Article 77 GDPR

From GDPRhub
Article 77 - Right to lodge a complaint with a supervisory authority
Chapter 10: Delegated and implementing acts

Legal Text


Article 77 - Right to lodge a complaint with a supervisory authority

1. Without prejudice to any other administrative or judicial remedy, every data subject shall have the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the data subject considers that the processing of personal data relating to him or her infringes this Regulation.

2. The supervisory authority with which the complaint has been lodged shall inform the complainant on the progress and the outcome of the complaint including the possibility of a judicial remedy pursuant to Article 78.

Relevant Recitals

Recital 141: Right to Lodge a Complaint and Right to an Effective Judicial Remedy
Every data subject should have the right to lodge a complaint with a single supervisory authority, in particular in the Member State of his or her habitual residence, and the right to an effective judicial remedy in accordance with Article 47 of the Charter if the data subject considers that his or her rights under this Regulation are infringed or where the supervisory authority does not act on a complaint, partially or wholly rejects or dismisses a complaint or does not act where such action is necessary to protect the rights of the data subject. The investigation following a complaint should be carried out, subject to judicial review, to the extent that is appropriate in the specific case. The supervisory authority should inform the data subject of the progress and the outcome of the complaint within a reasonable period. If the case requires further investigation or coordination with another supervisory authority, intermediate information should be given to the data subject. In order to facilitate the submission of complaints, each supervisory authority should take measures such as providing a complaint submission form which can also be completed electronically, without excluding other means of communication.

Commentary

Article 77 GDPR opens Chapter VIII of the GDPR which establishes rules on remedies, liability and penalties.

Article 77(1) GDPR grants data subject a remedy in case they consider that processing of their personal data infringes the GDPR. Specifically, this provision stipulates that the data subject has a right to lodge a complaint with a supervisory authority (“SA”) in case of GDPR violations.

Article 77(2) GDPR obliges the SA with which the complaint has been lodged to inform the complainant on the progress and the outcome of the complaint. Such information has to include a reference to the data subject's right to an effective judicial remedy against a decision or inactivity by the SA in accordance with Article 78 GDPR.

Both Article 77(1) and (2) GDPR are directly applicable and do not require transposition into national law. However, the details of the complaints procedure are subject to Member State law, which must observe the requirements and objectives of the GDPR - including the fact that lodging a complaint must be cost free for the data subject in accordance with (Article 57(3) GDPR[1].

In the absence of EU rules governing the matter, it is for each Member State, in accordance with the principle of the procedural autonomy of the Member States, to lay down the detailed rules of administrative and judicial procedures intended to ensure a high level of protection of rights which individuals derive from EU law. [… ]


[T]he detailed rules for the implementation of those concurrent and independent remedies should not call into question the effectiveness and effective protection of the rights guaranteed by that regulation.


Those detailed rules must not be less favourable than those governing similar domestic actions (principle of equivalence); nor must they render practically impossible or excessively difficult the exercise of rights conferred by EU law (principle of effectiveness) […].

CJEU - C-132/21 - Nemzeti Adatvédelmi és Információszabadság Hatóság, margin number 45 et seqq..


Many SAs provide forms that ensure that a complainant includes all relevant information as suggested in the last sentence of Recital 141 GDPR.[2]

(1) Right to a formal complaint

According to Article 77(1) GDPR, every data subject shall have the right to lodge a complaint with a SA, in particular in the Member State of their habitual residence, place of work or place of the alleged infringement, if the data subject considers that the processing of personal data relating to them infringes the GDPR.

[T]he complaints procedure, which is not similar to that of a petition, is designed as a mechanism capable of effectively safeguarding the rights and interests of data subjects.

CJEU - C‑414/24 - Datenschutzbehörde (Articulation des recours), margin number 50.


It should be pointed out that the GDPR provides for parallel remedies for data subjects claiming that the GDPR has been infringed. In particular, they can file a complaint with a SA under this provision or they have the option to bring a case in front of a court (i.e. a judicial remedy) in accordance with Article 79 GDPR. These remedies can be exercised concurrently with and independently of each other.[3] In addition, data subjects have the right to claim compensation for damages resulting from an infringement of the GDPR in accordance with Article 82 GDPR.[4]

Under Article 80 GDPR, data subjects have the right to mandate certain not-for-profit bodies with lodging complaints with SA (Article 77 GDPR), bringing remedies against a decision or inactivity by the SA (Article 78 GDPR) and lodging a judicial remedy in front of a court (Article 79 GDPR).[5]

It should also be recalled that data subjects have to be informed about their right to lodge a complaint in accordance with Article 13(2)(d), 14(2)(e) and 15(1)(f) GDPR.

