Ten judgments of the Court of Justice of the European Union that built the GDPR case by case — and the lessons each holds for the members of India’s Data Protection Board.
By Adv. (Dr.) Prashant Mali — Advocate, Supreme Court of India & Bombay High Court
Founder, Cyber Law Consulting • Published on dpdpa.com/Blog • 10 August 2026
“Ubi jus incertum, ibi jus nullum.”
Where the law is uncertain, there is no law — and it falls to the adjudicator to make it certain.
A maxim • and a warning
On 13 November 2025, India did something quietly historic: it switched on the Digital Personal Data Protection Rules, 2025, and with them the provisions that establish the Data Protection Board of India under Section 18 of the DPDP Act, 2023. On paper, the Republic finally acquired the regulator that Puttaswamy had, eight years earlier, all but ordered into existence. And yet, as I write in August 2026, the Board has a statute, a seal, a Gazette entry, and a set of procedural rules — but not a single appointed Member. It is, in the elegant phrase of one recent commentator, established in law and absent in fact. The Search-cum-Selection Committees have issued nominations calls (notifications of 6 May and 6 June 2026); they have not yet issued an appointment.
This is an unusual and rather poignant moment to write for the Board, because the Board is not yet anyone. This piece is therefore addressed to an empty chair — a letter to the men and women who will shortly occupy it. When they do, they will inherit a compact 44-section statute and a near-blank sheet of interpretation. They will discover, as every data protection adjudicator eventually does, that the words of the Act are the easy part. The hard part — what “personal data” really means, when consent is truly free, how far the writ runs across a border, what a breach of a right is actually worth — is decided later, case by case, in the unglamorous accretion of reasoned orders.
Europe learned this the hard way. The General Data Protection Regulation has ninety-nine articles and a hundred and seventy-three recitals; it reads like a finished cathedral. But the GDPR you actually apply in practice was not built by the Parliament in Strasbourg. It was built, brick by patient brick, by the Court of Justice of the European Union in Luxembourg — a court so productive on data protection that “the year in CJEU privacy judgments” is now its own genre of law-firm writing, and which on a single day, 4 October 2024, handed down five GDPR rulings before lunch. Justice Holmes was right that the life of the law has not been logic but experience. The GDPR’s life has been Luxembourg.
DPDP Rules, 2025 — notified 13 November 2025 (G.S.R. 846(E)); phased commencement, with substantive obligations expected to bite around May 2027 and Consent Manager registration from November 2026.
The Board (DPBI) — a body corporate since 13 November 2025 under Section 18; digital-by-design; appeals lie to the TDSAT. As of August 2026, Chairperson and Members remain unappointed; selection is underway.
This blog — a comparative opinion, not a transplant manual. The GDPR and the DPDPA are cousins, not twins; every lesson below must be read through India’s own constitutional lens of Puttaswamy proportionality.
A necessary caveat
Cousins, not twins
Before drawing lessons from Europe, one must be candid about the distance between the two systems — a distance Professor Graham Greenleaf and others have mapped in detail. The DPDPA is deliberately leaner than the GDPR. It has no special category of “sensitive personal data” (a striking retreat even from the 2011 SPDI Rules under the IT Act). It has no free-standing right against automated decision-making, no data-portability right, and no statutory “right to be forgotten” as such — only a right to erasure under Section 12. Its lawful bases are consent (Section 6) and a closed list of “legitimate uses” (Section 7); there is no open-textured “legitimate interests” balancing clause. Cross-border transfer runs on a permissive negative-list model (Section 16), the mirror image of the GDPR’s adequacy-and-safeguards architecture. And crucially, the DPDPA gives the wronged individual no private action for compensation: penalties flow to the Consolidated Fund of India, not to the victim.
So the CJEU’s judgments cannot be lifted whole and dropped into a Board order. They are not precedents; they are parables. Each teaches a transferable habit of reasoning — about scope, about consent, about independence, about remedy — that a young regulator ignores at its peril. Read them, then, the way a common-law judge reads foreign authority: as persuasive wisdom, not binding command.
