BGH - VI ZR 375/2

From GDPRhub
BGH - VI ZR 375/24
Court: BGH (Germany)
Jurisdiction: Germany
Relevant Law: Article 6(1)(f) GDPR
Article 17(1)(d) GDPR
Article 19 GDPR
Article 82 GDPR
Decided: 12.05.2026
Published: 29.06.2026
Parties:
National Case Number/Name: VI ZR 375/24
European Case Law Identifier: ECLI:DE:BGH:2026:120526UVIZR375.24.0
Appeal from:
Appeal to: Not appealed
Original Language(s): German
Original Source: BGH (in German)
Initial Contributor: av

The Federal Court of Justice held that a debt collection agency had unlawfully transmitted information on outstanding debts to a credit information agency. The data subject was entitled to the revocation of the disputed data and non-material damages.

English Summary

Facts

A debt collection agency (the controller) sent reminders to a customer (the data subject) for delayed installment payments related to a terminated electricity contract in November 2019. The data subject considered the claimed sums to be excessive and refused to pay. The controller transmitted the information on outstanding debts of €795 and €817 to a credit information agency, which in turn made negative entries in its database. This lowered the credit score assigned to the data subject by the credit information agency.

The data subject sued the controller for disclosing outstanding receivables to the credit information agency. The court of first instance ordered the controller to revoke the negative entries contained in the credit ranking database and awarded the data subject €500 in damages. The controller appealed this decision.

The appellate court held that there had been no legal basis for the transmission of personal data, as the data subject had not consented to the processing and the requirements for legitimate interests pursuant to Article 6(1)(f) GDPR were not met. However, the court considered that the data subject had not suffered any non-material damage within the meaning of Article 82 GDPR. The controller appealed the case further to the Federal Court of Justice.

Holding

The Federal Court of Justice dismissed the controller’s appeal and referred the case back to the appellate court. First, the court held transmitting the personal data to the credit information agency had been unlawful due to the lack of a legal basis. It pointed out that the requirements for processing based on legitimate interests laid down in Article 6(1)(f) GDPR were not met. As such, legitimate public interests in preventing the granting of credit to those who are unable or unwilling to pay could justify the transfer of data to credit information agencies. However, no meaningful indications regarding the data subject’s ability or willingness to pay could be derived from the credit information entries at issue: the controller had failed to demonstrate the debts existed in the amount claimed. Therefore, it could not rely on legitimate interests as a legal basis.

Second, the court held that the data subject was entitled to the revocation of the disputed credit information entries due to the unlawful disclosure of their personal data. According to the court, this claim could be based on 1) the application of Article 19 GDPR in conjunction with Article 17(1) (d) GDPR, 2) Article 19 GDPR in conjunction with Articles 5(1)(a), 5(2), and 24(1) GDPR, or 3) national law by analogy.

Third, the court held that the data subject had suffered non-material damage within the meaning of Article 82 GDPR due to the harm caused to their economic reputation. The fact that the credit reports adversely affected the data subject’s credit score, which could then be taken into account by potential contractual partners, was enough to give rise to a claim for damages. The court pointed out that the transmission of personal data to one recipient and the risk of further transmissions to third parties already constituted loss of control; the data subject did not need to prove a feeling of helplessness, fear, or anxiety to be entitled to damages.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the German original. Please refer to the German original for more details.

FEDERAL COURT OF JUSTICE

IN THE NAME OF THE PEOPLE

JUDGMENT

VI ZR 375/24
in the legal dispute

Reference work: yes
BGHZ: no
BGHR: yes
JNeu: yes

GDPR Art. 6 para. 1 subpara. 1 letter f, Art. 17 para. 1 letter d, Art. 19 sentence 1, Art. 82 para. 1; German Civil Code (BGB) § 823 para. 1 ah, § 1004 para. 1 sentence 1

a) On the admissibility of the transfer of personal data in the context of
reporting an alleged outstanding debt to a credit reporting agency.

b) If personal data relating to alleged outstanding debts are unlawfully transferred to

a credit reporting agency, the data subject may have a claim against the transferring party for the removal of the consequences in the form of
the revocation of the report.


c) On the concept of non-material damage within the meaning of Article 82 GDPR.

Federal Court of Justice (BGH), Judgment of May 12, 2026 - VI ZR 375/24 - Higher Regional Court of Schleswig

Regional Court of Kiel

ECLI:DE:BGH:2026:120526UVIZR375.24.0 - 2 -

The Sixth Civil Senate of the Federal Court of Justice, in the oral proceedings
of May 12, 2026, with Presiding Judge Seiters, Judges Dr. Klein,

Dr. Allgayer and Böhm, and Judge Dr. Linder

rendered for justice:

Upon the plaintiff's cross-appeal, the judgment of the 17th Civil

Senate of the Schleswig-Holstein Higher Regional Court of

November 22, 2024, as amended by the rectification order

of December 17, 2024, is set aside with respect to costs and insofar as it is unfavorable to the plaintiff.

