OLG Stuttgart - 4 U 372/24
| OLG Stuttgart - 4 U 372/24 | |
|---|---|
| Court: | OLG Stuttgart (Germany) |
| Jurisdiction: | Germany |
| Relevant Law: | Article 6 GDPR Article 12 GDPR Article 15(1) GDPR Article 17 GDPR Article 18 GDPR Article 82 GDPR |
| Decided: | 29.04.2026 |
| Published: | 03.06.2026 |
| Parties: | Data subject Company that operates several social media platforms |
| National Case Number/Name: | 4 U 372/24 |
| European Case Law Identifier: | ECLI:DE:OLGSTUT:2026:0429.4U372.24.00 |
| Appeal from: | LG Stuttgart 29 O 117/24 |
| Appeal to: | Unknown |
| Original Language(s): | German |
| Original Source: | Landesrecht BW (in German) |
| Initial Contributor: | Ava Lang |
A court held that a social network operator unlawfully stored personal data collected from third-party apps without a legal basis under Article 6 GDPR. It granted an injunction and awarded €500 in non-material damages.
English Summary
Facts
The controller (the operator of multiple large social networking platforms) offered "Business Tools" that third-party website and app operators could integrate into their services. These tools transmitted visitors' personal data, such as identifiers, contact details, browsing information and interaction data, to the controller.
The data subject had used the social network since 2021. He had not consented to the controller's use of personal data transmitted through these Business Tools.
The data subject brought proceedings seeking, among other things, a declaration that the user contract did not permit the processing of such data, an injunction against further processing, restrictions on the use of already collected data, deletion or anonymisation of the data, and compensation under Article 82 GDPR.
The first-instance court rejected the declaratory claim, partially granted an injunction concerning the storage of off-site data, and dismissed most of the remaining claims. Both parties appealed.
Holding
The court distinguished between two types of processing: the collection of personal data on third-party websites and apps through the controller's Business Tools, and the storage and further processing of data after transmission to the controller.
Regarding the collection of data on third-party websites and apps, the court found that the controller and the third-party website operators were joint controllers under Article 26 GDPR. The controller failed to prove that the data subject had consented. However, the court rejected the injunction request against the controller for this stage of processing because the immediate infringement resulted from the conduct of the third-party website operators. The controller had contractually required website operators to obtain a valid legal basis and had not breached any specific duties arising from Article 26 GDPR.
Third, the court held that the controller unlawfully stored personal data received through the Business Tools. The controller argued that it processed the data for security and integrity purposes and relied on Article 6(1)(f) GDPR. However, the controller failed to explain which categories of data it processed, why the processing was necessary, how it was carried out, and how long the data were retained, so it failed to demonstrate a lawful basis for the storage of the data.
The court therefore upheld the injunction prohibiting the controller from storing the specified personal data collected from third-party websites and apps. It also found a risk of repeated infringement because the controller had already engaged in the unlawful storage.
Fourth, the court held that the data subject was entitled to restriction of processing under Article 18 GDPR. The controller had to preserve the already processed data, refrain from further use or disclosure, and retain them until the data subject requested deletion.
Fifth, the court ordered the controller to delete the personal data that had been stored since 1 June 2021.
Finally, the court awarded the data subject €500 in non-material damages under Article 82 GDPR for the unlawful processing of his personal data. However, it rejected the claim for higher compensation and did not award the requested pre-litigation legal costs.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the German original. Please refer to the German original for more details.
Judgment
1. The defendant's appeal against the judgment of the Stuttgart Regional Court of November 18, 2024, Case No. 29 O 117/24, is dismissed.
2. Upon the plaintiff's appeal, the judgment of the Stuttgart Regional Court of November 18, 2024, Case No. 29 O 117/24, is partially amended and entirely reformulated as follows:
2.1. The defendant is ordered, under penalty of a fine of up to €250,000.00 for each instance of non-compliance, or alternatively, imprisonment of its legal representative for up to six months, or up to two years in the case of repeated offenses, to refrain from storing the following personal data of the plaintiff collected on third-party websites and apps outside the defendant's networks:
a) personal data of the plaintiff generated on third-party websites and apps, whether transmitted directly or in hashed form, i.e., • Plaintiff's email address
• Plaintiff's telephone number
• Plaintiff's first name
• Plaintiff's last name
• Plaintiff's date of birth
• Plaintiff's gender
• Plaintiff's city
• External IDs of other advertisers (referred to by M... Ltd. as "external_ID")
• Client's IP address
• Client's user agent (i.e., collected browser information)
• M... Ltd.'s internal click ID
• M... Ltd.'s internal browser ID
• Subscription ID
• Lead ID
• anon_id
• the Android operating system's Advertising ID (referred to as "madid" by M... Ltd.)
and the following personal data of the plaintiff:
b) on websites
• the URLs of the websites, including their subpages
• the time of the visit
• the "referrer" (the website from which the user arrived at the current website),
• the buttons clicked by the plaintiff on the website, and
• other data referred to as "events" by M... that document the plaintiff's interactions on the respective website
c) in third-party mobile apps
• the name of the app, and
• the time of the visit
• the buttons clicked by the plaintiff in the app, and
• the data referred to as "events" by M... that document the plaintiff's interactions in the respective app.
2.2. The defendant is ordered to leave all personal data listed under points 2.1 a), b), and c) of the judgment, which has already been processed since June 1, 2021, unchanged from now on. This means, in particular, that the defendant may only delete this data upon the plaintiff's request and may not alter it, use it internally, or disclose it to third parties until that time.
2.3. The defendant is ordered to completely delete all personal data of the plaintiff that has already been stored pursuant to point 2.1 a) of the judgment since June 1, 2021, upon the plaintiff's request, but no later than six months after the final and binding conclusion of the proceedings.
2.4. The defendant is ordered to pay the plaintiff non-pecuniary damages in the amount of €500.00 plus interest at a rate of five percentage points above the base interest rate since January 20, 2024.
2.5. The remainder of the claim is dismissed.
3. The plaintiff's further appeal is dismissed.
4. The plaintiff shall bear 80% and the defendant 20% of the costs of the appeal proceedings. The plaintiff shall bear 85% and the defendant 15% of the costs of the proceedings at first instance.
5. Paragraphs 2.1 to 2.3 of this judgment are provisionally enforceable upon provision of security in the amount of €750.00 each.
Otherwise, this judgment and the judgment of the Stuttgart Regional Court are provisionally enforceable without security to the extent they are upheld. The respective judgment debtor may avert enforcement by providing security in the amount of 110% of the amount enforceable under this judgment, unless the judgment creditor provides security in the amount of 110% of the amount to be enforced before enforcement proceedings commence.
6. Leave to appeal to the Federal Court of Justice is granted.
7. The value in dispute for the appeal proceedings is set at €8,500.00.
8. The value in dispute set by the Regional Court at €18,000.00 for the proceedings at first instance is amended ex officio to €7,750.00.
Reasons
I.
Paragraph 1
1.
The defendant operates various social networks, including I.... Currently, more than 3.98 billion people use the defendant's products.
Paragraph 2
The defendant offers companies the opportunity to present advertisements to an audience on I... for a fee. The defendant offers so-called business tools to these third-party companies. If the third-party company integrates these business tools into its website, data from a user visiting that website is transmitted to the defendant. This includes standard technical data such as the device's IP address, which is transmitted as part of the HTTP request. Additional data, such as customer activity data on the websites or apps of third-party companies, is transmitted depending on the third-party company chosen and the specific business tool used (see in detail the defendant's brief of July 29, 2024, paragraphs 40-43). If the user has given their consent to the defendant, the transmitted data will be used for personalized advertising. Even if the user has refused consent, the defendant uses the data for security and integrity purposes.
Paragraph 3
The plaintiff has been using I... privately since 2021. He has not consented to the defendant's use of his personal data transmitted to the defendant via a business tool from third-party companies.
Paragraph 4
The plaintiff seeks in his action
Paragraph 5
1. a declaration that the parties' user agreement does not permit the processing of certain data of the plaintiff listed in the application,
Paragraph 6
2. an order prohibiting the defendant from processing the plaintiff's personal data on third-party websites and third-party apps outside the defendant's networks,
Paragraph 7
3. an order requiring the defendant to leave the plaintiff's personal data generated on third-party websites and third-party apps unchanged in their stored location and to delete it only upon request, and no later than six months after the final and binding conclusion of the proceedings,
Paragraph 8
4. an order requiring the defendant to delete the data pursuant to claim 1(a) upon request, but no later than six months after the final and binding conclusion of the proceedings, and to fully anonymize the data pursuant to claims 1(b) and (c),
Paragraph 9
5. The defendant was ordered to pay non-pecuniary damages in the amount of at least €5,000.
Paragraph 10
6. The defendant was ordered to reimburse the plaintiff for pre-litigation legal fees in the amount of €1,295.43.
Paragraph 11
The defendant requested that
Paragraph 12
the action be dismissed.
Paragraph 13
For details of the parties' submissions in the first instance, reference is made to the pleadings and the factual findings in the judgment of the Regional Court.
Paragraph 14
2.
The Regional Court partially granted the injunction and dismissed the action in all other respects.
Paragraph 15
The declaratory judgment action (item 1) was inadmissible for lack of a legitimate interest in such a judgment. The plaintiff could sue for performance and had done so with the claims for injunctive relief, deletion, and damages.
Paragraph 16
The injunction is justified insofar as it concerns the storage of personal off-site data. The claim arises from Article 17 of the GDPR, according to which the plaintiff can demand that the defendant cease storing his personal data. The defendant has not disputed that it receives and stores the plaintiff's personal data collected using its business tools. The fact that this occurs regardless of consent is evident from the defendant's explanation of the Conversions API. According to this explanation, the Conversions API aggregates events from users who have opted out of the use of their data and sends them to the defendant. Since the injunction is directed toward the future, it is irrelevant whether the defendant received and stored personal data in the past. Therefore, it is also irrelevant whether the plaintiff effectively consented to the data transfer to the defendant in the past, because the plaintiff revoked any such consent at the latest with the filing of the complaint.
...``` ```` ```` ``` `` `` `` ` ` ` ` ` ` ` ` ` ` ` ` ` ` ` ` ` ` ` ` ` ` ` ` ` ` ` ` ` ` ` ` ` ` ` ` ` ` Paragraph 17
The further injunction claims are unfounded because Article 17 GDPR only provides for a right to erasure or deletion. Other non-contractual grounds for claims under German law are precluded by the comprehensive regulation in the General Data Protection Regulation. Contractual injunction claims exist only in the case of a continuing breach of duty or contract, but not for preventive protection, as sought by the plaintiff.