Article 57(1)(f) GDPR obliges the supervisory authority to handle complaints lodged by data subjects in accordance with this provision.

Without prejudice to any administrative or judicial remedy

The right to file a complaint under Article 77(1) does not limit any other administrative or judicial remedies available. For instance, a data subject can still initiate legal proceedings against a controller or processor (as per Article 79 GDPR) irrespective of whether a complaint has been lodged with a supervisory authority, either concurrently or independently.[6] Lodging a complaint with a supervisory authority does not impact the eligibility or validity of other remedies.

Article 77(1), Article 78(1) and Article 79(1) of Regulation 2016/679, read in the light of Article 47 of the Charter, must be interpreted as permitting the remedies provided for in Article 77(1) and Article 78(1) of that regulation, on the one hand, and Article 79(1) thereof, on the other, to be exercised concurrently with and independently of each other. It is for the Member States, in accordance with the principle of procedural autonomy, to lay down detailed rules as regards the relationship between those remedies in order to ensure the effective protection of the rights guaranteed by that regulation and the consistent and homogeneous application of its provisions, as well as the right to an effective remedy before a court or tribunal as referred to in Article 47 of the Charter.

CJEU - C-132/21 - Nemzeti Adatvédelmi és Információszabadság Hatóság, margin number 57.


However, it should be recalled that the principle of procedural autonomy of the Member States requires that they lay down the detailed rules of administrative and judicial procedures. These detailed rules for the implementation of the concurrent and independent remedies provided by the GDPR should not call into question the effectiveness and effective protection of the rights guaranteed by the GDPR.[7] Therefore, the CJEU already held that a DPA cannot reject (to handle) a complaint solely on the ground that a judicial proceeding under Article 79(1) GDPR, concerning the same subject matter, have already been brought as this would compromise the effective protection of the rights guaranteed by the GDPR.[8] On the other hand, according to the CJEU a suspension mechanism in which a SA suspends a proceeding pending before a court until a court decision definitely closes the dispute in question seems compatible with the framework of remedies provided to the data subject.[9]

The decision of whether to choose the complaint procedure or another remedy (or multiple remedies) lies with the affected individual and may be influenced by practicality or efficiency aspects, in addition to legal considerations. Some of these aspects may be, legal costs, procedural expediency, the presence or absence of procedural rights including the right to be heard throughout the proceedings.

Another reason to file a complaint with the SA instead of using another legal remedy could be the intention to make the DPA aware of specific GDPR infringements, since complaints are an important medium for SAs to learn of and observe data protection practices.

"Complaints under Article 77(1) of the GDPR play an important role in terms of the supervisory authorities’ awareness of infringements of the rights protected by that regulation. Those complaints therefore contribute significantly to ensuring a consistent and high level of protection of natural persons within the European Union and to strengthening and setting out in detail the rights of those persons within the meaning of recitals 10 and 11 of that regulation."

CJEU - C‑416/23 - Österreichische Datenschutzbehörde, margin number 53.


It should also be noted that the data subject's right to complaint does not preclude the national legislator to implement provisions enabling competitors of a controller to challenge GDPR infringements in court as prohibited unfair commercial practices.[10]

The data subject shall have the right to lodge a complaint

The GDPR grants data subjects the right to file a complaint with a supervisory authority. Such complaint is no mere petition, rather it initiates a complaint procedure designed to effectively safeguard the rights and interests of data subjects.[11] In accordance with Article 57(1)(f) GDPR, the supervisory authority is required to handle complaints under Article 77 GDPR in all due diligence and to examine the nature of that complaint as necessary.[12]

"In order to handle complaints lodged, Article 58(1) of the GDPR confers extensive investigative powers on each supervisory authority. Where, following its investigation, such an authority finds an infringement of the provisions of that regulation, it is required to react appropriately in order to remedy the shortcoming found. To that end, Article 58(2) of that regulation lists the various corrective measures that the supervisory authority may adopt"

CJEU - C‑26/22 and C‑64/22 - SCHUFA Holding and Others (Discharge from remaining debts) (Joined Cases), margin number 57.

See also CJEU, Case C-474/24. NADA Austria, 14 July 2026, margin number 128.