❦ I – X ❧
I
Google Spain SL v AEPD & Mario Costeja González
Case C-131/12, CJEU (Grand Chamber), 13 May 2014
The right to erasure is born from a case
The holding
A Spaniard tired of an old auction notice about his debts surfacing when strangers searched his name. From that small indignity the Court fashioned a doctrine: a search engine is a controller of the personal data it indexes, and an individual may, in appropriate cases, require the de-referencing of results that are inadequate, irrelevant, or no longer relevant — unless a preponderant public interest in access prevails. The “right to be forgotten” entered EU law not by statute but by adjudication, and only later was codified as Article 17 GDPR.
For the Board
India has no express right to be forgotten — only the erasure right in Section 12 and the retention-and-deletion regime in Rule 8. The Delhi and Bombay High Courts have meanwhile been improvising an ad hoc RTBF jurisprudence (see Jorawer Singh Mundy and Zulfiqar Ahman Khan), tethered loosely to Puttaswamy. The lesson of Costeja is that erasure is where the abstract right to privacy meets the concrete architecture of the internet — and that the balance against the freedom of expression under Article 19(1)(a) of the Constitution cannot be struck by formula. The Board will be asked to draw this line long before Parliament clarifies it. It should build a principled, published test now, rather than deciding each plea on its facts and calling it a day.
II
Schrems I & Schrems II
Cases C-362/14 (6 Oct 2015) & C-311/18 (16 July 2020), CJEU (Grand Chamber)
Independence, and the courage to say no
The holding
An Austrian law student took on the transatlantic data economy — and won twice. Schrems I struck down the EU–US Safe Harbour arrangement; Schrems II demolished its successor, the Privacy Shield, holding that standard contractual clauses survive only where supplementary measures genuinely protect data against foreign surveillance. Buried in Schrems I is a quieter but deeper holding: a supervisory authority must be able to examine a transfer with complete independence, even when its own government has blessed the destination.
For the Board
India’s Section 16 inverts Europe’s logic — transfers are free unless the Central Government blacklists a country. That places the transfer question largely outside the Board’s hands. But the real Schrems lesson is not about transfers at all; it is about institutional spine. A data protection authority earns its legitimacy on the day it rules against the very executive that appoints and funds it. The composition, tenure protection, and removal safeguards around the Board (Sections 18–20 read with the Rules) will be tested not by the easy cases against private fiduciaries, but by the hard one against the State. Independence is not a founding document; it is a habit proven under pressure.
III
Breyer v Germany · EDPS v SRB
Cases C-582/14 (19 Oct 2016) & C-413/23 P (4 Sept 2025), CJEU
What counts as personal data is the whole ballgame
The holding
In Breyer, the Court held that a dynamic IP address is personal data in the hands of a website operator if it has a realistic legal means to obtain the identity behind it — a relative, context-sensitive test of identifiability. Nine years later, in SRB, the Court refined the point for the age of pseudonymisation: the same dataset may be personal data for the controller who holds the re-identification key and effectively anonymous for a recipient who cannot realistically re-identify anyone. Identifiability is a question of capability, not metaphysics.
For the Board
The single most consequential ruling the Board will ever make is also its most abstract: what is “personal data” under Section 2(t), and who is a “Data Principal” under Section 2(j)? Adopt too broad a test and every hashed identifier, every device token, every anonymised research set is dragged into the regime. Adopt too narrow a test and re-identification attacks gut the law from beneath. The scholarship here is decades deep — from Schwartz and Solove’s work on the instability of “personally identifiable information” to the CJEU’s own relative approach. The Board should reach for the relative, risk-based standard of Breyer and SRB rather than a brittle binary. Get this wrong and every later order rests on sand.
Define “personal data” too grandly and you regulate the whole internet; too meanly and you regulate nothing at all.
