BGH - Az. VI ZR 396/24
| BGH - Az. VI ZR 396/24 | |
|---|---|
| Court: | BGH (Germany) |
| Jurisdiction: | Germany |
| Relevant Law: | Article 28 GDPR Article 32 GDPR Article 82 GDPR |
| Decided: | 11.11.2025 |
| Published: | |
| Parties: | |
| National Case Number/Name: | Az. VI ZR 396/24 |
| European Case Law Identifier: | |
| Appeal from: | OLG Dresden (Germany) |
| Appeal to: | |
| Original Language(s): | German |
| Original Source: | Rewis (in German) |
| Initial Contributor: | lde |
The Federal Court of Justice held that a streaming service failed to ensure the deletion of data by its processor after the termination of the processing agreement. It was found liable for immaterial damages caused by a data breach concerning the abandoned data, even when the information was subject to a previous, unrelated data breach.
English Summary
Facts
The controller is a music streaming service, which used an external processor until December 2019. At the time of termination of the contract, the processor informed the controller that all the personal data it was processing would be deleted. The controller never followed up on this communication to conduct the appropriate checks.
It was discovered that the processor actually did not delete the data until 2023, and that from 2022 the users data were sold on the darknet. The controller informed the data subjects as soon as it knew about the incident.
One of the data subjects affected sought compensation for immaterial damages. The Regional Court dismissed the claim, which was confirmed by the Court of Appeals.
The court did establish that the controller failed to comply with its obligations to carefully monitor its processor. Still, they also reasoned that the data subject did not suffer any immaterial damages as a result of it. It assessed that receiving spam emails cannot account as a damage, and that fears and anxiety are normal everyday feelings that cannot amount to damages, especially after 2 years from the data breach. The rationale was that the further away from the event, the lower the probability of an actual damage occurring. Moreover, the fear was also resulting from the fact that the data subject was also hacked before in an unrelated incident, so no causal link could be established.
The data subject filed an appeal to the Federal Court of Justice.
Holding
The court upheld the appeal, and sent the judgement back to the court of appeals for it to award appropriate damages to the data subject.
The court explained that a claim for damages under Article 82(1) needs, cumulatively,
1. A GDPR breach
2. The existence of an immaterial damage
3. A causal link between damage and breach.
The breach of the controller’s obligations under Article 28 and Article 32 GDPR had already been established previously.
Establishing the damage was more complicated. The court explained how the CJEU had already established that a claim for damages under Article 82 is admissible for infringements of Article 32 GDPR. The court of appeals’ finding that no immaterial damages were found did not take this into account. First of all, the data subject suffered a loss of control over their data, which was then misused (as it was sold on the darknet), which has to be construed as a immaterial damage. Legislation also pointed in this direction: Recital 146 GDPR affirms that “damage” must be interpreted broadly - a mere GDPR breach is not sufficient, it has to cause damage. Case law also affirmed that mere loss of control over one’s data as a result of a GDPR breach is sufficient. Other GDPR recitals also confirmed this, more specifically Recitals 75 and 85, reporting loss of control as a possible damage, even if no specific misuse follows from it.
In any case, the fact that there was a misuse of the data subject’s data leaves no doubt about the presence of a damage. The misuse, in particular, was the unauthorised transfer to third parties, in the form of selling the data subject’s data on the darknet. It followed that the fears and anxieties of the data subject were not hypothetical but well founded; Thus, immaterial damage can be assumed at least from the point where the data subject’s data was sold on the darknet.
In general, the court explained that the requirement for demonstrating fear of data misuse must not be excessive – the more plausible the misuse, the lower the requirements for fear of data misuse. The court of appeals erroneously assumed a threshold that cannot be applicable.
Finally, the presence of a causal link cannot be dismissed because of previous hacking to the detriment of the data subject.
The court agrees with the data subject that compensation for immaterial damages should be awarded, and refers the case back to the court of appeals.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the German original. Please refer to the German original for more details.
Principle
1. The controller must also guarantee the protection of the rights of data subjects in connection with the termination of a data processing agreement. The controller must ensure that—subject to any statutory retention obligations—no personal data remains with the processor that was provided to the processor by the controller for the purpose of fulfilling the contract. The controller must therefore take all necessary steps, as required by the circumstances of the individual case, to ensure that the personal data is actually returned to or deleted from the processor upon termination of the contract.
2. If personal data remains with the processor after termination of the contract, is intercepted there, and offered for sale on the darknet, this constitutes non-material damage within the meaning of Article 82(1) GDPR. Such damage is not precluded simply because the data was previously intercepted unlawfully.
Judgment
Upon the plaintiff's appeal on points of law, the judgment of the 4th Civil Senate of the Higher Regional Court of Dresden of November 5, 2024, is set aside with respect to costs and insofar as it was decided against the plaintiff on points 1 (non-pecuniary damages), 2 (declaratory judgment) regarding the alternative claim, and 4 (legal costs).
To the extent of the reversal, the case is remanded to the court of appeals for a new hearing and decision, including on the costs of the appeal on points of law.
By law
Facts
The plaintiff asserts claims for damages and declaratory judgment against the defendant – insofar as relevant to the appeal on points of law – based on an alleged violation of the General Data Protection Regulation (GDPR).
The defendant, based in France, operates the online music streaming service D. Until the contract ended on December 1, 2019, the defendant's external data processor was company O. On November 30, 2019, company O. informed the defendant by email that its website and the data contained therein ("your site and all the data on the site") would be deleted the following day. Company O. first confirmed that this had actually occurred in an email dated February 22, 2023. Prior to this, it had come to light that since November 2022, unknown hackers had been offering user data from the defendant's service for sale on the dark web. The data records originated from 2019. Contrary to the agreement with the defendant, company O. had not deleted them immediately after the contract ended, but rather had transferred them from the production environment to a test environment by company O.'s employees and subsequently either stolen by hackers or unlawfully disclosed them by company O.'s employees. The defendant informed the individuals affected by the incident after it became known.
