An Advocate General at the Court of Justice of the European Union advised on 10 September 2026 that Belgium's national data protection law cannot stop the country's regulator from fining a privately run association that operates publicly subsidised schools, in a dispute that began with a pupil well-being survey and a father's complaint more than seven years ago.

In Short

A Belgian school sent pupils an online survey about how they were feeling without telling their parents first, and the country's privacy regulator fined the organisation that runs it. The organisation argued that Belgian law protects public bodies from such fines and that, because it receives government money, it counts as one - and one of the legal advisers at Europe's highest court has now said it does not. If the judges agree, privately run organisations doing public-interest work on public money, from schools to care providers, can still be fined when they mishandle your data.

Seven years over a pupil survey

The case, registered as C-458/25, Gegevensbeschermingsautoriteit v Onderwijsgroep Zusters der Christelijke Scholen Zuid-Kempen VZW, reached the Luxembourg court as a reference for a preliminary ruling from the Hof van Cassatie, Belgium's Court of Cassation. Advocate General Manuel Campos Sánchez-Bordona delivered the opinion, which was written in Spanish and published in English as a provisional text.

Its origins are modest. On 22 July 2019, the father of a pupil lodged a complaint with the Gegevensbeschermingsautoriteit, Belgium's Data Protection Authority, against a school belonging to the association, a non-profit body referred to throughout the proceedings as the OZCS. The school had distributed a survey on pupils' well-being through a digital platform. According to the opinion, the complaint listed four problems: parents had not been informed of the survey in advance, their consent had not been obtained, more data had been processed than was necessary, and no assessment of the impact of the processing on data protection had been carried out.

The regulator ruled on 16 June 2020. It found that the OZCS was the data controller and established four infringements of the GDPR: of Article 6(1), which sets out the lawful grounds for processing; of Article 8, on the conditions for a child's consent to information society services; of Article 5(1)(c), the data minimisation principle; and of Article 5(1)(a), read together with Articles 12(1) and 13, which govern transparency and the information owed to people whose data is collected. The missing impact assessment, raised in the complaint, does not appear among the four findings as the opinion records them. The authority ordered the processing brought into compliance and imposed an administrative fine of 2,000 euros.

What followed was a procedural relay between Brussels courts. The Marktenhof, the Market Court that hears appeals against the authority's decisions, held on 18 November 2020 that the decision was not sufficiently reasoned on the exemption contained in Article 221(2) of Belgium's data protection law, and ordered the regulator to reconsider. On 15 March 2021, the authority fined the OZCS again, this time 1,000 euros. Its reasoning, according to the opinion, was that an establishment providing subsidised independent education is a public authority within the meaning of the Belgian law but not for the purposes of Article 83(7) of the GDPR.

The Market Court annulled that second decision on 6 October 2021, ruling that no fine could be imposed at all. The Court of Cassation set the judgment aside on 9 January 2023 and returned the case. On 27 February 2024 the Market Court annulled the regulator's decision once more. The authority appealed on a point of law a second time, and the Court of Cassation chose to ask Luxembourg. The request was received on 11 July 2025.

Written observations came from the OZCS, the Belgian authority, the Belgian and Bulgarian governments and the European Commission. All but the OZCS appeared at the hearing on 20 May 2026. The opinion does not set out the Bulgarian government's position.

Three Market Court judgments, two appeals to the Court of Cassation and a reference to the EU's highest court - all over a penalty that was halved between the first decision and the second. Why would a regulator chase a four-figure penalty that far? Because the question is not about the amount. It is about who, in Belgium, can be fined at all.

The provision at the centre

Article 83 of the GDPR sets the general conditions for administrative fines and, in paragraphs 4 to 6, their ceilings. Paragraph 7 carves out room for national choice. According to the regulation, "each Member State may lay down the rules on whether and to what extent administrative fines may be imposed on public authorities and bodies established in that Member State."

Belgium used that room in its Law of 30 July 2018 on the protection of natural persons with regard to the processing of personal data. Article 221(2) provides that Article 83 of the GDPR "does not apply to public authorities or to their employees or agents, except where they are legal persons governed by public law offering goods or services in a market."

