LG Leipzig - 05 O 2351/23

From GDPRhub
LG Leipzig - 05 O 2351/23
Court: LG Leipzig (Germany)
Jurisdiction: Germany
Relevant Law: Article 4(7) GDPR
Article 5(1) GDPR
Article 6(1) GDPR
Article 82 GDPR
Decided: 04.07.2025
Published:
Parties: Data Subject versus Social Media Platform Operator
National Case Number/Name: 05 O 2351/23
European Case Law Identifier:
Appeal from:
Appeal to: Unknown
Original Language(s): German
Original Source: Rewis (in German)
Initial Contributor: Shravan

A court held that a social media platform unlawfully collects unlimited data about its users from third party websites and apps through its third-party tracking tools. The court ordered it to pay €5,000 in non-material damages to a data subject for the mere loss of control of their data.

English Summary

Facts

The data subject is a user of a well known social media platform (the controller).

The controller also offers various Business Tools that can generate advertising revenue for website operators and app developers and are integrated by them on their websites and mobile applications.

The data subject filed a case before the court of first instance (Regional Court of Leipzig-LG Leipzig) alleging that the controller is unlawfully processing his personal data by tracking him through the Business Tools embedded on third-party websites and mobile apps (specifically the Pixel and Conversions API) on numerous major news sites and apps. These Business Tools collect and transmit data such as IP addresses, user-agents, device characteristics, click IDs, referrer URLs, and fingerprinting information to the controller, even when the user is not logged in to the controller's platforms. The Business Tools process personal data indiscriminately, because they don't have a built-in option to decide which data is processed and which is not, therefore processing all data, including about health, political views, ideology, finances and sexuality. The tracking bypasses browser-level protections and can even collect data from users who do not consent to the use of their data. As a result, the data subject maintains that the controller can recognise every individual user at all times as they surf the internet or use an app, through a method called 'digital fingerprinting'. Only after the data has been sent to the controller's servers does the controller evaluate if it has the legal authorisation to further process the data. The controller then sends the data collected to third countries and in particular the USA.

The data subject claimed that he never provided his consent for processing of his personal data obtained via the Business Tools and he has suffered loss of control over his data, since he has visited websites in which the business tools where installed.

The data subject requested the court to issue a declaratory judgement, order the controller delete his data and to pay him immaterial damages in the amount of €5,000.

The controller, without denying the tracking through the Business Tools, first claimed that the collection of data on third-party websites and apps is lawful and does not require a legal basis because it is not himself a controller. It merely made the tools available to third-party site owners, who were responsible for obtaining consent. Second, in the opinion of the controller, the data subject is only objecting to data processing for the purpose of providing personalised advertising, for which it always relies on effective consent. In this case data subject had not provided consent and personal advertising did not take place. Any other data processing carried out was justified for security and integrity purposes. Lastly, the controller claimed that the data subject did not sufficiently specify which specific processing purposes he wishes to challenge.

Holding

The court held that the controller acted as a controller under Article 4(7) GDPR with respect to data collected via its Business Tools embedded on third-party websites. It found that the decisive factor is that the data collected is shared with the controller for a specific purpose, the personalisation of the user experience, thus to a renewed use of the data by the controller. Therefore it could not shift responsibility to third-party operators.

The court granted the request for a declaratory judgement. It is undisputed that the data collection and processing within the Business Tools and the forwarding of the data to the controller is practiced in any case. The court held that the user agreement between the controller and the data subject does not permit the processing of personal data listed by the data subject[1]. The controller cannot rely on consent, since the data subject had not given such consent in the profile settings of his account Article 6(1)(a) GDPR, neither on any other grounds of Article 6 or Article 9 GDPR, since they were not sufficiently presented. Furthermore, the controller violated the principle of accountability Article 5(2) GDPR for failing to prove that the data was processed in compliance with Article 5(1)(a) GDPR and the principle of data minimisation Article 5(1)(c) GDPR.

The court granted an injunctive relief under Article 17 GDPR in conjunction with Article 79 GDPR because it found the risk of repetition of the unlawful processing of personal data. The data subject's complete submission on the controller's actions with regard to the collection and processing of personal data through the Business Tools must be taken as undisputed in the judgment since the controller's submission is limited to the fact that it does not process data for the purpose of providing personalised advertising in the absence of the data subject's consent. The court also found that the data subject did not have to state the specific purpose of the data processing it wishes to challenge when establishing the facts in dispute.

As a result, the court awarded the data subject €5,000 in non-material damages under Article 82 GDPR for loss of control over his personal data. The processing of personal data in the present case is particularly extensive, concerning potentially unlimited amounts of data and resulting in almost complete monitoring of the user's online behavior. It is already possible in the abstract, that the user has the feeling of being continuously monitored. Therefore, in this case there was no need for the court to hear the justification of fears and anxieties from the data subject, as he can in any case rely on the minimum impairment of the average person concerned within the meaning of the GDPR resulting from the above-mentioned scope of damage and the court can estimate the resulting degree of individual concern. The reason for this is that since the data subject cannot determine what the defendant actually intends to do with the data or what it is already doing, since this is not known precisely, the data subject's expectation or fear cannot be concretised to a specific behavior. The court held that this cannot and must not be to his disadvantage.

For the calculation of the awarded compensation the court took into consideration the scope and extend of the data collected, the duration of the infringement and the value of the personal data for the controller on the relevant market. The court points out that this case differs significantly from the so-called scraping cases, in which a minimum damage of €100 is considered appropriate for the mere loss of control, because the quantity and quality of data at issue is many times greater, so that the minimum damage must be classifies as much higher.

Comment

This is a landmark decision in German case law about the practices followed by Meta, affirming that platform operators remain controllers under the GDPR when deploying tracking tools like pixels and server-side APIs on third-party websites. The court rejected attempts to shift responsibility to external site operators and took a strict stance on consent, explicitly excluding legitimate interest as a lawful basis for opaque, persistent tracking.

The ruling aligns with the CJEU’s Fashion ID judgment (C‑40/17), which established joint controllership for embedded third-party trackers, and follows German case law such as OLG Hamm, 12 U 98/23, where Meta was held liable for unlawful use of the Meta Pixel, and LG Heidelberg, 2 O 4/23, which addressed improper use of Google Analytics.

By recognising the loss of control over personal data as non-material harm under Article 82 GDPR, the court added to the growing line of decisions awarding damages for covert profiling. It is important in this case to highlight that the mere loss of control was deemed enough to justify non material damages.

Notably, the injunction backed by enforceable penalties shows that courts are increasingly prepared to demand real technical restraint, and not just visible consent banners, particularly in cases involving fingerprinting, profiling, or hard-to-detect server-side collection.

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the German original. Please refer to the German original for more details.

Subject
5,000 euros in damages for processing of personal data on third-party websites.

Tenor
It is established that the user agreement between the parties for the use of the network "A" under the email address "..." does not permit the processing of personal data to the following extent since 25 May 2018:
personal data of the plaintiff arising on third-party websites and apps, whether transmitted directly or in hashed form, i.e.
Email of the claimant
Telephone number of the claimant
First name of the claimant
Surname of the claimant
Date of birth of the claimant
Gender of the claimant
Place of the claimant
External lDs of other advertisers (called "external_lD" by C. Ltd.)
IP address of the client
User agent of the client (i.e. collected browser information)
internal click ID of C. Ltd.
internal browser ID of C. Ltd.
Subscription ID
Lead ID
anon_id
and the following personal data of the complaining party
on websites
the URLs of the websites and their subpages
the time of the visit
the "referrer" (the website from which the user came to the current website)
the buttons clicked by the plaintiff on the website and
other data mentioned by "C. Events" that document the interactions of the plaintiff on the respective website
in third-party mobile apps
the name of the app and the time of the visit
the buttons clicked by the plaintiff in the app, and
the data referred to by C. as "events", which document the interactions of the plaintiff in the respective app.
The defendant is ordered to refrain from processing personal data on third-party websites and apps outside the defendant's networks in accordance with the request under 1. above, subject to a fine of up to EUR 250,000.00 to be imposed by the court for each case of infringement, or, alternatively, imprisonment of up to six months to be enforced on its legal representative, or up to two years in the event of a repeat offence.
The defendant is ordered to pay the plaintiff compensation in the amount of EUR 5,000.00 plus interest thereon at five percentage points above the respective basic rate of interest since 1 September 2023.
The defendant is ordered to indemnify the plaintiff against pre-trial legal fees in the amount of EUR 540.50.
The remainder of the action is dismissed
The defendant shall bear the costs of the legal dispute
The judgement is provisionally enforceable against security in the amount of EUR 20,000.
Decision:
The value in dispute is set at a total of EUR 14,000

Facts of the case
1
In connection with the use of so-called business tools, the plaintiff seeks injunctive relief and monetary compensation from the defendant in addition to a declaration of unlawful data processing due to alleged unlawful processing of personal data.

2
The defendant operates the social networks "B." and "A.", among others. The defendant developed various business tools that can generate advertising revenue for website operators and app developers and are therefore integrated by them on their websites and in their apps.

3
The plaintiff has been using the A. network exclusively privately under the email address "..." since [...].2013. The plaintiff did not consent to the processing of personal data for the purpose of providing personalised advertising via the setting "Information from advertising partners about your activities".

4
The defendant does not demand any money in return for the use of the network. The social network is largely financed by online advertising. When using the network, the plaintiff is shown adverts based on their interests, which the defendant's algorithms have analysed. Since November 2023, users have been able to choose a subscription model in which they can switch off the display of adverts by paying a monthly fee.

5
The setting "Your activities outside the C. Technologies" allows users to control and retrieve a summary of the information associated with their accounts about the user's activities on apps and/or websites that have been shared with the defendant by third-party companies for advertising purposes ("Activity information shared by third-party companies"). In addition to the possibility for users to retrieve a summary of their "Recent Activities" via the setting "Your activities outside of C. Technologies", users can have the information on activities shared by third-party companies for advertising purposes separated from the respective A. account with regard to the display of personalised advertising and/or switch off the future links between the A. account and the information on activities shared by third-party companies with regard to the display of personalised advertising.

