The Court of Justice of the European Union (CJEU) recently issued two GDPR-related rulings that are of great importance to you as a business owner and to your competitors. These rulings address the question of whether breaches of privacy legislation can be classified as unfair trade practices, and whether commercial interest can qualify as a legitimate interest for data processing under the GDPR. In this blog we explain both topics.
1. Can a breach of the GDPR be classified as an unfair trade practice?
On 4 October 2024, the CJEU ruled on the question of whether a competitor can hold another business owner liable for a breach of the GDPR as constituting an unfair trade practice (i.e. a tortious act). The case concerned a pharmacist who sold medicines via Amazon and, in doing so, collected customers’ health data without explicit consent. A competing pharmacist argued that this was in breach of the GDPR.
The Court ruled that health data is processed in online medicine sales, for which explicit consent is required under the GDPR. What makes this ruling notable is that the competitor had the right to raise the GDPR breach as an unfair trade practice against the competitor. This is a remarkable development, since it gives businesses the ability to hold each other legally accountable for breaches of the GDPR, even where there is no direct harm to the consumer, who is the directly interested party under the GDPR.
Unfair trade practices can lead to substantial damages. After all, unfair competition involves concrete financial harm consisting of lost profit and income.
What does this mean for your business?
This ruling creates additional legal risks for businesses. Not only consumers, but now also your competitors can hold you liable for breaches of the GDPR. This gives competitors a powerful legal tool to take action and potentially claim damages if your business violates the GDPR. Compliance with the GDPR is therefore crucial not only for consumer trust, but also to avoid legal disputes with competitors.
Please note: if you are considering taking legal action against a competitor, bear in mind that you must then do the same yourself. Fully correct compliance with the GDPR is almost impossible (due to the sometimes vague standards in the law). Full compliance with cookie and spam rules is readily achievable. Think this through carefully before taking action. We are of course happy to advise you on this.
2. Commercial interest as legitimate interest under the GDPR
Another CJEU ruling concerns the question of whether commercial interest can qualify as a “legitimate interest” for data processing under the GDPR. This arose in the case of the Royal Dutch Lawn Tennis Association (KNLTB), in which members’ personal data was sold to third parties for marketing purposes without consent. The Dutch Data Protection Authority (AP) imposed a fine of €525,000 on the KNLTB in 2020, but the KNLTB challenged this, resulting in the CJEU ruling that a commercial interest can, in some cases, be a legitimate interest. The AP’s interpretation has thereby been definitively set aside!
Under the GDPR (Article 6(1)(f)), it is possible to process personal data on the basis of a legitimate interest, provided three conditions are met:
- The legitimate interest must be lawful;
- The processing must be necessary to serve that interest;
- The interest of the data controller must outweigh the rights and freedoms of the data subjects.
The CJEU rightly points out in its ruling that the European legislature did not provide in the GDPR that an interest is only “legitimate” if it is explicitly laid down in law. A commercial interest, such as direct marketing, can also be a legitimate interest, but a balancing of interests must take place. As long as the commercial interest is not contrary to the law and the balancing exercise shows that the commercial interest outweighs the privacy rights of the data subjects, there is nothing wrong with it.
What does this mean for your business?
First, it is important that, before using the data for direct marketing purposes, you inform the data subjects and ask for consent that their personal data will be passed on to third parties for advertising or marketing purposes.
Please note: this ruling does not give your organization a free pass to process personal data without consent. This ruling does certainly create room to invoke commercial interest as a legitimate interest for data processing. Always carry out a careful assessment in writing (and record it in the processing register) as to whether your commercial interest outweighs the privacy rights of the data subjects. Data subjects must also be informed of your plans and given the opportunity to object. If this does not happen, the processing may still be unlawful.
The case has for now been referred back to the district court, which will examine this question further. To be continued.
New EDPB guidelines
On 10 October 2024, the European Data Protection Board (“EDPB”) published new guidelines on the use of the “legitimate interest” legal basis. These clarify the steps businesses must take before they can rely on this legal basis. The EDPB emphasizes that it is important for businesses to demonstrate that their commercial interest is genuinely legitimate and that the processing of personal data is necessary to achieve that interest. In addition, a thorough balancing of interests must take place, in which the rights of data subjects are safeguarded.
Determining whether a commercial interest outweighs the privacy rights of data subjects can be a legally complex balancing exercise. The business lawyers of The Legal Company are happy to think this through with you.
Conclusion
The recent CJEU rulings bring about important changes for businesses and other organizations, such as sports and professional associations. On the one hand, competitors can challenge GDPR breaches as unfair trade practices, which creates additional legal risks. On the other hand, the Court gives businesses more room by allowing commercial interest as a legitimate interest, provided a careful balancing of interests takes place.
Businesses should therefore review their privacy policy, not only to avoid fines from regulators, but also to avoid legal action from competitors. In addition, the CJEU’s and EDPB’s interpretation of legitimate interest will serve as a guide for how businesses can balance their commercial interests with the protection of personal data.
Does your business face complex privacy issues or legal challenges around the GDPR? Whether you want to prevent a competitor from holding you liable for a breach, or want to take a strong legal position against a competitor that is violating privacy rules, we are ready to support you. Contact us at info@thelegalcompany.nl or call 020 345 0152.
We can also help you draft or improve your internal privacy policy. With in-depth knowledge of the GDPR, we help you turn privacy issues into opportunities for your business. Contact us today for an advisory consultation.