Paragraph 18
The request for erasure is inadmissible because the data to be deleted or anonymized is only described in abstract terms, and it is not specifically stated which of the data originate from third-party websites or apps. The request would therefore be unenforceable. Insofar as the plaintiff demands anonymization, the request is also inadmissible because it is undisputed that it is possible to separate the data from previous activities from the plaintiff's account, so that the plaintiff lacks a legitimate interest in legal protection. Furthermore, Article 17 GDPR does not grant a right to anonymization, but only to erasure.
Paragraph 19
The claim for damages is unfounded because the plaintiff has not demonstrated any damages. He has not specified which data the defendant collected without his consent, nor has he provided any evidence that the defendant used the data transmitted to it via business tools to display personalized advertising, either without or against his will. Only this, not the mere storage of the data, can establish tangible damages. According to the plaintiff's statements during his hearing, there are also doubts as to whether the described negative feelings are related to the defendant's business tools in question, because the plaintiff reported that, according to his law firm, his data had been resold, was publicly accessible, and that he had received an email regarding a data breach. All of this is irrelevant to the present proceedings.
Paragraph 20
The defendant is not required to reimburse pre-litigation legal fees (item 6). No default regarding the granted injunction has been demonstrated. Furthermore, the legal fees were covered by the court fees, as the plaintiff had not demonstrated a separate mandate for the pre-litigation assertion of the claims. In any case, an out-of-court approach would have had no prospect of success, so the costs would not have been necessary.
Paragraph 21
3.
In his appeal, the plaintiff continues to pursue his claims from the first instance, supplementing the injunction claim with a subsidiary claim (point 7). In support of his appeal, he essentially argues the following:
Paragraph 22
A legitimate interest in a declaratory judgment exists. The possibility of future harm exists even if the court grants the other claims. In any event, the claim is admissible as an interim declaratory judgment pursuant to Section 256 Paragraph 2 of the German Code of Civil Procedure (ZPO).
Paragraph 23
The claim for an injunction against future data processing is fully justified. Even the initial collection of the data by the business tools must be prevented to ensure effective legal protection, because the data is automatically transmitted to the defendant's servers. A claim for injunctive relief arises from Article 17 GDPR. The concept of storage is to be interpreted more broadly than assumed by the Regional Court. Furthermore, corresponding claims under national law are not precluded.
Paragraph 24
The request to keep the plaintiff's personal data unchanged at its current location is justified pursuant to Article 18(1)(b) GDPR. According to this provision, the data subject may refuse the erasure of their personal data and instead request the restriction of its processing.
Paragraph 25
The request for erasure or anonymization of the data is sufficiently specific. The plaintiff cannot know which data the defendant has already collected about them.
Paragraph 26
The claim for damages is justified. The damage consists of a comprehensive loss of control, which is caused by the violation of Articles 5 and 25 GDPR.
Paragraph 27
The claim for reimbursement of pre-litigation legal fees is justified. The costs are recoverable not only as damages for delay, but also under Sections 280 and 241 Paragraph 2 of the German Civil Code (BGB). The assertion that the pre-litigation legal work was not promising is incorrect. At the time of the pre-litigation work in this case, it was not yet foreseeable how the defendant would react.
Paragraph 28
In addition, the plaintiff submits, in response to the Senate's observations during the appeal hearing, that he visited, among others, the websites s….de, z….de, m….de, and a….com. On the pages z….de and m….de, the M… pixel is activated even before the plaintiff has made a decision regarding the cookie banner. Therefore, on these pages, personal data is transmitted to the defendant before any consent is given by the visitor to the respective page.
Paragraph 29
4.
With its appeal, the defendant seeks the complete dismissal of the action. The defendant essentially argues the following in support of its claim:
Paragraph 30
The Regional Court wrongly granted the injunction in part:
Paragraph 31
The Regional Court erred in assuming that the defendant had not disputed that the conversion data was sent to the defendant via the Conversions API, even if users had opted out of the use of their data. However, in its rejoinder, the defendant denied processing the data about a user's activities on the third-party company's websites/apps, which the third-party company sends to it via the Conversions API, for the purpose of delivering personalized advertising to the user on I... if the user had not consented via the setting "Information from advertising partners about your activities."
Paragraph 32
The plaintiff's submissions are insufficiently substantiated. In the first instance, the plaintiff neither specified the websites or apps he allegedly visited nor the time at which this is said to have occurred. Furthermore, he had not presented any evidence of the alleged visits to the websites/apps. The submission in the second instance was untimely. Therefore, it remains unclear which third-party websites and apps fall within the scope of the applications. Consequently, it has not been proven that the alleged websites even use the business tools in dispute or that they transmitted the plaintiff's personal data to the defendant via these business tools. Notwithstanding the foregoing, the defendant proactively examined the websites z....de and m....de and determined that they did not comply with the terms and conditions for business tools. The defendant requested the operators of these websites to rectify the issues and inform the defendant of the measures taken.
Paragraph 33
The Regional Court erred in law by assuming that the defendant's receipt of the data and thus its temporary storage violated the General Data Protection Regulation (GDPR). The defendant, however, interprets the plaintiff's claim as relating to the processing of data from third-party websites and apps for the provision of personalized advertising, and the defendant does not process the data for this purpose unless the user has expressly given their consent.
Paragraph 34
The injunction application is inadmissible because the plaintiff has not specified which processing purpose the injunction is directed against, other than the purpose of processing the data for the provision of personalized advertising. Insofar as the Regional Court prohibits the defendant from storing all data, regardless of the processing purpose and regardless of whether the processing is lawful in individual cases, this contradicts the General Data Protection Regulation (GDPR), which permits lawful data processing. For example, the defendant uses the data obtained via the business tools in question to protect the security of its servers, including ensuring that malicious actors do not misuse the business tools in question to carry out spam, scraping, or other cyberattacks through these products. A ban on this practice would endanger the entire community of the defendants and, indeed, the internet as a whole.
Paragraph 35
The injunction application constitutes an inadmissible disguised action for performance. Since it is the third-party companies that have chosen to use the business tools in question to send data to the defendants, the focus of the application appears to be on compelling the defendants to implement technical and organizational measures to protect the plaintiff's personal data. The wording of the application and the actual objective are therefore contradictory.
Paragraph 36
Furthermore, Article 17 of the GDPR does not grant a right to injunctive relief. Claims for injunctive relief under national law are precluded due to the exhaustive nature of the General Data Protection Regulation.
Paragraph 37
There is no risk of repetition or initial infringement. Since the plaintiff did not name any third-party websites or apps that he allegedly visited and that used the business tools in question, he also failed to demonstrate that the defendant had infringed any of the plaintiff's rights in the past. Nor was there any evidence of an imminent infringement of the plaintiff's rights, because, lacking the plaintiff's consent, the defendant would not process data from third-party websites and apps for the purpose of providing personalized advertising.
Paragraph 38
In any event, the plaintiff's claim for injunctive relief was impermissibly broad because the defendant had to process the data obtained through the business tools to at least some extent, namely to determine whether it constituted personal data of a user and, depending on the user's settings, to decide whether further action could be taken with regard to that data.
Paragraph 39
Civil proceedings are not the appropriate legal instrument for taking a general action against the defendant's business model. The investigation and – in the event of established violations – the sanctioning of general “business models” is a matter of public law and the competent authorities.
Paragraph 40
5.
The plaintiff requests the following regarding his own appeal:
Paragraph 41
The judgment of the Stuttgart Regional Court of first instance dated November 18, 2024, is amended and reworded as follows.
Paragraph 42
1) It is determined that the parties' user agreement for the use of the network "I..." under the username "b...__c..." does not permit the processing of the following personal data to the following extent since June 1, 2021:
Paragraph 43
a) Personal data of the plaintiff generated on third-party websites and apps, whether transmitted directly or in hashed form, i.e., Paragraph 44
- Plaintiff's email address
Paragraph 45
- Plaintiff's telephone number
Paragraph 46
- Plaintiff's first name
Paragraph 47
- Plaintiff's last name
Paragraph 48
- Plaintiff's date of birth
Paragraph 49
- Plaintiff's gender
Paragraph 50
- Plaintiff's city
Paragraph 51
- External IDs of other advertisers (referred to by M... Ltd. as "external_ID")
Paragraph 52
- Client's IP address
Paragraph 53
- Client's user agent (i.e., collected browser information)
Paragraph 54
- M... Ltd.'s internal click ID
Paragraph 55
- M... Ltd.'s internal browser ID
Paragraph 56
- Subscription ID
Paragraph 57
- Lead ID
Paragraph 58
- anon_id
Paragraph 59
- the Android operating system's Advertising ID (referred to as "madid" by M... Ltd.)
Paragraph 60
and the following personal data of the plaintiff
Paragraph 61
b) on websites
Paragraph 62
- the URLs of the websites, including their subpages
Paragraph 63
- the time of the visit
Paragraph 64
- the "referrer" (the website from which the user arrived at the current website)
Paragraph 65
- the buttons clicked by the plaintiff on the website and
Paragraph 66
- other data referred to by M... as "events," which document the plaintiff's interactions on the respective website
Paragraph 67
c) on mobile devices Third-party apps
Paragraph 68
- the name of the app and
Paragraph 69
- the time of the visit
Paragraph 70
- the buttons clicked by the plaintiff in the app and
Paragraph 71
- the data referred to by M... as "Events," which document the plaintiff's interactions in the respective app.
Paragraph 72
2) The defendant is ordered, under penalty of a fine of up to €250,000.00 for each instance of non-compliance, or alternatively, imprisonment of its legal representative for up to six months, or up to two years in the case of repeated violations, to refrain from processing personal data on third-party websites and apps outside the defendant's networks in accordance with the application in point 1.
... Paragraph 73
3) The defendant is ordered to leave all personal data listed under claim 1 a., b., and c., which has already been processed since June 1, 2021, unchanged at its current location, i.e., in particular, to delete it only upon the plaintiff's request, but no later than six months after the final and binding conclusion of the proceedings, and not to alter it, use it internally, or disclose it to third parties until that time.
Paragraph 74
4) The defendant is ordered to completely delete all personal data of the plaintiff that has already been stored since June 1, 2021, pursuant to claim 1 a., upon the plaintiff's request, but no later than six months after the final and binding conclusion of the proceedings, and to confirm the deletion to the plaintiff, as well as to completely anonymize all personal data that has already been stored since June 1, 2021, pursuant to claim 1 b. and c.
... Paragraph 75
5) The defendant is ordered to pay the plaintiff non-pecuniary damages, the amount of which is to be determined at the court's discretion, but which shall be at least €5,000.00, plus interest at a rate of five percentage points above the base interest rate since December 5, 2023.
Paragraph 76
6) The defendant is ordered to reimburse the plaintiff for pre-litigation legal fees in the amount of €1,295.43.
