OLG Stuttgart - 4 U 353/24

From GDPRhub
OLG Stuttgart - 4 U 353/24
Court: OLG Stuttgart (Germany)
Jurisdiction: Germany
Relevant Law: Article 6(1)(a) GDPR
Article 6(1)(f) GDPR
Article 6(1) GDPR
Article 15(1) GDPR
Article 17 GDPR
Article 17(1)(d) GDPR
Article 18 GDPR
Article 18(1)(b) GDPR
Article 26 GDPR
Decided: 29.04.2026
Published:
Parties:
National Case Number/Name: 4 U 353/24
European Case Law Identifier:
Appeal from: LG Stuttgart (Germany)
12 O 170/23
Appeal to: Unknown
Original Language(s): German
Original Source: Landesrecht BW (in German)
Initial Contributor: ap

A court found that a social media platform unlawfully processed a data subject's off-site data through its “Business Tools”, and ordered the company to fulfil the data subject’s requests for information, restriction, and future erasure. In addition, the court ordered the company to pay the data subject €500 in non-material damages.

English Summary

Facts

The controller is a company that operates several social media platforms, as well as software products grouped under the term “Business Tools“. Third parties can integrate the Business Tools into their websites and apps (subject to the controller’s Terms of Use) to track data subjects and display personalised advertising on data subjects’ social media platforms. Third parties process data subjects’ personal data (such as their IP address, operating system or time zone) and transfer this data to the controller. The data is processed regardless of whether the data subject is logged into one of the controller’s platforms. The business tools are used on a wide range of high-traffic websites and related apps. A data subject (who uses the controller’s platform for personal purposes) filed a claim with the Regional Court of Stuttgart. The data subject requesting the court to order the controller to stop processing their data through third party websites and apps, provide them with full access to their data, erase said data after providing complete access and pay the data subject a minimum of €5,000 in non-material damages.

The Regional Court dismissed the claim, on the grounds that the data subject had not provided sufficient evidence to substantiate their claims. In addition, the court considered that the data subject actions were contradictory, as it demanded the controller to cease processing personal data while not accepting cookies. The court stated that the request for the erasure (Article 17 GDPR) and restriction (Article 18 GDPR) of the data subject’s data were not compatible with the injunction sought by the data subject. Finally, the court considered that the controller had provided the data subject with access in accordance with Article 15(1) GDPR.

The data subject appealed the decision to the court. The data subject argued that the injunction against future data processing was justified, because the data is automatically transferred to the controller by third parties. Furthermore, the lower court interpreted the erasure and restriction requests too narrowly. Finally, the data subject argued that the “self help tool” of the controller did not fulfil their request for access. On the other hand, the controller argued that the data subject had not provided evidence on how third parties processed their data. The claim was also too vague and unfounded, as the data subject had not yet decided whether to consent to their data being processed for advertising purposes or pay an ad-free subscription (this is also known as “Pay or Okay”).

Holding

According to the court, it must be assumed that the data subject visited websites that implemented the controller’s business tools, and therefore the data subjects’ data was collected and transferred to the controller. The data subject claimed this in general terms and specified it in relation to individual websites in the second instance; the court considered that the general claim in the first instance was sufficient to substantiate the data subject’s claims, including demonstrating that their personal data was unlawfully processed.

The court also stated that the individual websites were responsible for obtaining data subject’s consent to process their data and transfer it to the controller. The court considered the controller and website operators as joint controllers, in accordance with CJEU case law.[1] However, as a joint controller, the company operating the social media platforms bore the burden of proof in demonstrating that the data subject consented to the processing.

The court partially upheld the data subject’s claims.

Claims that were dismissed

The court dismissed three of the data subject’s claims on procedural grounds. First, the court dismissed the data subject’s request to declare that the user agreement did not allow the controller to process the data subject’s data through third parties. The court stated that it could bring an injunction and not a request for declaratory judgment. The court also dismissed the data subject’s request to order the controller to cease processing personal data on third party websites and apps without a legal basis (consent or legal bases under Articles 6(1)(b) to (e) GDPR).

The court dismissed the data subject’s injunction claim for data erasure (Article 17 GDPR). According to the court, Article 17 GDPR does not grant a right to injunctive relief. However, the GDPR does not preclude national law from allowing these claims (e.g. Sections 823 and 1004 of the German Civil Code). In this case, however, the court considered that the controller lacked the conditions under national law to be liable for injunctive relief; specifically, the court considered the fact that the controller developed the business tools insufficient to consider that it had directly violated its obligations as a joint controller under Article 26 GDPR.[2]

Claims that were upheld

The court first upheld the data subject’s request to order the defendant to not delete the processed data (Article 18 GDPR), but did not order the controller to leave the data at the location it is stored. Under Article 18(1)(b) GDPR, the data subject may request to restrict the processing if the processing is unlawful and they oppose the erasure of the data. The court considered that the data processing was unlawful, as the controller stored the data on security and integrity grounds without proving it had a legal basis under Article 6(1)(f) GDPR to do so. Specifically, the controller had not specified why it processed the data for security purposes, why it was necessary, or the storage periods.

The court also upheld the data subject’s claim for access to information under Article 15(1) GDPR. The court stated that the controller had deliberately restricted the information provided through its “self help tools”, and had therefore not complied with its information obligations. The court considered these tools as particularly unsuitable to provide information on the processing of data outside the social network. Once this information obligation is fulfilled, the court stated that the controller had the obligation to fulfil the data subject’s request for erasure under Article 17(1)(d) GDPR (if the personal data is unlawfully processed).

Finally, the court upheld the data subject’s claim for damages, but reduced it to €500. The claim for damages were well founded, as the controller violated the GDPR, and caused the data subject to suffer damage (loss of control over their data), and there was a causal link between the two.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the German original. Please refer to the German original for more details.

Baden-Württemberg State Law Citizen Service: Document View
Quick Navigation

Screen Reader Instructions
Search

Table of Contents
Document

Main Menu
Baden-Württemberg Logo
Header

State of Baden-Württemberg, Plain Language, Sign Language

Table of Contents
Document without Table of Contents
Quick Search
Search in All Categories

Result Navigation

Go to Search

Document Tools

PDF View of Document

Print Document

Navigation in the Table of Contents
Document Content
Document Header
Court: Stuttgart Higher Regional Court, 4th Civil Senate
Date of Decision: April 29, 2026
Case Number: 4 U 353/24
ECLI: ECLI:DE:OLGSTUT:2026:0429.4U353.24.00
Document Type: Judgment
Source: juris Logo
Legal Norms: Art. 6 EUV 2016/679, § 823 para. 1 BGB, § 1004 BGB, Art. 12 EU Regulation 2016/679, Article 15(1) EU Regulation 2016/679 ... more
Document tab

Short text Long text

Principle

On claims by users of social networks regarding the use of business tools

Hide procedural history Procedural history
Lower court: Stuttgart Regional Court, 12th Civil Chamber, October 24, 2024, Case No. 12 O 170/23
Judgment

I. Upon the appeal of the plaintiff, the judgment of the Stuttgart Regional Court of October 24, 2024, Case No. 12 O 170/23, is partially amended and reformulated as follows:

(a) 1. The defendant is ordered to leave all personal data listed under 1. a), b), and c), which has already been processed since May 25, 2018, unchanged with immediate effect, and in particular to delete this data only after complete disclosure has been provided in accordance with point 2 of the judgment. Until this point, the following data must not be altered, reused internally, or disclosed to third parties:

a) On third-party websites and apps visited by the plaintiff, the following personal data that serves to identify the plaintiff, whether transmitted directly or in hashed form, i.e.:

- Plaintiff's email address

- Plaintiff's telephone number

- Plaintiff's first name

- Plaintiff's last name

- Plaintiff's date of birth

- Plaintiff's gender

- Plaintiff's city

- External IDs of other advertisers (referred to by M... Ltd. as "external_ID")

- Client's IP address

- Client's user agent (i.e., collected browser information)

- M... Ltd.'s internal click ID


- M... Ltd.'s internal browser ID


- Subscription ID

- Lead ID

- anon_id

b) on third-party websites visited by the plaintiff

- the URLs of the websites, including their subpages

- the time of the visit

- the referrer (the website from which the user arrived at the current website), the buttons clicked by the plaintiff on the website, and

- other data referred to as "Events" by M... that document the plaintiff's interactions on the respective website

- other data referred to as "Events" by M... that document the plaintiff's interactions on the respective website

c) in third-party mobile apps used by the plaintiff

- the name of the app and

- the time of the visit

- the buttons clicked by the plaintiff in the app and

- the data referred to as "Events" by M... that document the plaintiff's interactions in the respective app.


2. The defendant is ordered to provide the plaintiff with information pursuant to Article 15(1)(a), (c), (g), and (h) of the GDPR regarding which personal data, as described in section I.1.(a) - (c), the defendant has processed since May 25, 2018, and in the course of this processing has linked the plaintiff's user account on the "F..." network under the email address "Jxxx.fxxx@gmx.de", in particular, but not exclusively, through the "M... Business Tools",

furthermore, for each piece of data collected,

whether and, if so, which specific personal data of the plaintiff the defendant has disclosed to third parties (advertising partners, other partners, affiliated companies, or other third parties) since May 25, 2018, and at what time, naming these third parties,

whether and, if so, which specific personal data of the plaintiff the defendant has disclosed since May 25, 2018, and at what time (start, duration, End) in which third country the data has been stored;

to what extent the plaintiff's personal data has been and is being used for automated decision-making, including profiling. The defendant must provide meaningful information about the logic involved, as well as the scope and intended impact of such processing on the data subject.

3. The defendant is ordered to completely delete all personal data already stored since May 25, 2018, in accordance with clause I. 1 a), four weeks after providing complete information.

4. The defendant is ordered to pay the plaintiff non-pecuniary damages in the amount of €500.00, plus interest at a rate of five percentage points above the base interest rate since September 29, 2023.

5. The remainder of the claim is dismissed.

II. The plaintiff's further appeal is dismissed.

III. The plaintiff shall bear 70% and the defendant 30% of the costs of the litigation in both instances.

IV. The judgment in paragraphs I.1 to I.3 is provisionally enforceable upon provision of security in the amount of €750.00 in each case.

Otherwise, this judgment is provisionally enforceable without security. The respective judgment debtor may avert enforcement by providing security in the amount of 110% of the amount enforceable under the judgment, unless the judgment creditor provides security in the amount of 110% of the amount to be enforced before enforcement proceedings commence.

