Opinion of Advocate General Medina delivered on 1 October 2026
Provisional text
OPINION OF ADVOCATE GENERAL
MEDINA
delivered on 1 October 2026 ( 1 )
Case C ‑ 12/25
Bisdom Gent VZW
v
Gegevensbeschermingsautoriteit,
joined parties:
JM,
Unie Vrijzinnige Verenigingen VZW,
Centre d’Action Laïque VZW,
Centrale Raad der niet confessionele levensbeschouwelijke gemeenschappen van België VZW,
FA,
MO,
RV,
TA,
CH,
LV,
NA,
BU,
MI,
DO,
BZ,
DF,
RA,
JD
(Request for a preliminary ruling from the hof van beroep te Brussel (Court of Appeal, Brussels, Belgium))
( Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data and the free movement of such data – Religious associations – Baptismal register – Articles 6, 17, 21 and 89 of Regulation (EU) 2016/679 – Concept of ‘filing system’ – Right to erasure – Lawfulness of processing – Right to object – Processing for archiving purposes in the public interest or for historical research purposes – Articles 7, 8 and 10 of the Charter of Fundamental Rights of the European Union – Respect for private and family life – Protection of personal data – Freedom of thought, conscience and religion – Article 17 TFEU – Principles of neutrality and autonomy )
I. Introduction
1. ‘Render therefore unto Caesar the things which are Caesar’s, and unto God the things that are God’s’. This phrase, which one of the Synoptic Gospels attributes to Jesus, ( 2 ) is often regarded as a reflection of the fundamental dichotomy, faced by individuals since the dawn of time, of distinguishing between the realm of the secular State (with its laws which apply to everyone ( 3 )) and the realm of belief and religion (which belongs to the inner conscience of every person ( 4 )).
2. That phrase is also viewed by many as a call for the separation of Church and State. History shows, however, that religions and churches have had significant influence – both in Europe and elsewhere – on the legitimacy of political government, the shaping of local culture and the formation of a society’s identity. Accordingly, throughout the centuries, secular laws have regulated certain aspects pertaining to both religion (understood as a system of beliefs) and churches (that is, the communities and institutions which bring together and represent worshippers).
3. That is also true in today’s world, although the specific features of each legal system as regards that matter vary from State to State, including in Europe. ( 5 ) As far as the EU legal order is concerned, it could be said, in a nutshell, that the relationship between ‘Caesar and God’ is structured along four main axes.
4. First, the European Union recognises the contribution made by religion to the creation of today’s European culture . As the preamble to the EU Treaty makes clear, in deciding to establish a European Union, the drafters of the Treaties have, inter alia, ‘[drawn] inspiration from the cultural, religious and humanist inheritance of Europe, from which have developed the universal values of the inviolable and inalienable rights of the human person, freedom, democracy, equality and the rule of law’. ( 6 ) That common heritage finds more concrete expression, inter alia, in the values of the European Union set out in Article 2 TEU and in the fundamental rights recognised in the Charter.
5. Second, freedom of religion constitutes one of those fundamental rights, as part and parcel of the ‘freedom of thought, conscience and religion’ enshrined in Article 10 of the Charter. According to paragraph 1 of that provision, ‘everyone has the right to freedom of thought, conscience and religion. This right includes freedom to change religion or belief and freedom, either alone or in community with others and in public or in private, to manifest religion or belief, in worship, teaching, practice and observance.’ ( 7 )
6. Third, the European Union has limited regulatory powers in religious matters. In particular, it has been given an explicit mandate to take appropriate action to combat discrimination on grounds, inter alia, of religion or belief. ( 8 ) More generally, Article 17(1) TFEU states that ‘the Union respects and does not prejudice the status under national law of churches and religious associations or communities in the Member States.’ That provision expresses the neutrality of the European Union towards the organisation by the Member States of their relations with religious associations. ( 9 ) The European Union accepts and values the existing diversity in the ways in which the relationship between Church and State, as maintained by the Member States, is built, and does not interfere with them.
7. It also follows from Article 17(1) TFEU, read in the light of Article 12 of the Charter (‘Freedom of assembly and of association’), that religious associations enjoy autonomy to manage their internal affairs without undue public interference. ( 10 ) The term ‘internal affairs’ should be understood as referring to matters that are directly related to their core ethos, such as internal administrative structures, appointment of minsters and doctrinal questions.
8. Fourth, the aforementioned principles of neutrality and autonomy cannot be understood as providing an implicit basis for regarding religious associations as exempt from compliance with provisions of EU law that may affect their activities. ( 11 ) Nor can the Member States enact rules which grant exceptions to, or derogations from, the applicable provisions of EU law, unless expressly permitted to do so under that law. ( 12 ) In fact, the Court has ruled in several cases on the compatibility with EU law of certain practices adopted by religious communities ( 13 ) or specific national measures which governed aspects of that Member State’s relationship with those communities. ( 14 )
9. This follows, quite clearly, from the fact that the European Union is a community based on the rule of law , ( 15 ) resting on the belief that no one is above the law or beneath its protection. ( 16 )
10. The interplay between those features and the possible tensions arising in that context come to the fore in the present case. By its questions, the referring court is essentially asking the Court of Justice whether the provisions of the General Data Protection Regulation ( 17 ) (‘the GDPR’) entitle a person, baptised as a minor and willing to dissociate himself or herself from the Roman Catholic Church ( 18 ) in adulthood, to have his or her personal data erased from the baptismal register.
11. Providing an answer to that question requires that various factors relating to religious rights and freedoms be taken into account: the right of individuals to change religion and have their privacy respected; the Church’s autonomy to manage its internal matters as it sees fit; and the extent of Member States’ discretion to regulate the role that churches play in society. In so far as, in the present case, those factors pull in different directions, it is my view that a fair balance must be struck between them. Neither religious communities nor their current or former members are above the law or beneath its protection. The rights and interests of both should, as far as possible, be reconciled.
II. Legal framework
A. European Union law
12. Article 2(1) of the GDPR, concerning the material scope thereof, states that the regulation ‘applies to the processing of personal data wholly or partly by automated means and to the processing other than by automated means of personal data which form part of a filing system or are intended to form part of a filing system’.
13. Article 4(6) of the GDPR defines ‘filing system’, for the purposes of that regulation, as ‘any structured set of personal data which are accessible according to specific criteria, whether centralised, decentralised or dispersed on a functional or geographical basis’.
14. Under Article 6 of the GDPR, entitled ‘Lawfulness of processing’:
‘1. Processing shall be lawful only if and to the extent that at least one of the following applies:
…
(f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
…’
15. Article 9 of the GDPR, entitled ‘Processing of special categories of personal data’ provides:
‘1. Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation shall be prohibited.
2. Paragraph 1 shall not apply if one of the following applies:
…
(d) processing is carried out in the course of its legitimate activities with appropriate safeguards by a foundation, association or any other not-for-profit body with a political, philosophical, religious or trade union aim and on condition that the processing relates solely to the members or to former members of the body or to persons who have regular contact with it in connection with its purposes and that the personal data are not disclosed outside that body without the consent of the data subjects;
…’
16. Article 17 of the GDPR, concerning the right to erasure (‘right to be forgotten’), provides:
‘1. The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller shall have the obligation to erase personal data without undue delay where one of the following grounds applies:
…
(c) the data subject objects to the processing pursuant to Article 21(1) and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant to Article 21(2);
(d) the personal data have been unlawfully processed;
…
3. Paragraphs 1 and 2 shall not apply to the extent that processing is necessary:
…
(d) for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) in so far as the right referred to in paragraph 1 is likely to render impossible or seriously impair the achievement of the objectives of that processing; …
…’
17. Article 21 of the GDPR, entitled ‘Right to object’, states, in paragraph 1 thereof:
‘The data subject shall have the right to object, on grounds relating to his or her particular situation, at any time to processing of personal data concerning him or her which is based on point (e) or (f) of Article 6(1), including profiling based on those provisions. The controller shall no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims.’
18. Article 89 of the GDPR, entitled ‘Safeguards and derogations relating to processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes’, states:
‘1. Processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, shall be subject to appropriate safeguards, in accordance with this Regulation, for the rights and freedoms of the data subject. Those safeguards shall ensure that technical and organisational measures are in place in particular in order to ensure respect for the principle of data minimisation. Those measures may include pseudonymisation provided that those purposes can be fulfilled in that manner. Where those purposes can be fulfilled by further processing which does not permit or no longer permits the identification of data subjects, those purposes shall be fulfilled in that manner.
2. Where personal data are processed for scientific or historical research purposes or statistical purposes, Union or Member State law may provide for derogations from the rights referred to in Articles 15, 16, 18 and 21 subject to the conditions and safeguards referred to in paragraph 1 of this Article in so far as such rights are likely to render impossible or seriously impair the achievement of the specific purposes, and such derogations are necessary for the fulfilment of those purposes.
3. Where personal data are processed for archiving purposes in the public interest, Union or Member State law may provide for derogations from the rights referred to in Articles 15, 16, 18, 19, 20 and 21 subject to the conditions and safeguards referred to in paragraph 1 of this Article in so far as such rights are likely to render impossible or seriously impair the achievement of the specific purposes, and such derogations are necessary for the fulfilment of those purposes.
…’
19. Article 91 of the GDPR, entitled ‘Existing data protection rules of churches and religious associations’, stipulates:
‘1. Where in a Member State, churches and religious associations or communities apply, at the time of entry into force of this Regulation, comprehensive rules relating to the protection of natural persons with regard to processing, such rules may continue to apply, provided that they are brought into line with this Regulation.
2. Churches and religious associations which apply comprehensive rules in accordance with paragraph 1 of this Article shall be subject to the supervision of an independent supervisory authority, which may be specific, provided that it fulfils the conditions laid down in Chapter VI of this Regulation.’
B. National law
20. Article 19 of the Belgian Constitution provides:
‘Freedom of worship, its public practice and freedom to demonstrate one’s opinions on all matters are guaranteed, but offences committed when this freedom is used may be punished.’
21. Article 21 of the Belgian Constitution reads as follows:
‘The State does not have the right to intervene either in the appointment or in the installation of ministers of any religion whatsoever or to forbid these ministers from corresponding with their superiors, from publishing the acts of these superiors, but, in this latter case, normal responsibilities as regards the press and publishing apply.
…’
III. Facts, procedure and the questions referred
22. On 26 June 1955, JM – the complainant in the proceedings before the Disputes Chamber of the Gegevensbeschermingsautoriteit / Autorité de protection des données (Data Protection Authority, Belgium; ‘the GBA’) ( 19 ) – was baptised in the Parish of Bijloke in Ghent (Belgium). By letter dated 25 March 2021, he contacted Bisdom Gent (Diocese of Ghent) to request that, in application of the GDPR, any reference to his person be deleted from any physical or digital register or archive.
23. Bisdom Gent then recorded JM’s departure from the Church on 2 April 2021, striking through but keeping the relevant personal data legible. On 7 April 2021, Bisdom Gent informed JM by letter that his withdrawal from the Roman Catholic Church had been noted on the list of church-leavers of the Parish of Ghent.
24. By letter dated 14 April 2021 to Bisdom Gent, JM expressed his dissatisfaction with this course of action and reiterated his request to have any personal data concerning him deleted from any physical or digital register or archive. That same day, JM filed a complaint with the GBA, stating his disagreement with the interpretation of the GDPR applied by Bisdom Gent and demanding that any connection between his person and any religion or organisation with a philosophical basis be erased.
25. By Decision No 169/2023 of 19 December 2023 (‘the contested decision’), the Disputes Chamber of the GBA found that Bisdom Gent had infringed the GDPR, in particular Article 5(1)(a) thereof, read in conjunction with Article 6(1)(f), as well as Article 5(1)(b) and (c), Article 9 and Article 12(1) to (4), read in conjunction with Articles 13 and 17. The Disputes Chamber decided on the basis, inter alia, of Article 58(2)(c) of the GDPR to order Bisdom Gent to comply with JM’s request of to exercise his right to object and his right to data erasure, in accordance with the requirements of Article 12 of the GDPR, and consequently to put an end to any unlawful processing of his personal data (Article 21(1) of the GDPR) as well as to proceed with the erasure of his personal data (Article 17(1)(c) of the GDPR) within 30 days of the notification of that decision.
26. Bisdom Gent brought an appeal against the contested decision before the hof van beroep te Brussel (Court of Appeal, Brussels, Belgium). That court, harbouring doubts as to the proper interpretation of the relevant provisions of EU law, decided to stay the proceedings and to refer the following questions to the Court of Justice for a preliminary ruling:
‘(1) Is Article 17 [of the GDPR], read in conjunction with the right to the protection of personal data as guaranteed by Article 8 of the [Charter], the freedom of thought[,] conscience and religion as guaranteed by Article 10 of the Charter and Article 9 [ECHR] and the principle of separation of Church and State as enshrined in Articles 19 and 21 of the Belgian Constitution, to be interpreted as meaning that a person who was baptised as a minor and who, as an adult, wishes to dissociate himself or herself from the Roman Catholic Church, has or does not have the right to have his or her personal data erased from the baptismal register?
(2) In that regard, does it make any difference for the purposes of Article 17(1)(c) [of the GDPR] that, according to the controller, the entry in the baptismal register affects the aforementioned fundamental rights (freedom of religion) of the controller and the Roman Catholic Church community it represents?
(3) Does it make a difference in that respect that this baptismal register is not digital, but a unique material carrier in the form of [a] book with [double-sided] pages in which details of other data subjects are also given on the back?
