EU GDPR enforcement

CJEU Closes Sweden's Publishing-Certificate Loophole, Exposing Commercial Court-Records Vendors to Direct GDPR Damages

A 9 July 2026 CJEU ruling strips Sweden's constitutional press exemption from a paid criminal-records database, reviving an individual's damages claim EU-wide.

The Lexbase Ruling, by the Numbers People of Internet Research · EU SEK 300,000 Revived damages claim ND's Article 82 claim against Lega… 27 Member states bound The judgment applies across the EU… 10+ Years conviction stayed searchable ND's 2011 robbery conviction remai… ~40% GDPR fines challenged on appeal Share of cumulative administrative… peopleofinternet.com
The Lexbase Ruling, by the Numbers People of Internet Research · EU SEK 300,000 Revived damages claim 27 Member states bound 10+ Years conviction stayed searchable ~40% GDPR fines challenged on ap… peopleofinternet.com

Key Takeaways

A rubber-stamp certificate meets its limit

On 9 July 2026, the Court of Justice of the European Union ruled in ND v Legal Newsdesk Sweden AB (Case C-199/24) that Sweden cannot use its constitutional "publishing certificate" system to remove a commercial database wholesale from GDPR scope. The judgment, issued by the Fifth Chamber following an Advocate General Szpunar opinion delivered 4 September 2025, arose from a reference by the Attunda District Court and settles a question that has hung over Swedish data protection law for years: can a business buy its way out of the GDPR simply by holding a piece of paper.

The database at issue, Lexbase, is operated by Legal Newsdesk Sweden AB (formerly Garrapatica AB) and lets subscribers search Swedish criminal court judgments by name. A man identified in the ruling as ND was convicted of robbery in 2011; more than a decade later he discovered his conviction was still fully searchable on Lexbase. The company removed the record only under its own internal retention policy, not in response to his erasure request, and he sued for SEK 300,000 (roughly €26,000) in damages under GDPR Article 82. Sweden's legal position was that Lexbase's publishing certificate — a constitutional press-freedom credential the state grants with minimal scrutiny — placed the entire service outside the GDPR's reach, leaving ND with no EU-law remedy at all (CJEU press release No 100/26; EUR-Lex judgment text).

What the Court actually decided

The Court rejected that reading. GDPR Article 85 lets member states reconcile data protection with freedom of expression, but only by carving out processing done for "journalistic, academic, artistic or literary purposes" — it does not authorize a general exemption keyed to any national press-law credential. Making conviction records searchable online for a fee, the Court held, does not in principle amount to journalistic processing unless the operator exercises something resembling actual editorial judgment: selection, verification of the facts, and an identifiable editorial policy, rather than bulk republication of public records. Critically, the Court also held that a member state cannot use Article 85 to strip individuals of their GDPR Chapter VIII remedies — supervisory complaints, judicial actions under Article 79, and compensation under Article 82 — even where a national free-expression framework applies. The Court left the final call on whether Lexbase's specific service clears the journalism bar to the Swedish court, but ND's damages claim is now reinstated and proceeding (Advokatfirman Lindahl analysis).

The case for the ruling

The privacy case here is genuinely strong, and it deserves to be stated plainly rather than waved away. Sweden's own criminal-justice system treats old convictions as eligible for expungement from certain public records after set periods — the entire premise of a "spent conviction." A commercial vendor charging subscribers to keep that same conviction permanently and prominently searchable, indefinitely, under a certificate that Swedish authorities grant close to automatically on request, is hard to distinguish from renting out a loophole. GDPR's data minimization and purpose-limitation principles exist precisely to stop personal data from circulating forever merely because it was once lawfully public. A national carve-out broad enough to swallow the entire regulation for any company that files the right paperwork undermines the harmonization the GDPR was built to deliver across all 27 member states, and the Court was right to police that boundary.

Where the line gets harder to hold

Where the ruling runs into real difficulty is the test it substitutes: "editorial policy" and "verification of the factual allegations." That standard maps cleanly onto a newsroom. It maps far less cleanly onto the legal-tech, compliance-screening, and due-diligence sectors that legitimately need to index and republish public court records — background-check providers, credit-risk databases, sanctions and litigation-history screening tools used by banks and employers across the EU. None of these exercise newsroom-style editorial selection over individual records, because their value proposition is comprehensiveness, not curation. Under this ruling, each now carries direct Article 82 exposure — a private damages route that, unlike an administrative fine, cannot be neutralized by a regulator settlement and is harder to appeal away; commentators note roughly 40% of cumulative GDPR fines to date have been challenged or annulled on appeal, a safety valve private damages claims largely lack.

The better fix is not to abandon the journalism test but to sharpen it with something closer to a bright line: tie permissible retention of criminal-record data to the same expungement periods Swedish law already applies to the underlying conviction, rather than forcing every records aggregator into an open-ended editorial-policy inquiry decided case by case in national courts. That would close the actual loophole — indefinite, unaccountable monetization of decade-old convictions — without dragging ordinary compliance and legal-research infrastructure through years of Article 82 litigation to find out where the new line sits. Until national courts or the EDPB supply that clarity, expect commercial data vendors across the bloc to over-remove defensively, which is its own cost to legitimate public-interest access to court records.

"The mere placing online, in return for payment, of decisions on criminal convictions does not in principle constitute processing of personal data for 'journalistic purposes.'" — CJEU press release, 9 July 2026

Sources & Citations

  1. CJEU Press Release No 100/26
  2. EUR-Lex, Case C-199/24 judgment text
  3. PPC Land: CJEU blocks Sweden's GDPR exemption
  4. Advokatfirman Lindahl: CJEU sets limits on Sweden's GDPR exemption