V. Leave to appeal on points of law is granted.

VI. The value in dispute for the appeal proceedings is set at €8,250.00.

VII. The value in dispute, set by the Regional Court at €20,000.00 for the proceedings at first instance, is hereby amended ex officio to €8,250.00.

Reasons

I.

1.

Paragraph 1

The defendant operates various social networks, including I... and F.... Currently, more than 3.98 billion people use the defendant's products.

Paragraph 2

The defendant offers companies the opportunity to present advertisements to an audience on the respective social network for a fee. The defendant provides these third-party companies with so-called business tools. If the third-party company integrates these business tools into its website, data from a user visiting that website is transmitted to the defendant. This includes standard technical data such as the device's IP address, which is transmitted as part of the HTTP request. Additional data, such as customer activity data on third-party websites or apps, is transmitted depending on the third-party company chosen and the specific business tool used. If the user has given their consent to the defendant, the transmitted data will be used for personalized advertising. Even if the user has refused consent, the defendant uses the data for security and integrity purposes.

Paragraph 3

The plaintiff uses a social network operated by the defendant for private purposes. The plaintiff has not consented to the defendant's use of their personal data transmitted to the defendant via a business tool from third-party companies.


The plaintiff uses the defendant's social network privately. Paragraph 4

The plaintiff ultimately seeks the following in the first instance:

Paragraph 5

1. a declaration that the parties' user agreement does not permit the processing of certain data of the plaintiff listed in the application,

Paragraph 6

2. an order prohibiting the defendant from processing the plaintiff's personal data on third-party websites and third-party apps outside the defendant's networks,

Paragraph 7

3. an order prohibiting the defendant from leaving the plaintiff's personal data generated on third-party websites and third-party apps unchanged in their stored location and from deleting it only after full disclosure has been provided, and from altering, internally reusing, or disclosing it to third parties until that time,

Paragraph 8

4. information pursuant to Article 15(1)(a), (c), (g), and (h) of the GDPR regarding which personal data the defendant has processed in accordance with the application under points 1(a) to (c) since [date]. May 25, 2018, processed and, in the course of this, linked to the plaintiff's user account, in particular, but not exclusively, through the "M... Business Tools,"

Paragraph 9

5. The defendant is ordered to completely delete the personal data already stored since May 25, 2018, pursuant to claim no. 1 a), four weeks after providing complete information, and to confirm the deletion to the plaintiff, as well as to completely anonymize or, at the defendant's option, delete all personal data already stored since May 25, 2018, pursuant to claims no. 1 b) and c),

Paragraph 10

6. The defendant is ordered to pay non-pecuniary damages in the amount of at least €5,000,

Paragraph 11

7. The defendant's order to reimburse the plaintiff for pre-litigation legal fees in the amount of €1,295.43.

Paragraph 12

The defendant moved in the court of first instance to

Paragraph 13

dismiss the action.

Paragraph 14

For details of the parties' submissions in the court of first instance, reference is made to the pleadings and the factual findings in the judgment of the Regional Court.

2.

Paragraph 15

The Regional Court dismissed the action.

Paragraph 16

The declaratory judgment action (point 1) was inadmissible for lack of a legitimate interest in such a judgment. The plaintiff could sue for performance and had done so with the requests for injunctive relief and deletion. Furthermore, the claim was unfounded because the plaintiff had not presented any substantiated arguments.

Paragraph 17

The injunction application (point 2) is also unfounded. If the application were understood to aim at prohibiting certain data processing operations, it would no longer be covered by the scope of protection of Article 17 GDPR, and recourse to provisions of German national law would not be permissible. However, even if the injunction application were to be understood as referring to the processing of data transmitted via the business tools, the claim would still be invalid, since, according to the defendant's submissions, the data processing to be prohibited is not taking place. Furthermore, the plaintiff must accept the consequences of contradictory conduct (§ 242 of the German Civil Code) if, on the one hand, it demands the cessation of data processing and, on the other hand, fails to fulfill necessary obligations to cooperate and its own duties by accepting cookies.


However, even if the injunction application were understood to refer to the processing of data transmitted via the business tools, the claim would still not exist, since, according to the defendant's submissions, the data processing to be prohibited is not taking place. Paragraph 18

The further injunction (point 3), which seeks to prevent the defendant from leaving the plaintiff's already processed personal data unchanged at its current location and deleting it only after providing full information, and not altering, internally using, or disclosing this data to third parties until then, lacks a legitimate interest in legal protection. Moreover, the request is unfounded because it contradicts the plaintiff's objective. There is no legal basis for such a request under the GDPR; in particular, Article 18(1)(c) GDPR is not applicable. Furthermore, the request would violate the principles of purpose limitation, data minimization, and storage limitation, and would effectively result in the defendant having an unlimited obligation to store the data.

Paragraph 19

The defendant has already complied with the right of access (point 4) pursuant to Article 15(1) GDPR.


Paragraph 20

The request for erasure (point 5) is inadmissible because the data to be erased or anonymized is only described in abstract terms, and it is not specified which data the defendant must delete and which it may retain for the plaintiff's continued use of their account. Furthermore, there is no legitimate interest in legal protection, as the plaintiff has the option of deleting the data themselves.

Paragraph 21

The claim for damages (point 6) is unfounded because the plaintiff has not demonstrated any damages. They have not specified which data the defendant collected without their consent, nor have they provided any evidence that the defendant used the data transmitted to them via the business tool to display personalized advertising, either without or against their will. The unpleasant feeling cited by the plaintiff does not, in itself, justify an obligation to pay damages. Furthermore, there is a lack of concrete evidence demonstrating the causal link between the defendant's alleged breach of duty and the plaintiff's alleged damages.

Paragraph 22

A claim also does not arise from the alleged violation of the plaintiff's general right of personality. The plaintiff has not substantiated any tangible non-material harm.

Paragraph 23

Since there is no claim on the merits, there is also no claim for pre-litigation legal fees and interest.

3.

Paragraph 24

In its appeal, the plaintiff continues to pursue its claims from the first instance, supplementing the injunction claim (paragraph 2) with a subsidiary claim (paragraph 8).

Paragraph 25

In support of its appeal, the plaintiff essentially argues the following:

Paragraph 26

A legitimate interest in a declaratory judgment exists. The possibility of future harm exists even if the court grants the other claims. In any event, the application is admissible as an interim declaratory judgment pursuant to Section 256 Paragraph 2 of the German Code of Civil Procedure (ZPO).

Paragraph 27

The application for an injunction against future data processing is fully justified. Even the initial collection of the data by the business tools must be prevented to ensure effective legal protection, because the data would be automatically transmitted to the defendant's servers. A claim for an injunction arises from Article 17 of the GDPR. The concept of storage must be interpreted more broadly than assumed by the Regional Court. Furthermore, the Regional Court misinterprets the defendant's submissions, which did not falsely claim that it does not process the plaintiff's data.

Paragraph 28

The application in point 3 is justified pursuant to Article 18 Paragraph 1 Letter b) of the GDPR. According to this provision, the data subject may refuse the erasure of their personal data and instead request the restriction of its use.

Paragraph 29

The application in point 4 is based on Article 15 of the GDPR. The plaintiff's asserted rights to information would not be satisfied by the availability of a "self-help tool" that only allows access to rudimentary information.

Paragraph 30

The claim in point 5 is admissible and well-founded. The defendant neither claims that the plaintiff can delete the specified data, nor has the defendant asserted at any point in its submissions that the data is needed to operate the plaintiff's F... account. Insofar as the Regional Court believes that anonymization is not provided for in the General Data Protection Regulation (GDPR), it fails to recognize that this constitutes partial deletion within the meaning of Article 17 GDPR, because it irreversibly removes the components of the respective data that allow for the identification of the data subject. Anonymization is therefore to be understood as a subcategory of deletion and not something different.

Paragraph 31

The claim in point 6, which seeks monetary compensation or non-pecuniary damages, is also well-founded. In addition to demonstrating a loss of control, the plaintiff has sufficiently substantiated the extensive and significant impairments. Neither a threshold of significance nor pathologically measurable impairments of the plaintiff are prerequisites for a claim for monetary compensation. The Regional Court did not address the existence and amount of the asserted claim for monetary compensation, which arises not from Article 82 GDPR, but from Section 823 Paragraph 1 of the German Civil Code (BGB) in conjunction with Article 2 Paragraph 1 and Article 1 Paragraph 1 of the German Basic Law (GG).

Paragraph 32

The asserted claim for payment of pre-litigation legal fees follows the dismissal of the other claims. Had the Stuttgart Regional Court correctly ruled the asserted claims to be justified—in accordance with the above explanations—it would subsequently have had to also rule the claim under point 7 to be justified.


(Paragraph 32) Paragraph 33

In addition, the plaintiff submits, in response to the Senate's observations during the appeal hearing, that it regularly visits the websites b….de, f….de, s….de, s…-a….de, b….com, and o….de.

4.

Paragraph 34

The defendant defends the judgment of the court of first instance.

Paragraph 35

In support of its position, the defendant essentially argues the following:

Paragraph 36

The plaintiff has not sufficiently substantiated its claims, in particular, it has not adequately demonstrated its individual standing to sue. It is insufficient to submit virtually formulaic and almost identical pleadings that fail to demonstrate whether, when, and via which websites or apps data might have been processed using the business tools in dispute, to what extent such processing might be unlawful, on what specific basis the plaintiff has these subjective impressions of "loss of control" or "fear of misuse" that it allegedly experiences, or to what extent the defendant's actions might have caused these feelings. In this respect, the defendant also bears no secondary burden of proof.

Paragraph 37

The declaratory judgment action is inadmissible for lack of a legitimate interest in such a judgment and is also too vague and cannot be reinterpreted as an action for an interim declaratory judgment. The declaratory judgment action is also unfounded, as the defendant does not process business tool data for the provision of personalized advertising to the plaintiff, who has not yet decided whether to grant the defendant permission to use the information collected about its products for advertising purposes or whether to subscribe to the ad-free service.

Paragraph 38

The injunction action is also inadmissible and unfounded.

Paragraph 39

The plaintiff neither specifies nor substantiates which processing purpose is allegedly unlawful and which processing purposes—beyond the processing of business tool data for the provision of personalized advertising—should be prohibited. Furthermore, the action is not sufficiently specific. Moreover, Article 17 GDPR does not provide a legal basis for an injunction.

Paragraph 40

The application for leave to remain in effect is also inadmissible and unfounded.


