Can a commercial database containing criminal record data invoke the freedom of the press? And may a bank keep the arrangements it makes with an external service provider regarding customer data out of sight of those very customers? Both questions were recently addressed in case law. The Court of Justice of the EU (hereinafter: the Court) handed down a judgment on the scope of the journalistic exemption in Article 85 GDPR. In the Netherlands, the District Court of Amsterdam ruled that ING must grant access to its contractual arrangements with Google regarding payments via Google Pay. Read more about these rulings in this case law blog.
On 9 July 2026, the Court handed down a judgment on Article 85 GDPR and how the journalistic exemption is to be interpreted in the context of online publications of personal data. The Court makes clear that Member States may not stretch the journalistic exemption and tightens the definition of journalistic purposes.
How did the journalistic exemption work again? The GDPR protects personal data, but sometimes clashes with the freedom of expression. Consider a journalist conducting research into a public figure: strict application of all GDPR rules would render his work virtually impossible. For that reason, Article 85 of the GDPR contains a special regime. It follows from paragraph 1 that Member States must reconcile both fundamental rights. In addition, paragraph 2 provides that they may, for journalistic, academic, artistic and literary purposes, derogate from large parts of the GDPR. Without that exception, matters such as news reporting, scientific research and artistic expression would be seriously compromised.
That freedom is, however, subject to clear limits. Derogation is permitted only for those four specific purposes. Not for other activities, not even where the freedom of expression is at stake. Nor may the legal protection of the data subject (including the right to lodge a complaint with the supervisory authority, the right of access to a court and the right to compensation) ever be derogated from. What is precisely meant by 'journalistic purposes' was unclear until this judgment. All that was established was that the concept had to be interpreted broadly.
The case concerned the Swedish company Legal Newsdesk Sweden, which operates the Lexbase database. Anyone willing to pay can search this database for individuals and companies that have been criminally prosecuted in Sweden. The applicant, too, appeared in it: he had been convicted in 2011 and his data remained accessible online for years. When the applicant requested erasure, this did not occur immediately, but only later on the basis of Legal Newsdesk's internal retention policy. Ultimately, he claimed SEK 300,000 (approx. €26,000) in compensation for infringement of the GDPR.
Legal Newsdesk raised a defence against this claim. It relied on the Swedish "utgivningsbevis", a constitutional publication certificate which, under Swedish law, entails that the GDPR does not apply. Under that construction, anyone who considers themselves aggrieved can only bring criminal or civil defamation proceedings, a considerably higher threshold than a GDPR claim. The Swedish court doubted whether this was compatible with Union law and referred the case to the Court.
The Court answers three questions.
1. May Member States go further than Article 85(2) allows?
The answer to this is no. According to the Court, paragraph 1 does not provide an autonomous basis for creating derogations from the GDPR going further than those already permitted by paragraph 2. Exceptions to the GDPR must be interpreted strictly, and only the four specifically mentioned forms of expression justify such derogations. What the Swedish legislature did therefore went too far.
2. May legal protection be restricted?
Here too, the answer is negative. Article 85(2) exhaustively sets out from which parts of the GDPR Member States may derogate where personal data are processed for journalistic purposes. Chapter VIII of the GDPR, which governs the right to lodge a complaint with the supervisory authority, the right to an effective judicial remedy and the right to compensation, is not mentioned in that enumeration. Derogation from it is therefore not permitted. Member States may, of course, lay down procedural rules on the basis of procedural autonomy, but may not impose additional substantive conditions. A scheme that compels the data subject to enforce his rights through defamation proceedings (with all the evidential difficulties that entails) is thereby incompatible.
3. When are journalistic purposes at issue?
The Court acknowledges that the concept must be interpreted broadly, but at the same time formulates four cumulative characteristics. First, the processing must be aimed at the disclosure to the public of information, opinions or ideas. Second, there must be some form of processing, or at least disclosure to the public of information, opinions or ideas. Third, factual assertions must have been verified for accuracy. And fourth, the activity must be subject to the moral and ethical rules of the journalistic profession.
Importantly, the commercial nature (payment) and the sensitive nature of the data (criminal convictions) do not in themselves preclude the existence of journalism. A paid news site, too, can be journalistic. However, Lexbase was not, according to the Court: the database made public documents available without editing, without an editorial line and without journalistic ethics. The fact that those documents may be useful to journalists does not alter that assessment: they must be exclusively intended for journalistic activities.
Anyone who discloses personal data from public sources, whether court records, land registry data or other registers, cannot straightforwardly rely on the journalistic exemption. Without editorial processing, verification and journalistic ethics, the GDPR applies in full, including the additional safeguards of Article 10 GDPR for criminal record data. Business models built on aggregating and reselling such data will have to be critically scrutinised.