6
According to the contract terms it uses, the defendant holds the right to analyse the behaviour of its users not only when they use its own products and services, but also on a large number of websites and apps. The creation of an account in the defendant's network requires that the user agrees to the terms of use (current version dated 7 September 2023, Annex K 1). These stipulate, among other things, that the plaintiff makes the data collected by the defendant, including data resulting from the use of other group-owned services and other internet activities of the user outside the defendant's networks, available to the defendant for the presentation of "personalised experiences" and for "other purposes". Other purposes are listed in the terms of use (Annex K3, p. 96 et seq.): "In response to a legal request", "To comply with applicable laws", "For purposes of protection, security and integrity", "For legal disputes". The Terms of Use refer to the Defendant's Data Policy, which explains, inter alia, that the information and devices provided by the user will be collected and interconnected for all of the Defendant's products used, including the information of the Defendant's partners sent via the Business Tools. A cookie policy, which in turn is referenced in the Data Policy, contains the reference that the Defendant may place page-related text information (cookies) on the user's device and thus obtain information that is stored there when the user accesses the Defendant's applications or websites of other companies that use the Defendant's Business Tools, without any further action by the user being required. The defendant shares the plaintiff's "information" with advertisers and "audience network publishers", partners who use the defendant's "analytics services", "integrated" partners, measurement solution providers, marketing solution providers, various "service providers" and "external researchers".

7
The integration of the disputed business tools apps and websites of third-party companies is done by inserting a simple script in the code of the websites and apps ("C. Pixel" for websites and "App Events via A.-SDK" for apps), which is not noticed by the technically average user, and since 2021 optionally by integrating a script on the servers of the website and app operators ("Conversions APl" and "App Events APl"), whereby the collection of data is no longer carried out on the user's computer. This is also not noticed by the technically savvy user and can no longer be prevented. On numerous high-reach websites and apps in Germany, "C. Pixel" or "App Events via A.SDK" are running in the background, including on numerous major news sites and apps (e.g. spiegel.de, bild.de, welt.de, faz.net, stern.de), major travel sites and apps (e.g. tripadvisor.de, hrs.de, holidaycheck.de, kayak.de, momondo.de), sites and apps that offer medical help (e.g. apotheken.de, shopapotheke. de, docmorris.de, aerzte.de, helios-gesundheit.de, jameda.de), dating and erotic sites (parship.de, amorelie.de, orion.de, lovescout24.de), as well as sites with content from the innermost intimate sphere (krebshilfe.de, tfp-fertility.com (sperm bank), nie-wiederalkohol. de, nvve.nl (euthanasia; see the list of the plaintiffs' representatives' research in the attachment "List_C._Pixel_on_sensitive_websites" and attachment "List_of_most_visited_websites_C._Pixel"). The business tools there process personal and highly personal data relating to health, political views, ideology, finances and sexuality.

8
Every user is individually recognisable at all times as soon as they access the internet or use an app, even if they are not logged in to the defendant's networks or have installed their apps. This recognition is achieved through so-called "digital fingerprinting", through which a user can be permanently traced online. On the other hand, every single click and every text entry on such third-party websites and apps can be tracked by the defendant. The defendant knows which pages and subpages were visited and when, and what was clicked on, searched for or purchased there (cf. examples of the pages niewiederalkohol.de, shop-apotheke.com, medikamente-per-klick.de, jameda.de, amorelie.de, statement of claim pp. 9-11, pp. 9-11 of the file). file). The defendant sends the data collected worldwide to third countries, in particular the USA, and passes it on to third parties and authorities as required.

9
The defendant carries out "digital fingerprinting" using the user's personal data listed in the application under 1. All this data is assigned to the individual C.-lD as part of "Advanced Matching" and is linked to the location data of the mobile device, used and thus fully individualised. Due to the fingerprinting, the assignment of a technical device to the user works with an accuracy of over 99% even if the user does not use his account with the defendant or is not logged in and does not allow its cookies. Accordingly, all data is also collected when users are not logged in to their networks. Since the providers of the most important browsers (Apple Safari, Mozilla Firefox, Google Chrome) have been gradually preventing the setting of cookies by third-party providers since 2019 and the execution of script applications has also been made more difficult, at least in incognito mode, the defendant introduced the "Conversions APl" and the "App Events APl" in 2021. According to the undisputed statement of claim, their sole purpose is to circumvent all attempts at protection by users and browser manufacturers with the cooperation of website operators and app providers and to continue to enable data collection - in this case not even noticeable to the technically savvy user - even if the user uses incognito mode and does not allow cookies from third-party sites and even if they use a VPN (virtual private network). Users who have logged on to the defendant's networks at some point in their lives can be assigned to them and linked to all other aggregated data. This is possible because the Conversions API can be connected to the website operator's server and the data required for fingerprinting as well as "analogue" personal data such as the user's name or address can be provided from there in hashed form without the user being able to trace or even prevent this. Figuratively speaking, hash values are the "fingerprints of files". The defendant's business tools record the data of all users indiscriminately, because the business tools have no built-in option to decide which data is processed and which is not.

10
All data is then sent to the defendant's servers. Only there does the defendant evaluate whether it has the legal authorisation to further process the - already processed - data. A "digital fingerprint" is a combination of such a quantity of data that can be retrieved in the browser (so-called "browser fingerprint") or from the user device (so-called "device fingerprint"), which makes it possible to identify the respective user solely on the basis of this data. According to the Bundeskartellamt's findings, such an assignment is possible in over 99.24% of all cases (see BKartA, decision of 6 February 2019, ref. B;6-22116, para. 580, BeckRS 2019, 4895; list of identification parameters at C. Pixel, Annex "Parameter-Kundeninfo"). The defendant can then use this personal data to link the browser, which has already been identified as unique, with absolute certainty to the actual person in front of the computer (advanced matching). Even if no cookies are set, the business tools transfer all the personal data mentioned in request 1 that could be collected to the defendant. The defendant can use all techniques -- i.e. Third party cookies, first party cookies to aggregate data over a long period of time without immediate assignment to the user, but to the browser used by the user, first party cookies in combination with the click-lD to assign the aggregated data to the user, Digital fingerprinting for aggregating data over a long period of time without immediate assignment to the user via data from the "HTTP header" and IP address as well as digital fingerprinting if user data is available - for assigning the aggregated data to the user and thus, for example, assigning the data aggregated over a long period of time via the first party cookie about activities on third-party sites to a unique user through the unique identification by digital fingerprinting. The defendant refers to user actions that it can record as "events". This can be, for example, calling up a page ("PageView"), sending a search command ("Search"), filling out a form ("Lead"), placing an item in the shopping basket ("AddToCart") or purchasing an item ("Purchase"). The defendant's business tools automatically search the websites and apps on which they are activated for corresponding events and change their code so that the use of the corresponding buttons or keystrokes are sent to the defendant each time they are used.

11
In order to obtain as comprehensive a data set as possible, the defendant encourages website operators to send it as much information as possible from website visitors. The website operators also have an interest in sending the defendant all available information about the respective users. This is because the more data the defendant has at its disposal, the more successful customer acquisition will be. The defendant aggressively advertises its business model to third parties (Annex "Parameter_Kundeninfo"). The Conversions API fulfils the same function as C. Pixel and, according to the plaintiff, represents the defendant's reaction to the GDPR and the increasing sensitivity of users. The defendant actively advertises the Conversions API to be used by website operators to collect and send data to the defendant from those users who do not consent to the use of their data (Annex C._Playbook, in particular p. 23). Since it does not have to be loaded into the user's browser, the user cannot switch it off. Neither an "incognito mode" nor anti-spy software or a VPN help here (Annex "Anlagenkonvolut_Conversions_APl"). The defendant also uses the corresponding systems for users who have not activated the buttons "Allow optional cookies" and "Information about activities of advertising partners" (cf. example of use of spiegel.de, replica p. 25 to 33).

12
The processed information is forwarded by the business tools directly to the defendant's servers from the time of their installation by the respective website operator. This is followed by further processing operations on the server side, such as storage, comparison with the data records stored with the defendant for clear assignment, modification by pseudonymisation if necessary and further use. The defendant only now determines whether the information collected and forwarded can now be assigned to a user who has consented to this type of processing as part of a comparison and then decides to pseudonymise the data and use it further for "limited purposes". It is clear from the defendant's general terms and conditions that the defendant also uses the personality profile created for this purpose for non-advertising purposes. With regard to the further technical details of the defendant's data collection and processing, for example "third party cookies", in particular the defendant's "user login cookie", "first party cookies", in particular "_fbp" and "_fbc" of the defendant, which contain internal browser LDs and internal click LDs generated by the business tools, "click LD" as well as the digital fingerprint via "automated advanced matching" and "manual advanced matching", reference is made to the explanations in the reply of 5 September 2024, pages 1 to 2.09.2024, pages 12 to 35.

13
In May 2023, the Irish data protection authority DPC imposed a fine of EUR 1.2 billion for the unauthorised transfer of data of the defendant's European users to the USA.

14
In the lawyer's letter of 3 August 2023 submitted as Annex K 3, the plaintiff asserted claims for information pursuant to Art. 15 GDPR, erasure pursuant to Art. 17 GDPR and damages against the defendant before the court, setting a deadline of 31 August 2023. Please refer to Annex K3 for further details. No payment was made by the defendant.

15
The plaintiff claims that he visited websites on which the business tools at issue were installed. As a result of the associated processing of personal data, he has suffered a loss of control over this data. He felt uncomfortable, overprotected and restricted. He was not aware of the full extent of the defendant's espionage and feared that the data would be misused. He feels that his privacy has been violated, in particular because he has not given his consent to this. The plaintiff believes that the processing of personal data obtained via the "C. Business Tools" by the defendant is unlawful and, in particular, not covered by consent. According to the case law of the ECJ, by integrating the business tools on third-party websites, the defendant becomes the "controller" within the meaning of the GDPR for all websites and apps on which its code runs. The plaintiff is of the opinion that the claim for damages to which he is entitled should be quantified at a minimum of EUR 5,000.

