That’s one of the last decisions edit by the Court of the justice of European Union.
“The operator of an online marketplace must, before publication of those advertisements and by
means of appropriate technical and organisational measures, identify advertisements that contain sensitive data, such as the data at issue in the present case, and verify whether the user preparing to place such an advertisement is the person whose sensitive data appear in it.
If that is not the case, the the operator must verify whether the person whose data are being published has given his or her explicit consent to publication.
In the absence of that consent, the operator of an online market place
must refuse publication of the advertisement in question, unless it is covered by one of the other exceptions provided for by the GDPR.
Furthermore, the operator of an online marketplace must endeavour to prevent
advertisements containing sensitive data which are published on its website from being copied and unlawfully published on other websites.
To that end, it must implement appropriate technical and organisational security measures.
https://curia.europa.eu/jcms/upload/docs/application/pdf/2025-12/cp250150en.pdf