The defendant's appeal against the aforementioned judgment is dismissed.



To the extent of the reversal, the case is remanded to the court of appeals for a new hearing

and decision, including on the costs of the appeal proceedings.


By law

Statement of Facts:

1. The plaintiff is suing the defendant debt collection agency for

the revocation of outstanding receivables and compensation for non-pecuniary damages after the report

of outstanding receivables to SCHUFA Holding AG (hereinafter: SCHUFA).


2. In 2014, the plaintiff received electricity from i.-Energie GmbH.

This company terminated the contract without notice because the plaintiff was in arrears with advance payments.

With a final invoice dated October 11, 2014,

it billed him €529.16. Subsequently,

a debt collection agency, acting on behalf of i.-Energie GmbH, sent reminders to

the plaintiff. By letter dated November 29, 2014, the plaintiff informed

i.-Energie GmbH that he had received neither the invoice nor the reminders.

Regardless, he rejected the claim of €529.16 as "excessive and over-

excessive." He requested a "corrected invoice." Da-

Subsequently, on December 2nd and 9th, 2014, i.-Energie GmbH sent its final invoice – unchanged.



On November 25th, 2019, the defendant assumed the debt collection services

for the claim arising from the final invoice. On March 12th, 2021,

it initiated the inclusion of the claim as a negative entry in the database of

SCHUFA. This negative entry negatively impacted the credit score determined by SCHUFA for the plaintiff.


On March 18th, 2022, a further

report was sent to SCHUFA regarding the claim.


4 The Regional Court ordered the defendant – insofar as it is relevant in the appeal proceedings – to revoke the negative entry in the SCHUFA database

concerning an existing payment default and an outstanding claim of €795 as of March 12, 2021, as well as an outstanding claim of €817 as of March

18, 2022.

Furthermore, it awarded the plaintiff €500 in damages

for pain and suffering, as well as pre-litigation legal fees.

On the defendant's appeal, the Higher Regional Court dismissed the claim for damages.

In all other respects, it dismissed the appeal.

5 With its appeal on points of law, which was granted by the Higher Regional Court, the defendant

continues to pursue its objective of having the action dismissed in its entirety.

The plaintiff, with his cross-appeal, seeks the reinstatement of the Regional Court's

judgment in its entirety. - 4 -

Grounds for the Decision:

I.

6 The Court of Appeal, whose judgment is published, inter alia, in ZIP 2025, 212,

states the following in support of its decision—insofar as it is relevant here:

7 The plaintiff can demand from the defendant the revocation of the negative entry

at SCHUFA by analogy to Section 1004 Paragraph 1, Section 823 Paragraph 1

of the German Civil Code (BGB) in conjunction with Article 6 Paragraph 1 of the GDPR. It can remain open whether the

General Data Protection Regulation contains its own claim for injunctive relief or removal of the intrusion,

because the Regulation does not, in any case, preclude the

application of this claim under national law. The reporting of the defendant's disputed claims to SCHUFA is unlawful and

establishes a claim by the plaintiff against

the defendant for injunctive relief and an injunction, such that the unlawful transfer of the data to

SCHUFA must be revoked. In the absence of the plaintiff's consent,

only Article 6(1)(f) GDPR could be considered as the legal basis for the transfer of the data to

SCHUFA.

The burden of proof for demonstrating that the data processing was lawful lies with

the defendant.

The requirements for a legitimate interest and the balancing criteria for the conflicting interests of the data subject within the framework of Article

Article 6 GDPR are specified by Section 31(2) BDSG, or this provision can

be used as an aid to interpretation when applying Article 6 GDPR. The legislator implicitly assumes that only claims

that comply with the requirements of Section 31 Paragraph 2 of the German Federal Data Protection Act (BDSG) are legitimately

transmitted and used for determining score values. The two

justifying grounds of Section 31 Paragraph 2 - 5 -

Sentence 1 Nos. 4 and 5 of the BDSG, which are relevant here, presuppose the due date of the claim to be reported

and establish further prerequisites for the legality of the

transmission. The plausible

presentation of the claim to be reported is also a prerequisite, as its mere assertion does not

justify the reporting.

8 Here, the existence of the claim in dispute is already

questionable. The reported claim is a claim arising from

a final invoice within the framework of an energy supply contract, which

is composed of various items. Insofar as a payment claim for compensation for utility services is asserted therein,

this claim is based on Section 433 Paragraph 2 of the German Civil Code (BGB). A corresponding contractual and supply relationship existed between the plaintiff and i.-Energie GmbH,

undisputedly.

It is also plausibly asserted that the plaintiff did not make the monthly installments due as owed.

However,

the final bill for electricity charges does not only include the 1,306.8 kWh consumed,

but rather 1,543.86 kWh, possibly due to a flat-rate agreement.