16
In the reply dated 5 September 2024, the plaintiff amended the original claims from the statement of claim under no. 1 and 2. In addition, the plaintiff had previously applied in the alternative by way of a step-by-step action to order the defendant to provide information about the personal data processed by it, to erase it after the information has been provided and to pay damages due to the processing of the information provided, in the event that the application under no. 1 is not granted. Finally, in the alternative, the plaintiff requested that the defendant be ordered to delete or anonymise all of the data referred to in request no. 1 in the event that the request under no. 1 and 3 is granted. 1 is granted.

17
Finally, the plaintiff applies:

It is established that the user agreement between the parties for the use of the network "A." under the email address "..." does not permit the processing of personal data to the following extent since 25 May 2018:
personal data of the Claimant arising on third-party websites and apps, whether transmitted directly or in hashed form, i.e.
Email of the claimant
Telephone number of the claimant
First name of the claimant
Surname of the claimant
Date of birth of the claimant
Gender of the claimant
Place of the claimant
External lDs of other advertisers (called "external_lD" by C. Ltd.)
lP address of the client
User agent of the client (i.e. collected browser information)
internal click lD of C. Ltd. internal
Browser lD of C. Ltd.
Subscription ID
Lead ID
anon id
and the following personal data of the complaining party
on websites
the URLs of the websites together with their subpages the time of the visit
the "referrer" (the website from which the user came to the current website)
the buttons clicked by the plaintiff on the website and other data referred to by C. as "events" that document the interactions of the plaintiff on the respective website
The defendant is ordered to refrain from processing personal data on third-party websites and apps outside the defendant's networks in accordance with the request under 1. above, subject to a fine of up to EUR 250,000.00 to be imposed by the court for each case of infringement, or, alternatively, imprisonment of up to six months to be enforced on its legal representative, or up to two years in the event of a repeat offence.
The defendant is ordered to pay the plaintiff appropriate monetary compensation, the amount of which is at the discretion of the court, but which is at least EUR 5,000.00, plus interest at five percentage points above the basic rate of interest since 1 September 2023.
The defendant is ordered to indemnify the plaintiff for legal fees in the amount of EUR 1,054.10.
18
The defendant applies,

19
dismiss the action.

20
The defendant believes that the collection of data on third-party websites and apps is lawful. It does not require a legal basis in this respect. Rather, the operator of the third-party website or the app provider is responsible for obtaining consent from the user. The third-party companies are primarily responsible for the installation and use of the business tools, for providing information on the use of the business tools to the visitors of the respective website or app and, finally, they are responsible for creating a legal basis for the collection and transmission of data to the defendant by means of the business tools in dispute. According to para. 3d of the Business Tool Terms and Conditions, third-party companies are responsible for obtaining the consent required under the ePrivacy Directive for storing and accessing cookies or other information on an end user's device. The data processing by means of the Business Tools is also otherwise lawful and in accordance with the GDPR. In the opinion of the defendant, the plaintiff is only objecting to the processing of personal data for the purpose of providing personalised advertising. In this respect, the defendant always relies on effective consent pursuant to Art. 6 para. 1 lit. a GDPR. However, such data processing for advertising purposes did not take place here, as the plaintiff had not given such consent. Nor had the plaintiff given consent to the use of C. cookies on other websites and apps. The plaintiff had the simple option of deciding to take out the ad-free subscription. He would then no longer see any adverts at all. The other data processing carried out was justified in particular for security and integrity purposes. This is also explained by the defendant's privacy policy. Furthermore, the complaint does not sufficiently specify which specific processing purposes the plaintiff wishes to challenge. A description of the specific websites and apps visited and equipped with a business tool is missing, so that the defendant cannot adjust its procedural behaviour to this. Tools such as the business tools at issue are a natural and ubiquitous part of the internet.

21
Reference is made to the pleadings exchanged between the parties and the documents submitted for the file for further details of the facts and the dispute.

Reasons for the decision
22
The admissible action is also largely successful on the merits

23
l. The action is admissible in its entirety.

24
1. the Regional Court of Leipzig has international, factual and local jurisdiction.

25
a) The international jurisdiction of the German courts arises from Art. 79 para. 2 sentence 2 (in conjunction with Art. 82 para. 6) GDPR. Pursuant to Art. 79 para. 2 sentence 1 GDPR, the courts of the Member State in which the controller or processor has an establishment have jurisdiction for actions against a controller or processor. In addition, Art. 18 para. 1 GDPR should also establish international jurisdiction (according to OLG Dresden, judgement of 10 Dec. 10.12.2024, ref. 4 U 815/24, GRUR-RS 2024, 38639 para. 2).

26
aa) The Chamber refers comprehensively to the references of the Regional Court of Lübeck (judgement of 10 January 2025 - 15 O 269/23, GRUR-RS 2025, 81 para. 25) for the derivation of the defendant's responsibility within the meaning of the GDPR with direct reference to the platform: "The defendant is a controller or processor within the meaning of the GDPR. According to Att. 4 No. 7, 8 GDPR, controllers are natural or legal persons, public authorities, agencies or other bodies which alone or jointly with others determine the purposes and means of the processing of personal data. Processors are natural or legal persons, public authorities, agencies or other bodies which process personal data on behalf of the controller. In the present case, as the operator of the platform, the defendant alone has to decide on the purposes and means of the processing of personal data, so that it is to be regarded as a controller within the meaning of the GDPR (see CJEU, judgment of 5 June 2018 - C-210/16 -, para. 30, juris; see also below for details); it is also not an authority of a Member State that has acted in the exercise of its sovereign powers."

27
bb) According to the plaintiff's factual submission, the defendant is also a controller within the meaning of Art. 4 No. 7 GDPR for the business tools at issue.

28
In this respect, reference is made to the correct statements of the Regional Court of Stuttgart (judgement of 24 October 2024, Ref. 12 O 170/23, GRUR-RS 2024, 36702 para. 23): "The defendant itself submits that third-party companies can integrate business tools of the defendant on their website or in their app and choose to share customer data with the defendant in order to create better and more interactive content and adverts and to build an audience for advertising campaigns. It does not lead to a different conclusion that the third party companies - also - have relevant obligations towards the visitors of their website and/or app and in this respect are the relevant responsible parties for the installation and use of the business tools at issue, the disclosure of information to the visitors of their website or app in relation to the use of the C. Business Tools and the collection and transmission of the data the defendant through tools such as the business tools at issue. This may result in further data protection claims of the users of the respective sites against the respective operators. However, the decisive factor is that the data collected ultimately does not remain with the third-party companies for processing and use there, but rather is shared with the defendant for a specific purpose. Whether this data is anonymised or otherwise alienated in the process is irrelevant. As a result, the transfer leads to a personalisation of the user experience at the defendant and thus to a renewed use of the data by the defendant. The defendant is also aware of this fact, as it asks its users for corresponding consent when setting "Information about activities of advertising partners" and also offers ad-free use of the A. platform as an ad-free subscription for a fee."

29
b) The local jurisdiction arises in any case from Section 44 para. 1 sentence 2 BDSG, as the plaintiff has its habitual residence at its place of residence in Leipzig.

30
2. the contractual relationship at issue is governed by the German law chosen by the parties pursuant to Art. 3 (1), 6 (2) of Regulation (EC) No. 593/2008 of the European Parliament and of the Council of 17 June 2008 on the law applicable to contractual obligations (Rome I Regulation; OJ 2008 L 177 , 6). The applicability of the GDPR results from Art. 3 para. 1 GDPR in geographical terms and from Art. 2 para. 1 GDPR in substantive terms. According to Art. 99 para. 2 GDPR, the regulation has been directly applicable in the member states since 25 May 2018. The data processing at issue took place after this date.

31
3 Insofar as the applications from the statement of claim of 10 October 2023 were partially amended in the reply of 5 September 2024, this is admissible.

32
a) The amendment of the original claims under numbers 1 and 2 is a case of Section 264 No. 1 ZPO and therefore not a genuine amendment of the claim. A further withdrawal of the action within the meaning of Section 264 No. 2 and 269 (1) ZPO cannot be recognised here, as the motions were merely specified more precisely and there was no change to the original subject matter of the dispute (see the comments by Stein/Roth ZPO Section 264 para. 6 under the heading of an "incorrectly formulated motion", see also OLG Dresden, judgement of 1 December 2010, Ref. 1 U 475/10, NJW-RR 2011, 924, 927).

33
b) The dropping of the original alternative step claim, on the other hand, constitutes a limitation of the subject matter of the dispute pursuant to Section 264 No. 2 ZPO. As the amendment to the action was already made before the trial, the defendant's consent pursuant to Section 269 (1) ZPO was not required.

34
4. the application seeking a declaration that the parties' licence agreement does not permit the processing of the data listed is admissible.

35
a) The prerequisite for the admissibility of the action for a declaratory judgement is the existence or non-existence of a legal relationship pursuant to Section 256 (1) ZPO and a legal interest in the immediate determination of this relationship.

36
aa) A legal relationship is a legal relationship between persons derived from the facts presented, which contains a subjective right or from which such a right can arise. Only the legal relationship itself can be the subject of the determination, not preliminary questions or individual elements, but individual rights, obligations or consequences of a legal relationship as well as the content and scope of an obligation to perform (BGH, judgement of 22 January 2015, case no. Vll ZR 353/12, NJW-RR 2015, 398 para. 17). The legal relationship must be sufficiently specific in order to be able to establish clear individualisation, in particular with regard to the scope of legal force (BGH, judgement of 4 October 2000, case no. VIII ZR 289/99, NJW, 2001, 445). An action aimed at merely establishing the unlawfulness of conduct is inadmissible (BGH, judgement of 20 April 2018, case no. V ZR 106/17, NJW 2018, 3441 para. 13).

37
The legal relationship derived from the facts presented in the complaint is the relationship between the plaintiff and the defendant, which arises from the licence agreement for the use of the network "A." under the e-mail address ". In this respect, the application for a declaratory judgement extends to the question of whether the defendant is permitted to process the personal data mentioned in the application under point 1 since 25 May 2018 on the basis of the structure of this contract - in the GTC.

38
In this context, it was not necessary for the plaintiff to state which data was specifically stored. It was sufficient to use collective designations for the data categories. This follows from the fact that a more detailed determination of the individual data records of the plaintiff side was not made until the end due to the lack of submission by the defendant as part of its secondary burden of proof. Since the plaintiff himself has no insight into the data processed by the defendant, he must be permitted procedurally to limit his submission to the circumstances known to him in order to ensure effective legal protection. This requirement was sufficiently taken into account by the enumeration of the individual data categories.

