Case law
Onderwijsgroep Zusters der Christelijke Scholen Zuid-Kempen
ECLI:EU:C:2026:750
- Gericht
- Court of Justice of the European Union
- Aktenzeichen
- C-458/25
- Datum
- 10.09.2026
- Dokumenttyp
- Advocate General's Opinion
Provisional text
OPINION OF ADVOCATE GENERAL
CAMPOS SÁNCHEZ-BORDONA
delivered on 10 September 2026 (1)
Case C‑458/25
Gegevensbeschermingsautoriteit
v
Onderwijsgroep Zusters der Christelijke Scholen Zuid-Kempen VZW
(Request for a preliminary ruling from the Hof van Cassatie (Court of Cassation, Belgium))
( Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – General conditions for imposing administrative fines – Article 83(7) – Power of the Member States to lay down the rules determining whether and to what extent administrative fines may be imposed on public authorities and bodies – Concepts of ‘public authority’ and ‘public body’ – Legal person governed by private law that provides subsidised free education – Exemption from the administrative fine provided for in the national legislation – Processing the personal data of children )
1. In 2019, the Belgian authority responsible for the protection of personal data (2) imposed an administrative fine on the owner of a subsidised educational establishment, for having infringed the legislation in that area.
2. Article 83(7) of Regulation (EU) 2016/679 (3) permits the Member States to lay down ‘rules on whether and to what extent administrative fines may be imposed on public authorities and bodies’ that infringe the provisions of that regulation. The Belgian legislature has made use of that provision to exclude the imposition of administrative fines on public authorities, except where they are legal persons governed by public law offering goods or services in a market.
3. The aim of this reference for a preliminary ruling is to establish whether a legal person governed by private law that provides subsidised independent education constitutes a ‘public authority’, within the meaning of Article 83(7) of the GDPR.
I. Legislative framework
A. EU law. The GDPR
4. Recital 38 reads:
‘Children merit specific protection with regard to their personal data, as they may be less aware of the risks, consequences and safeguards concerned and their rights in relation to the processing of personal data. Such specific protection should, in particular, apply to the use of personal data of children for the purposes of marketing or creating personality or user profiles and the collection of personal data with regard to children when using services offered directly to a child. The consent of the holder of parental responsibility should not be necessary in the context of preventive or counselling services offered directly to a child.’
5. Article 5 (‘Principles relating to processing of personal data’), paragraph 1, provides:
‘Personal data shall be:
(a) processed lawfully, fairly and in a transparent manner in relation to the data subject (“lawfulness, fairness and transparency”);
…
(c) adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (“data minimisation”);
…’
6. Article 6 (‘Lawfulness of processing’), paragraph 1, provides:
‘Processing shall be lawful only if and to the extent that at least one of the following applies:
(a) the data subject has given consent to the processing of his or her personal data for one or more specific purposes;
…
(f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
…’
7. Article 8 (‘Conditions applicable to child’s consent in relation to information society services’) states:
‘1. Where point (a) of Article 6(1) applies, in relation to the offer of information society services directly to a child, the processing of the personal data of a child shall be lawful where the child is at least 16 years old. Where the child is below the age of 16 years, such processing shall be lawful only if and to the extent that consent is given or authorised by the holder of parental responsibility over the child.
Member States may provide by law for a lower age for those purposes provided that such lower age is not below 13 years.
2. The controller shall make reasonable efforts to verify in such cases that consent is given or authorised by the holder of parental responsibility over the child, taking into consideration available technology.
…’
8. Article 57 (‘Tasks’), paragraph 1, states:
‘Without prejudice to other tasks set out under this Regulation, each supervisory authority shall on its territory:
…
(b) promote public awareness and understanding of the risks, rules, safeguards and rights in relation to processing. Activities addressed specifically to children shall receive specific attention;
…’
9. Article 58 (‘Powers’), paragraph 2, provides:
‘Each supervisory authority shall have all of the following corrective powers:
…
(d) to order the controller or processor to bring processing operations into compliance with the provisions of this Regulation, where appropriate, in a specified manner and within a specified period;
…
(i) to impose an administrative fine pursuant to Article 83, in addition to, or instead of measures referred to in this paragraph, depending on the circumstances of each individual case;
…’
10. Article 83 (‘General conditions for imposing administrative fines’) provides:
‘1. Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article in respect of infringements of this Regulation referred to in paragraphs 4, 5 and 6 shall in each individual case be effective, proportionate and dissuasive.
2. Administrative fines shall, depending on the circumstances of each individual case, be imposed in addition to, or instead of, measures referred to in points (a) to (h) and (j) of Article 58(2). …
…
7. Without prejudice to the corrective powers of supervisory authorities pursuant to Article 58(2), each Member State may lay down the rules on whether and to what extent administrative fines may be imposed on public authorities and bodies established in that Member State.
…’
B. Belgian law. The Data Protection Law
11. In accordance with Article 5 of the Data Protection Law: (4)
‘The definitions contained in [the GDPR] shall apply.
