When individuals complain about how their personal data has been used, they are often up against organisations with far greater resources, technical knowledge and legal support. That imbalance is particularly obvious in cases involving major technology platforms, targeted advertising and complex cross-border data protection procedures.
A recent ruling of the EU General Court in Lisa Ballmann v European Data Protection Board is therefore worth watching closely. Although it is an EU case, and the UK is no longer part of the EU, it speaks to a wider and very practical question that remains highly relevant to privacy and data protection lawyers in England and Wales: how much transparency should a complainant be entitled to when a regulator is dealing with their data protection complaint?
What was the Ballmann case about?
The case arose from a complaint connected with Meta’s Facebook service and its data processing practices for online advertising. The underlying issue concerned so-called “forced consent” for personalised advertising, which, in broad terms, is whether users were being pushed into accepting the use of their personal data for advertising purposes in circumstances where consent may not have been freely given.
The European Data Protection Board (EDPB) had adopted a binding decision in December 2022 which required the Irish Data Protection Commission to rule against Meta in relation to Facebook. Lisa Ballmann, supported by the privacy organisation NOYB, then sought access to documents in the EDPB’s administrative file which had been used in preparing that binding decision.
The EDPB refused access. Its position was that Ms Ballmann was not likely to be adversely affected by the binding decision and therefore did not have a right to be heard.
What did the General Court decide?
On 16 July 2025, the General Court rejected the EDPB’s approach and annulled its decision refusing access. The Court held that the right of access to one’s file under Article 41(2)(b) of the Charter of Fundamental Rights of the European Union is not limited to situations where the person is adversely affected by the relevant measure.
That distinction matters. The Court made clear that a request for access to a file is not the same as asking for a right to be heard. In other words, a complainant may have a right to see the file even if they are not in a position to insist on making further submissions before the decision is taken.
For privacy campaigners, data subjects and practitioners that is an important procedural point. It supports the idea that complainants should not be kept at arm’s length from a process that concerns their own data protection complaint, particularly where the case has moved into the more opaque territory of regulatory decision-making.
Why does this matter for data protection complaints?
Data protection law gives individuals important rights, including the right to complain to a supervisory authority if they believe their personal data has been misused. However, anyone who has been involved in a regulatory complaint will know that the process can feel slow, technical and one-sided.
Large organisations will usually understand the regulatory process, have specialist advisers and know how to frame their arguments. Individuals often do not. If a complainant cannot see what material has been considered, or how a regulator has approached the issues, it becomes much harder to understand whether their complaint has been properly dealt with.
The Ballmann ruling is therefore significant because it reinforces a basic principle of fairness: where a person brings a data protection complaint, they should not necessarily be excluded from the file simply because the regulator says the decision does not adversely affect them.
Relevance in England and Wales
Following Brexit, decisions of the EU General Court are not binding on UK courts in the same way they would have been before the end of the transition period. The UK now has its own version of the GDPR, known as the UK GDPR, supplemented by the Data Protection Act 2018.
That said, EU data protection developments remain highly relevant. The UK data protection regime is closely related to the EU framework, and UK courts and practitioners continue to pay attention to EU decisions, particularly where they deal with common concepts such as transparency, fairness, regulatory procedure and the rights of data subjects.
For individuals in England and Wales, the practical point is this: if you bring a complaint about misuse of personal data, you should expect a process that is fair, transparent and capable of meaningful scrutiny. If a regulator or organisation refuses to disclose relevant information, it may be worth taking advice on whether that refusal can be challenged.
Implications for privacy claims and data protection disputes
From the perspective of a solicitor acting in privacy and data protection claims, the decision is useful for three reasons.
First, it underlines the importance of procedural rights. Data protection disputes are not just about whether information was collected, shared or used unlawfully. They are also about whether the individual was treated fairly when they tried to enforce their rights.
Secondly, it may encourage greater scrutiny of regulatory decision-making. Where a complaint has been rejected, delayed or dealt with in a way that appears incomplete, complainants may increasingly ask what material was before the decision-maker and whether they were given a proper opportunity to understand the process.
Thirdly, it is a reminder that transparency is not just an abstract data protection principle. It has real practical consequences. Without access to relevant information, individuals may struggle to assess whether their rights have been breached, whether a complaint has been properly investigated, or whether further legal action is appropriate.
What should individuals do if they are concerned about misuse of personal data?
If you believe your personal data has been misused, whether by a technology company, employer, public body or other organisation, it is sensible to keep a clear record of what has happened. This may include copies of correspondence, screenshots, privacy notices, account settings, subject access request responses and any complaint correspondence.
You may be able to make a complaint to the Information Commissioner’s Office, bring a civil claim for compensation or seek other remedies depending on the facts. In some cases, the issue may involve distress, reputational harm, financial loss or the unauthorised sharing of sensitive information.
Early legal advice can help identify the strongest route forward. That may include sending a data protection complaint, making a subject access request, challenging an inadequate response or pursuing a privacy claim where the impact is serious enough to justify legal proceedings.
How can we help?
Kevin Modiri is a Partner in our expert Dispute Resolution team, specialising in civil disputes, insolvency, inheritance disputes, data breach claims and defamation claims.
If you want to discuss personal data misuse or something similar, please do not hesitate to contact Kevin or another member of the team in Derby, Leicester, or Nottingham on 0800 024 1976 or via our online enquiry form.
Contact us