An Advocate General at the Court of Justice of the European Union advised on 10 September 2026 that Belgium's national data protection law cannot stop the country's regulator from fining a privately run association that operates publicly subsidised schools, in a dispute that began with a pupil well-being survey and a father's complaint more than seven years ago.
In Short
A Belgian school sent pupils an online survey about how they were feeling without telling their parents first, and the country's privacy regulator fined the organisation that runs it. The organisation argued that Belgian law protects public bodies from such fines and that, because it receives government money, it counts as one - and one of the legal advisers at Europe's highest court has now said it does not. If the judges agree, privately run organisations doing public-interest work on public money, from schools to care providers, can still be fined when they mishandle your data.
Seven years over a pupil survey
The case, registered as C-458/25, Gegevensbeschermingsautoriteit v Onderwijsgroep Zusters der Christelijke Scholen Zuid-Kempen VZW, reached the Luxembourg court as a reference for a preliminary ruling from the Hof van Cassatie, Belgium's Court of Cassation. Advocate General Manuel Campos Sánchez-Bordona delivered the opinion, which was written in Spanish and published in English as a provisional text.
Its origins are modest. On 22 July 2019, the father of a pupil lodged a complaint with the Gegevensbeschermingsautoriteit, Belgium's Data Protection Authority, against a school belonging to the association, a non-profit body referred to throughout the proceedings as the OZCS. The school had distributed a survey on pupils' well-being through a digital platform. According to the opinion, the complaint listed four problems: parents had not been informed of the survey in advance, their consent had not been obtained, more data had been processed than was necessary, and no assessment of the impact of the processing on data protection had been carried out.
The regulator ruled on 16 June 2020. It found that the OZCS was the data controller and established four infringements of the GDPR: of Article 6(1), which sets out the lawful grounds for processing; of Article 8, on the conditions for a child's consent to information society services; of Article 5(1)(c), the data minimisation principle; and of Article 5(1)(a), read together with Articles 12(1) and 13, which govern transparency and the information owed to people whose data is collected. The missing impact assessment, raised in the complaint, does not appear among the four findings as the opinion records them. The authority ordered the processing brought into compliance and imposed an administrative fine of 2,000 euros.
What followed was a procedural relay between Brussels courts. The Marktenhof, the Market Court that hears appeals against the authority's decisions, held on 18 November 2020 that the decision was not sufficiently reasoned on the exemption contained in Article 221(2) of Belgium's data protection law, and ordered the regulator to reconsider. On 15 March 2021, the authority fined the OZCS again, this time 1,000 euros. Its reasoning, according to the opinion, was that an establishment providing subsidised independent education is a public authority within the meaning of the Belgian law but not for the purposes of Article 83(7) of the GDPR.
The Market Court annulled that second decision on 6 October 2021, ruling that no fine could be imposed at all. The Court of Cassation set the judgment aside on 9 January 2023 and returned the case. On 27 February 2024 the Market Court annulled the regulator's decision once more. The authority appealed on a point of law a second time, and the Court of Cassation chose to ask Luxembourg. The request was received on 11 July 2025.
Written observations came from the OZCS, the Belgian authority, the Belgian and Bulgarian governments and the European Commission. All but the OZCS appeared at the hearing on 20 May 2026. The opinion does not set out the Bulgarian government's position.
Three Market Court judgments, two appeals to the Court of Cassation and a reference to the EU's highest court - all over a penalty that was halved between the first decision and the second. Why would a regulator chase a four-figure penalty that far? Because the question is not about the amount. It is about who, in Belgium, can be fined at all.
The provision at the centre
Article 83 of the GDPR sets the general conditions for administrative fines and, in paragraphs 4 to 6, their ceilings. Paragraph 7 carves out room for national choice. According to the regulation, "each Member State may lay down the rules on whether and to what extent administrative fines may be imposed on public authorities and bodies established in that Member State."
Belgium used that room in its Law of 30 July 2018 on the protection of natural persons with regard to the processing of personal data. Article 221(2) provides that Article 83 of the GDPR "does not apply to public authorities or to their employees or agents, except where they are legal persons governed by public law offering goods or services in a market."
The breadth of the Belgian exemption depends on the definition in Article 5 of the same law, which sets out four categories of public authority. The first covers the federal State, the federated entities and local authorities. The second covers legal persons governed by public law that depend on them. The third is the category on which this case turns: persons "whatever their form or nature" that were established to meet needs in the general interest not having an industrial or commercial character, have legal personality, and are either mainly funded by the authorities in the first two categories, subject to their management supervision, or governed by a board more than half of whose members they appoint. The fourth covers associations of any of those. The third category closely tracks the definition of a body governed by public law in the EU's 2014 public procurement directive, which the opinion reproduces in a footnote.