For the purposes of applying this law, “public authority” shall mean:
1. the federal State, the federated entities and local authorities;
2. legal persons governed by public law that depend on the federal State, the federated entities or local authorities;
3. persons, whatever their form or nature, which:
– have been established for the specific purpose of meeting needs in the general interest, not having an industrial or commercial character; and
– have legal personality; and
– whose activity is mainly funded by the public authorities or bodies mentioned in paragraphs 1 and 2, or whose management is subject to supervision by those authorities or bodies, or where more than half the members of the administrative, management or supervisory body of the person in question are appointed by those authorities or bodies;
4. associations formed by one or more of the public authorities provided for in paragraphs 1, 2 and 3.’
12. Article 221(2) of the DPL states:
‘Article 83 of [the GDPR] does not apply to public authorities or to their employees or agents, except where they are legal persons governed by public law offering goods or services in a market.’
II. Facts, dispute and question referred for a preliminary ruling
13. On 22 July 2019, the father of a pupil lodged a complaint with the DPA against a centre that provides subsidised independent education belonging to the Onderwijsgroep Zusters der Christelijke Scholen Zuid-Kempen VZW (Educational Group of the Sisters of the Christian Schools of Zuid-Kempen, non-profit association; ‘the OZCS’).
14. The complaint concerned a survey regarding the pupils’ well-being, distributed to the pupils via a digital platform.. The complainant reported that the establishment:
(a) had not previously informed the parents of the survey;
(b) had not obtained their consent;
(c) had processed more data than was necessary; and
(d) had acted unlawfully, by failing to carry out an assessment of the impact of the processing operations on the protection of personal data.
15. On 16 June 2020, the DPA ruled that the OZCS was the data controller and established four infringements of the GDPR, relating to: (a) Article 6(1); (b) Article 8; (c) Article 5(1)(c); and (d) Article 5(1)(a), read together with Article 12(1) and Article 13.
16. The DPA ordered that the processing be brought into compliance with the infringed provisions of the GDPR and imposed an administrative fine of EUR 2 000 on the OZCS.
17. The OZCS challenged the decision of the DPA before the Marktenhof (Market Court, Belgium). That court, by a judgment of 18 November 2020, held, in so far as is relevant here, that the decision of the DPA was not sufficiently well reasoned in relation to the exemption under Article 221(2) of the DPL. It ordered the DPA to reconsider its decision and provide reasons with regard to the administrative fine.
18. On 15 March 2021, acting on the judgment of the Marktenhof (Market Court), the DPA decided to impose an administrative fine, reasoning that an establishment that provides subsidised independent education, while it is a public authority within the meaning of Article 5(2) of the DPL, is not so for the purposes of Article 83(7) of the GDPR. On that second occasion, the amount of the administrative fine was EUR 1 000.
19. A new challenge was brought before the Marktenhof (Market Court), which, by a judgment of 6 October 2021, ruled that the DPA could not impose an administrative fine on the OZCS and, consequently, annulled the contested decision.
20. The DPA brought an appeal on a point of law before the Hof van Cassatie (Court of Cassation, Belgium), which, by a judgment of 9 January 2023, set aside the judgment of 6 October 2021 and sent the case back to the Marktenhof (Market Court).
21. By a judgment of 27 February 2024, the Marktenhof (Market Court) upheld the challenge brought by the OZCS and annulled the decision of the DPA, holding that it could not impose any administrative fine.
22. The DPA brought an appeal on a point of law against the judgment of 27 February 2024 before the Hof van Cassatie (Court of Cassation), which has referred the following question to the Court of Justice for a preliminary ruling:
‘Does Article 83(7) of [the GDPR], in conjunction with recitals 38 and 58 and Article 6(1)(f), Article 8 and Article 57(1)(b) thereof, preclude national legislation under which the supervisory authority cannot impose administrative fines on legal persons constituted under private law which provide subsidised independent education?’
III. Procedure before the Court of Justice
23. The request for a preliminary ruling was received at the Court on 11 July 2025.
24. Written observations were submitted by OZCS, the DPA, the Belgian and Bulgarian Governments and the European Commission. All those parties, with the exception of the OZCS, appeared at the hearing held on 20 May 2026.
IV. Analysis
A. Preliminary observation
25. The referring court wishes to know whether a legal person governed by private law that provides subsidised independent education is a public authority for the purposes of Article 83(7) of the GDPR, in view of the specific protection for children provided for in the legislation on personal data. (5)
26. That final element of the question referred links the concept of ‘public authorities’ with the nature of the individuals (in this case, children) whose data may have been unlawfully processed. Hence the referring court has connected Article 83(7) of the GDPR with the recitals (6) or provisions of that regulation that concern children.
27. Like the Commission, (7) I think that connection is unnecessary in order to respond to the request for a preliminary ruling. The concept of ‘public authorities and bodies’ does not depend on the legal interest harmed in each case. ‘Public authorities and bodies’ are such by reason of their nature and their intrinsic conditions; not on the basis of the unlawful conduct for which they may be responsible, nor on the basis of the persons whose rights or interests they have harmed. That concept has only one meaning and not as many as might arise from the field and the circumstances in which the activity of authorities and bodies fitting its definition takes place.
28. In what follows, therefore, I shall confine myself to the interpretation of Article 83(7) of the GDPR, without giving particular consideration to the rules on the protection of children, to which I shall only refer in the final part of this Opinion.