39
Contrary to the view of the defendant, the legal relationship to be determined is not an abstract determination of the unlawfulness of an act (but so LG Stuttgart, judgement of 05.02.2025, Ref. 27 O 190/23, GRUR-RS 2025,920, para. 17). The application made here is not limited to merely establishing the unlawfulness of the data collection, but goes beyond this. The application seeks a declaratory judgement that the user agreement with the GTC does not permit the processing of personal data. The specific rights and obligations of the user agreement - in particular their limits under the GDPR - are thereby submitted to judicial review. The aim is to clarify the contractual permissibility of the behaviour practised by the defendant and to review the permissible processing of personal data on the basis of the user agreement. Beyond the mere determination of the invalidity of an individual GTC clause, it is to be clarified in court as a negative fact which rights of the defendant cannot - in principle - arise from the specific licence agreement, taking into account the other circumstances, in particular the lack of consent. In its case law, the BGH also assumes that the permissibility of behaviour based on a specific contract is open to review in the form of an action for a declaratory judgement (BGH, judgement of 20 February 2008, case no. VIII ZR 139/07, NJW 2008, 1303, para. 9).

40
bb) "A legal interest in the determination of the legal relationship arises if the right or legal position is threatened by a current danger or uncertainty and the judgement sought is suitable to eliminate this danger" (Thomas/Putzo/Seiler, S 256 ZPO, para. 13 with further references). Uncertainty of a factual nature exists if there is a dispute between the parties as to whether the defendant is infringing the rights of the plaintiff or is seriously contesting them (BGH, judgement of 7 February 1986, case no. V ZR 201/84, NJW 1986, 2507). The interest in a declaratory judgement ceases to exist as soon as the plaintiff has an easier way of achieving his goal. This is particularly the case if the plaintiff can bring a positive action for performance instead of a negative declaratory action (BGH, judgement of 13 December 1984, case no. I ZR 107/82, NJW 1986, 1815).

41
The plaintiff does not have to be referred to an action for performance aimed at obtaining an injunction against data processing, as the scope of his interest in legal protection, which he asserts with the declaratory action, goes beyond the injunction against data processing alone (see also Regional Court Ellwangen (Jagst), judgement of 06.12.2024, ref. 2 O 222/24, official printout, notified by the plaintiff; a.A. Regional Court Lübeck, judgement of 10.01 .2OZS, Ref. 15 O 269123, GRUR-RS 2025,81, para. 33 et seq. on the grounds that the action for a declaratory judgement is completely exhausted in the parallel claims for damages and injunctive relief). The clarification of the legal issue in dispute is also important for further subsequent claims, which are not sufficiently taken into account by the mere application for injunctive relief. In addition, the declaratory action takes into account the objective of procedural economy recognised by the case law of the BGH (see BGH, judgement of 9 November 2022, case no. Vlll Z,R272120 NJW 2023, 1567 para. 30). In this respect, a parallel can be drawn to the permissible determination of a liability for damages "on the merits" in the case of unfinished damage developments. In these cases, even the remote possibility that further consequential damage is to be expected from the same (completed) event giving rise to liability is sufficient to justify an interest in a declaratory judgement (BGH, judgement of 15 July 1997, case no. Vl ZR 184/96, NJW 1998, 160). The factual submission on probability is part of the substantive grounds for the action (Thomas/Putzo/Seiler, S 256 ZPO, para. 14). This must apply all the more in the present case, in which the behaviour giving rise to liability has not yet been completed, but is continuing, in that the data processing in dispute is still taking place. If, in an action for damages, it is permissible to seek a declaration that the defendant is obliged to compensate for all material and immaterial damages arising from a specific (accident) event, the action for a declaratory judgement in this case is the counterpart to this. When the obligation to pay damages is established, the event giving rise to liability has been completed and lies entirely in the past; in the present case, however, the damage has not yet come to an end. In this constellation, the plaintiff only has the option of establishing that the licence agreement does not permit the form of data collection that the defendant famously claims is permissible.

42
From the court's point of view, it is probable in the present case, based on the facts presented by the plaintiff, that the plaintiff is already entitled or will be entitled to further claims due to the data processing at issue. Since the plaintiff is currently unable to name all previous and future personal data breaches and their specific forms of action, if an interest in a declaratory judgement were to be rejected, he would be forced to present and, if necessary, prove the unlawfulness of the data processing again for each further claim asserted in the action that has its origin in the data processing at issue here. In this respect, he would be exposed to a considerable litigation risk. It would also mean an additional burden on the courts. This can be prevented by an anticipatory action for a declaratory judgement - and this alone. According to his factual submission, the plaintiff fears that the defendant will pass on or has already passed on the data it has collected to third parties (see only statement of claim, p. 12 f., p. 12f. of the file) and thus commit further potentially unlawful acts. The defendant has not dispelled these fears. In particular, by failing to provide a procedural explanation of the plaintiff's allegations, it has shown to the court's satisfaction that it practices a non-transparent handling of user data, even vis-à-vis the court, despite its procedural duty of truth. Finally, the plaintiff is at liberty to assert further non-material damages in the future resulting from the ongoing infringement. In this respect, the cease and desist order merely offers the possibility of being used as a basis for determining administrative remedies pursuant to S 890 ZPO. However, it is not a basis for further claims for damages and is therefore not equivalent.

43
A decision by the court in relation to the application for a declaratory judgement is suitable for eliminating the uncertainty of the parties by clarifying whether the processing of personal data is permitted on the basis of the user agreement. The decision provides the parties with a "guideline" (Thomas/PutzoiSerTer, Section 256 ZPO, para. 14) for their future behaviour. The defendant also famously defended itself to the end of the proceedings with the statement that it would not carry out the data processing as described in the application under no. l, as the plaintiff had not given his consent to the data processing. In addition, however, in contradiction to the first statement, it declares that it lawfully processes personal data that it has received from third-party companies via the business tools for other purposes (see most recent statement of 9 May 2025, p. 12 = p. 973 of the file). Accordingly, the defendant consciously or unconsciously continues the behaviour submitted by the plaintiff for legal review. In this respect, a judicial clarification is required.

44
Finally, the plaintiff also has an immediate interest in a declaratory judgement, as he wishes to continue using his account on the defendant's network. Immediate clarification of the conditions of use is relevant for further use.

45
b) The request for a declaratory judgement is sufficiently specific within the meaning of S 253 para. 2 no. 2 ZPO. Insofar as the defendant believes that the plaintiff must specifically state which third-party websites and apps use the business tools, this is not convincing. With the annex "List of frequently visited websites in Germany with C. Pixel" (p. 201 of the plaintiff's annex), the plaintiff has sufficiently demonstrated that the large number of websites regularly accessed by an unspecified Internet user use the defendant's business tools. The list of websites is a cross-section of websites from which an internet user usually accesses at least one page per day. The websites cover all categories of Internet use (news, politics, health, sexuality, religion, finance, etc.). According to general life experience, it can be assumed that internet users access websites from the list presented. If, as part of the burden of proof, the court were to require the plaintiff to disclose every website he has visited in recent years in the form of a browser history, the purpose of an action based on the violation of data protection regulations would be reduced to absurdity, since it is precisely the plaintiff's aim to prevent the collection of personal data by the defendant and thus also to keep information about his own browser history - insofar as it is only known to the defendant - secret from others.

46
Insofar as the defendant criticised the wording of the original application in the statement of claim as being too vague "in a legally compliant interpretation of the party's contract of use for the use of the network 'A.'", the application was amended accordingly with the amendment to the statement of claim in the reply of 5 September 2024, so that it was no longer necessary to decide on this.

47
4. the application for injunctive relief is also admissible. The plaintiff has no simpler means of preventing the data processing at issue. Insofar as the defendant enables the separation of the interface between the business tools and the plaintiff's user account in its settings, this is limited solely to the purposes of providing personalised advertising. The defendant's statements always refer to the "data processing in dispute", whereby, in deviation from the subject matter of the dispute determined by the court of data processing by the Business Tools, it generally limits this only to data processing for advertising purposes (see in particular the statement of defence of 23 May 2025, p. 19, p. 291 of the file). The defendant therefore speaks in this context of "information provided by advertising partners" (statement of defence of 23 May 2025, p. 22, 8.294 of the file). Furthermore, it is undisputed that data processing continues to take place permanently for integrity and security purposes. It is also undisputed that data collection and processing within the Business Tools and the forwarding of data to the defendant is practised in any case.

48
II The action is largely well-founded.

49
1. the application for a declaratory judgement is successful on the merits

50
The contract of use between the two parties does not permit the processing of personal data listed by the plaintiff since 25 May 2018. The data processing operations on which the judgement is based are not covered by the plaintiff's consent. In particular, the defendant cannot rely on consent pursuant to Art. 6 para. 1 lit. a GDPR, as the plaintiff has not given such consent in the profile settings of his account. The defendant has not sufficiently submitted any other grounds for justification pursuant to Art. 6 and 9 GDPR.

51
The defendant may not process "app, browser and device information" and "information from partners, providers and third parties" permanently and without restriction without separate consent to "fulfil a contract", to "fulfil a legal obligation", to protect "essential interests", to "safeguard public interests" or for the "legitimate interests" of the defendant.

52
As the ECJ states in its judgement of 4 July 2023 (judgement of 4 July 2023, ref. C-252/21, NJW 2023, 2997), if there is no consent within the meaning of Art. 6 para. 1 subpara. 1 letter a and Art. 9 para. 2 letter a GDPR, it must be examined whether the processing is justified in any case pursuant to Art. 6 para. 1 subpara. 1 letters b to f GDPR. According to Art. 5 GDPR, the data controller bears the burden of proof that "the data are collected, inter alia, for specified, explicit and legitimate purposes and processed lawfully, fairly and in a manner that is comprehensible to the data subject".

