GDPR in the Mirror of CJEU Case Law: Lines, Trends and Consequences for DACH Controllers

5 min readLast updated By Philipp Staiger

Context: the GDPR as a framework regulation requiring interpretation

Since the GDPR became applicable on 25 May 2018, the Court of Justice of the European Union (CJEU) has developed an increasingly dense body of case law on its interpretation. The GDPR is designed as a framework regulation and contains numerous undefined legal concepts. Concepts such as legitimate interests under Art. 6(1)(f) GDPR, non-material damage under Art. 82(1) GDPR or the necessity of a processing operation can only be reliably operationalised through case law.

Dr. M. Hofstetter emphasises that the case law of the CJEU is decisive for controllers in the DACH region for two reasons. First, preliminary rulings under Art. 267 TFEU produce indirect effect for all Member States. Second, Swiss practice under the DSG (Federal Act on Data Protection / FADP), which entered into force on 1 September 2023, increasingly aligns with European interpretive lines where the concepts overlap. A systematic classification of the substantive duties is set out in our GDPR guide.

International data transfers: Schrems II and its consequences

With the Schrems II judgment of 16 July 2020 (Case C-311/18, ECLI:EU:C:2020:559) the Grand Chamber declared the adequacy decision on the EU-US Privacy Shield invalid. At the same time, the Court clarified the requirements for Standard Contractual Clauses under Art. 46(2)(c) GDPR. Since then, controllers have been obliged to carry out a case-by-case assessment of the level of legal protection in the recipient state before each third-country transfer and to take supplementary measures where required.

The consequence for Swiss controllers is twofold. First, the Schrems II line applies via the extraterritorial scope of the GDPR under Art. 3(2) GDPR to the processing of data of persons in the Union. Second, the FDPIC has adopted the methodology for Swiss transfers under Art. 16 DSG and supplemented it with a list of recognised third countries. With the EU-U.S. Data Privacy Framework of 10 July 2023 a new legal basis was created for certified US recipients; the Schrems II requirements, however, continue to apply to non-certified recipients.

Non-material damages: the line since C-300/21

A second central line concerns damages under Art. 82 GDPR. In the Österreichische Post judgment of 4 May 2023 (Case C-300/21, ECLI:EU:C:2023:370) the CJEU clarified that a mere infringement of the GDPR does not, on its own, establish a claim for damages. What is required is rather proof of concrete non-material damage, although this does not have to exceed a threshold of seriousness.

This line was further refined in the follow-up decisions Natsionalna agentsia za prihodite of 14 December 2023 (Case C-340/21, ECLI:EU:C:2023:986) and MediaMarktSaturn of 25 January 2024 (Case C-687/21, ECLI:EU:C:2024:72). The CJEU confirmed that a justified fear of misuse of data may also constitute compensable damage. For controllers this means a considerable tightening of liability, especially in the case of data breaches affecting large numbers of data subjects. The notification duty under Art. 33 GDPR within 72 hours remains the most important procedural anchor for limiting damage.

The right of access: scope and limits

The third defining line concerns the right of access under Art. 15 GDPR. In the FT judgment of 26 October 2023 (Case C-307/22, ECLI:EU:C:2023:811) the CJEU clarified that a controller must in principle provide the copy under Art. 15(3) GDPR free of charge and in a form that enables the data subject to exercise their rights. In the Pankki S judgment of 22 June 2023 (Case C-579/21, ECLI:EU:C:2023:501) the Court specified that log data may also be covered insofar as they contain statements about the data subject.

A. Brunner classifies this line from an operational perspective. Implementing the right of access requires a consolidated view of all systems in which personal data are processed. Controllers that do not maintain complete Records of Processing Activities (ROPA) under Art. 30 GDPR regularly run into the conflict between the one-month deadline under Art. 12(3) GDPR and the substantive completeness of the response. An integration with the ISMS under ISO/IEC 27001 is here an effective lever.

Legitimate interests and controllership

In the KNLTB judgment of 4 October 2024 (Case C-621/22, ECLI:EU:C:2024:857) the CJEU further concretised the interpretation of legitimate interests under Art. 6(1)(f) GDPR. The Court confirmed that purely economic interests can in principle be taken into account, provided that the balancing exercise with the interests of the data subjects is carefully documented. This line stands in continuity with the Meta Platforms judgment of 4 July 2023 (Case C-252/21, ECLI:EU:C:2023:537), which addressed the interplay of data protection and competition law.

For the concept of controller under Art. 4(7) GDPR the Fashion ID judgment of 29 July 2019 (Case C-40/17, ECLI:EU:C:2019:629) remains the reference point. CJEU case law tends towards a broad reading of joint controllership under Art. 26 GDPR. Controllers should therefore regularly review contracts and processing constellations with service providers, platforms and group companies for the question of co-controllership.

Fines: group liability and the standard of culpability

With the judgments Deutsche Wohnen of 5 December 2023 (Case C-807/21, ECLI:EU:C:2023:950) and Nacionalinis visuomenes sveikatos centras of the same day (Case C-683/21, ECLI:EU:C:2023:949) the CJEU clarified central questions of sanctioning law under Art. 83 GDPR. First, the imposition of a fine on a legal person does not require fault on the part of a representative body; fault in a functional sense is sufficient. Second, for the calculation of the fine under Art. 83(5) GDPR the group turnover within the meaning of the EU-law undertaking concept must be taken into account.

This line has direct consequences for group structures with Swiss parent or subsidiary companies. The maximum administrative fine bracket of EUR 20 million or 4 percent of the worldwide annual turnover of the preceding financial year under Art. 83(5) GDPR is calculated not on the directly liable entity but on the economic unit as a whole. Groups should adjust their governance structures accordingly.

What this means for Swiss companies

K. Aebischer brings the perspective of a Swiss SME CISO. Three operational consequences result from the CJEU line. First, controllers should document their third-country transfers following the Schrems II methodology and use the EU-U.S. Data Privacy Framework as legal basis only where the recipient is certified and the scope of application is met. Second, breach notification processes should be set up so that the 72-hour deadline under Art. 33 GDPR and the parallel notification duty under Art. 24 DSG can be observed.

Third, the handling of access requests should be set up technically and organisationally to meet the broadened reach defined by the CJEU. A comparative consideration of the Swiss and European regimes is set out in our DSG guide (German-language pillar). The division of roles between data protection officer and CISO is systematically described in our overview DPO vs. CISO.

How SIDD supports you

SIDD accompanies controllers in implementing the duties arising from CJEU case law. In our mandate as external DPO under GDPR Art. 37 we take responsibility for the ongoing monitoring of conformity and the communication with the supervisory authorities. In our mandate as Swiss data protection advisor under Art. 10 DSG we manage the parallel implementation of the Swiss duties.

For controllers without an establishment in the Union we provide the EU Representative under Art. 27 GDPR. As at the time of publication, further densification of case law is to be expected in particular on damages, on profiling processing under Art. 22 GDPR and on joint controllership. N. Köhler adds, from the editorial perspective, that internal data protection documentation should be kept concise, current and audit-ready. SIDD supports the consolidation of this documentation along the respective decisive CJEU line.

GDPR in the Mirror of CJEU Case Law: Lines, Trends and Consequences for DACH Controllers

INSIGHT

All
13 April 2026
Philipp Staiger
CJEU case law has been concretising the interpretation of the GDPR since 2018 and increasingly shapes the application of the Swiss DSG. The article analyses the key lines and derives concrete duties for controllers in the DACH region.

Subscribe to our newsletter for free here

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.