The parties did not elaborate on this point despite discussion during the oral proceedings.

Furthermore, in addition to the pure electricity charges, the final bill also contains further claims that are not readily understandable and were not explained in more detail by the defendant during the proceedings.

The invoice included a so-called "non-performance damage"

as well as a reminder and transfer fee.

In addition, two installments paid by the plaintiff in the amounts of €79 and €50

were listed, but then so-called default costs of €163.47

and €54.37 were deducted, resulting in a negative balance

of -€88.84.

Therefore, at least with regard to these invoice items,

doubts exist as to the sufficient substantiation of the reported claim.











... Rather, both the expiration of the statute of limitations and

the lack of clarity regarding the individual reported items further argue against

an interest in the disclosure of the information. While the statute of limitations defense subsequently raised by the

plaintiff had not yet been

invoked at the time of the report, meaning that the credit industry's interest in being informed

about an outstanding claim had not yet ceased,

it nevertheless appears doubtful, from the perspective of the objectively

expired statute of limitations, whether the plaintiff could still have

expected in 2021 that a claim arising in 2014 would be reported to a credit agency. The fact that in the final invoice presented here, payment claims

for electricity supply have been mixed with other claims in such a way

that the existence of the actual payment claim cannot be determined with sufficient certainty

can also be interpreted as an indication that

the defendant – contrary to Recital 71 of the General Data Protection Regulation (GDPR)

has not taken sufficient organizational measures

to minimize the risk of errors in the data. If the defendant

fails to take sufficient precautions for the accuracy of the transmitted data by failing to differentiate according to the type of claims,

the interest in processing the data cannot be considered "legitimate" within the meaning

of Article 6(1) GDPR.

10 The plaintiff cannot, however, claim payment of

damages from the defendant. While Article 82

paragraph 1 GDPR could be considered as a legal basis for such a claim, the transfer of data to SCHUFA violated

the General Data Protection Regulation. The defendant also failed to provide relief under Article 82(3) GDPR. It cannot be argued that it was unaware of the details of the contractual relationship and the plaintiff's dispute

with respect to the claim against i.-Energie GmbH.

Precisely because the permissible reporting to SCHUFA depends on

due date, dispute, notification, etc., it is negligent

to make the report without being aware of such relevant circumstances.
... There is a lack of sufficient evidence of non-material damage that

arose from the unlawful data transfer. The plaintiff considers

the impact of the entry initiated by the defendant on his credit

rating to be significant. In the eyes of creditors or contractual partners,

he is considered insolvent due to this entry, and there are massive

impairments in the assessment of his creditworthiness by

third parties. The plaintiff has substantiated his assessment with correspondence,

which shows that several contract negotiations apparently failed because of

his SCHUFA credit rating. However, the cases presented by the plaintiff

do not show that the entry initiated by the defendant at SCHUFA specifically led to the failure of the contracts. Neither the plaintiff's low base score nor the resulting concerns of the plaintiff's potential contractual partners could be solely based on

the defendant's report in dispute. The plaintiff's credit score
was also, and certainly significantly, influenced by the further circumstances that

the plaintiff had previously refused to provide a statement of assets,

later provided one, and had also undergone consumer insolvency proceedings

without the defendant's involvement.

It therefore cannot be established that the unlawful - 8 -

transfer of data by the defendant to SCHUFA was the cause of the refusal

of contracts by a telephone provider and a

car insurance company to enter into contracts. Similarly, the plaintiff's alleged further failed contract negotiations with another telephone provider and two legal expenses insurance companies cannot be attributed

to the defendant's conduct as the primary cause.
... 12 Finally, there is no risk of losing control

over the plaintiff's personal data. The recipient of the data,

SCHUFA, is known. The conditions under which information is

provided by SCHUFA are clearly regulated, and it is comprehensible to whom

it is disclosed. The data is also of a moderate sensitivity.

Moreover, the order to remedy the consequences by revoking the

report to SCHUFA can also serve a compensatory function and is sufficient to

guarantee comprehensive legal protection.

II.

13 The defendant's appeal against this decision is unsuccessful.

The defendant's order to revoke the two SCHUFA reports concerning

(alleged) outstanding debts of €795 (as of March 12, 2021) and €817

(as of March 18, 2022) withstands legal review. The Court of Appeal

correctly concluded that the notifications in dispute

were unlawful and that the plaintiff is therefore entitled to a claim for the removal of the consequences in

the form of the revocation of the notifications against the defendant.

14 1. The lawfulness of the data transfer in dispute is governed

solely by the General Data Protection Regulation (GDPR), whose temporal (Art. 99

para. 2 GDPR), territorial (Art. 3 GDPR), and material (Art. 2 paras. 1–9)

GDPR scope is applicable. The transmission of the plaintiff's personal data by the defendant to SCHUFA in connection with the notifications constitutes processing within the meaning of Article 4 No. 2 GDPR.