The plaintiff is a user of the defendant's service. His data is stored in the defendant's customer profile. The data record accessed during the incident in question contained the plaintiff's first name, last name, gender, email address, language, and registration date.
The plaintiff seeks, insofar as relevant to the appeal proceedings, compensation for non-pecuniary damages because the defendant failed to implement the technical and organizational security measures required by the General Data Protection Regulation (GDPR). Since learning of the data breach, he has been concerned about the whereabouts and potential misuse of his data in the form of identity theft, phishing, unsolicited advertising calls, and advertising emails. Furthermore, the plaintiff seeks a declaratory judgment that the defendant is obligated to compensate him for all future pecuniary damages resulting from the unauthorized publication of his data on the internet in 2022. He also seeks reimbursement of his extrajudicial legal fees.
The Regional Court dismissed the action. The Higher Regional Court dismissed the plaintiff's appeal. The plaintiff is pursuing the aforementioned claims by way of the appeal on points of law, which was granted by the Higher Regional Court.
Reasons for the Decision
A.
In its reasoning, the Higher Regional Court stated, insofar as relevant to the appeal on points of law, that the defendant had indeed culpably breached its obligations under Articles 28 and 32 of the GDPR to carefully monitor its external data processor, Company O., in particular by failing to request express written confirmation from Company O. that the data records held by the latter had actually been deleted. The email from Company O., which merely announced a deletion, was insufficient both formally and substantively. Furthermore, the causal link between the breach of the monitoring obligations and the hacking incident could not be denied: Had the data been deleted by O. upon the defendant's required inquiry, it could not have been accessed there.
The plaintiff did not suffer any causal non-material damage as a result of the data breach, because he failed to credibly demonstrate any emotional harm caused by the data loss in question. The loss of control over the data and its publication on the darknet did not result in any non-material damage within the meaning of Article 82 GDPR. If a loss of control without consequences for the data subject were considered non-material damage, the amount of compensation would regularly have to be zero in light of the compensatory function of Article 82(1) GDPR. The plaintiff's fear that the data would be misused could not be considered justified. The hacked email address was not particularly sensitive data belonging to the plaintiff, but rather data from his social sphere. While the email address could be misused to send spam emails, material damage could only occur if the link sent with the email was used. Receiving such emails, without further negative consequences, does not in itself constitute non-material damage. Moreover, the annoyance of such messages affects individuals whose data has not been hacked in a comparable way. A connection between receiving spam emails and the data breach in question cannot be proven. According to the website "haveibeenpwned.com," the plaintiff's email address had already been hacked before the incident in question. The plaintiff's general written assertion that he experienced significant unease and anxiety about potential misuse does not meet the requirements for substantiation. It is not specific to the plaintiff but is repeated verbatim in numerous lawsuits. General worries, anxieties, and unease are everyday feelings that do not justify any well-founded fear. During his hearing, the plaintiff stated that he had noticed a significant increase in spam messages and phishing attacks after the incident. However, these messages were automatically moved to the spam folder by his account, so there was no significant risk. He further stated that he was concerned his data would continue to be used for spam. He also used the email address for other social media accounts and with Amazon. Moreover, he did not readily give out his email address. He blocked spam emails and did not read emails from unknown senders. This did not go beyond the standard practices required and routinely followed in online activities. The harassment described during the hearing had not reached a level that would have prompted the plaintiff to change his email address to prevent any potential misuse. Therefore, the fear of misuse could not be considered justified. The appeals court could not draw any conclusions about the plaintiff's discomfort beyond what all private individuals using the internet endure when confronted with unsolicited messages where it remains unclear where the sender obtained the data necessary for the spam.
The declaratory judgment action was inadmissible for lack of standing. In cases involving the infringement of an absolute right, as here, the mere possibility of harm is sufficient. A legitimate interest in a declaratory judgment can only be denied if, from the injured party's perspective, there is no reasonable grounds to at least expect harm to occur. This was the case here. Even two years after the incident, no harm had occurred. The probability of harm decreasing with increasing time since the hacking event, making it increasingly difficult to prove the causal link. This is all the more true given that it is likely the plaintiff has already been affected by hacking attacks on several occasions without any resulting material damage. There is also no concrete evidence to suggest that the plaintiff's assets are at risk. Therefore, it can be assumed that no further material damage is to be expected.
B.
The appeal is well-founded.
I.
Based on the findings of the Court of Appeal, its assessment that the plaintiff has not suffered any non-material damage within the meaning of Article 82(1) GDPR does not withstand review on appeal.
1. The General Data Protection Regulation (GDPR) is applicable territorially pursuant to Article 3(1) GDPR and, since the information stored at company O. on behalf of the defendant contained the plaintiff's personal data, is also applicable materially pursuant to Article 2(1) GDPR. Regarding the temporal applicability, the decisive factor is not the date of registration of a user account with the defendant, but rather the date of the hacking incident (see Federal Court of Justice judgment of November 18, 2024 - VI ZR 10/24, BGHZ 242, 180 para. 19). According to the findings of the Court of Appeal, this incident occurred with respect to the plaintiff at least after May 25, 2018, and thus after the date on which the General Data Protection Regulation (GDPR) came into force (Art. 99 para. 2 GDPR).
2. The international jurisdiction of German courts is based on Article 82(6) in conjunction with Article 79(2), second sentence, of the GDPR. The plaintiff, as the data subject, has his or her habitual residence in Germany.