Paragraph 41

The request to keep the plaintiff's data unchanged at its current location contradicts the plaintiff's request for erasure and anonymization, making it impossible for the defendant to comply with both requests. Furthermore, the GDPR does not provide a legal basis for a right to retain data unchanged, and the GDPR does not permit recourse to national law.

Paragraph 42

The Regional Court correctly dismissed the request for access to information because it was fulfilled by the defendant's out-of-court letter, which referred to the defendant's service tools.

Paragraph 43

A claim for non-pecuniary damages/monetary compensation fails because the defendant has not violated either Article 5 or Article 25 of the GDPR. However, even assuming a violation, the plaintiff has not demonstrated that it suffered any damage as a result of the violation. In particular, the plaintiff has always had control over its data due to the data usage settings available to it. A claim for monetary compensation for a violation of her personal rights is already excluded – due to the lack of an opening clause in the GDPR. But even if this claim were considered admissible, its requirements would not be met, since the plaintiff has not demonstrated a serious violation of her personal rights that could only be remedied by a monetary payment.

Paragraph 44

The Regional Court was also correct in denying the claim for reimbursement of pre-litigation legal fees. Apart from the fact that no principal claim existed, the plaintiff had failed to demonstrate that the involvement of a lawyer prior to litigation was necessary.


``` 5.

Paragraph 45

The plaintiff ultimately requests that

Paragraph 46

the judgment of the Stuttgart Regional Court of October 24, 2024, be amended and that judgment be rendered as follows:

Paragraph 47

1. It is declared that the parties' user agreement for the use of the network "F..." under the email address "Jxxx.fxxx@gmx.de" does not permit the defendant to process the following personal data of the plaintiff to the following extent:

Paragraph 48

a) on third-party websites and apps visited by the plaintiff, the personal data that serves to identify the plaintiff, whether transmitted directly or in hashed form, i.e.,

Paragraph 49

- Plaintiff's email address

Paragraph 50

- Plaintiff's telephone number

Paragraph 51

- Plaintiff's first name

Paragraph 52

- Plaintiff's last name Plaintiff

Paragraph 53

- Plaintiff's date of birth

Paragraph 54

- Plaintiff's gender

Paragraph 55

- Plaintiff's place of residence

Paragraph 56

- External IDs of other advertisers (referred to by M... Ltd. as "external_ID")

Paragraph 57

- Client's IP address

Paragraph 58

- Client's user agent (i.e., collected browser information)

Paragraph 59

- M... Ltd.'s internal click ID

Paragraph 60

- M... Ltd.'s internal browser ID


Paragraph 61

- Subscription ID

Paragraph 62

- Lead ID

Paragraph 63

- anon_id

Paragraph 64

b) on third-party websites visited by the plaintiff

Paragraph 65

- the URLs of the websites, including their subpages

Paragraph 66

- the time of the visit

Paragraph 67

- the referrer (the website from which the user arrived at the current website), the buttons clicked by the plaintiff on the website, and

Paragraph 68

- other data referred to by M... as "events," which document the plaintiff's interactions on the respective website.


Paragraph 69

c) in the third-party mobile apps used by the applicant

Paragraph 70

- the name of the app and - the time of the visit

Paragraph 71

- the buttons clicked by the applicant in the app and

Paragraph 72

- the data referred to by M... as "Events," which document the applicant's interactions in the respective app.



Paragraph 72 Paragraph 73

2. The defendant is ordered, under penalty of a fine of up to EUR 250,000.00 for each instance of non-compliance, or alternatively, imprisonment of its legal representative for up to six months, or up to two years in the case of repeated offenses, to refrain from processing the plaintiff's personal data on third-party websites and apps outside the defendant's networks without the plaintiff's effective consent, as requested in point 1, unless a legal basis pursuant to Article 6(1)(b) to (e) GDPR exists in the individual case.

Paragraph 74

3. The defendant is ordered to cease all processing of the plaintiff's personal data as requested in points 1(a), (b), and (c). The defendant is ordered to leave the personal data listed, which has already been processed since May 25, 2018, unchanged in its current location. Specifically, the defendant is ordered to delete this data only after the plaintiff has fully provided the requested information in point 4, and to refrain from altering it, using it internally, or disclosing it to third parties until that time.

Paragraph 75

4. The defendant is ordered to provide the plaintiff with information pursuant to Article 15(1)(a), (c), (g), and (h) of the GDPR regarding which personal data has been processed in accordance with points 1(a) to (c). The defendant has processed the plaintiff's personal data since May 25, 2018, and in doing so has linked it to the plaintiff's user account on the "F..." network under the email address "Jxxx.fxxx@gmx.de", in particular, but not exclusively, through the "M... Business Tools",

Paragraph 76

furthermore, for each piece of data collected,

Paragraph 77

whether, and if so, which specific personal data of the plaintiff the defendant has disclosed to third parties (advertising partners, other partners, affiliated companies, or other third parties) since May 25, 2018, and at what time, identifying these third parties,

Paragraph 78

whether, and if so, which specific personal data of the plaintiff the defendant has stored in which third country since May 25, 2018, and at what time (start, duration, end);

Paragraph 79

To what extent the plaintiff's personal data has been and is being used for automated decision-making, including profiling. The defendant must provide meaningful information about the logic involved, as well as the scope and intended impact of such processing on the data subject.

Paragraph 80

5. Pursuant to Section 259 of the German Code of Civil Procedure (ZPO), the defendant is ordered to completely delete all personal data already stored since May 25, 2018, in accordance with claim 1 a., four weeks after providing the plaintiff with complete information and to confirm the deletion, and to completely anonymize all personal data already stored since May 25, 2018, in accordance with claims 1 b. and c.
...`


] Paragraph 81

6. The defendant is ordered to pay the plaintiff non-pecuniary damages, the amount of which is to be determined at the court's discretion, but which shall be at least €5,000.00, plus interest at a rate of five percentage points above the base interest rate since July 18, 2023.

Paragraph 82

7. The defendant is ordered to reimburse the plaintiff for pre-litigation legal fees in the amount of €1,295.43.

Paragraph 83

8. Alternatively, if the second claim is inadmissible or unfounded:

Paragraph 84

The defendant is ordered, under penalty of a fine of up to €250,000.00 for each instance of non-compliance, or alternatively, imprisonment of its legal representative for up to six months, or up to two years in the case of repeated offenses, to refrain from processing personal data on third-party websites and apps outside the defendant's networks in accordance with the first claim,

Paragraph 85

unless the defendant presents and proves justifications relating to specific individual processing operations concerning the plaintiff's personal data, with individual reference to these operations,

Paragraph 86

which is why the data processing cannot be justified, in particular, by

Paragraph 87

- the conclusion of the contract for the use of the "F..." network and/or "I...",

Paragraph 88

- consent via the "Information from advertising partners about your activities" button on the "F..." and/or "I..." network,

Paragraph 89

- consent via the "M... Cookies in other apps and on other websites" button on the "F..." and/or "I..." network,

Paragraph 90

- the provision of a service to fulfill the contract for the use of the "F..." and/or "I..." network,

Paragraph 91

- abstract research for the benefit of society, the abstract promotion of protection, integrity, and security,

Paragraph 92

- the defendant's economic interest in the personalization of advertisements,

Paragraph 93

- the abstract goal of informing law enforcement and penal authorities to prevent, detect, prosecute, establish, or

Paragraph 94

- other legitimate interests of the defendant asserted across users in the Data processing.

Paragraph 95

The defendant requests that

Paragraph 96

the plaintiff's appeal be dismissed.

6.

Paragraph 97

For further details and the parties' additional submissions in the second instance, reference is made to the written pleadings and the transcripts of the oral hearing.

II.

Paragraph 98

The plaintiff's appeal is admissible. In particular, it was filed and substantiated in due form and time.

Paragraph 99

On the merits, it is only partially successful.

Paragraph 100

The plaintiff's appeal is unfounded with respect to claims 1, 2, and 8.

Paragraph 101

The declaratory judgment claim (item 1) is inadmissible, the injunction claim (item 2) is unfounded, and the alternative claim (item 8) is inadmissible.

Paragraph 102

With regard to the claims for unchanged storage (point 3), for access (point 4), for erasure or anonymization (point 5), and for damages (point 6), the plaintiff's appeal is partially successful.

A.

Paragraph 103

The international jurisdiction, which must also be examined ex officio at the appellate level, is based on Article 79(2), second sentence, GDPR with respect to all claims based on the General Data Protection Regulation, and on Article 82(6) GDPR with respect to claim point 6. It can remain undecided whether Article 79(2) GDPR also applies to competing claims for damages and injunctive relief under national law (see Auernhammer/v. Lewinski, GDPR/BDSG, 8th ed. 2024, GDPR, Article 79, para. 6), since international jurisdiction with regard to these claims would otherwise arise from Article 17(1)(c) and Article 18(1) of the Brussels I Regulation.

B.

Paragraph 104

Regarding the individual claims:

Paragraph 105

Claim No. 1 (Declaratory Judgment):

Paragraph 106

With Claim No. 1, the plaintiff seeks a declaration that the parties' user agreement does not permit the processing of specifically identified personal data of the plaintiff.

Paragraph 107

The claim in point 1 is inadmissible. The declaratory judgment action lacks the necessary legal interest.

Paragraph 108

Pursuant to Section 256 Paragraph 1 of the German Code of Civil Procedure (ZPO), an action may be brought to establish the existence or non-existence of a legal relationship if the plaintiff has a legitimate interest in having the legal relationship established as soon as possible.

1.

Paragraph 109

A legal relationship is required, i.e., a connection between a person and another person or thing resulting from a specific set of facts, which contains a subjective right that can be established with res judicata effect or from which such a right can arise (Zöller/Greger, ZPO, 36th ed., Section 256, para. 4).

Paragraph 110

Such a legal relationship exists. A user agreement exists between the parties regarding the defendant's social network, and the subject of the declaratory judgment action is whether this user agreement gives rise to a right for the defendant to process personal data of the plaintiff that the defendant obtained through third-party business tools (contra: Higher Regional Court of Dresden, judgment of February 3, 2026, 4 U 292/25, juris, para. 136 et seq.; similarly, Higher Regional Court of Naumburg, judgment of February 5, 2026, 9 U 44/25, juris, para. 157; Higher Regional Court of Munich, judgment of December 18, 2025, 14 U 881/25, GRUR-RS 2025, 36464, para. 51).

2.

Paragraph 111

However, the necessary legal interest in a declaratory judgment is lacking. The priority of an action for performance precludes a declaratory judgment.

Paragraph 112

A declaratory judgment is not warranted if an action for performance is possible and reasonable for the plaintiff, and if such an action would fully satisfy its objective (Zöller/Greger, loc. cit., § 256, para. 14). An action for performance in this sense also includes an (preventive) injunction (Federal Court of Justice, NJW-RR 2016, 1404, para. 16).

Paragraph 113