Section 31 of the German Federal Data Protection Act (BDSG) is applicable regardless of the disputed question of whether this regulation is compliant with EU law (left open: ECJ, Judgment of 7 December

2023 - C-634/21, EuGRZ 2023, 642 para. 72; denying compliance due to the lack of an opening clause for national legislators: Ehmann in Simitis/Hornung/Spiecker.

Döhmann, Datenschutzrecht [Data Protection Law], 2nd ed., Section 31 BDSG para. 6 et seq.; Buchner/Petri in Kühling/Buchner, GDPR BDSG, 4th ed., Article 6 GDPR para. 161 and para. 199 f.),

not applicable, since this provision does not directly regulate the transfer of data

to credit reporting agencies (see Federal Court of Justice judgment of October 14, 2025 - VI ZR

431/24, VersR 2026, 235 para. 30 with further references).

15 2. Article 6(1), first subparagraph, GDPR contains an exhaustive and

conclusive list of the cases in which the processing of personal data

can be considered lawful. Therefore, processing must fall under one of the cases provided for in this provision in order to be

considered lawful. This is not the case here.


16 a) According to the finding of the Court of Appeal – which was not challenged on appeal –

the plaintiff had not consented to the transfer of data
concerning the claims in dispute to SCHUFA, and thus no

legal basis for processing existed under Article 6(1), first subparagraph, point (a) GDPR.

17 b) If no valid consent exists, the processing of personal

data is nevertheless justified if it is necessary for one of the reasons listed in Article 6(1), first subparagraph, points (b) to (f) GDPR,

which must be interpreted narrowly (established case law of the CJEU,

see judgment of 12 September 2024 – C-17/22 and C-18/22, NJW 2024, 3637 – 10 –

paragraphs 36 et seq. with further references). According to the only justification relevant here,

Article 6(1), first subparagraph, point (f) GDPR, the processing of personal data is lawful if it is "necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data …". According to the established

case law of the Court of Justice of the European Union (hereinafter:

Court), the processing of personal data under this provision is lawful

subject to three cumulative conditions: First, a legitimate

interest must be pursued by

the controller or a third party; second, the processing of the personal data must be necessary

for the purposes of the legitimate interest; and third, the interests or fundamental rights and freedoms

of the data subject whose data are to be protected must not override the legitimate

interest of the controller or a third party (CJEU, Judgment of 9 January 2025 - C-394/23, NJW 2025, 807, para. 45 with further references).

18 These conditions are not met with regard to the

notifications at issue. The transfer of the plaintiff's personal data in question was not necessary for the purposes of safeguarding the

legitimate interests at issue here.


19 aa) Credit reporting agencies such as SCHUFA act to safeguard

legitimate interests within the meaning of Article 6(1)(f) GDPR (see Federal Court of Justice, Judgment of December 18, 2025 - I ZR 97/25, NJW 2026, 845

paragraphs 15 et seq. with further references). - 11 -


20 (1) In addition to their own economic interests, credit reporting agencies safeguard the legitimate interests of their clients (in particular potential

lenders) (see European Court of Justice, Judgment of December 7, 2023 - C-26/22 and C-

64/22, NJW 2024, 417 paragraphs 82 et seq.). The analysis by a credit reporting agency can,
insofar as it enables an objective and reliable assessment of the creditworthiness

of the potential customers of the credit reporting agency's contractual partners,

compensate for information discrepancies and thereby reduce fraud risks and other

uncertainties (ECJ, loc. cit., para. 93).

21 (2) That lenders may obtain information on the creditworthiness of consumers

is recognized in European law (cf.Article 8 of Directive

2008/48/EC on consumer credit agreements, henceforth Articles 18 et seq. of Directive [EU]

2023/2225 on consumer credit agreements; Articles 18 to 21 of Directive

2014/17/EU on consumer credit agreements for residential property; ECJ, Judgment

of 7 December 2023 - C-26/22 and C-64/22, NJW 2024, 417, paras. 84 et seq.). The

requirements for a creditworthiness assessment are, however, governed by national

law (see ECJ, Judgment of 11 January 2024 - C-755/22, WM 2024,

340, para. 22). German law expressly recognizes creditworthiness checks by credit agencies for general consumer loan agreements in Section 505b Paragraph 1 of the German Civil Code (BGB).

Such a creditworthiness check is also intended to prevent

consumers from incurring credit obligations that exceed their financial

capacity (see BeckOGK/Knops, as of March 15, 2026,

BGB Section 505b, marginal note 2), and thus indirectly serves consumer protection (see also Recital 54 et seq. of Directive [EU] 2023/2225). Beyond the scope of consumer loan agreements, creditworthiness assessments to prevent payment defaults are also in the overall economic interest (ECJ, Judgment

of 7 December 2023 - C-26/22 and C-64/22, NJW 2024, 417, para. 86). - 12 -

22 bb) With regard to the transfer of personal data to credit reporting agencies that are useful for achieving these interests,

justification under Article 6(1)(1) also applies.