The breadth of the Belgian exemption depends on the definition in Article 5 of the same law, which sets out four categories of public authority. The first covers the federal State, the federated entities and local authorities. The second covers legal persons governed by public law that depend on them. The third is the category on which this case turns: persons "whatever their form or nature" that were established to meet needs in the general interest not having an industrial or commercial character, have legal personality, and are either mainly funded by the authorities in the first two categories, subject to their management supervision, or governed by a board more than half of whose members they appoint. The fourth covers associations of any of those. The third category closely tracks the definition of a body governed by public law in the EU's 2014 public procurement directive, which the opinion reproduces in a footnote.

Read that way, a private non-profit association that runs schools on public money can fall within the Belgian definition. The Court of Cassation's question asks whether EU law allows that result. The question it referred reads: "Does Article 83(7) of [the GDPR], in conjunction with recitals 38 and 58 and Article 6(1)(f), Article 8 and Article 57(1)(b) thereof, preclude national legislation under which the supervisory authority cannot impose administrative fines on legal persons constituted under private law which provide subsidised independent education?"

A European definition, not a Belgian one

The GDPR does not define "public authorities and bodies". According to the opinion, the OZCS and the Belgian government argued that the gap leaves the definition to member states. The OZCS relied on the Article 29 Working Party's Guidelines on Data Protection Officers, adopted on 13 December 2016 and revised on 5 April 2017, which state that the concept "is to be determined under national law". The Belgian authority and the Commission argued the opposite: without an express reference to national law, the term has to be read uniformly across the Union as an autonomous concept of EU law.

The Advocate General sided with the regulator and the Commission, and gave six reasons. Article 83(7) makes no reference to national law for the meaning of its terms. The margin it grants covers only whether, and to what extent, fines may be imposed on public authorities - not which bodies count as such. Before the GDPR, penalties for data protection breaches were largely left to member states under Article 24 of Directive 95/46, and the legislature chose to end that. The term "public authority" appears in a considerable number of GDPR provisions; the Belgian authority listed more than a dozen in its written observations. The Court has already treated other undefined GDPR terms as autonomous, including "non-material damage" in Österreichische Post (C-300/21, 4 May 2023) and "criminal offence" in Latvijas Republikas Saeima (C-439/19, 22 June 2021). And the regulation's stated aim, in recital 150, is "to strengthen and harmonise administrative penalties".

The practical risk of the alternative is spelled out plainly. If member states could define the category freely, according to the opinion, "it would be sufficient to designate as public authorities entities whose characteristics were not, in fact, consistent with the aim of the exemption at issue." The Advocate General also recalled the Court's judgment of 5 December 2023 in Nacionalinis visuomenės sveikatos centras (C-683/21), which held that member states lack the power to determine the substantive conditions for imposing GDPR fines. For comparison he cited Poltorak (C-452/16 PPU, 10 November 2016), in which the Court required a uniform reading of "judicial authority" under the European arrest warrant framework.

A footnote disposes of one textual complication: recital 154, which ties the term to national law on public access to documents, is confined in the Advocate General's view to Article 86 alone.

The direction of travel is familiar. The Court read the GDPR's freedom-of-expression derogation narrowly in a Swedish case decided on 9 July 2026, holding that exemptions authorised by Article 85(2) must be construed strictly. In April, Advocate General Rimvydas Norkus rejected a Bavarian law that barred any access to supervisory authority files, concluding that blanket national exclusions from data subject rights were incompatible with the regulation.

Sovereign power as the dividing line

Having established that EU law supplies the definition, the opinion turns to what it contains. A literal reading of the combination of "authority" or "body" with "public", according to the Advocate General, points to entities characterised by the exercise of sovereign powers - special powers beyond those that follow from the rules governing relations between individuals. A public body can act in the economy on the same terms as everyone else; what distinguishes it is its status and its prerogatives under public law.

The GDPR's own wording supports that reading. Its recitals distinguish "the performance of a task carried out in the public interest" from "the exercise of official authority". Recital 45, read with Article 79(2), indicates that public-interest tasks may be entrusted to persons governed by private law, "such as a professional association", while tasks involving public powers are reserved to a public authority or another person governed by public law. Recital 31 offers examples of public authorities: tax and customs authorities, financial market authorities, financial investigation units and administrative authorities.

From this the Advocate General concludes that the concept in Article 83(7) covers "solely" authorities or bodies governed by public law that are entrusted with tasks falling within the exercise of public authority. Carrying out a task in the general interest is not enough. A contrary reading, the opinion says, would allow member states to expand the exception excessively and create significant disparities between them.