... Paragraph 77
Alternatively, in the event that the second claim is inadmissible or unfounded:
Paragraph 78
7) The defendant is ordered, under penalty of a fine of up to €250,000.00 for each instance of non-compliance, or alternatively, imprisonment of its legal representative for up to six months, or in the case of repeated offenses, up to two years, to refrain from processing personal data on third-party websites and apps outside the defendant's networks in accordance with the first claim, unless the defendant presents and proves specific justifications relating to individual processing operations concerning the plaintiff's personal data, explaining why the data processing cannot be justified, in particular, with regard to
Paragraph 79
- the conclusion of the contract for the use of the "F..." and/or "I..." network,
Paragraph 80
- a Consent via the "Information from advertising partners about your activities" button on the "F..." and/or "I..." network,
Paragraph 81
- consent via the "M... Cookies in other apps and on other websites" button on the "F..." and/or "I..." network,
Paragraph 82
- the provision of a service to fulfill the contract for the use of the "F..." and/or "I..." network,
Paragraph 83
- abstract research for the benefit of society, the abstract promotion of protection, integrity, and security,
Paragraph 84
- the defendant's economic interest in personalizing advertisements,
Paragraph 85
- the abstract goal of informing law enforcement and penal authorities to prevent, detect, prosecute, establish, or
Paragraph 86
- other legitimate interests of the defendant in data processing asserted across multiple users.
Paragraph 87
The defendant requests that
Paragraph 88
the plaintiff's appeal be dismissed.
Paragraph 89
The defendant, in its own appeal, requests that
Paragraph 90
the judgment of the Stuttgart Regional Court of November 18, 2024 (the "appealed judgment"), Case No. 29 O 117/24, M..., served on November 20, 2024, be amended insofar as the claim was granted, and that the claim be dismissed in its entirety.
Paragraph 91
The plaintiff requests that
Paragraph 92
the defendant's appeal be dismissed.
Paragraph 93
6.
For further details and the parties' submissions in the second instance, reference is made to the written pleadings filed and the transcripts of the oral hearing.
II.
Paragraph 94
1.
The plaintiff's appeal is inadmissible with respect to the pre-litigation legal fees (appeal request no. 6).
Paragraph 95
a)
If the Regional Court based the dismissal of a single claim on two legally independent grounds, each of which alone justifies the dismissal, a sufficient statement of grounds for appeal exists only if both grounds are challenged – in a manner sufficient on their own. If the appellant challenges only one of the two grounds, the appeal is inadmissible (Zöller/Heßler, ZPO, 36th ed. 2026, § 520, para. 39).
Paragraph 96
b)
The Regional Court based its dismissal of the claim, inter alia, on the grounds that the pre-litigation legal fees were covered by the court fees because a separate instruction to assert the claims out of court had not been demonstrated. The plaintiff's grounds of appeal do not address this reasoning, which alone justifies the dismissal of the claim. The appeal is therefore inadmissible to that extent.
Paragraph 97
2.
In all other respects, the appeals of the plaintiff and the defendant are admissible.
III.
Paragraph 98
The plaintiff's appeal is unfounded with respect to claims 1, 2, and 7. The declaratory judgment claim (point 1) is inadmissible, the injunction claim (point 2) is unfounded, and the alternative claim (point 7) is inadmissible. With respect to the claims for unaltered storage (point 3), deletion or anonymization (point 4), and damages (point 5), the plaintiff's appeal is partially successful.
Paragraph 99
The defendant's appeal is unfounded. The plaintiff is entitled to the injunction (point 2) in the version granted by the Regional Court.
Paragraph 100
A.
The international jurisdiction, which must also be examined ex officio in the appeal proceedings, is based on Article 79(2), second sentence, GDPR with respect to all claims based on the General Data Protection Regulation (GDPR), and on Article 82(6) GDPR with respect to claim point 5. It is unnecessary to decide whether Article 79(2) GDPR also applies to concurrent claims for damages and injunctive relief under national law (as argued by Auernhammer/v. Lewinski, GDPR/BDSG, 8th ed. 2024, GDPR, Article 79, para. 6), since international jurisdiction with respect to these claims would otherwise arise from Article 17(1)(c) and Article 18(1) of the Brussels I Regulation (Recast).
Paragraph 101
B.
Regarding the individual claims:
Paragraph 102
Claim No. 1 (Declaratory Judgment Claim):
Paragraph 103
With Claim No. 1, the plaintiff seeks a declaration that the parties' user agreement does not permit the processing of the plaintiff's specifically identified personal data.
Paragraph 104
Claim No. 1 is inadmissible. The declaratory judgment action lacks the necessary legal interest.
Paragraph 105
Pursuant to Section 256 Paragraph 1 of the German Code of Civil Procedure (ZPO), an action may be brought to establish the existence or non-existence of a legal relationship if the plaintiff has a legitimate interest in having the legal relationship established as soon as possible.
Paragraph 106
1.
A legal relationship is required, i.e., a connection between a person and another person or thing resulting from a specific set of facts, which contains a subjective right that can be established with res judicata effect or from which such a right can arise (Zöller/Greger, loc. cit., Section 256, Paragraph 4).
Paragraph 107
Such a legal relationship exists. A user agreement exists between the parties regarding the social network I... and the subject of the declaratory judgment action is whether this user agreement gives rise to a right for the defendant to process the plaintiff's personal data, which the defendant obtained via third-party business tools (contra: Higher Regional Court of Dresden, judgment of February 3, 2026, 4 U 292/25, juris, para. 136 et seq.; similarly, Higher Regional Court of Naumburg, judgment of February 5, 2026, 9 U 44/25, juris, para. 157; Higher Regional Court of Munich, judgment of December 18, 2025, 14 U 881/25, GRUR-RS 2025, 36464, para. 51).
Paragraph 108
2.
The required legal interest in a declaratory judgment is lacking. The priority of an action for performance precludes such an interest.
... Paragraph 109
The plaintiff lacks a legitimate interest in a declaratory judgment if an action for performance is possible and reasonable for the plaintiff, and if such an action would fully satisfy their objective (Zöller/Greger, loc. cit., § 256, para. 14). An action for performance in this sense also includes an (preventive) injunction (Federal Court of Justice, NJW-RR 2016, 1404, para. 16).
Paragraph 110
An action for performance is possible. The plaintiff is demanding quantified damages for the past and the deletion or anonymization of the data already collected; for the future, the plaintiff can demand an injunction and is now doing so. These actions fully satisfy their objective.
Paragraph 111
The plaintiff's opposing argument in the grounds of appeal is unconvincing. The plaintiff can also obtain certainty regarding the currently existing legal relationship by filing an injunction, which, if successful, allows him to enforce against the defendant should the defendant fail to comply with the injunction. The plaintiff's reference to the Federal Court of Justice's reasoning in its judgment on data scraping (Federal Court of Justice, judgment of November 18, 2024, VI ZR 10/24, para. 48) is unconvincing in this respect, as the two declaratory judgment claims are not comparable. The declaratory judgment claim assessed by the Federal Court of Justice sought a declaration of the defendant's liability for future damages, and not—as in the present case—a declaration that the user agreement does not permit the processing of personal data. Furthermore, data scraping, with its ongoing publication of personal data on the internet, carries the risk of misuse of this data by third parties. This risk does not exist in the present case, as the data is merely stored by the defendant, and the plaintiff can proceed with the injunction against the defendant.
The declaratory judgment claim assessed by the Federal Court of Justice sought a declaration of the defendant's liability for future damages, and not—as in the present case—a declaration that the user agreement does not permit the processing of personal data. Paragraph 112
3.
The action is also inadmissible as an interlocutory declaratory judgment.
Paragraph 113
a)
Contrary to the wording of the statute, an interlocutory declaratory judgment is admissible even if—as in this case—a dispute existed between the parties regarding the legal relationship before the proceedings (Becker-Eberhard in MüKo/ZPO, 7th ed. 2025, § 256, para. 83).
Paragraph 114
b)
While no legitimate interest in a declaratory judgment is required for an interlocutory declaratory judgment (Zöller/Greger, loc. cit., § 256, para. 39), the judgment on the main action may not already exhaustively regulate the legal relationship between the parties. The legal relationship to be clarified incidentally must have, or be capable of acquiring, significance between the parties beyond the current subject matter of the dispute (Zöller/Greger, loc. cit., § 256, para. 40). This is lacking.
Paragraph 115
However, the injunction application in the first instance only concerned the processing of data by the third-party companies that had integrated the defendant's business tools into their website and apps. According to the wording of the application, the injunction did not include the cessation of data processing with regard to the data transmitted to the defendant by these third-party companies ("to refrain from processing personal data on third-party websites and apps outside the defendant's networks"). Therefore, the storage of the data on the defendant's servers was not the subject of the dispute in the first instance.
However, the injunction application in the first instance was not the subject matter of the dispute. Paragraph 116
However, the legitimate interest in a declaratory judgment must exist until the conclusion of the last oral hearing (Zöller/Greger, loc. cit., § 256, para. 16), and in the second instance, the defendant is also prohibited from storing the plaintiff's data transmitted to it by the third-party companies, according to the judgment of the Regional Court. The fact that the Regional Court, contrary to § 308 para. 1 of the German Code of Civil Procedure (ZPO), awarded the plaintiff something he had not even requested does not change this, since the plaintiff requested that the defendant's appeal be dismissed. By doing so, he adopted the Regional Court's decision and permissibly expanded his claim in the appeal proceedings to include the injunction awarded to him (cf. Zöller/Feskorn, loc. cit., § 308, para. 7).
Paragraph 117
c)
Furthermore, an action for an interim declaratory judgment requires that the legal relationship be prejudicial. This must be a necessary element for the subsumption in the main decision (Becker-Eberhardt in MüKo/ZPO, loc. cit., § 256, para. 85). This is also not the case.
Paragraph 118
With the declaratory judgment action, the plaintiff seeks a declaration that the contractual relationship between the parties does not grant the defendant the right to process the plaintiff's data on third-party websites and apps without the plaintiff's consent or another legal justification. In particular, the plaintiff seeks a declaration that the clauses in the defendant's general terms and conditions, which grant the defendant a right to process the data in dispute even without consent, are invalid and that the defendant does not have the right to continuously collect all of the plaintiff's data on third-party websites and apps without cause (Reply, pp. 65, 68).
Paragraph 119
Such a declaration is not necessary for the decision on the other claims. For the injunction claim, the declaratory judgment sought by the plaintiff is irrelevant, as the claim must be dismissed due to the defendant's lack of standing as a disturber of the peace. For the damages claim, however, a violation of the General Data Protection Regulation (GDPR) by the defendant is a prerequisite. The data processing in question must therefore not be covered by any of the legal bases for processing under Article 6(1) or Article 9(2) GDPR. The necessary declaratory judgment for this is not identical to the question of whether the general terms and conditions of the contract concluded between the parties grant the defendant the right to process the plaintiff's data on third-party websites and apps, irrespective of the plaintiff's consent and other legal grounds.