Article 1(f) GDPR is relevant (cf. regarding the transmission of positive data

for the purpose of fraud prevention, Federal Court of Justice judgment of October 14, 2025 - VI ZR

431/24, VersR 2026, 235, para. 35 et seq.). Accordingly, the Federal Court of Justice

explained the legal situation before the General Data Protection Regulation came into force,

that the information system of credit reporting agencies serves both the interests of credit

institutions and the lending business sector as well as the interests of

the individual borrower (Federal Court of Justice judgment of June 20, 1978 - VI ZR

66/77, NJW 1978, 2151, juris para. 17). Legitimate public interests
in protection against the granting of credit to insolvent or unwilling borrowers

could therefore justify the disclosure of data to credit agencies (cf.

Federal Court of Justice, Judgment of July 7, 1983 - III ZR 159/82, NJW 1984, 436, juris para. 20; see also Senate Judgment of February 22, 2011 - VI ZR 120/10, NJW 2011, 2204
para. 21; Senate Decision of June 24, 2003 - VI ZR 3/03, NJW 2003, 2904, juris

para. 6; Senate Judgment of December 17, 1985 - VI ZR 244/84, NJW 1986, 2505,

juris para. 16).

23 cc) Regarding the requirement of necessity for the processing of personal

data for the pursuit of the legitimate

interest, it must be examined whether the legitimate interest in processing

the data can be achieved just as effectively by other means that are less intrusive on the fundamental rights and freedoms of the

data subjects, in particular the rights to respect for private life and to the protection of personal data guaranteed by Articles 7 and 8 of the Charter of Fundamental Rights of the European Union,

whereby such processing must be limited to what is strictly necessary

to achieve that legitimate interest. - 13 -

The requirement of necessity for data processing must be examined

together with the principle of data minimization, which is enshrined in Article 5(1)(c) GDPR and requires that personal data

be adequate, relevant, and limited to what is necessary for the purposes of the processing (ECJ, Judgment of 9 January 2025

- C-394/23, NJW 2025, 807, paras. 48 et seq. with further references).

24 dd) According to these principles, the transfer of personal

data can only be considered necessary if it is suitable for serving the realization of the legitimate interest. This cannot be affirmed with regard to the

disclosures at issue. For the purposes described above under

aa) and bb), data concerning receivables transmitted can only be useful

if meaningful indications of the debtor's

ability to pay or willingness to pay can be derived from them.

Such conclusions could not be drawn from the receivables data at issue.

However,

such conclusions could not be drawn from the receivables data in dispute.


25 (1) According to the findings of the

Court of Appeal, which were not challenged by the appeal, the plaintiff rejected the receivables underlying the reports from the final invoice of i.-Energie GmbH as "excessive and excessive" by letter dated

November 29, 2014 – i.e., even before the data was transmitted to
SCHUFA – and requested

a "corrected invoice". He thus asserted a legitimate reason – from his

perspective – for not paying the final invoice.

The defendant has not provided a plausible explanation that the asserted claim existed in the amount reported

contrary to the plaintiff's assertion.

The Court of Appeals found it plausible only


that the plaintiff was in arrears with his advance payments. - 14 -

However, advance payments were not claimed in the final invoice.

Regarding the principal claim for

the electricity deliveries stated in the final invoice, the Court of Appeals explained that the invoice

was not based on the actual consumption of 1,306.8 kWh, but rather on a value of

1,543.86 kWh, possibly due to a flat-rate

agreement. Despite discussion during the oral proceedings, the parties did not present any further arguments on this point.

Furthermore, the Court of Appeals found that the

final invoice contained various ancillary claims, not readily understandable and

not further explained by the defendant, for

"damages for non-performance," reminder and transfer fees, and two different

amounts of "default costs," some of which were offset against the advance payments made by the plaintiff.

The grounds for appeal do not raise any procedural objections in this respect.

In particular, they do not claim that the Court of Appeals

imposed excessive requirements for the substantiation of the claims

and therefore disregarded the defendant's offers of proof regarding their validity.
... 26 (2) The data transfers in dispute thus concerned a

untitled, contested, and not even plausible claim in its entirety

and were therefore not suitable for enabling an objective and reliable

assessment of the creditworthiness of the potential customers of the credit agency's contractual

partner. Consequently, all further

objections raised by the Court of Appeal and challenged by the appellant regarding the legality of the disputed entries are no longer decisive.


27 3. Due to the unlawful transfer of his

personal data, which, according to the unchallenged findings of the Court of Appeal,

remains stored at SCHUFA, the plaintiff is entitled to the asserted

claim for the removal of the disputed entries from SCHUFA.




the consequences of the unlawful transfer of his personal data, which, according to the unchallenged findings of the Court of Appeal,

remains stored at SCHUFA,

the plaintiff is entitled to the asserted claim for the removal of the disputed entries.