(4) Does it make a difference that the book itself is an historical artefact and that the baptismal register is a unique record of historical facts that are not recorded anywhere else, as a result of which the data processing also occurs for archiving in the public interest, scientific or historical research or statistical purposes within the meaning of Article 17(3)(d) [of the GDPR]?
(5) To the extent that there might be a right to data erasure within the meaning of Article 17(1) [of the GDPR] and in so far as there might not be an exception to this right within the meaning of Article 17(3) [of the GDPR], is the right to data erasure by analogy satisfied by the annotation that a person has left the church in the margin of the baptismal register?’
27. Written observations have been submitted by Bisdom Gent, the individuals who intervened in the main proceedings (JM, BZ, DF, RA, JD and FA), the GBA, the Czech, French, Italian, Latvian, Hungarian, Austrian and Romanian Governments, and the European Commission. At the hearing held on 30 June 2026, those parties, with the exception of the French, Hungarian and Romanian Governments, presented oral arguments as well as their answers to the written and oral questions put by the Court.
IV. Analysis
28. By its five questions, which can be examined together, the referring court asks the Court, in essence, whether Article 17(1) and (3) of the GDPR, read in the light of Articles 8 and 10 of the Charter, must be interpreted as meaning that an individual who was baptised as a minor and who, as an adult, wishes to dissociate himself or herself from the religious community in question ( in casu , the Roman Catholic Church), has the right to have his or her personal data erased from the baptismal register. If so, the referring court also wishes to know whether the mere annotation, in the margin of the baptismal register, that a person has left the religious community constitutes ‘erasure’ within the meaning of Article 17(1) and (3) of the GDPR.
29. In that regard, the referring court points out that (i) entries in the baptismal register affect the exercise of the activities of the religious community in question, and (ii) the baptismal register is not digital, but a unique material carrier in the form of a book with double-sided pages in which details of other data subjects are also recorded.
30. The present Opinion is structured as follows.
31. In the first part of the Opinion (A), I shall briefly explain why the GDPR is applicable in the case at issue in the main proceedings.
32. The second part of the Opinion (B) is devoted to the assessment of the circumstances which are relevant in order to establish whether the complainant can successfully rely on one of the grounds for erasure envisaged in Article 17(1) of the GDPR. Two of those grounds may be relevant in the present case. The first concerns the alleged unlawful processing of the complainant’s personal data by the controller, which will require a discussion of Article 6(1)(f) of the GDPR. The second ground concerns the complainant’s right, under Article 21 of the GDPR, to object to the processing of his or her personal data.
33. The third part of the Opinion (C), concerns the controller’s argument that, should the complainant be able to rely on one of the grounds for erasure set out in Article 17(1) of the GDPR, the further processing of the complainant’s personal data could nonetheless be justified, under paragraph 3 of that article, as necessary for, inter alia, archiving purposes in the public interest or for historical research purposes.
34. Finally, in the fourth part of the Opinion (D), I shall discuss the concept of ‘erasure’ for the purposes of the GDPR.
A. The applicability of the GDPR
35. A question which must be addressed at the outset arises as to whether the provisions of the GDPR are applicable in the main proceedings, since some of the parties who submitted observations expressed doubts in that respect.
36. The GDPR, according to Article 2(1) thereof, ‘applies to the processing of personal data wholly or partly by automated means and to the processing other than by automated means of personal data which form part of a filing system or are intended to form part of a filing system’.
37. In the light of the arguments raised in the parties’ written and oral submissions, four issues concerning the application of the GDPR ratione materiae , ratione personae and ratione temporis to the dispute in the main proceedings deserve a brief discussion.
38. First, in the light of the broad definition of ‘personal data’ set out in Article 4(1) of the GDPR, it is common ground that the baptismal register contains personal data of the individuals who have been baptised. Indeed, according to the Code of Canon Law, Canon (‘Can.’) 877 §1, ‘the pastor of the place where the baptism is celebrated must carefully and without any delay record in the baptismal register the names of the baptized, with mention made of the minister, parents, sponsors, witnesses, if any, the place and date of the conferral of the baptism, and the date and place of birth.’
39. Second, I am unconvinced by the arguments, put forward by Bisdom Gent and the Latvian Government, that the GDPR is not applicable in the main proceedings on the ground that the baptismal register is not a ‘filing system’ within the meaning of Article 4(6) of the GDPR. ( 20 )
40. In that respect, I would point out, first, that both recital 15 of the GDPR and the case-law of the Court make clear that the GDPR applies not only to the processing of personal data by automatic means, but also to the manual processin g of personal data. ( 21 ) In the latter case, however, the application of the GDPR presupposes that those data form part, or are intended to form part, of a filing system .
41. The term ‘filing system’ is defined in Article 4(6) of the GDPR as ‘any structured set of personal data which are accessible according to specific criteria, whether centralised, decentralised or dispersed on a functional or geographical basis’. No ‘specific manner in which a filing system must be structured and the form it must take’ is laid down by the GDPR. ( 22 ) In fact, as the Court has held, the very text of the provision (‘any’) and its objective (to ensure an equal level of protection irrespective of the techniques used to process the data ( 23 )) require a broad interpretation of the term. ( 24 )
42. The Court has found that what is crucial in that regard is whether, irrespective of the actual structure or form of a filing system, the personal data contained therein are arranged according to a particular logic so that they can be easily retrieved. ( 25 ) That purpose-driven understanding of the term corresponds to its technical and historical meaning: filing systems are indeed the nucleus of archival science, a field of knowledge and research which traces its origins back to ancient record-keeping on clay tablets and papyrus scrolls. ( 26 ) Standard methods to file and archive information and documents include alphabetical, numerical, chronological and subject-based systems.
43. It follows from the order for reference that baptisms in the Roman Catholic Church are recorded on the basis of a geographical criterion (in the register of the parish where they are celebrated ( 27 )) and, within the relevant register, they are recorded in chronological order (that is, according to the date of celebration). Baptismal registers thus contain a ‘structured’ set of personal data, of a decentralised nature, which allows easy retrieval of all the information concerning a specific baptism on the basis of the place and date of celebration.
44. The Latvian Government, however, emphasises the fact that the criteria employed to structure the filing system do not directly concern the data subjects who were baptised. In my view, that is immaterial. Unlike its predecessor, Directive 95/46/EC, ( 28 ) nowhere does the GDPR impose such a requirement, which would go against the broad interpretation given by the Court to the concept of ‘filing system’ and would partly frustrate the objectives of Article 4(6) thereof.
45. Nor is it of any relevance that the personal data contained in the registers are accessible to a very limited number of people, or that the retrieval of those data requires prior knowledge of some of the details of the event in question, which argument has been made by Bisdom Gent. Whether a ‘structured set of personal data’ constitutes a filing system within the meaning of Article 4(6) of the GDPR depends only on its objective features and not on the identity and/or number of the persons who can access it or their familiarity with the structure of the filing system or with the details of the event in question.
46. Consequently, baptismal registers constitute filing systems within the meaning of Article 4(6) of the GDPR.
47. Third, the GDPR applies, ratione personae , to entities such as churches and religious communities. As explained in points 6 to 9 above, the principles of autonomy and neutrality stemming from Article 17(1) TFEU do not call that into question. The case-law of the Court is quite clear in that regard. ( 29 ) In fact, a number of provisions of the GDPR are expressly concerned with the application of the regulation to churches and religious associations. ( 30 )
48. Fourth and lastly, it should be added, for the sake of clarity, that the relevant processing of the complainant’s personal data in the present proceedings is, quite clearly, not that relating to the first annotation of his personal data after the celebration of the baptism. That event largely pre-dates the entry into force of any EU rule on data protection. In that connection, I would point out that, under Article 91(1) of the GDPR, ‘where in a Member State, churches and religious associations or communities apply, at the time of entry into force of this Regulation, comprehensive rules relating to the protection of natural persons with regard to processing, such rules may continue to apply, provided that they are brought into line with this Regulation.’
49. Therefore, what is called into question in the present proceedings is the lawfulness of the data processing – in the form of storage and, where appropriate, retrieval and use ( 31 ) – in the light of the EU rules currently in force (namely the provisions of the GDPR, read in the light of the provisions of the Charter).( 32 ) In particular, the analysis below will focus on the period after the complainant requested that the controller erase his personal data from the baptismal register.
50. On the basis of the considerations above, it is clear that the GDPR is applicable in the main proceedings, as the GBA correctly held in the contested decision. ( 33 ) Accordingly, I shall now turn to the various legal issues which arise from the questions referred.
B. The grounds for erasure
51. At the heart of those questions lies the right to erasure (or ‘right to be forgotten’) which Article 17 of the GDPR grants to data subjects in certain circumstances. In short, the main question is whether, as the GBA determined in the contested decision, the complainant was, in the case at hand, entitled to rely on that provision in order to require the data controller ( in casu , Bisdom Gent) to delete his personal data contained in the baptismal register.
52. It should be recalled that Article 17(1) of the GDPR lists six alternative grounds on which the data subject is to have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller is to have the obligation to erase personal data without undue delay.
53. In the main proceedings, the complainant and the GBA referred to the grounds set out in Article 17(1)(c) and (d) of the GDPR. Point (c) concerns the situation in which the data subject objects to the processing pursuant to Article 21(1) of the GDPR and there are no overriding legitimate grounds for the processing, while point (d) concerns the situation in which the personal data of the data subject have been unlawfully processed. In the present case, the lawfulness of the processing depends on whether data processing was, in accordance with Article 6(1)(f) of the GDPR, necessary for the purposes of the legitimate interests pursued by the controller and which were not overridden by the interests or fundamental rights and freedoms of the data subject which required protection. ( 34 )
54. Those two grounds will be examined in turn, starting with the ground set out in Article 17(1)(d) of the GDPR. The Court has in fact made clear that ‘the applicability of Article 21 of the GDPR and, consequently, the possible existence of a right to object presuppose the existence of lawful processing’. ( 35 )
55. This order of analysis also reflects the logic underpinning the two grounds for erasure of personal data. In essence, both grounds require, at some stage in the legal assessment, the balancing of the opposing rights and interests at stake: those of the data controller, on the one hand, and those of the data subject, on the other. Ideally, those rights and interests should be reconciled. Failing that, however, it may be necessary to determine which ones, in a specific set of circumstances, must prevail. ( 36 ) Depending on the ground for erasure relied upon, that exercise may yield different results. That follows from the differing rationales and natures of the two grounds in question here.
56. Article 17(1)(d) of the GDPR is largely a backward-looking provision which essentially allows a data subject to react to their personal data having been unlawfully processed. It should not be overlooked that, under the provisions of the GDPR, a controller must be able to demonstrate that processing is performed in accordance with the provisions of that regulation at any time. ( 37 ) In fact, when processing is based on Article 6(1)(f) of the GDPR, it is essential that, in order to ensure lawful processing, the controller weigh up the various competing interests even before any processing is done. By definition, the controller may be unaware at that stage of the specific circumstances pertaining to each and every individual whose data will be processed. ( 38 )
57. The balancing referred to in the preceding point must, accordingly, take place at a relatively broad level, by primarily focusing on the rights and interests of the data subjects concerned as a whole. The test to determine the processing’s lawfulness is strict but, as will be explained below, not as strict as that applicable under Article 17(1)(c).
58. Article 17(1)(c) of the GDPR is more a forward-looking provision, enabling data subjects to oppose future processing of their data, for reasons relating to their own specific situation. The balancing is, accordingly, to be carried out when the data controller becomes aware of the data subject’s objection and the reasons therefor. In such a case, whilst all the general factors taken into account under Article 6(1)(f) of that regulation remain relevant, this ex post evaluation supplements them with other factors that are specific to the data subject having objected to the processing. ( 39 ) The balancing under Article 17(1)(c) is, in fact, centred on ‘the circumstances surrounding the data subject’s particular situation’. ( 40 )
59. There is another important difference between the two provisions: the test to be met by the data controller in order to justify the processing of data, despite the objection of the data subject, is particularly stringent. Indeed, when a data subject objects under Article 21(1) of the GDPR, only ‘ compelling legitimate grounds’ may override the interests and rights of the data subject concerned. ( 41 ) In addition, Article 21(1) of the GDPR introduces a presumption in favour of the data subject: ( 42 ) after the objection is communicated to the controller, the latter ‘shall no longer process the personal data unless [it] demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject’. ( 43 )
60. It seems to me that such a distinction between the type of assessment required when there may have been unlawful processing, on the one hand, and when a data subject objects to a (presumably lawful) processing, on the other hand, is already apparent from the judgment in Google Spain . ( 44 ) My understanding of Article 17(1) of the GDPR is also borne out by the clear wording of the provision: point (d) uses a verb in the perfect tense (‘have been … processed’), whereas point (c) uses a verb in the present tense (‘objects’). ( 45 )
61. In the light of the foregoing, in the following sections I shall first examine whether the controller has, before becoming aware of the complainant’s objection , lawfully processed the complainant’s personal data (1). Thereafter, I shall assess the possibility for the complainant of objecting to the processing of his personal data (2).
