CJEU Expands GDPR’s Reach to Include Oral Data Disclosure

17th April 2024

The Court of Justice of the European Union reinforces protections for sensitive data 

The Court of Justice of the European Union ruled that in the case of Endemol Shine Finland Oy (Case C-740/22), oral disclosure of information could be considered as processing of personal data, thus subject to EU data protection laws. 

Case Details

This case arose when production company Endemol Shine asked a Finnish District Court to provide information found in their filing system on the criminal background of an individual participating in a competition run by Endemol Shine. The court refused saying that it had no legal basis for this data to be processed, and Endemol Shine responded by filing a report with the Eastern Finland Court of Appeal. 

This court then referred the case to the CJEU, enquiring if data relating to criminal convictions can be disclosed orally to ensure public access to official documents, and significantly, if an oral disclosure of information about said individual would be considered processing of personal data.   

CJEU Ruling

The CJEU ruling stated that:

  • Article 2(1) and Article 4(2) of the EU GDPR’s definitions of ‘processing’ also refer to oral disclosure of data.
  • Article 86 of the EU GDPR does not apply in this specific case, and any information about an individual’s criminal background cannot be disclosed without a legitimate reason, regardless of whether another individual or a business is asking for it.

This case is unusual because it became more about the legal meaning of oral processing rather than the need to balance the right to data privacy with public access to documents. Up until this ruling, information held in memory and only disclosed verbally was assumed to not fall under the scope of the GDPR. There is little case law on oral data processing but for the law to be effective at protecting individual’s rights, then oral disclosure must be considered as a form of processing. The CJEU also noted that despite the ruling in this case, oral disclosure of manually processed data that does not form part of a filing system may not fall under the EU GDPR. 

Public Interest vs. Individual Rights

This case arose because a private company asked a court to provide it with information which it believed to be in the public interest.

Freedom of Information legislation entitles individuals to ask public authorities to provide information on any of their statutory activities, but an exemption exists allowing for disclosure to be declined if the information is classified as ‘personal data’. Article 86 of the GDPR allows for personal data to be disclosed in order to reconcile public access to official documents; a few cases of relevance here are Case C-439/19 Latvijas Republikas Saeima, in which the CJEU ruled that publishing data on penalty points for traffic violations was not in the public interest, as it was not necessary to improve road safety.

In two other cases which were ruled upon jointly due to their similarities, Cases C‑37/20 and C‑601/20 WM and Sovim SA v Luxembourg Business Registers, the CJEU ruled in favour of data privacy over public interest. In these cases, anti-money laundering laws state that financial entities include their ‘ultimate beneficial owners’ details on a publicly accessible register. However, the CJEU ruled that allowing unrestricted access to these particular individuals’ data would leave them vulnerable to fraud and other crimes. 

The need for a balance between an individual’s right to privacy and public interest is important when applying data protection laws. In this case, the court did not find that Endemol Shine was acting in the public interest when it asked for sensitive information about the individual’s potential criminal background. In another circumstance, this could have gone another way, where the court ruled that disclosure of the individual’s criminal background was in the public interest. This is why it is important to bear in mind the specific circumstances of every case. 

See more about this case:

Hunton Privacy & Information Security Law Blog

International Association of Privacy Professionals Blog

EU Law Live Blog

 

Author: Paul Adams LLB (HONS)

Paul is an information governance specialist and one of the founder Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.

Let us ease your mind

If you have any queries, questions or requests then please get in touch. We’re always very happy to talk, you’ll find a friendly voice on the end of the line or simply fill out the form below.

    Your Contact Details