An action for performance is possible. For past events, the plaintiff can demand quantified damages and the deletion or anonymization of data already collected; for future events, the plaintiff can demand an injunction. These actions fully satisfy their objective.

Paragraph 114

Certainty regarding the currently existing legal relationship can also be obtained by means of an injunction, which, if successful, can also be enforced against the defendant should the latter fail to comply with the injunction. The plaintiff's reference to the Federal Court of Justice's reasoning in the judgment on data scraping (Federal Court of Justice, judgment of November 18, 2024, VI ZR 10/24, para. 48) is not convincing in this respect, as the two declaratory judgment claims are not comparable. The declaratory judgment claim assessed by the Federal Court of Justice sought a declaration of the defendant's liability for future damages and not—as in the present case—a declaration that the user agreement does not permit the processing of personal data. Furthermore, with data scraping, the ongoing publication of personal data on the internet carries the risk of misuse of this data by third parties. This risk does not exist in the present case, as the data is merely stored with the defendant, and the plaintiff can proceed with the injunction against the defendant.

3.

Paragraph 115

The action is also inadmissible as an interlocutory declaratory judgment.

a)

Paragraph 116

Contrary to the wording of the statute, an interlocutory declaratory judgment is admissible even if—as in this case—a dispute existed between the parties regarding the legal relationship before the proceedings (Becker-Eberhard in MüKo/ZPO, 7th ed. 2025, § 256, para. 83).

b)

Paragraph 117

However, an interlocutory declaratory judgment requires that the legal relationship be prejudicial. This relationship must be a necessary element for the subsumption inference contained in the main decision (Becker-Eberhard in MüKo/ZPO, ibid., § 256, para. 85). This is not the case.


Paragraph 118

With the declaratory judgment action, the plaintiff seeks a declaration that the contractual relationship between the parties does not grant the defendant the right to process the plaintiff's data on third-party websites and apps without the plaintiff's consent or another legal justification. In particular, the plaintiff seeks a declaration that the clauses in the defendant's general terms and conditions that grant the defendant the right to process the data in question even without consent are invalid and that the defendant does not have the right to continuously collect all of the plaintiff's data on third-party websites and apps without cause (Reply, pp. 65, 68).

Paragraph 119

Such a declaration is not necessary for the decision on the other claims.

Paragraph 120

For the injunction claim, the declaratory judgment sought by the plaintiff is irrelevant, as the injunction claim must be dismissed due to the defendant's lack of standing as an infringer. For a claim for damages, a violation of the General Data Protection Regulation (GDPR) by the defendant is a prerequisite. The data processing in question must therefore not be covered by any of the legal bases for processing under Article 6(1) or Article 9(2) GDPR. However, the necessary finding is not identical to the question of whether the general terms and conditions of the contract concluded between the parties grant the defendant the right to process the plaintiff's data on third-party websites and apps, irrespective of the plaintiff's consent and irrespective of any other legal justification.

Paragraph 121

Claim No. 2 (Injunction):

Paragraph 122

With Claim No. 2, the plaintiff seeks an injunction against the defendant, prohibiting the processing of personal data pursuant to Claim No. 1 on third-party websites and apps outside the defendant's networks – without consent or a legal basis pursuant to Article 6(1)(b) to (e) GDPR.

1.

Paragraph 123

The claim in point 2, both according to its wording and the grounds for the claim, seeks to prohibit the defendant from processing the plaintiff's personal data located on third-party websites and third-party apps. This does not refer to data already transmitted to the defendant by the third-party companies, but rather to data processing carried out prior to that transmission by the business tools on the third-party websites and apps. This is clear not only from the unambiguous wording of the claim, but also from its reasoning. In its reply, the plaintiff expressly addresses the defendant's (joint) responsibility for data processing on the third-party websites and apps and states that the subject of this claim is data that has not already been processed by the defendant (i.e., on its own websites and servers). That the plaintiff understands its claim in this sense is also demonstrated by its arguments in the statement of grounds of appeal regarding the merits of claim no. 2. The plaintiff states there that the initial collection of data by the business tools results in this data being automatically transmitted to the defendant's servers. Therefore, it is necessary to effectively prevent the data processing operations that precede the final storage on the defendant's servers.

2.

Paragraph 124

The plaintiff's appeal is unfounded.

Paragraph 125

A claim for injunctive relief does not arise from Article 17 GDPR.

Paragraph 126

Article 17 GDPR grants a right to erasure, but not a right to an injunction (ECJ, Judgment of 4 September 2025, C-655/23, para. 43). The General Data Protection Regulation (GDPR) does not, however, preclude provisions of national law from which claims for injunctive relief may arise (ECJ, loc. cit., paras. 46 et seq.).

Paragraph 127

Therefore, a claim for injunctive relief pursuant to Sections 823 and 1004 of the German Civil Code (BGB) due to infringement of the general right of personality is conceivable.

a)

Paragraph 128

The plaintiff's general right of personality is affected. Personal data is among the protected legal interests within the scope of the general right of personality (Grüneberg/Sprau, BGB, 85th ed. 2026, Introductory Note to Section 823, para. 33). It can be assumed that the plaintiff visited websites that had implemented the defendant's business tools and that the plaintiff's personal data was collected and transmitted to the defendant in the process.


Paragraph 129

The plaintiff asserted this in general terms in the first instance and specified it with regard to individual websites in the second instance. The general submissions in the first instance were sufficient, as the plaintiff had thereby presented all the facts necessary to substantiate the asserted right in a coherent manner. Nothing more was required (see Zöller/Greger, loc. cit., § 138, para. 8a).

Paragraph 130

The defendant cannot argue that the plaintiff is required to specifically name the websites it visited. It is incumbent upon the defendant to contest the plaintiff's submissions if, to the defendant's knowledge, the plaintiff never visited websites using the defendant's business tools or if the defendant never received any personal data from the plaintiff resulting from such visits. This is also possible for the defendant, as it can see from its systems which data it processes and whether and how this affects the plaintiff's personal data (see Naumburg Higher Regional Court, Judgment of February 5, 2026, 9 U 44/25, juris, para. 289).

Paragraph 131

The defendant does not effectively deny that the plaintiff visited websites on which the defendant's business tools were installed. The defendant denied the plaintiff's corresponding assertion (only) for lack of knowledge. The Senate understands the defendant's denials in subsequent pleadings in the same way. This denial for lack of knowledge is inadmissible, as the question of which data was transmitted to the defendant concerns an area that falls within the defendant's own knowledge (see Hamm Higher Regional Court, Judgment of March 9, 2026, I-8 U 13/25, judgment transcript p. 21).

b)

Paragraph 132

The plaintiff has convincingly demonstrated that its personal data, collected during its visits to websites with the defendant's implemented business tools, was processed unlawfully.

Paragraph 133

The defendant relies on the fact that the processing of the plaintiff's personal data on third-party websites and apps where its business tools are implemented is lawful, based on the plaintiff's consent pursuant to Article 6(1)(a) GDPR when visiting the website or using the app.

aa)

Paragraph 134

Justification for data processing based on the plaintiff's consent to the operator of the website containing one or more of the defendant's business tools is generally possible.

Paragraph 135

According to the terms of use of the business tools, the operator of the website who integrates a business tool of the defendant into their website must ensure that they have all the necessary rights and authorizations, as well as a legal basis, for disclosing and using the business tool data.

Paragraph 136

The applicant's view that the defendant cannot delegate the responsibility for obtaining consent to the respective website operator because it is solely or at least jointly responsible with the website operator for the processing of data by its business tools is incorrect. The decision of the CJEU cited by the applicant as evidence for its legal position (CJEU, Judgment of 29 July 2019 – C-40/17 – “Like” Button – Fashion ID) states the opposite, namely that the responsibility for obtaining consent for the processing of personal data lies with the website operator and not with the defendant. Although the CJEU states in the aforementioned decision that the website operator and the defendant, as the provider of the business tools, jointly decided on the means underlying the collection of personal data of website visitors and its transfer by transmission, as well as on the purposes of the collection and transfer of the data by transmission (CJEU, ibid., paras. 79, 81), the website operator is therefore also to be considered a controller (CJEU, ibid., para. 85). However, the necessary consent of the data subject for the collection of the data and its transfer by transmission to the defendant must be obtained by the website operator, not by the defendant, since the processing of the personal data is triggered by a visitor accessing the operator's website (CJEU, ibid., para. 102).


The CJEU is therefore also to be considered a controller (CJEU, ibid., para. 85). bb)

Paragraph 137

The defendant claims that the plaintiff gave consent pursuant to Article 6(1)(a) GDPR when visiting third-party websites and apps on which the defendant's business tools are implemented. As the (joint) controller, the defendant bears the burden of proof and the burden of production to demonstrate that the data subject gave consent and that the consent meets the requirements of Article 4(11) GDPR and Article 7 GDPR. The plaintiff disputed the latter.

c)

Paragraph 138

However, in the present case, it is unnecessary to determine whether the plaintiff gave the required consent, because even if the plaintiff did not give valid consent, the defendant cannot be held liable for an injunction against the data processing taking place on the third-party company's website.

Paragraph 139

The claim for injunctive relief analogous to Sections 823 Paragraph 1 and 1004 of the German Civil Code (BGB) requires that the person against whom the injunction is sought be a disturber of the peace. The defendant lacks this disturber status.

aa)

Paragraph 140

A disturber of the peace is anyone who, even without being a perpetrator or accomplice, willfully and with adequate causation contributes in any way to the impairment of the legally protected interest or whose conduct gives rise to a fear of impairment, regardless of the nature and extent of their contribution. If the impairment has its direct cause in the conduct of third parties, the breach of duties to act is additionally required. Apart from specific statutory obligations, these duties are generally determined by the extent to which the responsible party contributes to the impairment and whether reasonable means of intervention are available to them (Grüneberg/Sprau, loc. cit., before Section 823, paragraphs 31, 35).


A disturber of the peace is anyone who, even without being a perpetrator or accomplice, willfully and with adequate causation contributes to the impairment of the legally protected interest in any way, or whose conduct gives rise to a fear of impairment, regardless of the nature and extent of their contribution. bb)

Paragraph 141

