CJEU C‑414/24 (18 June 2026): parallel GDPR remedies are not exclusive
The CJEU confirms that GDPR complaints to the authority (Art. 77) and judicial actions (Art. 79) are parallel and not mutually exclusive. An authority may not dismiss a complaint solely because a court action is pending.
Verified fact — On 18 June 2026, the CJEU (C‑414/24, Datenschutzbehörde) confirmed that the GDPR routes of complaint to a supervisory authority (Art. 77) and court action (Art. 79) can be exercised in parallel. An authority may not reject a complaint solely because a court action on the same subject matter is pending or already adjudicated. Official source: full judgment on EUR‑Lex (EN): 62024CJ0414 and (FR): 62024CJ0414. Case file: InfoCuria C‑414/24.
The case
Referred for a preliminary ruling, the Court clarified the interplay between:
- the right to lodge a complaint with a supervisory authority (GDPR Article 77), and
- the right to an effective judicial remedy against a controller (GDPR Article 79).
The Court’s answer: the two avenues are parallel and not mutually exclusive. The right to an effective remedy (Charter, Article 47) precludes an authority from declaring a complaint under Article 77 inadmissible or closed solely because a case under Article 79 is pending.
Legal reasoning
- Legal basis: Articles 77, 78 and 79 of GDPR Chapter VIII, read in the light of Article 47 of the Charter. For a refresher on the GDPR Articles 77–79, see also the CNPD (Chapter VIII FR/EN/DE).
- Interpretation: the Court confirms that these remedies are cumulative and “without prejudice” to each other (see C‑132/21, 12/01/2023; SCHUFA C‑26/22 and C‑64/22, 07/12/2023). A national system allowing automatic dismissal of a complaint because an Article 79 action is pending undermines the right to an effective remedy and the GDPR’s enforcement architecture.
- Practical scope: a supervisory authority may coordinate or suspend case by case, but it may not refuse, in principle, to handle an Article 77 complaint due to an ongoing Article 79 case.
Impact in Luxembourg
CNPD procedure: the official “Procedure for complaints before the CNPD” (updated 06/03/2026) includes an admissibility condition that “the very subject of the complaint is not simultaneously the subject of court proceedings.” In light of C‑414/24, such automatic inadmissibility is hardly compatible with the GDPR: the CNPD should allow parallel exercise and, where needed, organise targeted procedural coordination rather than rejection. For operational compliance in Luxembourg, also see our page on CNPD compliance in Luxembourg.
DPOs, CISOs, in‑house counsel: when an employee, customer or candidate brings a court action (Art. 79) while filing a complaint (Art. 77), expect parallel proceedings. Stances and responses (Arts. 12–15: access, rectification, erasure, restrictions) must be consistent and defensible in both fora. Need support structuring approvals and responses? See our DPO mandate and data subject rights responses.
Deadlines and content: keep to deadlines (GDPR Art. 12(3) — one month extendable) and ensure evidence quality: what you submit to the authority may also be used in court, and vice versa.
2026 context: the CNPD highlights efficient complaint handling and cooperation between authorities (EDPB workshop, Luxembourg, 25–27/03/2026). The CJEU’s clarification reinforces this shift from formal admissibility to merits, with heightened traceability expectations.
Use cases
- Banks/insurers/PSFs and employers: access (Art. 15) or restriction (Art. 18) requests in HR disputes, claims, PEP/KYC or fraud often cross authority/court boundaries. Prepare duplicable evidence files from the first reply.
- NIS 2 operators and DORA entities: after a security incident with personal impact (Art. 34 notification, log access requests), a damages action (Arts. 82/79) may arise while a complaint (77) targets your information/minimisation practices.
- Public sector and education: “GDPR charters” and general notices are challenged via parallel complaints and actions; authorities must address the merits and avoid automatic dismissals.
Frequent pitfalls
- Conditioning internal admissibility of access requests on the absence of ongoing litigation. Align procedures with the principle of parallel remedies.
- “Minimal” replies without proof (extraction logs, recipient lists, timestamps).
- Conflating “trade secrets” with blanket refusals: provide reasoned, proportionate responses (Arts. 12(4), 15(4)).
- Automatic “freeze” of complaint handling upon service of a writ: only targeted, reasoned, reviewable stays are defensible.
- Fragmented governance: implement a single approval flow (templates, QA, evidential archiving ≥ 3 years).
Official sources
- CJEU, 18 June 2026, C‑414/24, Datenschutzbehörde — EUR‑Lex (EN): https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62024CJ0414 and (FR): https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX:62024CJ0414; case file InfoCuria C‑414/24.
- CNPD Luxembourg — Chapter VIII (GDPR remedies): EN and FR.
- CNPD — Procedure for complaints (updated 06/03/2026): PDF.
- CNPD — News: “complaint handling” workshop (25–27/03/2026): link.
- CNPD — GDPR Chapter III (rights 15–22): link.
In brief
Since 18 June 2026, any corporate policy in Luxembourg conditioning the handling of a GDPR complaint on the absence of parallel litigation must be revised. Implement traceable, consistent responses ready for both the CNPD and the courts.
Luxgap regulatory expertise article. For personalised guidance on this topic, contact us or configure your online quote.
A question on this topic?
Our team usually replies within one business day. Configure your quote or write to us.
Build my quote →