In the ever-evolving landscape of privacy law, the European Court of Justice’s (CJEU) ruling of February 27, 2025, clarifies the balance between the right to access personal data and the protection of trade secrets.
The judges in Luxembourg addressed a delicate and increasingly relevant issue: to what extent can a data controller invoke trade secrets to deny a data subject access to their personal data?
The right to access personal data, enshrined in Article 15 of the GDPR, is a cornerstone of European data protection regulations. It’s not merely about knowing what information is processed but also understanding how it is processed and its implications. However, Article 15 and Recitals 4, 63, and 71 of the GDPR stipulate that this right is not absolute. It must be balanced against other fundamental rights, including – and this is the core of the ruling – those related to trade secrets and intellectual property.
This judgment is set to have a significant impact not only on European citizens but also on businesses, which will need to rethink their approach to data management and know-how protection.
The Case: Credit Scoring and Opaque Algorithms
Case C-203/22 originated from a dispute where an individual requested access to their personal data from an Austrian credit scoring company, along with an explanation of the automated mechanism used for their “profiling” and credit worthiness score. The company denied access to some information, arguing that revealing the algorithmic system’s operation would compromise its trade secrets and involve third-party data.
The case was brought before national courts, which asked the CJEU whether it was lawful, in light of the GDPR, to deny access based on a national provision that generally excludes a data subject’s access to their personal data if such access risks disclosing a commercial or business secret of the data controller or third parties.
The Court’s Ruling: No to Automatic Denials
The Court outlined the applicable principles and provided specific answers. First and foremost, a national law that allows for the automatic rejection of personal data access requests solely because they might involve the disclosure of trade secrets is inadmissible. Any limitation to the right of access must be assessed on a case-by-case basis, considering the fundamental rights of all parties involved.
If a data controller believes that the information to be provided to the data subject contains third-party data protected by trade secrets, they are obliged to refer the matter to the supervisory authority or the competent court. Only these bodies can weigh the rights and interests at stake to determine the scope of the data subject’s right of access. The Court invoked the principle of proportionality, emphasizing the need to always seek a balance between transparency and confidentiality, avoiding overly rigid approaches from either side.
A particularly relevant part of the judgment concerns automated decisions, such as those made through credit scoring systems. Article 15 of the GDPR provides that data subjects have the right to obtain “meaningful information about the logic involved” in automated decision-making processes.
This does not mean that companies must disclose the source code of their algorithms. However, they must still provide comprehensible explanations of how the system functions and “how” the data subject, or a variation in their data, would affect the obtained result, such as a solvency profile. The right to an “explanation” is therefore not a theoretical abstraction, but a concrete need for understanding, essential for exercising other rights, such as challenging a decision or requesting its human review.
A New Balance Between Transparency and Innovation
This ruling helps redefine the relationship between citizens, businesses, and technology. While it strengthens the right to informational self-determination, it also obliges companies to rethink their compliance strategies. It will no longer be sufficient to generically invoke trade secrets to oppose access requests. Businesses will need to demonstrate, with concrete justifications, that the disclosure of information would cause actual harm to their competitiveness or the protection of their know-how.
Furthermore, it will be the responsibility of supervisory authorities – and, if necessary, the courts – to conduct a careful assessment of the interests involved, deciding if, how, and to what extent access should be granted, perhaps even partially or in an anonymized form. In any case, the point of balance can never be found in the abstract, but only through a concrete and reasoned analysis of each individual case.
On the other hand, a possible side effect of the judgment is the risk of a progressive “judicialization of the right of access.” If every request involving a potential trade secret must be examined by an independent authority, there is a danger of creating bureaucratic bottlenecks and lengthy delays, which could deter citizens from exercising their rights.
Therefore, an organizational effort will be required from supervisory authorities, as well as cultural maturation from businesses, which will need to equip themselves with technical and legal tools to manage requests efficiently, transparently, and in compliance with the law.
Ultimately, the Court is building a jurisprudence that does not take an ideological stance on one side but attempts to balance the rights of individuals with the needs of businesses, transparency with competitiveness. This is a subtle but necessary balance to ensure a legally robust digital society.
Teresa Franza