ECJ ruling: GDPR breaches do not automatically render evidence inadmissible
Can evidence obtained in breach of data protection rules nevertheless be used in court? In its judgment of 18 June 2026 in Case NTH Haustechnik GmbH v EM (C-484/24), the European Court of Justice (ECJ) has provided important clarification on the relationship between the GDPR and national rules governing evidence in judicial proceedings.
The case arose from an employment-related dispute involving a German company and a former employee, who had also been married to the company’s managing director. Following their separation, the company established that she had sold goods allegedly belonging to the business through her private eBay account, with sales amounting to approximately EUR 13,217. According to the referring court, an employee of the company who was also the son of the former employee and the managing director accessed the private eBay account using her username and password. The credentials had reportedly been identified through information contained in a computer’s browsing history and a family file stored on a server.
The ECJ held that neither the GDPR nor the EU Charter of Fundamental Rights (EUCFR) establishes an automatic prohibition on a national court using evidence containing personal data merely because those data were obtained unlawfully. The processing performed by a court when determining the admissibility and relevance of evidence serves the proper administration of justice and the right to a fair trial. The ECJ expressly recalled that the right to protection of personal data is not absolute and must be considered alongside other fundamental rights, including the right to an effective remedy and a fair trial under Art. 47 EUCFR.
This does not, however, retrospectively legitimise the original collection of the data. The judgment distinguishes the lawfulness of obtaining and processing personal data by a party from the subsequent question whether a court may process and consider those data as evidence. The applicable GDPR requirements therefore remain relevant to the party that obtained the information, irrespective of whether a national court ultimately admits the evidence. The decision should consequently not be understood as creating a general exemption from data protection requirements for investigations conducted in anticipation of litigation.
The judgment also addresses data retention in connection with litigation. Under Article 17(3)(e) GDPR, the right to erasure does not apply where processing is necessary for the establishment, exercise or defence of legal claims. This exception does not in itself validate an unlawful initial collection of personal data, but it may permit data that are otherwise subject to deletion to be retained where they are genuinely necessary for legal proceedings. At the same time, the principle of data minimisation under Art. 5(1)(c) GDPR continues to apply: once evidence is admitted, courts must consider whether the personal data contained in it are limited to what is necessary and, where appropriate, whether measures such as partial anonymisation are required.
The decision is particularly relevant to internal investigations and employment disputes, where evidence may originate from emails, access logs, electronic devices or other sources containing personal data. Its principal significance lies in confirming that the question of whether personal data were collected lawfully and the question of whether evidence may subsequently be used in judicial proceedings are legally distinct. The precise consequences for admissibility remain subject to the applicable national procedural rules and the circumstances of the individual case.