How other fields of EU law draw the same line

Three other areas of EU law use similar words, and the opinion finds them pointing in different directions. Public procurement reads them broadly: under Saudaçor (C-174/14, 29 October 2015) the rules reach State-controlled entities outside the public administration, and FIGC and Consorzio Ge.Se.Av. (3 February 2021) treated associations governed by private law as contracting authorities. VAT reads them narrowly: Article 13(1) of Directive 2006/112 spares bodies governed by public law only for activities they carry out as public authorities, and because exceptions to a broadly defined tax are construed strictly, the case law weighs whether an entity exercises public-law powers.

The Commission proposed a third benchmark: the case law, dating back to Foster and Others (C-188/89, 12 July 1990), on bodies that count as the State when individuals rely on unimplemented directives - including bodies under the authority or supervision of a public authority, and bodies entrusted with a public-interest task and given special powers to perform it. According to the opinion, the Commission considered that both of those scenarios could apply to the OZCS.

The Advocate General declined to transplant it. That case law, he wrote, was built to compensate for member states' failure to transpose directives, and has little to do with an optional exception to a harmonised sanctions regime. "In short, different contexts and purposes result in concepts with different content." If a systematic benchmark has to be chosen, the opinion favours the restrictive VAT reading, because Article 83(7) is an optional exception and the Court has interpreted GDPR exceptions strictly before, in Land Hessen (C-272/19, 9 July 2020) and Österreichische Datenschutzbehörde (C-416/23, 9 January 2025).

A carve-out born alongside the 20 million euro ceiling

The most telling part of the opinion is historical. When the Commission proposed the GDPR in 2012, according to Article 79 of its draft (COM(2012) 011 final), maximum fines ranged from 250,000 euros to 1,000,000 euros and up to 2% of annual turnover. At the Council's suggestion, recorded in its first-reading position of 8 April 2016, those limits rose to the levels now in Article 83(4) to (6) - from 10 million to 20 million euros and up to 4% of annual turnover - and the possibility for member states to spare public bodies was included at the same time.

The exception, in other words, arrived with the higher ceilings. The Belgian authority argued that it can be seen as a safeguard for public finances, and that purely economic objectives cannot justify restrictions of the kind at issue. The OZCS offered a second justification: continuity in the performance of a task in the general interest. It pointed to judgment No 3/2021 of Belgium's Constitutional Court, delivered on 14 January 2021, which examined Article 221(2). According to that judgment, as quoted in the opinion, the parliamentary preparatory work justified sparing certain public sector controllers from fines by "the need to ensure the continuity of the public service" - objectives the Constitutional Court considered legitimate in themselves, while adding that it was necessary to verify whether the measure was "objective and reasonably justified" given its effects on the right to data protection.

The Advocate General accepted that, in some cases, a heavy fine on a public authority could jeopardise a general-interest task. But he did not think either aim required switching off fines for an entity whose activity is hard to distinguish from that of other private operators providing secondary education, that is not integrated into State structures and does not wield public-law powers, and whose public funds and continuity can be protected by adjusting the amount of the fine to the circumstances.

Subsidies, certificates and advertising

The OZCS built part of its case on Congregación de Escuelas Pías Provincia Betania (C-74/16), a State aid judgment of 27 June 2017. The Court held there that a State running a system of public education financed largely from public funds is fulfilling social, cultural and educational obligations rather than engaging in gainful activity, and that a single establishment can carry on both economic and non-economic activities if it keeps separate accounts. The Advocate General found nothing in that judgment to suggest an independent school becomes a public authority merely because it receives State funding.

The provisional text contains at least one citation inconsistency. Footnote 44, listing a further judgment the OZCS relied on, dates Commission v Germany (C-318/05) to 11 September 2017, while its identifier, EU:C:2007:495, corresponds to a 2007 decision.

Applying the criteria, the opinion leaves the final assessment to the Court of Cassation but states the Advocate General's view directly: the OZCS "is not a legal person that forms part of the State in the broad sense", nor has it been invested with special powers within the scope of public authority. Each of the connecting factors raised in the proceedings was examined and set aside.