... Paragraph 120
Claim No. 2 (Injunction):
Paragraph 121
With Claim No. 2, the plaintiff seeks a judgment ordering the defendant to refrain from processing personal data pursuant to Claim No. 1 on third-party websites and apps outside the defendant's networks.
Paragraph 122
1.
Claim No. 2, both according to its wording and the grounds for the claim, seeks to prohibit the defendant from processing the plaintiff's personal data located on third-party websites and apps. This refers not to data already transmitted to the defendant by the third-party companies, but rather to data processing that occurs prior to such transmission by the business tools on the third-party websites and apps. This is clear not only from the unambiguous wording of the claim, but also from its reasoning. In his reply, in which he first presented his claim in its current form, the plaintiff explicitly addresses the (joint) responsibility of the defendants for data processing on third-party websites and apps, stating that the subject of this claim is data that has not already been processed by the defendants (i.e., on their own websites and servers) (reply, pp. 57, 71). That the plaintiff understands his claim in this way is also demonstrated by his arguments in the grounds of appeal regarding the merits of claim no. 2 (grounds of appeal, p. 6). There, the plaintiff states that the initial collection of data by the business tools results in this data being automatically transmitted to the defendants' servers. Therefore, it is necessary to effectively prevent the data processing operations that precede the final storage on the defendants' servers.
The plaintiff's understanding of his claim in this way is also evident in his statements in the grounds of appeal regarding the merits of claim no. 2 (grounds of appeal, p. 6). Paragraph 123
However, the Regional Court did not understand this application in the aforementioned sense, but rather interpreted it as referring to data already transmitted to the defendant. This is evident to some extent from the wording in the operative part of the judgment under point 1.a), which refers to the transmission of data in direct or hashed form. Most importantly, however, the Regional Court expressly states in its reasoning that the prohibition is directed only against the storage of data that was collected outside the defendant's social networks and transmitted to the defendant (LGU p. 9 under gg)).
Paragraph 124
For the appeal proceedings, this means that the defendant's appeal concerns claim no. 2 with the content granted by the Regional Court (hereinafter 3.), while the plaintiff's appeal concerns the claim with the meaning intended by the plaintiff (hereinafter 2.).
Paragraph 125
2.
Regarding the plaintiff's appeal (data processing on third-party websites and apps):
Paragraph 126
The plaintiff's appeal is unfounded.
Paragraph 127
A claim for injunctive relief does not arise from Article 17 GDPR. Article 17 GDPR grants a right to erasure, but not a right to injunctive relief (ECJ, Judgment of 4 September 2025, C-655/23, para. 43). However, the General Data Protection Regulation does not preclude provisions of national law from which claims for injunctive relief may arise (ECJ, ibid., paras. 46 et seq.). This gives rise to a claim for injunctive relief pursuant to Sections 823 and 1004 of the German Civil Code (BGB) due to infringement of the general right of personality.
Paragraph 128
a)
The plaintiff's general right of personality is affected. Personal data is among the protected legal interests within the scope of the general right of personality (Grüneberg/Sprau, BGB, 85th ed. 2026, Introduction to Section 823, para. 33). It must be assumed that the plaintiff visited websites that had implemented the defendant's business tools and that the plaintiff's personal data was collected and transmitted to the defendant in this context.
Paragraph 129
The plaintiff asserted this in general terms in the first instance and specified it with regard to individual websites (z....de and m....de) in the second instance. The general submissions in the first instance were sufficient, as the plaintiff had thereby presented all the facts necessary to establish the asserted right. Nothing more was required (see Zöller/Greger, loc. cit., § 138, para. 8a).
Paragraph 130
The defendant cannot argue that the plaintiff is required to specifically name the websites he visited. It is incumbent upon the defendant to refute the plaintiff's claims if, to the defendant's knowledge, the plaintiff never visited websites containing the defendant's business tools or if the defendant never received any personal data of the plaintiff from such visits. The defendant is able to do so because it can see from its systems which data it processes and whether and how this involves the plaintiff's personal data (see Naumburg Higher Regional Court, judgment of February 5, 2026, 9 U 44/25, juris, para. 289).
Paragraph 131
The defendant does not dispute that the plaintiff visited websites on which the defendant's business tools were installed. The defendant merely denies that the plaintiff visited each of the 466 websites listed in Exhibit K2. That he visited some of these websites—such as m….de—is not disputed. Insofar as the defendant expressly denies that the plaintiff visited any of the five websites depicted on pages 10 to 12 of the statement of claim or any of the 24 websites listed on page 9 of the statement of claim (statement of defense, para. 71), the websites z….de and m….de are not among those listed. Therefore, the plaintiff's visit to these websites is not disputed.
Paragraph 132
Furthermore, the defendant only denied the plaintiff's corresponding assertions for lack of knowledge. The Senate understands the defendant's denials in subsequent pleadings in the same way. This denial based on lack of knowledge is inadmissible, as the question of which data was transmitted to the defendant concerns an area within the defendant's own control (see Higher Regional Court of Hamm, judgment of March 9, 2026, I-8 U 13/25, judgment transcript p. 21).
Paragraph 133
b)
The plaintiff has convincingly demonstrated that his personal data, collected during his visits to websites with the defendant's implemented business tools, was processed unlawfully.
Paragraph 134
The defendant relies on the admissibility of processing the plaintiff's personal data on the third-party websites and apps where its business tools are implemented, on the grounds that the plaintiff gave his consent pursuant to Article 6(1)(a) GDPR when visiting the website or using the app.
Paragraph 135
(aa)
Justification for data processing by obtaining the plaintiff's consent to the operator of the website that incorporates one or more of the defendant's business tools is, in principle, possible.
Paragraph 136
According to the terms of use of the business tools, the operator of the website that integrates a business tool of the defendant into its website must ensure that it has all necessary rights and authorizations, as well as a legal basis, for disclosing and using the business tool data.
Paragraph 137
The plaintiff's view that the defendant cannot delegate the responsibility for obtaining consent to the respective website operator because it is solely or at least jointly responsible with the website operator for the processing of data by its business tools is incorrect. The decision of the CJEU cited by the plaintiff as evidence for his legal position (CJEU, Judgment of 29 July 2019 – C-40/17 – “Like” Button – Fashion ID) states the opposite, namely that the responsibility for obtaining consent for the processing of personal data lies with the website operator and not with the defendant. Admittedly, the CJEU states in the aforementioned decision that the website operator and the defendant, as the provider of the business tools, jointly decided on the means underlying the collection of personal data of website visitors and its transfer by transmission, as well as on the purposes of the collection and transfer of the data by transmission (CJEU, ibid., paras. 79, 81). Therefore, the website operator should also be considered a data controller (CJEU, ibid., para. 85). The operator of the website, not the defendant, must obtain the data subject's necessary consent for the collection and transfer of the data to the defendant, since the processing of personal data is triggered when a visitor accesses the operator's website (ECJ, loc. cit., para. 102).
Paragraph 138
bb)
The plaintiff has, at least in his submissions on appeal regarding the websites z....de and m....de, contested the defendant's assertion that he had given consent pursuant to Article 6(1)(a) GDPR when visiting the third-party websites and apps on which the defendant's business tools are implemented. The plaintiff's submissions on this point are now undisputed. The defendant itself states that it has determined that the websites z....de and m....de do not comply with the terms and conditions for business tools.
Paragraph 139
In any event, the defendant, as the (joint) controller, bears the burden of proof and the burden of production to demonstrate that the data subject has given consent and that this consent meets the requirements of Article 4 No. 11 GDPR and Article 7 GDPR. The defendant has failed to provide sufficient evidence in this regard.
Paragraph 140
c)
However, despite the lack of valid consent from the plaintiff for the data processing taking place on the third-party company's website, the defendant cannot be held liable for injunctive relief.
Paragraph 141
The claim for injunctive relief analogous to Sections 823 para. 1, 1004 of the German Civil Code (BGB) requires that the party to be held liable for injunctive relief be a disturber of the peace. The defendant lacks this disturber of the peace.
Paragraph 142
(aa)
A disturber is anyone who, even without being a perpetrator or accomplice, willfully and with adequate causation contributes in any way to the infringement of the legally protected interest or whose conduct gives rise to a fear of such infringement, regardless of the nature and extent of their contribution. If the infringement has its direct cause in the conduct of third parties, the breach of duties to act is additionally required. Apart from specific statutory obligations, these duties are generally determined by the extent to which the responsible party contributes to the infringement and has reasonable means of intervention available to them (Grüneberg/Sprau, loc. cit., before § 823, paras. 31, 35).
Paragraph 143
(bb)
The defendant, in the absence of consent or its invalidity, willfully and with adequate causation contributed to the infringement of the general right of personality of the affected website visitor. The defendant cannot claim liability by arguing that it did not integrate the business tools into the third-party company's website itself, since it provided the business tools specifically for integration into the third-party company's website or app.
Paragraph 144
However, a further requirement is that the defendant breached any duties of care, because the infringement is directly caused by the conduct of the website operator, who, contrary to the agreement with the defendant, collected and transmitted the data without a sufficient legal basis. The mere fact that the defendant developed the business tools at issue in these proceedings and made them available to the third-party company does not, therefore, lead to its being considered a direct infringer (contra: Higher Regional Court of Dresden, Judgment of March 12, 2026, 17 U 625/25, judgment transcript p. 56).
Paragraph 145
It is not apparent that the defendant breached any duties of care arising from the specific provisions of the General Data Protection Regulation (GDPR).
Paragraph 146
(i)
The defendant is (jointly) responsible for the data processing carried out using the business tools.
Paragraph 147
According to Article 4, No. 7, first sentence of the GDPR, the controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing. Where two or more controllers jointly determine the purposes and means of the processing, they are joint controllers (Article 26, paragraph 1, first sentence of the GDPR).
Paragraph 148
The CJEU has already ruled that the defendant and the company that integrates the defendant's social plug-in (in this specific case, the "Like" button) into its website jointly decided on the means underlying the collection and transmission of personal data of website visitors, as well as on the purposes of the collection and transmission of the data, and that the defendant is therefore a joint controller within the meaning of Article 26 GDPR for the data processing (CJEU, Judgment of 29 July 2019 – C-40/17 – "Like" Button – Fashion ID, paragraphs 79, 81, 85). The same applies to the business tools at issue.
Paragraph 149
(ii)
However, it is not apparent that the defendant has breached any obligations arising from joint controllership within the meaning of Article 26 GDPR.
Paragraph 150
It has already been explained above that the defendant, and not the third-party contractor, is responsible for obtaining consent.
