{"id":50027,"date":"2025-12-17T11:24:32","date_gmt":"2025-12-17T10:24:32","guid":{"rendered":"https:\/\/www.eh.at\/?p=50027"},"modified":"2026-02-09T13:09:11","modified_gmt":"2026-02-09T12:09:11","slug":"cjeu-in-russmedia-digital-platform-operators-as-controllers-for-sensitive-user-data-the-end-of-the-provider-privilege-in-relation-to-personal-data-processing","status":"publish","type":"post","link":"https:\/\/www.eh.at\/en\/cjeu-in-russmedia-digital-platform-operators-as-controllers-for-sensitive-user-data-the-end-of-the-provider-privilege-in-relation-to-personal-data-processing\/","title":{"rendered":"CJEU in Russmedia Digital: platform operators as controllers for (sensitive) user data \u2013 the end of the provider privilege in relation to personal data processing"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"50027\" class=\"elementor elementor-50027\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-f1e1a9c elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"f1e1a9c\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-503ff83\" data-id=\"503ff83\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-5e78dbf elementor-widget elementor-widget-text-editor\" data-id=\"5e78dbf\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>17.12.2025<br \/>by <i><a href=\"https:\/\/www.eh.at\/en\/team\/gernot-fritz\/\">Gernot Fritz<\/a>, <a href=\"https:\/\/www.eh.at\/en\/team\/tanja-pfleger\/\">Tanja Pfleger<\/a><\/i><\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4313049 elementor-widget elementor-widget-text-editor\" data-id=\"4313049\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>On 2 December 2025, the Court of Justice of the European Union delivered a judgment that will reverberate far beyond the facts of the case at hand. In <em>Russmedia Digital and Inform Media Press<\/em> (<a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/HTML\/?uri=CELEX:62023CJ0492\" target=\"_blank\" rel=\"noopener\">C-492\/23<\/a>), the Court fundamentally recalibrated the role of online platforms under EU data protection law. The message is clear and uncompromising: where online marketplaces process personal data contained in user advertisements, they cannot shield themselves behind the traditional hosting privilege. The GDPR applies in full, and it applies first.<\/p><p>The decision is not limited to classical classified advertisement portals. Its reasoning potentially affects any platform that enables user-generated content containing personal data and monetises the dissemination of that content. In that sense, <em>Russmedia Digital<\/em> marks a decisive step away from the long-standing notion of the \u201cneutral intermediary\u201d.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e410fbf elementor-widget elementor-widget-heading\" data-id=\"e410fbf\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">A fake advertisement with very real consequences<\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4d100dd elementor-widget elementor-widget-text-editor\" data-id=\"4d100dd\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>The case arose from an advertisement published on the Romanian classified ads platform <em>publi24.ro<\/em>. The advertisement falsely portrayed a woman, using her real photographs and telephone number, as offering sexual services. The content was published without her knowledge and without any form of consent. Shortly after publication, the advertisement was copied verbatim and republished on other websites, each referencing the original source.<\/p><p>Russmedia Digital removed the advertisement from its platform less than one hour after receiving a complaint. At that point, however, the damage had already been done: the content continued to circulate on other sites beyond the control of the original platform. The affected individual brought an action for damages, claiming non-material harm resulting from the unlawful processing of her personal data and the violation of her rights to privacy, honour, reputation and personal portrayal.<\/p><p>Against this background, the referring Romanian court essentially asked whether the platform operator could rely on the liability exemptions of the E-Commerce Directive (now mirrored in the Digital Services Act), or whether the GDPR independently imposed responsibility and liability for the processing of the personal data contained in the advertisement.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-0d63454 elementor-widget elementor-widget-heading\" data-id=\"0d63454\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">The questions referred: GDPR responsibility versus provider privilege<\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-faacaf7 elementor-widget elementor-widget-text-editor\" data-id=\"faacaf7\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>The questions referred to the Court sought clarification on two closely connected points. First, whether the operator of an online marketplace that allows users to post advertisements (anonymously and either free of charge or for remuneration) fails to comply with its obligations under the GDPR where an advertisement contains personal data, including sensitive personal data, in breach of that regulation. Second, whether the liability exemptions for intermediary service providers under Articles 12 to 15 of the E-Commerce Directive are applicable in such a situation.<\/p><p>In essence, the Court was asked to decide whether data protection responsibility can be displaced by sector-specific privileges for intermediaries (such as platform providers). The Court\u2019s answer leaves little room for doubt.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-66b29d2 elementor-widget elementor-widget-heading\" data-id=\"66b29d2\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Platform operators as (joint) controllers under the GDPR<\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-de91748 elementor-widget elementor-widget-text-editor\" data-id=\"de91748\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>The CJEU qualifies the operator of an online marketplace such as Russmedia Digital as a (joint) controller within the meaning of the GDPR, notwithstanding the fact that the concrete content of the advertisement originates from a user. The decisive criterion is not authorship of the content, but influence over the purposes and means of processing.