Read that way, a private non-profit association that runs schools on public money can fall within the Belgian definition. The Court of Cassation's question asks whether EU law allows that result. The question it referred reads: "Does Article 83(7) of [the GDPR], in conjunction with recitals 38 and 58 and Article 6(1)(f), Article 8 and Article 57(1)(b) thereof, preclude national legislation under which the supervisory authority cannot impose administrative fines on legal persons constituted under private law which provide subsidised independent education?"
A European definition, not a Belgian one
The GDPR does not define "public authorities and bodies". According to the opinion, the OZCS and the Belgian government argued that the gap leaves the definition to member states. The OZCS relied on the Article 29 Working Party's Guidelines on Data Protection Officers, adopted on 13 December 2016 and revised on 5 April 2017, which state that the concept "is to be determined under national law". The Belgian authority and the Commission argued the opposite: without an express reference to national law, the term has to be read uniformly across the Union as an autonomous concept of EU law.
The Advocate General sided with the regulator and the Commission, and gave six reasons. Article 83(7) makes no reference to national law for the meaning of its terms. The margin it grants covers only whether, and to what extent, fines may be imposed on public authorities - not which bodies count as such. Before the GDPR, penalties for data protection breaches were largely left to member states under Article 24 of Directive 95/46, and the legislature chose to end that. The term "public authority" appears in a considerable number of GDPR provisions; the Belgian authority listed more than a dozen in its written observations. The Court has already treated other undefined GDPR terms as autonomous, including "non-material damage" in Österreichische Post (C-300/21, 4 May 2023) and "criminal offence" in Latvijas Republikas Saeima (C-439/19, 22 June 2021). And the regulation's stated aim, in recital 150, is "to strengthen and harmonise administrative penalties".
The practical risk of the alternative is spelled out plainly. If member states could define the category freely, according to the opinion, "it would be sufficient to designate as public authorities entities whose characteristics were not, in fact, consistent with the aim of the exemption at issue." The Advocate General also recalled the Court's judgment of 5 December 2023 in Nacionalinis visuomenės sveikatos centras (C-683/21), which held that member states lack the power to determine the substantive conditions for imposing GDPR fines. For comparison he cited Poltorak (C-452/16 PPU, 10 November 2016), in which the Court required a uniform reading of "judicial authority" under the European arrest warrant framework.
A footnote disposes of one textual complication: recital 154, which ties the term to national law on public access to documents, is confined in the Advocate General's view to Article 86 alone.
The direction of travel is familiar. The Court read the GDPR's freedom-of-expression derogation narrowly in a Swedish case decided on 9 July 2026, holding that exemptions authorised by Article 85(2) must be construed strictly. In April, Advocate General Rimvydas Norkus rejected a Bavarian law that barred any access to supervisory authority files, concluding that blanket national exclusions from data subject rights were incompatible with the regulation.
Sovereign power as the dividing line
Having established that EU law supplies the definition, the opinion turns to what it contains. A literal reading of the combination of "authority" or "body" with "public", according to the Advocate General, points to entities characterised by the exercise of sovereign powers - special powers beyond those that follow from the rules governing relations between individuals. A public body can act in the economy on the same terms as everyone else; what distinguishes it is its status and its prerogatives under public law.
The GDPR's own wording supports that reading. Its recitals distinguish "the performance of a task carried out in the public interest" from "the exercise of official authority". Recital 45, read with Article 79(2), indicates that public-interest tasks may be entrusted to persons governed by private law, "such as a professional association", while tasks involving public powers are reserved to a public authority or another person governed by public law. Recital 31 offers examples of public authorities: tax and customs authorities, financial market authorities, financial investigation units and administrative authorities.
From this the Advocate General concludes that the concept in Article 83(7) covers "solely" authorities or bodies governed by public law that are entrusted with tasks falling within the exercise of public authority. Carrying out a task in the general interest is not enough. A contrary reading, the opinion says, would allow member states to expand the exception excessively and create significant disparities between them.
