Three new judgments on the right to information: What companies need to consider now
Three new judgments of the European Court of Justice (ECJ) have further specified the information claims of the GDPR. These decisions concern, in particular, the duty of controllers to respond to requests for information, even if they appear to be excessive. In addition, data must be provided in a machine-readable form in order to enable processing by third parties. The rulings underline that companies must not simply refuse when a request for information is made, but must provide the data in a form that is comprehensible to computers. This applies for example to CSV files or XML formats. The decisions are particularly relevant for companies working with third parties, as they need to make data processing more transparent. In addition, it becomes clear that those responsible must not limit their duties to the mere provision of data, but also check the quality and relevance of the data. The rulings show that the GDPR is not only a framework, but also contains concrete guidelines for action that companies must observe. The information claims are a central part of the GDPR, as they enable the data subjects to obtain information about their data processing. The new rulings clarify how far these claims go and how companies must meet them. The decisions are a sign that the European Union takes GDPR compliance seriously and commits companies to making their processing more transparent. Companies must therefore be aware that they not only provide the data, but also check its quality and relevance. Information claims are a central component of the GDPR and play a decisive role in securing the rights of those affected. The new judgments help to define the limits of information claims and show how companies can implement them in concrete terms. The decisions are especially important for companies working with third parties, as they need to make data processing more transparent. In addition, the judgments underline that those responsible must not limit their duties to the mere provision of data, but also check the quality and relevance of the data. The new rulings are a sign that the GDPR is not only a framework, but also contains concrete guidelines for action that companies must observe. The compensation claims are a central part of the GDPR and play a decisive role in securing the rights of those affected. The new judgments help to define the limits of information claims and show how companies can implement them in concrete terms. The decisions are especially important for companies working with third parties, as they need to make data processing more transparent. In addition, the judgments underline that those responsible must not limit their duties to the mere provision of data, but also check the quality and relevance of the data. The new rulings are a sign that the GDPR is not only a framework, but also contains concrete guidelines for action that companies must observe. Information claims are a central component of the GDPR and play a decisive role in securing the rights of those affected.
## What does this mean for your company? The three judgments show that companies cannot simply refuse when a request for information is made. You must provide the data in a machine-readable form and check the quality of the data. This is especially true for companies that work with third parties, as they need to make data processing more transparent. The obligations of the controllers are not only limited to the provision of data, but also to ensuring the relevance and quality of the data. Companies must be aware that they not only consider the GDPR as a framework, but also have to observe concrete action guidelines. Information claims are a central component of the GDPR and play a decisive role in securing the rights of those affected. The new judgments help to define the limits of information claims and show how companies can implement them in concrete terms.
## How ISN/xynap supports this The infrastructure is GDPR compliant and offers a secure, self-hosted platform that supports compliance with GDPR requirements.