3. According to the settled case law of the Court of Justice of the European Union (hereinafter: the Court), a claim for damages within the meaning of Article 82(1) GDPR requires an infringement of the General Data Protection Regulation, the existence of material or non-material damage, and a causal link between the damage and the infringement, these three requirements being cumulative (see, for example, CJEU, Judgment of 4 October 2024 – C-200/23, DB 2024, 2952, para. 140; further references in the Federal Court of Justice's judgment of 18 November 2024 – VI ZR 10/24, BGHZ 242, 180, para. 21). The burden of proof for these prerequisites generally rests with the person claiming compensation for (non-material) damage under Article 82(1) GDPR (see ECJ, loc. cit., para. 141, and the Senate's judgment, loc. cit., with further references). In the context of a claim for damages under Article 82(1) GDPR, the data subject is not required to prove fault on the part of the controller. Rather, Article 82 GDPR provides for liability for presumed fault, and the burden of exoneration rests with the controller pursuant to Article 82(3) GDPR (see ECJ, Judgment of 11 April 2024 – C-741/21, NJW 2024, 1561, paras. 44 et seq., and the Senate's judgment, loc. cit., with further references).
a) The Court of Appeal's assessment that the defendant is liable under tort law for the fact that the plaintiff's data was not deleted by company O. after the termination of the data processing agreement, and that it could therefore be accessed by company O. (through hacking or unauthorized disclosure by company O. employees) and subsequently offered for sale on the darknet, is legally unobjectionable. This is not merely a breach of the GDPR by the data processor O., for which the defendant is liable pursuant to Article 82(2), first sentence, GDPR – subject to the possibility of exculpation under Article 82(3) GDPR. Furthermore, the defendant itself is guilty of a breach of the General Data Protection Regulation (GDPR), which, as the Court of Appeal correctly observed, consists of the fact that, upon termination of the contract with its data processor O., it accepted O.'s announcement of data deletion without obtaining confirmation that comprehensive data deletion had actually taken place (see aa)). Because of this breach of duty, which caused the damage, the defendant cannot be exonerated under Article 82(3) GDPR (bb)).
aa) In any event, the defendant has violated its obligations under Article 5(2) in conjunction with Article 5(1)(c), (e), and (f) GDPR, as well as under Article 32(1) GDPR.
``` (1) If a controller within the meaning of Article 4 No. 7 GDPR transfers data processing to a processor, this does not relieve the controller of its data protection obligations (Gabel/Lutz in Taeger/Gabel, GDPR-BDSG-TTDSG, 4th ed., Art. 28 para. 2). The controller remains the "master of the processing" and is therefore responsible to the data subject for compliance with data protection regulations when the data is processed by the processor as its "extended arm" (Martini in Paal/Pauly, GDPR BDSG, 3rd ed., Art. 28 para. 2; Bergt in Kühling/Buchner, GDPR BDSG, 4th ed., Art. 82 para. 55). Only in the case of so-called excessive processing, where the processor itself determines the purposes and means of processing in violation of the General Data Protection Regulation (Art. 28 para. 10 GDPR), will this controller and the original controller potentially be released from liability (cf. for liability under Art. 83 GDPR, CJEU, Judgment of 5 December 2023 - C-683/21, ZD 2024, 209, para. 85). This applies, among other things, if the processor has processed data in a manner incompatible with the framework or modalities of processing as defined by the controller, or in a manner where it cannot reasonably be assumed that the controller would have consented (CJEU, ibid.). However, even in these cases, the controller may be liable if they fail to use contractual means to ensure the processor complies with the contract (see Petri in Simitis/Hornung/Spiecker gen. Döhmann, Datenschutzrecht [Data Protection Law], 2nd ed. 2025, GDPR Art. 28 para. 94).
The controller must also guarantee the protection of the data subjects' rights in connection with the termination of the contract. In this respect, it is important to note that the transfer of personal data from the controller to the processor constitutes an infringement of the data subjects' rights to respect for private life and to the protection of personal data, guaranteed by Articles 7 and 8 of the Charter of Fundamental Rights of the European Union. This infringement is only justified as long as the conditions for processing on behalf of the controller are met. However, if the contractual relationship no longer exists, there is no longer any justification for the data to remain with the data processor (BeckOK Datenschutzrecht/Spoerr, 53rd ed., as of August 1, 2025, GDPR Art. 28 para. 78). It is therefore also and especially the responsibility of the controller to ensure that – subject to any statutory retention obligations – no personal data remains with the data processor that was provided to them by the controller for the purpose of fulfilling the contract (BeckOK/Spoerr, ibid., Art. 28 para. 79; Petri in Simitis/Hornung/Spiecker gen. Döhmann, Datenschutzrecht, 2nd ed., GDPR Art. 28 para. 78; Hartung in Kühling/Buchner, ibid., Art. 28 para. 77). The processor's right of access to this data ceases upon termination of the contract; therefore, access to it must be denied to the processor from that point onward (Martini, loc. cit., Art. 28, para. 50). Accordingly, Article 28(3), second sentence, point (g) of the GDPR stipulates that the contract or other legal instrument on which the data processing is based pursuant to Article 28(3) of the GDPR must provide that, after completion of the processing services, the processor shall, at the controller's discretion, either delete or return all personal data and delete any existing copies, unless Union or Member State law requires the retention of the personal data. Furthermore, Article 28(3), second sentence, point (h) of the GDPR requires that the data processor provide the controller with all necessary information to demonstrate compliance with the obligations laid down in Article 28 of the GDPR, including the obligation to erase or return data, and enable and contribute to audits by the controller or an auditor appointed by the controller.