62. Before doing so, an observation of a systemic nature must be made. It follows from the case-law that, in both scenarios, it is in principle for the referring court to make the final assessment as to whether a data subject has the right to request erasure of his or her personal data. ( 46 ) It is, in particular, for that court to weigh up the competing rights and interests referred to above, in the light of the criteria and factors established by the relevant case-law of the Court of Justice. ( 47 ) Indeed, the outcome of that assessment depends on the specific circumstances of each situation, ( 48 ) which are thus best assessed on a case-by-case basis.( 49 ) Nevertheless, it is open to the Court, when giving a preliminary ruling on a reference, to give clarifications to guide the national court in that determination. ( 50 )
1. The lawful processing of personal data
63. The lawful or unlawful nature of the processing of personal data depends, generally, on whether the conditions set out in the following two provisions of the GDPR are satisfied. ( 51 )
64. First, Article 5 of that regulation, which lays down a number of key principles relating to the processing of personal data (in particular, the requirements that data are ‘processed lawfully, fairly and in a transparent manner’ and, moreover, ‘adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed’). The latter principle – that of data minimisation – will be of particular importance in the legal analysis here. ( 52 )
65. Second, Article 6 of that regulation sets out an ‘exhaustive and restrictive’ list of the cases in which data processing is lawful. ( 53 ) As the Court has made clear, the six scenarios envisaged therein are alternatives ( 54 ) and must be interpreted restrictively ( 55 ) in the light of the principles laid down in Article 5 of the GDPR. ( 56 )
66. In the present case, there is also a third provision which is relevant: Article 9 of the GDPR, which concerns the processing of special categories of personal data. In particular, Article 9(1) provides that the processing of personal data revealing, inter alia, religious or philosophical beliefs is in principle prohibited. However, Article 9(2)(d) states that that prohibition does not apply where ‘processing is carried out in the course of its legitimate activities with appropriate safeguards by a foundation, association or any other not-for-profit body with[, inter alia, a religious aim] and on condition that the processing relates solely to the members or to former members of the body or to persons who have regular contact with it in connection with its purposes and that the personal data are not disclosed outside that body without the consent of the data subjects’.
67. It is apparent that, in so far as the processing of personal data by the Church (i) concerns individuals who have been baptised, and (ii) is carried out for purposes that are related to its ordinary religious activities (such as the proper administration of sacraments, which will be discussed below), the conditions set out in Article 9(2)(d) are met. In particular, the personal data of the individuals in question are only accessible to a restricted number of persons belonging to the Church, and there are safeguards in place to avoid unauthorised access (for example, they are kept in locked safes or dedicated rooms). Accordingly, and subject to confirmation by the referring court, the prohibition of processing set out in Article 9(1) of the GDPR does not, in my view, apply to the processing of personal data such as that at issue in the main proceedings.
68. This means that the key issue is whether any of the grounds for lawful processing set out in Article 6 of the GDPR is applicable. It is not disputed that Bisdom Gent’s processing of the complainant’s personal data is not based on consent. However, Bisdom Gent argues that such processing is lawful under Article 6(1)(f) of the GDPR. That provision authorises the processing of personal data that is ‘necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child’.
69. According to settled case-law, that provision lays down three cumulative conditions for the processing of personal data to be lawful: (i) the pursuit of a legitimate interest by the data controller or by a third party; (ii) the need to process personal data for the purposes of the legitimate interests pursued; and (iii) the interests or fundamental freedoms and rights of the person concerned do not take precedence over the legitimate interest of the controller or of a third party. ( 57 )
(a) Pursuit of a legitimate interest
70. As regards the first condition, the Court has held that, in the absence of a definition of the concept of ‘ legitimate interest ’ in the GDPR, a wide range of interests is, in principle, capable of being regarded as legitimate. In particular, that concept is not limited to interests enshrined in and determined by law. ( 58 )
71. In its Guidelines 1/2024, the EDPB took the view that, in order to be ‘legitimate’, an interest of the data controller should be lawful (that is, not contrary to EU or Member State law); clearly and precisely articulated (to ensure it may be balanced against the rights and interests of the data subjects); and real and present, not speculative. ( 59 ) It is apparent that those three criteria find clear support in the case-law and are, indeed, of particular relevance to the present analysis. ( 60 )
72. In the present case, Bisdom Gent states that the main purpose of the processing is to ensure a proper administration of the sacraments, which requires an accurate record of those which have been administered to each member of the Church. In particular, Bisdom Gent stresses that, in principle, baptism can be administered only once and it is thus necessary to prevent believers from being baptised twice.
73. In the contested decision, the GBA accepted that such an objective could be considered a ‘legitimate interest’ for the purposes of Article 6(1)(f) of the GDPR. None of the parties that submitted observations in the present proceedings has raised any doubts in that regard.
74. I too agree with the GBA. Sacraments are religious rites of the utmost importance for the Roman Catholic Church. Baptism, one of the seven sacraments recognised by that church, is of particular significance. The Code of Canon Law refers to it as ‘the gateway to the sacraments’. ( 61 )
75. As the Court has emphasised, the right to freedom of conscience and religion enshrined in Article 10(1) of the Charter includes the freedom, either alone or in community with others and in public or in private, to manifest religion or belief, in worship, teaching, practice and observance. In fact, the term ‘religion’ in the Charter must be understood in a broad sense, covering both the forum internum , that is, the fact of having a belief, and the forum externum , that is, the manifestation of religious faith in public. The celebration of religious rites, such as is the administration of the sacrament of baptism, falls within the scope of the forum externum of that freedom. ( 62 )
76. In the light of the principles of neutrality and autonomy enshrined in Article 17(1) TFEU, ( 63 ) it thus stands to reason that the interest to ensure that sacraments, including baptism, are administered correctly is considered legitimate within the meaning of Article 6(1)(f) of the GDPR. That interest meets the three criteria set out in point 71 above: it is lawful, sufficiently specific and not hypothetical.
(b) Necessity of data processing
77. As regards the second condition, the requirement of necessity, the Court has consistently stated that it ‘is not met where the objective pursued by [the] processing of data could reasonably be achieved just as effectively by other means less restrictive of the fundamental rights of data subjects … since derogations and limitations in relation to the principle of protection of such data must apply only in so far as is strictly necessary’. ( 64 ) In that context, it should be borne in mind that ‘the condition relating to the need for processing must be examined in conjunction with the data minimisation principle enshrined in Article 5(1)(c) of the GDPR, in accordance with which personal data must be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed’. ( 65 )
78. The requirement of necessity has two complementary and closely related components. ( 66 ) First, it is important to ensure that the measure is appropriate in order to achieve the objective pursued. Clearly, a measure incapable of achieving its aim cannot be regarded as being ‘strictly necessary for the attainment of that legitimate interest’. Second, it should be ascertained whether the measure is essential : processing cannot be considered necessary if the interest pursued by the data controller can ‘reasonably be achieved just as effectively by other means less restrictive of the fundamental freedoms and rights of data subjects’. ( 67 )
79. In the present case, it could be argued that, as long as a person is associated (or may reasonably be presumed to be associated) with a religious community, that community may legitimately consider it necessary to keep accurate records of the sacraments administered to him or her. In particular, the storage of the relevant personal data of the believers having been baptised contributes directly towards the pursuit of the objective of ensuring a correct administration of sacraments.
80. In addition, despite the possible existence of alternative measures that may be less intrusive with the rights and interests of the data subjects in question, ( 68 ) the storage of the personal data in the baptismal register appears, to my mind, a more effective measure to take with regard to all the persons who belong to the religious community. The processing is, after all, also made in the interest of the data subjects themselves, who may need to provide proof of baptism when requesting the administration of other sacraments. An overly stringent application of the requirement of necessity therefore appears, in this context, to be unwarranted. ( 69 )
81. Accordingly, subject to confirmation by the referring court, a number of elements would appear to corroborate the necessity of the processing, within the meaning of Article 6(1)(f) of the GDPR.
(c) Balance of interests
82. Lastly, the condition that the interests or fundamental rights and freedoms of the person concerned by the data processing do not take precedence over the legitimate interests of the controller or of a third party requires that national courts weigh up and strike a balance between the competing rights and interests.
83. Metaphorically speaking, the referring court will have to place, on the one side of the scales, the data subject’s rights and interests adversely affected by the further processing, and, on the other side of the scales, the controller’s rights and interests that would be adversely affected by putting a stop to the processing.
84. The text of the GDPR and the case-law of the Court provide some guidance on how that exercise should be performed.
85. Among the factors to be considered is, first, the ‘ reasonable expectations of data subjects, based on their relationship with the controller … at the time and in the context of the collection of the personal data that processing for that purpose may take place. The interests and fundamental rights of the data subject could in particular override the interest of the data controller where personal data are processed in circumstances where data subjects do not reasonably expect further processing’. ( 70 )
86. Moreover, the scale of processing and its impact on the rights and interests of the data subjects are of major importance. ( 71 ) As regards the latter element, although there is no requirement to establish any form of prejudice caused to the data subject, ( 72 ) it would naturally be of particular relevance were they to be exposed to physical, material or non-material damage, ( 73 ) including emotional distress. ( 74 )
87. The large number of persons who have access to the personal data in question and, where relevant, the wide-ranging effects of dissemination that their processing may have could potentially increase the seriousness of the interference with the rights of the data subject in question. ( 75 ) By contrast, in some cases, the seriousness of the impact could be seen as minor if the data processed are publicly available, depending on the extent to which those data already appear in public sources.( 76 ) Moreover, evaluating the actual impact of the processing of the data in question is not a one-sided type of exercise: the possible benefits that the data subjects concerned draw from the processing should, naturally, also be added to the equation. ( 77 )
88. Furthermore, the balancing of the competing interests requires particular caution when the data processed belong to a special category, within the meaning of Article 9 of the GDPR (such as those revealing religious or philosophical beliefs), ( 78 ) or when they concern a child, as expressly provided in Article 6(1)(f) of the GDPR. ( 79 ) Similarly, data processing over long periods of time may also need special vigilance from the controller, since the passing of time may well affect both the interests of the controller in the processing of the data, and the impact of the processing of those data on the rights and interests of the data subjects in question. ( 80 )
89. At the same time, the existence of appropriate safeguards against unlawful access and processing, in order to ensure the integrity and confidentiality of the data, may also be relevant in this context. ( 81 )
90. As has been explained above, it is for the referring court to weigh up and strike a balance between the competing interests, in the light of the criteria set out above. In the present case the following factors merit particular consideration, in my view.
91. On the one hand, it is true that the processing involves a special category of data which, moreover, often involve children. It is likewise clear that the processing interferes with several fundamental rights of the data subjects concerned.
92. First, the processing of an individual’s personal data which concern very private matters, such as the date and place of birth, family links and religious beliefs, interferes with that individual’s privacy. Moreover, since the processing of those data may take place without that individual’s consent, and it is not a one-off or occasional occurrence but could potentially occur repeatedly over the course of that individual’s lifetime, it clearly affects his or her right of self-determination with regard to the use of such data. The interference with the data subject’s rights to respect for private and family life (Article 7 of the Charter) and protection of personal data (Article 8 of the Charter) is thus undeniable.
93. Second, if an individual is baptised during childhood and did not, therefore, consent to the data processing, such processing occurs irrespective of whether the individual concerned considers himself or herself part of the religious community in question. As the ECtHR has found, ‘the right to manifest one’s religion or beliefs also has a negative aspect, namely an individual’s right not to be obliged to disclose his or her religion or beliefs and not to be obliged to act in such a way that it is possible to conclude that he or she holds – or does not hold – such beliefs’. ( 82 ) Data processing, thus, interferes also with the freedom of thought, conscience and religion (Article 10 of the Charter) of the data subject concerned.
94. On the other hand, however, I have explained why the controller carries out the data processing in question in the pursuit of a legitimate interest that is also protected by Article 10 of the Charter.
95. Moreover, so long as the data subject concerned can be presumed to be part of the religious community in question, a number of elements appear to point to the absence, a priori, of any significant adverse interference with that data subject’s fundamental rights.
96. First of all, it seems reasonable to consider that a person who has been baptised would normally expect his or her personal data to be kept on the baptismal register, at least as long as that person considers himself or herself a member of that religious community. Next, the scale of processing, in terms of the amount of data processed (those relevant to the identification of the person baptised) and the number and type of operations performed (mainly storage of the data and access thereto when necessary), is quite limited. The number of persons with access to that information is also limited, and there are safeguards in place to prevent unauthorised access.
97. Furthermore, even when the data concern a child, the decision to have their personal data processed following the baptism is, presumably, consciously taken by the parents or legal guardians of that child and constitutes an expression of their right to ensure that their children are raised in line with their religious and philosophical convictions. ( 83 )
98. Last but not least, the storage of the personal data of baptised individuals is, arguably, also made in the interest of those individuals, who could be required to provide proof of the baptism should they wish to receive other sacraments (such as confirmation or religious marriage).
99. In the light of the foregoing, and subject to verification by the referring court, it would appear that the processing of the personal data of the complainant by the Church, before he formally objected to it, could be regarded as being in compliance with Article 6(1)(f) of the GDPR. If that were indeed the case, it would mean that the complainant could not request erasure of his personal data on the basis of Article 17(1)(d) of the GDPR before Bisdom Gent was informed of his objection to the processing of his data.
100. The assessment of whether the complainant may request erasure by objecting to the processing is a question that must be addressed on the basis of Article 17(1)(c) of the GDPR. That provision makes reference to Article 21(1) thereof.
2. T he data subject objects to the data processing
101. Article 21(1) of the GDPR grants the data subject the right to object, on grounds relating to his or her particular situation, at any time, to processing of personal data concerning him or her, which right is based, inter alia, on Article 6(1)(f) thereof, as is the case in the main proceedings. However, that provision allows the controller to continue processing the data, inter alia, if it ‘demonstrates compelling legitimate grounds … which override the interests, rights and freedoms of the data subject’.
