CJEU Allows Court Use of Evidence Obtained in Breach of the GDPR (Case C-484/24)

In Case C-484/24 the Court of Justice of the EU confirms that a GDPR breach in obtaining evidence does not, by itself, exclude it from judicial proceedings, while requiring courts to apply data minimisation, anonymise where appropriate and protect third-party data. Key holdings and practical impact in Spanish litigation.

1. A ruling that reshapes evidence strategy across the EU

The Court of Justice of the European Union (CJEU) has answered one of the most recurrent questions in litigation practice: can a court rely on evidence containing personal data obtained in breach of the General Data Protection Regulation (GDPR)?

In Case C-484/24 ([full text on EUR-Lex](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62024CJ0484)) the answer is nuanced but clear: a GDPR breach in obtaining the evidence does not, in itself, require its exclusion from the proceedings. The Court does, however, impose specific duties on national courts so that the judicial use of that data remains lawful.

This matters in every dispute where WhatsApp messages, e-mails, recordings, geolocation data or CCTV footage are produced — employment, family, banking, tenancy and personal-injury cases alike.

2. Two distinct questions of lawfulness

The technical core of the judgment is a distinction that was previously blurred:

| Layer | What is assessed | Applicable rule |
|---|---|---|
| Obtaining the data | How the party acquired the personal data | Articles 5 and 6 GDPR, against whoever obtained it |
| Judicial processing | Whether the court may admit and assess it | Articles 5, 6(1)(e) and 6(3) GDPR, against the court |

Unlawfulness at the first layer does not automatically contaminate the second. The court's own processing has an independent legal basis: the performance of a task carried out in the public interest and in the exercise of official authority.

3. The five key holdings

a) GDPR is not an exclusionary rule A breach by the party producing the evidence does not automatically render it inadmissible. The GDPR contains no "fruit of the poisonous tree" doctrine.

b) Judicial processing is assessed autonomously The judge may assess the data provided the court's own processing complies with the GDPR: defined purpose, legal basis under Article 6(1)(e), and respect for the Article 5 principles.

c) Reinforced data-minimisation duty Before incorporating or disclosing the data, the court must verify that only adequate, relevant and strictly necessary data is used, adopting anonymisation or pseudonymisation where appropriate. In practice: no bulk dumps of an entire phone, mailbox or location history when three messages suffice.