53
In its decision of 4 July 2023, the ECJ (loc. cit. = NJW 2023, 2997) specified the requirements for the justification of data processing in accordance with the aforementioned provisions. It states the following:

54
"4 Art. 6 I subpara. 1 lit. b of Regulation (EU) 2016/679 must be interpreted as meaning that the processing of personal data by the operator of an online social network, which consists in the collection, linking and use of data of the users of such a network, which originate from other services of the group to which this operator belongs or result from the access of third party websites or apps by these users, are collected, linked to the respective user account of the social network, can only be regarded as necessary for the performance of a contract to which the data subjects are party within the meaning of this provision if such processing is objectively necessary for the fulfilment of a purpose which is an integral part of the contractual performance intended for those users, so that the main subject matter of the contract could not be fulfilled without such processing.

55
5 Art. 6 I subpara. 1 lit. (f) of Regulation (EU) 2016/679 must be interpreted as meaning that the processing of personal data by the operator of an online social network, which consists in the collection, linking and use of the data of the users of such a network, which originate from other services of the group to which that operator belongs or result from the access to third party websites or apps by those users, can only be regarded as necessary for the purposes of the legitimate interests pursued by the controller or by a third party within the meaning of that provision, if the operator in question has provided the users from whom the data was collected with a legitimate interest in the data processing, if this processing is carried out within the limits of what is absolutely necessary to realise this legitimate interest and if a weighing of the opposing interests, taking into account all relevant circumstances, shows that the interests or fundamental rights and freedoms of these users do not override the legitimate interest of the controller or third party.

56
6. art. 6 I subpara. 1 lit. c of Regulation (EU) 2016/679 must be interpreted as meaning that the processing of personal data by the operator of an online social network, which consists in the collection, linking and use of data of the users of such a network that originate from other services of the group to which this operator belongs or result from the access of third party websites or apps by these users, is justified under this provision, is justified under this provision if it is necessary for compliance with a legal obligation to which the controller is subject under Union or Member State law this legal basis pursues an aim of public interest and is proportionate to the legitimate aim pursued and this processing is limited to what is strictly necessary.

57
(7) Article 6 I(1)(d) and (e) of Regulation (EU) 2016/679 must be interpreted as meaning that the processing of personal data by the operator of an online social network, which consists in the collection, linking and use of data of the users of such a network, which originate from other services of the group to which that operator belongs or result from the consultation of third party websites or apps by those users, is not, in principle, subject to review by the referring court, to be regarded as necessary within the meaning of point (d) in order to fulfil vital interests. d) necessary to protect the vital interests of the data subject or of another natural person or necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller within the meaning of point (e)."

58
In the decision of 4 July 2023, C-252/21, the ECJ also states (ECJ, loc. cit., NJW 2023,2997, para. 239 et seq.):

59
"Similarly, the referring court shall, in accordance with Aft. 6(1)(e) GDPR, the referring court will have to assess whether C. Platforms Ireland is entrusted with a task carried out out in the public interest or in the exercise of official authority, such as research for the benefit of society or the promotion of protection, integrity and security, although, given the nature and essentially economic and commercial character of the activity of that private operator, it seems unlikely that it has been entrusted with such a task.

60
In addition, the referring court may have to examine whether the data processing carried out by C. ptatforms lreland is carried out within the limits of what is strictly necessary, having regard to its scope and its significant impact on the users of the social network A."

61
In its pleadings, the defendant relies solely on data processing for the purpose of the security and integrity of its systems, i.e. Article 6(1)(1)(e) GDPR:

62
"C. will only use this user's information collected via cookies and similar technologies for limited purposes, such as security and integrity purposes. These security and integrity purposes include protection and harm prevention (e.g. child safety and combating potential criminal activity (including dangerous organisations) and hate speech) and combating certain known security threats, such as cyber security threats (e.g. hacking, cyber espionage). By way of illustration, C.'s systems can check whether an IP address contained in data transmitted by the C. Business Tools is congruent with one of relatively few IP addresses associated with threats identified in the past."

63
(Duplicate of 26 November 2024, p. 48, B/-522 of the file)

64
Beyond this generalised submission, the defendant does not provide any further substantiation. However, the rest of the submission is not sufficient to meet the strict requirements of the EU Court of Justice regarding Art. 6 para. 1 subpara. 1 letter e GDPR. The defendant does not explain how users' personal data can be used to fulfil the stated purposes. In this respect, the necessity criterion of the ECJ is not sufficiently taken into account. Furthermore, it is not clear to what extent and in what way personal data is collected. In this respect, the court cannot review the appropriateness of the data processing. The other grounds for justification within Art. 6 GDPR were also not sufficiently presented. As these requirements are already lacking, the stricter requirements under Art. I GDPR are not fulfilled. Furthermore, the defendant's actions violate Art. 5 para. 2 GDPR for the same reasons. According to the accountability principle enshrined in this provision, the controller must be able to prove that the personal data is collected and processed in compliance with the principles set out in Art. 5 para. 1 GDPR (ECJ, judgement of 4 October 2024, Ref. C-446121, NJW 2025,207 para. 55). Article 5 (1) GDPR enshrines, among other things, the principle of data minimisation (lit. c), which stipulates that personal data must be "adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed" (ECJ, loc. cit., NJW 2023,2997).

65
There was no need to notify the defendant pursuant to Section 139 ZPO, as the defendant was sufficiently aware from other court proceedings that its submission was not sufficient for justification under the provisions of the GDPR (see only Ellwangen (Jagst) Regional Court, loc. cit., p. 30).

66
2 The plaintiff is entitled to injunctive relief under Art. 17 GDPR in conjunction with Art. 79 GDPR. Art. 79 GDPR. Although the wording of the provision only includes a right to erasure, the plaintiff can also claim an injunction under Art. 17 GDPR in conjunction with Art. 79 GDPR. Art. 79 GDPR, the plaintiff can also derive a claim for injunctive relief. "The obligation to erase data also implies the obligation not to store this data again in the future." (LG Berlin ll, judgement v. 11.04.2021 Az. 58 O 72/24, p. 8, official printout, communicated by the plaintiff; also deriving a claim for injunctive relief from Art. 17 GDPR OLG Düsseldorf, Urt. v, 05.10.2023, 16 U 127/22, GRUR-RS 2023, 28156 and BeckOK DatenschutzRlWorms, 52nd Ed. 1.11.2024, DS-GVO Art. 17 para. 77a). The material prerequisite for the claim is the specific risk of unlawful processing of personal data.

67
a) The defendant is a data processing controller within the meaning of the GDPR (see above) and processes personal data within the meaning of Art. 4 No. 1 and 2 GDPR in the form specified in the facts of the case: The defendant collects personal data of users as soon as they access websites or apps with the business tools or when they interact with these websites. The defendant then links the data obtained to the user account of the plaintiff. Finally, the data is used for the above-mentioned purposes (ECJ, judgement of 04.07.2023, ref. C-252l21, GRUR 2023,1131, para. 71). Pursuant to S 133 (3) and (4) ZPO, the complete plaintiff's submission on the defendant's actions with regard to data collection and processing - in particular on the functioning of the business tools, the transfer of personal data and the creation of user profiles - must be taken as undisputed in the judgement. The defendant did not counter the plaintiff's submission in any significant way. The defendant's submission is essentially limited to the fact that, in the absence of the plaintiff's consent, it does not carry out any data processing for the purpose of providing personalised advertising. In addition, the defendant admits that it uses the data transmitted to it via the business tools for other purposes such as "integrity and security" (see, inter alia, duplicate of 26 January 2024, para. 81, p. 522 of the file).

68
Contrary to the defendant's opinion, the plaintiff has sufficiently demonstrated that the defendant processes its data in the business tools at issue. The plaintiff does not have to specify the specific purpose of the processing of personal data that it wishes to challenge when establishing the facts in dispute. The GDPR only makes a differentiation according to the purpose of the processing of personal data in terms of justification, in particular in Art. 6 and 9 GDPR. Accordingly, it is solely the task of the defendant to specify the purpose it is pursuing in more detail when presenting a justification. Moreover, the defendant, which is in possession of the plaintiff's data, cannot rely on a denial with ignorance.

69
Insofar as the defendant objects in the context of the denial that some of the data is data that is always collected and processed due to the nature of the Internet, this cannot be accepted. This data also falls within the scope of the GDPR. The legislator was aware of this and stated in recital 30 that natural persons may be assigned online identifiers such as IP addresses, cookie identifiers or other identifiers associated with their device, software applications, tools or protocols. Furthermore, the defendant's data processing goes far beyond this standard technical data.

70
b) There are no grounds for justification for the data processing at issue (see above).

71
c) The risk of repetition required for injunctive relief is given. The infringement already committed and continuing by the defendant justifies the factual presumption of its repetition (BGH, judgement of 17 July 2008, Ref. lZR219/05, GRUR 2008, 996, para. 32).

72
d) The threat of an administrative fine is based on Section 890 (2) ZPO. Recourse to the national provision is necessary because the GDPR, with the sanction provision in Art. 83 GDPR, does not provide an equivalent provision that is equally suitable for enforcing the injunction to grant effective legal protection (see also Landau Regional Court, default judgement of 26 February 2024, Ref. 2 O 239123, p. 13, official printout, notified by the plaintiff).

73
3. the plaintiff is entitled to compensation for non-material damage in the amount of EUR 5,000 pursuant to Art. 82 GDPR plus interest thereon to the extent tenorised. Whether there is also a claim pursuant to S S23 para. 1 BGB in conjunction with Art. Art. 1, 2 GG, as this does not justify a higher claim for damages. In addition, the plaintiff can demand default interest.

74
a) The facts giving rise to liability are fulfilled. The defendant has violated the requirements of the GDPR (see above).

