Skip to content
EU Sanctions Compliance Challenges Data Privacy Under GDPR

EU Sanctions Compliance Challenges Data Privacy Under GDPR

First seen 9 Oct 2026, 23:34 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 10, 2026 at 21:32 UTC
  • •EU sanctions against Russia require extensive data collection for compliance.
  • •GDPR restricts public access to personal data without legitimate interest.
  • •Companies face a structural tension between sanctions compliance and data privacy.

The EU's expanding sanctions against Russia impose stringent Know-Your-Customer (KYC) requirements, which necessitate extensive data collection and processing. However, compliance with these sanctions must also adhere to the General Data Protection Regulation (GDPR). The Court of Justice of the European Union (CJEU) ruled in Case C‑798/24 (Jautiva) that GDPR prohibits national laws mandating the public availability of personal data for sanctions implementation without legitimate interest. This creates a conflict where increased data collection for sanctions compliance heightens exposure to data protection law violations. Companies must navigate this tension to ensure compliance with both sanctions and data privacy laws while managing the risks associated with personal data processing.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-09
CJEU ruling on GDPR and sanctions
The Court of Justice of the European Union ruled that GDPR prevents mandatory public disclosure of personal data for sanctions without legitimate interest.
Freshfields

More articles in this cluster (2)

Common questions

How do EU sanctions affect data privacy?
EU sanctions require data collection for compliance, which must also adhere to GDPR regulations.
What did the CJEU ruling entail?
The CJEU ruled that GDPR prohibits mandatory public disclosure of personal data for sanctions without demonstrating a legitimate interest.
What should companies do to comply?
Companies must implement strategies to balance compliance with both sanctions and GDPR, ensuring they manage personal data risks effectively.