ECJ ruling on the disclosure of personal data

- Companies must name specific recipients of personal data.
- Categories of recipients or a reference to a privacy policy are not sufficient.
- The ECJ strengthens the rights of data subjects to detailed information.
- Companies must respond to information requests within one month.
- The duty to provide information also includes recipients in third countries.
Along with fundamental changes and expanded obligations for companies, the rights of data subjects have been strengthened to improve the protection of their personal data.
Article 15 of the GDPR plays a key role here by strengthening the access rights of data subjects and giving them the opportunity to see how their data is being processed and shared.
ECJ strengthens right of access under GDPR
The European Court of Justice (ECJ) has now further expanded this right and clarified how companies' duty to provide information should be understood. In this article, we show you how the ECJ has interpreted the right of access and how you should handle it.
Key takeaways from the ECJ ruling
- Companies are required to provide information about processed data and its use upon request from data subjects.
- Data subjects have the right to know which personal data has been shared with whom (for example, in the case of external data processing).
- The ECJ has clarified that this obligation is not sufficiently met by simply naming categories of recipients or referring to one's own privacy policy.
- Rather, companies are required to disclose the specific identity of third parties that have received and processed personal data from the company.
Access to personal data: What are the obligations for companies?
The GDPR includes, among other things, fundamental obligations for companies regarding the handling of personal data. Companies must provide special protection for the personal data of customers and business partners, carefully review and document processing activities, and delete data when it no longer serves a legitimate purpose.
Do you need legal support?
Our team consists of more than 90 data protection experts who are happy to provide you with comprehensive advice on the subject. Feel free to contact us at any time.
A central topic here is the obligation to enable the person affected by data processing to access their stored and processed data (the so-called right of access). This regulation can be found in Art. 15 para. 1 GDPR.
What are the benefits of the right of access under Article 15 of the GDPR for data subjects?
In addition, the data subject has the right, after receiving information, to have the data used deleted if they do not consent to the processing and use of that data (the so-called right to erasure or right to be forgotten, Article 17(1) GDPR). In case of doubt, this can also result in limitations for working with the affected individuals.
In plain language: Data subjects have the right to know whether companies are using their personal data and, if so, which data. If they exercise this right and submit an access request, the company must respond within one month and take appropriate action (e.g., deleting the data if requested).
Lawsuit from Austria: ECJ rules on GDPR right of access
For a long time, it was unclear exactly what is required to fulfill the obligation to provide information. With its recent ruling, the European Union's highest court has now shed light on the matter and clarified the obligations companies have regarding providing information to data subjects.
The legal dispute originated from a lawsuit in Austria in which a data subject exercised their right of access under Article 15 of the GDPR against Österreichische Post AG. Specifically, the individual wanted to know whether any personal data about them had been stored and, if so, what that data was and who the specific recipients were. Österreichische Post AG informed the individual that their personal data was only processed "to the extent legally permitted." They also provided a link to their website and the information available there. The individual then filed a lawsuit in the Austrian courts, demanding disclosure of the specific recipients of their personal data.
Both the court of first instance and the court of appeal dismissed the lawsuit, citing the wording of Article 15 of the GDPR, which grants companies a choice regarding the "recipients or categories of recipients." The Supreme Court of Austria (OGH), which heard the case as the final instance, was uncertain about the question of a potential hierarchy and consequently referred the question of the interpretation of Article 15 of the GDPR to the ECJ.
Result: Extensive disclosure of personal data
In its judgment of January 12, 2023 (C-154/21), the ECJ clarified that it is generally not sufficient to disclose mere categories of recipients or to refer to the lawfulness of the processing. Upon request, the data subject must be informed of the specific recipients of their personal data.
The ECJ allows only a few exceptions to this obligation, namely:
- when it is not (or not yet) possible to identify the specific recipients of the data, or
- when the requests are manifestly unfounded or excessive.
The European Court of Justice justifies its decision by stating that an extensive right of access is necessary to ensure that data subjects have sufficient information to exercise other important rights, in particular the right to erasure, restriction of processing, or the right to object to the processing of their own data.
In short: In the case of Österreichische Post AG, the ECJ held that a mere reference to the website and a blanket statement regarding lawfulness were insufficient; instead, the company should have named the specific recipients.
Court ruling on the right of access tightens obligations for companies
For companies, the ECJ ruling means that they now face stricter obligations regarding access requests from data subjects. It is no longer sufficient to simply refer to privacy policies or categories of third parties that have received personal data from the controller.
Instead, companies must now respond individually to specific access requests from natural persons and provide data subjects with the information they need to exercise their rights.
This not only tightens the duty to provide information itself, but the new requirements also have implications for other obligations under the GDPR:
- It is advisable to review GDPR compliance within your company, with a particular focus on the record of processing activities.
- Processing agreements with third parties (especially recipients in third countries) should be properly reviewed and managed in a legally compliant manner. This helps to access information about specific recipients efficiently and quickly.
- Information about specific recipients should be transmitted to the person requesting access within the stipulated 4-week response period.
How can information be provided correctly to individuals?
Companies should ensure they respond to access requests carefully. This means they must disclose the exact processing activities as well as the identity of specific recipients. While the ECJ ruling may have implications for other GDPR obligations (e.g., Art. 14 GDPR), this cannot be inferred from the ruling itself.
Compliance with data protection regulations is important for maintaining reputation and customer satisfaction. Furthermore, violations of the GDPR can result in significant fines of up to 2% of global annual turnover.
Conclusion: Implementing GDPR-compliant access to personal data
Companies are therefore advised to take care of an efficient listing of data processing in a record of processing activities well in advance. This can help in responding to requests from data subjects within the specified timeframe. It is also advisable to keep employees responsible for providing information informed about current developments and to train them accordingly so that they can fulfill their GDPR obligations.
Do you have further questions on this topic? Our experts will be happy to advise you free of charge.