— The first and hardest question a Board must answer
IV
Planet49 GmbH
Case C-673/17, CJEU (Grand Chamber), 1 October 2019
Consent by inertia is not consent
The holding
A promotional lottery hid its cookie consent behind a pre-ticked box. The Court held this fails the GDPR standard: valid consent demands an active, specific, informed, unambiguous choice by clear affirmative action, and cannot be bundled with an unrelated purpose or inferred from a user’s failure to un-tick. Silence, the Court effectively ruled, is golden only for the person who chooses to stay silent — not for the one who profits from their inattention.
For the Board
Section 6 sets India’s consent bar high on paper — free, specific, informed, unconditional, unambiguous, with a clear affirmative action, and as easy to withdraw as to give — and Rule 3 layers on itemised notice. The Board will very soon face India’s own Planet49: dark patterns, consent-walls, and the peculiarly Indian problem of genuine, informed consent across languages, literacies, and interfaces. Planet49 and its successors (through Meta v Bundeskartellamt) teach that the medium of consent is where rights are won or lost. The Consent Manager ecosystem (Rule 4) is India’s bold structural bet on solving consent fatigue; the Board must ensure it becomes an instrument of choice, not a new and more elaborate box already ticked.
V
Fashion ID GmbH v Verbraucherzentrale NRW
Case C-40/17, CJEU (Second Chamber), 29 July 2019
You cannot contract your way out of responsibility
The holding
An online retailer embedded Facebook’s “Like” button; the button quietly transmitted visitors’ data to Facebook whether or not they clicked. The Court held the retailer a joint controller for the collection and transmission it enabled — responsibility follows the influence you exercise over the means and purposes of processing, even where you never touch the data yourself. Responsibility is apportioned to the stage of processing each party actually determines.
For the Board
The DPDPA’s architecture rests on a single load-bearing figure — the Data Fiduciary (Section 2(i)) — and a supporting Data Processor. But the real digital economy is a lattice of SDKs, analytics pixels, ad-tech intermediaries, and platform plug-ins in which everyone points at everyone else. Fashion ID is the Board’s field guide to that lattice: liability tracks control, not the fine print of a data-processing agreement, and two or more parties can be fiduciaries together. When the first “it was the vendor’s fault” defence lands on the Board’s desk, this is the case that answers it.
VI
Meta Platforms Inc. v Bundeskartellamt
Case C-252/21, CJEU (Grand Chamber), 4 July 2023
One dataset, many regulators
The holding
Germany’s competition authority found Meta’s cross-service data combination abusive; the question reached Luxembourg. The Court held that a competition regulator may, incidentally, assess GDPR compliance; that “necessity” for performing a contract is read strictly; that merely visiting a website or app can reveal special-category data engaging Article 9; and that a user typing sensitive information does not thereby make it “manifestly public.” It also gestured at “consent or pay.”
For the Board
India has no sensitive-data category and no legitimate-interest clause, so parts of this judgment do not map. But its deepest lesson is institutional and it maps perfectly: data protection does not live on an island. The same conduct can simultaneously engage the CCI (competition), the RBI, SEBI and IRDAI (financial data), TRAI (telecom), and MeitY (intermediary rules). The Board must decide early how it will coordinate — comity, deference, joint action — rather than colliding with sister regulators in a turf war that only the regulated will enjoy. And on the substance of Section 7’s “legitimate uses,” Meta’s strict reading of “necessity” is a useful discipline against elastic self-service justifications.
VII
UI v Österreichische Post AG
Case C-300/21, CJEU (Third Chamber), 4 May 2023
A right without a remedy is a slogan
The holding
Austria’s postal service profiled a man’s presumed political affinities; he sued for non-material damage. The Court struck a careful balance: a mere infringement of the GDPR does not, by itself, entitle a claimant to compensation — some actual damage must be shown — but once shown, there is no de minimis threshold of seriousness the harm must clear. Later rulings added that even the loss of control over one’s data, or a well-founded fear of misuse, can qualify, and that an apology may sometimes suffice.