The SA is also required to take action where the exercise of one or more of the corrective powers provided for in Article 58(2) GDPR is appropriate, necessary and proportionate to remedy the shortcoming found and ensure that that GDPR is fully enforced.[13]

The meaning of the term "complaint" is not defined by Article 77, nor by the GDPR in general. Given the lack of a strict legal definition, the term should be interpreted in a broad way, with the only exclusion of those cases where a data subject is not lamenting any negative situation specifically affecting him or her. In terms of object, the content of a complaint is not restricted to the 'rights of the data subject' that form the object of Chapter 3 of the GDPR.[14]

The complaint procedure itself is - in accordance with the principle of procedural autonomy of the Member States - subject to the national rules of administrative procedures. Accordingly, each national law must implement the procedural aspects of the remedies provided for in the GDPR.[15] However, the national rules for administrative proceedings in connection to a remedy governed by EU law cannot be unfavourably compared to remedies provided for by national law:

[T]hose detailed rules must not be less favourable than those governing similar domestic actions (principle of equivalence); nor must they render practically impossible or excessively difficult the exercise of rights conferred by EU law (principle of effectiveness) [...]

CJEU - C‑414/24 - Datenschutzbehörde (Articulation des recours), margin number 44.


Procedurally, the GDPR itself does not set any particular requirements. E.g. there is no stipulation that lodging a complaints requires a prior interaction with the controller (i.e. exercising rights directly against the controller prior to lodging a complaint). However, this interaction might be required due to the nature of the complaint, such as case of a complaint due to violation in the right of access. However, outside these cases and as long as a similar requirement is not established at the national level, a SA has no power to dismiss a complaint on the only basis that the data subject did not reach out to the controller in the first place. It has to be stressed that the lodging itself does not preclude further communications between data subject and controller, nor the possibility to close the case in an amicable way. Concerning the time for the lodging of a complaint, the GDPR does not establish any particular limitation. However, some Member States have established deadlines, starting e.g. from the moment when the violation became known to the data subject.[16] Also this element has to be read in light of the principle of procedural autonomy, however, the CJEU indicated that – subject to the principles of equivalence and effectiveness – a time limit for lodging GDPR violations is generally compatible with the GDPR.[17]

SAs are obliged to facilitate the submission of complaints, inter alia, by measures such as providing complaint submission forms which can also be completed electronically.[18] However, SAs should not exclude other means of submitting complaints. Filing a complaint (as well as the complaint proceedings itself) is generally free of charge unless a complaint is manifestly unfounded or excessive.[19]

It should be recalled, that the GDPR provides for a special cooperation mechanism in the case of cross border proceedings. See Commentary on Article 60 GDPR for more information on that.

For more information on the complaints procedure in general, see also Commentary on Article 57(1)(f) GDPR.

Data subjects also have the right to an effective judicial remedy against a decision by the SA as well as against inaction of the SA. Similarly, a controller or processor has a remedy against a decision by the SA (see Commentary on Article 78 GDPR).

In case there is a processing of personal data which infringes the Regulation

The provision requires that a complaint can be filed when the "data subject considers that the processing of personal data relating to him or her infringes the Regulation." From this perspective, there are two essential conditions; first, there must be a processing of personal data relating to a specific individual. Second, the processing must infringe the GDPR.

Processing of personal data

The controller, joint controller, or processor must have processed the personal data of the data subject. Consequently, if no data processing has ever occurred, there is obviously no basis for filing a complaint. However, this interpretation should not lead to extreme outcomes.

First and foremost, by virtue of the favour granted to them for submitting the complaint, it is not required for the data subject to provide an objective and robust demonstration of the ongoing processing. The case must certainly be contextualized, allowing the SA to initiate, if deemed necessary, the appropriate investigations. In any event, the level of detail required for substantiation is unquestionably lower compared to what is stipulated in civil procedures, as it is incumbent upon the SA to develop its own legal assessment.[20]

Moreover, there are certain situations where, even in the absence of data processing, a complaint may still seem justifiable, avoiding systematically unacceptable interpretations. First, consider, for example, the case of the privacy policy under Article 13 of the GDPR. This information is typically provided before the data processing begins, and yet, there is no doubt that the right to information under Article 13 GDPR is a fundamental right and a violation of it can be subject to a complaint to the supervisory authority. Second, a similar situation arises with Article 15(1) of the GDPR, which grants the data subject the right to obtain "from the controller confirmation as to whether or not personal data concerning him or her are being processed." If the controller fails to respond to such a request, a clear violation of the GDPR occurs. Once again, there is no doubt that the data subject can file a complaint under Article 77 of the GDPR, simply due to not having received such a response, regardless of whether any personal data processing has actually taken place or is ongoing. Third, another scenario is when a controller, upon being informed of the data subject's intention to take legal action for unlawful data processing, intentionally deletes the data to avoid potential liabilities, thus violating Article 17(3)(e) of the GDPR. In this case, indeed, no ongoing data processing exists, and a strict application of Article 77 would lead to the complaint being deemed inadmissible. However, once again, such a conclusion would be entirely unacceptable.