Paragraph 151
The defendant has also not violated the obligation under Article 26(1), second sentence, and (2) GDPR to specify in a transparent agreement with the third-party contractor which of them fulfills which obligations under the General Data Protection Regulation. It is undisputed that the defendant informs the third-party contractors within the framework of the agreement that they are responsible for obtaining valid consent. The Business Tool Terms of Use, in which the defendant informs the third-party contractors that they must obtain valid consent (Exhibit B5), suffice as an agreement within the meaning of Article 26 GDPR, as Article 26 GDPR does not contain a specific formal requirement for the agreement (Auernhammer/Schreibauer, loc. cit., Article 26 GDPR, para. 17).
Paragraph 152
The plaintiff's submissions do not reveal any other breach of duties by the defendant.
Paragraph 153
(iii)
Article 26(3) GDPR does not imply that the defendant can nevertheless be sued for injunctive relief by the plaintiff.
Paragraph 154
According to Article 26(3) GDPR, the data subject may assert their rights under the General Data Protection Regulation against each of the controllers, irrespective of the details of the agreement concluded by the defendant with the respective third-party company. However, these rights are limited to the data subject's rights under Chapter 3 GDPR (Bertermann in Ehmann/Selmayer, GDPR, 3rd ed. 2024, Article 26, para. 29; Spoerr in BeckOK Datenschutzrecht, as of August 1, 2025, Article 26, para. 58). Claims for injunctive relief are therefore not covered by Article 26(3) GDPR, because they are not provided for in Articles 12 to 23 GDPR (Bertermann, ibid.). The result is not different even if, according to the wording of the provision, not only the rights of the data subject under Chapter 3 GDPR are meant, but all rights regulated in the General Data Protection Regulation, because the claim for injunctive relief is not regulated in the General Data Protection Regulation, but arises supplementarily from the provisions of national law.
Paragraph 155
3.
Regarding the defendant's appeal (processing of the data transmitted to the defendant):
Paragraph 156
The defendant's appeal is unfounded.
Paragraph 157
a)
The defendant's appeal is not well-founded simply because the plaintiff did not actually assert the claim awarded to him by the Regional Court. As already explained above, by requesting the dismissal of the defendant's appeal, the plaintiff adopted the Regional Court's decision and permissibly expanded his claim in the appellate proceedings to include the injunction awarded to him (see Zöller/Feskorn, loc. cit., § 308, para. 7).
Paragraph 158
b)
The injunction cannot be based on the use of the data for personalized advertising. In this respect, there is no risk of repetition.
Paragraph 159
aa)
The substantive legal requirement for an injunction is the risk of repetition.
Paragraph 160
As a rule, a prior unlawful infringement establishes a factual presumption of this. Even a first serious threat of infringement is sufficient. However, there is no actual presumption in their favor (Grüneberg/Herrler, loc. cit., § 1004, para. 32; Grüneberg/Sprau, loc. cit., before § 823, para. 29).
Paragraph 161
bb)
The plaintiff has not substantiated his claim that the defendant used his personal data for advertising purposes in the past. In any case, he has not offered any evidence for such a claim. The plaintiff merely asserts in general terms that the defendant unlawfully processed his personal data. No more specific arguments have been presented. Insofar as the plaintiff asserts that the settings of the "Optional Cookies" and "Information on Advertising Partner Activities" buttons have no effect whatsoever on the functionality of the business tools and the data processing taking place within them, and offers expert testimony to support this assertion, this assertion also fails to establish that the defendant used the plaintiff's personal data for advertising purposes without his consent.
Paragraph 162
There is also no risk of initial infringement, as the defendant expressly stated in its pre-litigation response to the plaintiff's attorney's letter that it would not use the plaintiff's data transmitted to it via business tool for advertising purposes without consent (Exhibit B10).
Paragraph 163
c)
However, the injunction is justified because the defendant indisputably stores the plaintiff's personal data for security and integrity purposes and, despite a court order, has failed to provide the necessary evidence that this is permissible under Article 6(1)(f) GDPR.
Paragraph 164
aa)
According to Article 6(1)(f) GDPR, the processing of personal data is lawful if the processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.
Paragraph 165
Legitimate interests in this sense also include the prevention of fraud (Recital 47, sixth sentence). Furthermore, the processing of personal data by operators of electronic communications networks and services constitutes a legitimate interest of the respective controller to the extent that it is strictly necessary and proportionate for ensuring network and information security, i.e., insofar as it ensures the ability of a network or information system to reliably prevent disruptions or unlawful or malicious interference that could affect the availability, authenticity, completeness, and confidentiality of stored or transmitted personal data, as well as the security of related services offered or accessible via those networks or information systems. Such a legitimate interest may, for example, consist of preventing unauthorized access to electronic communication networks and the dissemination of malicious code, as well as defending against attacks in the form of targeted server overload ("denial-of-service" attacks) and damage to computer and electronic communication systems (Recital 49).
Paragraph 166
The processing must be necessary to protect the legitimate interest. This necessity is waived if there are also suitable, demonstrably effective alternative methods of data processing that are less burdensome for the data subjects under data protection law (Auernhammer/Kramer, loc. cit., Art. 6, para. 79). The controller must present the factual basis that is intended to support the necessity of the data processing (Albers/Veit in BeckOK DatenschutzR, loc. cit., GDPR Art. 6, para. 69).
Paragraph 167
If the storage of data is necessary for security purposes, it must be examined whether the interests or fundamental rights and freedoms of the data subjects outweigh the interest in processing. An overriding interest of the data subjects is not precluded from the outset. It depends on which data is stored and processed, to what extent, and for what period (Auernhammer/Kramer, loc. cit., Art. 6, para. 88).
Paragraph 168
bb)
The defendant argued in the first instance that the storage of the data was necessary for security and integrity purposes, including monitoring attempted attacks on the defendant's systems, such as deliberately overloading the website.
Paragraph 169
However, despite the court's prompting in the first appeal hearing, the defendant failed to specify the security and integrity purposes in more detail. She continues to assert, only in general terms, that she uses the data collected via the business tools.
Paragraph 170
- to detect anomalous activity that might be intended to disrupt the defendant's services, such as atypical patterns in download speeds or anomalous device/network activity,
Paragraph 171
- for troubleshooting and operational data collection,
Paragraph 172
- to detect hostile actors whose actions might violate the defendant's policies, such as hacking activities, data from prohibited sources, security risks, especially for minors, potential criminal activities of dangerous organizations, and manipulation tactics, including coordinated fake behavior.
Paragraph 173
This general statement is insufficient. It fails to identify which of the plaintiff's data the defendant processes for security and integrity purposes, how this processing occurs, why the processing of the data is necessary for the stated security and integrity purposes, and how long the defendant stores the data for these purposes. Such information is required because it is the only way to determine whether the processing of personal data is necessary to protect the legitimate interest asserted by the defendant and whether this interest outweighs the plaintiff's interests and fundamental rights and freedoms. The defendant is aware of this, as evidenced by its response to the court's request for clarification, where it lists the above questions in paragraph 1 of its written submission. Nevertheless, the following statements do not provide a single answer to any of these questions.
[Statement on this matter is required because it is not relevant to the legal process.] Paragraph 174
The further arguments presented in the last written submission of March 27, 2026, are also insufficient to substantiate the alleged security and integrity purposes. Insofar as the defendant states in this submission that it deletes data from its systems within three hours, this timeframe refers to the example presented at that point. The submission does not indicate that the defendant generally deletes data transmitted to it via business tools after three hours (paragraphs 25 et seq.). Furthermore, the defendant only deletes the data if it deems no further investigation necessary. It remains unclear according to which criteria the defendant determines this necessity. In any case, there is no concrete connection here either to the plaintiff's personal data stored by the defendant.
Paragraph 175
cc)
The defendant's further objection that it needs to process the data it receives in order to determine whether the data is linked to an account with it and whether processing is permissible according to the account settings is unfounded. This objection is irrelevant because the Regional Court only prohibited the defendant from storing the data, not from comparing the data.
Paragraph 176
Moreover, the objection would also be unfounded with regard to comparing the data. A comparison of incoming data with existing accounts is only possible if the data was lawfully collected. If the data was lawfully collected, for example, based on the data subject's consent to the collection and transfer of this data to the defendant, then this consent also covers the comparison with existing data. However, if the data was unlawfully collected, the defendant has no legitimate interest in determining whether the data is linked to an account with it.
Paragraph 176
Moreover, the objection would also be unfounded with regard to comparing the data. Paragraph 177
d)
The previous unlawful infringement establishes a factual presumption of a risk of recurrence.
Paragraph 178
e)
The injunction issued by the Regional Court against the defendant, prohibiting the storage of the plaintiff's personal data collected on third-party websites and apps and transmitted to the defendant, is not overly broad simply because the injunction would also cover permissible conduct. This is not the case, as the defendant—as explained above—has not convincingly demonstrated a legal basis for processing under Article 6 GDPR.
Paragraph 179
The fact that the conditions for permissible storage may exist in the future does not preclude the injunction. If valid consent is given at a later date, or if a legal basis for data processing by the defendant arises after the conclusion of the oral proceedings, the defendant may assert this by filing an action to set aside enforcement pursuant to Section 767(2) of the German Code of Civil Procedure. This can also be directed against a claim for injunctive relief (Higher Regional Court of Dresden, Judgment of February 3, 2026, 4 U 292/25, juris, para. 183). The view of the Higher Regional Court of Munich, and subsequently the Higher Regional Court of Naumburg, that expressly permitted conduct must be excluded from the prohibition (Higher Regional Court of Munich, Judgment of December 18, 2025, 14 U 1068/25, GRUR-RS 2025, 36441, paras. 187-194; Higher Regional Court of Naumburg, Judgment of February 5, 2026, 9 U 44/25, juris, paras. 295-297), is therefore not to be followed. In any case, a operative clause like those in the cases of the Higher Regional Courts of Munich and Naumburg would likely be indefinite in the present case, because the parties are precisely disputing whether the data processing in question is legally permissible.
Paragraph 180
Claim No. 3 (Storage):
Paragraph 181
The plaintiff's appeal is successful with respect to the claim that the defendant is ordered to leave the data unchanged and not to delete it. It is unfounded insofar as the plaintiff seeks an order requiring the defendant to leave the data at its current location.
Paragraph 182
1.
With Claim No. 3, the plaintiff seeks an order compelling the defendant to leave the data specified in Claim No. 1 unchanged at its current location, not to alter it, not to disclose it to third parties, and to delete the data only upon the plaintiff's request or six months after the final and binding conclusion of the proceedings.
Paragraph 183
The plaintiff expressly clarified during the appeal hearing that the claim is solely aimed at ensuring that the data remains unchanged at its current location with immediate effect. This claim does not seek any future deletion. This is the subject of application no. 4. Therefore, only the request for the unchanged storage of the data and the prohibition of its disclosure to third parties are to be assessed.
Paragraph 184
2.
The legal basis for the plaintiff's request is Article 18 GDPR. Article 18(1) GDPR grants a data subject the right, under the conditions specified therein, to request from the controller the restriction of processing.