However, the controller may not simply conclude a contract with the data processor that imposes a contractual obligation on the processor to erase the data and provide proof of erasure upon termination of the contract. Rather, upon termination of the contractual relationship, the controller must take all necessary steps, depending on the circumstances of the individual case, to ensure that the data processor fulfills its contractual obligations, meaning that the personal data is no longer stored by the processor and that the controller no longer has access to it. Whether this obligation arises from Article 28 GDPR, because paragraph 1 and paragraph 3 sentence 2 letter h, when interpreted reasonably, implies a duty of control on the part of the controller (cf. Gabel/Lutz, Art. 28, para. 27, 31; BeckOK/Spoerr, Art. 28, para. 35; Martini, Art. 28, para. 20; Hartung, Art. 28, para. 60), can remain undecided. This obligation arises, in any case, from the principle of data minimization (Art. 5 para. 1 letter c GDPR) and, in particular, from the principle of storage limitation (Art. 5 para. 1 letter e GDPR), which concerns the storage period and results in the obligation to delete or return data upon termination of the contractual relationship (Martini, loc. cit., Art. 28 para. 50; Petri in Simitis/Hornung/Spiecker gen. Döhmann, Datenschutzrecht [Data Protection Law], 2nd ed., GDPR Art. 28 para. 78). The controller is "responsible" for compliance with these principles pursuant to Art. 5 para. 2 GDPR. Furthermore, the controller's obligation to ensure that the processor is deprived of access to the personal data of the data subjects upon termination of the contract arises from the obligation, derived from Art. 5 para. 2 in conjunction with Art. 5 para. 1 letter f and Art. 32 para. 1 GDPR, to guarantee appropriate security of the personal data. According to Article 32(1) GDPR, the controller must implement appropriate technical and organizational measures to ensure an appropriate level of security, taking into account, among other things, the likelihood and severity of the risk to the rights and freedoms of natural persons. Article 32(2) GDPR requires that, in assessing the appropriate level of security, particular consideration must be given to the risks associated with data processing, including unauthorized access to stored data. The risk of unauthorized access to stored data does not only arise in the event of a cyberattack by external third parties, but also when the data remains stored with the processor after the termination of the contractual relationship, even though the processor's right of access has expired upon termination of the contract. The controller must prevent this "as far as possible" by taking appropriate measures (regarding this limitation, see CJEU, Judgment of 14 December 2023 - C-340/21, NJW 2024, 1091, para. 30). He must therefore contribute what is necessary under the circumstances of the individual case to ensure that the personal data is actually returned or deleted by the processor upon termination of the contract. The burden of proof for the suitability of the security measures he has taken in this respect lies with the controller (see ECJ, loc. cit., paras. 52, 56).
If the controller has breached this duty incumbent upon him, and in particular has not insisted on the processor's contractual compliance with regard to data deletion or return upon termination of the contract, he cannot evade responsibility for this simply by pointing to an excess of duties committed by the processor through its unauthorized retention and further processing of the data. The controller is solely responsible for the consequences of his own breach of duty.
(2) Based on the findings of the Court of Appeal, the defendant failed to comply with the duty set out in (1). While it had entered into contractual agreements with company O. to comply with the requirements of Article 28(3), second sentence, letters g and h of the GDPR, the defendant failed to do so. Specifically, company O. was to, at the defendant's option, either return a complete copy of all the defendant's personal data to the defendant and delete all other copies, or delete all data and all copies thereof; the deletion was to take place within 21 days of the termination of the contract. Furthermore, the defendant was required to receive written confirmation that it (and its sub-processors) had "fully complied" with the obligation to return or delete the data within the specified period. It is irrelevant whether the defendant, by failing to exercise its contractual right of choice, committed a breach of duty that was (partly) responsible for the subsequent unauthorized access of the data. In any case, the defendant breached its duty to contribute what was necessary under the circumstances of the present case to ensure that the personal data was actually returned or deleted by the data processor upon termination of the contract, by accepting the announcement from company O. that it would delete the defendant's "site" and all data on the "site" the following day. The announced activity did not even meet the contractually owed and data protection-related requirement of comprehensive deletion, including all data copies. Therefore, and because the contractually required written confirmation that the deletion obligations had been "fully complied with"—that is, that the deletion of all data and data copies had been completed—was not forthcoming, the defendant, in its responsibility for the personal data of its customers, was obligated to request this confirmation immediately after the 21-day period had expired. The defendant's inquiry with O., as determined by the Court of Appeals, only in 2023—more than three years after the termination of the contract and only after the hacking incident became known—was clearly belated and could no longer prevent the latter.
... (3) In the present case, it is unnecessary to decide whether, as the respondent argues, only data processing that violates the provisions of the General Data Protection Regulation can be the basis for a claim for damages under Article 82(1) GDPR, and thus whether the failure to comply with merely abstract obligations outside of a specific processing operation cannot give rise to liability for damages (for the state of the debate, see the evidence in the Federal Court of Justice's judgment of 18 November 2024 – VI ZR 10/24, BGHZ 242, 180, para. 23; for the view that no processing is required, see the Opinion of the Advocate General at the Court of Justice of the European Union (Szpunar) of 18 September 2025 in Case C-526/24, juris, para. 77). The Court of Justice has already ruled that infringements of the provisions of Articles 5 to 11 GDPR, i.e., Chapter 2 of the General Data Protection Regulation, which establish the principles for the processing of data, also constitute unlawful data processing (see CJEU, Judgment of 4 May 2023 - C-60/22, ZD 2023, 606, paragraphs 54-57). Therefore, there are no concerns regarding the applicability of Article 82(1) GDPR to infringements of Article 5 GDPR (see Senate Judgment, loc. cit., paragraph 24, with further references to the case law of the CJEU). Furthermore, the Court of Justice has already held that, in cases of infringements of, among others, Article 32 GDPR, a claim for damages under Article 82 GDPR is possible (see CJEU, judgments of 25 January 2024 – C-687/21, CR 2024, 160, paras. 42 et seq.; of 14 December 2023 – C-340/21, NJW 2024, 1091, paras. 52 et seq.).