29. In doing that interpretative work, I shall pay particular attention to the fact that the GDPR aims to ensure a high level of protection of (all) natural persons within the European Union, by means of a variety of instruments, which include sanctions. The GDPR establishes a legal framework which implements the requirements arising from the right, protected by Article 8 of the Charter of Fundamental Rights of the European Union, to the protection of personal data. (8)
30. That having been established, the first question to be addressed is where the concept at issue is to be found in national law or in EU law.
B. ‘Public authorities and bodies’ as an autonomous concept of EU law
31. Neither Article 83(7) of the GDPR, nor any other provision of that regulation, defines the concept of ‘public authorities and bodies’. As a result of that silence:
– According to the OZCS and the Belgian Government, it is for the Member States to define such concepts. (9)
– Conversely, according to the DPA and the Commission, in the absence of an express reference to national law, the consistent and homogeneous application of EU law requires such concepts to be interpreted uniformly, as is appropriate to an autonomous concept of EU law.
32. The arguments for the phrase ‘public authorities and bodies’ being autonomous in nature are, in my opinion, more convincing.
33. First, Article 83(7) of the GDPR does not refer to national law in order to define those concepts. (10) According to settled case-law of the Court of Justice, from the necessity of ensuring both uniform application of EU law and also the principle of equality it follows that the terms of a provision of EU law which makes no express reference to the law of the Member States for the purpose of determining its meaning and scope must be given an autonomous and uniform interpretation throughout the European Union.
34. Second, Article 83(7) of the GDPR only refers to the national ‘rules’ with regard to the possibility of determining whether and to what extent administrative fines may be imposed on public authorities and bodies. As the DPA explains, the margin of discretion which that provision confers on the Member States is limited solely to their power to exempt such authorities and bodies from such fines (in full or in part), and does not include the power to determine which authorities are concerned.
35. Third, prior to the adoption of the GDPR, sanctions for the infringement of rules relating to data protection were, to a great extent, left to the discretion of the Member States. (11) In adopting the GDPR, the EU legislature opted to change that situation, such that the supervisory authorities would impose equivalent sanctions (12) for infringements of that regulation.
36. Fourth, the concept of ‘public authority’ appears in a considerable number of provisions of the GDPR, (13) which suggests that the EU legislature did not wish to entrust the Member States with the definition of a category that is of such importance in the system of the GDPR.
37. Fifth, other key concepts in the GDPR which, like that examined here, do not refer to national law for their definition have been held by the Court of Justice to be conceptually autonomous. For example, with regard to damage for which the infringing party may be required to pay compensation. (14)
38. Finally, the GDPR aims ‘to ensure consistent and homogeneous application of the rules for the protection of the fundamental rights and freedoms of those [natural] persons with regard to the processing of personal data throughout the European Union.’ (15)
39. In particular, as the DPA has emphasised, (16) the EU legislature wished ‘to strengthen and harmonise administrative penalties for infringements of this Regulation’. (17) To that end, it has designed a system of sanctions that is without precedent in most other areas of EU law.
40. That harmonising design would be neither consistent nor uniform if it conferred on the Member States absolute freedom to determine the scope of the concept of ‘public authority’ contained in Article 83(7) of the GDPR and, consequently, to exempt, at their discretion and by means of legislation merely intended to achieve that end, certain entities from administrative fines applicable under the GDPR. It would be sufficient to designate as public authorities entities whose characteristics were not, in fact, consistent with the aim of the exemption at issue.
41. I recall that, according to the Court of Justice, from a combined reading of Articles 83 and 84 of the GDPR, it follows that the Member States lack the power to determine the substantive conditions for imposing administrative fines, such conditions being governed solely by EU law. (18)
42. The problem arising here is similar, mutatis mutandis, to that faced by the Court of Justice when deciding whether the concept of ‘judicial authority’, contained in Article 6(1) of Framework Decision 2002/584/JHA, (19) was an autonomous concept or whether its meaning and scope were left to the assessment of each Member State. Unequivocally, the Court held that that concept required an autonomous and uniform interpretation throughout the European Union. (20)
43. To sum up, in my view, the notion of ‘public authorities and bodies’ contained in Article 83(7) of the GDPR constitutes an autonomous concept of EU law, which it is not for the national law of the Member States to define.
C. Concept of ‘public authorities and bodies’
1. Literal criterion
44. The interpretation, from a literal point of view, of the phrase at issue points to the combination of the noun ‘authority’ (or body) and the adjective ‘public’ describing a group of entities that are characterised, at first glance, by exercising sovereign powers; that is to say, special powers in relation to those resulting from the rules applicable to relations between individuals.
45. A public authority or a public body may intervene in the life of the economy without exercising the powers conferred on it by its privileged status (that is, acting as just another agent, under the same conditions as the rest, subject to private law). However, what, strictly speaking, characterises the exercise of public authority is, at the organisational and functional levels, its status and its prerogatives or special powers, governed by public law.
46. The classification of an entity as a public authority is, then, linked to the performance of activities carried out in accordance with legal rules that are characteristic of an institution of the State (in the broad sense), leaving aside those which it carries out under the same legal conditions as private economic operators.
47. The usefulness of the textual interpretation criterion is, however, limited in this case. In fact, depending on the field of EU law applying it, the same or a similar expression has been used with differing meanings, to which I shall refer next.