75
b) The plaintiff has suffered non-material damage. Damage within the meaning of Art. 82 GDPR can be any material or immaterial loss. Although the mere violation of the GDPR is not in itself sufficient to establish a claim for damages (ECJ, judgement of 4 May 2023, file no. C-300/21, GRUR-RS 2023,8972 Ls. 1), there is also no materiality threshold that must be exceeded (see only ECJ, loc. cit., GRUR-RS 2023,8972). In particular, the loss of control over personal data or the fear of misuse of one's own data are already recognised as damages in case law (BGH, Urt. v. 1g.11.2024, Ref. Vt zR 10t24, GRUR-RS 2024,31967 para. 30 and others with reference to the ECJ). Once the loss of control has been established, it is not necessary for the person concerned to demonstrate any particular fears or anxieties, as these circumstances can only be used to establish a further deepening of the damage (BGH, loc. cit., GRUR-RS 2024,31967 para. 31)' According to the facts on which the action is based, "almost the entire online behaviour of the plaintiff was documented and evaluated in personality profiles. This means that the inviolable core area of the plaintiff's private life is also affected. This so-called profiling in particular represents a very intensive intrusion. According to Recitals 60 and 63 of the GDPR, the data subject must be informed in particular that profiling is taking place and what the consequences are. According to Recital 75, the processing of personal data for the purpose of creating personal profiles poses a particular risk of harm. This states: 'The risks to the rights and freedoms of natural persons - with varying probability of occurrence and severity - may arise from the processing of personal data which could lead to physical, material or non-material damage, in particular where the processing results in discrimination, identity theft or fraud, financial loss, damage to reputation, loss of confidentiality of privileged personal data, unauthorised reversal of pseudonymisation or other significant economic or social disadvantages, if the rights of the data subjects are deprived of their rights and freedoms or prevented from controlling the personal data concerning them, if personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or any other personal data is processed, political opinions, religious or philosophical beliefs or trade union membership, and genetic data, data concerning health or sex life or criminal convictions and offences or related security measures are processed, when personal data are evaluated, in particular when aspects relating to work performance, economic situation, health, personal preferences or interests, the reliability of the data subject's personal data are evaluated, personal preferences or interests, reliability or behaviour, location or relocation are analysed or predicted in order to create or use personal profiles, when personal data of vulnerable natural persons, in particular children's data, are processed or when the processing involves a large amount of personal data and a large number of data subjects." (Ellwangen (Jagst) District Court, loc. cit., p. 42 f.). In any case, this entails a considerable loss of control and the risk of further abusive use of the data. Since the processing of personal data in the present case is particularly extensive - it concerns potentially unlimited amounts of data and results in almost complete monitoring of the user's online behaviour - it is already possible in the abstract, according to the ECJ, that the user may have the feeling of being continuously monitored (ECJ, loc. cit., GRUR 2023, 1131, para. 118).

76
c) The damage is causally attributable to the behaviour of the defendant, as it caused the loss of control in particular through the use of the business tools.

77
d) The nature and scope of the claim for damages are governed by the national provisions in Sections 249 et seq. and Section 287 BGB in conjunction with the European legal requirements of the offence giving rise to liability in Art. 82 GDPR.

78
aa) According to the case law of the ECJ, the GDPR only allows damages for the purpose of compensation, not also for satisfaction. The provision does not require that the degree of severity and the form of intent of the controller be taken into account when assessing damages. In return, however, the ECJ requires national courts to ensure that the amount of non-material damages owed is "by its nature no less serious than personal injury" (see ECJ, judgement of 20 June 2024, Ref. C-182122, C-189/22, NJW 2024, 2599). In detail:

79
(1)The ECJ clarifies that Articles 83 and 84 GDPR, which essentially fulfil punitive purposes, may not be invoked in the context of Article 82 GDPR, as the provision aims to compensate for losses suffered (ECJ, loc. cit., NJW 2024, 25gg para. 22). Deterrence and punishment purposes are therefore not accessible to the provision, so that so-called punitive damages are ruled out.

80
(2) In the absence of specific European regulations to determine the amount of the claim under Art. 82 GDPR, the national courts must apply the existing national provisions in light of the equivalence and effectiveness of Union law according to the case law of the ECJ (ECJ, loc. cit., NJW 2024, 2599 para. 27).

81
(3)Insofar as the ECJ rules out the possibility that the compensatory function of the claim for damages within the meaning of Art. 82 GDPR takes into account the controller's intent or the severity of the infringement, it also indicates that the amount of damages must fully compensate for the specific damage suffered (ECJ, loc. cit., NJW 2024, 2599 para. 2s).

82
(4) With regard to the comparison of physical, material and non-material damage, the CJEU refers to recital 146 of the GDPR and points out that "[t]he concept of damage ... should be interpreted broadly in the light of the case-law of the CJEU in a manner that is fully consistent with the objectives of that Regulation" and that "the data subjects ... should receive full and effective damages for the harm suffered" (ECJ, loc. cit., NJW 2024, 2599 para. 36). It also states that the national provisions transposing the non-material claim for damages must not make it impossible or excessively difficult to exercise the rights conferred by Union law, in particular the GDPR (ECJ, loc. cit., NJW 2024, 2599 para. 34).

83
The ECJ thus expresses that German case law, which has so far only awarded non-material damages for violations of personality rights in very exceptional cases and only to a limited extent overall, cannot be upheld when applying the GDPR (see also Kühling/BuchnerlBergt, 4th ed. 2024, GDPR Art. 82 para. 18a; Ehmann/SelmayrlNemitz, 3rd ed. 2024, GDPR Art. 82 para. 38). It follows not least from this that, despite the restriction to mere compensation for the disadvantages suffered, the amount of compensation for pain and suffering can exceed the amounts established in national case law practice from tables of compensation for pain and suffering or similar (see also KühlingiBuchnerlBergt, 4th ed. 2024, GDPR Art. 82 para. 18d with further references). "Fitting in" with previous national case law practice would be contrary to the interpretation of the claim for damages under Art. 82 GDPR, which is autonomous under European law. Insofar as other courts partially refer to national claims for damages such as Section 823 para. 1 BGB in conjunction with Art. Art. 1 para. 1, 2 para. 1 GG in order to be able to include the further protection categories of these claims (satisfaction and prevention) - ultimately in order to dogmatically circumvent the supposed restrictions of the ECJ with the help of these claims - this approach is redundant for the reasons mentioned above.

84
(5) In all of this, the ECJ emphasises that the claim for damages under Art. 82 GDPR, in addition to the sanctions under Art. 83 GDPR, must also be suitable for ensuring compliance with the provisions of the GDPR (ECJ, loc. cit., NJW 2024, 1561 para. 62).

85
bb) The amount of the claim for damages must be estimated in accordance with the national provision of Section 287 ZPO. Pursuant to Section 287 (1) sentence 1 ZPO, the court decides on the basis of its own judgement after assessing all the circumstances. This is the gateway for the above-mentioned European legal requirements. According to Section 287 (1) sentence 2 ZPO, it is ultimately at the discretion of the court whether it takes evidence as part of the assessment of damages.

86
(1) The starting point for the assessment of a non-material claim for damages must primarily be the loss of data suffered by the plaintiff. This must be differentiated with regard to the different levels of protection guaranteed by fundamental rights for the data concerned. This applies in particular if special categories of personal data within the meaning of Art. I GDPR are affected (OLG Dresden, judgement v. 10.12.2024, ref. 4 U 808124, ZD 2025,221 marginal no. 2Q. In addition, the scope of the data collected and the duration of the infringement must be taken into account. These are categories for determining the depth or intensity of the damage, which are not to be equated with the degree of seriousness of the infringement, which the ECJ declares cannot be taken into account (ECJ, loc. cit., NJW 2024 , 25gg para. 26). In addition, the ability of the data subject to recover their data or to control it may play a role (OLG Dresden, loc. cit., ZD 2025,221, para. 20).

87
Furthermore, the court determined a corresponding connecting factor for the value of the personal data when estimating the damage. For this purpose, it took into account the value of personal data for the defendant - insofar as this could be estimated - as well as the general value of personal data on the relevant legal or illegal market. The consideration of the value of the data for the infringer is also demanded in the literature, at least in the area of commercial use (Simitis/Hornung/Spiecker gen. Döhmann, Datenschutzrecht, DS-GVO Art. 82 para. 31, with further references).

88
(2) For the extent and scope of the data concerned, please refer to the references above, also for the fundamental rights sensitivity of the data concerned. In addition, due to the defendant's silence on the data processing in dispute up to the end of the trial, it appears hopeless that the plaintiff will obtain concrete knowledge of whether he could regain control of the data by deletion or similar. In addition, beyond the fiction of confession, it is not actually possible to determine whether and to what extent the data has already been passed on to third parties and data backup is also excluded for this reason.

89
To make matters worse, even if the plaintiff had given the consent provided by the defendant with regard to the collection and processing of data for the purpose of personalised advertising, this would have been ineffective, as the general and indiscriminate collection of data violates, among other things, the principle of data minimisation and the unlimited storage of personal data for the purpose of targeted advertising is disproportionate (see only ECJ, loc. cit., NJW 2025, 207 para. 58 et seq.). For the value of the data for the defendant, the court referred to the findings of the FCO (decision of 2 May 2022, case no. B 6-27121, BeckRS 2022, 47486 para. 432). Accordingly, the defendant has one of the leading advertising offerings in the social media sector. In 2020, the defendant generated USD 86 billion in advertising revenue, in 2021 already USD 1 15 billion. Total revenue in 2021 amounted to USD 118 billion, meaning that the share of advertising revenue accounted for 97% (BKartA loc. cit., para. 7). The advertising is predominantly personalised and is based on individual tailoring for the respective user. The user should be shown advertising that could be of interest to them based on their personal consumer behaviour, interests and life situation (BKartA loc. cit., para. 53). If a user does not wish to be shown personalised advertising, he has the option of selecting such an option in return for paying a monthly fee. Based on this, the court is convinced that the value of data is essential for the defendant's business model and that the data collected by the defendant is of considerable value to it - even if it does not use the data for advertising purposes according to the admissible denial in this respect. The financial value of a single user profile, in which all personal data is stored, is enormous for participants in data processing markets. Various studies confirm that the measurement of value also corresponds to the perception in society (see only the study "Der Wert persönlicher Daten - lst Datenhandel der bessere Datenschutz?", Berlin, 2016, commissioned by the Expert Council for Consumer Affairs at the Federal Ministry of Justice and Consumer Protection; infographic "Preis, den Erwachsene in den USA für personenbezogene Daten aufrufen würde (in US-Dollar)", Statista with source data from Morning Consult from 2019, available at https://cdn.statcdn.com/infographic/images/normal/18449.jpeg).

90
Moreover, it would not seem appropriate to classify individual data as irrelevant, as it is intrinsic to the personal data breach in question that the abstract data in itself only unfolds its full potential for use in the overall view, i.e. after being linked to a personal profile Kühling/Buchner/Bergt, 4th ed. 2024, GDPR Art. 82 para. 18b, beck-online).