For the Board
Here the comparison turns sharp and uncomfortable. The DPDPA gives the injured individual no right to compensation at all. The Board imposes penalties (up to ₹250 crore under Section 33 and its Schedule) that flow to the Consolidated Fund — not a rupee to the data principal whose dignity was breached. This is a design choice of real philosophical weight: India has built a regime of deterrence without restoration. The Board cannot rewrite the statute, but it should be clear-eyed that European data subjects can be made whole while Indian ones, for now, can only be avenged. Where the maxim runs ubi jus, ibi remedium — where there is a right, there must be a remedy — the Board’s penalty orders are, for the citizen, the only remedy on offer. It should wield that power as though it were.
VIII
La Quadrature du Net & Others
Joined Cases C-511/18, C-512/18 & C-520/18, CJEU (Grand Chamber), 6 Oct 2020
The State is not exempt from proportionality
The holding
Confronting national security laws mandating bulk retention of traffic and location data, the Court refused to treat “national security” as a magic phrase that suspends fundamental rights. General and indiscriminate retention is, as a rule, incompatible with EU law; only targeted, time-limited, judicially-supervised measures, proportionate to a genuine and serious threat, survive scrutiny. The panopticon, the Court effectively said, cannot be the default setting of a free society.
For the Board
This is where India’s design diverges most starkly — and where the Board’s hands are most tied. Section 17(2) hands the Central Government sweeping power to exempt State instrumentalities from the Act, and the Board has no jurisdiction to test those exemptions. The CJEU polices the State; the DPBI, by statutory design, largely cannot. But the reasoning of La Quadrature already lives in Indian law — it is the proportionality standard of Puttaswamy itself. The Board cannot strike down a State exemption, but in every matter that does fall within its remit it can insist that necessity and proportionality are demonstrated, not asserted — and it can, in its reports and advice to Government, be the institutional conscience that names the gap the courts may one day have to fill.
IX
Google LLC v CNIL
Case C-507/17, CJEU (Grand Chamber), 24 September 2019
How far does the writ run?
The holding
France’s regulator wanted de-referencing to apply worldwide, on every Google domain. The Court declined to impose a global erasure by default: EU law requires de-referencing across the Union’s versions, with measures to seriously discourage cross-border access, but does not oblige a global delisting — while pointedly not forbidding one either. Territorial ambition, the Court held, must be tempered by comity and the competing interests of other States.
For the Board
Section 3(b) gives the DPDPA long arms: it reaches processing outside India that is connected with offering goods or services to data principals within India. That is the ambition. Google v CNIL is the reality check: a regulator’s reach and its grasp are different things, and enforcement against a foreign fiduciary with no Indian assets is a problem of comity, cooperation, and practical leverage, not merely of drafting. The Board should invest early in mutual-assistance relationships and in remedies (against Indian-facing app stores, payment rails, and intermediaries) that actually bite — rather than issuing brave orders into the void.
X
SCHUFA (Scoring) · Dun & Bradstreet Austria
Cases C-634/21 (7 Dec 2023) & C-203/22 (27 Feb 2025), CJEU
The machine must explain itself
The holding
In SCHUFA, the Court held that generating a credit score that effectively determines whether a bank extends credit is itself a “decision based solely on automated processing” caught by Article 22 GDPR — you cannot launder an automated decision by having a human rubber-stamp it. In Dun & Bradstreet, it held that the data subject is entitled to meaningful, intelligible information about the logic of such a decision, and that trade secrets are not a trump card that defeats the right to an explanation.
For the Board
And here is the gap that should keep the incoming Members awake. The DPDPA, drafted in the age of generative AI, contains no equivalent of Article 22 — no right against solely-automated decisions, no right to an explanation, no meaningful check on algorithmic profiling. In a country racing to deploy AI in credit, welfare, hiring, and policing, that is a chasm, and the Board cannot legislate one shut. What it can do is read the transparency and fairness obligations it does possess as generously as the text permits, and use its statutory advisory voice to press for reform. As I have argued at book length elsewhere, the laws we write for machines are, in the end, laws we write for ourselves; a data protection regime silent on the algorithm is a regime already a generation behind its subject.
❦ ❧
The GDPR you apply in practice was assembled in Luxembourg between 2014 and 2025 — long after the text was “finished.”