102. As mentioned above, Article 21(1) of the GDPR sets out a rather stringent test that the controller has to satisfy in order to justify processing personal data in spite of the data subject’s objection thereto. That provision permits the controller to disregard the objection only where it demonstrates compelling grounds that justify processing, and the burden of proof in that respect lies with the controller. Indeed, the default rule is that, when faced with an objection, the controller must halt the processing (‘the controller shall no longer process the personal data unless …’). ( 84 )
103. At this stage, it may be useful to consider the meaning of the term ‘compelling’. The GDPR does not define it, nor is it entirely clear from the text of the provision what that adjective refers to exactly. It could refer to the ‘legitimate grounds’: the grounds relied upon by the controller would then not need to be only ‘legitimate’ but also essential or vital to the activity of the controller. ( 85 ) However, it could also refer to a compelling need on the part of the controller to process the data. Although Article 21(2) of the GDPR omits an explicit reference to the necessity requirement, it remains an essential factor in the analysis. ( 86 ) Lastly, it could also simply be intended to reflect the significant weight that the data subject’s rights and interests must have when they are weighed against those of the controller. ( 87 )
104. To my mind, all three standpoints outlined above are correct: the term ‘compelling’ permeates the assessment of the three requirements. That term, along with the equivalent expressions used in the other language versions of the regulation, ( 88 ) is clear in that it reflects a requirement of cogency and forcefulness of the reasons which authorise the controller to disregard the clear will of the data subject concerned.
105. As the EDPB states in its Guidelines 1/2024, that term implies a higher threshold to meet for the data controller than that applicable under Article 17(1)(d) of the GDPR. ( 89 ) That interpretation is expressly confirmed by the case-law. The Court has ruled that, when faced with an objection under Article 21(1) of the GDPR, it is only ‘exceptionally’ that a national court may find the existence of overriding legitimate grounds capable of justifying the processing in question. ( 90 )
106. After all, if the test under point (c) of Article 17(1) of the GDPR were not stricter than that set out in point (d) thereof, it would mean that no processing validly based on Article 6(1)(f) of that regulation could ever be objected to by the data subject in question. ( 91 ) That would render Article 21(1) of the GDPR partly ineffective, and would call into question the Court’s finding that the right to object presupposes the existence of lawful processing. ( 92 )
107. That particularly stringent test reflects the basic principle that lies at the very heart of the body of rules that is the GDPR: the processing of personal data is prohibited unless expressly authorised. Article 6(1) thereof is clear in that regard: ‘processing shall be lawful only if and to the extent that at least one of the following [exceptions] applies …’. ( 93 ) And those exceptions must be interpreted restrictively, as the Court has repeatedly stated. ( 94 )
108. The underlying idea, as follows from recital 7 of the GDPR, is that ‘natural persons should have control of their own personal data.’ Article 21 of the GDPR is a direct expression of that principle. ( 95 ) Against that backdrop, it is self-evident that the processing of the personal data of an individual who has not only never consented to the processing, but has even expressly objected to it, requires special justification. This is consistent with the main objective of the GDPR: to ensure a high level of protection of the fundamental rights and freedoms of natural persons, in particular their rights to privacy and to protection of their personal data, as enshrined in Articles 7 and 8 of the Charter and Article 16(1) TFEU. ( 96 )
109. If that is indeed the case, then it stands to reason to consider the adjective ‘compelling’ as being of particular relevance across the three steps of the legal assessment which the referring court is required to conduct: an evaluation of the interest invoked by the controller, the need for processing, and balancing of the competing rights and interests at stake.
110. In the light of the foregoing, whether the complainant could, in the case at hand, successfully oppose the processing of his personal data on the basis of Article 17(1)(c) of the GDPR requires a careful assessment which is, to my mind, far more complex than that made above with respect to the lawfulness of the processing in question.
(a) Compelling legitimate grounds
111. First, as regards the condition requiring the controller to demonstrate ‘compelling legitimate grounds’ for the processing, I agree with the EDPB that the grounds invoked for that processing ‘should be essential to the controller (or to the third party in whose legitimate interest the data are being processed) to be considered compelling’. ( 97 )
112. In other words, the mere fact that the interest pursued by the controller in the processing is lawful is not sufficient. As I see it, that interest must be considered worthy of particular protection under EU or national law, and the pursuit of that interest directly tied to one of the controller’s core functions.
113. I find it difficult to draw a clear distinction between interests which may give rise to ‘compelling legitimate grounds’ and those which may not. Indeed, they cannot be assessed in the abstract but only at a more concrete and specific level, in the circumstances of each case. That said, I should add that, for example, interests which relate to the protection of human dignity, human health or the environment are, in my view, more likely to meet the test than the pursuit of a mere commercial interest. ( 98 ) Yet again, not all interests which are trade-related or of an economic nature are equal: for instance, the interest consisting in honouring an existing contract appears more worthy of protection than the interest consisting in setting up an effective marketing strategy. ( 99 ) In addition, since the pursuit of commercial goals constitutes the very raison d’être of certain entities, restricting their data processing capacity may, at times, undermine their fundamental activities.
114. In the present case, as has already been discussed, the controller argues that the processing of the personal data concerned is necessary in order to ensure the correct administration of sacraments. That is an interest intrinsically linked to the exercise of the forum externum of the freedom of religion and to the need to ensure the operational autonomy of religious communities. Those are rights and interests of great significance in the legal systems of both the European Union and the Member States. Moreover, there is an obvious nexus between the Church’s spiritual mission and the correct administration of sacraments.
115. Therefore, the interest relied on by Bisdom Gent can, in principle, be regarded as being ‘compelling’ within the meaning of Article 21(1) of the GDPR.
(b) Necessity of data processing
116. I shall turn now to the condition consisting in the need for that processing in order to pursue the stated objective. I would observe, as a preliminary point, that the reasons relied upon for the processing can hardly be considered ‘compelling’ unless the requirement that that processing be appropriate to attaining its objective and that it be proportionate is carefully verified. As the EDPB correctly notes, ‘showing that the processing would simply be beneficial or advantageous to the controller would not necessarily meet [that] threshold’. ( 100 ) A fortiori, a subjective preference on the part of the controller cannot amount to a pressing need to perform a data processing activity. ( 101 )
117. In my view, what is crucial in that regard is whether losing the ability to process the personal data in question would, for the controller, critically endanger its ability to carry out its mission as defined in its statutes. In a case such as the one at hand, that would mean determining whether depriving Bisdom Gent of its capacity to store and retrieve the complainant’s personal data would seriously hinder its spiritual mission.
118. The assessment is, admittedly, a complex one.
119. On the one hand, it is reasonable that, given the significance that sacraments – and baptism first and foremost – have for the Catholic doctrine, the Church may consider it important to keep its records as intact and complete as possible. From the Church’s point of view, it seems logical that, considering baptism to be a ‘once-in-a-lifetime’ sacrament and a gateway to future sacraments, the personal data of an individual who has been baptised may not be erased even where that individual intends to sever his or her ties with the Church. As I understand it, according to the doctrine of the Roman Catholic Church, the effects of baptism are permanent. Viewed from that perspective, it is arguably more accurate simply to add, on the baptismal register, the information concerning that person’s intention not to be part of the Church any longer.
120. It may be worth pointing out, in that context, that Article 9(2)(d) of the GDPR expressly recognises that a body with a philosophical or religious aim might need to process personal data of both its current and former members.
121. On the other hand, however, a number of factors appear to suggest that losing the ability to process the complainant’s personal data might, perhaps, not seriously hinder Bisdom Gent’s capacity to accomplish its spiritual mission.
122. In the first place, the scenario in which the complainant might wish, in future, to re-join the Church and, in that context, receive further sacraments is clearly possible, albeit not very likely given the age at which the complainant exercised his rights under the GDPR and the reasons given for his request for erasure of his personal data. ( 102 ) In any event, recital 64 of the GDPR states that ‘a controller should not retain personal data for the sole purpose of being able to react to potential requests .’ ( 103 )
123. In the second place, it is not entirely clear in which circumstances there could be a real risk that a person such as the complainant might be baptised twice. When asked at the hearing to clarify its arguments, Bisdom Gent was unable to provide specific examples of situations in which such a risk would be both plausible and likely to occur.
124. Arguably, there are two scenarios in which the erasure of a data subject’s personal data could give rise to legal uncertainty, potentially resulting in a double baptism: (i) a person may want to re-join the Church and, to that end, asks to be baptised for a second time; or (ii) a person may want to re-join the Church, and its ministers, unaware of his or her first baptism, require that the data subject be baptised again.
125. In the first scenario, I understand that, given the lack of a centralised filing system, there is nothing to preclude an individual who has already been baptised from being baptised for a second time, in a different parish, if the individual in question really wishes to do so. ( 104 ) Indeed, it would be sufficient, for that individual, to choose a parish in which the religious ministers have no knowledge of where and when he or she could have already received the sacrament of baptism. Indeed, without the cooperation of the individual concerned or information from other individuals familiar with the situation, the question of whether a person has already been baptised cannot readily be answered. This appears to be confirmed by the detailed analysis of this point made by the GBA in the contested decision. ( 105 )
126. It is, however, for the referring court to determine whether or not the storage of the data relating to the baptism of a person such as the complainant is actually appropriate in order to achieve the objective pursued in the first scenario.
127. In the second scenario – where a person wishing to re-enter the church is asked to prove his or her first baptism, for example in order to enter into a religious marriage – he or she would, arguably, be able to produce various forms of evidence in that regard. There are various provisions in the Code of Canon Law on this matter. ( 106 ) Alternatively, the person could probably prove his or her baptism by producing the correspondence exchanged with the relevant parish on the basis of which his or her personal data were erased from the baptismal register. ( 107 )
128. In the light of the foregoing, the referring court should also verify whether, as the complainant argues, keeping the baptismal records fully intact goes beyond what is necessary to prove that baptism has been administered to a specific individual.
129. Lastly, there is another factor that the referring court may wish to take into account in order to rule on the ‘necessity’ of the processing. As confirmed by Bisdom Gent, there are circumstances in which the Code of Canon Law exceptionally permits baptism potentially to be administered to a person twice. One example is ‘conditional baptism’, ‘if there is a doubt whether a person has been baptised or whether baptism was conferred validly’. ( 108 )
(c) Balance of interests
130. Lastly, the assessment to be conducted by the referring court when balancing the different rights and interests at stake also appears to be quite complex. The crux of the matter is, as has been explained above, how to weigh up two sets of competing interests and rights that are, in the EU legal order, both considered worthy of significant protection: on the one hand, the complainant’s right to respect for private and family life, his right to protection of personal data, and his freedom of thought, conscience and religion; on the other hand, the autonomy of the Church and its freedom of thought, conscience and religion.
131. Before discussing the balancing of those rights and interests under Article 21(1) of the GDPR in more detail, I should say, from the outset, that in my view none of those interests should systematically prevail over the others. That would render the protection of the rights and interests of either the data subject or the religious community illusory. ( 109 )
132. Therefore, I cannot agree with the position taken on this matter by certain parties which submitted observations, for example the Commission. In essence, those parties give little or no consideration to the rights and interests of the data subjects concerned, arguing that, irrespective of the specific situation of those individuals, the balancing of the competing interests had to be resolved in favour of the rights and interests of the controller.
133. However, that is manifestly not what is provided for in Article 21(1) of the GDPR. This point should be emphasised: the outcome of the weighing up of those interests cannot be determined a priori by simply interpreting the relevant rules of EU primary and secondary law in the abstract. Article 21(1) of the GDPR requires that the competent authority or court examine the specific circumstances of each case. The wording of the provision is clear in that respect (the right to object is exercised ‘on grounds relating to his or her particular situation’) and the case-law of the Court confirms it. ( 110 )
134. As the EDPB states, ‘the presence of compelling legitimate grounds needs to be assessed on a case-by-case basis and be linked to a specific objection .’ ( 111 ) I agree. The reasons given by the data subject for his or her objection to the processing can be quite revealing as to the possible impact that a refusal by the controller could have on that data subject. A national court may, for example, draw inferences from an unsubstantiated or poorly reasoned objection, or one based on frivolous arguments. By contrast, an objection rooted in the data subject’s specific situation and backed by serious moral grounds demands a more careful assessment.
135. Moreover, the wording of Article 21(1) of the GDPR also demonstrates the clear intention on the part of the EU legislature to confer enhanced protection on the rights and interests of data subjects when they object to the processing of their personal data. Once again, the case-law of the Court confirms this. ( 112 )
136. Having clarified the points set out above, I shall now discuss some of the factors that the referring court may wish to take into account in its review under Article 21(1) of the GDPR.
137. On the one hand, the referring court should consider the impact that the erasure of the complainant’s personal data could have on the interest pursued by the controller: ensuring the correct administration of the sacraments. That interest constitutes, first, the exercise, by the members of the Church, of their right ‘in community with others … to manifest … religion or belief, in worship, teaching, practice and observance’, as stipulated in Article 9 ECHR. That interest is also an expression of the Church’s autonomy, intended as a religious association enjoying the right of self-organisation under the combined reading of Articles 10 and 12 of the Charter and Article 17(1) TFEU. Those provisions protect the internal life of religious associations from unjustified public interference. ( 113 ) In short, the crucial point is the degree to which halting the data processing and erasing the personal data in question would seriously hinder the aforementioned activities.
138. On the other hand, the referring court should consider the level of interference that the continuous processing of personal data could constitute with the complainant’s enjoyment of his fundamental rights.