91
(3) Although the BGH states in its case law (BGH, loc. cit., GRUR-RS 2024,31967 para. 31) states that the particular fears and anxieties of the data subject serve as the basis for the court to determine the extent of the damage incurred, there was no need to hear the plaintiff in the present case, as the plaintiff can in any case rely on the minimum impairment for the average data subject within the meaning of the GDPR resulting from the above-mentioned scope of the damage in the specific case. According to the ECJ (most recently judgement of 4102024, loc. cit., NJW 2025, 207 para. 62), the potentially unlimited data processing by the defendant can result in a feeling of continuous intrusion into the private lives of those affected. Based on an average data subject within the meaning of the GDPR who is exposed to the aforementioned acts of infringement, it is possible for the court to estimate the resulting degree of individual concern.

92
(a) According to the case law of the Federal Court of Justice, the national standard of Section 286 of the German Code of Civil Procedure (ZPO) generally allows the court of fact "to determine what is to be considered true and what is not to be considered true solely on the basis of the parties' submissions and without taking evidence" (BGH, decision of 27 September 2017, ref. Xll ZR 48117, NJW-RR 2018, 249)' Although this case law is specifically aimed at the formation of the court's conviction on the basis of an informational hearing, it is also to be understood as meaning that the court is free to form its conviction in accordance with S 286 ZPO beyond the strict evidence. This applies in particular in the case of the estimation of damages pursuant to Section 287 ZPO, where the freedom of the court to form its own conviction is additionally extended. In this respect, the court was free to dispense with an informational hearing of the plaintiff - as most other courts have done to date. The court was convinced that if the plaintiff had been heard, no further knowledge could have been expected beyond the communication of the generally rather diffuse feeling of data loss and uncertainty. The reason for this is that it is precisely the problem of the plaintiff and also of the court to determine what the defendant actually intends to do with the data or what it is already doing. Since this will not be known until the end, the plaintiff's expectation or fear cannot be concretised to a specific behaviour. This cannot and must not be to his disadvantage.

93
(b) As the ECJ emphasises in its case law beyond data protection law, e.g. in trademark law, the standard of review for the courts under Union law for a service aimed at a general public is also a normally informed, reasonably observant and circumspect average consumer (see only ECJ, judgment of 29 April 2004, Ref. 29 April 2004, Ref. C-456101 P and C-457101 P, GRUR Int 2004, 631, para. 35; judgement of 8 October 2020, Ref. C-456l19, GRUR 2020, 1 195, para. 32). These principles can also be applied to the present case, as the defendant's services or product are open to the general public. Thus, in addition to the specific concern of an individual person, the average person concerned within the meaning of the GDPR can also be determined. Insofar as - as in the present case - the specific affectedness presented does not go beyond the extent of the general affectedness and thus no deepening of the damage can be derived from the plaintiff's submission, the court can only refer to the general impairment of the average person affected within the meaning of the GDPR.

94
The court was therefore able to take an average, informed and reasonable data subject as a basis without having to take into account the respective subjective perception of the specific plaintiff, and to use their affectedness as a benchmark for minimum damage.

95
(4) The minimum impairment is already particularly serious without the addition of further circumstances and differs significantly from the so-called scraping cases, in which a minimum damage of EUR 100 is considered appropriate for the mere loss of control (see only OLG Dresden, loc. cit., ZD 2025, 221 para. 20 with further references). Unlike in the scraping cases, the quantity and quality of the data at issue is many times greater, so that the minimum damage must be categorised as much higher. According to the case law of the ECJ, data processing by the defendant constitutes per se a serious interference with the rights to respect for private life and the protection of personal data guaranteed by Article 1.7 and 8 GrCh (ECJ, loc. cit., NJW 2025, 207 para. 63), which is not justified. The violation of these fundamental rights is also perceived by the average person affected within the meaning of the GDPR as a significant impairment in the aforementioned sense. The enlightened and reasonable average data subject within the meaning of the GDPR is aware of the significance and scope of the data collected about them, as they are aware of the relevance of personal data within a digitalised society and economy (see above on society's perception of the value of data). The loss of control over almost all data relating to their online usage activities means that they are permanently and irrevocably negatively affected, which manifests itself externally in various worries and fears. In any case, the user is forced to deal with the loss of personal data and is permanently influenced by this in terms of their further behaviour when using the Internet.

96
Based on the above, the court considers an amount of EUR 5,000 to be appropriate damages. By way of comparison, the Higher Regional Court of Dresden considered a claim for damages in the amount of EUR 5,000 to be appropriate in a decision due to spying by using a detective agency (Higher Regional Court of Dresden, judgement of 30 November 2021, case no. 4 U 1158121, NZG 2022,335). The scope of the data affected in the present proceedings goes beyond the scope of the proceedings before the Higher Regional Court of Dresden, as according to the plaintiff's submission, which is to be regarded as conceded, his entire private life in the digital sphere was and still is recorded permanently and not just limited to individual aspects. Since the GDPR came into force, the defendant's actions, which are to be regarded as admitted, constitute such a far-reaching infringement that far exceeds the scope of previously known cases, so that the minimum amount can be equated with that of the Dresden Higher Regional Court in the above-mentioned proceedings without the need to demonstrate any particular individual concern.

97
In this decision, the court is aware of the fact that awarding an amount of EUR 5,000 without the requirement of a specific demonstration of an intensity exceeding the minimum level of impairment established by the court practically means that a large number of users of the defendant can bring an action without major effort. However, there are no serious objections to this, as this form of private enforcement is precisely the intention of the European legislature and the case law of the ECJ, according to the above explanations, and serves in the form of so-called private enforcement to ensure compliance with the law. The tendency of the European legislature to enable private enforcement cannot be ignored in recent times, e.g. in the context of the Digital Markets Act (Kersting/Meyer-Lindemann/PodszunlDietrich/Jung,5th ed. 2025, DMA Art. 20-Art. 27 para. 54 with further references). In this sense, Art. 82 GDPR is "only" a further facet of the development towards more private enforcement (see also Paal/Kritzer, NJW 2022,'2433 para. 2). In this respect, the fact that almost every user of the defendant is equally affected is not a reason against the award of a substantial claim for damages (but so LG Stuttgart, loc. cit., para. 66). Likewise, the plaintiff does not have to be referred to the fact that the sanctioning of the defendant's "business practices" is not the task of civil law claims, but that public law in the sense of public enforcement exists for this purpose (see, however, LG Lübeck, loc. cit., para. 90).

98
The fact that the plaintiff continues to use the defendant's services even after becoming aware of the data processing does not have the effect of reducing the claim in the sense of contradictory behaviour. The defendant occupies an outstanding cross-market position in the area of social media platforms, which the Federal Cartel Office has already established within the meaning of Section 19a ARC (Federal Cartel Office, decision of 2 May 2022, file no. 8,6- 27121). Especially for participation in social life, the defendant's networks are now essential services for the average citizen (see recitals 1, 3 to the Regulation 202212065), which in fact cannot be replaced by an alternative network (for a summary of the background, see Mohr, EuZW 2019, 265 with reference to the Bundeskartellamt's A. decision of 6 February 2019). Even if the user becomes aware of the defendant's data protection violations, it is therefore not reasonable to expect the user to delete all profiles with the defendant and terminate its use. Rather, the defendant must ensure that the plaintiff can use its networks in compliance with the GDPR (also in the future). It is precisely through the action here that the plaintiff expresses that he is not indifferent to the defendant's personal data breaches, but that he wants to enforce GDPR-compliant use. Unlike in the scraping cases, it was also not possible for the plaintiff here - apart from the complete deletion of the profiles - to adjust his user behaviour on the defendant's platforms in such a way that further data protection violations are prevented (cf. Paal, ZfD R 2023, 325). Accordingly, contributory negligence on the part of the injured party within the meaning of S 254 BGB is also ruled out, whereby it is disputed for the claim for damages under Art. 82 GDPR whether an exclusion of liability in the sense of an all-or-nothing rule can only be considered under the conditions of Art. 82 para. 3 GDPR (see Kühling/BuchnerlBergf DS-GVO Art. 82 para. 5g with further references to the opposing view).

99
e) Furthermore, the plaintiff is entitled to default interest from the claim for damages pursuant to SS 2S6 para. 1, 288 para. 1 BGB. The defendant was in default as a result of the pre-litigation payment request of 3 August 2023 (Annex K 3), meaning that interest is payable from 1 October 2023.

100
4. the plaintiff can demand partial indemnification from the defendant for his pre-trial legal costs in the amount of EUR 540.50, Art. 82 para. 1 GDPR, §§ 249 para. 1, 257 sentence 1 BGB.

101
The claim for damages under Art. 82 GDPR also includes, as a further material damage item, the costs incurred by the out-of-court appointment of a lawyer (BGH, judgement of 18 November 2024, Ref. Vl Z,R10124, GRUR 2024, 1g10 para. 7g). Extrajudicial representation by a lawyer was necessary and expedient at the time. In particular, it was not foreseeable at the time that the defendant would refuse any pre-trial settlement. Moreover, the matter is extremely complex and the plaintiff could not reasonably be expected to assert it out of court alone.

102
However, it had to be taken into account that the out-of-court costs could be assessed solely on the basis of the value in dispute of the claim for damages in the amount of EUR 5,000. For the other claims, only a claim for damages for delay (SS 2g0 para. 1 and 2, 286 BGB) could be considered. However, the costs of the first reminder asserted here are not eligible for compensation in this respect (see only BGH, judgement of 12 May 2016, Ref. lX ZR 2}gt15, NJW-RR 2017, 124 para. 20). Contrary to the plaintiff's legal opinion, the defendant was also not in default beforehand. Based on this, the recoverable extrajudicial costs amount to EUR 540.50. According to S 60 para. 1 RVG, the previous fee law applicable until 31 May 2025 is to be applied to the remuneration if the unconditional order to deal with the same matter within the meaning of S 15 RVG was issued before a change in the law came into force, i.e. before 1 June 2025.