Paragraph 185
According to Article 4(3) GDPR, the restriction of processing means the marking of stored personal data with the aim of limiting its future processing. If processing has been restricted, the personal data may – apart from being stored – only be processed with the consent of the data subject or if the other conditions specified in Article 18(2) GDPR are met. In substance, the restriction of processing corresponds to the concept of blocking (Auernhammer/Eßer, loc. cit., Article 4, para. 62).
Paragraph 186
3.
The restriction of processing may be requested by the data subject, among other things, if the processing is unlawful and the data subject objects to the erasure of the personal data and instead requests the restriction of its use (Article 18(1)(b) GDPR).
Paragraph 187
The aforementioned conditions are met. The processing of the data was unlawful. Reference is made to the explanations under point 3 regarding claim 2. The further condition for the right to restriction, namely that the data subject objects to erasure, is also met. The plaintiff has made a corresponding request not to erase the data, at least with claim 3.
Paragraph 188
4.
However, the prohibition sought by the plaintiff does not fully correspond to the legal consequences associated with a restriction. The plaintiff's request that the data remain at the stored location is not covered by the legal basis.
Paragraph 189
a)
The right to restriction of processing does not imply that the data must remain at the location where it is stored, as Recital 67 expressly provides that the data may be temporarily transferred to another processing system. In this respect, the applicant's claim is therefore unfounded, and his appeal is unsuccessful.
Paragraph 190
b)
Furthermore, the application in point 3 is well-founded.
Paragraph 191
Once the processing has been restricted, the controller is prohibited from altering the data, using it internally, or disclosing it to third parties (see Auernhammer/Stollhoff, loc. cit., Art. 18, para. 25). The controller may also no longer delete the data, because the deletion of data also constitutes processing under the legal definition in Art. 4 No. 2 GDPR. The controller therefore does not have the option of deleting the data instead of restricting its processing (Auernhammer/Stollhoff, loc. cit., Art. 18, para. 26).
Paragraph 192
The plaintiff's claim is not precluded by the fact that, according to Art. 18 para. 2 GDPR, personal data may be processed even if its processing has been restricted pursuant to Art. 18 para. 1 GDPR, if the data subject consents or if this is done for the establishment, exercise or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State. The defendant has not argued that any of these conditions are met. Therefore, it cannot be assumed that the requested prohibition on further internal use of the data and on disclosing it to third parties would be too broad because it would also encompass permissible conduct.
Paragraph 193
Claim No. 4 (Deletion and Anonymization):
Paragraph 194
With Claim No. 4, the plaintiff seeks an order compelling the defendant to:
Paragraph 195
- completely delete all of the plaintiff's data specified in Claim No. 1 a upon the plaintiff's request, but no later than six months after the final and binding conclusion of the proceedings (hereinafter referred to as 1.),
Paragraph 196
- confirm the deletion to the plaintiff (hereinafter referred to as 2.),
Paragraph 197
- completely anonymize all personal data already stored pursuant to Claims 1 b) and c) since June 1, 2021 (hereinafter referred to as 3.).
Paragraph 198
1.
The application for erasure is admissible and well-founded.
Paragraph 199
a)
The application for erasure is admissible.
Paragraph 200
aa)
The action seeks erasure only six months after the judgment becomes final or after a request has been issued. The claim for erasure is not due until the specified date because the plaintiff expressly requests the storage of the data until that date. It is therefore an action for future performance (see Naumburg Higher Regional Court, loc. cit., para. 308).
Paragraph 201
An action for future performance is only admissible under the conditions of Sections 257 to 259 of the German Code of Civil Procedure (ZPO) (Foerste in Musielak/Voit, ZPO, 22nd ed. 2025, Section 257, para. 6). According to Section 259 of the German Code of Civil Procedure (ZPO), an action for future performance may be brought if, under the circumstances, there is justified concern that the debtor will evade timely performance. For this concern to exist, it suffices that the debtor seriously disputes the claim or the obligation to perform. Bad faith or even malicious intent is not required (Becker-Eberhard in MüKo/ZPO, loc. cit., Section 259, para. 13).
Paragraph 202
The defendant seriously disputed that it was obligated to delete the personal data and, in this respect, pointed out that it was authorized to continue storing the data for security and integrity reasons. The defendant thus seriously disputed its obligation to perform. The prerequisites for an action for future performance are therefore met.
Paragraph 203
bb)
The admissibility of the action is not precluded by the fact that the deletion before the expiry of six months after the judgment becomes final is contingent upon a prior request by the plaintiff, i.e., upon a suspensive condition. This circumstance does not alter the sufficient specificity of the application.
Paragraph 204
A claim is generally sufficiently specific if it concretely identifies the claim asserted, thereby defining the scope of the court's decision-making authority (Section 308 of the German Code of Civil Procedure), clarifies the content and extent of the res judicata effect of the requested decision (Section 322 of the German Code of Civil Procedure), does not shift the risk of the plaintiff losing the case to the defendant through avoidable imprecision, and finally allows for enforcement of the judgment without further litigation in enforcement proceedings (Federal Court of Justice, NJW 1999, 954).
Paragraph 205
Considering all these aspects, there is, in principle, no objection to a due date for the requested deletion that is linked to the request. The Federal Court of Justice's decision cited above concerned a claim for payment of monthly compensation for use until the return of the item. There are no apparent reasons to assess the specificity of the request differently for a request for deletion after return. The Federal Court of Justice's considerations also apply in the present case. Whether the plaintiff has requested the defendant to delete the data can generally be determined easily and reliably. The necessary examination can be carried out before the commencement of enforcement proceedings in the enforcement clause procedure, since this is a suspensive condition (Sections 726, 731 of the German Code of Civil Procedure).
Paragraph 206
cc)
The application is also not inadmissible due to a lack of specificity regarding the data to be deleted or anonymized.
Paragraph 207
The Regional Court deemed the application inadmissible because the data to be deleted or anonymized was only described in abstract terms, and it was not specifically stated which of the data originated from third-party websites or apps. It was not apparent from the stored data itself whether it originated from third-party websites or apps, or from F... or I.... This is not convincing in light of the requirements for the specificity of a claim set out above in section bb):
Paragraph 208
The defendant does not even claim that it is unable to determine whether the data stored by it originates from third-party websites or apps. It argues that the claim contains an inadmissible extrajudicial condition and that there is no legitimate interest in bringing an action for future performance. However, it does not argue at any point that it can no longer determine the origin of the data. Insofar as the defendant argues in its response to the appeal that the plaintiff's request for erasure and anonymization is too vague because it fails to specify which concrete data are the subject of the plaintiff's requests, it merely refers to two judgments of regional courts and to an alleged discussion in Section B.I. However, in Section B.I., the defendant only addresses the question of which processing purpose the plaintiff is challenging with its action (paragraphs 10 et seq.). The objection that the data the plaintiff seeks to have erased or anonymized is not sufficiently specified does not appear in the relevant section.
Paragraph 209
Therefore, there is no doubt as to the specificity of the request. The data in question is specifically identified by its origin. The decision concerns only this data; therefore, there is no doubt as to the content and scope of the res judicata effect. Enforcement of the judgment is possible pursuant to Section 888 of the German Code of Civil Procedure (ZPO), as the deletion or anonymization of the data stored by the defendant constitutes a non-delegable action.
Paragraph 210
b)
The claim for erasure is justified.
Paragraph 211
The right to erasure of unlawfully processed personal data is governed by Article 17(1)(d) of the GDPR. According to this provision, the controller must erase unlawfully processed personal data without undue delay where requested by the data subject.
Paragraph 212
The aforementioned conditions are met. With regard to the unlawful processing, reference is made to the above statements concerning the defendant's appeal against the injunction granted by the Regional Court. The plaintiff has also made a request. The fact that he does not request immediate erasure, but rather erasure at a later date, is not detrimental, because the requirement for a claim, according to the purpose of the provision, is not a request for immediate erasure, but only a request for erasure that the controller must then comply with without undue delay (see Kamann/Braun in Ehmann/Selmayr, loc. cit., Art. 17, para. 42).
Paragraph 213
2.
The plaintiff's appeal regarding the asserted claim for confirmation of erasure is unfounded.
Paragraph 214
The legal basis for the plaintiff's request for confirmation of erasure is Article 12(3), first sentence, GDPR. According to this provision, the controller must provide the data subject with information about the measures taken in response to a request pursuant to Articles 15 to 22 GDPR – including a request for erasure pursuant to Article 17 GDPR – without undue delay and at the latest within one month.
...``
```
````
````````````````````````````````````````````````````````````````````````````````
```
```
```
```
Paragraph 215
This is also a claim for future performance, as the deletion has not yet taken place and, according to the plaintiff, is not yet intended to take place.
Paragraph 216
The application is inadmissible because the requirements for an application for future performance are not met. In particular, there is no concern of non-performance within the meaning of Section 259 of the German Code of Civil Procedure (ZPO), because the defendant has never disputed its obligation to confirm the deletion of the plaintiff's personal data should it delete the plaintiff's data.
Paragraph 217
3.
Furthermore, the plaintiff's appeal regarding the claim for complete anonymization of the data pursuant to claim no. 1 b) and c) is unfounded.
Paragraph 218
a)
The application is admissible. In particular, it does not lack standing simply because, with regard to data anonymization, it is possible to separate the data of previous activities from the plaintiff's account. This possibility does not eliminate the legal interest in obtaining the requested anonymization. Data is considered anonymized when the data in question cannot be, or can no longer be, identified (Auernhammer/Eßer, loc. cit., Art. 4, para. 72). However, data separation would only result in anonymization if it were guaranteed that re-establishing the link to a specific individual would require a disproportionate expenditure of time, costs, and labor (Auernhammer/Eßer, loc. cit., Art. 4, para. 73). The defendant's submissions do not indicate that this is the case.
Paragraph 219
b)
Contrary to its potentially misleading wording, the application is not substantively contradictory to application no. 3. According to application no. 3, the defendant is to leave the stored data unchanged in its current location; according to application no. 4, the defendant is to anonymize the data. The plaintiff has clarified, however, that the request for anonymization of the data pursuant to claim 1(b) and (c) is subject to the same time limit as the request for erasure of the data pursuant to claim 1(a), namely, that anonymization is to take place only upon the plaintiff's request, but no later than six months after the final and binding conclusion of the proceedings.
Paragraph 220
(c)
The request for anonymization is unfounded, as there is no legal basis for the requested anonymization of the data. While the General Data Protection Regulation (GDPR) grants a right to erasure under certain conditions, it does not grant a right to anonymization. To the extent that the plaintiff argues by way of a fortiori that the right to anonymization is contained as a "lesser" right within the right to erasure under Article 17 GDPR, this cannot be accepted, because how the controller fulfills the data subject's right to erasure is his own business (Kamann/Braun in Ehmann/Selmayer, loc. cit., Article 17, para. 40), especially since anonymization can cause more effort than erasure.
