According to Advocate General Medina, anyone who was baptized as a child and wishes to sever ties with the church as an adult has, in principle, the right to have their personal data erased from the baptismal register under the General Data Protection Regulation. The church may refuse such a deletion only if it demonstrates compelling legitimate grounds, and a note in the margin does not constitute a deletion. That is the gist of the Opinion of Advocate General Medina dated October 1, 2026, in Case C-12/25, Diocese of Ghent v. the Data Protection Authority. The Court of Justice has yet to issue a ruling and is not bound by that opinion.
In short:
- On October 1, 2026, Advocate General Medina advises the Court of Justice that a baptized person who leaves the Church may, in principle, demand that their name be removed from the baptismal register, unless the diocese demonstrates compelling and justified grounds.
- The key issue is the right to object under Article 21 of the GDPR: once an objection has been filed, a mere legitimate interest is no longer sufficient, and the church must demonstrate that it cannot properly administer its sacraments without that data.
- The Diocese of Ghent had merely noted the complainant’s resignation on April 2, 2021, in the margin and legibly crossed out his information; according to the Advocate General, this constitutes, at most, a correction and not an erasure of data.
The facts
The complainant was baptized on June 26, 1955, in the parish of Bijloke in Ghent. In a letter dated March 25, 2021, he asked the Diocese of Ghent to remove any reference to him from any physical or digital register or archive, citing the General Data Protection Regulation (GDPR). On April 2, 2021, the diocese recorded his withdrawal from the Church. It deleted his data but left it readable, and added his name to the parish’s list of those who have left the Church.
The complainant was not satisfied with that. On April 14, 2021, he reiterated his request and filed a complaint with the Data Protection Authority (GBA) that same day. He demanded that any link between himself and any religion or philosophical organization be removed.
The GBA's Dispute Resolution Board ruled in his favor in its Decision 169/2023 of December 19, 2023, largely upheld the decision. It found violations of, among others, Articles 5, 6, 9, 12, 13, and 17 of the GDPR and ordered the diocese to erase the complainant’s personal data within thirty days. The diocese filed an appeal with the Brussels Court of Appeals. In its Interim Judgment of December 11, 2024 The court had doubts about the interpretation of the GDPR and referred five questions to the Court of Justice for a preliminary ruling: Is there a right to be erased from the baptismal register? Does the church’s freedom of religion play a role in this? Does it matter that the register is a unique paper book? Does the exception for archiving and historical research apply? And is a note in the margin sufficient as erasure?
In addition to the diocese, the complainant, and the GBA, several other former members of the church, the Union of Liberal Associations, the Centre d’Action Laïque, the Central Council of Non-Denominational Philosophical Communities, seven member states, and the European Commission also joined the debate. The hearing took place on June 30, 2026.
The Advocate General's opinion
An opinion by the Advocate General is an independent recommendation to the Court of Justice on how it should answer the questions referred for a preliminary ruling. The Court often follows that opinion, but is not bound by it. Therefore, everything stated below represents the position of Advocate General Medina and does not yet constitute case law.
Whether the GDPR applies to a church's paper baptismal register
The Diocese of Ghent and the Latvian government argued that a baptismal register is not a “file” and that the GDPR therefore does not apply. The Advocate General rejects that argument. According to Article 4(6) of the GDPR, a file is any structured set of personal data accessible according to specific criteria. Baptisms are recorded by parish and in chronological order, so that each baptism can be easily located by place and date. That is sufficient, as the Court of Justice has already ruled in its judgment Jehovah's Witnesses (ECJ, July 10, 2018, C-25/17). The fact that the registry is accessible only to a few individuals does not alter this.
The GDPR does not preclude the autonomy of the church either. Article 17 of the Treaty on the Functioning of the European Union requires the Union to respect the status of churches under national law, but that does not mean that churches are above the law. In fact, the GDPR explicitly regulates data processing by churches and religious associations in Article 9(2)(d) and Article 91.
Whether the processing prior to the objection was lawful
The complainant and the GBA relied on two grounds for erasure: the unlawfulness of the processing (Article 17(1)(d) of the GDPR) and the objection to the processing (Article 17(1)(c) of the GDPR). The Advocate General first examines the first ground, because a right to object presupposes lawful processing, as the Court of Justice held in its judgment Mousse (ECJ, January 9, 2025, C-394/23).