<\/p><p>Russmedia Digital did not merely provide technical storage \u201cfor\u201d advertisers. According to its general terms and conditions, the platform reserved extensive rights to use the published content (including the personal data contained therein) for its own commercial purposes. These rights covered dissemination, transmission, reproduction, modification, translation, transfer to partners and removal of content at any time, without the need to justify such actions. In doing so, the platform pursued its own economic interests linked to the circulation of the data.<\/p><p>Beyond this contractual framework, the platform shaped the processing in multiple ways. It defined categories and headings for advertisements, determined presentation, duration, visibility, ranking and target audience, and organised the overall structure through which the data were disseminated. It also enabled anonymous postings, thereby facilitating the publication of personal data without any built-in assurance that the advertiser was entitled to disclose them.<\/p><p>Taken together, these elements led the Court to conclude that the platform exercised decisive influence over the essential elements of the processing. It therefore participated in determining both purposes and means and could not escape responsibility by arguing that it did not itself determine the content of the advertisement. Such an argument, the Court emphasised, would be incompatible with the broad, functional and protection-oriented concept of \u201ccontroller\u201d enshrined in the GDPR.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-02f9ff7 elementor-widget elementor-widget-heading\" data-id=\"02f9ff7\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Why special categories of data are at the core of the decision<\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5db0290 elementor-widget elementor-widget-text-editor\" data-id=\"5db0290\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>A central pillar of the judgment concerns the application of Article 9 GDPR. The Court reiterates that data relating to a natural person\u2019s sex life or sexual orientation fall squarely within the special categories of personal data that benefit from enhanced protection. This concept must be interpreted broadly, in light of the particularly serious interference with fundamental rights that such processing may entail.<\/p><p>Crucially, the Court clarifies that the classification of data as sensitive does not depend on their truthfulness. Even false information alleging sexual behaviour or services retains its character as data concerning sex life. The fact that the content is untrue and harmful does not diminish, but rather reinforces, the need for heightened protection, given the severe impact such data can have on the affected person\u2019s rights and dignity.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-86f84bb elementor-widget elementor-widget-heading\" data-id=\"86f84bb\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Concrete obligations for platforms dealing with sensitive data<\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-0f35b5a elementor-widget elementor-widget-text-editor\" data-id=\"0f35b5a\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>Where sensitive data are concerned, the Court formulates concrete and proactive obligations for platform operators acting as controllers. Before publication, they must implement appropriate technical and organisational measures enabling them to identify advertisements that contain special categories of data, verify whether the advertiser is the person whose sensitive data appear in the content, and refuse publication where this is not the case unless the advertiser can demonstrate explicit consent or another applicable exception under Article 9(2) GDPR.<\/p><p>This shifts data protection firmly into the design phase of platform services. For sensitive data, \u201cdata protection by design\u201d is no longer a general aspiration but a requirement to screen, assess and, where necessary, block content before it goes live.<\/p><p>From a practical perspective, this raises significant challenges. Proof of valid consent is inherently fragile: consent can be forged, must be freely revocable and must be withdrawn as easily as it is given. Platforms must therefore implement mechanisms ensuring that withdrawals reach them effectively and are acted upon without delay.<\/p><p>The judgment leaves open how to assess situations in which users upload their own sensitive data. The Court does not explicitly address whether such conduct constitutes \u201cexplicit consent\u201d or whether the data should be regarded as \u201cmanifestly made public\u201d within the meaning of Article 9(2)(e) GDPR. While there are arguments in favour of this interpretation, significant uncertainty remains as to whether and to what extent such a legal basis would also cover onward transfers and further dissemination to third parties. In light of purpose limitation and good faith processing, a narrow interpretation will often be the safer approach.<\/p><p>In addition, the Court requires platform operators to implement security measures aimed at preventing sensitive advertisements from being copied and unlawfully republished on other websites, taking into account the risks involved and the state of the art. While such copying can never be entirely prevented, the obligation is to make it meaningfully more difficult through appropriate safeguards.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-08b53b0 elementor-widget elementor-widget-heading\" data-id=\"08b53b0\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Implications for \u201cordinary\u201d personal data<\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-bf5a4b7 elementor-widget elementor-widget-text-editor\" data-id=\"bf5a4b7\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>Although the case revolves around sensitive data, its implications go further. The Court recalls that all personal data processed on online marketplaces are subject to the general principles of the GDPR. Processing must be lawful, fair and transparent, based on a valid legal basis, accurate, kept up to date and secured by appropriate technical and organisational measures.<\/p><p>The enhanced ex ante duties formulated by the Court (such as prior identification of problematic content and identity verification) are explicitly articulated only for special categories of data. However, this does not absolve platforms from assessing the legality of processing \u201cordinary\u201d personal data. Where users post information about themselves, implicit consent or self-initiated publication will often be available. The situation is far more delicate when data relate to third parties who have no relationship with the platform.