2. Systematic criterion
48. EU law contains a relative abundance of definitions of the concepts ‘authority’, ‘public authority’, ‘public body’ and other equivalent concepts. The Court of Justice, for its part, has been required to interpret those concepts in different contexts.
49. Those definitions have been arrived at taking account of the characteristics of the provisions in which they are found and the objectives pursued by those provisions. For that reason, between the different areas of the [EU legal] order, there are disparities – which are at times notable – as regards how broad or narrow they may be.
50. The reason for such marked divergence in the descriptions of the same formal category resides in the fact that, in order to interpret an autonomous concept of EU law, particular account must be taken of the context in which it used and the objectives pursued by the rules of which it is part. (21)
51. By way of example, I shall subsequently refer to some of those areas. First, however, I shall give a combined reading of Article 83(7) of the GDPR and other provisions and recitals of that regulation that refer to the concepts at issue.
52. The EU legislature does not equate the concept of ‘public authorities’ with that of ‘private bodies acting in the public interest’. (22) The preamble to the GDPR (23) refers to ‘the performance of a task carried out in the public interest or in the exercise of official authority’, from which I deduce that tasks in the public interest are not to be confused with the exercise of official authority.
53. The final sentence of recital 45 of the GDPR, read together with Article 79(2) of that regulation, (24) implies that tasks in the public interest are those which may be entrusted to natural or legal persons governed ‘by private law, such as a professional association’, while tasks falling within the exercise of public authority or prerogatives of powers conferred by public law may only be carried out by a ‘public authority or another natural or legal person governed by public law’.
54. In the same vein, recital 31 of the GDPR offers examples of ‘public authorities’, namely, tax and customs authorities, financial market authorities or financial investigation units and administrative authorities, which, strictly speaking, exercise sovereign powers.
55. From those elements, I deduce that the concept of ‘public authorities and bodies’ contained in Article 83(7) of the GDPR refers solely to authorities or bodies governed by public law and entrusted with carrying out tasks which fall within the exercise of public authority or prerogatives of powers conferred by public law.
56. The fact that an entity governed by private law carries out a task in the general or public interest is not sufficient to classify it as a ‘public authority or body’ within the meaning of Article 83(7) of the GDPR. A contrary interpretation would permit the Member States to expand the scope of the exception excessively and would create significant disparities between the Member States.
57. Having established the foregoing, I shall review how the concepts at issue here are used in other pieces of EU legislation.
(a) Public procurement
58. In the area of public contracts subject to Directive 2014/24/EU (25) (and, previously, to Directive 2004/18/EC), (26) a broad definition of the concepts ‘contracting authorities’ and ‘bodies governed by public law’ applies.
59. In relation to Article 1(9) of Directive 2004/18, the Court of Justice defined its scope in a sufficiently elastic manner so as to ensure that ‘the rules on, in particular, transparency and non-discrimination which are required in connection with the award of public contracts apply to all State entities which do not form part of the public administration but which are nevertheless controlled by the State, in particular by means of their financing or their management. (27)
60. In the case of a contracting authority, the Court of Justice applies a broad concept of public authority or body, to the point of according that status to entities established in the form of an association governed by private law which carry out activities that are not necessarily public in nature. (28)
(b) VAT
61. According to Article 13(1) of Directive 2006/112/EC, (29) ‘other bodies governed by public law shall not be regarded as taxable persons [for VAT] in respect of the activities or transactions in which they engage as public authorities, even where they collect dues, fees, contributions or payments in connection with those activities or transactions.’ (30)
62. The Court of Justice has held that the general rule on which the common system of VAT is based is that the scope of that tax is defined very broadly as covering all supplies of services for consideration, including those provided by bodies governed by public law. (31) Exceptions to that rule are to be interpreted strictly. (32)
63. The case-law makes use of a very restricted concept for the purposes of regarding public bodies as not being taxable persons for VAT. It prohibits the application, in that field, of concepts that are accepted in the field of public procurement and it attaches qualified importance to the fact that the entity exercises powers conferred by public law. (33)
(c) Entities forming part of the State for the purposes of the application of directives (in general)
64. The Commission suggests that, in order to determine whether it is possible, in this dispute, to speak of a public authority or a public body, the Court of Justice should follow the case-law relating to the fact that directives do not have direct effect between private individuals. (34)
65. According to the Commission, it follows from that case-law that an entity forms part of the State: either (a) because it is a legal person governed by public law which forms part of the State in a broad sense; or (b) because it is subject to the authority or supervision of a public authority; or (c) because a public authority has entrusted it with carrying out a task in the public interest and has conferred special powers on it for that purpose. The final two scenarios could, according to the Commission, be applied to the original dispute.
66. In my opinion, that suggestion, debated by the parties during the hearing, should not be viewed as an invitation to transfer the case-law referred to by the Commission mechanically and without nuance. Developed in a very specific context (the effect of directives) in order to give a ruling on a question different from that arising here, I doubt its usefulness for this dispute.
67. The case-law on the direct effect of directives responds to the need to make up for the failure on the part of the Member States to comply with their obligation to adopt the implementing measures required by those directives. In certain circumstances and under certain conditions, the common rules on the application and effect of one of the sources of EU law are modified for that purpose. That case-law adopts a criterion based on the functional integration into the structure of the State of entities against which private individuals may enforce the provisions of a directive directly.