Hence, in general terms, a complaint under Article 77 is only admissible when there is ongoing processing of personal data related to the complainant. No hard evidence about this shall be provided by the data subject. Nevertheless, in certain situations specifically foreseen in the law ("lex specialis"), the complaint remains admissible even if no processing occurred.

An infringement of the Regulation

The data subject must at least allege that their data is processed in violation of the GDPR. It is subject to debate whether there is a limitation to the infringements of the GDPR that can be addressed via complaints. For example, some SAs have taken the stance that the right to lodge a complaint is limited to violations of data subject rights under Chapter III of the GDPR (“Rights of the data subject“).[21] However, the provision does not provide for such a restriction. Data subjects can therefore file complaints also for other violations of the GDPR.[22]

In particular, the CJEU held that data subjects have the right to lodge a complaint in case a controller infringes their obligation to conclude a joint controllership agreement under Article 26 GDPR or keep a record of processing activities under Article 30 GDPR.[23] Of course, the complainant has to argue that their personal data is processed by the controller in connection to the processing operation affected by such infringement - it is not sufficient to argue that a third party might be affected by the processing.[24]

The complainant must set out the facts of the case in a way that allows the SA to understand which infringement is claimed by the data subject. The SA should not require complainants to provide very detailed information in their initial complaint but the SA can ask the complainant to provide further information in the course of the procedure.[25]

In the past, it was subject to debate whether a data subject can already file a complaint in case an infringement of the GDPR has not happened but is foreseeable in the near future. This debate was ended by the CJEU which held that a complaint under Article 77 GDPR can already be lodged with a supervisory authority in case there are specific indications that a processing of personal data infringing the GDPR is imminent or will take place in the near future.[26]

Restricting the obligation to handle complaints incumbent on supervisory authorities under Article 57(1)(f) of the GDPR, by interpreting Article 77(1) of the GDPR as precluding any possibility of a complaint being lodged with a supervisory authority where the controller is preparing to process data, would be contrary to the objectives pursued by that regulation, in particular the objective of ensuring a high level of protection of natural persons with regard to the processing of personal data within the European Union.


Accordingly, a complaint made under Article 77 of the GDPR may be regarded as admissible, despite the fact that the processing of personal data forming the subject matter of that complaint has not yet taken place on the date on which the data subject lodges that complaint with the supervisory authority, provided, however, that that processing is not purely hypothetical.

CJEU - C‑474/24 - NADA Austria and Others, margin number 134 et seq.


Similarly, the CJEU already held that a data subject can lodge a complaint in case their personal data "has been or could be transferred to a third country",[27] and that any attempt to process personal data also constitutes processing of personal data.[28]

With a(ny) supervisory authority

The GDPR only requires that a SA is addressed by the complaint. This general rule is only limited by a non-exhaustive list of possible SAs. This means that a complainant may file a complaint with any SA in the European Economic Area, independent of location.[29]

Habitual residence

The most common place to lodge a complaint is the home jurisdiction of the complainant. The habitual residence is a term used in different EU laws[30] and requires an objective assessment of the factual residence. Especially in cross border cases, data subjects might want to choose to lodge complaints at the place of their habitual residence, as this allows for the data subject to file the complaint in (one of) the official languages of the relevant Member State, rather than the official language of the Member State that the controller is based in.

Place of work

Similar to the habitual residence, complainants can lodge a complaint before the SA of their work place. It is not required that the complaint has any connection to the place of work.

Place of alleged infringement

The complaint can also be lodged before the SA of the place of the alleged infringement. This clause is a typical form of jurisdiction that is aimed at aligning the location of the decision maker with the location of facts. Example: The SA that is closest to a CCTV camera may be best placed to gather factual evidence on the CCTV system, without the need to request mutual assistance from other SAs.