<\/p><p>Here, reliance on legitimate interests frequently reaches its limits. The judgment in <em>Mousse \/ CNIL &amp; SNCF Connect<\/em> (<a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/HTML\/?uri=CELEX:62023CJ0394\" target=\"_blank\" rel=\"noopener\">C-394\/23<\/a>) underscores that legitimate interests can only serve as a legal basis if they are clearly and timely communicated to the data subject. For platform-external individuals, such transparency is often practically impossible. As a result, reliance on legitimate interests for third-party data will, in many cases, be difficult to defend robustly.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-47580fe elementor-widget elementor-widget-heading\" data-id=\"47580fe\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">GDPR versus E-Commerce Directive and DSA<\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6df23b2 elementor-widget elementor-widget-text-editor\" data-id=\"6df23b2\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>The Court unequivocally rejects the idea that the liability privilege of the E-Commerce Directive can displace GDPR responsibility. Questions of personal data processing are governed exclusively by the GDPR. The host provider privilege neither limits nor replaces data protection obligations and offers no shield against GDPR violations.<\/p><p>This reasoning carries over directly to the Digital Services Act. While the DSA limits content-related or civil liability for third-party content, it does not alter the classification of platform operators as controllers where they process personal data. The Court stresses that sector-specific (liability and content) privileges must not undermine the GDPR\u2019s protective framework. This approach aligns with the EDPB\u2019s understanding of the DSA as complementary to, and without prejudice to, data protection law.<\/p><p>In practice, this means that DSA privileges are layered on top of existing GDPR obligations; they do not dilute them.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-36e9603 elementor-widget elementor-widget-heading\" data-id=\"36e9603\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Practical significance and liability exposure<\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7618fc5 elementor-widget elementor-widget-text-editor\" data-id=\"7618fc5\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>The <em>Russmedia Digital<\/em> judgment is likely to trigger significant reassessment among platform operators. It requires a genuine paradigm shift. Platforms that allow sensitive personal data to be published must actively ensure their protection, even where content originates from users. In particular, operators must verify whether the person depicted or described is actually the advertiser or whether valid consent exists. Absent such verification, publication must be refused.<\/p><p>This will fundamentally alter platform workflows, moderation processes and technical architectures and may significantly reduce the volume of permissible content. At the same time, the liability stakes are high. Platforms that continue to rely on the fiction of neutrality risk not only reputational harm but also substantial administrative fines and civil damages claims.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-c70a690 elementor-widget elementor-widget-heading\" data-id=\"c70a690\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Conclusion<\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-9d7ae45 elementor-widget elementor-widget-text-editor\" data-id=\"9d7ae45\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>The <em>Russmedia Digital<\/em> judgment marks a turning point in EU data protection law for online platforms. It leaves no room for exceptions based on intermediary status and confirms that the provider privilege has no place in the GDPR context.<\/p><p>Those who set the framework for publication must also bear responsibility for its consequences. Allowing false and harmful content to circulate under the guise of technical neutrality is no longer acceptable under EU law. Platform operators will need to rethink their business models, technical systems and compliance strategies to meet this new reality.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>17.12.2025by Gernot Fritz, Tanja Pfleger On 2 December 2025, the Court of Justice of the European Union delivered a judgment that will reverberate far beyond the facts of the case at hand. In Russmedia Digital and Inform Media Press (C-492\/23), the Court fundamentally recalibrated the role of online platforms under EU data protection law. The [&hellip;]<\/p>\n","protected":false},"author":20,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"rank_math_lock_modified_date":false,"inline_featured_image":false,"footnotes":""},"categories":[235],"tags":[385,782,781],"group":[],"area":[],"location":[],"systype":[],"class_list":["post-50027","post","type-post","status-publish","format-standard","hentry","category-legal-update-en","tag-cjeu","tag-personal-data","tag-russmedia-digital"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.eh.at\/en\/wp-json\/wp\/v2\/posts\/50027"}],"collection":[{"href":"https:\/\/www.eh.at\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.eh.at\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.eh.at\/en\/wp-json\/wp\/v2\/users\/20"}],"replies":[{"embeddable":true,"href":"https:\/\/www.eh.at\/en\/wp-json\/wp\/v2\/comments?post=50027"}],"version-history":[{"count":17,"href":"https:\/\/www.eh.at\/en\/wp-json\/wp\/v2\/posts\/50027\/revisions"}],"predecessor-version":[{"id":50536,"href":"https:\/\/www.eh.at\/en\/wp-json\/wp\/v2\/posts\/50027\/revisions\/50536"}],"wp:attachment":[{"href":"https:\/\/www.eh.at\/en\/wp-json\/wp\/v2\/media?parent=50027"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.eh.at\/en\/wp-json\/wp\/v2\/categories?post=50027"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.eh.at\/en\/wp-json\/wp\/v2\/tags?post=50027"},{"taxonomy":"group","embeddable":true,"href":"https:\/\/www.eh.at\/en\/wp-json\/wp\/v2\/group?post=50027"},{"taxonomy":"area","embeddable":true,"href":"https:\/\/www.eh.at\/en\/wp-json\/wp\/v2\/area?post=50027"},{"taxonomy":"location","embeddable":true,"href":"https:\/\/www.eh.at\/en\/wp-json\/wp\/v2\/location?post=50027"},{"taxonomy":"systype","embeddable":true,"href":"https:\/\/www.eh.at\/en\/wp-json\/wp\/v2\/systype?post=50027"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}