As explained above, in the present case, the defendant infringed, among other things, its obligations under Article 5(2) in conjunction with Article 5(1)(c), (e) and (f) GDPR, as well as under Article 32(1) GDPR, with the consequence that the personal data of the defendant's customers, including the plaintiff, remained stored (and thus processed within the meaning of Article 4(2) GDPR) at company O. for a longer period than was permissible under data protection law. Even under a restrictive interpretation of Article 82(1) GDPR, there is a violation of the General Data Protection Regulation within the meaning of this provision.
bb) The Court of Appeal's assessment that the defendant cannot be exonerated under Article 82(3) GDPR—for example, by invoking conduct by its data processor that was contrary to instructions or the contract, or by citing a hacking attack by unauthorized third parties—is not subject to legal challenge on appeal. Exoneration would require the defendant to prove that it is in no way responsible for the circumstances that caused the damage, i.e., that it is not at fault (Boehm in Simitis/Hornung/Spiecker gen. Döhmann, Datenschutzrecht [Data Protection Law], 2nd ed., GDPR, Article 82, para. 24). Since the defendant is guilty of its own (at least slightly) negligent breach of the General Data Protection Regulation (GDPR), it would have to prove that there is no causal link whatsoever between this breach and the damage suffered by the plaintiff (see ECJ, judgments of 11 April 2024 - C-741/24, NJW 2024, 1561, para. 51; of 14 December 2023 - C-340/21, NJW 2024, 1091, para. 72). It has failed to do so. The Court of Appeal's assessment that it could be assumed that company O. would have responded to the defendant's required inquiry regarding the execution of the deletion and would have deleted the data still held by it is not subject to legal challenge on appeal. The defendant's breach of duty was thus a contributing cause of the fact that personal data of its customers, including the plaintiff, remained with company O. despite the termination of the contract, was transferred from the production to a test environment, was either stolen by hackers or unlawfully disclosed by employees of company O., and subsequently offered for sale on the darknet.
b) Based on the findings of the Court of Appeal, its assessment that the plaintiff suffered no non-material damage within the meaning of Article 82(1) GDPR is erroneous. According to the Court of Appeal's findings, the following personal data of the plaintiff was affected by the incident: first and last name, gender, email address, language, and his registration date with the defendant. The plaintiff not only lost control over this data because, after the termination of the data processing agreement, company O. and third parties (hackers) had unauthorized access to the data, but the data was also subsequently misused by being offered for sale on the darknet. At the latest, this has resulted in non-material damage to the plaintiff. Furthermore, such damage has occurred due to the plaintiff's well-founded fear, contrary to the opinion of the appellate court, that the data published on the darknet could be (further) misused through the sending of spam emails.
This fear is to be considered justified. (aa) In the absence of a reference in Article 82(1) GDPR to the national law of the Member States within the meaning of that provision, the concept of "non-material damage" must be defined autonomously under EU law (established case law, see, for example, CJEU judgments of 4 September 2025 - C-655/23, NJW 2025, 3137, para. 55; of 4 October 2024 - C-200/23, DB 2024, 2952, para. 139 with further references; further references in the Federal Court of Justice judgment of 18 November 2024 - VI ZR 10/24, BGHZ 242, 180, para. 28). According to Recital 146, third sentence, of the GDPR, the concept of damage should be interpreted broadly in a manner that fully complies with the objectives of this Regulation. However, according to the Court of Justice's case law, a mere violation of the provisions of the General Data Protection Regulation (GDPR) is not sufficient to establish a claim for damages; rather, as an independent condition for a claim, the occurrence of damage (as a result of this violation) is also required (established case law, see CJEU, judgments of 4 September 2025 – C-655/23, loc. cit., para. 56; of 4 October 2024 – C-200/23, loc. cit., para. 140 with further references; further references in the Senate judgment of 18 November 2024 – VI ZR 10/24, loc. cit.).
... The Court further stated that Article 82(1) GDPR precludes national legislation or practice that makes compensation for non-material damage within the meaning of that provision conditional upon the damage suffered by the data subject reaching a certain degree of severity or significance, or exceeding a "de minimis" threshold (CJEU, judgments of 4 September 2025 - C-655/23, loc. cit., para. 58; of 4 October 2024 - C-200/23, loc. cit., para. 149 with further references; further references in the Senate judgment of 18 November 2024 - VI ZR 10/24, loc. cit., para. 29). However, the Court also stated that, pursuant to Article 82(1) GDPR, the data subject is obliged to prove that they have actually suffered material or non-material damage. The rejection of a materiality threshold does not mean that a person affected by a breach of the General Data Protection Regulation that has had negative consequences for them would be relieved of the burden of proving that these consequences constitute non-material damage within the meaning of Article 82 of that Regulation (see ECJ, Judgment of 4 October 2024 - C-200/23, loc. cit., para. 142; further references in the Senate Judgment of 18 November 2024 - VI ZR 10/24, loc. cit.).
bb) As the Senate explained in its judgment of November 18, 2024 – VI ZR 10/24 (BGHZ 242, 180) – which, however, was issued after the contested decision – concerning a Facebook scraping incident and referring to the case law of the Court of Justice, non-material damage within the meaning of Article 82(1) GDPR can also be the mere and temporary loss of control over one's own personal data as a result of a breach of the General Data Protection Regulation (ibid., paras. 30 et seq.). If the data subject has provided evidence that they have suffered damage consisting solely of a loss of control as such, and the loss of control is thus established, it itself constitutes the non-material damage, and no further specific fears or anxieties of the data subject arising from it are required; these are merely capable of further deepening or increasing the non-material damage already incurred (ibid., para. 31).
