Masdi (Protection of natural persons with regard to the processing of personal data and the free movement of such data - Data processed when drawing up a COVID-19 certificate - Judgment) [2024] EUECJ C-169/23 (28 November 2024)

Masdi (Protection of natural persons with regard to the processing of personal data and the free movement of such data - Data processed when drawing up a COVID-19 certificate - Judgment) [2024] EUECJ C-169/23 (28 November 2024)

Article 14(5)(c) GDPR exempts controllers from the obligation to provide information for all personal data not collected directly from the data subject, whether obtained from third parties or generated by the controller from such data, provided that obtaining or disclosure is expressly laid down by law and...

Source-derived case information.

Citation
[2024] EUECJ C-169/23
Parties
Applicant: Nemzeti Adatvédelmi és Információszabadság Hatóság (National Authority for Data Protection and Freedom of Information, Hungary); Respondent: UC; Issuing Authority: Budapest Főváros Kormányhivatala (Budapest Metropolitan Government Office, Hungary)
Jurisdiction
European Union
Procedural Posture
Preliminary Ruling (cjeu) / Judgment on Reference From National Court
Outcome
Preliminary ruling issued; questions answered as set out in the judgment.
Legal Topics
GDPR Article 14(1) and (5)(c), GDPR Article 32, GDPR Article 77(1), Obligation to Provide Information, Exceptions to Information Obligations, Supervisory Authority Competence, Security of Processing, COVID 19 Immunity Certificates
European Union Law Data Protection Law Administrative Law GDPR Article 14(1) and (5)(c) GDPR Article 32 GDPR Article 77(1) Obligation to Provide Information Exceptions to Information Obligations +3 more

Source-derived case record

Summary, issues, holding and outcome

More case intelligence is available

Unlock the full research layer for this judgment.

Downloadable case file Legal principles 4 Authorities cited 9 Party arguments 2
Sign in to unlock

Parties

Nemzeti Adatvédelmi és Információszabadság Hatóság (National Authority for Data Protection and Freedom of Information, Hungary)

Applicant

UC

Respondent

Budapest Főváros Kormányhivatala (Budapest Metropolitan Government Office, Hungary)

Issuing Authority

Procedural Posture

Preliminary Ruling (cjeu) / Judgment on Reference From National Court

  1. 1 Does the exception in Article 14(5)(c) GDPR apply only to data obtained from third parties or also to data generated by the controller?
  2. 2 Is the supervisory authority competent to verify if national law provides appropriate measures to protect data subjects' legitimate interests under Article 14(5)(c) GDPR?
  3. 3 Does this verification include assessment of security measures under Article 32 GDPR?

Ratio Decidendi

Article 14(5)(c) GDPR exempts controllers from the obligation to provide information for all personal data not collected directly from the data subject, whether obtained from third parties or generated by the controller from such data, provided that obtaining or disclosure is expressly laid down by law and appropriate measures to protect data subjects' legitimate interests exist. Supervisory authorities are competent to verify the existence of such measures in national law but are not required to assess the appropriateness of security measures under Article 32 GDPR in this context.

Court Disposition

Preliminary ruling issued; questions answered as set out in the judgment.

Orders

  • Article 14(5)(c) GDPR applies to all personal data not collected directly from the data subject, including data generated by the controller from third-party data.
  • Supervisory authorities are competent to verify if national law provides appropriate measures to protect data subjects' legitimate interests for the purposes of Article 14(5)(c) GDPR.