68. In addition to entities whose status as a public authority is well known, the case-law attributes that status to bodies, whatever their legal form, which have been made responsible, pursuant to a measure adopted by the State, for providing a public service under the control of the State and have for that purpose special powers beyond those which result from the normal rules applicable in relations between individuals. (35)
69. It is, then, a question of entities which act, functionally, as organs of official authority, carrying out tasks in the general interest under the protection of the State and making use of powers inherent in sovereign power; entities which, to some extent, are the State which has failed to comply with its obligation to adopt the measures required by a directive, the effect of which has been compromised.
70. The whole of that complex body of argument has little to do with the rule contained in Article 83(7) of the GDPR, authorising the Member States to introduce an exception, qualitatively limited in scope, to the sanctions regime. Such an exception is not comparable to one which – emanating from the case-law of the Court of Justice – affects the rules concerning the effect of one of the sources of EU law (directives). The exception appears in the GDPR as just one more of the elements which define the system of sanctions protecting personal data. The concept of ‘public authorities and bodies’ cannot, then, be held up as being comparable to those used to define the effect of directives.
71. In short, different contexts and purposes result in concepts with different content.
72. At any rate, if it were necessary to give precedence to the systematic criterion, in my view, the concept of ‘public authorities and bodies’, contained in Article 83(7) of the GDPR, should be interpreted in a restrictive manner; closer, therefore, to the interpretation that is common in Directive 2006/112.
73. Indeed, Article 83(7) of the GDPR must be interpreted strictly, as it introduces an (optional) exception to the general harmonised sanctions regime provided for by the GDPR. (36)
3. Contextual and teleological criterion
74. The concept of ‘public authorities and bodies’ must be defined according to the context and purpose of the provision of which it forms part.
75. With regard to the context, the provision, as I have explained, is included in the system for the application of administrative fines to infringements of the GDPR. The exception at issue prevents the action of a penalty instrument characterised by its dissuasive effect, by creating an exemption from administrative fines which constitute ‘a key element in ensuring respect for the rights of those [natural] persons, in accordance with the purpose of [the GDPR] of ensuring a high level of protection of such persons with regard to the processing of personal data.’ (37)
76. Certainly, together with administrative fines, there are other, alternative, measures which help to ensure the effective enforcement of the GDPR. (38) However, the scale of the administrative fines provided for in Article 83(4) to (6) of the GDPR reveals the determination of the legislature to establish a robust system to ensure the effectiveness of its provisions. The dissuasive effect of administrative fines which can be for remarkably large amounts has thus become a key element of the system of sanctions.
77. Moreover, administrative fines have been expressly harmonised. Article 84(1) of the GDPR, on the other hand, permits the Member States to determine ‘the rules on other penalties applicable to infringements of this Regulation in particular for infringements which are not subject to administrative fines pursuant to Article 83’.
78. The genesis of Article 83(7) of the GDPR reveals the connection between the economic significance of the administrative fines established in that regulation and the exception at issue.
79. The Commission’s initial proposal included maximum limits on the administrative fines of between EUR 250 000 and EUR 1 000 000 and up to 2% of annual turnover. (39) At the suggestion of the Council, (40) those limits were increased to those of the current Article 83(4) to (6) of the GDPR, with the possibility of the Member States agreeing on the exception that would end up being Article 83(7) then being included. (41)
80. As the DPA maintains, the exception contained in Article 83(7) of the GDPR could be seen as a safeguard favouring the protection of the public finances. If that were so, as the DPA also recalls in relation to restrictions on the fundamental freedoms guaranteed by the FEU Treaty, objectives of a purely economic nature cannot constitute overriding reasons of public interest capable of justifying such restrictions.
81. The OZCS relies on a justification in addition to the protection of the public finances: continuity in carrying out a task in the general interest, which the Belgian Constitutional Court has emphasised in examining Article 221(2) of the DPL. (42)
82. It is possible that, in certain cases, the imposition of administrative fines on public authorities entrusted with a task in the general interest could jeopardise the carrying out of that task and, consequently, affect its continuity, if the financial burden implied by the fines is considerable.
83. However, it would be necessary to consider whether, given those safeguarding functions – in relation to the public finances and continuity in carrying out tasks in the general interest – it is justified to expand the concept of ‘public authorities and bodies’ to the point where it includes legal persons governed by private law that provide subsidised independent education.
84. In my opinion, in order to achieve those two objectives, it is not essential to sacrifice the power to impose penalties conferred on authorities responsible for data protection, where:
– the characteristics of the infringing entity are difficult to distinguish from those of other legal persons carrying on substantively the same activity (secondary education), without the latter being regarded as public authorities;
– the infringing entity is not integrated into State structures and does not satisfy the requirements necessary to fit the definition of official authority (exercise of special powers equating to the prerogatives of powers conferred by public law);
– it is possible to ensure that any resources of that entity that come from public funds are protected, as well as the continuity of its general interest functions, by varying the amount of the administrative fines according to the circumstances.