How other fields of EU law draw the same line
Three other areas of EU law use similar words, and the opinion finds them pointing in different directions. Public procurement reads them broadly: under Saudaçor (C-174/14, 29 October 2015) the rules reach State-controlled entities outside the public administration, and FIGC and Consorzio Ge.Se.Av. (3 February 2021) treated associations governed by private law as contracting authorities. VAT reads them narrowly: Article 13(1) of Directive 2006/112 spares bodies governed by public law only for activities they carry out as public authorities, and because exceptions to a broadly defined tax are construed strictly, the case law weighs whether an entity exercises public-law powers.
The Commission proposed a third benchmark: the case law, dating back to Foster and Others (C-188/89, 12 July 1990), on bodies that count as the State when individuals rely on unimplemented directives - including bodies under the authority or supervision of a public authority, and bodies entrusted with a public-interest task and given special powers to perform it. According to the opinion, the Commission considered that both of those scenarios could apply to the OZCS.
The Advocate General declined to transplant it. That case law, he wrote, was built to compensate for member states' failure to transpose directives, and has little to do with an optional exception to a harmonised sanctions regime. "In short, different contexts and purposes result in concepts with different content." If a systematic benchmark has to be chosen, the opinion favours the restrictive VAT reading, because Article 83(7) is an optional exception and the Court has interpreted GDPR exceptions strictly before, in Land Hessen (C-272/19, 9 July 2020) and Österreichische Datenschutzbehörde (C-416/23, 9 January 2025).
A carve-out born alongside the 20 million euro ceiling
The most telling part of the opinion is historical. When the Commission proposed the GDPR in 2012, according to Article 79 of its draft (COM(2012) 011 final), maximum fines ranged from 250,000 euros to 1,000,000 euros and up to 2% of annual turnover. At the Council's suggestion, recorded in its first-reading position of 8 April 2016, those limits rose to the levels now in Article 83(4) to (6) - from 10 million to 20 million euros and up to 4% of annual turnover - and the possibility for member states to spare public bodies was included at the same time.
The exception, in other words, arrived with the higher ceilings. The Belgian authority argued that it can be seen as a safeguard for public finances, and that purely economic objectives cannot justify restrictions of the kind at issue. The OZCS offered a second justification: continuity in the performance of a task in the general interest. It pointed to judgment No 3/2021 of Belgium's Constitutional Court, delivered on 14 January 2021, which examined Article 221(2). According to that judgment, as quoted in the opinion, the parliamentary preparatory work justified sparing certain public sector controllers from fines by "the need to ensure the continuity of the public service" - objectives the Constitutional Court considered legitimate in themselves, while adding that it was necessary to verify whether the measure was "objective and reasonably justified" given its effects on the right to data protection.
The Advocate General accepted that, in some cases, a heavy fine on a public authority could jeopardise a general-interest task. But he did not think either aim required switching off fines for an entity whose activity is hard to distinguish from that of other private operators providing secondary education, that is not integrated into State structures and does not wield public-law powers, and whose public funds and continuity can be protected by adjusting the amount of the fine to the circumstances.
Subsidies, certificates and advertising
The OZCS built part of its case on Congregación de Escuelas Pías Provincia Betania (C-74/16), a State aid judgment of 27 June 2017. The Court held there that a State running a system of public education financed largely from public funds is fulfilling social, cultural and educational obligations rather than engaging in gainful activity, and that a single establishment can carry on both economic and non-economic activities if it keeps separate accounts. The Advocate General found nothing in that judgment to suggest an independent school becomes a public authority merely because it receives State funding.
The provisional text contains at least one citation inconsistency. Footnote 44, listing a further judgment the OZCS relied on, dates Commission v Germany (C-318/05) to 11 September 2017, while its identifier, EU:C:2007:495, corresponds to a 2007 decision.
Applying the criteria, the opinion leaves the final assessment to the Court of Cassation but states the Advocate General's view directly: the OZCS "is not a legal person that forms part of the State in the broad sense", nor has it been invested with special powers within the scope of public authority. Each of the connecting factors raised in the proceedings was examined and set aside.
- Supervision. The Flemish authority monitors the OZCS's compliance with minimum learning objectives, but that does not place it in a position very different from non-subsidised private schools.
- Certificates. The power to issue educational certificates is not proof of public-law prerogatives. At the hearing, the Belgian authority observed that private establishments receiving no subsidy hold the same power without being treated as public authorities.
- Teaching. The Court held in Commission v Luxembourg (C-473/93, 2 July 1996) that teaching posts do not involve participation in the exercise of public-law powers, a point the opinion applies specifically to secondary education, citing Bleis (C-4/91, 27 November 1991).