Paragraph 221
The Higher Regional Courts of Munich, Naumburg, and Hamm have also ruled in this sense (Higher Regional Court of Munich, Judgment of December 18, 2025, 14 U 881/25, GRUR-RS 2025, 36464, para. 138; Higher Regional Court of Naumburg, Judgment of February 5, 2026, 9 U 44/25, juris, para. 320; Higher Regional Court of Hamm, Judgment of March 9, 2026, I-8 U 13/25, judgment transcript p. 32). The fact that the aforementioned Higher Regional Courts ordered the defendant to delete the data instead of anonymizing it is solely due to the fact that in those cases, the plaintiff had requested anonymization or, "at the defendant's option," deletion. This is different in the present case. The plaintiff has requested only anonymization.
Paragraph 222
The contrary view of the Higher Regional Court of Dresden, which recognizes a right to anonymization (Judgment of February 3, 2026, 4 U 292/25, juris, para. 191; Judgment of March 17, 2026, 4 U 709/25, judgment transcript p. 28), cannot be followed. The Higher Regional Court of Dresden argues that the controller can also comply with the obligation to delete data by means of appropriate anonymization if the data subject requests it. However, the fact that the controller can also fulfill their obligation to delete data by means of anonymization does not mean that they are obligated to anonymize it, because the controller has discretion regarding the means and procedures for deletion, provided that the selected measures lead to the necessary deletion (Kamann/Braun in Ehmann/Selmayr, loc. cit., Art. 17, para. 40).
Paragraph 223
Claim No. 5 (Damages):
Paragraph 224
The appeal regarding claim No. 5, in which the plaintiff seeks non-material damages in the amount of at least €5,000.00, is justified in the amount of €500.00.
Paragraph 225
The legal basis for the plaintiff's claim is Article 82 GDPR. According to Article 82(1) GDPR, any person who has suffered material or non-material damage as a result of an infringement of the General Data Protection Regulation has the right to compensation from the controller. The prerequisites for a claim for damages are therefore a violation of the General Data Protection Regulation (GDPR), the existence of non-material damage, and a causal link between the damage and the violation, with these three prerequisites being cumulative (Federal Court of Justice, Judgment of November 18, 2024, VI ZR 10/24, para. 21).
Paragraph 226
1.
A violation of the General Data Protection Regulation (GDPR) has occurred.
Paragraph 227
a)
For the plaintiff's claim for non-material damages, both potential violations of the GDPR during the collection of personal data by the business tools, which fall under the joint responsibility of the defendant and the operator of the website with the business tools, and violations after the transmission of this data to the defendant must be considered, since the violations alleged by the plaintiff in this respect constitute a single subject matter of the dispute.
Paragraph 228
The subject matter of the dispute encompasses all alleged violations of the General Data Protection Regulation (GDPR) related to the data processing in question, which, from the parties' perspective and in a manner that grasps the essence of the matter, belong to the complex of facts at issue for decision (Federal Court of Justice, Judgment of November 18, 2024, VI ZR 10/24, para. 17). From a natural perspective, the alleged violations of the GDPR cannot be assessed in isolation before and after the transfer of the data to the defendant, as they all stem from a single event: the defendant's provision of the business tools and the implementation of these tools on the third-party companies' websites.
The subject matter of the dispute includes all alleged violations of the General Data Protection Regulation related to the incriminated data processing, which, from a natural perspective and in a manner that grasps the essence of the matter, belong to the complex of facts submitted for decision (Federal Court of Justice, Judgment of November 18, 2024, VI ZR 10/24, para. 17). Paragraph 229
b)
As explained above regarding the claim for injunctive relief, the defendant violates the General Data Protection Regulation (GDPR) by processing the plaintiff's personal data transmitted to it via the Business Tool, since none of the conditions for processing the data specified in Article 6(1) GDPR are met. Furthermore, there is also a violation of the GDPR with regard to the collection and transmission of personal data on the third-party websites, as the defendant has failed to provide sufficient evidence of the plaintiff's necessary consent. With regard to the websites z....de and m....de, it is undisputed that the plaintiff's consent is lacking.
Paragraph 230
c)
The defendant is also responsible for the infringement regarding the collection of data on the websites of the third-party companies z....de and m....de, as it is jointly responsible with the third-party company within the meaning of Article 26 GDPR (see CJEU, Judgment of 29 July 2019, C-40/17 – “Like” Button – Fashion ID). The fact that the harmful act was carried out by the third-party company and not by the defendant does not preclude liability, because in the case of joint controllers, it is sufficient that the other controller involved has carried out a harmful act (Auernhammer/Schürmann/Baier, loc. cit., Article 82, para. 16).
Paragraph 231
Regarding the possibility of exoneration under Article 82(3) GDPR, reference is made to the following explanations under point 4.
Paragraph 232
2.
The plaintiff has also suffered damage.
Paragraph 233
a)
The concept of non-material damage in Article 82(1) GDPR encompasses negative feelings, such as worry or anger, experienced by the data subject as a result of the unauthorized disclosure of their personal data to a third party, and which
Paragraph 234
- result from a loss of control over that data,
Paragraph 235
- result from its potential misuse, or
Paragraph 236
- result from reputational damage
Paragraph 237
caused, provided the data subject demonstrates that they experience such feelings and their negative consequences as a result of the infringement of this Regulation in question (ECJ, Judgment of 4 September 2025, C-655/23, GRUR-RS 2025, 22639, paragraph 64).
Paragraph 238
b)
The damage here consists of a loss of control. The argument that the data was only passed on to the defendant and not to other third parties is not valid. The Federal Court of Justice (BGH) also affirmed a loss of control in a case where the personnel file management of federal civil servants was improperly carried out by employees of the State of Lower Saxony (BGH, NJW 2025, 1656, para. 14 et seq.). The fact that the employees of the State of Lower Saxony were bound by confidentiality did not preclude the finding of damage (BGH, ibid., para. 16). Furthermore, the plaintiff has no way of comprehending the scale of the data processing carried out by the defendant (see Higher Regional Court of Naumburg, judgment of February 5, 2026, 9 U 44/25, juris, para. 341), and the plaintiff has no means of regaining control over the data through his own actions, since neither changing the privacy settings nor deleting his account would result in the complete deletion of the data stored by the defendant (see Higher Regional Court of Dresden, judgment of February 3, 2026, 4 U 292/25, juris, para. 197). In light of this, a loss of control due to the unauthorized transfer of personal data to the defendant cannot be denied.
Paragraph 239
No other damage within the meaning of the case law of the CJEU is apparent. Damage to reputation resulting from the storage of the data transferred to the defendant is just as unlikely as concern about the potential misuse of the data. The plaintiff has neither alleged nor proven such consequences.
Paragraph 240
3.
The necessary causal link between the damage and the defendant's breach also exists. If the defendant had not processed, and in particular had not stored, the plaintiff's personal data transmitted to it via business tools, the plaintiff would not have suffered any loss of control over this data.
Paragraph 241
4.
Pursuant to Article 82(3) GDPR, the controller is exempt from liability under Article 82(2) GDPR if it proves that it is in no way responsible for the circumstances that caused the damage. Responsibility refers to fault in the sense of German legal terminology, and not to data protection liability (Quaas in BeckOK Datenschutzrecht, 55th ed., as of February 1, 2026, GDPR, Art. 82, para. 17; Aliprandi, Datenschutzrechtlicher Schadensersatz nach Art. 82 DS-GVO, p. 448).
Paragraph 242
With regard to the data processing carried out by the defendant itself, an exemption from liability under Art. 82 para. 3 GDPR is clearly not applicable. No evidence has been presented to support the defendant's claim of negligence.
Paragraph 243
The same applies, in effect, to the collection and transfer of the plaintiff's personal data by the third-party contractors.
Paragraph 244
However, the view, sometimes expressed in commentary literature, that joint controllers are denied the possibility of exoneration under Article 26(3) GDPR (see Auernhammer/Schreibauer, loc. cit., Article 26, para. 18) is not to be followed. While Article 26(3) GDPR states that, irrespective of the details of the agreement between the joint controllers, the data subject may assert their rights under this Regulation against each of the controllers individually, Article 82(3) and (4) GDPR contains a more specific provision for claims for damages. This provision, in addition to the inherent joint and several liability, also allows the controller, under the stringent conditions of Article 82(3) GDPR, to provide individual evidence of exoneration (Spoerr in BeckOK DatenschutzR, loc. cit., GDPR Article 26, para. 63). It is argued that the provision in Article 26(3) GDPR only concerns the rights regulated in Chapter 3 of the GDPR, i.e., the rights regulated in Articles 12 to 23 GDPR (see Bertermann in Ehmann/Selmayr, loc. cit., Article 26, para. 29), or that while Article 26(3) GDPR enables the data subject to assert their rights against any controller, the obligation to comply is governed by the agreement reached (see Piltz in Gola/Heckmann, GDPR, 3rd ed. 2022, Article 26, paras. 35 et seq.).
Paragraph 245
However, the defendant has failed to prove that it bears no responsibility whatsoever for the circumstances that caused the damage. The defendant has merely submitted the agreement concluded with the third-party companies pursuant to Article 26 GDPR. It is irrelevant whether, based solely on this agreement, the defendant was entitled to assume that the website operator exercised the necessary due diligence in obtaining consent. Even if this were the case, the defendant would at least have to demonstrate, and if necessary prove, that it was unaware of the faulty implementation of the business tools on the third-party websites z….de and m….de – for example, due to complaints from other customers. No evidence has been presented to this effect.
Paragraph 246
5.
The amount of non-material damages under Article 82(1) GDPR is governed by national law, as the General Data Protection Regulation does not establish rules for calculating the damages owed under Article 82 GDPR. Therefore, damages must be estimated pursuant to Section 287 of the German Code of Civil Procedure (ZPO), taking into account the EU principles of equivalence and effectiveness. The decisive factor is the amount required to ensure full and effective compensation for the damage suffered, as set out in Recital 146 of the GDPR, whereby neither the degree of fault nor the existence of a right to injunctive relief is to be taken into account as reducing the claim (see CJEU, Judgment of 4 September 2025, C-655/23, paragraphs 69, 72 et seq., 83).