28 a) Such a claim could already arise from the provisions of the

General Data Protection Regulation (GDPR). In this respect, Article

19, first sentence, GDPR could serve as a point of reference, according to which a controller has the obligation

to notify all recipients to whom personal data have been disclosed of any rectification or erasure of such data or restriction of processing carried out in accordance with Articles 16, 17(1), or 18 GDPR, unless

this proves impossible or involves a disproportionate effort (so-called obligation to provide further notification; see, for the definition, Kamann/Braun in

Ehmann/Selmayer, Datenschutz-Grundverordnung [General Data Protection Regulation], 3rd ed., GDPR Art. 19, paras. 1-3; Dix in Simitis/Hornung/Spiecker gen. Döhmann, Datenschutzrecht [Data Protection Law],

2nd ed., GDPR Art. 19, para. 7; each with further references). The obligation under Article 19, first sentence, of the GDPR

corresponds to a directly applicable right under EU law of the

data subject to notification (Kamann/Braun in Ehmann/Selmayer, loc. cit.

para. 17). Furthermore, the Court has ruled that, in the event that a data subject

withdraws their consent to data processing vis-à-vis a controller,

the controller, in view of their obligations

under Article 5(1)(a), (2), Article 24(1) and Article 19, first sentence, of the GDPR, may be obliged

to inform any person who has transmitted the data concerned to them,

as well as the person to whom they in turn transmitted the data, of the withdrawal (see CJEU, Judgment of 27 October 2022 - C-129/21, CR

2022, 811, paras. 83 et seq.).

29 b) However, it is unnecessary to decide whether the claim asserted in the present case against the

defendant as the controller responsible for the unlawful data processing,

for the revocation of the notifications, can be based on a direct application of Article 19 sentence 1 in conjunction with Article 17 paragraph 1 letter d GDPR (in this direction, Stuttgart Administrative Court, BeckRS 2023, 8803 para. 22; Wiesbaden Administrative Court, ZD

2022, 247 paras. 54, 56) or whether it arises from a corresponding application of

Article 19 sentence 1 GDPR in conjunction with the accountability and compliance

obligations (Article 24 paragraph 1 and Article 5 paragraph 1 letter a, paragraph 2 GDPR) of the defendant.

For if such a claim for redress could not be derived from the

General Data Protection Regulation (GDPR) itself, it would have to be recognized under national

law by analogy to Section 1004 Paragraph 1 Sentence 1, Section 823 Paragraph 1

German Civil Code (BGB) in conjunction with Article 1 Paragraph 1, Article 2 Paragraph 1 of the German Basic Law (GG) due to the violation of the plaintiff's general right of personality,

in its manifestation as the right to informational self-determination, caused by the unlawful

data processing. Whether, in addition, Section 1004 Paragraph 1 Sentence 1 by analogy, Section 823 Paragraph 2 of the German Civil Code (BGB) in conjunction with Article 6 of the GDPR could also be considered as a legal basis for a claim

can remain undecided here.




30 aa) According to the case law of the Federal Court of Justice (BGH) concerning the legal situation before the General Data Protection Regulation (GDPR) came into force,

a data subject whose data was not covered by data protection law (at that time Section 24 of the Federal Data Protection Act (BDSG aF))

has a right to have the data subject withdrawn from the unlawfully transmitted

data by the transmitting entity due to the violation of their general

right of personality, at least if the data recipient has not yet deleted the data or has not yet been legally ordered to delete it.

(cf. BGH, Judgment of July 7, 1983 - III ZR 159/82, NJW 1984, 436). In the case of a

data transfer not covered by Article 6 GDPR, nothing else can apply.

31 bb) Derivation of the claim from national law would be permissible under EU law in the

case where the General Data Protection Regulation does not provide a person affected by an unlawful data transfer with a right to have the consequences remedied.

- 17 -

32 The Court has already ruled that the General Data Protection Regulation (GDPR) does not contain any provisions that expressly or implicitly provide

that a data subject has a right to bring an action to preventive legal action

compulsing the controller of personal data to refrain from any future infringement

of the provisions of this Regulation, in particular in the form of repeating unlawful

processing (CJEU, Judgment of 4 September 2025

- C-655/23, NJW 2025, 3137, para. 43). Nor does any of the provisions
of Chapter VIII of the GDPR oblige Member States to provide for such a preventive legal remedy (ibid., para. 45). However, it should be assumed that the Member States

are not prevented from providing for such a preventive remedy with the aim of requiring the controller to refrain from any further infringement

of these rights (ibid., paras. 46-52, referring to CJEU, judgment of 4 October 2024 - C-21/23, NJW 2025, 33, paras. 59 et seq.). The General Data Protection Regulation (GDPR), as is evident from its recital 10,

aims, among other things, to ensure a consistent and high level of data protection for

natural persons when their personal data is processed.