139. It is true that, as set out above, the scale of the processing, in terms of both the amount of data processed and the number and type of operations performed, is rather limited, as is also the group of persons authorised to process those data. However, it does not necessarily follow from this that the processing can only produce a limited impact on the data subject’s enjoyment of his or her fundamental rights. In fact, in the present case, a number of factors suggest a level of interference of a certain significance.
140. In the first place, the referring court should examine whether a person who intends to sever all ties with a religious community could nonetheless reasonably expect that such a community will continue to store his or her personal data for the entire duration of his or her life and, possibly, also beyond.
141. In the second place, the fact that the complainant never consented to the processing at the time when his data were first recorded in the register, since he was baptised as a child , may also carry a lot of weight. As explained above, the processing of a child’s data flows from a decision adopted by his or her parents or legal guardians which constitutes an exercise of their right to ensure the education of their children in conformity with their religious and philosophical convictions.
142. However, it is doubtful that parental authority extends to making religious decisions that create a permanent, irreversible ‘lock-in’ effect for the child. Indeed, the decision of the parents to have their child baptised would de facto give the religious community a far-reaching ability to process the data for the entirety of that child’s life. Even in adulthood, that person would never be able to withdraw his or her parents’ (implicit or express) consent to the processing of his or her data, ( 114 ) notwithstanding the sensitive nature of those data, which reveal his or her religious beliefs. ( 115 )
143. My doubts on this point are compounded by recital 65 of the GDPR, according to which ‘[the data subject’s right to have his or her personal data erased and no longer processed] is relevant in particular where the data subject has given his or her consent as a child and is not fully aware of the risks involved by the processing, and later wants to remove such personal data, especially on the internet. The data subject should be able to exercise that right notwithstanding the fact that he or she is no longer a child.’ It could then be argued that such a principle should a fortiori be applicable in cases where the child, either at baptism or even later, has never given consent to the processing of his or her personal data. ( 116 )
144. In the third place, and most importantly, the assessment of the actual impact that the further processing may have on the data subject’s psychological (and, in some cases, possibly physical) integrity and wellbeing is another factor of the utmost importance.
145. In that regard, the Commission expressed the view at the hearing that the impact produced on the data subjects concerned by the processing would necessarily be minimal , especially since the data in question are not made public by the Church.
146. I disagree.
147. To begin with, the Commission is, in my view, not in a position to assess, in full knowledge of the facts, the actual impact that a refusal to halt the processing of the data and erase them may have on a given individual exercising his or her rights under the GDPR. The situations may differ greatly, and it is naturally for the referring court to make that assessment, in the light of all relevant circumstances of fact and law.
148. In addition, that argument appears to be based on a misunderstanding. In a case such as that at issue here, the possible harm that the controller’s refusal might cause to the data subjects in question (for example, in the form of emotional distress) does not stem from the fact that other persons may perceive them as belonging to a religious community with which they are not associated. The alleged harm appears to be of a different nature.
149. It should be recalled that the freedom of thought, conscience and religion, enshrined in Article 10 of the Charter, also includes the ‘freedom to change religion’ or belief. ( 117 ) Such freedom entails that of holding or not holding religious beliefs and of practising or not practising a religion, and must thus be regarded as ‘a precious asset for atheists, agnostics, sceptics and the unconcerned’.( 118 )After all, Article 10 of the Charter sets out, first and foremost, a right of self-determination , which is of central importance to the individual’s identity, moral integrity, maintenance of relationships with others, and a settled and secure place in the community. ( 119 )
150. Consequently, it cannot be ruled out that some data subjects might suffer emotional distress as a result of the fact that a religious community, to which they belonged in the past, decides to process their personal data in perpetuity, citing doctrinal tenets regarding the permanent and indissoluble nature of baptism. It is the right of the data subjects to self-determination that is negatively affected by the processing, and not, as the Commission implied, simply their public image or perception.
151. In addition, it cannot be excluded that there may be circumstances in which the actual impact which the controller’s refusal may have on the data subject could go further than that, resulting in a significant interference with another fundamental right of the individual: the right to respect for physical and mental integrity, enshrined in Article 3(1) of the Charter.
152. There is some force in the argument, put forward by some of the parties which submitted observations, that a person who has experienced traumatic incidents in his or her interactions with other members of a religious community could suffer severe psychological (or, in extreme cases, even physical ( 120 )) harm from the awareness that that community continues to store his or her personal data, considering their bond to be enduring. In forensic psychology, the idea that some victims may need to find some specific form of ‘closure’ of their past experiences is widely discussed. ( 121 ) It is thus plausible that, in some cases, it might be important for the data subject, psychologically, to have the certainty that all ties with his or her former religious community have definitively been severed or, put differently, that that community has complied with his or her request to be forgotten.
153. Accordingly, I take the view that Article 17(1)(c) and Article 21(1) of the GDPR, read in the light of Articles 3, 7, 8 and 10 of the Charter and of Article 17(1) TFEU, must be interpreted as meaning that a data subject who was baptised as a minor and who, as an adult, wishes to dissociate himself or herself from the religious community in question has, in principle, the right to have his or her personal data erased from the baptismal register where the controller fails to demonstrate compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject.
154. It is for the national court to assess whether the controller has discharged its burden, in the light of the specific circumstances of the individual situation before it, taking into account, in particular, the reasons which led the data subject to request the erasure of his or her personal data and the possible impact that the controller’s refusal to erase those data may have on the data subject’s integrity.
C. Further processing for the purposes of archiving in the public interest and of historical research
155. Should the referring court come to the conclusion that, in the present case, the controller was unable to demonstrate compelling legitimate grounds capable of overriding the interests, rights and freedoms of the data subject, there is a final step in the legal assessment that that court is to conduct.
156. Indeed, in order to justify the processing, Bisdom Gent also relies on Article 17(3)(d) of the GDPR, according to which the right to erasure does not apply when the processing is necessary ‘for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) in so far as the right [of erasure] is likely to render impossible or seriously impair the achievement of the objectives of that processing’.
157. Furthermore, under Article 89(1) of the GDPR, ‘processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, shall be subject to appropriate safeguards, in accordance with this Regulation, for the rights and freedoms of the data subject. Those safeguards shall ensure that technical and organisational measures are in place in particular in order to ensure respect for the principle of data minimisation. …’
158. In the present case, Bisdom Gent relies on two of the grounds referred to in Article 17(3) and Article 89(1) of the GDPR, claiming that the processing of the complainant’s personal data is necessary for the purposes of archiving in the public interest and of historical research .
159. Before assessing the applicability of those provisions in the main proceedings, I will make some brief remarks concerning the concept of ‘further processing’ for the purposes of the GDPR.
160. In that connection, I would recall that Article 5(1)(b) of the GDPR provides that personal data should, in principle, be ‘collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes … (“purpose limitation”)’. It can hardly be disputed that the personal data of the individuals being baptised are collected for a specific purpose: ensuring the correct administration of the sacraments.
161. However, in the present case, there appears to be no need to ascertain whether the purpose limitation condition is satisfied, since Article 5(1)(b) of the GDPR adds that ‘further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with Article 89(1), not be considered to be incompatible with the initial purposes’. ( 122 ) The sole requirement laid down in the GDPR is that, before such further processing, ‘the controller has assessed the feasibility to fulfil those purposes by processing data which do not permit or no longer permit the identification of data subjects’ (recital 156). This is an element that is for the referring court to ascertain.
162. It follows that, even if collected for another purpose, Bisdom Gent might be able to continue processing the complainant’s personal data, in disregard of the latter’s objection, if the further processing is carried out in compliance with the requirements of Article 89(1) and, obviously, Article 17(3) of the GDPR. ( 123 )
163. In the light of the text of those provisions, three main conditions must be satisfied for the processing in question to fall within the scope thereof. The processing should (i) be carried out for the purposes of archiving in the public interest and/or historical research ; (ii) be necessary to achieve the objectives pursued, in so far as the erasure of the complainant’s personal data would be ‘likely to render impossible or seriously impair’ their achievement; and (iii) comply with the safeguards laid down in EU and national law to protect the rights and freedoms of data subjects.
164. In that regard, it is my view that, in so far as the examination of those conditions requires factual assessments and the interpretation of provisions of national law, it is a task that falls to the referring court. However, I consider it important to provide that court with some guidance on the matter.
(a) The purposes of archiving in the public interest and of historical research
165. The first element to be examined is whether the processing in question is carried out not only to pursue the Church’s own interests but also for purposes of archiving in the public interest and/or of historical research.
166. I shall begin with the concept of ‘archiving in the public interest’. At the outset, I think it worthwhile to stress the importance that archives have in our society. As the ECtHR has emphasised, they ‘constitute an essential and irreplaceable element of culture, contributing to the survival of human memory’. ( 124 )
167. That said, only those kept ‘in the public interest’ fall within the scope of Article 89 of the GDPR. An explanation of that concept can be found in recital 158 of the GDPR which refers to ‘public authorities or public or private bodies that hold records of public interest [and are] services which, pursuant to Union or Member State law, have a legal obligation to acquire, preserve, appraise, arrange, describe, communicate, promote, disseminate and provide access to records of enduring value for general public interest.’
168. In the light of that definition, I would agree with the European Archives Group ( 125 ) that, under the GDPR, it is not the nature of the archives which matters but rather the mission of the body that carries out the archiving activity. ( 126 ) Regardless of whether the body in question is public or private in nature, it must, at least as far as the archiving activity is concerned, act in the public interest . In fact, recital 158 of the GDPR states that the bodies in question ‘should be services’. The term ‘services’ (which is consistent across the various language versions of the regulation) conveys the idea that, in that sphere, the body must carry out a task that is useful to society as a whole. In other words, the data processing required for archiving purposes can only be justified when that processing is – exclusively or at least in part ( 127 ) –selfless in nature and aimed at furthering a greater good.
169. In fact, the body must be under a legal obligation to hold records of the information or documents which contain the personal data in question. ( 128 ) The legal basis of such obligation may be found in EU law or in national law. ( 129 ) The concept of ‘national law’ should be construed broadly. As follows from recital 41 of the GDPR, it does ‘not necessarily require a legislative act adopted by a parliament’. At the same time, however, that legal basis ‘should be clear and precise and its application should be foreseeable to persons subject to it’. In my view, any act that is an expression of public authority and that has been published, or otherwise made easily accessible to the public, would suffice.
170. It should be emphasised, in this context, that Member States enjoy broad discretion to entrust private entities with the task of archiving certain information or documents in the public interest and, as a consequence, also to determine what records are of ‘enduring value for general public interest’ within the meaning of recital 158 of the GDPR. This is a fortiori true in respect of religious communities, ( 130 ) in the light of the principle of neutrality enshrined in Article 17(1) TFEU.
171. The requirement to carry out such activities in the public interest is also reflected in the very elaborate reference, in recital 158 of the GDPR, to the specific activities expected from the body doing the archiving: ‘to acquire, preserve, appraise, arrange, describe, communicate, promote, disseminate and provide access to records’. Clearly, I do not think that passage should be read as meaning that the body in question must perform each and every one of those tasks. In my view, such a list is simply intended to reflect the tasks that are typically performed by archivists.
172. However, I cannot conceive of an activity of archiving in the public interest that does not involve some access to the records, be it for the public authorities and/or the general public, either on a continuous basis or at some later stage. By definition, there cannot be ‘archiving in the public interest’ if the records of a private entity are only accessible to the persons belonging to the entity in question.
173. Lastly, it should be pointed out that the question whether the processing of personal data by religious associations is carried out on grounds of public interest should be determined on a case-by-case basis. Recital 55 of the GDPR states that ‘the processing of personal data by official authorities for the purpose of achieving the aims, laid down by constitutional law or by international public law, of officially recognised religious associations, is carried out on grounds of public interest’. ( 131 ) It follows, a contrario , that a similar presumption does not apply to processing carried out by the religious associations themselves.
174. Since there is no relevant EU law on the matter, it is, accordingly, for the referring court to determine whether, under national law, Bisdom Gent is required to keep records of the individuals who have been baptised and, if appropriate, whether it is in the public interest.
175. Next, the concept of ‘historical research’ should be assessed. First, the term ‘research’ should be understood broadly, covering the systematic process of collecting, analysing and interpreting information in order to further human theoretical or applied knowledge, regardless of the public or private nature of the funding. ( 132 ) Since the term ‘in the public interest’ appears only with respect to ‘archiving’, it follows that research carried out (solely or mainly) in the controller’s own interest could also fall within the scope of Article 89 of the GDPR. ( 133 ) Such an understanding is in line with Article 179(1) TFEU, according to which ‘the [European Union has] the objective of strengthening its scientific and technological bases by achieving a European research area in which researchers, scientific knowledge and technology circulate freely, and encouraging it to become more competitive, including in its industry, while promoting all the research activities deemed necessary by virtue of [the Treaties].’
176. The term ‘historical’ refers, quite clearly, to events, people or phenomena which occurred in the past. As recital 160 of the GDPR states, historical research includes research for genealogical purposes. ( 134 ) That said, I wonder whether the concept of ‘history’ can be interpreted so broadly as to encompass the consultation and study of everything which has happened in the distant or recent past. If so, justification on grounds of historical research could be invoked by almost any controller as regards almost any large set of personal data, irrespective of who would ultimately benefit from such research. ( 135 ) The risk that the rules of the GDPR could easily be circumvented should thus be avoided.
