What Changed
- The EDPB updated its One-Stop-Shop thematic case digest on the right to object and right to erasure to reflect hundreds of new DPA decisions.
- The revision was conducted under the Support Pool of Experts programme as part of the EDPB 2024-2027 Strategy to enhance DPA supervisory capacity.
- The digest summarizes common GDPR infringements, internal compliance evaluations, and corrective measures regarding request processing like direct marketing objections and account deletions.
Data protection officers, legal counsel, and cross-border businesses operating within the European Union need to align their internal compliance procedures with recent regulatory enforcement trends. The European Data Protection Board (EDPB) has published an updated version of its One-Stop-Shop (OSS) case digest focusing on the right to object and the right to erasure under the General Data Protection Regulation (GDPR).
This updated publication was developed under the EDPB's Support Pool of Experts (SPE) programme, an initiative integrated into the EDPB 2024-2027 Strategy. The SPE programme assists European Data Protection Authorities (DPAs) in building supervisory and enforcement capacity by providing access to specialized expertise and developing common compliance tools.
The thematic case digest analyzes decisions selected from the EDPB public register under Article 60 of the GDPR. It provides structured insight into how DPAs evaluate organizational processes implemented to fulfill data subject requests. Additionally, the digest identifies common compliance failures and outlines corrective measures issued by DPAs. Practical scenarios highlighted in the digest include exercising the right to object to direct marketing processing and handling requests for account or online profile deletion. The digest was revised to incorporate hundreds of new One-Stop-Shop decisions finalized since the original digest was compiled.
Alongside this release, recent DPA enforcement actions reflect strict scrutiny over data subject rights and location data processing. For instance, the Irish Data Protection Commission fined Google 403 000 000 EUR following an inquiry into location data processing. Separately, the Spanish DPA fined Securitas Direct 100 000 EUR for making the exercise of data subject rights more difficult by directing individuals to a chargeable telephone number. The EDPB is also harmonising fining methodology and adopting final DSA-GDPR guidelines.
Organizations processing personal data of EU residents should consult the updated digest to review their request-handling workflows, ensure unhindered exercise of data rights, and avoid non-compliance penalties under the GDPR. Official details are available through the EDPB.
Who May Be Affected
Data controllers, legal professionals, and compliance managers handling EU personal data, as well as European Data Protection Authorities.
Cross-Border Context
Applies across the European Union under the Article 60 GDPR One-Stop-Shop mechanism, directly impacting cross-border data processing operations.
What to check next
- Review the full EDPB updated One-Stop-Shop case digest on the EDPB website.
- Examine specific DPA decisions cited regarding direct marketing objections and account deletion workflows.
This article provides general information and does not constitute legal advice. Consult the official text and obtain advice appropriate to your circumstances where needed.
Prepared automatically with AI assistance from the official sources linked on this page. Translations and explanations do not replace the official text.