EDPBI:FR:OSS:D:2022:351: GDPR decision metadata and cohort analysis
A structured technical profile of the EDPB final one-stop-shop register entry, with legal-reference, outcome, authority and topic comparisons across 1,326 unique registered decisions.
What this register entry establishes
The EDPB register records EDPBI:FR:OSS:D:2022:351 with a decision date of 18 March 2022, lead supervisory authority FR, main legal reference “Article 5 (Principles relating to processing of personal data)” and outcome “Reprimand”. The EDPB classifies it under Basic principles, Data subject rights.
Decision-register record
| EDPBI identifier | EDPBI:FR:OSS:D:2022:351 |
|---|---|
| Decision date | 18 March 2022 |
| Lead supervisory authority | FR |
| Concerned supervisory authorities | None listed |
| Main legal reference | Article 5 (Principles relating to processing of personal data) |
| Relevant topics | Basic principles; Data subject rights |
| Outcome | Reprimand |
| Official decision | Open the EDPB-hosted PDF |
The identifier is the safest citation key for cross-checking this record. Country code, year and serial components can help organise research, but they are not substitutes for the decision text.
How to review the main legal reference
Article 5 contains the GDPR’s core processing principles, including lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, security and accountability.
Identify the specific principle at issue, the processing stage where it applies, and the evidence the authority used to test accountability.
A “main legal reference” is a register classification, not necessarily an exhaustive list of every GDPR provision discussed. When extracting precedent or compliance actions, read the full PDF for the factual test, procedural posture, other provisions, remedies and any limits on the authority’s reasoning.
Legal-reference and outcome cohort
Across the captured register, 146 unique decisions share this exact main legal-reference label. The comparison answers a narrow research question—how the EDPB register classifies similar records—without claiming that identical labels mean identical facts or holdings.
| Recorded outcome in this legal-reference cohort | Decisions | Share |
|---|---|---|
| Reprimand | 40 | 27.4% |
| Dismissal/Rejection of the case | 26 | 17.8% |
| Administrative fine | 24 | 16.4% |
| Compliance order | 21 | 14.4% |
| No violation | 15 | 10.3% |
| Amicable settlement | 10 | 6.8% |
| No sanction | 5 | 3.4% |
| Other | 4 | 2.7% |
| Definitive ban on data processing | 1 | 0.7% |
The most frequent recorded outcome in this exact-label cohort is “Reprimand” (27.4%). That distribution describes register classification only; it is not a forecast for a new case.
Topic classification and related decisions
Basic principles
The captured register contains 117 unique decisions tagged “Basic principles”. Topic tags are useful discovery facets, but the full decision controls the scope of the case.
Data subject rights
The captured register contains 1,030 unique decisions tagged “Data subject rights”. Topic tags are useful discovery facets, but the full decision controls the scope of the case.
Closest certified decision profiles
Technical decision-review checklist
- Verify the record. Match the EDPBI identifier, date and PDF on the official register before relying on a secondary description.
- Extract facts separately from holdings. Record the processing operation, roles, data categories, data subjects, geography and timeline before summarising the legal test.
- Map every cited provision. Treat this card’s main legal reference as a starting point; capture all GDPR articles and national-law provisions actually used in the decision.
- Identify the procedural route. Note the lead and concerned authorities, cooperation steps, objections, appeals and whether the published text is final for the point being researched.
- Separate infringement from remedy. Record findings, corrective powers, fine methodology, deadlines and compliance orders as distinct elements.
- Test comparability. Compare business model, scale, intent, duration, mitigation and authority—not merely the article number or outcome label.
- Check later developments. Verify appeals, replacement decisions, updated guidance and later case law before using the decision operationally.
Article 27 and non-EU organisations
This decision card is not, by itself, an Article 27 territorial-scope determination. A non-EU controller or processor should separately assess Article 3: establishment, offering goods or services to people in the Union, and monitoring behaviour in the Union. Where Article 3(2) applies and no exception covers the processing, Article 27 may require a representative in the Union.
The EDPB’s territorial-scope guidance explains that the representative is an additional contact point and does not replace the controller’s or processor’s own responsibility. The designation, mandate, location and accessibility should be documented against the actual processing and data-subject geography.
Research questions this page can and cannot answer
Does the outcome label describe the whole remedy?
No. A register label is a discovery field. The PDF may include multiple findings, corrective measures, deadlines or procedural qualifications.
Can another organisation treat this decision as a direct precedent?
Not without a comparability analysis. Supervisory-authority decisions are highly fact dependent, and later appeals, national procedure or subsequent EDPB and court materials can affect how they should be used.
Why compare exact legal-reference labels?
Exact-label cohorts make the method reproducible and reduce subjective grouping. Their limitation is equally clear: differently worded labels may concern overlapping provisions, while identical labels may cover different conduct.
Does this profile provide legal advice?
No. It is a source index and analytical research aid. Qualified counsel or a specialist should review the primary decision and current law for a specific compliance position.
Sources, provenance and limitations
| Official source | Role in this page | Snapshot / access |
|---|---|---|
| EDPB final one-stop-shop decision register | Identifier, date, authorities, legal reference, topics and outcome | 2026-08-14 |
| Official decision PDF — EDPBI:FR:OSS:D:2022:351 | Primary decision text for findings and operative orders | 2022-03-18 |
| General Data Protection Regulation | Binding GDPR article text | Current official legal source |
| EDPB Guidelines 3/2018 on territorial scope | Article 3 and Article 27 interpretation | Version 2.1 |
Build certificate: policy 2026-08-14.1; 1,203 non-navigation words; 8 source facts; EDPB snapshot 212f041b5aa0fd09… . All classifications and counts were computed offline. The live page performs no source API, PDF extraction, database or AI call.
Limitations: Register metadata can be corrected or expanded after capture. Cohort counts reflect this snapshot and do not measure underlying incidence, enforcement probability or legal merit. The decision PDF and current official law remain controlling sources.