These are, however, subsequent to the contested decision – in a case concerning a Facebook scraping incident, and the case concerning a Facebook scraping incident, with reference to the case law of the Court of Justice, non-material damage within the meaning of Article 82(1) GDPR can also consist of the mere and temporary loss of control over one's own personal data as a result of a breach of the General Data Protection Regulation (ibid., para. 31). (1) This legal opinion, which the Senate has reiterated in the aforementioned judgment and in subsequent decisions (Senate judgments of 28 January 2025 - VI ZR 109/23, NJW 2025, 1060 para. 16 et seq.; of 11 February 2025 - VI ZR 365/22, NJW 2025, 1656 para. 15) and which is shared by the Federal Labour Court (see Federal Labour Court, judgment of 8 May 2025 - 8 AZR 209/21, NZA 2025, 1248 para. 24), is, according to some legal scholars (see Mörsdorf/Momtazi, JZ 2025, 425, 428 et seq.; Paal, NJW 2025, 261, 263 et seq.; Spittka, DSB), 2024, 311, 312 et seq.; Schürgers/Hirschberger, NZA 2025, 216, 221 et seq.) and, according to the respondent, are inconsistent with the case law of the Court of Justice. In particular, it is argued that the Court of Justice considered the loss of control as such only as a possible cause of non-material damage, but not as the non-material damage itself.
[The text abruptly ends here, so the translation stops here.] (2) Contrary to this view, as the Court of Justice pointed out in its judgment of 4 September 2025 - C-655/23 (NJW 2025, 3137, paragraph 59), the recitals of the General Data Protection Regulation list the prevention of the data subject from "controlling the personal data concerning him or her" (Recital 75 GDPR) and the "loss of control over his or her personal data" (Recital 85 GDPR) as examples of possible harm within the meaning of Article 82(1) GDPR. Referring to Recital 85 of the GDPR, the Court has repeatedly pointed out, including in its most recent decisions on this subject, that the EU legislator intended the concept of damage to include the "mere loss of control" over the personal data of those individuals as a result of an infringement of the GDPR, even if there had been no actual misuse of the data in question (CJEU, judgments of 4 September 2025 - C-655/23, NJW 2025, 3137, para. 60; of 4 October 2024 - C-200/23, DB 2024, 2952, para. 145; of 14 December 2023 - C-340/21, NJW 2024, 1091, para. 82). Similarly, in its judgment of 11 April 2024 – C-741/21, NJW 2024, 1561, paragraph 42, the Court of Justice stated that recital 85 of the GDPR expressly includes the “loss of control” among the damages that can be caused by a personal data breach. In the same judgment (ibid.) and in its judgment of 20 June 2024 – C-590/22, ZD 2024, 519, paragraph 33, the Court held that the loss of control over personal data – even if only temporary – can constitute non-material damage within the meaning of Article 82(1) GDPR (English version: “constitute”, French version: “constituer”), giving rise to a claim for damages, provided that the data subject proves that they have actually suffered such damage – however minor it may be. This supports the Senate's view that the loss of control itself can constitute damage within the meaning of Article 82(1) GDPR, and that only this loss needs to be proven to establish a claim for damages.
However, the wording is not consistent, even when comparing the different language versions. The German version of the Court of Justice's judgment of 25 January 2024 – C-687/21, CR 2024, 160, paragraph 66, states that the data subject may "suffer" non-material damage within the meaning of Article 82(1) GDPR due to the temporary loss of control. The Court of Justice's judgments of 14 December 2023 – C-456/22, NZA 2024, 56, paragraph 22, and of 4 October 2024 – C-200/23, DB 2024, 2952, paragraph 150, state that the loss of "sovereignty" over this data may "cause" damage. However, in the English and French versions, the terms "loss of control" and "perte de contrôle" are used uniformly, and the link to the intangible damage is uniformly established by the words "cause/causing" and "causer". In the German language versions, the word "verursachen" (only) appears in paragraph 156 of the Court of Justice's judgment of 4 October 2024 - C-200/23 (loc. cit.) and in the Court of Justice's judgment of 4 September 2025 - C-655/23, NJW 2025, 3137, paragraph 60, where it states that a temporary loss of control by the data subject over their personal data may be sufficient to "cause" non-material damage within the meaning of Article 82(1) GDPR, provided that the data subject proves that they have actually suffered such damage – however minor it may be – without this concept of non-material damage requiring proof of "additional noticeable negative consequences" (emphasis added). If this sentence is considered in isolation, the mere loss of control could only be the cause of a separate non-material damage, which the data subject would have to prove, without requiring proof of additional tangible negative consequences. However, this would raise the question of precisely what constitutes non-material damage as an intermediate stage between loss of control and additional tangible negative consequences. In particular, this interpretation would be difficult to reconcile with the Court's statement (repeated immediately beforehand in paragraph 60 of its judgment of 4 September 2025 - C-655/23) that the EU legislature, in its exemplary list of types of damage, intended to include in this concept, inter alia, the mere loss of control over the personal data of those individuals as a result of a breach of the GDPR, and with the formulation used by the Court in other judgments that the loss of control can "constitute" non-material damage. In his Opinion of 18 September 2025 in Case C-526/24, the Advocate General (Szpunar) of the Court of Justice, referring inter alia to the Court's judgment of 4 September 2025 in Case C-655/23, used the word "constitute" ("constituer") rather than "cause" ("causer") (paragraph 89). In this context, it is also necessary to consider the objective pursued by the General Data Protection Regulation (GDPR) of ensuring a high level of protection for natural persons with regard to the processing of personal data, as well as Recital 146, third sentence, of the GDPR, which requires a broad interpretation of the concept of damage in a manner that fully complies with the objectives of the GDPR.
cc) However, these considerations, which support the classification of the loss of control as non-material damage – also according to the Court's case law – are ultimately not decisive in the present case. For here, as in the Facebook scraping cases (see Federal Court of Justice judgment of November 18, 2024 – VI ZR 10/24, BGHZ 242, 180), there has not only been a loss of control, but also, as a consequence, the misuse of personal data, resulting in non-material damage.
