New contract necessity questions for corporate processing referred to the CJEU

In today’s EU Official Journal, new questions submitted to the CJEU: What is “necessary” for performance of a contract under the GDPR, and can customary business practices be taken into account in this assessment? In languages such as French where gender traditionally has an influence on many words in a sentence and also on how you address someone (“Dear Sir/Madam” is also an example), knowing the gender of the person in front of me helps know whether to use the feminine or masculine in how I write to that person [note that there are ways to make text gender-neutral or to take into account more than 2 genders].

A case lodged before the CJEU (C-394/23) will examine whether this type of information can be “necessary” for performance of a contract (or justified under legitimate interests) – see in particular the first question:

“In order to assess whether data collection is adequate, relevant and limited to what is necessary, within the meaning of Article�5(1)(c) of the GDPR�(1)�and the need for processing in accordance with Article�6(1)(b) and (f) of that regulation, may account be taken of commonly accepted practices in civil, commercial and administrative communications, with the result that the collection of data relating to customers� civil titles, which is limited to �Mr� or �Ms�, may be regarded as necessary, without this being precluded by the principle of data minimisation?

The second question is less clear, as it suggests that the existence of a right to object might be taken into account, in reference to Art. 21 GDPR (even though only applies in the case of legitimate interest processing, not contract processing):

“In order to assess the need for the compulsory collection and processing of data relating to customers� civil titles, even though some customers consider that they do not come under either of the two civil titles and that the collection of such data is not relevant in their case, should account be taken of the fact that those customers may, after having provided those data to the data controller in order to benefit from the service offered, exercise their right to object to the use and storage of those data by relying on their particular situation, in accordance with Article�21 of the GDPR?”

I wonder whether that second question should not have been formulated differently – the concern of most organisations is not whether there is an Art. 21 GDPR right to object but whether the personalisation aspect can be an *optional* service without fear of “necessity” disappearing under data protection rules.

Keep an eye on that one – link to the case file: https://lnkd.in/e6S4gdxi

privacy

🫖

Did this analysis get you thinking? Reach out!

DataLaws.net is entirely open-access, and instead of getting your data in exchange for this content, how about another trade? If this commentary saved you research time or sparked an idea, feel free to invite me over for tea, chai or a hot chocolate next time you are around Brussels or Antwerp - or invite me over to your offices for a chat!

Get in touch ↗   Let's connect on LinkedIn ↗