  • Supervision. The Flemish authority monitors the OZCS's compliance with minimum learning objectives, but that does not place it in a position very different from non-subsidised private schools.
  • Certificates. The power to issue educational certificates is not proof of public-law prerogatives. At the hearing, the Belgian authority observed that private establishments receiving no subsidy hold the same power without being treated as public authorities.
  • Teaching. The Court held in Commission v Luxembourg (C-473/93, 2 July 1996) that teaching posts do not involve participation in the exercise of public-law powers, a point the opinion applies specifically to secondary education, citing Bleis (C-4/91, 27 November 1991).
  • Funding. The Commission acknowledged at the hearing that merely receiving a subsidy is not sufficient. The share of the OZCS's budget covered by public subsidies has not been established; a figure of "more than 50%" was mentioned at the hearing without further precision, and the OZCS, absent, could not supply more specific numbers.

Then comes a detail that ties a school survey to the advertising business. According to the opinion, the Belgian government acknowledged that the OZCS has private sources of income - fees paid by pupils' parents, donations and sales of assets - which prove that it carries on an economic activity, "for which the OZCS is even able to make use of advertising."

The fine itself became part of the argument. Article 83(2)(k) requires supervisory authorities to weigh "any other aggravating or mitigating factor" when deciding whether to fine and how much. That provision, the Advocate General observed, had already done its job: given the association's non-profit status and its general-interest activity, the 1,000 euro penalty "far from jeopardises its continuance as an educational establishment."

Treating the OZCS as a public authority, by contrast, would protect continuity in a disproportionate way. Faced with an infringement harming pupils' rights, the Belgian authorities could never use what the opinion calls "the most effective safeguarding mechanism available to them". Their corrective power would be reduced, in the Advocate General's words, "to issuing a mere warning or a reprimand."

Children, set aside and then brought back

The Court of Cassation framed its question around children: recitals 38 and 58, Article 6(1)(f), whose legitimate interestground is expressly qualified where the data subject is a child, Article 8, and Article 57(1)(b), which tells supervisory authorities to give specific attention to activities addressed to children. Recital 38 states that "Children merit specific protection with regard to their personal data".

The Advocate General, like the Commission, considered that link unnecessary for defining the concept. Public authorities and bodies are such by reason of their nature, according to the opinion, not by reason of the persons whose rights they harm; the concept "has only one meaning".

Children return in the final paragraphs of the analysis. The reading favoured by the OZCS and the Belgian government, the opinion warns, would let every private-law entity that performs a general-interest task and receives public subsidies claim the exception. Tasks of that kind, "in particular, in the fields of health, education and social action", frequently involve sensitive data - what the regulation treats as special category data - or data about vulnerable people, children among them. Supervisory authorities, the Advocate General concludes, cannot be categorically deprived of fines against a private entity simply because it teaches in the general interest and receives public money; such an interpretation "would substantially reduce the ability of supervisory authorities to ensure compliance with the GDPR".

The proposed answer to the Court of Cassation is that Article 83(7) "precludes national legislation under which the supervisory authority cannot impose administrative fines on legal persons constituted under private law which provide independent education and, for that purpose, receive subsidies from public funds."

What happens next

An Advocate General's opinion does not bind the Court of Justice. The judges will now deliberate and deliver a judgment, for which no date has been set. PPC Land noted in April that the Court follows the Advocate General's reasoning in the majority of cases; in one recent data protection example, an opinion delivered on 1 August 2025 on body cameras was followed by a judgment on 18 December 2025 that confirmed its conclusion.

Once Luxembourg rules, the Court of Cassation will apply the answer to the appeal against the Market Court's judgment of 27 February 2024. If the Court of Justice follows the opinion, Article 221(2) could no longer shield private-law entities of the OZCS's kind, and the third category of Belgium's Article 5 definition - persons "whatever their form or nature" meeting the funding or control tests - would not, on its own, carry an exemption from fines. Public-law bodies offering goods or services in a market, which Belgian law already leaves liable to fines, were not at issue.

Nor is the reasoning confined to Belgium. Any member state using Article 83(7) with a definition wider than bodies wielding public-law powers would meet the same test, although the opinion does not survey other national laws.

Why this matters for the marketing community

The first reason is jurisdictional. Belgium's authority is the regulator that found the IAB Europe Transparency and Consent Framework non-compliant with Article 6 and fined IAB Europe 250,000 euros in February 2022. The Market Court that twice annulled the school fine is the same court that confined IAB Europe's joint controllership to TC String processing on 14 May 2025, annulled the regulator's validation of IAB Europe's action plan on 7 January 2026, and annulled a Belgian authority decision on direct marketing in December 2025 over its handling of legitimate interest. How far Brussels judges allow the regulator to reach is a recurring question for the programmatic industry, and this opinion pushes toward a wider reach.