The processing of baptismal data falls under the exception set forth in Article 9(2)(d) of the GDPR for religious organizations that process data of members and former members, subject to appropriate safeguards. The question of a legal basis under Article 6 of the GDPR remains. The diocese invokes its legitimate interest: the proper administration of the sacraments, and in particular, preventing anyone from being baptized twice. According to the Advocate General, that interest is legitimate, specific, and genuine, and is protected by the freedom of religion under Article 10 of the Charter of Fundamental Rights.
As long as a person belongs to the religious community, the Advocate General considers the maintenance of the baptismal register to be necessary and in balance with the rights of the baptized person. A baptized person may reasonably expect that their baptism will remain registered; the processing is limited to storage and occasional consultation; and the baptized person has a personal interest in this for later sacraments such as confirmation or a church wedding. The processing prior to the complainant’s objection therefore appears to be lawful. On this point, the opinion differs from the decision of the GBA, which did not consider the processing to be necessary.
Whether the complainant can successfully object to further processing
The right to object under Article 21(1) of the GDPR allows the data subject to object, on the basis of his or her specific situation, to processing based on a legitimate interest; the controller must then cease processing, unless it demonstrates compelling legitimate grounds that override the data subject’s interests. This is the crux of the conclusion. The word “compelling” raises the bar in three respects: the interest must be essential to the controller’s core mission, the processing must be genuinely necessary, and the balancing test must take into account the specific circumstances of the person objecting. The Court of Justice accepted such grounds only as an exception in the judgment SCHUFA Holding (ECJ, December 7, 2023, C-26/22 and C-64/22).
The Advocate General acknowledges that, in principle, the diocese’s interest is compelling: the sacraments touch on the very heart of the Church’s spiritual mission. However, she takes issue with the claim of necessity. At the hearing, the diocese was unable to provide a concrete example of a real risk of double baptism. There is no centralized baptismal registry, so anyone who truly wishes to be baptized again can simply choose another parish. Anyone who later wishes to return can prove their baptism in accordance with the provisions of the Code of Canon Law or the correspondence regarding his resignation. That same code also provides for conditional baptism when it is uncertain whether someone has already been baptized. And Recital 64 of the GDPR prohibits retaining data solely for the purpose of responding to potential future requests.
In weighing the interests, the Advocate General considers three factors. A person who severs all ties with a church cannot be expected to accept that the church will retain their data for life. The complainant never gave consent as a child, and Recital 65 of the GDPR states that the right to erasure is particularly relevant for those who were subject to data processing as children. And above all: the refusal may affect the data subject’s psychological integrity. The freedom of religion under Article 10 of the Charter includes the right to change one’s religion, and for those who have experienced trauma within a religious community, the assurance that all ties have been permanently severed can be of vital importance. In this regard, the Advocate General also refers to the right to physical and mental integrity under Article 3 of the Charter.
The decision: In principle, the complainant has the right to erasure, unless the diocese demonstrates compelling legitimate grounds. The national court must assess this on a case-by-case basis, paying particular attention to the complainant’s reasons and the consequences of a refusal for his integrity.
Whether the exception for archiving and historical research overrides the right to erasure
Article 17(3)(d) of the GDPR excludes the right to erasure when processing is necessary for archiving in the public interest or for historical research in accordance with Article 89(1), GDPR, to the extent that erasure would render those purposes impossible or seriously compromise them. The diocese invoked both grounds.
According to Recital 158 of the GDPR, archiving in the public interest presupposes that a body is legally required to acquire, preserve, and make accessible data of lasting value. The Advocate General derives two conditions from this. The diocese must have an archiving duty under national law, and the archives must be accessible to the government or the public at some point. A private registry accessible only to its own clergy is not an archive in the public interest. It is for the Belgian court to determine whether the diocese has such a statutory duty.
In the context of historical research, the term is understood more broadly to include genealogical research as well. However, the diocese confirmed at the hearing that it does not conduct any research itself and, at most, merely preserves data that external researchers may use at some point. That is archiving, not research. In both cases, the judge must also determine whether the value of the registers truly depends on their complete integrity, and whether researchers must know the identity of every person baptized or can work with anonymized data. The Advocate General points out that baptismal registers are updated anyway—for example, with subsequent sacraments or with the fact of leaving the Church—so the argument of the inviolable historical artifact does not convince her.