(1) It is clear from the Court of Justice's case law that non-material damage within the meaning of Article 82(1) GDPR exists at least when the loss of control has not been without consequence, but rather when the data in question has actually been misused. From the Court of Justice's recent reiteration that the EU legislature intended the concept of damage to include, in particular, the mere loss of control over one's own personal data, even if there had been no actual misuse of the data in question (ECJ, judgments of 4 September 2025 - C-655/23, NJW 2025, 3137, para. 60; of 4 October 2024 - C-200/23, DB 2024, 2952, para. 145; of 14 December 2023 - C-340/21, NJW 2024, 1091, para. 82, emphasis added), it can be concluded that non-material damage must be affirmed all the more if the data have actually been misused. The same conclusion follows from the Court of Justice's case law, according to which a data subject's fear, triggered by a breach of the General Data Protection Regulation, that their personal data may be misused by third parties, can in itself constitute non-material damage within the meaning of Article 82(1) GDPR, provided that this fear can be considered "justified" under the given specific circumstances and with regard to the data subject, i.e., that the risk of misuse by an unauthorized third party is not purely hypothetical (see, for example, CJEU judgments of 4 October 2024 - C-200/23, DB 2024, 2952, paras. 143 et seq. with further references; of 25 January 2024 - C-687/21, CR 2024, 160, paras. 65, 67, 68; Federal Court of Justice judgment of 13 May 2025 - VI ZR 186/22, CR 2025, 585 para. 28 et seq.; see below dd) for further details. As with loss of control, it is therefore not necessary for a fear to qualify as non-material damage that the feared misuse of the data actually occurs. However, if the risk of misuse has materialized, then non-material damage is all the more likely to have occurred.
In particular, this does not additionally require "emotional" damage caused by the misuse of data. The latter cannot be based on the Court's answer, in paragraph 64 of its judgment of 4 September 2025 – C-655/23 (NJW 2025, 3137), to the fourth preliminary question referred by the Senate, stating that "Article 82(1) GDPR must be interpreted as meaning that the term 'non-material damage' in that provision includes negative feelings experienced by the data subject as a result of the unauthorized disclosure of their personal data to a third party, such as worry or anger, and caused by a loss of control over that data, its possible misuse, or damage to reputation, provided that the data subject demonstrates that they experience such feelings and their negative consequences as a result of the infringement of the GDPR in question." The fourth question referred to the Court did not concern whether and under what conditions a loss of control or even a misuse of data constitutes non-material damage, but rather whether Article 82(1) GDPR should be interpreted as meaning that mere negative feelings such as anger, resentment, dissatisfaction, worry, and anxiety, which are inherently part of the general risks of life and often of daily experience, are sufficient to establish non-material damage within the meaning of that provision (ibid., para. 35). The answer, that proven negative feelings, along with their negative consequences caused by a loss of control, etc., are covered by the concept of non-material damage, does not lead to the conclusion that such negative feelings are absolutely necessary to establish damage.
(2) Applying these standards, non-material damage within the meaning of Article 82 GDPR must be assumed in the present case at least from the point in time when the plaintiff's personal data was published on the darknet and offered for sale there. Previously, the plaintiff had lost control over this data because his personal data remained stored with Company O. despite the termination of the contractual relationship. This meant that both Company O. and third parties who hacked the data or obtained it from Company O. employees had unauthorized access to the data. The data was then misused following its subsequent publication on the dark web.
Whether the plaintiff's data in question had already been hacked before the incident in question, as the Court of Appeal found on the website "haveibeenpwned.com," is irrelevant to the existence of damages. Each unlawful access to the data intensifies the loss of control and increases the risk of misuse (by the same or a different group of people). Therefore, the fact that the same data had already been hacked can, in itself, only be relevant when assessing the amount of damages.
The existence of damages is not determined solely by whether the plaintiff's data had already been hacked before. (dd) In this case, non-material damage is also established by the plaintiff's fear, triggered by the disclosure of the incident, that the data published on the darknet could be misused (once again). The Court of Appeal's assessment that this fear is unfounded is based on legal errors.
(dd) (1) The Court of Justice has established that the (perceived) fear of a data subject, triggered by an infringement of the General Data Protection Regulation, that their personal data may be misused by third parties as a result of such an infringement, can, in itself, constitute non-material damage within the meaning of Article 82(1) GDPR, provided that such fear, together with its adverse consequences, is duly proven (CJEU, judgments of 4 September 2025 - C-655/23, NJW 2025, 3137, para. 61; of 4 October 2024 - C-200/23, DB 2024, 2952, paras. 143 et seq.; of 20 June 2024 - C-590/22, ZD 2024, 519, paras. 32, 35, 36; of 25 January 2024 - C-687/21, CR 2024, 160 para. 65; Senate judgments of 13 May 2025 - VI ZR 186/22, CR 2025, 585 para. 28; of 18 November 2024 - VI ZR 10/24, BGHZ 242, 180 para. 32). In contrast, the mere assertion of a fear without proven negative consequences is insufficient, as is a purely hypothetical risk of misuse by an unauthorized third party (ECJ, judgments of 20 June 2024 - C-590/22, loc. cit. para. 35; of 25 January 2024 - C-687/21, loc. cit. para. 68; Senate judgments of 13 May 2025 - VI ZR 186/22, loc. cit. para. 29; of 18 November 2024 - VI ZR 10/24, loc. cit.). The concern must be deemed "justified" under the given specific circumstances and with regard to the person concerned (ECJ, judgments of 4 October 2024 - C-200/23, loc. cit. para. 143 with further references; of 14 December 2023 - C-340/21, NJW 2024, 1091 para. 85; Senate judgment of 13 May 2025 - VI ZR 186/22, loc. cit.). As with loss of control, it is not necessary that the data actually be misused (see above, sub cc) (1)). The negative consequences associated with a well-founded fear of data misuse can also include negative feelings such as worry and anger, even though these may be part of the general risks of life (see ECJ, Judgment of 4 September 2025 - C-655/23, loc. cit., paras. 62, 64).
