Pursuing Religion Is a Fundamental Right, but So Is Data Protection

In an upcoming case the European Court of Justice will be asked to balance the freedom of religion with the right of data protection.

It reminds us that the right of data protection is not absolute, but must be weighed against other fundamental rights enshrined in the Charter of Fundamental Rights. The European citizens have the right „to manifest their religion or belief, in worship, teaching, practice and observance“ as expressed in Article 10 of the Nice Treaty, signed on December 2000. It forms the basis of the European Union’s constitution with regard to citizens’ rights. The GDPR is also based on the Charter. Article 8 states that data protection is a fundamental right and that data may only processed for specific purposes, with compliance being controlled by an independent authority.

Proportionate and strictly necessary

The President of the European Court of Justice (CJEU), Koen Lenaerts, met with European DPOs in Brussels in 2018 a few days after the GDPR took effect. In his lecture Lenaerts said that the work of the Court is to interpret and weigh the fundamental rights against each other. He added that state limitation of fundamental rights must be proportionate and strictly necessary.1

Lenaerts signalled a number of upcoming European Court cases in the area of data protection that have unfolded in the five years since the introduction of the GDPR. One of these cases is the Meta vs Bundeskartellamt case (C-252/21), which addresses the use of contracts and legitimate interest as legal grounds for processing.

The CJEU ruled that even though the services of Facebook are free of charge, the user „cannot reasonably expect that the operator of the social network will process that user’s personal data, without his or her consent, for the purposes of personalised advertising“. In such circumstances the interests and fundamental rights of a user override the interest of Facebook in personalised advertising (para 117). Following several discussions about the use of legitimate interest, the European Data Protection Board issued their Guidelines 1/2024 on processing of personal data based on Article 6(1)(f) GDPR. The guidelines had not been issued in its final version as of June 2025.

On page 5 the EDPB Guidelines 1/2024 state that for processing to be based on the legal basis of legitimate interest, three cumulative conditions must be fulfilled. First, there has to be a legitimate interest, second, the personal data must be related to that legitimate interest; and third: «the interests or fundamental freedoms and rights of the concerned data subjects do not take precedence over the legitimate interest(s) of the controller or of a third party.“

The Netherlands DPA had previously questioned whether the right to do business constitutes a fundamental right in relation to data protection law. In a CJEU judgment of 4 October 2024 (C-621/22), it is established that a commercial interest of the controller could constitute a legitimate interest within the meaning of Article 6(1)(f) GDPR. Like in other balancing exercises, its lawfulness must be assessed on a case-by-case basis (para 49).

The right to manifest religion or belief

How does a Christian European church „manifest religion or belief in terms of worship, teaching, practice and observance“ for a child? Children are usually baptised at an early age. In practice, the religious rights of children are managed by an adult, mostly by their parents.

Recital 55 of the GDPR states: „Moreover, the processing of personal data by official authorities for the purpose of achieving the aims, laid down by constitutional law or by international public law, of officially recognised religious associations, is carried out on grounds of public interest.“

One such officially recognised religious association is the Church of Sweden. When a member of the church gets a child, the population register informs the church in order that the church may offer baptism to the child. If the parents don’t take up the offer within four months, the child’s personal data is deleted from the church’s register.

This practice seems to be in accordance with European law and strikes a reasonable balance between the newborn child’s right to data protection and the child’s right to be baptised according to the beliefs of its parents. Recital 55 entails an obligation for the government to provide the necessary birth information to the church. If that were not the case, neither church nor society would respect the fundamental right of the child to be included in the practice and observance of its parents‘ religion.

The Finnish and Danish governments follow a similar practice as that of Sweden. The Norwegian government, however, refuses to give the Church of Norway relational data from the population register. Most parents register their child for baptism anyway, but the Norwegian state does not seem to take its obligation under international law seriously in this respect. The religious rights of the child seem to weigh less than the child’s right to data protection. In addition to the Nordic countries, that are mainly evangelical, the Catholic church is the officially recognised religious community in some countries, for example Malta and Ireland.

One of the challenges of applying the GDPR’s right to erasure (the right to be forgotten) to churches is that baptism is mostly performed once in Christian cultures. The christening which took place in one church is usually recognised by the other. A person who converts to another church is usually not baptised again. This means that churches maintain records of people who have been babtised.

A decision by the Irish Data Protection Commissioner on 27 February 2023 reflects the practice in many European churches. The local parish is not sole processor of personal data, but has a joint controllership with the next administrative level, the archbishop. Since the archdiocese maintains the baptismal register, it is the sole controller of the baptism records when it comes to storage, retention and alteration. As legal ground for the processing the archdiocese claims legitimate interest. In this Irish case, a data subject did not want to be associated with the Catholic church any more. The archdiocese refused to erase the baptism record on the grounds that it was a historical fact and that, since a person can only be baptised once, the personal data is still needed for its purpose. In its decision, the Irish Data Protection Commissioner ruled that the baptism record could not be erased, but could be amended. „In circumstances where a data subject no longer wishes to be a member of the Catholic Church a supplementary statement could be added by the Archbishop to the Baptism Register entry stating No longer wishes to be identified as a Roman Catholic“.

Will the GDPR prevail over the church’s legitimate interest?

The Belgian DPA has come to a different conclusion than the Irish DPA. The Catholic diocese of Ghent refused a request for erasure. The data subject complained to the Belgian DPA, which decided that „the lifelong processing of data, moreover of a sensitive nature, of a person who has asked to leave the Roman Catholic Church cannot therefore be justified if such processing is neither proportional nor strictly necessary to the admittedly legitimate interests of the Roman Catholic Church.“

The case has been referred to the CJEU for a preliminary ruling (C-12/25, Bisdom Gent). Among the questions posed are:

  • Does it make any difference that the entry in the register affects the freedom of religion of the controller and the community it represents?
  • Does it make a difference that the register is not digital, but a unique material carrier in the form of a book in which details of other data subjects are also given on the back of the pages?
  • Does it make a difference that the book itself is a historical artefact and that the baptismal register is a unique record of historical facts that are not recorded anywhere else, meaning that the data processing also occurs for archiving, research or statistical purposes?

Its outcome may set a precedent for cases throughout the EEA, where members of the church were baptised as a child and now wish to exercise their right of erasure according to the GDPR.

About the author

Nils Indahl


Data Protection Officer at the Church of Norway

Nils G. Indahl is the data protection officer (DPO) of the Church of Norway, Norway’s leading religious association. The church has 3, 7 million registered members.
He is chair of the Norwegian Association of Data Protection Officers.
When the General Data Protection Regulation (GDPR) was introduced in 2018, Indahl was the DPO of the City of Drammen.

1 available at YouTube www.youtube.com/watch?v=fZaKPaGbXNg (last accesed on 14.10.2025).

Die neusten Datenschutztrends

Bleiben Sie stets auf dem Laufenden und verpassen Sie keine Neuigkeiten mehr! Melden Sie sich für unseren Newsletter an und erhalten Sie regelmäßig Einladungen zu unseren Events und alle aktuellen Positionspapiere und Handreichungen.

Anmeldung zum Newsletter

Um sich für den beschriebenen Newsletter anzumelden, tragen Sie bitte hier Ihre E-Mail-Adresse ein. Sie können sich jederzeit über den Abmeldelink in unseren E-Mails abmelden.