Whether a marginal note is a deletion
The Advocate General answers the fifth question most definitively. In plain language, “data erasure” means deletion or removal. A note stating that someone has left the church, with a legible strike-through, is at most a rectification within the meaning of Article 16 of the GDPR. Worse still: the diocese added new personal data to the registry, thereby expanding the processing rather than terminating it.
The argument of historical falsification does not hold up. A service provider who removes a customer from its database does not, either, falsify the former business relationship. The right to erasure also does not entitle the data subject to have all traces of the baptism removed: only the data that identifies him, such as name and date of birth, must be removed. The complainant agreed to this at the hearing and did not object to anonymization or pseudonymization either. The record stating that a baptism took place at a specific location and date may remain. The unique, double-sided paper book does not pose an obstacle: opaque stickers covering the identifying information are sufficient, and it is up to the data controller to find a workable method.
Legal analysis and interpretation
Why the objection—and not the legality—decides the case
In December 2023, the GBA had ruled against the diocese on the grounds that the processing was not necessary under Article 6(1)(f) of the GDPR. The Advocate General takes a different approach. She considers the maintenance of a baptismal register to identify church members to be lawful and shifts the focus of the debate to the moment when the baptized person objects. This is a significant legal distinction. Under Article 6, the data controller weighs the interests in advance and in general, without knowing the specific individual. Under Article 21, the weighing takes place afterward and is tailored to the individual raising the objection, with a reversed starting point: ceasing processing is the rule, and continuing processing is the exception.
In practice, this means that a church or association does not lose its case because its registry is allegedly unlawful, but because it must justify, for each individual objection, why it still needs that person’s data. The Advocate General bases this argument on the judgment Google Spain (ECJ, May 13, 2014, C-131/12), which already drew a distinction between unlawful processing and an objection to lawful processing, and on the Guidelines 1/2024 from the European Data Protection Board on legitimate interests. If you want to better understand the right to object, you’ll find the basics on our page about the data protection law.
The dissenting opinion: Former members are literally listed in the GDPR
The diocese’s strongest argument is not found in the Advocate General’s opinion, but in the regulation itself. Article 9(2)(d) of the GDPR expressly permits religious organizations to process data regarding both their members and their former members. The EU legislature has thus provided for a church to maintain records of those who have left the church. Furthermore, the European Commission and various governments argued at the hearing that the impact on the data subject is minimal, since the church never discloses the data, and that the balance of interests must therefore tip in favor of the church.
The Advocate General acknowledges the first argument but does not act on it: Article 9 lifts the prohibition on sensitive data but does not replace the test set forth in Article 21. This is defensible, although she could have addressed it in greater depth. Article 9(2)(d) does show, however, that the legislature did not consider the retention of data on former members to be problematic in and of itself, which weakens the argument based on the data subject’s reasonable expectations. She sharply rejects the second argument. In her view, the harm caused by a refusal does not lie in how others view the data subject, but in his self-determination: the knowledge that a community with which he has broken ties will retain his data forever because it considers the bond to be unbreakable. This interpretation of Article 10 of the Charter is new and far-reaching. The Court of Justice may rule differently on this point and give greater weight to the legislature’s choice in Article 9. Until the judgment is issued, this remains the most uncertain aspect of the case.
A narrow loophole for archives, and a limited right to erasure
Two aspects of the ruling are less spectacular but equally important in practical terms. The archival exception under Article 89 of the GDPR is interpreted strictly: without a statutory archival duty and without any form of access for the government or the public, there is no archiving in the public interest. This is consistent with the ruling Hurbain vs. Belgium of the European Court of Human Rights (ECHR, July 4, 2023, No. 57292/16), which, in principle, requires archives to be kept in their entirety but allows for exceptions. Belgian law is decisive in this matter: it is up to the Brussels Court of Appeal to determine whether the diocese has a legal obligation to retain the records.
The right to erasure itself is, in fact, more limited than the complainant initially requested. It is not the baptism that is removed from the register, but rather the identifying information. This is consistent with the position previously taken by the Marktenhof, as we analyzed in our blog post on the question of whether Whether an organization may retain pseudonymized data following a request for erasure: Minimal data processing is the standard, in both directions. And the separation of church and state in Articles 19 and 21 of the Constitution remains intact. The Advocate General emphasizes that no GDPR measure alters the Church’s doctrine regarding the irreversibility of baptism. The law governs the registry, not the sacrament.