The second concerns organisations that straddle public and private money. Many subsidised schools, universities, care providers and cultural bodies run websites, analytics, newsletters, surveys and paid campaigns like any other advertiser. The opinion records that the OZCS itself advertises. Under the Advocate General's reading, public funding and a general-interest mission do not remove such organisations from the fining regime; only the exercise of public-law powers does. The Belgian regulator already handles public-sector respondents in the digital sphere: in a binding decision published in July, the European Data Protection Board ordered it not to dismiss a noyb cookie-banner complaint against VRT, the Flemish public broadcaster.

Third, children's data is a stated priority in Belgium. The authority's strategic plan for 2026 to 2028, published on 23 December 2025, names two enforcement themes: large-scale high-risk processing, including advertising technology, and the processing of minors' personal data. The same plan describes an authority of roughly 90 staff whose recruitment credits have been frozen through 2029, with 173 litigation chamber decisions in 2024. Elsewhere, the Austrian authority ordered Microsoft to stop placing tracking cookies on devices used by schoolchildren through Microsoft 365 Education, in a decision made public on 27 January 2026, after the school in question said it was responsible only for a pupil's email address. German supervisory authorities, meanwhile, argued in November 2025 that Recital 38's protection against using children's data for advertising and profiling never made it into the regulation's binding text. For the education technology, survey and analytics tools that schools rely on, the opinion points toward the controllers deploying them staying within reach of fines, pending the Court's judgment.

Fourth, the opinion makes a case for proportionate fines over categorical exemptions. Headline figures dominate coverage: national authorities issued 1,145,760,374 euros in GDPR fines during 2025, according to the EDPB's annual report, while analysis published in May 2026 found that close to 40% of the 7.1 billion euros in headline fines since 2018 had been annulled or was under challenge. The most prominent reversal, Luxembourg's annulment of Amazon's 746 million euro fine on 12 March 2026, rested on the fault requirement set out in Deutsche Wohnen and Nacionalinis - the same December 2023 case law the Advocate General cites here. Most enforcement never reaches that scale: EDPB statistics showed an average of only 1.3% of cases ending in a monetary penalty between 2018 and 2023, and Portugal's regulator issued just two fines, totalling 47,000 euros, in all of 2025. The Advocate General's reasoning treats Article 83(2) calibration, not categorical exemption, as the proper tool for protecting organisations of limited means - which keeps the fine available against smaller controllers as well as the largest platforms.

Finally, the case touches the mechanics of compliance that sit behind any data-driven campaign. The complaint alleged a missing impact assessment; the EDPB adopted its first standardised DPIA template on 10 March 2026. The findings covered lawful basis, children's consent, minimisation and transparency - the same four areas at issue in many advertising disputes. And the regulation being interpreted is itself under revision: amendments proposed through the Commission's Digital Omnibus package in November 2025 remain under negotiation.

Timeline

Summary

Who: Advocate General Manuel Campos Sánchez-Bordona of the Court of Justice of the European Union, in a case between Belgium's Data Protection Authority (Gegevensbeschermingsautoriteit) and the Onderwijsgroep Zusters der Christelijke Scholen Zuid-Kempen VZW, a non-profit association running subsidised independent schools. The Belgian and Bulgarian governments and the European Commission also submitted observations.

What: A non-binding opinion concluding that "public authorities and bodies" in Article 83(7) of the GDPR is an autonomous EU concept limited to public-law bodies exercising public-law powers, and that the article precludes Belgian legislation preventing fines on private-law entities that provide independent education with public subsidies. The underlying fine is 1,000 euros, reduced from an original 2,000 euros, for four infringements linked to a pupil well-being survey.

When: The opinion was delivered on 10 September 2026. The complaint dates from 22 July 2019, the reference was received on 11 July 2025, and the hearing took place on 20 May 2026. No judgment date has been set.

Where: The Court of Justice in Luxembourg, on a reference from Belgium's Court of Cassation, following three rounds before the Market Court in Brussels. The reasoning applies to any member state using Article 83(7).

Why: Belgium's Article 221(2) excludes GDPR fines for public authorities, and its Article 5 definition can include private bodies funded or supervised by the State. The Advocate General found that a broad reading would let subsidised private entities in health, education and social action - sectors that often process children's or sensitive data - escape the regulation's main sanction, leaving regulators with only warnings and reprimands.