4. Impact of the judgment in Escuelas Pías (43)
85. In support of its position, the OZCS argues that education is a task in the general interest which, in Belgium, is also carried out by entities governed by private law that are subsidised by the public authorities. It maintains that it is a non-economic activity, as the Court of Justice has already held. (44)
86. In the judgment in Escuelas Pías, it was a question of clarifying whether certain exemptions from national taxes fell within the scope of the prohibition established in Article 107(1) TFEU (State aid). That dispute allowed the Court of Justice to examine up to what point the concepts of ‘undertaking’ and ‘economic activity’ were present in the courses provided by educational establishments, depending on whether they were financed essentially by private funds or with State subsidies.
87. In the judgment in Escuelas Pías, the following was held:
– In establishing and maintaining a system of public education, which is, as a general rule, financed from public funds and not by pupils or their parents, the State is not seeking to engage in gainful activity, but is fulfilling its social, cultural and educational obligations towards its population. (45)
– In that context, it is possible that a single establishment may carry on a number of activities, both economic and non-economic, provided that it keeps separate accounts for the different funds that it receives so as to exclude any risk of cross-subsidisation of its economic activities by means of public funds received for its non-economic activities. (46)
– To ascertain whether the prohibition in Article 107(1) TFEU was applicable to the exemption then at issue, ‘the referring court will have to determine … which, if any, of the … educational activities are economic in nature.’ (47)
88. From those declarations and the others made in the judgment in Escuelas Pías, it does not, however, follow that an independent educational establishment may be regarded as a public authority merely because it receives State funding.
5. Application of those criteria to the original case
89. It is for the referring court, in light of the information available to it, to assess the factual situation and, where relevant, to determine whether or not the State financing of the educational establishment conditions its actions to the point of integrating it into structures of the State that could be categorised as public authorities.
90. That notwithstanding, I do not believe that the OZCS has the inherent characteristics of a public authority. It is not a legal person that forms part of the State in the broad sense, nor has it been invested with special powers that fall within the scope of the exercise of public authority or prerogatives of powers conferred by public law. (48)
91. In my opinion, it is precisely the exercise of prerogatives of powers conferred by public law – or the absence of such exercise – that makes it possible to determine whether an entity falls within the concept of ‘public authorities and bodies’, within the meaning of Article 83(7) of the GDPR, or whether, conversely, it is in a situation comparable to that of entities limited to carrying out general interest functions or operating in a market.
92. The fact that the OZCS is subject to the supervision of the Flemish authority as regards compliance with minimum learning objectives does not place it in a position very different from that of other, non-subsidised, private educational establishments.
93. The ability to issue educational certificates does not, in itself, prove that the OZCS enjoys prerogatives of powers conferred by public law. At the hearing, the DPA observed that, in Belgian law, that power also exists for similar private establishments that do not receive any public subsidy, without them being regarded as public authorities on that account.
94. While it is for the referring court to make such findings, everything appears to point to the fact that, in Belgium, the power to issue certificates is an indication that the educational establishment carries out a task in the general (or public) interest, in the context of the general regulation of education. But that factor is not, in itself, sufficient to conclude that it exercises prerogatives of powers conferred by public law.
95. In that regard, I recall that the Court of Justice has held that holding a teaching position does not involve direct or indirect participation in the exercise of powers conferred by public law or duties designed to safeguard the general interests of the State or of other public authorities. (49) That declaration is specifically extended to the field of secondary education. (50)
96. In my opinion, nor is it justified to stretch the definition of the concept of ‘public authorities and bodies’ to the point of including in it an entity whose principal connection with official authority consists, in reality, in receiving subsidies from the State.
97. As the Commission acknowledged during the hearing, merely receiving a subsidy is not sufficient for the subsidised entity to be regarded as a ‘public authority’. In any event, it has not been possible to determine what percentage of the funding of the OZCS public subsidies represent. (51) And, moreover, the Belgian Government acknowledges that that educational establishment has sources of private financing (inter alia, fees paid by the parents of the pupils, donations and sales of assets) which prove that it carries on an economic activity, for which the OZCS is even able to make use of advertising.
98. If, as I have already mentioned, the objective pursued by the exception in Article 83(7) of the GDPR is to ensure continuity in the carrying out of tasks in the general interest, that end could be achieved, in the case of an entity such as the OZCS, by means of Article 83(2) of the GDPR.
99. In accordance with the GDPR, ‘administrative fines shall [be imposed], depending on the circumstances of each individual case … When deciding whether to impose an administrative fine and deciding on the amount of the administrative fine in each individual case due regard shall be given to … any other aggravating or mitigating factor applicable to the circumstances of the case …’ (Article 83(2)(k) of the GDPR).
100. In fact, the effect of Article 83(2) of the GDPR has been sufficient to ensure that, given the non-profit nature of OZCS and the fact that it carries on an activity in the general interest, the fine finally imposed on it – EUR 1 000 – far from jeopardises its continuance as an educational establishment.
101. Conversely, designating the OZCS as a public authority would ensure that outcome (continuity in the carrying out of its task in the general interest) in a disproportionate manner: faced with an infringement of the GDPR to the detriment of the rights of the pupils, the Belgian data protection authorities could not, under any circumstances, make use of the most effective safeguarding mechanism available to them, namely, the imposition of an administrative fine. Their corrective power would thus be limited, in accordance with Article 58(2) of the GDPR, to issuing a mere warning or a reprimand.