The comparison, condensed
The mirror — and where the glass is missing
If a single table could brief the incoming Board, it would be this one: for each European mechanism, the nearest Indian provision — and, in red, the places where India has simply left the mirror empty.
Theme
GDPR & CJEU
DPDPA 2023 / Rules 2025
Erasure / RTBF
Art. 17; Costeja (C-131/12)
Section 12 erasure; Rule 8 retention. No express RTBF.
Data Fiduciary, Section 2(i) — co-fiduciaries by analogy.
Lawful basis / sensitive data
Arts. 6, 9; Meta v Bundeskartellamt
Sections 4, 7 “legitimate uses.” No sensitive category; no legitimate-interest clause.
Compensation
Art. 82; Österreichische Post
No private compensation. Penalties to Consolidated Fund (Section 33).
State surveillance
Arts. 6, 23; La Quadrature du Net
Section 17(2) exemptions. Board has no jurisdiction to test them.
Territorial reach
Art. 3; Google v CNIL
Section 3(b) extraterritorial application.
Automated decisions
Arts. 15(1)(h), 22; SCHUFA, D&B
No ADM right; no right to explanation.
Beneath the ten, four
The lessons behind the lessons
Strip the ten cases to their marrow and four cross-cutting truths remain — the ones I would want framed on the wall of the Board’s first meeting room.
1. The definition is the destiny.
Everything downstream — consent, breach, penalty, transfer — depends on what “personal data” and “Data Principal” are held to mean. Breyer and SRB warn that this is a question of realistic capability to identify, not of labels. Decide it first, decide it well, and publish the reasoning.
2. Independence is proven, not proclaimed.
Schrems teaches that a regulator’s worth is measured on the day it disappoints the government that made it. The Board’s credibility will be built or broken in its first hard case against the State or a national champion.
3. Proportionality is the master key.
La Quadrature abroad and Puttaswamy at home speak the same grammar. Even where the Board’s jurisdiction is narrow, proportionality — necessity, minimal intrusion, demonstrable justification — is the lens through which every order should be reasoned.
4. A right without a remedy is a rumour.
Ubi jus, ibi remedium. Because the DPDPA offers the citizen no compensation, the Board’s orders are the remedy. That is a heavy trust. A regulator that becomes a mere post-office — forwarding complaints, logging breaches, issuing form letters — will have kept the letter of the Act and lost its soul.
#
Case
The habit to inherit
I
Google Spain (C-131/12)
Build a published erasure test; balance dignity against Art. 19(1)(a).
II
Schrems I & II
Rule against your own maker when the law requires it.
III
Breyer · SRB
Adopt a relative, risk-based test of identifiability.
IV
Planet49 (C-673/17)
Police dark patterns; make Consent Managers real choice.
V
Fashion ID (C-40/17)
Liability follows control, not the contract.
VI
Meta v Bundeskartellamt
Coordinate with sister regulators; read “necessity” strictly.
VII
Österreichische Post
Treat penalty orders as the citizen’s only remedy.
Match ambition with cooperation and remedies that bite.
X
SCHUFA · D&B
Read transparency generously; press to close the ADM gap.
Ten judgments, ten habits — a one-page induction for an eleven-day-old regulator.
In closing
An empty chair, and the weight upon it
There is something almost fitting in writing this while the Board’s chair sits empty. A statute is a promise; an institution is the keeping of it. India has kept the first half — the Act, the Rules, the Gazette — and stands at the threshold of the second. When the Chairperson and Members are at last appointed, they will not find a finished body of law waiting for them. They will find forty-four sections, a set of rules, and a vast, echoing silence where the interpretation should be. That silence is not a defect. It is an invitation. The GDPR’s meaning lives in Luxembourg’s judgments; the DPDPA’s meaning will live in the Board’s orders, and nowhere else.
The European experience offers no template to copy, but it offers something better: proof that a data protection law becomes real only through the patient courage of the body that enforces it. The Court of Justice took eleven years and more than ninety-nine judgments to make the GDPR mean what it says. India’s Board should not expect to take less. It should begin, though, with the right instincts — and those instincts are already written, in ten judgments from a court a continent away, waiting to be read by whoever finally sits down in that chair.