Furthermore, Recital 11 of this Regulation states,

in particular, that effective protection of this data requires strengthening the rights of
data subjects and tightening the obligations for those

who process and decide on personal data.

The possibility for the data subject to bring an action against the controller

for an injunction against future infringements of the substantive provisions of the General Data Protection Regulation does not impair these

objectives, but rather can enhance the practical effectiveness of these provisions and thus improve the high level of protection for data subjects with regard to the processing of their personal data sought by this Regulation (ECJ, Judgment of 4 September 2025

- C-655/23, NJW 2025, 3137, paras. 49 et seq.).

33 These considerations also apply to claims for injunctive relief, which grant the

data subject the right to take action against an infringement of their general

right of personality resulting from the continued effect of an unlawful

transfer of their personal data by the controller.

Such claims are also suitable for strengthening the practical effectiveness

of the provisions of the General Data Protection Regulation, in particular the
controller's obligations to process data only under the conditions set out in Article 6 GDPR,

and for improving the high level of protection sought by the Regulation with regard to the processing of personal

data. Member States are therefore not precluded under Union law

from extending the legal remedies available to the data subject by granting

a right to injunctive relief under national law.

III.


34 The applicant's admissible cross-appeal is successful. The dismissal

of his claim for compensation for non-material damage by the Court of Appeal

does not withstand legal review.

35 1. According to Article 82(1) GDPR, any person who has suffered material or non-material damage as a result of an infringement

of the Regulation has the right to compensation from the controller. The defendant

is guilty of such an infringement. As explained in section II,

it transmitted the plaintiff's personal data to SCHUFA without being authorized to do so.
... 37 a) In the absence of a reference in Article 82(1) GDPR to the national law of the Member States,

the concept of "non-material damage" must be defined autonomously under EU law within the meaning of that provision (established case law,

see, for example, CJEU, Judgment of 4 September 2025 - C-655/23, NJW 2025, 3137, para. 55; Federal Court of Justice judgments of 11 November 2025 - VI ZR 396/24, GRUR 2026, 95, para. 25; of 18 November 2024 - VI ZR 10/24, BGHZ 242, 180, para. 28; each with further references; Federal Court of Justice judgment of 18 December 2025 - I ZR 97/25). NJW 2026, 845 para. 56).

According to Recital 146, sentence 3 of the GDPR, the concept of damage should be

interpreted broadly, in a manner that fully complies with the objectives of this Regulation.

The mere violation of the provisions of the

General Data Protection Regulation (GDPR) is, according to the case law of the Court of Justice of the European Union (CJEU), not sufficient to establish a claim for damages; rather,

in addition, as an independent prerequisite for a claim,

the occurrence of damage (as a result of this violation) is required (established case law,

see CJEU, Judgment of 4 September 2025 - C-655/23, NJW 2025, 3137 para. 56;

Federal Court of Justice judgments of 11 November 2025 - VI ZR 396/24, GRUR 2026, 95 para. 25;

of 18 November 2024 - VI ZR 10/24, BGHZ 242, 180 para. 28; each with further references;

Federal Court of Justice, Judgment of 18 December 2025 - I ZR 97/25, NJW 2026, 845 Rn. 56).


38 The Court further held that Article 82(1) GDPR precludes

national legislation or practice which makes compensation for non-material

damage within the meaning of that provision conditional on the

damage suffered by the data subject reaching a certain degree of severity or seriousness (CJEU, judgments of 4 September 2025

- C-655/23, NJW 2025, 3137, paragraph 58; of 20 June 2024 - C-590/22, DB 2024, - 20 -

1676, paragraph 26; of 11 April 2024 - C-741/21, NJW 2024, 1561, paragraph 36; of 4 May

2023 - C-300/21, VersR 2023, 920 para. 51). However, the Court also

declared that, pursuant to Article 82(1) GDPR, this person is obliged to

demonstrate that they have actually suffered material or non-material damage. The rejection of a materiality threshold does not mean that a

person affected by a breach of the General Data Protection Regulation (GDPR)

that has had adverse consequences for them would be exempt from proving

that these consequences constitute non-material damage within the meaning of Article 82 of that Regulation (see CJEU, judgments of 4 October 2024 - C-200/23, DB

2024, 2952, para. 142; of 20 June 2024 - C-590/22, DB 2024, 1676, para. 27; of

11 April 2024 - C-741/21, NJW 2024, 1561, para. 36).

39 b) Accordingly, the plaintiff suffered non-material damage due to the impairment

of his economic reputation (Recitals 75 and 85 GDPR).

According to the unchallenged

findings of the Court of Appeal, the entries in dispute impaired the credit score determined by SCHUFA for the plaintiff.