In the Netherlands, Article 43 of the GDPR Implementation Act (UAVG) governs the exemptions for data processing for journalistic purposes. This judgment shows that this provision must be interpreted strictly, and that the rights under Chapter VIII of the GDPR may never be excluded or impeded by national legislation. Data subjects therefore always retain their right to lodge a complaint with the Dutch Data Protection Authority, their right of access to the courts and their right to compensation, regardless of which freedom of the press the controller invokes.
Traditional news media, incidentally, will generally satisfy the four criteria formulated by the Court. They will still be able to rely on the journalistic exemption after this judgment.
The Dutch Consumers' Association (Consumentenbond) and the Foundation for Aggrieved Parties in Action (Stichting Benadeelden in Actie, SBIA) want to know what Google precisely does with the payment data of ING customers. ING refused to share its contracts. The District Court of Amsterdam has subsequently ordered the bank to provide transparency regarding privacy in payments via Google Pay.
Anyone who holds an ING account and wishes to pay contactlessly with an Android telephone has been unable to bypass Google since September 2024. ING discontinued its own payment app and since then offers only Google Pay. The Consumers' Association and SBIA are concerned about the privacy of ING customers who pay using this payment method. According to those organisations, customer data end up with Google, which is known for previous privacy breaches. With every payment via Google Pay, ING shares data with Google. Not only name, address and telephone number upon activation, but also the details of every transaction: when you paid, how much, and at which shop. Google stores those data, at the very least in order to be able to display a payment overview to customers. The interest groups question whether Google possibly also uses those data to enrich profiles and sell advertisements.
The data flow between ING and Google can be divided into two moments. Upon activation, Google receives the name, address and telephone number of the account holder. Those data are necessary in order to digitally link the payment card to the customer's Google account. With every payment, ING shares the date, the time, the amount and the name and location of the shop. Without those data, the transaction cannot be processed. Google, however, also retains those data: users can request an overview of their payments in Google Pay.
The District Court establishes that ING and Google process these data for the same purpose: facilitating contactless payment. This gives rise to joint controllership. ING argued that it is jointly responsible with Google only for the activation of the payment token. For everything else, Google would be independently responsible. The District Court rejects that reasoning. The GDPR provides that parties are joint controllers where they jointly determine the purposes and means of processing. That is the case here. ING and Google work together with a single purpose: enabling customers to pay via Google Pay. The parties process the same data for that purpose.
That qualification entails obligations. Joint controllers must, in accordance with Article 26 GDPR, transparently determine who is responsible for what, in particular for the exercise of the rights of data subjects and the provision of information to them. Moreover, the essence of those arrangements must be made available to the data subjects whose data are concerned. ING states that it has made arrangements with Google, but refuses to share their content. That is difficult to reconcile with the transparency that the GDPR precisely prescribes.
The processing of personal data is only lawful if there is a legal basis for it in Article 6 GDPR. For the execution of the payment itself, that basis is clear: the processing is necessary for the performance of a contract, since without the transaction data the payment cannot be processed. However, does that processing go further than what is necessary for the payment? The Google Payments Privacy Notice refers to Google's general privacy policy and states that data are used for "every day business purposes". This is a rather open-ended term. According to the District Court, Google earns money with profiles and targeted advertising. If Google were to use payment data to enrich user profiles, the question arises as to which legal basis would apply. Consent is not expressly requested, and under the legal basis of legitimate interest, the privacy interests of data subjects will weigh heavily, particularly in the case of data that reveal a great deal about a person's daily life. The Consumers' Association wishes to be able to verify this matter. Without access to the contracts, it cannot be established which data processing has been agreed, or whether Google adheres to it.
In this case, the District Court pointed to ING's banking duty of care, which may entail that ING must stipulate guarantees to prevent Google from using personal data for purposes unrelated to payment. The protection of personal data thus follows indirectly from this duty of care. The District Court considers that the data at issue are "highly privacy-sensitive". Payment data reveal where a person goes, what a person buys, when and how often. If ING directs its customers to an external party for a basic banking function such as making payments, it may be expected to stipulate safeguards for the protection of those data. Whether ING has done so must be apparent from the contracts that it is now required to produce.
In this ruling, the District Court has expressly held that a confidentiality arrangement between ING and Google cannot prevent the Consumers' Association from obtaining access. Even where controllers have agreed confidentiality between themselves, the right of data subjects to know how controllers have arranged their mutual relationship remains intact. Transparency obligations can therefore not be contracted away.
And this applies far beyond banking. Working with external parties on data processing? Let us help you navigate.