Anyone who processes personal data without valid consent risks a fine from the Data Protection Authority (GBA). But what if the database in question hasn’t been used for years by the time the regulator makes its decision? In a judgment dated June 3, 2026 The Marktenhof confirms that data broker Infobel is the General Data Protection Regulation (GDPR) violated, but it reduces the fine from 40,000 to 5,000 euros and overturns the orders to remove the content and to notify, because they each lacked a specific subject matter. The case illustrates where the line is drawn between establishing an infringement and ensuring the proportionality of the sanction.
The facts
The case stems from a complaint filed by a citizen with the GBA on October 18, 2023, against Infobel, a commercial data broker. The complainant discovered that his personal data had been processed and resold for direct marketing purposes without him ever having given Infobel direct consent to do so. The data originally came from a telecommunications operator, which had passed it on to Infobel; Infobel, in turn, supplied it to a media agency that sent marketing materials to the complainant.
The GBA’s Dispute Resolution Chamber split the case and handled the portion against Infobel separately. On November 27, 2025, it ruled in its decision No. 199/2025 Finding that Infobel had violated Articles 5.1(a), 6, and 24 of the GDPR, it imposed an administrative fine of 40,000 euros and ordered the erasure of the data for which no valid legal basis could be demonstrated, with notification to all customers. Infobel filed an appeal with the Marktenhof.
One factual detail proved decisive: Infobel had already deleted the entire database it had obtained from the operator in 2023, with the exception of data pertaining to individuals who had explicitly requested not to be contacted anymore. That deletion was confirmed and not disputed during the hearing on June 25, 2025, before the Dispute Resolution Chamber.
The decision
The Marktenhof declares the appeal admissible and partially well-founded. The substantive GDPR determination remains in effect, but the penalty will be significantly adjusted.
The GDPR violation has been confirmed
The Court confirms that Infobel, as the data controller, must be able to demonstrate that the data subject has given valid consent. Pursuant to Article 7(1) of the GDPR, the burden of proof regarding valid consent rests with the data controller, and Article 24 of the GDPR requires the data controller to demonstrate that the processing is lawful. A mere reference to contractual statements or guarantees from the supplier is not sufficient. The consent given in 2006 through the operator’s terms and conditions did not meet the requirements of Article 4(11) of the GDPR: it was not freely given (the marketing purpose was intertwined with the telecommunications contract), was not specific (there was no separate opt-in for resale), was not informed (the complainant could not have known that Infobel, in particular, would exploit his data for commercial purposes), and was not unambiguous (it involved an opt-out system). The violation of Article 5.1(a) in conjunction with Articles 6 and 24 of the GDPR is therefore established.
The Court also rejects the argument that the GBA applied Articles 24 and 7 of the GDPR anachronistically by assessing a situation from 2006 under standards introduced at a later date. The processing at issue is ongoing processing that continued after May 25, 2018; the validity of the consent is assessed at the time of that ongoing processing, not at the time of the original collection.
The orders for erasure and notification are set aside
In this regard, the Court of Appeal disagrees with the Dispute Resolution Chamber. Because Infobel had already deleted the data in question in 2023, the order to delete the data lacks any concrete subject matter. Furthermore, the Court rules that an order that applies generally to “all data for which Infobel cannot demonstrate a valid legal basis” exceeds the Dispute Chamber’s authority: a supervisory authority cannot issue a general deletion order without a prior, individualized investigation and without a complaint. The order is therefore without subject matter and is set aside. The ancillary order requiring notification to customers meets the same fate.
The fine is reduced to 5,000 euros
The Court exercises full jurisdiction over the sanction. It first rejects the argument that the fine is intended to penalize three separate violations: the violations of Articles 5.1.a), 6, and 24 of the GDPR constitute a single, coherent violation, and Article 83(3) of the GDPR permits the imposition of a single fine for this, capped at the amount applicable to the most serious violation.
However, the Court ruled that the Dispute Chamber had misjudged the severity of the case. It characterized the processing as “significant” and “large-scale,” even though the exact number of individuals affected was unknown and there had been only one complaint. It did not take sufficient account of mitigating circumstances: Infobel had no prior violations or complaints, had cooperated with the proceedings, and had already deleted the database in 2023—a measure that limited the harm to the individuals concerned. Applying the EDPB Guidelines 04/2022 Regarding the calculation of administrative fines, the Court reduces the fine to 5,000 euros.