Cross country cases

The option to lodge a complaint with any SA does not mean that the SA with which the case has been lodged necessarily decides about the case. Which SA actually handles the case is subject to Article 55 and 56 GDPR. In any case the SA with which the complaint has been lodged remains a “supervisory authority concerned” under Article 4(22)(c) GDPR and the point of contact for the data subject (“one-stop shop”).[31]

(2) Duty to inform the data subject

Article 77(2) GDPR obliges the SA which which a complaint has been lodged to inform the complainant about the progress of the complaint and about their potential remedies. Specifically, “the supervisory authority with which the complaint has been lodged shall inform the complainant on the progress and the outcome of the complaint including the possibility of a judicial remedy pursuant to Article 78.

The SA which which the complaint has been lodged

This provision addresses only the SA with which the complaint has been lodged but not other SAs ultimately involved in the case under Articles 55 and 56 GDPR (in particular, the potential lead SA). The SA’s report on the progress as well as the final decision must include information on the possibility for a judicial remedy under Article 78(2) GDPR and Article 78(1) GDPR respectively. This fits into the system that the data subject (as well as the controller) should only be required to correspond with one SA.[32]

Information about the Progress and the outcome

Article 77(2) GDPR itself does not stipulate a deadline by which the data subject has to be initially informed about the progress of the complaint, nor does it contain rules on the frequency of such “progress reports”. However, Article 57(1)(f) GDPR contains the parallel obligation of the SA to handle complains lodged by data subjects. It requires the SA to inform the complainant of the progress and the outcome of the investigation within a reasonable period, in particular, if further investigation or coordination with another SA is necessary. Moreover, under Article 78(2) GDPR, a data subject has the right to an effective judicial remedy where the competent SA does not inform the data subject within three months on the progress or outcome of the complaint lodged pursuant to Article 77 GDPR, or when the SA does not handle the case.[33]

Therefore, in domestic cases, the SA which which the complaint was filed has to inform the complainant about the progress of the complaint procedure within three months. The same is true in cross-border cases. The information will similarly be provided to the complainant by the SA with which the complaint has been filed even if it is not the lead SA. First, the SA with which the complaint has been filed still has some competences in One-Stop-Shop proceedings under Article 60 GDPR, and the notification obligation under Article 78(2) GDPR therefore sill applies to it. Second, for practical reasons, the SA with which the complaint has been lodged will inform the data subject on behalf of the lead SA in such cases also in regard to the lead SA's obligation to inform about the progress of the complaint. For the information about the outcome of the decision, Article 60 (7)-(9) GDPR provides for more specific rules that must be complied with by the lead SA as well as the SA with which the complaint has been filed.[34] The information about the progress of the complaint procedure should, in particular, allow complainants to exercise their rights under Article 41(2) CFR, in particular, it should facilitate their right to be heard and their right to have access to their file. Similarly, the information about the outcome of the complaint procedure has to allow data subjects to exercise their right to an effective judicial remedy against a supervisory authority, taking into account Article 47 CFR.

If the complaint procedure is not finished within three months, it should be considered insufficient to inform the data subject just once about the progress of the procedure; rather, the SA must inform the complainant about the progress of the complaint every three months. However, such an information does not have to be overly detailed as long as it includes information about the status of the complaint, the steps taken since the last information, and the upcoming steps.[35] The information about the progress should therefore also include any meaningful new information that might have a significant impact on the procedure.[36]

In practice, the first information usually is an acknowledgement of receipt of the complaint. In case of a cross border procedure, the information is also combined with a notification that a lead SA under Article 56 GDPR was identified and that the case has been forwarded to that lead SA.

Inform about the possibility of a judicial remedy

The SA has to inform complainants about the possibility of a judicial remedy pursuant to Article 78 GDPR. It is argued that the the information about the data subject's remedy is only necessary in case they are informed about the outcome of the complaint procedure.[37] However, an argument could also be made for requiring that the SA informs the complainant about their remedy against the SA's inaction in accordance with Article 78(2) GDPR in order to make them aware that they have this option.