- Funding. The Commission acknowledged at the hearing that merely receiving a subsidy is not sufficient. The share of the OZCS's budget covered by public subsidies has not been established; a figure of "more than 50%" was mentioned at the hearing without further precision, and the OZCS, absent, could not supply more specific numbers.
Then comes a detail that ties a school survey to the advertising business. According to the opinion, the Belgian government acknowledged that the OZCS has private sources of income - fees paid by pupils' parents, donations and sales of assets - which prove that it carries on an economic activity, "for which the OZCS is even able to make use of advertising."
The fine itself became part of the argument. Article 83(2)(k) requires supervisory authorities to weigh "any other aggravating or mitigating factor" when deciding whether to fine and how much. That provision, the Advocate General observed, had already done its job: given the association's non-profit status and its general-interest activity, the 1,000 euro penalty "far from jeopardises its continuance as an educational establishment."
Treating the OZCS as a public authority, by contrast, would protect continuity in a disproportionate way. Faced with an infringement harming pupils' rights, the Belgian authorities could never use what the opinion calls "the most effective safeguarding mechanism available to them". Their corrective power would be reduced, in the Advocate General's words, "to issuing a mere warning or a reprimand."
Children, set aside and then brought back
The Court of Cassation framed its question around children: recitals 38 and 58, Article 6(1)(f), whose legitimate interestground is expressly qualified where the data subject is a child, Article 8, and Article 57(1)(b), which tells supervisory authorities to give specific attention to activities addressed to children. Recital 38 states that "Children merit specific protection with regard to their personal data".
The Advocate General, like the Commission, considered that link unnecessary for defining the concept. Public authorities and bodies are such by reason of their nature, according to the opinion, not by reason of the persons whose rights they harm; the concept "has only one meaning".
Children return in the final paragraphs of the analysis. The reading favoured by the OZCS and the Belgian government, the opinion warns, would let every private-law entity that performs a general-interest task and receives public subsidies claim the exception. Tasks of that kind, "in particular, in the fields of health, education and social action", frequently involve sensitive data - what the regulation treats as special category data - or data about vulnerable people, children among them. Supervisory authorities, the Advocate General concludes, cannot be categorically deprived of fines against a private entity simply because it teaches in the general interest and receives public money; such an interpretation "would substantially reduce the ability of supervisory authorities to ensure compliance with the GDPR".
The proposed answer to the Court of Cassation is that Article 83(7) "precludes national legislation under which the supervisory authority cannot impose administrative fines on legal persons constituted under private law which provide independent education and, for that purpose, receive subsidies from public funds."
What happens next
An Advocate General's opinion does not bind the Court of Justice. The judges will now deliberate and deliver a judgment, for which no date has been set. PPC Land noted in April that the Court follows the Advocate General's reasoning in the majority of cases; in one recent data protection example, an opinion delivered on 1 August 2025 on body cameras was followed by a judgment on 18 December 2025 that confirmed its conclusion.
Once Luxembourg rules, the Court of Cassation will apply the answer to the appeal against the Market Court's judgment of 27 February 2024. If the Court of Justice follows the opinion, Article 221(2) could no longer shield private-law entities of the OZCS's kind, and the third category of Belgium's Article 5 definition - persons "whatever their form or nature" meeting the funding or control tests - would not, on its own, carry an exemption from fines. Public-law bodies offering goods or services in a market, which Belgian law already leaves liable to fines, were not at issue.
Nor is the reasoning confined to Belgium. Any member state using Article 83(7) with a definition wider than bodies wielding public-law powers would meet the same test, although the opinion does not survey other national laws.
Why this matters for the marketing community
The first reason is jurisdictional. Belgium's authority is the regulator that found the IAB Europe Transparency and Consent Framework non-compliant with Article 6 and fined IAB Europe 250,000 euros in February 2022. The Market Court that twice annulled the school fine is the same court that confined IAB Europe's joint controllership to TC String processing on 14 May 2025, annulled the regulator's validation of IAB Europe's action plan on 7 January 2026, and annulled a Belgian authority decision on direct marketing in December 2025 over its handling of legitimate interest. How far Brussels judges allow the regulator to reach is a recurring question for the programmatic industry, and this opinion pushes toward a wider reach.
The second concerns organisations that straddle public and private money. Many subsidised schools, universities, care providers and cultural bodies run websites, analytics, newsletters, surveys and paid campaigns like any other advertiser. The opinion records that the OZCS itself advertises. Under the Advocate General's reading, public funding and a general-interest mission do not remove such organisations from the fining regime; only the exercise of public-law powers does. The Belgian regulator already handles public-sector respondents in the digital sphere: in a binding decision published in July, the European Data Protection Board ordered it not to dismiss a noyb cookie-banner complaint against VRT, the Flemish public broadcaster.
