Categories: Insights, Publications · News, Publications

Tag: GDPR, Privacy


29 Jan 2025

Data protection and collective agreements: provisions of national collective agreements that breach data protection rules should be disapplied

In its judgment of December 19, 2024,  case C-65/23, the Court of Justice of the European Union ruled that (i) the provisions of national collective labor agreements must comply with data protection regulations and that:(ii) ”Should the national court seized of the matter conclude, following its review, that certain provisions of the collective agreement […] do not comply with the conditions and limits set forth by the GDPR, it would be required not to apply such provisions […].”

The case  

The case originates from a claim filed by a German employee, who claimed that the company he worked for was unlawfully processing his personal data. In particular, the company used a SAP software for accounting purposes and the personal data entered in it was transferred to a server located in the United States of America. The company defended itself by claiming that the processing of personal data carried out was lawful because it complied with the provisions of the collective agreements applied in the company.

The employee therefore brought the case before the territorially competent national courts, seeking: (i) access to his personal data, (ii) the deletion of data concerning him and (iii) the recognition of compensation.

The German national judges, called upon to decide the case, raised questions about the scope of the applicability of Article 88 of the GDPR. Article 88 of the GDPR provides that “Member States may, by law or by collective agreements, provide for more specific rules to ensure the protection of the rights and freedoms in respect of the processing of employees’ personal data in the employment context […]”.

Can collective agreements establish rules on data processing, even by derogating from the provisions of the GDPR, or must they fully comply with them?

In its ruling, the Court of Justice clarified that when the provisions of a national collective agreement regulate the processing of personal data in the workplace, they must comply with the fundamental principles of the GDPR. The effect must be to bind its addressees (employers and trade unions) to ensure compliance with the principles of lawfulness, fairness, and transparency of the processing, the requirements for lawful consent, and the rules regarding the processing of special categories of personal data.

This means that if a judge were to determine that the provisions of a collective agreement regulating one or more personal data processing activities in the workplace violate the conditions and limits set by the applicable sectoral legislation, the judge would be required to disapply the non-compliant provisions, without the discretion available to the parties to the agreement in determining the “necessary” nature of a personal data processing activity preventing the court from exercising full judicial review in this regard.

Other related insights:    

Subscribe to our newsletter

Contact

Need information? Write to us and our team of experts will respond as soon as possible.

Fill in the form

More news and insights

1 Oct 2026

Corporate e-mail and defensive monitoring: when the GDPR and employment law lead to different outcomes 

The Piaggio case clearly illustrates how the same set of facts can give rise to profoundly different assessments depending on the perspective adopted. In its decision of 13…

1 Oct 2026

NASpI and Reinstatement: the Employee’s Election Causes Loss of the Benefit 

Headnote   In its recent judgment No. 24981 of 3 September 2026, the Italian Supreme Court held that, where a dismissal is set aside with an order of reinstatement…

1 Oct 2026

Did you know that… testimony given in court may have disciplinary relevance and, in the most serious cases, justify dismissal? 

The Italian Supreme Court, Labour Section, by order no. 25687 of 22 September 2026, addressed the issue of the disciplinary relevance of statements made by an employee in…

29 Sep 2026

Shadow AI in the workplace: how to govern risks, data, and security (Agenda digitale, 29 September 2026 – Vittorio De Luca and Martina De Angeli)

The spread of artificial intelligence tools used without corporate authorization exposes businesses to risks involving personal data, confidential information, know-how, and cybersecurity. To govern Shadow AI, organizations need…

24 Sep 2026

The concept of “territorial scope” in a non-compete agreement (Top24 Lavoro Ai – Il Sole 24 Ore, 24 September 2026 – Vittorio De Luca and Alessandro Ferrari)

Interpretative issues in light of the most recent case law on the nullity of non-compete agreements due to the indeterminacy of territorial scope By an order issued on…

16 Sep 2026

Did you know that… repeated violations of company procedures may justify the dismissal of a store manager?

The Italian Supreme Court (Labour Section), in Order No. 25231 of 11 September 2026, upheld the lawfulness of the dismissal for just cause of a store manager who…