Although the defendant intentionally and with adequate causation contributed to the infringement of the general right of personality of the affected website visitor in the absence of consent or ineffective consent, the defendant cannot claim that it did not integrate the business tools into the third-party company's website itself, since it provided the business tools specifically for the purpose of integration into the third-party company's website or app. However, a further requirement is that the defendant breached its duties, because the infringement has its direct cause in the conduct of the website operator, who may have collected and transmitted the data without a sufficient legal basis, contrary to the agreement reached with the defendant. The mere fact that the defendant developed the business tools at issue in these proceedings and made them available to third-party companies does not, therefore, mean that it should be considered a direct infringer (contra: Higher Regional Court of Dresden, judgment of March 12, 2026, 17 U 625/25, judgment transcript p. 56).

Paragraph 142

It is not apparent that the defendant violated any duties of care arising from the specific provisions of the General Data Protection Regulation (GDPR).

(1)

Paragraph 143

The defendant is (jointly) the controller for the data processing carried out by means of the business tools.

Paragraph 144

According to Article 4(7), first sentence, of the GDPR, the controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing. If two or more controllers jointly determine the purposes and means of processing, they are joint controllers (Article 26(1), first sentence, GDPR).

(2)

Paragraph 145

However, it is not apparent that the defendant has breached any obligations arising from joint controllership within the meaning of Article 26 GDPR.

Paragraph 146

It has already been explained above that the third-party contractor, not the defendant, is responsible for obtaining consent. The defendant has also not breached the obligation under Article 26(1), second sentence, and (2) GDPR to establish in a transparent manner in an agreement with the third-party contractor which of them fulfills which obligation under the General Data Protection Regulation. It is undisputed that the defendant informs the third-party contractors within the framework of the agreement that they are responsible for obtaining valid consent. The terms of use for the business tool, in which the defendant informs third-party companies that they must obtain valid consent, suffice as an agreement within the meaning of Article 26 GDPR, since Article 26 GDPR does not contain a specific formal requirement for the agreement (Auernhammer/Schreibauer, loc. cit., Article 26 GDPR, para. 17).

Paragraph 147

The plaintiff has not alleged any other breach of duties by the defendant.

(3)

Paragraph 148

Article 26(3) GDPR does not mean that the plaintiff can nevertheless seek an injunction against the defendant.

Paragraph 149

According to Article 26(3) GDPR, the data subject may, irrespective of the details of the agreement concluded by the defendant with the respective third-party company, assert their rights under the General Data Protection Regulation against each of the controllers. These claims, however, are limited to the rights of the data subject under Chapter 3 of the GDPR (Bertermann in Ehmann/Selmayer, GDPR, 3rd ed. 2024, Art. 26, para. 29; Spoerr in BeckOK Datenschutzrecht, as of August 1, 2025, Art. 26, para. 58). Claims for injunctive relief are therefore not covered by Art. 26(3) GDPR, because they are not provided for in Art. 12 to 23 GDPR (Bertermann, ibid.). The result remains the same even if, according to the wording of the provision, not only the rights of the data subject under Chapter 3 GDPR are meant, but all rights regulated in the General Data Protection Regulation, because the claim for injunctive relief is not regulated in the General Data Protection Regulation itself, but arises additionally from the provisions of national law.



Art. 26(3) GDPR does not provide for these rights. Paragraph 150

Claim No. 3 (Storage):

Paragraph 151

The plaintiff's appeal is successful with respect to the claim that the defendant is ordered to leave the processed data unchanged and not to delete it. It is unfounded insofar as the plaintiff seeks an order requiring the defendant to leave the data at its current location.

1.

Paragraph 152

With Claim No. 3, the plaintiff seeks an order compelling the defendant to leave the data specified in Claim No. 1 unchanged at its current location, not to alter it, not to disclose it to third parties, and to delete the data only after providing the information requested in Claim No. 4.

Paragraph 153

The plaintiff expressly clarified during the appeal hearing that the claim is solely aimed at ensuring that the data remains unchanged at its current location with immediate effect. This claim does not seek future deletion. This is the subject of application no. 5. Therefore, only the request for unchanged storage of the data and the prohibition of the transfer of the data to third parties needs to be assessed.

2.

Paragraph 154

The legal basis for the plaintiff's request is Article 18 GDPR.

Paragraph 155

Article 18(1) GDPR grants a data subject the right, under the conditions specified therein, to request from the controller the restriction of processing.

Paragraph 156

According to Article 4(3) GDPR, the restriction of processing means the marking of stored personal data with the aim of limiting its future processing. If processing has been restricted, the personal data may – apart from being stored – only be processed with the data subject's consent or if the other conditions specified in Article 18(2) GDPR are met. In substance, the restriction of processing corresponds to the concept of blocking (Auernhammer/Eßer, loc. cit., Article 4, para. 62).


3.

Paragraph 157

The restriction of processing can be requested by the data subject, among other things, if the processing is unlawful and the data subject objects to the erasure of the personal data and instead requests the restriction of its use (Article 18(1)(b) GDPR).

Paragraph 158

The aforementioned conditions are met.

a)

Paragraph 159

The processing of the data by the defendant was unlawful.

aa)

Paragraph 160

The plaintiff has not substantiated its claim that the defendant used the plaintiff's personal data for advertising purposes in the past. In any case, the plaintiff has not offered any evidence for such a claim. The plaintiff merely asserts in general terms that the defendant unlawfully processed its personal data. No more specific arguments have been presented. Insofar as the plaintiff argues that the settings of the "Optional Cookies" and "Information on Advertising Partner Activities" buttons have no effect whatsoever on the functionality of the business tools and the data processing taking place within them for the plaintiff, and supports this claim with expert evidence, this argument does not constitute an allegation that the defendant used the plaintiff's personal data for advertising purposes without the plaintiff's consent.

bb)

Paragraph 161

However, the processing of the plaintiff's data is unlawful because the defendant indisputably stores the plaintiff's personal data for security and integrity purposes and, despite a court order, has failed to provide the necessary evidence that this is permissible under Article 6(1)(f) GDPR.


(1)

Paragraph 162

According to Article 6(1)(f) GDPR, the processing of personal data is lawful if the processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.

Paragraph 163

Legitimate interests in this sense also include the prevention of fraud (Recital 47, sixth sentence). The processing of personal data by operators of electronic communications networks and services also constitutes a legitimate interest of the respective controller to the extent that it is strictly necessary and proportionate for ensuring network and information security, i.e., insofar as it ensures the ability of a network or information system to reliably prevent disruptions or unlawful or malicious interference that could compromise the availability, authenticity, completeness, and confidentiality of stored or transmitted personal data, as well as the security of related services offered or accessible via those networks or information systems. Such a legitimate interest may, for example, consist of preventing unauthorized access to electronic communications networks and the dissemination of malicious code, as well as preventing attacks in the form of targeted server overload ("denial-of-service" attacks) and damage to computer and electronic communications systems (Recital 49).

Paragraph 164

The processing must be necessary for the purposes of the legitimate interest. The necessity for data processing ceases to exist if there are also suitable, demonstrably effective alternative methods of data processing that are less burdensome for the data subjects under data protection law (Auernhammer/Kramer, loc. cit., Art. 6, para. 79). The factual basis that is intended to support the necessity of the data processing must be presented by the controller (Albers/Veit in BeckOK DatenschutzR, loc. cit., GDPR Art. 6, para. 69).

Paragraph 165

If the storage of data is necessary for security purposes, it must be examined whether the interests or the fundamental rights and freedoms of the data subjects outweigh the interest in processing. A preponderance of the data subjects' interests is not automatically ruled out. It depends on which data is stored and processed, to what extent, and for what period (Auernhammer/Kramer, loc. cit., Art. 6, para. 88).


(2)

Paragraph 166

The defendant argued in the first instance that the storage of the data was necessary for security and integrity purposes, including monitoring attempted attacks on the defendant's systems, such as the forced overloading of the website.

Paragraph 167

However, despite the court's request, the defendant failed to specify the security and integrity purposes in more detail. She continues to assert, only in general terms, that she uses the data collected via the business tools.

Paragraph 168

- to detect anomalous activity that might be intended to disrupt the defendant's services, such as atypical patterns in download speeds or anomalous device/network activity,

Paragraph 169

- for troubleshooting and operational data collection,

Paragraph 170

- to detect hostile actors whose actions might violate the defendant's policies, such as hacking activities, data from prohibited sources, security risks, particularly for minors, potential criminal activities by dangerous organizations, and manipulation tactics, including coordinated counterfeit behavior.

Paragraph 171

This general assertion is insufficient. It fails to specify which of the plaintiff's data the defendant processes for security and integrity purposes, how this processing occurs, why the processing of the data is necessary for the stated security and integrity purposes, and how long the defendant stores the data for these purposes. Such information is required because it is the only way to determine whether the processing of personal data is necessary to protect the legitimate interest claimed by the defendant and whether this interest outweighs the plaintiff's interests and fundamental rights and freedoms. The defendant is aware of this, as evidenced by its response to the court's request for clarification, and lists the above questions in paragraph 1 of its brief. Nevertheless, the following statements do not provide a single answer to any of these questions.

Paragraph 172

Further arguments presented in the brief of March 27, 2026, are also insufficient to substantiate the claimed security and integrity purposes. To the extent that the defendant states in this pleading that it deletes data from its systems within three hours, this timeframe refers to the example presented at this point. The defendant's statement at the relevant point does not indicate that it generally deletes data transmitted to it via business tools after three hours (see paragraphs 17 et seq. of this pleading). Furthermore, the defendant only deletes the data if it deems no further investigation necessary. It remains unclear what criteria the defendant uses to determine this necessity. In any case, there is no concrete connection here to the plaintiff's personal data stored by the defendant.

(3)

Paragraph 173

The conditions for the lawfulness of processing this data, as set out in Article 6(1)(b) to (e) of the GDPR, are also not met.

Paragraph 174

Any potential justification for the data processing fails because the defendant does not specify with sufficient precision which data it collects and for what purpose.