Third, children's data is a stated priority in Belgium. The authority's strategic plan for 2026 to 2028, published on 23 December 2025, names two enforcement themes: large-scale high-risk processing, including advertising technology, and the processing of minors' personal data. The same plan describes an authority of roughly 90 staff whose recruitment credits have been frozen through 2029, with 173 litigation chamber decisions in 2024. Elsewhere, the Austrian authority ordered Microsoft to stop placing tracking cookies on devices used by schoolchildren through Microsoft 365 Education, in a decision made public on 27 January 2026, after the school in question said it was responsible only for a pupil's email address. German supervisory authorities, meanwhile, argued in November 2025 that Recital 38's protection against using children's data for advertising and profiling never made it into the regulation's binding text. For the education technology, survey and analytics tools that schools rely on, the opinion points toward the controllers deploying them staying within reach of fines, pending the Court's judgment.
Fourth, the opinion makes a case for proportionate fines over categorical exemptions. Headline figures dominate coverage: national authorities issued 1,145,760,374 euros in GDPR fines during 2025, according to the EDPB's annual report, while analysis published in May 2026 found that close to 40% of the 7.1 billion euros in headline fines since 2018 had been annulled or was under challenge. The most prominent reversal, Luxembourg's annulment of Amazon's 746 million euro fine on 12 March 2026, rested on the fault requirement set out in Deutsche Wohnen and Nacionalinis - the same December 2023 case law the Advocate General cites here. Most enforcement never reaches that scale: EDPB statistics showed an average of only 1.3% of cases ending in a monetary penalty between 2018 and 2023, and Portugal's regulator issued just two fines, totalling 47,000 euros, in all of 2025. The Advocate General's reasoning treats Article 83(2) calibration, not categorical exemption, as the proper tool for protecting organisations of limited means - which keeps the fine available against smaller controllers as well as the largest platforms.
Finally, the case touches the mechanics of compliance that sit behind any data-driven campaign. The complaint alleged a missing impact assessment; the EDPB adopted its first standardised DPIA template on 10 March 2026. The findings covered lawful basis, children's consent, minimisation and transparency - the same four areas at issue in many advertising disputes. And the regulation being interpreted is itself under revision: amendments proposed through the Commission's Digital Omnibus package in November 2025 remain under negotiation.
Timeline
- 2012: The Commission proposes the GDPR with maximum fines of 250,000 euros to 1,000,000 euros and up to 2% of annual turnover (COM(2012) 011 final, Article 79).
- 8 April 2016: The Council's first-reading position carries higher ceilings of 10 million to 20 million euros and up to 4% of turnover, alongside the national option that becomes Article 83(7).
- 27 April 2016: Regulation (EU) 2016/679 is adopted.
- 30 July 2018: Belgium adopts its data protection law, including the Article 5 definition and the Article 221(2) exemption.
- 22 July 2019: A pupil's father complains to the Belgian Data Protection Authority about a well-being survey.
- 16 June 2020: The authority finds four GDPR infringements and fines the OZCS 2,000 euros.
- 18 November 2020: The Market Court orders the authority to give reasons on the Article 221(2) exemption.
- 14 January 2021: Belgium's Constitutional Court delivers judgment No 3/2021 examining Article 221(2).
- 15 March 2021: The authority fines the OZCS 1,000 euros.
- 6 October 2021: The Market Court annuls the decision, holding that no fine can be imposed.
- February 2022: The Belgian authority finds the TCF non-compliant and fines IAB Europe 250,000 euros.
- 9 January 2023: The Court of Cassation sets aside the Market Court judgment and sends the case back.
- 5 December 2023: The Court of Justice rules in Deutsche Wohnen and Nacionalinis that fault is a precondition for GDPR fines.
- 27 February 2024: The Market Court annuls the authority's decision again.
- 14 May 2025: The Market Court limits IAB Europe's joint controllership to TC String processing.
- 11 July 2025: The Court of Justice receives the Court of Cassation's reference in Case C-458/25.
- 1 August 2025: An Advocate General's opinion on body cameras, later followed by the Court, is delivered.
- November 2025: The Commission's Digital Omnibus proposes GDPR amendments.
- November 2025: German supervisory authorities call for stronger GDPR protection for children.
