Logo RGPD
RGPD.click
/
  1. Home
  2. Resources
  3. Fiches
  4. Key European Case Law & Rulings
Courses Guides Blog Resources News
Français English Nederlands
Fiche 53/54 Part 5 — Operational Obligations & Sanctions Advanced Reviewed 2026-08-23

Key European Case Law & Rulings

The Court of Justice of the European Union (CJEU) shapes and standardises the definitive interpretation of the GDPR. Its rulings carry binding authority across all member state courts and regulatory a

Open in interactive reader
🏛️ CJEU Case Law (2020-2025) 🇧🇪 Belgian DPA Precedents

Key European Case Law & Rulings

⚡ In 30 seconds

The CJEU resolves legal disputes on EU law interpretation. Its judgments decisively govern everyday GDPR compliance practice across all member states.

JudgmentSubject MatterPractical Impact
Schrems II (C-311/18, 2020)Cross-border transfersInvalidated EU-US Privacy Shield; requires supplemental transfer impact assessments (TIAs) for SCCs.
Google Spain (C-131/12, 2014)Right to be forgottenSearch engine operators qualify as controllers and must delist search results upon lawful request.
Meta / Bundeskartellamt (C-252/21, 2023)Market dominance & legal basesCompetition regulators can evaluate GDPR breaches; contractual necessity interpreted strictly.
SCHUFA (C-634/21, 2023)Automated scoring (Art. 22)Automated credit scores used by third parties constitute automated decisions subject to Article 22 restrictions.
⚡ Key Takeaways
  • Schrems II (C-311/18) struck down Privacy Shield and mandated robust Transfer Impact Assessments for transatlantic transfers.
  • Wirtschaftsakademie (C-210/16) established broad joint controllership (e.g., Facebook fan page administrators).
  • CJEU precedents prevail over divergent national interpretations, establishing uniform European privacy doctrine.
⚠️ Common Pitfall

Reading GDPR articles literally in isolation without monitoring CJEU rulings, which consistently apply stricter and more consumer-protective interpretations.

🛠️ Practical Action

Establish an ongoing regulatory monitoring process to track upcoming CJEU judgments, notably regarding consent mechanics and legitimate interests.

⚖️ Official sources: CJEU C-311/18, C-634/21, C-487/21, C-203/22 · Belgian DPA Rulings ✓ Last legal review: 23 August 2026

✓ Key takeaways

  • Schrems II (C-311/18) struck down Privacy Shield and mandated robust Transfer Impact Assessments for transatlantic transfers.
  • Wirtschaftsakademie (C-210/16) established broad joint controllership (e.g., Facebook fan page administrators).
  • CJEU precedents prevail over divergent national interpretations, establishing uniform European privacy doctrine.

⚠ Common pitfall: Reading GDPR articles literally in isolation without monitoring CJEU rulings, which consistently apply stricter and more consumer-protective interpretations.

→ Actionable practice: Establish an ongoing regulatory monitoring process to track upcoming CJEU judgments, notably regarding consent mechanics and legitimate interests.

← Civil Liability & Right to Compensation (Art. 82) Documented Compliance Roadmap →