(4)

Paragraph 175

The defendant's further objection that it must process the data it receives in order to determine whether the data is associated with an account held with it and whether processing is permissible according to the account settings is unfounded. A comparison of the incoming data with existing accounts is only possible if the data was lawfully collected. If the data was lawfully collected, for example, based on the data subject's consent to the collection and transfer of this data to the defendant, then this consent also covers the comparison with existing data. However, if the data was unlawfully collected, the defendant has no legitimate interest in determining whether the data is associated with an account held with it.

b)

Paragraph 176

The further requirement for the claim for restriction of processing, namely that the data subject refuses erasure, is also met. The plaintiff has made a corresponding request, at least in its application point 3, not to erase the data until the information is provided.

4.

Paragraph 177

However, the prohibition sought by the applicant does not fully correspond to the legal consequences associated with a restriction. The requirement that the data remain at the stored location is not covered by the legal basis for the claim.

a)

Paragraph 178

The right to restriction of processing does not imply that the data must remain at the stored location, as Recital 67 expressly provides that the data may be temporarily transferred to another processing system. In this respect, the claim is therefore unfounded, and the appeal is unsuccessful.

b)

Paragraph 179

Furthermore, the application in point 3 is well-founded.

Paragraph 180

Once the processing has been restricted, the controller is prohibited from altering the data, using it internally, or disclosing it to third parties (see Auernhammer/Stollhoff, loc. cit., Art. 18, para. 25). The controller is no longer permitted to delete the data, because even the deletion of data constitutes processing according to the legal definition in Article 4(2) GDPR. The controller therefore does not have the option of deleting the data instead of restricting its processing (Auernhammer/Stollhoff, loc. cit., Article 18, para. 26).

Paragraph 181

The plaintiff's claim is not precluded by the fact that, according to Article 18(2) GDPR, personal data may be processed even if its processing has been restricted pursuant to Article 18(1) GDPR, if the data subject consents or if this is done for the establishment, exercise, or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State. The defendant has not argued that any of these conditions are met. It is therefore not to be assumed that the requested prohibition on further internal use of the data and on disclosing it to third parties would be too broad, as it would also encompass permissible conduct.

Paragraph 182

Claim No. 4 (Information):

Paragraph 183

The plaintiff seeks information about the personal data processed by the defendant and linked to its user account since its creation, in particular, but not exclusively, due to the defendant's business tools. The information should include, for each piece of personal data collected, whether and when it was disclosed to third parties and, if so, the names of those third parties; whether and, if so, when the defendant stored this data in which third country; and to what extent the plaintiff's personal data was and is being used for automated decision-making, including profiling.

Paragraph 184

The plaintiff has a right of access to the data from the defendant pursuant to Article 15(1) GDPR.


a)

Paragraph 185

The defendant undisputedly processes the plaintiff's personal data pursuant to Article 4(1) and (2) GDPR, because, in particular, the defendant uses M... Business Tools to collect and store both standard technical data and so-called event data.

Paragraph 186

The defendant is also a controller pursuant to Article 4(7) GDPR (see also point 2(b)(aa)).

b)

Paragraph 187

Consequently, pursuant to Article 15(1), second sentence, GDPR, the plaintiff has a right of access to this personal data and further information, specifically listed in Article 15(1)(a) to (h) GDPR. The right of access thus includes, among other things, information about the purposes of the processing (Art. 15 para. 1 lit. a) GDPR), the recipients to whom the personal data have been or will be disclosed, in particular recipients in third countries (Art. 15 para. 1 lit. c) GDPR), and also the existence of automated decision-making, including profiling pursuant to Article 22 paragraphs 1 and 4 GDPR and – at least in these cases – meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject (Art. 15 para. 1 lit. h) GDPR).

Paragraph 188

The right of access also includes the question of when and in which third country the defendant stored data.

Paragraph 189

Art. 15 para. 1 GDPR includes – in the Senate's view – an obligation to provide information regarding data storage in third countries. In particular, Article 15(2) GDPR does not limit the obligation to provide information under Article 15(1) GDPR. This is already contradicted by the fact that Article 15(1)(c) GDPR expressly mentions the obligation to provide information about recipients in third countries. Moreover, such an interpretation contradicts the purpose of Article 15 GDPR, which is to enable data subjects to understand whether and how their personal data is processed, thus allowing them to make an informed and comprehensive assessment of the lawfulness of the processing. This includes knowing which of their personal data is transferred to a third country (see also Higher Regional Court of Jena, judgment of March 2, 2026, 3 U 31/25, BeckRs 2026, 2610, para. 73).


[See also Higher Regional Court of Jena, judgment of March 2, 2026, 3 U 31/25, BeckRs 2026, 2610, para. 73.] c)

Paragraph 190

The asserted right to information has not been extinguished by the defendant's statement in the information letter of August 8, 2024 (Exhibit B 8 LGA), according to which no processing of the plaintiff's personal data takes place for the purpose of providing personalized advertising, nor by the reference to the so-called self-help tools or the provision of corresponding instructions pursuant to Section 362 of the German Civil Code (BGB).

aa)

Paragraph 191

A right to information is generally fulfilled within the meaning of Section 362 Paragraph 1 of the German Civil Code (BGB) if the information provided, according to the debtor's stated intention, constitutes the information owed in its entirety. If the information is provided in this form, any potential inaccuracies in its content do not preclude fulfillment.

Paragraph 192

It is therefore essential for the fulfillment of the right to information that the party obligated to provide the information expresses, possibly implicitly, that the information is complete, i.e., that it fully covers the subject matter of the request for information (Federal Court of Justice, Judgment of June 15, 2021 – VI ZR 576/19 –, paragraphs 19-20, juris).

bb)

Paragraph 193

It is already evident from the defendant's reply (Exhibit B8 LGA) that the response only pertains to a limited area, namely the processing of personal data for the purpose of providing personalized advertising, and that the defendant otherwise referred to the self-help tools. However, this is insufficient for providing complete information; conversely, the defendant's deliberate limitation of the information, which, moreover, finds no justification or basis in the request for information, makes the incompleteness of the information apparent.


Paragraph 194

The reference to the self-service tool also fails to satisfy the right to information, because, based on the plaintiff's undisputed submissions, this tool is particularly unsuitable for disclosing the relevant processing of personal data outside the social network (so-called "off-F data") (see Jena Higher Regional Court, Judgment of March 2, 2026, 3 U 31/25 BeckRS 2026, 2610, para. 70; Munich Higher Regional Court, Judgment of December 18, 2025 - 14 U 2300/25e, GRUR-RS 2025, 36459, para. 138).

Paragraph 195

Claim No. 5 (deletion and anonymization):

Paragraph 196

With Claim No. 5, the plaintiff seeks an order compelling the Defendant,

Paragraph 197

to completely delete all of the plaintiff's data specified in claim no. 1 a) four weeks after full disclosure has been provided (hereinafter 1.),

Paragraph 198

to confirm the deletion to the plaintiff (hereinafter 2.),

Paragraph 199

to completely anonymize all personal data already stored since May 25, 2018, pursuant to claims 1 b) and c) (hereinafter 3.).

1.

Paragraph 200

The request for deletion is admissible and well-founded.

a)

Paragraph 201

The request for deletion is admissible.

aa)

Paragraph 202

The action seeks deletion only after disclosure has been provided. The claim for deletion is not due until the specified date because the plaintiff expressly requests the storage of the data until that date. It is therefore an action for future performance (cf. Higher Regional Court). Naumburg, loc. cit., para. 308).

Paragraph 203

An action for future performance is only admissible under the conditions of Sections 257 to 259 of the German Code of Civil Procedure (ZPO) (Foerste in Musielak/Voit, ZPO, 22nd ed. 2025, Section 257, para. 6). According to Section 259 ZPO, an action for future performance may be brought if, under the circumstances, there is justified concern that the debtor will evade timely performance. For this concern to exist, it suffices that the debtor seriously disputes the claim or the obligation to perform. Bad faith or even malicious intent is not required (Becker-Eberhard in MüKo/ZPO, loc. cit., Section 259, para. 13).

Paragraph 204

The defendant seriously disputed that it was obligated to delete the personal data and, in this respect, referred to the fact that it The defendant is authorized to continue storing the data for security and integrity reasons. The defendant has thus seriously contested its obligation to perform. The prerequisites for an action for future performance are therefore met.

bb)

Paragraph 205

The admissibility of the action is not precluded by the fact that the deletion depends on the provision of information, i.e., on a suspensive condition. This circumstance does not alter the sufficient specificity of the claim.

Paragraph 206

A claim is generally sufficiently specific if it concretely identifies the claim being asserted, thereby defining the scope of the court's decision-making authority (Section 308 of the German Code of Civil Procedure), clarifies the content and extent of the res judicata effect of the requested decision (Section 322 of the German Code of Civil Procedure), does not shift the risk of the plaintiff losing the case to the defendant through avoidable imprecision, and finally allows for enforcement of the judgment without further litigation in enforcement proceedings (Federal Court of Justice, NJW). 1999, 954).

Paragraph 207

From all these perspectives, there is, in principle, no objection to a due date for the requested deletion that is contingent upon the provision of information. The Federal Court of Justice's decision cited above concerned a claim for payment of monthly compensation for use until the return of the property. There are no apparent reasons to assess the specificity of the request differently for a deletion request after the provision of information. The Federal Court of Justice's considerations also apply in the present case. Whether the information requested under claim no. 4 has been provided by the defendant can generally be determined easily and reliably. The necessary examination can be carried out before the commencement of enforcement proceedings in the enforcement clause procedure, as this is a condition precedent (§§ 726, 731 of the German Code of Civil Procedure).

cc)

Paragraph 208

The application is also not inadmissible due to a lack of specificity regarding the data to be deleted or anonymized.


Paragraph 209

There is no doubt as to the specificity of the application. The data in question is specifically identified by its origin. The decision concerns only this data; therefore, there is no doubt as to the content and scope of the res judicata effect. Enforcement of the judgment is possible pursuant to Section 888 of the German Code of Civil Procedure (ZPO), since the deletion or anonymization of the data stored by the defendant constitutes a non-delegable action.

b)

Paragraph 210

The claim for erasure is also well-founded.

Paragraph 211