Specifically, what does this mean?
For those who wish to have their names removed from the baptismal register. Don’t wait for the court ruling to draft your request; instead, draft it carefully. Explicitly cite the right to object under Article 21 of the GDPR and the right to erasure under Article 17 of the GDPR, and explain the basis for your objection based on your personal circumstances. An objection without reasons can be used against you by the judge; an objection that cites serious moral or personal grounds requires careful consideration. Specifically request that your name and date of birth be redacted, and accept that the mention of your baptism may remain. If you receive a marginal note in response, the Advocate General states that this does not constitute erasure, and you may file a complaint with the GBA. If you are unsure whether your situation is sufficiently compelling, developing that justification will be the first step we take together with you.
For dioceses, parishes, and other faith-based organizations. The register itself is not in question; rather, it is the response to an objection that is. Prepare a procedure that assesses and justifies each objection individually, and document why this person’s data is still necessary. A general reference to legal doctrine or to the completeness of the archive will not suffice. Determine whether there is a legal archiving obligation under Belgian law and whether your records are accessible to government agencies or researchers; only then does Article 89 of the GDPR offer a solution. Also consider the practical aspects: a method for making identifying information unreadable without damaging the book or the data of others. Anyone wishing to prepare for this would be well advised to seek assistance from a lawyer specializing in GDPR which establishes the new standard for compelling legitimate grounds.
For organizations and businesses outside the church setting. The reasoning regarding the right to object is not based on religion. Any organization that processes data on the basis of a legitimate interest must demonstrate compelling grounds following an objection, and the Advocate General makes it clear that this standard is stricter than the ordinary balancing test under Article 6. Anyone who retains data from former members or former customers “just in case” runs afoul of Recital 64 of the GDPR.
Frequently asked questions (FAQ)
Can I have my name removed from the baptismal register?
According to Advocate General Medina’s opinion of October 1, 2026, in principle, yes. You are objecting to the processing under Article 21 of the GDPR and requesting erasure under Article 17 of the GDPR. The church may refuse only if it demonstrates compelling legitimate grounds that outweigh your interests. The Court of Justice has yet to confirm this opinion in a judgment.
Will my baptism then disappear from the records entirely?
No. According to the Advocate General, the right to erasure does not entitle one to have all traces of the baptism removed. Only the data that identifies you, such as your name and date of birth, must be made unreadable. The record stating that a baptism took place on a certain day in a certain parish may remain. The GDPR has no bearing on the Church’s doctrine regarding baptism itself.
Is it enough for the church to simply note my resignation in the margins?
No. According to the Advocate General, a note stating that you have left the church—with your personal data legibly crossed out—constitutes, at most, a correction and not an erasure. She even notes that, by doing so, the church is adding new personal data to the registry. If you receive such a response to an explicit request for erasure, you can file a complaint with the Data Protection Authority.
Can a church keep my information for its archives or for historical research?
Only under strict conditions. Archiving in the public interest presupposes a legal archival obligation under Belgian law and access to the archives by the government or the public. Historical research presupposes that the church itself conducts the research. In both cases, the court must determine whether the deletion would seriously jeopardize the purpose and whether anonymized data would suffice.
Conclusion
Advocate General Medina advises the Court of Justice to grant, in principle, the right to be removed from the baptismal register to anyone who was baptized as a child and leaves the church as an adult. The church’s register is lawful as long as a person belongs to the congregation, but following a substantiated objection, the church must demonstrate compelling and justified grounds, and the risk of double baptism did not convince her. A marginal note does not constitute erasure; rendering the name and date of birth illegible does. The final decision rests with the Court of Justice and then with the Brussels Court of Appeal, which must specifically weigh the interests involved in the Belgian case.
ICT Rechtswijzer is the knowledge platform of the Intellectual Property, IT Law, AI Law, Data Protection, and Media Law department at Everest Advocaten, led by Joris Deene, Esq. Our attorneys assist data subjects in drafting substantiated objections and requests for erasure, and assist data controllers in assessing and responding to such requests.



