10/12/2024 on Oct. 4, 2024, the Court of Justice of the European Union (hereinafter: the Court) once again confirmed that the concept of special personal data must be interpreted broadly. The Court ruled in the Lindenapotheke judgment that information entered by customers when ordering pharmacy drugs should be considered health data. In addition, the Court ruled that the General Data Protection Regulation (GDPR) does not preclude national legislation allowing competitors to challenge GDPR violations as unfair trade practices. In short, a landmark ruling that caused a lot of controversy. In this blog, you can read what the implications of this ruling may be for your organization.

Case background

The case stems from a dispute between two competing pharmacists in Germany.  'Lindenapotheke' (hereinafter: LA) has a license for the online sale of pharmacy drugs without a prescription on the online platform Amazon-Marketplace. When making such an online purchase, a customer must provide data such as name, delivery address, and information that allows individualization of the medicines. A competitor of Lindenapotheke 'Winthir Apotheke' (hereinafter: WA) requests LA to stop selling pharmacy drugs as long as customers do not give prior consent for data processing. WA cites German laws against unfair competition and claims that LA's sale of pharmacy drugs is unfair. According to WA, it violates the GDPR by not seeking prior consent from customers to share health data, as required under Article 9 of the GDPR. After the lower courts granted the claim, LA appealed to the German Federal Court of Justice. The latter in turn deemed it necessary to refer two preliminary questions to the Court regarding, first, the system of remedies established by the GDPR and, second, the category of special personal data.

Court's opinion in Lindenapotheke

Question 1: GDPR remedies

The Court finds that the GDPR's system of remedies does not preclude a national provision allowing a competitor to bring an action against an alleged infringer. The Court emphasizes that such an application does not undermine the system of remedies provided for in the GDPR, nor the objective of the GDPR which seeks a consistent level of protection of personal data in the EU. On the contrary, this possibility complements the remedies and strengthens the effectiveness of the GDPR as well as the protection of data subjects.

Question 2: interpretation of special personal data

The Court notes that data relating to a purchase, when they can be used to draw conclusions about the health status of an identified or identifiable person, must be considered health data within the meaning of Article 4(15) of the GDPR. In doing so, the Court emphasizes the broad interpretation of this concept, in line with the interpretation of the European Data Protection Board (EDPB). This means that data that may indirectly reveal sensitive information are also covered by the definition. Moreover, the Court did not consider it relevant for the assessment that the order is placed by a website visitor for another person.

What does this statement mean in practice?

It is no surprise that the concept of special personal data should be interpreted broadly. It follows from this ruling that it can even include data that says something about the health of a third party. Given this, it is essential to identify what type of data is being processed in your organization. In doing so, it is important to assess whether these data may - directly or indirectly - contain information about health, racial or ethnic origin, political opinions, religious or philosophical beliefs, sexual preferences, or genetic or biometric data of a person or his or her loved one. In fact, the processing of special personal data receives extra protection in the GDPR. Processing them is in principle prohibited, unless you can invoke an exception as mentioned in Article 9, paragraph 2, GDPR. Often that is explicit consent from the data subjects. You may therefore have to adjust your internal processes.  

Furthermore, the ruling opens the door for competitors to hold each other accountable for GDPR violations, provided that national law allows it. In the Netherlands, the Unfair Commercial Practices Act provides a possible legal starting point for this. The ruling is in line with case C-252/2. In that case, the Court held that a competition authority, in the context of investigating abuse of a dominant position by an undertaking on a particular market, can also investigate rules other than competition law, such as the GDPR. Together, the rulings form the basis for a new and dynamic playing field for GDPR enforcement, in which regulators (among themselves) and organizations can act together for more decisive compliance.

All in all, market players will have a strong incentive to enforce the GDPR on competitors. For example, they can use injunctions to stop data-related anti-competitive behavior and take action against competitors who gain an unfair advantage by not complying with privacy rules. These developments in the legal playing field highlight the importance of privacy compliance within your organization to further protect your competitive position.

Floor Dulack Legal Consultant

Want to know more?

Wondering how your privacy compliance compares to that of your competitors? Or would you like to gain better insight into what kind of personal data you process? Then contact us; we would be happy to help you with expert advice and practical solutions.

Our services orContact