land Hessen

A private credit information agency may not keep, in its own database, information taken from a public register about a natural person's discharge from remaining debts for longer than that information remains in the public register, even if it does so to provide information on that person's solvency.

C-60/224 May 2023

UZ v Bundesrepublik Deutschland

A controller's failure to comply with Articles 26 or 30 of Regulation 2016/679 does not by itself make the processing unlawful or give the data subject a right to erasure under Article 17(1)(d) or restriction under Article 18(1)(b). That remains so provided that the failure does not, as such, amount to an infringement of the principle of accountability in Article 5(2), read with Article 5(1)(a) and the first subparagraph of Article 6(1).

C-268/212 Mar 2023

Norra Stockholm Bygg AB v Per Nycander AB

When deciding whether to order production of a document containing personal data, the national court must consider the interests of the data subjects and balance them in light of all the circumstances, the type of proceedings, and the requirements of proportionality, in particular the data-minimisation principle in Article 5(1)(c) of Regulation 2016/679.

C-129/2127 Oct 2022

Proximus NV v Gegevensbeschermingsautoriteit

A national supervisory authority may require a provider of publicly available telephone directories and directory enquiry services, acting as controller, to take appropriate technical and organisational measures to inform third-party controllers that the subscriber has withdrawn consent. Those third-party controllers may include the telephone operator that supplied the subscriber's data to that provider and other directory or directory enquiry providers to whom that provider supplied the data.

C-77/2120 Oct 2022

Digi Távközlési és Szolgáltató Kft. v Nemzeti Adatvédelmi és Információszabadság Hatóság

The storage-limitation principle precludes a controller from storing, in a database created for testing and error correction, personal data previously collected for other purposes for longer than is necessary for those tests and corrections.

C-175/2024 Feb 2022

SIA 'SS' v Valsts ieņēmumu dienests

The collection by a Member State's tax authorities, from an economic operator, of information involving a significant amount of personal data is subject to Regulation 2016/679, in particular Article 5(1).

C-175/2024 Feb 2022

SIA 'SS' v Valsts ieņēmumu dienests

A Member State's tax authorities may not derogate from Article 5(1) of Regulation 2016/679 unless a legislative measure within the meaning of Article 23(1) grants them that right.

C-439/1922 Jun 2021

Proceedings brought by B

Regulation (EU) 2016/679, in particular Article 5(1), Article 6(1)(e) and Article 10, precludes national legislation that requires the public body responsible for the register of penalty points imposed on drivers of vehicles for road traffic offences to make those data accessible to the public, where the person requesting access does not have to establish a specific interest in obtaining them.

C-439/1922 Jun 2021

Proceedings brought by B

Regulation (EU) 2016/679, in particular Article 5(1), Article 6(1)(e) and Article 10, precludes national legislation that authorises the public body responsible for the register of penalty points imposed on drivers of vehicles for road traffic offences to disclose those data to economic operators for re-use.