The requirements for demonstrating a fear of data misuse must not be excessive. The mere fact that numerous legal actions following an incident affecting a large number of people contain identical formulations regarding concerns and fears about data misuse does not preclude the validity of the respective claim (see Federal Court of Justice, Judgment of 18 November 2024 - VI ZR 10/24, loc. cit., para. 36). The more plausible the fear of data misuse appears in the specific case, the lower the requirements for demonstrating it.
The more plausible the fear of data misuse appears in the specific case, the lower the requirements for demonstrating it. (2) The Court of Appeal's assessment that the applicant's concern about data misuse could not be considered well-founded is not in accordance with the Court of Justice's case law.
According to the Court of Appeal's findings, the applicant fears, in particular, receiving spam emails, including fraudulent ones, and identity theft as a result of the incident in question. When, as in this case, a natural person's name and email address are offered for sale on the darknet, it is highly probable that this data will be used to send advertising emails, as well as emails containing fraudulent content, to that person. The Court of Appeal does not appear to dispute this. Furthermore, there is a concrete risk that fraudulent emails will be sent to third parties under the name of the person concerned and seemingly from their email account. The mere sending of these spam emails to the plaintiff, or seemingly by him as the sender to third parties, constitutes the misuse of the plaintiff's data (after its publication on the darknet), so that the mere fear of this – objectively plausible – misuse represents non-material damage, provided this fear and its negative consequences are proven. Contrary to the opinion of the appellate court, the potential danger associated with spam emails, the precautionary measures that can be taken, and when such emails lead to material damage are irrelevant for the classification of the fear as justified. Since the misuse of data only needs to be feared, but need not actually occur, it is also immaterial whether the plaintiff has received or will receive spam emails specifically as a result of the incident in question. Considering that the hacked data was not particularly sensitive, that other people also receive spam emails whose data has not been hacked, that the plaintiff's discomfort did not exceed what all private individuals using the internet experience when receiving unsolicited messages, and that the plaintiff did not change his email address after becoming aware of the incident, the Court of Appeal ultimately assumed a threshold of materiality for the assumption of damages that does not exist according to the aforementioned case law of the Court of Justice. These considerations can only play a role in determining the amount of damages (see Federal Court of Justice judgment of November 18, 2024 - VI ZR 10/24, BGHZ 242, 180 para. 99). However, it must be taken into account that the fear of data misuse and the associated anxiety can be felt more strongly if the affected person has actual knowledge that their data has been offered for sale on the darknet.
† ... Finally, the fact that the plaintiff's data, according to the website "haveibeenpwned.com," was allegedly hacked even before the incident in question does not negate the concern that it will be misused again—by the same or different persons—as a result of the incident in question. In particular, contrary to the respondent's argument, there is no lack of causality between the breach in question and the concern as non-material damage.
II.
The dismissal of the declaratory judgment claim as inadmissible is also based on an error of law. In the appeal proceedings, the only remaining issue is the claim for a declaration that the defendant is obligated to compensate the plaintiff for all future material damages that he will incur as a result of the unauthorized publication of his data on the internet in 2022.
1. The Court of Appeal correctly stated as a starting point that the mere possibility of the claimed material damage occurring in the future is sufficient to establish a legitimate interest in a declaratory judgment; a further sufficient probability of damage is not required. The possibility of future damage is sufficient here because it does not concern purely pecuniary losses, but rather damage resulting from the violation of the plaintiff's right to informational self-determination under Article 2 Paragraph 1 of the Basic Law in conjunction with Article 1 Paragraph 1 of the Basic Law, or his right to the protection of personal data under Article 8 of the Charter of Fundamental Rights of the European Union (Federal Court of Justice judgment of November 18, 2024 - VI ZR 10/24, BGHZ 242, 180, paragraphs 48 et seq.). The Court of Appeal correctly points out that the possibility of further damage is lacking if, from the perspective of the injured party, there is no reason, upon reasonable consideration, to expect the occurrence of further damage (Senate judgment of April 8, 2025 - VI ZR 25/24, NJW 2025, 2619 para. 6 with further references).
2. The reasoning with which the Court of Appeals denied the mere possibility of future material damages does not withstand review on appeal.
The Court of Appeals reasoned that the probability of damage occurring decreases with increasing distance from the hacking incident and that, consequently, the causal link becomes increasingly difficult to prove. However, a decreasing probability does not preclude the possibility of damage occurring. In particular, the admissibility and merits of the declaratory judgment action do not depend on whether the plaintiff will be able to prove, should material damage occur, that it is directly attributable to the incident in question. This is only decisive for the success of any subsequent claim for performance.
The mere possibility of damage occurring cannot be denied on the Court of Appeals' grounds that the plaintiff has been affected by hacking attacks in the past without any causal material damage having yet occurred.
As explained above, it is highly likely that data such as a natural person's name and email address, offered for sale on the darknet, will be used to send fraudulent emails. The possibility that the plaintiff will continue to receive such emails as a result of the publication of his data on the darknet, and that this will lead to material damage, is therefore not so far-fetched that, from the plaintiff's perspective, it could reasonably be disregarded.
III.
Since the case is not yet ready for a final decision, it is remanded to the court of appeals for a new hearing and decision (Section 563, Paragraph 1, Sentence 1, Paragraph 3 of the German Code of Civil Procedure). For the standards to be applied in assessing damages, reference is made to the Federal Court of Justice's judgment of November 18, 2024 – VI ZR 10/24 (BGHZ 242, 180, paragraphs 93 et seq.).