102. An interpretation such as that favoured by the OZCS and the Belgian Government would mean that all entities governed by private law which carry out a task in the general interest and benefit from public subsidies could potentially take advantage of the optional exception provided for in Article 83(7) of the GDPR. However, by their very nature, tasks in the general interest (in particular, in the fields of health, education and social action) frequently involve the processing of sensitive data relating to natural persons or personal data relating to vulnerable individuals or individuals who merit ‘specific protection’, as in the case of children.
103. In that context, supervisory authorities should not, categorically, be deprived of the ability to impose administrative fines on an entity governed by private law, simply because that entity carries out teaching tasks in the general interest and receives public subsidies. Such an interpretation would substantially reduce the ability of supervisory authorities to ensure compliance with the GDPR and the protection of natural persons.
V. Conclusion
104. In the light of the foregoing considerations, I propose replying to the Hof van Cassatie (Court of Cassation, Belgium) as follows:
Article 83(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
must be interpreted as meaning that it precludes national legislation under which the supervisory authority cannot impose administrative fines on legal persons constituted under private law which provide independent education and, for that purpose, receive subsidies from public funds.
1 Original language: Spanish.
2 Gegevensbeschermingsautoriteit (Data Protection Authority; ‘the DPA’).
3 Regulation of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ 2016 L 119, p. 1) (‘the GDPR’).
4 Wet van 30 juli 2018 betreffende de bescherming van natuurlijke personen met betrekking tot de verwerking van persoonsgegevens (Law of 30 July 2018 on the protection of natural persons with regard to the processing of personal data) (Belgisch Staatsblad, 5 September 2018, p. 68616) (‘the DPL’).
5 Order for reference, section IV, point 5.
6 The question referred mentions recitals 38 and 58 of the GDPR, which deal with the protection of children.
7 Written observations of the Commission, paragraphs 24 to 26.
8 Judgment of 12 January 2023, Österreichische Post (Information regarding the recipients of personal data) (C‑154/21, EU:C:2023:3, paragraph 44).
9 In that regard, the OZCS relies on the Guidelines on Data Protection Officers adopted by the Article 29 Working Party established by Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data (OJ 1995 L 281, p. 31), adopted on 13 December 2016 and revised on 5 April 2017 (16/EN, WP 243 rev.01). Those guidelines state that the concept at issue ‘is to be determined under national law’ (section 2.1.1).
10 In the context of Article 86 of the GDPR, on the processing of and public access to official documents, recital 154 of that regulation states that ‘reference to public authorities and bodies should … include all authorities or other bodies covered by Member State law on public access to documents.’ In my opinion, that reference is strictly limited to Article 86 of the GDPR.
11 Article 24 of Directive 95/46.
12 Recitals 11 and 129 of the GDPR.
13 The DPA lists more than a dozen provisions in footnote 20 of its written observations; for instance, Article 6(1), second subparagraph, excludes the application to public authorities of one of the conditions relating to lawfulness of processing; Article 37(3) permits a single data protection officer to be designated where the controller or the processor is a public authority or body; Article 86 regulates access to personal data in official documents held by a public authority.
14 Judgment of 4 May 2023, Österreichische Post (Non-material damage in connection with the processing of personal data) (C‑300/21, EU:C:2023:370, paragraph 44): ‘the concept of “damage” and, specifically in the present case, the concept of “non-material damage”, within the meaning of Article 82 of the GDPR, must be given an autonomous and uniform definition specific to EU law, in the absence of any reference to the domestic law of the Member States.’ In a similar vein, the judgment of 22 June 2021, Latvijas Republikas Saeima (Penalty points) (C‑439/19, EU:C:2021:504, paragraphs 82 to 85), held the concept of ‘criminal offence’ to be autonomous in nature, in order to determine the applicability of Article 10 of the GDPR.
15 Judgment of 5 December 2023, Deutsche Wohnen (C‑807/21, EU:C:2023:950, paragraph 50). Emphasis added.
16 Paragraph 23 of the DPA’s written observations.
17 Recital 150 of the GDPR.
18 Judgment of 5 December 2023, Nacionalinis visuomenės sveikatos centras (C‑683/21, EU:C:2023:949, paragraph 70). It is true that, in this reference for a preliminary ruling, the debate centres on the substantive conditions in the strict sense, but the fundamental view regarding the autonomous nature of the concepts at issue seems to be equally applicable.
19 Council Framework Decision of 13 June 2002 on the European arrest warrant and the surrender procedures between Member States (OJ 2002 L 190, p. 1), as amended by Council Framework Decision 2009/299/JHA of 26 February 2009 (OJ 2009 L 81, p. 24).
20 Judgment of 10 November 2016, Poltorak (C‑452/16 PPU, EU:C:2016:858, paragraph 32).
21 Judgment of 11 September 2025, Österreichische Zahnärztekammer (C‑115/24, EU:C:2025:694, paragraph 62 and the case-law cited).