This credit score could be obtained from SCHUFA by the plaintiff's potential contractual partners and, according to further

findings of the Court of Appeal, which the defendant did not challenge,

was actually taken into account by the plaintiff's potential contractual partners in the course of several failed contract negotiations. It is therefore already established

that the defendant's reports at issue have impaired the plaintiff's creditworthiness

and thus its economic reputation in a manner that justifies a claim for damages

under Article 82(1) GDPR

(see Federal Court of Justice judgments of May 13, 2025 - VI ZR 67/23, CR 2025, 505, para. 16 et seq.; of

January 28, 2025 - VI ZR 183/22, NJW 2025, 1059, para. 12; see also Federal Court of Justice judgment

of December 18, 2025 - I ZR 97/25, juris, para. 59). Contrary to what the Court of Appeal

apparently believes, the lack of a materiality threshold

does not require that the low credit score and the resulting concerns of the plaintiff's potential contractual partners were solely or primarily based on the defendant's reports. Whether this was the case can only be relevant

for the amount of damages to which the plaintiff is entitled.


40 c) The reasoning with which the Court of Appeal denied the plaintiff's non-material

damage due to a loss of control over his personal

data is also legally flawed.


41 The Court of Appeal found that the entry concerning the disputed debt data at the SCHUFA level had already been transmitted to various

potential contractual partners of the plaintiff and could continue to be transmitted.


However, it argues that no damage occurred

because, in the case at hand, the data did not reach an unidentifiable and barely

definable group of unauthorized persons, and the data subject did not suffer

a loss of control in the sense of helplessness or being "observed,"

the recipient of the data was known, and the conditions

under which SCHUFA provides information are clearly regulated.



42 For the affirmation of the occurrence of non-material damage within the meaning of

Article 82(1) GDPR on the grounds of loss of control, it is sufficient

that the defendant transmitted the plaintiff's personal data to a third party (SCHUFA)

and that this has led to the risk of further data transmissions to

an indefinite number of third parties – here through potential SCHUFA inquiries (see Federal Court of Justice judgments of May 13, 2025 – VI ZR 67/23, CR 2025, 505

para. 19; of January 28, 2025 – VI ZR 183/22, NJW 2025, 1059 para. 12). By

providing the personal data or the score value influenced by it,

by SCHUFA for querying by third parties, the data unlawfully transmitted by - 22 -

the defendant has already been misused,

so that the question, which the defendant considers still requiring clarification,

as to whether, according to the case law of the Court of Justice, even a consequence-free, "mere" loss of control constitutes non-material damage within the meaning of Art. 82

para. 1 GDPR (cf. most recently the Senate judgment of November 11, 2025

- VI ZR 396/24, GRUR 2026, 95 para. 27 et seq.), does not arise here. Furthermore,

SCHUFA inquiries concerning the plaintiff have already been made in the present case. A

feeling of helplessness or of being "watched" on the part of the plaintiff

is not required for the determination of such non-material damage;

particular fears or anxieties of the affected person would merely

be suitable to further deepen or increase the non-material damage already incurred (cf. Federal Court of Justice judgments of November 11, 2025 - VI ZR 396/24, GRUR

2026, 95 para. 33; of November 18, 2024 - VI ZR 10/24, BGHZ 242, 180 para. 31).

43 d) Contrary to the opinion of the Court of Appeal, a claim for

damages under Article 82(1) GDPR cannot be denied on the grounds that the mere finding of unlawfulness or the judgment ordering the removal of the entry to

SCHUFA is sufficient to guarantee comprehensive legal protection because

it also has a compensatory character. According to the case law of the Court of Justice, the claim for damages under Article 82(1) GDPR serves (solely)

to compensate for the damage suffered. Compensation based on Article 82 GDPR

must be "complete and effective," meaning it must enable

full compensation for the specific

damage suffered as a result of the breach of the General Data Protection Regulation (see ECJ, Judgment of

September 4, 2025 - C-655/23, NJW 2025, 3137, para. 78; Senate Judgment of

January 28, 2025 - VI ZR 183/22, NJW 2025, 1059, para. 11; each with further references). However, as

compensation for the non-material damage already suffered by the plaintiff, - 23 -

the mere order requiring the defendant to revoke the negative entry with

SCHUFA is not suitable.

IV.

44 The defendant's appeal was therefore to be dismissed (§ 561 German Code of Civil Procedure). On

the cross-appeal, the judgment of the court of appeal was to be set aside insofar as it was detrimental to the plaintiff (§ 562 para. 1 of the German Code of Civil Procedure). The case was to be remanded to the court of appeal for a new hearing

and decision, including on the costs of the third instance (§ 563 para. 1 sentence 1 of the German Code of Civil Procedure).

Seiters Klein Allgayer

Böhm Linder

Lower Courts:

Kiel Regional Court, decision of January 9, 2024 - 17 O 130/23 -

Schleswig Higher Regional Court, decision of November 22, 2024 - 17 U 2/24 - - 24 -

Announced on:

May 12, 2026

Pasternak, Court Clerk
as Registrar of the Court