177. To my mind, the references made in the GDPR to ‘research’, be it scientific or historical, are mainly intended to address activities carried out by academic or research organisations or which may ultimately benefit society as a whole, even if carried out by commercial entities. ( 136 ) In particular, I am of the view that the term ‘historical’ refers to ‘history’, understood as human science the study of which may contribute to the advancement of human knowledge. By contrast, I am unsure as to whether research (be it scientific or historical) carried out or controlled by commercial undertakings, and which may result in preferential access to the results thereof, should fall within the scope of the GDPR provisions referring to research. ( 137 )
178. That said, it would appear that, owing to the differences in the national laws of the Member States in this area, the EU legislature decided not to deal with those questions – at least for the time being – and leave them to the national legislatures or, ultimately, the national courts. ( 138 ) In any event, it is unclear, at this stage, whether these interpretative uncertainties could in any way be relevant to the main proceedings. Indeed, Bisdom Gent confirmed at the hearing that it does not conduct historical research itself but, at most, stores and makes available data which may, at some point in time, be used by external researchers. If that is so – a matter which it is for the referring court to determine – the purpose of the processing which Bisdom Gent relies on is, in my view, one of archiving. An overly broad concept of ‘research’ would otherwise blur the distinction between the two grounds relating to ‘archiving in the public interest’ and ‘scientific or historical research’. ( 139 ) That would conflict with the text of Article 89(2) and (3) of the GDPR, which attaches different legal consequences to those grounds.
(b) Necessity of data processing
179. Article 17(3)(d) of the GDPR excludes the right to erasure where the processing is necessary for archiving purposes in the public interest or historical research purposes, ‘in so far as [that right] is likely to render impossible or seriously impair the achievement of the objectives of that processing’.
180. In the light of the wording of that provision, the referring court should, in my view, examine whether the erasure of the complainant’s personal data from the baptismal register would be likely to have a significant negative impact on the activities of archiving in the public interest and/or historical research in which Bisdom Gent might engage.
181. First, as regards archiving activities, the referring court should examine whether the erasure of certain personal data of the data subjects included in the baptismal registers would risk threatening the ‘enduring value for general public interest’ of those registers. In particular, the crucial question is whether the cultural, social or historical value which the national legislature attaches to those registers would be significantly harmed by the erasure. More specifically, that court should assess whether their value is predicated on their absolute integrity or, on the contrary, whether it would not be significantly diminished by some (limited and specific) ex post intervention affecting the personal data contained therein. As the ECtHR has stated, ‘since the role of archives is to ensure the continued availability of information that was published lawfully at a certain point in time, they must, as a general rule , remain authentic, reliable and complete’. ( 140 ) However, as that court has made clear, that is so only in principle, as that principle may, in specific cases, turn out to be inapplicable and exceptions may be justified. ( 141 )
182. In that respect, the argument, put forward by Bisdom Gent, that the registers are historical artefacts, the integrity of which can under no circumstances be undermined by altering the data contained therein, is not entirely convincing. Indeed, the entries into those registers are updated with additional information on relevant events which may occur throughout the lifetime of the individuals recorded therein: for example, additional sacraments or, as in the present case, an individual’s wish to distance himself or herself from the Church.
183. As regards, second, historical research – provided the Church does conduct such an activity ( 142 ) – the referring court should focus its assessment on the actual or potential value of those registers as a source of information for that purpose. As I have mentioned in point 4 above, the authors of the Treaties included Europe’s religious heritage amongst the sources of inspiration that shaped many of today’s core values and fundamental rights. Registers containing information about the membership of religious communities could, therefore, be of interest for historical researchers.
184. In order to ascertain whether a register such as that at issue could fall within the scope of the present exception, the referring court should consider, inter alia, (i) the type of research for which the registers could potentially be relevant (for example, genealogical and/or sociological); (ii) which sets of data, among those contained therein, could be valuable for such research; and (iii) whether the same data could be gathered from other reliable sources (for example, civil registers).
185. In my view, the data minimisation principle should once again be the main guiding principle here. To my mind, it is particularly relevant to inquire as to whether historical researchers need to be aware of the exact identity of each individual listed in the baptismal register or, on the contrary, the personal data of those individuals could be equally useful to them when presented in an aggregate and/or anonymised form.
186. The test to be met by the controller in order to rely on Article 89 of the GDPR in either case is not one of absolute necessity ( sine qua non ), since even a mere impairment in fulfilling the specific purposes of the processing of personal data is sufficient. However, the impairment must be of a certain magnitude and importance since the provision requires a serious impairment. That, in my view, means that the successful attainment of the objectives pursued through the archiving or research activities carried out by the controller should be rendered either impossible or considerably more uncertain or burdensome.
(c) C ompl iance with the safeguards laid down in EU and national law
187. Article 89(1) of the GDPR also provides that the processing of personal data for archiving purposes in the public interest or historical research purposes must ‘be subject to appropriate safeguards , in accordance with this Regulation, for the rights and freedoms of the data subject’. ( 143 )
188. There is neither an express list of measures that might constitute, nor a specific definition of, ‘safeguards’ for the purposes of Article 89(1) of the GDPR. That provision refers simply to safeguards of a ‘technical and organisational [nature]’. ( 144 ) This means that a wide variety of measures, be they reliant on technological solutions or based on administrative policies and processes, could be relevant. The common denominator is the aim of ensuring that the processing is carried out in conformity with the relevant rules, giving adequate protection to the rights and freedoms of the data subjects affected.
189. In particular, as follows from the wording itself of Article 89(1) of the GDPR, a primary goal of those measures should be to ensure respect for the principle of data minimisation : personal data must be processed – from both a quantitative and a substantive viewpoint ( 145 ) – as little as possible and only to the extent that they are needed to reach the objectives pursued with the archiving and historical research activities. ( 146 )
190. It is for that reason that Article 89(1) of the GDPR refers to forms of pseudonymisation and anonymisation amongst the measures that should be considered and, where possible, prioritised. ( 147 ) Indeed, that provision states that where the archiving and historical research purposes ‘can be fulfilled by further processing which does not permit or no longer permits the identification of data subjects, those purposes shall be fulfilled in that manner’. ( 148 )
191. It is apparent that, under the GDPR, up to four sets of safeguards may be applicable in a given situation. First, the safeguards that the provisions of the GDPR may require the controllers and/or processors to implement. ( 149 ) Second, the safeguards that may be established by the Commission, through the exercise of the delegated and implementing powers conferred by the EU legislature. ( 150 ) Third, the safeguards that the Member States may or must provide, under national law. ( 151 ) Fourth and last, the safeguards that may follow from the decisions adopted by the competent independent supervisory authority, in application of its corrective, authorisation and advisory powers. ( 152 ) In that regard, it should be recalled that, pursuant to Article 91(2) of the GDPR, ‘churches and religious associations which apply comprehensive rules [relating to the protection of natural persons with regard to the processing of personal data] shall be subject to the supervision of an independent supervisory authority, which may be specific, provided that it fulfils the conditions laid down in [in the relevant provisions of the GDPR].’ ( 153 )
192. It should also be pointed out that some of the safeguards laid down under EU or Member State laws may allow the controllers themselves a certain degree of latitude as to the choice of the measures to be implemented and/or how they should be implemented. Often, the controllers’ self-assessment is crucial in this context. It is, first and foremost, for them to carry out an initial assessment of the situation in order to identify the safeguards that may be ‘appropriate’ to the circumstances. They should do so taking into account, inter alia, the specific types of processing performed, the level of interference with the rights and interests of the data subject concerned, and the risks involved.
193. The wording of Article 89(1) of the GDPR makes it abundantly clear that compliance with the relevant safeguards is a condition for the lawfulness of the processing of personal data for archiving and historical research purposes. It is, accordingly, for the referring court to determine (i) the safeguards that were applicable with respect to the processing carried out by Bisdom Gent; (ii) whether such safeguards were ‘appropriate’ to the circumstances; and (iii) whether Bisdom Gent complied with those safeguards.
194. Concluding on this point, I take the view that Article 17(3) and Article 89 of the GDPR must be interpreted as meaning that, despite a data subject being in principle able to exercise the right to object set out in Article 21(1) of the GDPR, the controller can justify the further processing of the personal data in question if it demonstrates that such processing is carried out for archiving purposes in the public interest, or for historical research purposes which could contribute to the advancement of human knowledge, provided that appropriate safeguards are in place and complied with, and the data minimisation principle is respected.
D. The concept of ‘erasure’
195. Lastly, by its fifth question, the referring court asks the Court to clarify the concept of ‘erasure’ within the meaning of Article 17 of the GDPR. In particular, the referring court wonders whether a data subject’s right to erasure could be satisfied by a mere annotation, in the margin of the baptismal register, of the data subject’s departure from the Church, and the striking through of the relevant personal data which still leaves them legible.
196. The argument put forward by Bisdom Gent that such an annotation should be considered equivalent to a material erasure of the relevant personal data is unconvincing.
197. The meaning of the term ‘erasure’ (and of the equivalent terms used in the other language versions of the regulation) in everyday language is rather clear: deletion, removal, obliteration. However, the annotation made by Bisdom Gent is, at most, a rectification of the data.
198. However, the right to rectification and the right to erasure are two distinct rights within the scheme of the GDPR. The purpose of those two rights – which are set out in Articles 16 and 17 of the GDPR, respectively – is also different. The right to rectification aims at ensuring, first and foremost, that the personal data of a data subject are accurate, complete and up to date. By contrast, as the title of Article 17 itself makes clear, the right to erasure aims to ensure that the data subject in question may be ‘forgotten’ by the controller. To that end, the personal data stored by the controller should be deleted so that they can no longer be processed. ( 154 )
199. That objective is not, however, attained in a situation such as that at issue in the main proceedings. Indeed, as the complainant correctly observed at the hearing, the annotation made by Bisdom Gent in the baptismal register has increased the data processing: new personal data have been added to the register, and those data will continue to be stored therein. ( 155 )
200. It is true that, in certain situations, the controller may be able, or allowed by the data subject, to choose the most appropriate course of action between rectification or erasure, when some personal data stored turn out to be inaccurate or not strictly necessary. ( 156 ) However, it is clear that the same does not apply where a data subject has expressly requested the erasure of his or her personal data and the conditions laid down in the GDPR for the exercise of that right are fully satisfied . A different reading of the provisions would render Article 21(1) of the GDPR largely ineffective.
201. I am not persuaded by the arguments put forward by Bisdom Gent in support of the opposite view.
202. In the first place, I find the argument concerning an alleged falsification of history to be unconvincing. The initial collection of personal data is almost always triggered by an action of the data subject. The logic underlying Bisdom Gent’s argument would imply that almost any erasure of personal data would result in the falsification of an event that has occurred in the past. That cannot be correct.
203. For instance, a service provider in receipt of a request for the removal from its database of the personal data of one of its customers cannot object that such an act would amount to a misrepresentation of past commercial transactions. The case-law of the Court includes several specific examples where the underlying facts surrounding the data subject’s personal data in respect of which erasure had been requested were undisputed. ( 157 )
204. The same reasoning can be applied in the present case. The right to erasure does not entitle data subjects to request the removal, from the baptismal register, of all traces of their baptism. That right allows them only to request the deletion of their personal data; any other information about the baptism of an individual that has taken place at a given place and at a given time can lawfully be maintained on the baptismal register.
205. In that respect, the data minimisation principle should yet again play a key role in determining, specifically, what data should actually be erased and what data can remain in the records. Asked at the hearing about his views on this matter, the complainant appeared to be in favour of considering the possibility that data erasure could be limited to his name, surname and date of birth. In the complainant’s submission, any other information, irrespective of whether it could come under the definition of ‘personal data’ within the meaning of Article 4(1) of the GDPR could be maintained on the register. From the outset, the complainant also made clear that he did not object to measures such as anonymisation and pseudonymisation.
206. In my view, what really matters in this type of situation is that the erasure of the personal data should ensure that the person who has been baptised is no longer identified or at least is not easily identifiable.
207. In the second place, data subjects have no right, be it under the GDPR or any other provision of EU law, to request that the controller treat their baptism as though it had never occurred or is devoid of value. These are doctrinal matters in which, pursuant to Article 17(1) TFEU, the European Union cannot interfere. ( 158 ) At the risk of stating the obvious, I would point out that no action taken by Bisdom Gent to ensure compliance with the rules of the GDPR can be understood as having any bearing on the theological tenets of the Church.
208. In the third and final place, I find no basis in Bisdom Gent’s claim that deleting any data included on the baptismal register would irremediably prejudice the rights and interests of the Church or of other individuals whose baptism is also recorded on the same register.
209. The complainant agreed with the view that the deletion of his personal data would not need to be implemented by physically removing those data from the register, for example by cutting out the relevant pages or parts thereof. It should in fact be possible to proceed in such a way as to render the personal data in question illegible, whilst leaving intact any other data recorded in the same pages thereof. Arguably, the use of items such as opaque stickers that merely cover the personal data would be enough to ensure compliance with Article 17(1) of the GDPR. ( 159 ) It is, in any event, for the controller to find adequate methods of erasure; basic difficulties in identifying those methods cannot excuse the controller from failing to comply with the relevant rules of the GDPR. ( 160 )
210. I thus conclude, on this point, that a mere annotation, in the margin of the baptismal register, of a data subject’s departure from a religious community, and the striking through of the relevant personal data which still leaves them legible, does not amount to ‘erasure’ for the purposes of the GDPR.
211. The fact that the baptismal register is not digital, but a unique material carrier in the form of a book with double-sided pages in which details of other data subjects are also given, and which constitutes a unique record of historical facts that are not recorded anywhere else, does not call the foregoing considerations into question.
