Skip to main content
Promotional banner ad for the Penetration Testing Report Kit
Category: Enforcement and Compliance

Bundeskartellamt Judgment

Also known as: Meta v Bundeskartellamt, Meta Platforms Inc and Others v Bundeskartellamt, Case C-252/21
Simply put

The Bundeskartellamt Judgment refers to a decision issued by the Court of Justice of the European Union (CJEU) on 4 July 2023 in a case between Meta Platforms and the German competition authority (the Bundeskartellamt). The case arose after the German authority prohibited Meta from combining a user's data from several different sources without that user's consent. The judgment addressed how data protection rules relate to competition enforcement, and it examined the extent to which companies can rely on user consent when processing personal data.

Formal definition

The Bundeskartellamt Judgment (CJEU, Grand Chamber, Case C-252/21, Meta Platforms Inc and Others v Bundeskartellamt, judgment of 4 July 2023) arose from a preliminary reference concerning the German Bundeskartellamt's decision prohibiting Meta from combining user data across multiple sources without valid consent. According to the evidence available, the Court addressed two principal areas: (i) whether a national competition authority may, in exercising its competition-law powers, assess whether investigated conduct complies with the GDPR, which the judgment indicated is compatible with the GDPR's enforcement system provided certain conditions are met; and (ii) the interpretation of GDPR lawful bases, including the scrutiny of large platforms' reliance on consent as a legal ground for processing. The judgment is significant to consent practice because it bears on the standards for valid consent under the GDPR, particularly where a dominant undertaking is involved. This entry summarises the judgment at a general level based on the cited sources; it does not reproduce the Court's full operative rulings, and practitioners should consult the judgment text and subsequent regulatory and academic commentary for the precise holdings and their application to specific facts.

Why it matters

The Bundeskartellamt Judgment matters to consent practitioners because it bears on the standards for valid consent under the GDPR, particularly where a large or dominant platform relies on consent as its lawful basis for processing personal data. According to the cited sources, the case grew out of the German Bundeskartellamt's decision prohibiting Meta from combining a user's data from several different sources without that user's consent, and the CJEU's judgment of 4 July 2023 examined how data protection rules relate to competition enforcement. For teams designing consent flows, the judgment is relevant to the broader question of when consent can be considered freely given, especially in situations involving an imbalance of power between the user and the controller.

The judgment is also significant institutionally. According to the cited academic commentary, the Court clarified that it is compatible with the GDPR's enforcement system for a national competition authority to assess whether the conduct it investigates complies with the GDPR, subject to certain conditions. This intersection of competition law and data protection means that organizations may face scrutiny of their data-combination and consent practices from more than one type of regulator, not solely from data protection authorities.

Because this entry summarises the judgment at a general level based on the cited sources, it does not reproduce the Court's full operative rulings. Practitioners should treat the judgment as an important reference point on consent standards and cross-regime enforcement in the EU context, while consulting the judgment text and subsequent regulatory and academic commentary for the precise holdings and their application to specific facts. The judgment concerns EU law and should not be read as stating obligations under the UK regime or under US state privacy laws, which differ.

Who it's relevant to

Privacy officers and data protection professionals
Those responsible for lawful-basis decisions should be aware that the judgment scrutinises reliance on consent as a legal ground for processing, particularly for large platforms and where there may be an imbalance of power between user and controller. It is a relevant reference point when assessing whether consent in a given design can be considered freely given, though its precise application depends on the facts and on the full text of the ruling.
Legal counsel and compliance teams
Counsel advising on data-combination practices and consent frameworks in the EU may need to account for the judgment's treatment of GDPR lawful bases and its finding, as summarised in the cited commentary, that competition authorities may assess GDPR compliance in the course of competition enforcement. This suggests that data practices can attract scrutiny from more than one type of regulator. Counsel should consult the judgment text and subsequent guidance for the precise holdings.
Marketing and advertising compliance teams
Teams that combine user data across multiple sources or products for profiling and advertising should note that this was the type of conduct at issue in the underlying Bundeskartellamt decision. The judgment is relevant to how consent is relied upon for such cross-source data combination in the EU, though it does not itself prescribe a specific technical implementation.
Operators of large or dominant platforms
The judgment is especially relevant to undertakings with significant market power, because the cited commentary highlights its focus on Big Tech's reliance on consent as a lawful ground for processing. Such operators may face heightened scrutiny of whether consent obtained in the context of a dominant position meets GDPR standards.

Inside Bundeskartellamt Judgment

Bundeskartellamt
The German Federal Cartel Office, the national competition authority in Germany. In the matter commonly associated with this term, it acted on the interplay between competition law and data protection, addressing how a dominant undertaking's handling of user data may relate to abuse of a dominant market position.
Intersection of competition and data protection law
A central theme is the proposition that compliance with the GDPR can be relevant to a competition-law assessment, meaning a data protection authority's standards may inform whether data-processing conditions imposed on users are lawful. This links two distinct legal regimes that are otherwise governed by different authorities.
Consent and market power
The reasoning touches on whether consent obtained by a dominant undertaking can be considered freely given, given that users may have limited practical alternatives. This connects to the GDPR standard that valid consent must be freely given, specific, informed, and unambiguous.
Scope of application
The matter arises in the German and, on referral, EU legal context. Its reasoning concerns the GDPR's treatment of personal data processing; it does not itself set out rules on the placing of or access to information on a device, which in the EU falls under the ePrivacy Directive and its national implementations.