22 Recitals 122 and 128 of the GDPR.
23 Recitals 10 and 45 of the GDPR.
24 The latter provision refers to ‘a public authority … acting in the exercise of its public powers’.
25 Directive of the European Parliament and of the Council of 26 February 2014 on public procurement and repealing Directive 2004/18/EC (OJ 2014 L 94, p. 65). According to point 1 of Article 2(1) of that directive, contracting authorities are the State, regional or local authorities, bodies governed by public law or associations formed by one or more such authorities or one or more such bodies governed by public law. Public bodies, meanwhile, are defined as ‘bodies that have all the following characteristics: (a) they are established for the specific purpose of meeting needs in the general interest, not having an industrial or commercial character; (b) they have legal personality; and (c) they are financed, for the most part, by the State, regional or local authorities, or by other bodies governed by public law; or are subject to management supervision by those authorities or bodies; or have an administrative, managerial or supervisory board, more than half of whose members are appointed by the State, regional or local authorities, or by other bodies governed by public law’.
26 Directive of the European Parliament and of the Council of 31 March 2004 on the coordination of procedures for the award of public works contracts, public supply contracts and public service contracts (OJ 2004 L 134, p. 114). Article 1(9) of that directive provided that ‘“contracting authorities” means the State, regional or local authorities, bodies governed by public law, associations formed by one or several of such authorities or one or several of such bodies governed by public law.’
27 Judgment of 29 October 2015, Saudaçor (C‑174/14, ‘the judgment in Saudaçor’, EU:C:2015:733, paragraph 46).
28 Judgment of 3 February 2021, FIGC and Consorzio Ge.Se.Av. (C‑155/19 and C‑156/19, EU:C:2021:88, paragraph 48).
29 Council Directive of 28 November 2006 on the common system of value added tax (OJ 2006 L 347, p. 1).
30 Except where their treatment as non-taxable persons would lead to significant distortions of competition.
31 The judgment in Saudaçor, paragraph 48.
32 The judgment in Saudaçor, paragraph 49.
33 The judgment in Saudaçor, paragraphs 46 to 48, 69 and 70.
34 Paragraph 31 of the Commission’s written observations.
35 Judgment of 12 July 1990, Foster and Others (C‑188/89, EU:C:1990:313, paragraph 20).
36 See, by analogy, the judgment in Saudaçor (C‑174/14, EU:C:2015:733, paragraphs 47 and 48). The exceptions inserted into the GDPR have been interpreted strictly in the judgments of 9 July 2020, Land Hessen (C‑272/19, EU:C:2020:535, paragraph 68), and of 9 January 2025, Österreichische Datenschutzbehörde (Excessive requests) (C‑416/23, EU:C:2025:3, paragraph 33).
37 Judgment of 5 December 2023, Deutsche Wohnen (C‑807/21, EU:C:2023:950, paragraph 73).
38 Judgment of 4 May 2023, Bundesrepublik Deutschland (Court electronic mailbox) (C‑60/22, EU:C:2023:373, paragraphs 67 and 68).
39 Article 79 of the Proposal for a Regulation of the European Parliament and of the Council on the protection of individuals with regard to the processing of personal data and on the free movement of such [(GDPR)], COM(2012) 011 final – 2012/0011 (COD) C7-0025/12.
40 Position of the Council at first reading with a view to the adoption of a Regulation of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC [(GDPR)], of 8 April 2016, 5419/1/16 REV 1 ADD 1, section 9.5.
41 From EUR 10 million to EUR 20 million and up to 4% of annual turnover.
42 Paragraph 13 of the written observations of the OZCS. It refers to judgment of the Belgian Constitutional Court No 3/2021 of 14 January 2021. Paragraph B.27 of that judgment reads: ‘It is evident from the preparatory work for the contested provision that not imposing administrative fines on certain public sector data controllers was justified by the need to ensure the continuity of the public service and [the need] not to jeopardise the carrying out of a task in the general interest (Doc. parl., Chambre, 2017-2018, DOC 54-3126/001, pp. 229 and 230). Those objectives pursued by the legislature may, in themselves, be considered legitimate. Nevertheless, it is necessary to verify whether the measure is objective and reasonably justified, given the effects which it entails, in particular as regards the right to the protection of personal data.’
43 Judgment of 27 June 2017, Congregación de Escuelas Pías Provincia Betania (C‑74/16, ‘the judgment in Escuelas Pías’, EU:C:2017:496).
44 In that regard, in addition to the judgment in Escuelas Pías, it relies on the judgment of 11 September 2017, Commission v Germany (C‑318/05, EU:C:2007:495, paragraph 68).
45 The judgment in Escuelas Pías, paragraph 50.
46 The judgment in Escuelas Pías, paragraph 51.
47 The judgment in Escuelas Pías, paragraph 54.
48 Judgment of 10 October 2017, Farrell (C‑413/15, EU:C:2017:745, paragraph 34).
49 Judgment of 2 July 1996, Commission v Luxembourg (C‑473/93, EU:C:1996:263, paragraph 31 et seq.). Even though that and other subsequent judgments refer to the concept of public service within the meaning of the (current) Article 45(4) TFEU, its considerations relating to posts involving direct or indirect participation in the exercise of powers conferred by public law or duties designed to safeguard the general interests of the State or of other public authorities are applicable to the concepts at issue here.
50 Judgment of 27 November 1991, Bleis (C‑4/91, EU:C:1991:448, paragraph 7).
51 At the hearing, without being more precise, a figure of ‘more than 50%’ was mentioned. The OZCS did not attend the hearing and was therefore not able to provide more specific figures.