Legal analysis and interpretation
The data broker’s independent burden of proof remains central
The fundamental significance of this case lies not in the reduction of the fine but in the affirmation of the independent accountability of those who process purchased data. The Court explicitly enshrines this obligation in the interplay between Article 7(1) and Article 24 of the GDPR, thereby aligning with the Court of Justice’s Proximus ruling, in which it was held that anyone who receives data from a subscriber or a third party and wishes to use it for other purposes must obtain the data subject’s consent again (ECJ, October 27, 2022, C-129/21). The reasoning confirms that a B2B data protection chain does not function as a mere conduit: each link in the chain that acts as a data controller bears its own burden of proof and cannot hide behind contractual guarantees provided by the source.
It is a misconception to interpret this ruling as a softening of that stance. The violation is upheld in its entirety; only the penalty is made more proportionate. The message to the data brokerage sector therefore remains stern.
The Limits of Remedial Measures: No Abstract Order to Erase
From a legal perspective, the most interesting aspect is the delineation of the supervisory authority’s power to issue orders. The Court makes a fundamental distinction between remedial measures under Article 58(2) of the GDPR and the administrative fine under Article 83 of the GDPR, and rules that an order to erase data may not be formulated in abstract and open-ended terms. An order that extends to all data “for which no valid legal basis can be demonstrated,” without an individualized investigation and without an underlying complaint, falls outside the jurisdiction of the Disputes Chamber.
That is a significant limitation. Regulators tend to formulate their orders broadly to prevent recurrence, but the Court ties the remedial measure to the specific subject matter of the case. An order without a current subject matter—because the processing has already been discontinued—cannot remain in effect merely as a matter of principle.
Proportionality as a full-fledged test of validity, not as a mere formality
The reduction of the fine from 40,000 to 5,000 euros illustrates that the Marktenhof is effectively exercising its full jurisdiction. The Court does not merely assess whether the reasoning is formally sufficient, but also reassesses the severity of the violation and the mitigating circumstances itself. The fact that the regulator had labeled the violation as “large-scale” without determining the number of individuals involved, and had not sufficiently acknowledged the timely removal of the database, was sufficient to reduce the penalty by a factor of eight. For anyone challenging a GBA fine, this confirms that the proportionality test is an independent and fruitful basis for reconsideration, even when the violation itself is indisputably established.
Specifically, what does this mean?
For data brokers and marketing agencies. The core of Decision No. 199/2025 stands up to the appeal: anyone who uses purchased data must be able to prove the opt-in themselves and cannot rely on contractual guarantees from the supplier. Due diligence regarding the origin and validity of consent remains indispensable. At the same time, the ruling offers a concrete line of defense: anyone who removes a problematic database in a timely and demonstrable manner before the regulator issues a decision not only limits the damage but also secures a genuine mitigating circumstance that can significantly reduce the fine and render orders to delete the data moot.
For those who are contesting a GBA fine. An appeal to the Marktenhof is more than just a marginal review of legality. The Court exercises full judicial authority and independently reassesses the severity, mitigating circumstances, and proportionality. It is therefore worthwhile not only to challenge the violation itself, but also—and often with a greater chance of success—to challenge the proportionality of the sanction and the scope of the remedial measures imposed. Orders that are formulated in abstract terms or that have lost their purpose are particularly vulnerable.
For those involved. The finding that a data broker violated the GDPR stands: you can successfully have the unlawfulness of a processing operation established. Please note, however, that an individual complaint does not result in a general order to erase data from the processor’s entire database; the supervisory authority remains bound by the specific subject matter of your case.
Frequently asked questions (FAQ)
Can a GBA fine be reduced by a judge, even if the violation has been established?
Yes. The Marktenhof exercises full judicial authority and may independently reassess the fine based on the severity of the violation and any mitigating circumstances, even when the violation of the GDPR itself is not disputed. In this case, the fine of 40,000 euros was reduced to 5,000 euros.
Does it help to delete a problematic database before the GBA makes a decision?
Yes. The timely and verifiable deletion of the relevant data is considered a mitigating factor that may reduce the fine. Furthermore, a deletion order issued subsequently may be declared moot, since there is nothing left to delete.
Can the Data Protection Authority issue a general order to delete data?
Not unlimited. An order that applies generally to all data for which no legal basis can be demonstrated, without an individualized review and without an underlying complaint, exceeds the authority of the Dispute Resolution Chamber. The order must be limited to the specific subject matter of the case.
Conclusion
This ruling reaffirms the strict stance on the trade in personal data: a data broker bears the independent burden of proof regarding the validity of consent and cannot hide behind its supplier’s guarantees. At the same time, the Market Court demonstrates that the sanction is a fully-fledged and separate criterion. The finding of an infringement stood, but the fine was reduced by a factor of eight, and the overly broad orders were set aside because they had lost their specific purpose. The determination of an infringement and the proportionality of the sanction are thus two distinct issues, each with its own grounds for defense.