V. Conclusion
212. In conclusion, I propose that the Court answer the questions referred for a preliminary ruling by the hof van beroep te Brussel (Court of Appeal, Brussels, Belgium) as follows:
Article 17(1)(c) and(3), Article 21(1) and Article 89 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), read in the light of Articles 3, 7, 8 and 10 of the Charter of Fundamental Rights of the European Union and of Article 17(1) TFEU,
must be interpreted as meaning that:
– a data subject who was baptised as a minor and who, as an adult, wishes to dissociate himself or herself from the religious community in question has, in principle, the right to have his or her personal data erased from the baptismal register where the controller fails to demonstrate compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject. It is for the national court to assess whether or not the controller discharged its burden, in the light of the specific circumstances of the individual situation before it, taking into account, in particular, the reasons which led the data subject to request the erasure of his or her personal data, and the possible impact that the controller’s refusal to erase those data may have on the data subject’s integrity;
– further processing of the personal data in question is lawful where the controller demonstrates that the processing is carried out for archiving purposes in the public interest, or for historical research purposes which could contribute to the advancement of human knowledge, provided that appropriate safeguards are in place and complied with, and the data minimisation principle is respected;
– a mere annotation, in the margin of the baptismal register, of a data subject’s departure from a religious community, and the striking through of the relevant personal data which still leaves them legible, does not amount to ‘erasure’ for the purposes of Regulation 2016/679;
– the fact that the baptismal register is not digital, but a unique material carrier in the form of a book with double-sided pages in which details of other data subjects are also given, and which constitutes a unique record of historical facts that are not recorded anywhere else, does not call the foregoing considerations into question.
1 Original language: English.
2 Matthew 22:21.
3 In the EU legal order, see, first and foremost, Article 20 of the Charter of Fundamental Rights of the European Union (‘the Charter’), entitled ‘Equality before the law’.
4 See European Court of Human Rights (ECtHR), judgment of 1 July 2014, S.A.S. v. France (CE:ECHR:2014:0701JUD004383511, § 125).
5 See, in that regard, ECtHR, judgment of 9 July 2013, Sindicatul ‘Păstorul Cel Bun’ v. Romania (CE:ECHR:2013:0709JUD000233009, § 138). In legal scholarship, see also McCrea, R., ‘Justifiable caution: The approach of the Court of Justice to religion in the context of rapid change’, in Gašperin Wischhoff, J. and Stadtbäumer, T. (eds), In Good Faith – Freedom of Religion under Article 10 of the EU Charter , Verfassungsbooks, Berlin, 2026, pp. 23 to 33, at p. 28.
6 See also Article 17(3) TFEU: ‘Recognising their identity and their specific contribution , the Union shall maintain an open, transparent and regular dialogue with [the churches and religious associations or communities in the Member States].’ Emphasis added.
7 See, similarly, Article 9 of the European Convention on Human Rights (ECHR) and Article 18 of the United Nations’ Universal Declaration of Human Rights.
8 See, in particular, Article 19(1) TFEU and Article 21 of the Charter. See also Opinion of Advocate General Emiliou in Freikirche der Siebenten-Tags-Adventisten in Deutschland (C‑372/21, EU:C:2022:540, point 21).
9 See, to that effect, judgment of 17 April 2018, Egenberger (C‑414/16, ‘the judgment in Egenberger ’, EU:C:2018:257, paragraph 58).
10 See, to that effect, the judgment in Egenberger , paragraph 50, and judgment of 10 July 2018, Jehovan todistajat (C‑25/17, ‘the judgment in Jehovan todistajat ’, EU:C:2018:551, paragraph 74). See also, by analogy, ECtHR, judgment of 13 December 2001, Metropolitan Church of Bessarabia and Others v. Moldova (CE:ECHR:2001:1213JUD004570199, § 118).
11 See, generally, the Opinions of Advocate General Tanchev in Egenberger (C‑414/16, EU:C:2017:851, points 88 and 93) and of Advocate General Bobek in Cresco Investigation (C‑193/17, EU:C:2018:614, point 26).
12 See, to that effect, Opinion of Advocate General Emiliou in Freikirche der Siebenten-Tags-Adventisten in Deutschland (C‑372/21, EU:C:2022:540, point 22).
13 See, among many, the judgment in Egenberger ; the judgment of 17 March 2026, Katholische Schwangerschaftsberatung (C‑258/24, EU:C:2026:211); and my Opinion in the latter case (C‑258/24, EU:C:2025:555).
14 See, for example, judgment of 6 November 2018, Scuola Elementare Maria Montessori v Commission , Commission v Scuola Elementare Maria Montessori and Commission v Ferracci (C‑622/16 P to C‑624/16 P, EU:C:2018:873).
15 See, famously, judgment of 23 April 1986, Les Verts v Parliament (294/83, EU:C:1986:166, paragraph 23).
16 I am paraphrasing a statement made by former United States President Theodore Roosevelt in his Third Annual Message to Congress in 1903.
17 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (OJ 2016 L 119, p. 1).
18 Hereinafter also referred to as ‘the Catholic Church’ or simply ‘the Church’.
19 JM will also be referred to as ‘the complainant’.
20 It may be of interest to note that arguments based on the concept of a ‘filing system’ for the purposes of the GDPR have also been discussed before some national courts hearing cases similar to the one at hand here. See, in that respect, Court of Justice of the European Union, Research Note of the Research and Documentation Directorate, ‘Traitement des données à caractère personnel dans les registres des baptêmes de l’Église catholique romaine’, 26/007, June 2026 (‘the Research Note of the Research and Documentation Directorate’), pp. 12 to 17, and 47.
21 See, inter alia, the judgment in Jehovan todistajat , paragraph 53.
22 See Opinion of Advocate General Szpunar in Darashev (C‑312/24, EU:C:2025:671, point 58).
23 See, again, recital 15 of the GDPR.
24 See, to that effect, judgment of 7 March 2024, Endemol Shine Finland (C‑740/22, EU:C:2024:216, paragraph 37 and the case-law cited).
25 Ibid.
26 The ancient Library of Alexandria in Egypt (founded in the early third century BCE) was, to our knowledge, the world’s first research centre. Its ancient catalogue, known as the Pinakes , was compiled by Callimachus of Cyrene and organised the library’s collection of up to 500 000 papyrus scrolls. It is widely considered one of the world’s oldest filing systems. The Pinakes was mainly based on categories of genres and, within those categories, authors were listed alphabetically.
27 On that matter, see, mutatis mutandis , Opinion of Advocate General Mengozzi in Jehovan todistajat (C‑25/17, EU:C:2018:57, point 57).
28 Directive of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data (OJ 1995 L 281, p. 31). See recital 15 thereof, which referred to a ‘filing system structured according to specific criteria relating to individuals ’ (emphasis added).
29 See the judgment in Jehovan todistajat , especially paragraph 74.
30 See, in particular, Article 9(2)(d) and Article 91 of the GDPR. See also recital 165 thereof.
31 Those operations are considered to be forms of ‘processing’ under Article 4(2) of the GDPR.
32 See Article 99(2) of the GDPR.
33 Paragraphs 57 to 68 of the contested decision.
34 See, to that effect, judgment of 4 October 2024, Agentsia po vpisvaniyata (C‑200/23, EU:C:2024:827, paragraph 93).
35 See judgment of 9 January 2025, Mousse (C‑394/23, ‘the judgment in Mousse ’, EU:C:2025:2, paragraph 67), emphasis added. See also judgment of 4 October 2024, Agentsia po vpisvaniyata (C‑200/23, EU:C:2024:827, paragraph 93) and recital 69 of the GDPR.
36 Generally, on this point, with references to the case-law, Tridimas, T., ‘Wreaking the wrongs: Balancing rights and the public interest the EU way’, Columbia Journal of European Law , Vol. 29.2, 2023, pp. 185-213, in particular pp. 192-194.
37 See, in particular, Article 5(2), Article 7, Article 24(1) and recitals 42, 69 and 74 of the GDPR.
38 In fact, in its Opinion 06/2014 on the notion of legitimate interests of the data controller under Article 7 of Directive 95/46/EC, adopted on 9 April 2014, the Article 29 Data Protection Working Party referred to this exercise as an ‘a priori’ balancing test (see p. 45).
39 Ibid.
40 See, to that effect, judgment of 13 May 2014, Google Spain and Google (C‑131/12, ‘the judgment in Google Spain ’, EU:C:2014:317, paragraph 76). See also recital 69 of the GDPR.
41 Emphasis added.
42 Similarly, see European Data Protection Board (EDPB), ‘Guidelines 1/2024 on processing of personal data based on Article 6(1)(f) GDPR’, adopted on 8 October 2024 (‘Guidelines 1/2024’), paragraph 72.
43 Emphasis added.
44 See paragraphs 74 to 76 thereof. That case concerned the predecessor of the GDPR, Directive 95/46. Although the relevant provisions of Directive 95/46 and those of the GDPR do not coincide entirely, the Court’s considerations in that judgment appear fully relevant to the provisions currently in force.
45 A comparison of the various language versions of the GDPR confirms this finding. See, for example, the German- (‘ legt … Widerspruch … ein ’ and ‘ wurden … verarbeitet ’), French- (‘ s’oppose ’ and ‘ ont fait l’objet ’), Dutch- (‘ maakt … bezwaar ’ and ‘ zijn ’), Italian- (‘ si oppone ’ and ‘ sono stati trattati ’), Latvian- (‘ iebilst ’ and ‘ ir apstrādāti ’), Portuguese- (‘ opõe-se ’ and ‘ foram tratados ’) and Romanian-language (‘ se opune ’ and ‘ au fost prelucrate ’) versions of the GDPR.
46 See the judgment in Mousse , paragraph 48.
47 See judgment of 8 December 2022, Google (De-referencing of allegedly inaccurate content) (C‑460/20, EU:C:2022:962, paragraph 75).
48 See, to that effect, the judgment in Mousse , paragraph 50 and the case-law cited.
49 See, to that effect, judgment of 4 October 2024, Koninklijke Nederlandse Lawn Tennisbond (C‑621/22, ‘the judgment in KNLTB ’, EU:C:2024:858, paragraphs 46 and 49). See also Opinion of Advocate General Bobek in Rīgas satiksme (C‑13/16, EU:C:2017:43, points 67 and 68).
50 See, to that effect, judgment of 12 September 2024, HTB Neunte Immobilien Portfolio and Ökorenta Neue Energien Ökostabil IV (C‑17/22 and C‑18/22, EU:C:2024:738, paragraph 55 and the case-law cited).
51 See, to that effect, judgment of 4 September 2025, Quirin Privatbank (C‑655/23, EU:C:2025:655, paragraph 39 and the case-law cited).
52 See, in particular, point 189 below.
53 See the judgment in Mousse , paragraph 25 and the case-law cited.
54 See, to that effect, judgment of 4 July 2023, Meta Platforms and Others (General terms of use of a social network) (C‑252/21, ‘the judgment in Meta Platforms ’, EU:C:2023:537, paragraph 94).
55 See the judgment in Mousse , paragraphs 27 and 56 and the case-law cited.
56 See, inter alia, judgment of 7 December 2023, SCHUFA Holding (Discharge from remaining debts) (C‑26/22 and C‑64/22, EU:C:2023:958, paragraph 78).
57 See the judgment in Mousse , paragraph 45 and the case-law cited.
58 See, inter alia, the judgment in Mousse , paragraph 46 and the case-law cited. See also judgment of 12 September 2024, HTB Neunte Immobilien Portfolio and Ökorenta Neue Energien Ökostabil IV (C‑17/22 and C‑18/22, EU:C:2024:738, paragraphs 56 and 57), and, with further references to case-law, Opinion of Advocate General Bobek in Fashion ID (C‑40/17, EU:C:2018:1039, point 122).
59 See paragraph 17 thereof.
60 See, in respect of the first criterion, the judgment in KNLTB , paragraphs 40 and 49; as regards the second criterion, by analogy, Opinion of Advocate General Sharpston in Joined Cases Volker und Markus Schecke (C‑92/09 and C‑93/09, EU:C:2010:353, points 104, 105, 118 and 121); and, as to the third criterion, judgment of 11 December 2019, Asociaţia de Proprietari bloc M5A-ScaraA (C‑708/18, EU:C:2019:1064, paragraph 44).
61 Can. 849.
62 See, to that effect, judgments of 29 May 2018, Liga van Moskeeën en Islamitische Organisaties Provincie Antwerpen and Others (C‑426/16, EU:C:2018:335, paragraphs 42 to 45), and of 17 December 2020, Centraal Israëlitisch Consistorie van België and Others (C‑336/19, EU:C:2020:1031, paragraphs 44 and 52).
63 See, by analogy, ECtHR, judgment of 7 July 2011, Bayatyan v. Armenia (CE:ECHR:2011:0707JUD002345903, § 120).
64 See the judgment in Mousse , paragraphs 28 and 48 and the case-law cited.
65 Ibid., paragraph 49 and the case-law cited.
66 See, in that regard, Opinion of Advocate General Bobek in Rīgas satiksme (C‑13/16, EU:C:2017:43, point 71). On this point, generally and with additional references to the case-law, see Dalla Corte, L., ‘On proportionality in the data protection jurisprudence of the CJEU’, International Data Privacy Law , Vol. 12, Issue 4, 2022, pp. 259 to 275.
