Yesterday, the Luxembourg Administrative Court issued a historical ruling in the long-running dispute between Amazon Europe Core S.à r.l. and the Luxembourg data protection authority (CNPD), concerning the €746 million fine imposed by the latter in 2021.

The violations examined in the case were related to the legal basis for processing personal data and legitimate interest based advertising. The violations in their substance were confirmed. All parties as well as the court agreed that the violations were present. Yet the court annulled the entirety of the CNPD decision and referred the case back to the supervisory authority.

Why, you may ask? Forming a significant piece of case law that reminds us similar rulings in the context of competition law, the Court found that critical elements of enforcement reasoning were missing.

In plain English, it went a bit like that:

The supervisory authority identifies violations. → The supervisory authority imposes a fine.

The Court said: Weeell, it should have gone like that:

The supervisory authority identifies violations and proves the objective elements of the non-compliance. → The supervisory authority analyses whether there was intent, knowledge, negligence, purpose, i.e., proves the subjective elements of the non-compliance. → The supervisory authority imposes a fine.

(Elle Woods mens rea kind of moment 😉)

The decision offers several important lessons for both organisations and regulators when it comes to GDPR enforcement:

  1. Fines require proof of fault: Following the Court of Justice of the European Union (CJEU) judgments in Deutsche Wohnen and Nacionalinis (December 2023), supervisory authorities must determine whether an infringement was committed intentionally or negligently.
  2. Sanctions must be justified based on proportionality: Article 58 GDPR provides a broad range of erforcement tools, from warnings up to administrative fines in order of gravity. There should always be a structured analysis of why the specific measure was chosen instead of another one based on the principle of proportionality.
  3. Enforcement must remain within the scope of the investigation: A regulatory investigation must have a clear scope and enforcement decisions shall remain strictly within that perimeter. Elements outside of the scope cannot form the basis of enfocement measures.
  4. Confirmed violations do not automatically sustain a sanction: Procedural shortcomings in enforcement reasoning can invalidate sanctions even when the substantive issues are existent and undeniable.

As GDPR decisions increasingly face judicial scrutiny, courts are requiring supervisory authorities to provide detailed and structured reasoning, similar to what you would see in a court ruling, particularly when imposing very significant fines.

What does this mean for organisations and leadership teams?

  1. Regulatory decisions can be challenged. Together with your compliance risks, assess your litigation and defence strategy.
  2. Pair your compliance with strategic risk management. Data protection is not a stand-alone requirement, it is part of enterprise risk governance affecting financial exposure, reputation and operational continuity.
  3. Early legal and technical alignment matters. Organisations that combine legal insight, technical understanding and business strategy are far better positioned when it comes to enforcement risk.

Let’s not forget: this ruling does not end the case. The matter now returns to the CNPD so that it can reassess the sanction on the basis of the Court’s guidance. It will be interesting to see how this turns out…


0 Comments

Leave a Reply

Avatar placeholder

Your email address will not be published. Required fields are marked *