Common questions

Answers to the questions practitioners most commonly ask about Bundeskartellamt Judgment.

Did the Bundeskartellamt case create new cookie consent rules that I need to follow?
No. This proceeding originated as a competition (antitrust) matter brought by Germany's Federal Cartel Office, not as a cookie consent enforcement action under the ePrivacy Directive or its German implementation. While the case touched on data protection concepts and the interplay between competition law and the GDPR, it is a mischaracterization to treat it as establishing standalone cookie consent obligations. Cookie consent requirements continue to derive from the ePrivacy regime governing access to information on a user's device and, for any resulting personal data processing, from the GDPR. You should not read this judgment as a new rulebook for cookie banners.
Does this judgment mean a dominant company can never rely on consent as a lawful basis?
That overstates the position. The judgment addressed how a company's market position can affect whether consent is genuinely freely given, which is one of the GDPR's validity conditions. It does not amount to a blanket rule that dominant companies can never obtain valid consent. Rather, it signals that market power is a relevant factor in assessing whether users have a real choice. Whether consent is freely given in any given case remains fact-specific, and interpretations may continue to evolve through further guidance and litigation. It is not something this entry can resolve in the abstract for every scenario.
How should we assess whether consent is freely given when our organization has a strong market position?
Under the GDPR, valid consent must be freely given, specific, informed, and unambiguous, and freely given generally requires that users have a genuine choice without detriment for refusing. Where market power may limit that choice, organizations should document their reasoning, consider whether users can decline non-essential processing without losing access to a core service, and evaluate alternatives to consent, such as other lawful bases where appropriate. This is a legal judgment that should involve qualified counsel; a definitive answer depends on facts not covered by any single definition.
Does this affect how we should configure our consent management platform (CMP)?
A CMP supports compliance by presenting choices, capturing preferences, and logging consent records, but it does not itself resolve whether consent is freely given. To the extent this judgment reinforces the importance of genuine choice, you may wish to review whether your banner offers a real ability to refuse non-essential cookies and similar technologies (including pixels, local storage, and SDKs) as easily as accepting them. However, configuration choices should follow your own legal assessment rather than being driven by any interpretation of a single competition-law judgment.
Is this relevant outside Germany or the EU?
The judgment arises from German proceedings and engages EU data protection principles, so its most direct relevance is within the EU, and interpretations there may still develop. Its reasoning about freely given consent could inform practice in other EU member states, though enforcement positions vary. It should not be treated as authority in the UK or in US state privacy regimes such as the CCPA and CPRA, which operate under different legal frameworks and, in the US context, often rely on opt-out rather than opt-in. Always confirm the geographic scope before applying any conclusion.
What records should we keep to demonstrate that consent was validly obtained?
Consistent with GDPR accountability, organizations generally maintain records showing what users were told, what they agreed to, and when, along with the version of the notice or banner presented. Where questions about whether consent is freely given may arise, it can help to document the choices offered and any assessment of user choice. Record-keeping supports your position but does not by itself establish that consent was valid; that determination remains a matter of legal judgment on the specific facts, and this entry does not cover the full scope of applicable documentation obligations.

Common misconceptions

The judgment establishes cookie consent rules that apply everywhere.
Its reasoning is situated in the EU and German legal context and concerns the GDPR's approach to personal data processing and consent. Cookie consent obligations vary between the EU, the UK, and individual US states, and the placing of cookies specifically is governed in the EU by the ePrivacy Directive rather than by this judgment. Claims should not be presented as universal.
It means a competition authority now enforces the GDPR.
The GDPR is enforced by data protection authorities, not competition authorities. The point drawn from this matter is narrower: data protection standards may be relevant to a competition-law analysis of a dominant undertaking's conduct. The two regimes remain distinct, with different competent authorities and different legal tests.
It settles definitively when consent from a large platform is invalid.
The reasoning bears on whether consent can be freely given where a party holds significant market power, but the outcome is fact-dependent and interpretations continue to evolve. It does not provide a blanket rule that consent to any dominant provider is automatically invalid, and unresolved questions remain about how it applies to specific arrangements.

Best practices

Treat competition-law considerations and data protection compliance as separate but potentially connected assessments; do not assume that satisfying one automatically satisfies the other.
When relying on consent as a legal basis under the GDPR, evaluate whether it is genuinely freely given, specific, informed, and unambiguous, paying particular attention to situations where a user may lack a realistic alternative.
Keep the ePrivacy layer and the GDPR layer distinct: address the placing of and access to information on a device under the applicable ePrivacy rules, and address any subsequent personal data processing under the GDPR.
Confirm the geographic and legal scope before applying any conclusion drawn from this matter, since obligations differ across the EU, the UK, and individual US state regimes.
Document the reasoning and legal basis for data-processing and consent arrangements, and revisit them as regulatory interpretation and guidance evolve.
Seek qualified legal advice for fact-specific questions, as the application of these principles to a particular business model or consent flow depends on details not resolved by the judgment alone.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.