- 17 December 2025: A Brussels appeals court annuls a Belgian authority decision on direct marketing.
- 18 December 2025: The Court of Justice rules on body cameras, confirming the Advocate General's conclusion.
- 23 December 2025: The Belgian authority publishes its 2026-2028 strategy, prioritising minors' data.
- 7 January 2026: The Market Court annuls the validation of IAB Europe's action plan.
- 27 January 2026: Austria's authority orders Microsoft to stop tracking schoolchildren via Microsoft 365 Education.
- 10 March 2026: The EDPB adopts its first standardised DPIA template.
- 12 March 2026: Luxembourg's Administrative Court annuls Amazon's 746 million euro fine.
- 9 April 2026: The EDPB annual report records 1,145,760,374 euros in fines for 2025.
- 16 April 2026: Advocate General Norkus rejects a Bavarian blanket exclusion from access rights.
- 20 May 2026: Hearing in Case C-458/25; the OZCS does not attend.
- May 2026: Analysis finds close to 40% of 7.1 billion euros in GDPR fines annulled or under challenge.
- 9 July 2026: The Court of Justice rejects Sweden's GDPR exemption for a commercial database.
- 14 July 2026: The EDPB orders Belgium not to dismiss a cookie complaint against VRT.
- 10 September 2026: Advocate General Campos Sánchez-Bordona delivers his opinion in Case C-458/25.
Related PPC Land coverage
- EU court's top adviser says data watchdogs must honor GDPR access requests - An April 2026 opinion rejecting a blanket national exclusion from GDPR rights, on reasoning parallel to this case.
- CJEU blocks Sweden's GDPR exemption, reviving SEK 300,000 damages claim - The July 2026 judgment construing a member-state derogation strictly.
- Belgian data watchdog targets adtech with sweeping enforcement strategy - The authority's 2026-2028 plan naming minors' data and ad tech as priorities.
- EDPB forces Belgian regulator to reconsider dismissed noyb cookie case - A binding decision involving a Flemish public broadcaster and the Belgian authority.
- Belgian court limits IAB Europe's role in TCF framework - The Market Court's May 2025 ruling on joint controllership in programmatic consent.
- Belgian court hands IAB Europe a major TCF win - The January 2026 annulment of the regulator's action plan validation.
- Belgian court overturns data fine in direct marketing ruling - Another Brussels appeals court decision against the Belgian authority.
- Austrian regulator orders Microsoft to stop tracking school children - A school technology case in which controller responsibility was contested.
- German data protection authorities call for enhanced GDPR protections for children - Proposals to write Recital 38's advertising protections into the binding text.
- Eight years of GDPR: 40% of the €7.1B in fines annulled or under challenge - How much headline enforcement survives the courts.
- Why Amazon no longer has to pay its €746M GDPR fine - a legal breakdown - The fault requirement from the December 2023 judgments the opinion also cites.
- EDPB 2025 annual report: €1.15bn in GDPR fines, new AI and DMA rules - European fine totals for 2025.
Summary
Who: Advocate General Manuel Campos Sánchez-Bordona of the Court of Justice of the European Union, in a case between Belgium's Data Protection Authority (Gegevensbeschermingsautoriteit) and the Onderwijsgroep Zusters der Christelijke Scholen Zuid-Kempen VZW, a non-profit association running subsidised independent schools. The Belgian and Bulgarian governments and the European Commission also submitted observations.
What: A non-binding opinion concluding that "public authorities and bodies" in Article 83(7) of the GDPR is an autonomous EU concept limited to public-law bodies exercising public-law powers, and that the article precludes Belgian legislation preventing fines on private-law entities that provide independent education with public subsidies. The underlying fine is 1,000 euros, reduced from an original 2,000 euros, for four infringements linked to a pupil well-being survey.
When: The opinion was delivered on 10 September 2026. The complaint dates from 22 July 2019, the reference was received on 11 July 2025, and the hearing took place on 20 May 2026. No judgment date has been set.
Where: The Court of Justice in Luxembourg, on a reference from Belgium's Court of Cassation, following three rounds before the Market Court in Brussels. The reasoning applies to any member state using Article 83(7).
Why: Belgium's Article 221(2) excludes GDPR fines for public authorities, and its Article 5 definition can include private bodies funded or supervised by the State. The Advocate General found that a broad reading would let subsidised private entities in health, education and social action - sectors that often process children's or sensitive data - escape the regulation's main sanction, leaving regulators with only warnings and reprimands.
Discussion