Fiat justitia, ne pereat mundus. Let justice be done, that the world may not perish — and let the Board be the doing of it.
Sources & further reading
Judgments of the Court of Justice of the European Union
Google Spain SL v AEPD & Costeja González, C-131/12, EU:C:2014:317 (13 May 2014).
Schrems v Data Protection Commissioner, C-362/14, EU:C:2015:650 (6 Oct 2015); Data Protection Commissioner v Facebook Ireland & Schrems, C-311/18, EU:C:2020:559 (16 July 2020).
Breyer v Bundesrepublik Deutschland, C-582/14, EU:C:2016:779 (19 Oct 2016); EDPS v Single Resolution Board, C-413/23 P (4 Sept 2025).
Bundesverband v Planet49 GmbH, C-673/17, EU:C:2019:801 (1 Oct 2019).
Fashion ID GmbH v Verbraucherzentrale NRW, C-40/17, EU:C:2019:629 (29 July 2019).
Meta Platforms Inc. v Bundeskartellamt, C-252/21, EU:C:2023:537 (4 July 2023).
UI v Österreichische Post AG, C-300/21, EU:C:2023:370 (4 May 2023).
La Quadrature du Net & Others, Joined Cases C-511/18, C-512/18 & C-520/18, EU:C:2020:791 (6 Oct 2020).
Google LLC v CNIL, C-507/17, EU:C:2019:772 (24 Sept 2019).
SCHUFA Holding (Scoring), C-634/21, EU:C:2023:957 (7 Dec 2023); Dun & Bradstreet Austria, C-203/22 (27 Feb 2025).
Indian authority
K.S. Puttaswamy (Retd.) v Union of India (2017) 10 SCC 1 (privacy; proportionality); (Aadhaar) (2019) 1 SCC 1.
Shreya Singhal v Union of India (2015) 5 SCC 1.
Jorawer Singh Mundy v Union of India, Delhi HC (2021); Zulfiqar Ahman Khan v Quintillion Business Media, Delhi HC (2019) — on the emerging right to be forgotten.
Digital Personal Data Protection Act, 2023; Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E), notified 13 Nov 2025).
Scholarship & commentary
O. Lynskey, The Foundations of EU Data Protection Law (OUP 2015).
G. González Fuster, The Emergence of Personal Data Protection as a Fundamental Right of the EU (Springer 2014).
C. Kuner, Transborder Data Flows and Data Privacy Law (OUP 2013).
L.A. Bygrave, “Minding the Machine v2.0: The EU GDPR and Automated Decision-Making” (on Art. 22).
P.M. Schwartz & D.J. Solove, “The PII Problem: Privacy and a New Concept of Personally Identifiable Information” (2011) 86 NYU L Rev 1814.
D.J. Solove, “A Taxonomy of Privacy” (2006) 154 U Pa L Rev 477; S. Warren & L. Brandeis, “The Right to Privacy” (1890) 4 Harv L Rev 193.
G. Greenleaf, Asian Data Privacy Laws (OUP 2014) and subsequent analyses of India’s DPDP Act in Privacy Laws & Business International Report.
Committee of Experts (Chair: Justice B.N. Srikrishna), A Free and Fair Digital Economy (2018).
PM
Adv. (Dr.) Prashant Mali
Technology, cyber and data-protection lawyer practising before the Supreme Court of India and the Bombay High Court; Founder & President, Cyber Law Consulting; Chairman, Cyber & Law Foundation; creator of dpdpa.com. Author of eight books, including Seven AI Laws: The Future of Mankind.
Disclaimer. This blog is a comparative legal-educational opinion prepared for publication on dpdpa.com and reflects the position as understood on 10 August 2026, when the Data Protection Board of India had been constituted in law but its Chairperson and Members had not yet been appointed. It is general commentary, not legal advice for any specific matter, and does not create an advocate–client relationship. Case citations are provided for reference; readers should verify current status, as data-protection jurisprudence in both the EU and India continues to evolve. For advice on a particular situation, please consult qualified counsel.