The right to erasure of personal data that is unlawfully processed is governed by Article 17(1)(d) GDPR. According to this provision, the controller must erase personal data that has been unlawfully processed without undue delay if the data subject so requests.

Paragraph 212

The aforementioned requirements are met. With regard to the unlawful processing, reference is made to the above statements concerning claim no. 3. A request from the plaintiff has also been made. The fact that the plaintiff does not request immediate erasure, but rather erasure at a later date, is not detrimental, because the requirement for a claim, according to the purpose of the provision, is not a demand for immediate erasure, but only a request for erasure that the controller must then comply with without undue delay (see Kamann/Braun in Ehmann/Selmayr, loc. cit., Art. 17, para. 42).

2.

Paragraph 213

The plaintiff's appeal regarding the asserted claim for confirmation of erasure is unfounded.

Paragraph 214

The right to confirmation of erasure arises in principle from Article 12(3), first sentence, GDPR. According to this provision, the controller must provide the data subject with information about the measures taken in response to a request pursuant to Articles 15 to 22 GDPR – including a request for erasure pursuant to Article 17 GDPR – without undue delay and at the latest within one month.
























































] . ... Paragraph 215

This claim also concerns a claim for future performance, as the deletion has not yet taken place and, according to the plaintiff, is not yet intended to take place.

Paragraph 216

The application is inadmissible because the requirements for an application for future performance are not met. In particular, there is no concern of non-performance within the meaning of Section 259 of the German Code of Civil Procedure (ZPO), because the defendant has never disputed its obligation to confirm the deletion of the plaintiff's personal data should it delete the plaintiff's data.

3.

Paragraph 217

Furthermore, the plaintiff's appeal regarding the claim for complete anonymization of the data pursuant to claim nos. 1 b) and c) is unfounded.

a)

Paragraph 218

The application is admissible. The plaintiff's need for legal protection is not diminished simply because, with regard to data anonymization, it is possible to separate the data from previous activities from the plaintiff's account. This possibility does not negate the plaintiff's interest in obtaining the requested anonymization. Data is considered anonymized when the data in question cannot be, or can no longer be, identified (Auernhammer/Eßer, loc. cit., Art. 4, para. 72). However, separating the data would only result in anonymization if it were guaranteed that re-establishing the link to a specific individual would require a disproportionate expenditure of time, costs, and manpower (Auernhammer/Eßer, loc. cit., Art. 4, para. 73). The defendant's submissions do not indicate that this is the case.


Data is considered anonymized when the data in question cannot be, or can no longer be, identified (Auernhammer/Eßer, loc. cit., Art. 4, para. 72). b)

Paragraph 219

Contrary to its misleading wording, the application is not substantively contradictory to application no. 3. According to application no. 3, the defendant is to leave the stored data unchanged at its current location; according to application no. 5, the defendant is to anonymize the data. However, the plaintiff has clarified that the anonymization request made with regard to the data pursuant to application no. 1 b) and c) is subject to the same condition as the deletion request with regard to the data pursuant to application no. 1 a), namely the condition that anonymization is to take place only after the disclosure of the data.

c)

Paragraph 220

However, the request for anonymization is unfounded, as there is no legal basis for the requested anonymization of the data. While the General Data Protection Regulation (GDPR) grants a right to erasure under certain conditions, it does not grant a right to anonymization. To the extent that the plaintiff argues, by way of a fortiori reasoning, that the right to anonymization is contained as a "lesser" right within the right to erasure under Article 17 GDPR, this argument cannot be accepted, because how the controller fulfills the data subject's right to erasure is its own affair (Kamann/Braun in Ehmann/Selmayer, loc. cit., Article 17, para. 40), especially since anonymization can entail greater effort than erasure.





















... Paragraph 221

The Higher Regional Courts of Munich, Naumburg, and Hamm have also ruled in this sense (Higher Regional Court of Munich, Judgment of December 18, 2025, 14 U 881/25, GRUR-RS 2025, 36464, para. 138; Higher Regional Court of Naumburg, Judgment of February 5, 2026, 9 U 44/25, juris, para. 320; Higher Regional Court of Hamm, Judgment of March 9, 2026, I-8 U 13/25, judgment transcript p. 32). The fact that the aforementioned Higher Regional Courts ordered the defendant to delete the data instead of anonymizing it is solely due to the fact that in those cases, the plaintiff had requested anonymization or, "alternatively at the defendant's discretion," deletion. This is different in the present case. The plaintiff has requested anonymization only with regard to points 1 b and c of the statement of claim.

Paragraph 222

The contrary view of the Higher Regional Court of Dresden, which recognizes a right to anonymization (judgment of February 3, 2026, 4 U 292/25, juris, para. 191; judgment of March 17, 2026, 4 U 709/25, judgment transcript p. 28), cannot be followed. The Higher Regional Court of Dresden argues that the controller can also comply with the obligation to delete data by means of appropriate anonymization if the data subject requests anonymization. The fact that the controller can also fulfill their obligation to erase data by anonymizing it does not mean that they are obligated to do so, because the controller has discretion regarding the means and procedures for erasure, provided that the selected measures lead to the required erasure (Kamann/Braun in Ehmann/Selmayr, loc. cit., Art. 17, para. 40).

Paragraph 223

Claim No. 6 (Damages):

Paragraph 224

The appeal regarding Claim No. 6, in which the plaintiff seeks non-pecuniary damages in the amount of at least €5,000.00, is justified in the amount of €500.00.

Paragraph 225

The legal basis for the plaintiff's claim is Art. 82 GDPR. According to Article 82(1) GDPR, any person who has suffered material or non-material damage as a result of an infringement of the General Data Protection Regulation has the right to compensation from the controller. The prerequisites for a claim for compensation are therefore an infringement of the General Data Protection Regulation, the existence of non-material damage, and a causal link between the damage and the infringement, with these three prerequisites being cumulative (Federal Court of Justice, Judgment of November 18, 2024, VI ZR 10/24, para. 21).

1.

Paragraph 226

An infringement of the General Data Protection Regulation has occurred.


a)

Paragraph 227

For the claim for non-pecuniary damages, both any violations of the General Data Protection Regulation (GDPR) during the collection of personal data by the business tools, which fall under the joint responsibility of the defendant and the operator of the website using the business tools, and violations after the transfer of this data to the defendant must be taken into account, since the violations alleged by the plaintiff in this respect constitute a single subject matter of the dispute.

Paragraph 228

The subject matter of the dispute encompasses all alleged violations of the GDPR related to the incriminated data processing that, from a natural perspective, considering the parties' viewpoints and the essence of the matter, belong to the complex of facts at issue for the decision (Federal Court of Justice, Judgment of November 18, 2024, VI ZR 10/24, para. 17). From a natural perspective, the alleged violations of the General Data Protection Regulation cannot be assessed in isolation before and after the transfer of the data to the defendant, as they all stem from a single event, namely the provision of the business tools by the defendant and the implementation of these tools in the websites of the third-party companies.

b)

Paragraph 229

As explained above, the defendant's processing of the plaintiff's personal data transmitted to it via BusinessTool violates the General Data Protection Regulation (GDPR), as none of the conditions for processing the data set out in Article 6(1) GDPR are met.

2.

Paragraph 230

The plaintiff has also suffered damages.


a)

Paragraph 231

The concept of non-material damage in Article 82(1) GDPR encompasses negative feelings, such as worry or anger, experienced by the data subject as a result of the unauthorized disclosure of their personal data to a third party, and which

Paragraph 232

- result from a loss of control over that data,

Paragraph 233

- result from its potential misuse, or

Paragraph 234

- result from reputational damage

Paragraph 235


are caused, provided the data subject demonstrates that they experience such feelings and their negative consequences as a result of the infringement of this Regulation in question (ECJ, Judgment of 4 September 2025, C-655/23, GRUR-RS 2025, 22639, paragraph 64).

b)

Paragraph 236

In this context, the damage consists of a loss of control. The argument that the data was only passed on to the defendant and not to other third parties is not valid. The Federal Court of Justice (BGH) also affirmed a loss of control in a case where the personnel file management of federal civil servants was improperly carried out by employees of the State of Lower Saxony (BGH, NJW 2025, 1656, para. 14 et seq.). The fact that the employees of the State of Lower Saxony were bound by confidentiality did not preclude the finding of damage (BGH, ibid., para. 16). Furthermore, the plaintiff has no way of comprehending the scale of the data processing carried out by the defendant (see Higher Regional Court of Naumburg, judgment of February 5, 2026, 9 U 44/25, juris, para. 341) and has no means of regaining control over the data through its own actions, since neither changing the privacy settings nor deleting its account would result in the complete deletion of the data stored by the defendant (see Higher Regional Court of Dresden, judgment of February 3, 2026, 4 U 292/25, juris, para. 197). In light of this, a loss of control due to the unauthorized transfer of personal data to the defendant cannot be denied.

Paragraph 237

No other damage within the meaning of the case law of the CJEU is apparent. Damage to reputation resulting from the storage of the data transferred to the defendant is just as unlikely as concern about the potential misuse of the data. The plaintiff has neither alleged nor proven such consequences.

3.

Paragraph 238

The necessary causal link between the damage and the defendant's breach also exists. If the defendant had not processed, and in particular had not stored, the plaintiff's personal data transmitted to it via business tools, the plaintiff would not have suffered any loss of control over this data.

4.

Paragraph 239

Pursuant to Article 82(3) GDPR, the controller is exempt from liability under Article 82(2) GDPR if it proves that it is in no way responsible for the circumstances that caused the damage. Responsibility refers to fault in the sense of German legal terminology and not to data protection liability (Quaas in BeckOK Datenschutzrecht, 55th ed., as of February 1, 2026, GDPR, Art. 82, para. 17; Aliprandi, Datenschutzrechtlicher Schadensersatz nach Art. 82 DS-GVO, p. 448).

Paragraph 240

With regard to the data processing carried out by the defendant itself, an exemption from liability under Art. 82 para. 3 GDPR is clearly not applicable. No evidence has been presented to support the defendant's claim of lack of fault.

5.

Paragraph 241

The amount of non-material damages under Art. 82 para. 1 GDPR is governed by national law, as the General Data Protection Regulation does not establish rules for calculating damages owed under Art. 82 GDPR. Therefore, damages must be estimated pursuant to Section 287 of the German Code of Civil Procedure (ZPO), taking into account the EU principles of equivalence and effectiveness. The decisive factor is the amount required to ensure full and effective compensation for the damage suffered, as set out in Recital 146 of the GDPR, whereby neither the degree of fault nor the existence of a right to injunctive relief is to be taken into account as reducing the claim (see CJEU, Judgment of 4 September 2025, C-655/23, paragraphs 69, 72 et seq., 83).


