Skip to main content

The provider of an online marketplace may be the data controller for the processing of personal data included in an advertisement published on the marketplace.

This was established by the EU Court of Justice in its judgment of 2 December 2025, C-492/23, concerning a promotional message for sexual services in which photographs and the telephone number of a woman were used without her consent.

The Court ruled that the provider of the online marketplace can be considered a joint controller together with the anonymous advertiser and that, as such, it is subject to the obligations under the GDPR.

Therefore, with regard to liability arising from the processing of personal data, the liability exemption regime for intermediary service providers set out in Directive 2000/31/EC on electronic commerce and now contained in the Digital Services Act (Regulation EU 2022/2065) does not apply.

Although there is no obligation for the marketplace provider to monitor content, for example, before publishing advertisements, the provider must, in accordance with accountability and data protection by design and by default obligations, take the necessary measures to identify those containing sensitive data, verify that the data contained in the advertisement refer to the advertiser and, if this is not the case, prevent publication in the absence of the explicit consent of the data subject.