103
III The decision on costs is based on Section 92 (2) No. 1 ZPO. The plaintiff is only unsuccessful with a partial amount of the extrajudicial costs claimed. In any case, this amount is to be set at less than ten per cent (see OLG Cologne, judgement of 2 September 2022, case no. 20 U 266/21, NJOZ 2022, 1325 para. 56). Nothing to the contrary results from the provision in Section 45 (1) sentence 2 GKG with regard to auxiliary claims withdrawn prior to the court's decision.

104
The decision on provisional enforceability follows from section 709 sentence 1 ZPO.

105
IV. The amount in dispute is set at a total of EUR 14,000 in accordance with Sections 63 (2), 39 (1), 40, 43 (1), 48 (2) Salz 1, 48 (1) sentence 1 GKG in conjunction with Sections 3 et seq. of the German Code of Civil Procedure (ZPO) and is composed as follows:

Injunction: EUR 4,000
Declaratory judgement: EUR 5,000
Compensation: EUR 5,000
106
In civil legal disputes, the fees are based on the provisions applicable to the jurisdiction of the trial court, i.e. inter alia SS 3 to I ZPO, S 48 para. 1 sentence 1 GKG. According to Section 48 (2) sentence 1 GKG, the amount in dispute in non-pecuniary disputes is to be determined at the court's discretion, taking into account all circumstances of the individual case, in particular the scope and significance of the matter and the financial and income situation of the parties. A distinction is made between pecuniary and non-pecuniary disputes. Pecuniary disputes, i.e. those that are derived from a pecuniary legal relationship or are in any case directed towards pecuniary performance, are valued in accordance with Section 48 (1) GKG in accordance with the procedural value regulations of Sections 3 to g ZPO, while the G KG contains independent value regulations for non-pecuniary disputes.

107
Property law disputes are those that relate to property rights. However, not only all claims directly aimed at a pecuniary benefit (2.8. for monetary compensation due to a violation of personal rights) relate to assets, but also claims derived from non-pecuniary legal relationships that are not aimed at a pecuniary benefit (2.8. for injunctive relief), the pursuit of which also serves to protect economic interests in an essential way (BeckOK KostR/Toussaint, 47th ed. 1.10.2024, GKG § 48 para. 18).

108
One of the general principles of value calculation is to base the valuation on the interests of the respective applicant - in this case the plaintiff as the "attacker".

109
1. the value in dispute for the action for declaratory judgement was to be set at EUR 4,000.

110
Determining the application for injunctive relief with a value in dispute for the fees on the basis of a catch-all value is also appropriate in the context of the determination pursuant to Section 48 (2) GKG.

111
Since Section 48 (2) GKG also leaves the valuation to the (free) discretion of the court, there is no difference in the result to the procedural catch-all provision of Section 3 ZPO (BeckOK KostR/Ioussatnf, 47th ed. 1.10.2024, GKG S 48 para. 36). As a result, the criteria of Section 48 (2) GKG are also used for non-property law disputes in procedural law, i.e. when it comes to the jurisdictional or appeal value (BeckOK KostR/Ioussarnf, 47th ed. 1.10.2024, GKG S 48 para. 37). It is therefore often proposed to fall back on the standard value for lawyers' fees under Section 23 (3) sentence 2 RVG - EUR 5,000 - and to make this the standard amount in dispute for non-pecuniary disputes. The Higher Regional Court of Dresden also uses this as a basis when determining the amount in dispute for injunctive relief relating to data, but believes that, as the threshold value is to be increased or decreased depending on the individual case, the amount in dispute should be reduced to EUR 3,500 in scraping cases (OLG Dresden, decision of 31 July 2023 - 4 W 396/23, BeckRS 2023, 21123 para. 10).

112
When assessing the value in the scraping cases, the Dresden Higher Regional Court took into account the fact that securing the data, which is widely distributed on the Internet, is important for the plaintiff. On the other hand, however, the severity of the impairment must take into account the fact that the data concerned was from the social sphere and that he disclosed certain data in the knowledge that it was publicly accessible. He cannot use the defendant's social network without disclosing certain data that is accessible to all Internet users - such as name, gender and user ID - and he accepted this. With regard to the (lesser) severity of the allegation, the Dresden Higher Regional Court took into account in the scraping cases for the reduction of the amount in dispute that the defendant did not process the data in an unauthorised manner by actively doing so, but rather that the data made public by the users was siphoned off en masse by third parties in an unauthorised manner by means of automated procedures and that the plaintiff's allegation is aimed at the fact that the defendant did not take any precautions against this.

113
Even below this, the German Federal Court of Justice set the value of the injunctive relief in the scraping cases at a total of EUR 1,500 (Federal Court of Justice, decision of 10 December 2024, file no. VI ZR 7/24, GRUR-RS 2024,37952 para. 15).

114
The BGH has applied the following standards when determining the amount in dispute for injunctive relief in scraping cases: The decisive factor in an application for injunctive relief after an act of infringement has already occurred is the claimant's interest in preventing further similar infringements, which is largely determined by the nature of the infringement, in particular by its dangerousness and harmfulness to the owner of the infringed right. However, other factors independent of the infringement that has already occurred - such as the degree of probability of future infringements - may also have to be taken into account (see BGH, judgement of 12 May 2016, case no. I ZR 1115, NJW 2017, 814 para. 33 ft. with further references). The potential risk must be determined solely with regard to the specific dispute; there is also no room for general preventive considerations when assessing a claim for injunctive relief under civil law (BGH, loc. cit, NJW 2017,814 para. 42 with further references) as well as for an orientation towards any (overall) damage including other affected parties (see BGH, decision of 30 January 2004, Ref. Vl ZR 65/04, juris, para. 2; OLG Hamm, judgement of 15 August 2023, Ref. 15 August 2023, Ref. 7 U 19123,juris, para. 277). Finally, the overall structure of the valuation of non-pecuniary matters in dispute must not be lost sight of (BGH, decision of 26 November 2020, case no. lll Z.R124120, K& R 2021, 127 para. 11, summarising BGH, decision of 10 December 2024, case no. Vl ZR 7124, GRUR-RS 2024,37952 para.14).

115
For the determination in the specific case, the BGH states: "The plaintiff se/bsf has quantified his claim for payment of compensation for the damage incurred at EUR 1,000. In another parallel case, the Senate stated in more detail that it would not legally object to an assessment in the order of EUR 100 for the mere loss of control (judgement of 18 November 2024 VI ZR 10/24, juris para. 100). The plaintiff has also valued his application for a declaratory judgement with regard to any future damages at EUR 500; this also appears appropriate in view of the foreseeable difficulties in proving the causality of future damages' The act of infringement already occurred five years ago, without the mere loss of control having led to the occurrence of demonstrable damages or a further act of infringement; on the contrary, the defendant has since deactivated the searchability function in the form at the centre of the dispute. Both applications for injunctive relief have their starting point in the same act of infringement and are closely related in substance." (BGH, loc. cit., para. 15).

116
According to the plaintiff's allegations and presentation, which are decisive for the determination of value, the facts of the present case are completely different. In the present case, the plaintiff wishes to prevent the defendant from continuing to monitor his usage behaviour as part of his private life and to commercially exploit the results of the monitoring by passing them on to third parties in a manner that is no longer controllable for the user of the defendant's network. In this respect, it is fair to assume an initial amount in dispute of EUR 5,000 and to assume a value in dispute reduced to EUR 4,000 in a large number of cases in accordance with the information on the amount in dispute provided by the authorised representatives in the proceedings to date.

117
There are still no sufficient indications that the interest of a claimant in preventing further similar infringements by the defendant would be lower if he had to bear the costs of the proceedings himself and did not have them covered by legal expenses insurance - even if the proceedings against the defendant in connection with infringements of the GDPR, which are predominantly pending before the German courts, are financed by a legal expenses insurer. In this respect, it cannot be taken into account that the party who has to bear the costs of proceedings aimed at an injunction would - more realistically - quantify the interest in the injunction at a much lower amount.

118
2. the amount in dispute for the application for a declaratory judgement was to be set at EUR 5,000. Taking into account the statements under no. 1 and the statements on the admissibility of the action for a declaratory judgement, it must be assumed that this application has a greater interest in legal protection compared to the action for a cease and desist order, as the declaratory judgement extends to the future as well as the past and can prepare a large number of possible further claims against the defendant. The court therefore considers it appropriate to apply the standard amount in dispute without deduction in this case.

119
3. with regard to the application for payment of a claim for damages, the amount in dispute was to be assessed on the basis of the amount that appears appropriate on the basis of the plaintiff's submission of facts (Anders/Gehle/Gehle, 83rd ed. 2025, ZPO Anh. § 3 para. 99). In this respect, reference is made to the court's above comments on the merits of the claim.

120
4. the application for payment of extrajudicial costs was not to be taken into account when determining the amount in dispute, as this does not affect the amount in dispute for fees pursuant to section 43(1) of the German Civil Code (also via section 48(1)(1) of the German Civil Code in conjunction with section 4(1)(1) of the German Civil Procedure Code).

121
5. the auxiliary motions that have been dropped in the meantime are also not to be taken into account pursuant to g 45 para. 1 sentence 2 GKG.
  1. Data subject's personal data originating on third party websites and apps, whether transmitted directly or in hashed form, i.e. ▪ Email of the claimant ▪ Telephone number of the claimant ▪ First name of the claimant ▪ Surname of the claimant ▪ Date of birth of the claimant ▪ Gender of the claimant ▪ Place of the claimant ▪ External lDs of other advertisers (referred to by C. Ltd. called "external_lD") ▪ IP address of the client ▪ User agent of the client (d. h. collected browser information) ▪ internal click ID of C. Ltd. ▪ internal browser ID of C. Ltd. ▪ Subscription ID ▪ lead ID ▪ anon_id as well as the following personal data of the data subject b. on websites ▪ the URLs of the websites and their subpages ▪ the time of the visit ▪ the "referrer" (the website from which the user came to the current website) ▪ the buttons clicked by the plaintiff on the website and ▪ other data mentioned by "C. Events" that document the interactions of the plaintiff on the respective website c. in third-party mobile apps ▪ the name of the app and the time of the visit ▪ the buttons clicked by the plaintiff in the app and ▪ the data referred to by C. as "events", which document the interactions of the plaintiff in the respective app.