The decisive factor is the amount required to ensure full and effective compensation for the damage suffered, as set out in Recital 146 of the GDPR, whereby neither the degree of fault nor the existence of a right to injunctive relief is to be taken into account as a mitigating factor (see CJEU, Judgment of 4 September 2025, C-655/23, paragraphs 69, 72 et seq., 83). Paragraph 242

It must be taken into account that the data processing by the defendant is particularly extensive, as it potentially involves unlimited data on the online activities of its users and can create the impression that users' private lives are being continuously monitored (Higher Regional Court of Dresden, loc. cit., para. 197; Higher Regional Court of Jena, judgment of March 2, 2026, 3 U 31/25, BeckRS 2026, 2610, para. 156). In particular, there is a risk that, even if consent is refused, the defendant will use the data obtained via the business tools to create a detailed profile of the user (Higher Regional Court of Dresden, loc. cit., para. 197). Furthermore, from the plaintiff's perspective, it cannot be ruled out that particularly sensitive data within the meaning of Article 9(1) GDPR, such as health data or data concerning sexual orientation, are also affected by the data processing in question, since the mere fact that the plaintiff clicks on articles with relevant topics on a website using business tools is sufficient for the transmission of sensitive data, and the plaintiff, like any other internet user, would likely not be able to trace their online activity in detail afterwards (see Higher Regional Court of Jena, judgment of March 2, 2026, 3 U 31/25, BeckRS 2026, 2610, para. 90). The feeling of being under constant surveillance can give rise to the desire to refrain from clicking on such articles or visiting websites with such topics (see Higher Regional Court of Dresden, loc. cit., para. 197; Higher Regional Court of Naumburg, judgment of February 5, 2026, 9 U 44/25, juris, para. 356).

Paragraph 243

After a comprehensive assessment, and for these reasons, the Senate considers damages in the amount of €500.00 to be appropriate.

6.

Paragraph 244

The plaintiff is not entitled to any further damages, even on the grounds of a violation of her general right of personality.

Paragraph 245

The fact that the plaintiff is entitled to damages under Article 82 GDPR does not preclude a claim for damages under Article 823(1) of the German Civil Code (BGB) for infringement of the general right of personality (Federal Court of Justice, Judgment of July 29, 2025, VI ZR 426/24, para. 36). The general right of personality also includes the right to informational self-determination, which ensures that information about a person is protected from non-transparent processing and use by private entities (Grüneberg/Retzlaff, loc. cit., § 823, para. 132).

Paragraph 246

According to the established case law of the Federal Court of Justice, however, a culpable infringement of the general right of personality gives rise to a claim for monetary compensation only if it constitutes a serious infringement and the impairment cannot be adequately remedied in any other way. Whether a violation of personal rights is so serious as to warrant monetary compensation can only be assessed based on all the circumstances of the individual case. In particular, the significance and scope of the infringement, the occasion and motive of the perpetrator, and the degree of their culpability must be considered. The awarding of monetary compensation under the aforementioned conditions is justified by the principle that, without it, personal rights would be insufficiently protected against serious infringements, with the consequence that legal protection of personality would be weakened (Federal Court of Justice, Judgment of March 12, 2024, VI ZR 1370/20, para. 70).


In this context, the significance and scope of the infringement, as well as the occasion and motive of the perpetrator, and the degree of their culpability, must be taken into account. Paragraph 247

In the present case, there is no serious infringement of the plaintiff's general right of personality that could not be satisfactorily remedied in any way other than by the payment of monetary compensation (see Higher Regional Court of Naumburg, loc. cit., paras. 366 et seq.; Higher Regional Court of Munich, GRUR-RS 2025, 36464, paras. 116 et seq.; Higher Regional Court of Dresden, judgment of March 17, 2026, 4 U 709/25, judgment transcript p. 33; Higher Regional Court of Hamm, judgment of March 9, 2026, I-8 U 13/25, judgment transcript p. 38; contra: Higher Regional Court of Dresden, judgment of March 12, 2026, case no. 17 U 625/25, judgment transcript p. 68). It should be noted that the plaintiff is already receiving non-material damages pursuant to Article 82 GDPR for the defendant's data protection breach. The plaintiff's harm is further mitigated by the fact that, in the present proceedings, the defendant is prohibited from processing the plaintiff's data transmitted to it via the business tool (see Higher Regional Court of Munich, GRUR-RS 2025, 36464, para. 121). It should also be considered that the plaintiff continues to use the defendant's social network and, by doing so alone, already provides the defendant with a vast amount of data.

7.

Paragraph 248

The damages amount of €500.00 is subject to interest at a rate of 5 percentage points above the base interest rate from the date the action was filed, pursuant to Sections 291 para. 1 and 288 para. 1 sentence 2 of the German Civil Code (BGB). A further claim for interest from July 18, 2023, onwards is not valid, as the plaintiff has not proven receipt of the pre-litigation letter, which the defendant disputes.

Paragraph 249

Claim No. 7 (Reimbursement of Pre-Litigation Legal Fees)

Paragraph 250

The plaintiff has no claim against the defendant for reimbursement of pre-litigation legal fees.

Paragraph 251

Since the defendant has denied receipt of the pre-litigation letter, it is not apparent that the defendant was in default.

Paragraph 252

Furthermore, pre-litigation legal fees are covered by the court fees. The plaintiff has not demonstrated a separate mandate for the pre-litigation assertion of the claims. Incurring these costs would also not have been necessary, because in the context of the mass-acquired, serial mandates, it was clear from the outset that an out-of-court approach offered no prospect of success.

Paragraph 253

Claim No. 8 (alternative claim to the injunction claim No. 2):

Paragraph 254

The condition for a decision on the alternative claim is met, since the main claim asserted in Claim No. 2, which concerns the processing of the plaintiff's personal data on third-party websites and apps outside the defendant's networks, is unfounded in accordance with the above explanations.

Paragraph 255

The alternative claim is admissible in the appeal proceedings pursuant to Section 533 of the German Code of Civil Procedure (ZPO). Although the defendant has expressly refused consent, the alternative claim is relevant because it concerns the same subject matter of the dispute and its admission is suitable for resolving the dispute within the framework of the pending legal proceedings (see Zöller/Heßler, loc. cit., Section 533, para. 6). Since the factual basis for the alternative claim is the same as for the main claim, Section 533 No. 2 ZPO does not preclude the admissibility of the alternative claim.

Paragraph 256

However, the alternative claim is not sufficiently specific and is therefore inadmissible.

Paragraph 257

In the alternative claim, individual processing operations are exempted from the prohibition in relation to the main claim, provided that the defendant presents and proves "justifications with individual reference to these operations" with regard to these processing operations. Both the term "justifications" and the required "individual connection" to the respective processing operation are ambiguous and require interpretation. The same applies to the question of when the arguments presented regarding the justifications are sufficient or conclusive and when these arguments are sufficiently proven. While terms requiring interpretation are not generally inadmissible in an injunction application, they are inadmissible when the dispute specifically concerns whether the challenged conduct falls under them (Zöller/Greger, loc. cit., § 253, para. 13c). This is the case here, as the parties are disputing precisely whether the defendant can rely on the security and integrity purposes it has asserted with regard to the data processing it has carried out.

IV.

1.

Paragraph 258

The decision on costs is based on Sections 92 para. 1 and 97 para. 1 of the German Code of Civil Procedure (ZPO).

Paragraph 259

The provisional enforceability of clauses I. 1 to 3 of the judgment is governed by Section 709 of the German Code of Civil Procedure (ZPO), since these claims are not for money or assets of monetary value and therefore do not constitute pecuniary disputes (see Götz in MüKo/ZPO, loc. cit., Section 708, para. 17). Insofar as the defendant argues that the security required under Section 709 ZPO must be many times the value in dispute of the relevant claim because this corresponds to the irreparable damage that enforcement would cause the defendant, the defendant fails to provide any comprehensible explanation as to why the unchanged storage and subsequent deletion of the plaintiff's personal data transmitted to it via business tools should cause such damage.

Paragraph 260

In all other respects, the provisional enforceability is governed by Sections 708 No. 10 and 711 ZPO.

2.

Paragraph 261

The appeal on points of law is admissible for both parties pursuant to Section 543 Paragraph 2 Sentence 1 No. 1 of the German Code of Civil Procedure (ZPO). The case is of fundamental importance because, in an indefinite number of parallel cases, the standards to be applied to the data subjects' submissions regarding internet use are interpreted differently. Furthermore, there are differences regarding the admissibility of a declaratory judgment action, the scope of an injunction, and whether the right to erasure under Article 17 GDPR also includes, as a lesser right, a right to anonymization.

3.

Paragraph 262

The value in dispute for the appeal proceedings is set at €8,250.00 and is also to be adjusted to €8,250.00 for the proceedings before the Regional Court.


a)

Paragraph 263

The value in dispute for the appeal proceedings is €8,250.00 and is composed as follows:

Paragraph 264

- Item 1: Declaratory judgment: €500

Paragraph 265

- Item 2: Injunction against processing on third-party websites: €750

Paragraph 266

- Item 3: Storage: €750

Paragraph 267

- Item 4: Disclosure: €500

Paragraph 268

- Item 5: Deletion/Anonymization: €750

Paragraph 269

- Item 6: Damages: €5,000

Paragraph 270

The alternative claim asserted and decided under point 8 is not to be considered additionally for the purposes of determining the value in dispute for the appeal proceedings, as it does not exceed the claim under point 2. further independent interest.

b)

Paragraph 271

The reduction of the value in dispute for the proceedings at first instance ex officio is based on an application of Section 63 Paragraph 3 Sentence 1 No. 2 of the Court Costs Act (GKG). According to this provision, if the proceedings are pending before the appellate court with regard to the merits or regarding the decision on the value in dispute, the cost assessment, or the determination of costs, the appellate court may amend the determination within the time limits of Section 63 Paragraph 3 Sentence 2 of the Court Costs Act (OLG Stuttgart, NJW-RR 2020, 255 para. 26; Schneider, NJW 2017, 3764, each with further references). The decision falls within these limits, as the judgment of the Regional Court has not yet become final.

Paragraph 272

The statements regarding the value in dispute in the appeal proceedings apply accordingly to the value in dispute at the Regional Court.

Permalink

If you highlight the link (hold down the left mouse button), you can copy it with the right mouse button and paste it into your browser or bookmarks. You can copy and use this link if you want to link to this exact document:

https://www.landesrecht-bw.de/perma?d=NJRE001641279

Help
Legal Notice
Privacy Policy
Accessibility
...
  1. See C-40/17 (Fashion ID), margins 79, 81, 85, 102
  2. This reasoning was the opposite to OLG Dresden, judgment of March 12, 2026, 17 U 625/25, p. 56