The decisive factor is the amount required to ensure full and effective compensation for the damage suffered, as set out in Recital 146 of the GDPR, whereby neither the degree of fault nor the existence of a right to injunctive relief is to be taken into account as a mitigating factor (see CJEU, Judgment of 4 September 2025, C-655/23, paragraphs 69, 72 et seq., 83). Paragraph 247
It must be taken into account that the data processing by the defendant is particularly extensive, as it potentially involves unlimited data on the online activities of its users and can create the impression that users' private lives are being continuously monitored (Higher Regional Court of Dresden, loc. cit., para. 197; Higher Regional Court of Jena, judgment of March 2, 2026, 3 U 31/25, BeckRS 2026, 2610, para. 156). In particular, there is a risk that, even if consent is refused, the defendant will use the data obtained via the business tools to create a detailed profile of the user (Higher Regional Court of Dresden, loc. cit., para. 197). Furthermore, from the plaintiff's perspective, it cannot be ruled out that particularly sensitive data within the meaning of Article 9(1) GDPR, such as health data or data concerning sexual orientation, are also affected by the data processing in question, since for the transmission of sensitive data it is sufficient that the plaintiff clicks on articles with relevant topics on a website such as z....de, and it is unlikely that the plaintiff, like any other internet user, would be able to trace his online activity in detail afterwards (cf. Jena Higher Regional Court, judgment of March 2, 2026, 3 U 31/25, BeckRS 2026, 2610, para. 90). The feeling of being under constant surveillance can give rise to the desire to refrain from clicking on such articles or visiting websites with such topics (see Higher Regional Court of Dresden, loc. cit., para. 197; Higher Regional Court of Naumburg, judgment of February 5, 2026, 9 U 44/25, juris, para. 356).
Paragraph 248
For these reasons, the Senate considers damages in the amount of €500.00 to be appropriate.
Paragraph 249
6.
The plaintiff is not entitled to any further damages, even on the grounds of a violation of his general right of personality.
Paragraph 250
The fact that the plaintiff is entitled to damages under Article 82 GDPR does not preclude a claim for damages under Article 823(1) of the German Civil Code (BGB) for infringement of the general right of personality (Federal Court of Justice, Judgment of July 29, 2025, VI ZR 426/24, para. 36). The general right of personality also includes the right to informational self-determination, which ensures that information about a person is protected from non-transparent processing and use by private entities (Grüneberg/Retzlaff, loc. cit., § 823, para. 132).
Paragraph 251
According to the established case law of the Federal Court of Justice, however, a culpable infringement of the general right of personality gives rise to a claim for monetary compensation only if it constitutes a serious infringement and the impairment cannot be adequately remedied in any other way. Whether a violation of personal rights is so serious as to warrant monetary compensation can only be assessed based on all the circumstances of the individual case. In particular, the significance and scope of the infringement, the occasion and motive of the perpetrator, and the degree of their culpability must be considered. The awarding of monetary compensation under the aforementioned conditions is justified by the principle that, without it, personal rights would be insufficiently protected against serious infringements, with the consequence that legal protection of personality would be weakened (Federal Court of Justice, Judgment of March 12, 2024, VI ZR 1370/20, para. 70).
In this context, the significance and scope of the infringement, as well as the occasion and motive of the perpetrator, and the degree of their culpability, must be taken into account. Paragraph 252
In the present case, there is no serious infringement of the plaintiff's general right of personality that could not be satisfactorily remedied in any way other than by the payment of monetary compensation (see Higher Regional Court of Naumburg, loc. cit., paras. 366 et seq.; Higher Regional Court of Munich, GRUR-RS 2025, 36464, paras. 116 et seq.; Higher Regional Court of Dresden, judgment of March 17, 2026, 4 U 709/25, judgment transcript p. 33; Higher Regional Court of Hamm, judgment of March 9, 2026, I-8 U 13/25, judgment transcript p. 38; contra: Higher Regional Court of Dresden, judgment of March 12, 2026, case no. 17 U 625/25, judgment transcript p. 68). It should be noted that the plaintiff is already receiving non-material damages pursuant to Article 82 GDPR for the defendant's data protection breach. The plaintiff's suffering is further mitigated by the fact that, in the present proceedings, the processing of the plaintiff's data transmitted to the defendant via the business tool is prohibited (see Higher Regional Court of Munich, GRUR-RS 2025, 36464, para. 121). It should also be noted that the plaintiff continues to use I... and thereby already provides the defendant with a vast amount of data.
Paragraph 253
7.
The damages amount of €500.00 is subject to interest at a rate of 5 percentage points above the base interest rate from the date the action was filed, i.e., from January 20, 2024, pursuant to Sections 291 para. 1 and 288 para. 1 sentence 2 of the German Civil Code (BGB). A further claim for interest from December 5, 2023, onwards is not valid, as the plaintiff has not proven receipt of his reminder dated November 6, 2023, which the defendant disputes.
Paragraph 254
Claim No. 7 (alternative claim to the injunction claim No. 2):
Paragraph 255
The condition for a decision on the alternative claim is met, as the main claim asserted in Claim No. 2, which concerns the processing of the plaintiff's personal data on third-party websites and apps outside the defendant's networks, is unfounded in accordance with the above explanations.
Paragraph 256
The filing of the alternative claim in the appeal proceedings is admissible pursuant to Section 533 of the German Code of Civil Procedure (ZPO). The defendant has expressly refused consent. The alternative claim is, however, expedient because it concerns the same subject matter of the dispute and its admissibility is suitable for resolving the dispute within the framework of the pending legal proceedings (see Zöller/Heßler, loc. cit., § 533, para. 6). Since the factual basis for the alternative claim is the same as for the main claim, Section 533 No. 2 of the German Code of Civil Procedure (ZPO) does not preclude the admissibility of the alternative claim.
Paragraph 257
The alternative claim, however, is not sufficiently specific and is therefore inadmissible. In the alternative claim, individual processing operations are exempted from the prohibition in relation to the main claim, provided that the defendant presents and proves "justifications with an individual connection to these operations" with regard to these processing operations. Both the term "justifications" and the required "individual connection" to the respective processing operation are ambiguous and require interpretation. The same applies to the question of when the arguments presented regarding the grounds for justification are sufficient or conclusive and when these arguments are sufficiently proven. While terms requiring interpretation are not generally inadmissible in an injunction application, they are inadmissible when the dispute specifically concerns whether the challenged conduct falls under such terms (Zöller/Greger, loc. cit., § 253, para. 13c). This is the case here, as the parties are disputing precisely whether the defendant can rely on the security and integrity purposes it has asserted with regard to the data processing it has undertaken.
IV.
Paragraph 258
1.
The decision on costs is based on §§ 92 para. 1, 97 para. 1 of the German Code of Civil Procedure (ZPO).
Paragraph 259
The provisional enforceability of clauses 2.1 to 2.3 of the judgment is governed by Section 709 of the German Code of Civil Procedure (ZPO), as these claims are not for money or assets of monetary value and therefore do not constitute pecuniary disputes (see Götz in MüKo/ZPO, loc. cit., Section 708, para. 17). Insofar as the defendant argues that the security required under Section 709 ZPO must be many times the value in dispute of the relevant claim because this corresponds to the irreparable damage that enforcement would cause the defendant, the defendant fails to provide any comprehensible explanation as to why the unchanged storage and subsequent deletion of the plaintiff's personal data transmitted to the defendant via business tools should cause such damage.
Paragraph 260
In all other respects, the provisional enforceability is governed by Sections 708 No. 10 and 711 ZPO.
Paragraph 261
2.
The appeal on points of law is admissible for both parties pursuant to Section 543 Paragraph 2 Sentence 1 No. 1 of the German Code of Civil Procedure (ZPO). The case is of fundamental importance because, in an indefinite number of parallel cases, the standards to be applied to the data subjects' submissions regarding internet use are interpreted differently. Furthermore, there are differences regarding the admissibility of a declaratory judgment action, the scope of an injunction, and the question of whether the right to erasure under Article 17 GDPR also includes, as a lesser right, a right to anonymization.
Paragraph 262
3.
The value in dispute for the appeal proceedings is set at €8,500.00. The value in dispute for the proceedings before the Regional Court is to be adjusted to €7,750.00.
Paragraph 263
a)
The amount in dispute for the appeal proceedings is €8,500.00 and is composed as follows:
Paragraph 264
Applicant's appeal
Paragraph 265
- Item 1: Declaratory judgment: €500.00
Paragraph 266
- Item 2: Injunction against processing the data on third-party websites: €750.00
Paragraph 267
- Item 3: Storage: €750.00
Paragraph 268
- Item 4: Deletion/Anonymization: €750.00
Paragraph 269
- Item 5: Damages: €5,000.00
Paragraph 270
Defendant's appeal
Paragraph 271
- Item 2: Injunction against storing the data: €750.00 €
Paragraph 272
For the purposes of determining the value in dispute for the appeal proceedings, claim no. 2 must be considered twice, as it concerns two different subjects of dispute in the appeal proceedings: firstly, the prohibition of the processing of personal data on the third-party websites and apps, as per claim no. 2, and secondly, the prohibition of the storage of the data already transmitted to the defendant and therefore stored on its servers, as per the judgment of the Regional Court.
Paragraph 273
The Senate assesses the value of each injunction claim at €750.00. In the case of an injunction claim following an infringement, the decisive factor is the interest in preventing further similar infringements, which is primarily determined by the nature of the infringement, in particular its dangerousness and harmfulness to the holder of the infringed right. However, other factors independent of the infringement that has already occurred – such as the degree of probability of future infringements – may also be taken into account (Federal Court of Justice, decision of December 10, 2024, VI ZR 7/24, para. 14 with further references). The fact that the present case concerns data relating to the plaintiff's online behavior over a longer period does not demonstrate an increased risk compared to the harvesting of personal data such as telephone number, name, and place of work in so-called scraping cases. In those cases, the Federal Court of Justice has regularly set the value in dispute for injunction applications at €750.00. The Senate sees no reason to deviate from this. It is irrelevant whether the defendant's interest in having the injunction overturned outweighs the plaintiff's interest in obtaining the injunction, because, according to Section 47 Paragraph 2 Sentence 1 of the Court Costs Act (GKG), the value in dispute for the appeal proceedings is limited to the value of the subject matter of the first instance proceedings.
Paragraph 274
b)
The reduction of the value in dispute for the first instance proceedings ex officio is based on the application of Section 63 Paragraph 3 Sentence 1 No. 2 of the Court Costs Act (GKG). Thereafter, if the proceedings are pending before the appellate court regarding the merits or the decision on the value in dispute, the cost assessment, or the determination of costs, the appellate court may amend the determination within the time limits of Section 63 Paragraph 3 Sentence 2 of the Court Costs Act (OLG Stuttgart, NJW-RR 2020, 255 para. 26; Schneider, NJW 2017, 3764, each with further references). The decision falls within these limits, as the regional court's judgment has not yet become final.
Paragraph 275
The explanations regarding the value in dispute in the appeal proceedings apply accordingly to the value in dispute at the regional court. However, with regard to claim no. 2, the value of €750.00 is to be considered only once, as the plaintiff's claim was solely directed at the processing of his data on third-party websites and apps. The amount in dispute for the proceedings before the regional court is therefore €7,750.00.
...