67 See the judgment in Mousse , paragraphs 48 and 63.
68 See point 127 of this Opinion.
69 On more stringent and more nuanced applications of the requirement of necessity, according to the specific circumstances of the case, see, generally, Sartor, G., ‘Article 6 Commentary: Lawfulness of processing’, in Spiecker, I. et al. (eds), General Data Protection Regulation: Article-by-Article Commentary , Nomos – Beck – Hart, New York, 2023, p. 318.
70 Recital 47 of the GDPR, emphasis added. See also the judgment in KNLTB , paragraphs 55 and 56. Similarly, the ECtHR also considers relevant whether, in some specific situation, individuals could have ‘a legitimate expectation that their private life would be protected’. See, for example, judgment of 7 February 2012, von Hannover v. Germany (CE:ECHR:2012:0207JUD004066008, § 88).
71 See, inter alia, the judgment in Meta Platforms , paragraph 116.
72 See, to that effect, the judgment in Google Spain , paragraphs 96 and 99.
73 See, by analogy, the judgment in Mousse , paragraph 60, with reference to recital 75 of the GDPR.
74 See, inter alia, the judgment in Meta Platforms , paragraph 118, and the judgment of 4 October 2024, Agentsia po vpisvaniyata (C‑200/23, EU:C:2024:827, paragraphs 151, 155 and 156). See also the Guidelines 1/2024, paragraph 46.
75 See, for example, the judgment in Google Spain , paragraph 87, and judgment of 5 June 2023, Commission v Poland (Independence and private life of judges) (C‑204/21, EU:C:2023:442, paragraph 374).
76 See, in particular, judgment of 24 November 2011, Asociación Nacional de Establecimientos Financieros de Crédito (C‑468/10 and C‑469/10, EU:C:2011:777, paragraph 44).
77 As stressed, for example, in Kamara, I. and De Hert, P. ‘Understanding the balancing act behind the legitimate interest of the controller ground: A pragmatic approach’, in Selinger, E., et al. (eds), The Cambridge Handbook of Consumer Privacy , Cambridge University Press, 2018, pp. 332 and 333.
78 In that respect, see also recitals 51 and 52 of the GDPR.
79 As regards the specific protection which is to be afforded to children, see also recital 38 of the GDPR and the judgment in Meta Platforms , paragraph 111.
80 See, by analogy, the judgment in Google Spain , paragraphs 93 to 95 and 98; and judgment of 9 March 2017, Manni (C‑398/15, EU:C:2017:197, paragraph 64). Similarly, ECtHR, judgment of 6 June 2006, Segerstedt-Wiberg and Others v. Sweden (CE:ECHR:2006:0606JUD006233200, § 90). See also recital 39 of the GDPR.
81 See, inter alia, Article 5(1)(f), Article 6(4)(e) and Article 9(2)(d) of the GDPR.
82 See, for example, ECtHR, judgment of 25 June 2020, Stavropoulos and Others v. Greece (CE:ECHR:2020:0625JUD005248418, § 44).
83 See Article 14(3) of the Charter and, by analogy, Article 2 of Protocol No. 1 to the ECHR. See also Article 8(1) and recital 38 of the GDPR.
84 Emphasis added.
85 In that sense, see, for example, Guidelines 1/2024, paragraph 73.
86 See, to that effect, judgment of 8 December 2022, Google (De-referencing of allegedly inaccurate content) (C‑460/20, EU:C:2022:962, paragraphs 7, 34, 35 and 71).
87 See, in that sense, Zanfir-Fortuna, G., ‘Comment to Article 21’, in Kuner, C., et al. (eds), The EU General Data Protection Regulation: A Commentary , Oxford University Press, Oxford, 2020, p. 517.
88 Such as, for example, in Czech (‘ závažné ’), German (‘ zwingende ’), Greek (‘ επιτακτικούς ’), French (‘ impérieux ’), Italian (‘ cogenti ’), Latvian (‘ pārliecinošiem ’), Hungarian (‘ erejű ’), Dutch (‘ dwingende ’) and Finnish (‘ huomattavan tärkeä ’).
89 Paragraph 73.
90 See judgment of 7 December 2023, SCHUFA Holding (Discharge from remaining debts) (C‑26/22 and C‑64/22, EU:C:2023:958, paragraphs 112 and 113).
91 In this sense, Zanfir-Fortuna, G., footnote 87, op. cit., , p. 517.
92 See point 54 of this Opinion.
93 Emphasis added.
94 See point 65 of this Opinion.
95 In legal scholarship, see Zanfir-Fortuna, G., footnote 87, op. cit.: ‘the right to object is another manifestation of the “control centric” nature of the EU data protection legal framework’ (at p. 509).
96 See, inter alia, the judgment in Mousse , paragraph 21, with reference to Article 1 and recitals 1 and 10 of the GDPR.
97 See point 103 of this Opinion.
98 As regards the pursuit of a mere economic interest, see, for example, the judgment in Google Spain , paragraphs 81, 97 and 99.
99 See, for example, recitals 44 and 70 as well as Article 6(1)(b) and Article 21(3) of the GDPR.
100 Guidelines 1/2024, paragraph 73.
101 See, by analogy, Opinion of Advocate General Jääskinen in Google Spain and Google (C‑131/12, EU:C:2013:424, point 108).
102 See, similarly, contested decision, paragraph 138.
103 Emphasis added.
104 I wonder, in passing, how likely it is that such a scenario would occur. It would be surprising that a person who wishes to re-join the Church would consider a second baptism to be essential when he or she is informed that, in the eyes of the Church, that is not only unnecessary but also (in principle) precluded.
105 See paragraphs 119 and 120 of the contested decision.
106 See, in particular, Can. 842 § 1 and Can. 876.
107 As I shall explain, in points 204 to 206 of this Opinion, in order to comply with Articles 17 and 21 of the GDPR, it is not necessary to remove from the register any information whatsoever concerning the administration of baptism to the data subject requesting erasure. Removing the most sensitive data that permit the identification of the person concerned will suffice.
108 See Can. 869. For another situation, see also Can. 870.
109 See, by analogy, judgment of 4 October 2024, Agentsia po vpisvaniyata (C‑200/23, EU:C:2024:827, paragraph 114), and my Opinion in the same case (EU:C:2024:445, point 56).
110 See the case-law cited in point 58 above.
111 Guidelines 1/2024, paragraph 73. Emphasis added.
112 See the case-law cited in point 105 above.
113 See, by analogy, ECtHR, judgment of 26 October 2000, Hasan and Chaush v. Bulgaria (CE:ECHR:2000:1026JUD003098596, § 62).
114 It is of interest, in that respect, that according to Article 7(3) of the GDPR, ‘the data subject shall have the right to withdraw his or her consent at any time. … It shall be as easy to withdraw as to give consent.’
115 See, in the same vein, judgment of 5 June 2023, Commission v Poland (Independence and private life of judges) (C‑204/21, EU:C:2023:442, paragraphs 341 and 375).
116 After all, Article 12(1) of the UN Convention on the Rights of the Child (adopted on 20 November 1989), provides that ‘States Parties shall assure to the child who is capable of forming his or her own views the right to express those views freely in all matters affecting the child, the views of the child being given due weight in accordance with the age and maturity of the child.’
117 On this matter, with references to the case-law, see my Opinion in Katholische Schwangerschaftsberatung (C‑258/24, EU:C:2025:555, point 39 et seq.).
118 See, to that effect, ECtHR, judgment of 1 July 2014, S.A.S. v. France (CE:ECHR:2014:0701JUD004383511, § 124 and the case-law cited). This line of case-law has also been expressly referred to in the Court of Justice’s case-law: see, recently, judgment of 13 October 2022, SCRL (Religious clothing) (C‑344/20, EU:C:2022:774, paragraph 35).
119 I am drawing inspiration here from the Court’s findings with respect to the right to respect for private and family life set out in Article 7 of the Charter, with reference to the case-law of the ECtHR. See judgment of 18 December 2025, Slagelse Almennyttige Boligselskab, Afdeling Schackenborgvænge (C‑417/23, EU:C:2025:1017, paragraph 171). In legal scholarship, placing emphasis on the freedom of religion as a right to self-determination, see Wischhoff, J.G. and Stadtbäumer, T., footnote 5, op. cit., p. 13.
120 For example, victims of abuse may require medical and/or psychological help, including hospitalisation at times, to overcome certain traumas.
121 See, with further references, Bandes, S.A., et al. (eds), Research Handbook on Law and Emotion , Edward Elgar, 2021.
122 Emphasis added. See also recital 50 of the GDPR.
123 For the sake of completeness, I would add that, pursuant to Article 9(2)(f) of the GDPR, the general prohibition on processing personal data revealing, inter alia, religious or philosophical beliefs does not apply to ‘processing [that] is necessary for archiving purposes in the public interest , scientific or historical research purposes or statistical purposes in accordance with Article 89(1) based on Union or Member State law’. That is so under the condition that such processing is ‘proportionate to the aim pursued, respect[s] the essence of the right to data protection and provide[s] for suitable and specific measures to safeguard the fundamental rights and the interests of the data subject’ (Article 9(2)(g) thereof). However, I do not think that Bisdom Gent need rely on that provision since, as explained in points 66 and 67 above, its processing of sensitive data may be based on Article 9(2)(d) of that regulation.
124 ECtHR, judgment of 4 July 2023, Hurbain v. Belgium (CE:ECHR:2023:0704JUD005729216, § 182).
125 An official Commission expert group established in 2006.
126 European Archives Group, Guidance on Data Protection for Archive Services – EAG guidelines on the implementation of the General Data Protection Regulation in the archive sector, 2018, p. 10.
127 See Article 89(4) of the GDPR.
128 This does not follow only from recital 158 of the GDPR but, in casu , also from Article 9(2)(j) of the GDPR.
129 For examples of Member States’ laws on this point, see the Research Note of the Research and Documentation Directorate, especially pp. 28 to 47.
130 That is applicable where religious associations are, under national law, considered private entities. Naturally, the situation is different where they are public entities under national law.
131 Emphasis added.
132 See, by analogy, recital 159 of the GDPR.
133 See Svanberg,C.W., Commentary to Article 89, in Kuner, C., et al. (eds), op. cit. footnote 87, p. 1246.
134 It should be pointed out that, in any case, the provisions of the GDPR do not apply to the personal data of deceased persons, although Member States may lay down rules in that regard. See recitals 27, 158 and 160 of the GDPR.
135 Let us think, for example, of digital platforms that store detailed data concerning the online purchases made by, or the browsing history of, individuals in order to improve their software.
136 In that connection, see for example recital 113 of the GDPR, suggesting that ‘the legitimate expectations of society for an increase of knowledge’ is an element that ‘should be taken into consideration’ when assessing the scope of exceptions for scientific or historical research purposes.
137 I am borrowing certain expressions here from recital 12 of Directive (EU) 2019/790 of the European Parliament and of the Council of 17 April 2019 on copyright and related rights in the Digital Single Market and amending Directives 96/9/EC and 2001/29/EC (OJ 2019 L 130, p. 92).
138 See EDPB, Study on the secondary use of personal data in the context of scientific research – Final Report , October 2020.
139 The connection between the two activities is emphasised in recital 157 of the GDPR.
140 ECtHR, judgment of 4 July 2023, Hurbain v. Belgium (CE:ECHR:2023:0704JUD005729216, § 184). Emphasis added.
141 To that effect, ibid., §§ 185, 186 and 255 to 257.
142 For example, research to better understand societal developments in religious communities, carried out for a purpose that is legally and ethically acceptable for the society concerned.
143 Emphasis added.
144 See, for example, the measures referred to in recitals 78, 83, 84, 98 and 100 of the GDPR.
145 Opinion of Advocate General Szpunar in Mousse (C‑394/23, EU:C:2024:610, point 32).
146 EDPB, Study on the appropriate safeguards under Article 89(1) GDPR for the processing of personal data for scientific research – Final Report , August 2021, p. 9.
147 On this point, see also recitals 26, 28 and 29 of the GDPR.
148 Emphasis added.
149 See, for example, Article 24(1), Article 25(1) and Article 32(1) of the GDPR.
150 See recital 156 and Articles 92 and 93 of the GDPR.
151 See, in particular, recital 156 and Article 89(2) and (3) of the GDPR.
152 See, in particular, Article 58 of the GDPR.
153 For some examples of Member States’ laws on this matter, see the Research Note of the Research and Documentation Directorate, pp. 22 to 28.
154 To that effect, see, for example, recital 65 and Article 5(1)(d) of the GDPR.
155 See also the contested decision, paragraph 138.
156 See, for example, recital 39 of the GDPR: ‘Every reasonable step should be taken to ensure that personal data which are inaccurate are rectified or deleted.’
157 See, for example, the judgment in Google Spain , paragraphs 92 to 94, and, by analogy, judgment of 30 January 2024, Direktor na Glavna direktsia ‘Natsionalna politsia’ pri MVR – Sofia (C‑118/22, EU:C:2024:97, paragraph 60).
158 See, by analogy, European Commission of Human Rights, Decision of 6 February 1967, X. v. Iceland (CE:ECHR:1967:0206DEC000252565).
159 In addition, the use of removable opaque stickers (if appropriate, in combination with tamper-evident seals or stamps) could also be envisaged in some situations, in line with the data minimisation principle. For example, that may be the case where the religious communities are, under national law, precluded from making any permanent alteration to the registers on the ground that those registers must be handed over to the public authorities for the purposes of archiving in the public interest or historical research. The use of such stickers and, as the case may be, of tamper-evident seals or stamps would ensure that only the public authorities or the researchers could, in due course, have access to the personal data in question.
160 See, to that effect, recitals 74, and 78 and Article 24(1) of the GDPR.