Decisions

→ You can find all related decisions in Category:Article 77 GDPR

References

  1. Bergt, in Kühling, Buchner, DS-GVO BDSG, Article 77 GDPR, margin number 26 (C.H. Beck 2024, 4th Edition).
  2. E.g. see https://data-protection-authority.gv.at/data-protection-in-austria/right-to-lodge-a-complaint, last accessed on 18.06.2026.
  3. CJEU, Case C-132/21, Nemzeti Adatvédelmi és Információszabadság Hatóság, margin number 35 (available here).
  4. For more information see Commentary on Article 82 GDPR.
  5. See Commentary on Article 80 GDPR for more information.
  6. CJEU, Case C-132/21, Nemzeti Adatvédelmi és Információszabadság Hatóság, 12 January 2023, margin number 35 (available here).
  7. CJEU, Case C-414/24, Datenschutzbehörde v. Dr. GS, 18 June 2026, margin number 43 (available here).
  8. CJEU, Case C-414/24, Datenschutzbehörde v. Dr. GS, 18 June 2026, margin number 57 and 59 (available here).
  9. CJEU, Case C-414/24, Datenschutzbehörde v. Dr. GS, 18 June 2026, margin number 54 (available here).
  10. CJEU, Case C-21/23, ND v. DR, 4 October 2024, margin number 73 (available here).
  11. CJEU, Joint Case C-26/22 and C-64/22, Schufa, 7 December 2023, margin number 58 (available here).
  12. CJEU, Joint Case C-26/22 and C-64/22, Schufa, 7 December 2023, margin number 56 (available here); see also CJEU, Case C-474/24. NADA Austria, 14 July 2026, margin number 127 (available here).
  13. CJEU, Case C-414/24, Datenschutzbehörde v. Dr. GS, 18 June 2026, margin number 51 (available here).
  14. Tambou, in Spiecker gen. Döhmann, Papakonstantinou, Hornung, De Hert, General Data Protection Regulation, Article 77, margin number 21 (Nomos Verlagsgesellschaft 2023, 1st edition)
  15. CJEU, Case C-414/24, Datenschutzbehörde v. Dr. GS, 18 June 2026, margin number 41 et seq. (available here).
  16. See e.g. the Austrian Datenschutzgesetz Art. 2 § 24, which establishes a 1-year deadline
  17. CJEU, Case C-414/24, Datenschutzbehörde v. Dr. GS, 18 June 2026, margin number 56 (available here).
  18. See Article 57(2) GDPR.
  19. See Article 57(3) and (4) GDPR.
  20. Boehm in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 77 GDPR, margin number 6 (C.H. Beck 2019).
  21. Datenschutzbehörde, 13 September 2018, das Bundesministerium für Europa, Integration und Äußeres, das Bundeskanzleramt, DSB-D123.070/0005-DSB/2018, (available here).
  22. Compare e.g. Schweiger, in Knyrim, DatKomm, Article 77 GDPR, margin number 11 (Manz 2021), Boehm, in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 43 GDPR, margin numbers 5 (NOMOS 2025, 2nd Edition); Nemitz, in Ehmann, Selmayr, DS-GVO, Article 77 GDPR, margin number 14 (C.H. Beck 2024, 3rd Edition); Bergt, in Kühling, Buchner, DS-GVO BDSG, Article 77 GDPR, margin number 10 (C.H. Beck 2024, 4th Edition).
  23. CJEU, Case C-60/22, Bundesrepublik Deutschland, 4 May 2023, margin number 67 (available here).
  24. Bergt, in Kühling, Buchner, DS-GVO BDSG, Article 77 GDPR, margin number 10 with further references (C.H. Beck 2024, 4th Edition).
  25. Boehm, in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 43 GDPR, margin numbers 5 et seq. (NOMOS 2025, 2nd Edition).
  26. CJEU, Case C-474/24. NADA Austria, 14 July 2026, margin number 139 (available here).
  27. CJEU, Case C-311/18, Facebook v Schrems, 16 July 2020, margin number 119 (available here).
  28. CJEU, Case C-474/24. NADA Austria, 14 July 2026, margin number 131 (available here).
  29. Bergt in Kühling, Buchner, DS-GVO BDSG, Article 77 GDPR, margin number 9 (Beck 2024, 4th Edition).
  30. E.g. see Article 1(j) of Regulation 883/2004 of the European Parliament and the Council of 29 April 2004 on the coordination of social security systems (available here).
  31. See also Bergt in Kühling, Buchner, DS-GVO BDSG, Article 77 GDPR, margin number 9 (Beck 2024, 4th Edition).
  32. Bergt, in Kühling, Buchner, DS-GVO BDSG, Article 77 GDPR, margin number 24 (C.H. Beck 2024, 4th Edition).
  33. See also Commentary on Article 57 and 78 GDPR.
  34. See Commentary on Article 60 GDPR.
  35. Compare Bergt, in Kühling, Buchner, DS-GVO BDSG, Article 77 GDPR, margin number 22 (C.H. Beck 2024, 4th Edition).
  36. Boehm, in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 77 GDPR, margin numbers 19 (NOMOS 2025, 2nd Edition).
  37. Boehm, in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 43 GDPR, margin numbers 23 with further references (NOMOS 2025, 2nd Edition).

index.php?title=Category:GDPR Articles