SG Nürnberg - S 5 SF 65/24 DS

From GDPRhub
SG Nürnberg - S 5 SF 65/24 DS
Court: SG Nürnberg (Germany)
Jurisdiction: Germany
Relevant Law: Article 4(7) GDPR
Article 4(8) GDPR
Article 4(10) GDPR
Article 4(12) GDPR
Article 5(1)(f) GDPR
Article 24(1) GDPR
Article 24(1) GDPR
Article 26 GDPR
Article 28 GDPR
Article 32(1) GDPR
Article 32(2) GDPR
Article 82(1) GDPR
Article 82(2) GDPR
Article 85 GDPR
§ 183 SGG
§ 81b(1) SGB X
Decided: 10.06.2026
Published: 18.06.2026
Parties:
National Case Number/Name: S 5 SF 65/24 DS
European Case Law Identifier:
Appeal from:
Appeal to: Unknown
Original Language(s): German
Original Source: sozialgerichtsbarkeit.de (in German)
Initial Contributor: n/a

A court dismissed a data subject's €3,000 damages claim against a health insurer and its processor, holding that a zero-day vulnerability, which led to a data breach, did not violate security requirements under Article 32 GDPR.

English Summary

Facts

The data subject (a child born in 2018), represented by her parents, was insured with the controller (a statutory health insurance provider) and participated in its digital bonus programme. The bonus programme was managed via an app. To handle the information technology operations of this programme, the controller hired the processor (an IT service provider), establishing a data processing agreement under Article 28 GDPR alongside specific information security guidelines.

To provide these services, the processor utilised "MOVEit Transfer," a market-leading file transfer software developed by Progress Software Corp.

On 31 May 2023, the software developer publicly announced a critical, previously unknown "zero-day" vulnerability in the software (later assigned CVE-2023-34362). At that exact moment, no security patch was available.

On the very same day, 31 May 2023, the processor – alongside thousands of other companies worldwide – became the victim of a global cyberattack carried out by the hacker group "Clop." The hackers exploited this zero-day vulnerability to install a "web-shell" backdoor (typically named human2.aspx), bypassing authentication to exfiltrate database records. The compromised data included the data subject's first and last name, health insurance number, bonus points balance, and a bank account number (IBAN) belonging to her mother. No medical, health, or social security data was exfiltrated.

On 1 June 2023, the developer released a security patch, which the processor installed immediately.

On 2 June 2023, the German Federal Office for Information Security (BSI) issued a formal IT security warning (No. 2023-240133-1100, Version 1.1). The BSI classified the IT threat level as "3 / Orange" (business-critical), confirming active exploitation with data exfiltration. The BSI recommended immediately blocking all HTTP and HTTPS traffic to MOVEit environments, checking for specific Indicators of Compromise (IoCs) in the web server directories, and applying the newly released patch before reconnecting systems to the network.

On 16 June 2023, the processor informed the controller about the incident.

On 17 June 2023, the controller issued a public press release confirming that its external service provider for the bonus programme had been targeted on 31 May 2023. The release stated that the security vulnerability had been closed, that there was never any connection to the controller's internal IT systems, and that relevant supervisory authorities had been notified. The controller subsequently notified the data subject's parents.

On 27 March 2024, the data subject, via legal counsel, sent a formal warning letter to the controller demanding an injunction, a declaration of liability for all potential future damages, and non-material damages of at least €3,000. Following the controller's refusal, the data subject filed a lawsuit with the Nuremberg Social Court (Sozialgericht Nürnberg), later expanding the claim to the processor as a joint defendant.

Holding

The Court dismissed the lawsuit as partly inadmissible and otherwise unfounded, establishing the following legal principles:

First, the Court held that a successful third-party cyberattack does not establish an irrebuttable presumption that a controller or processor failed to implement appropriate security measures under Article 32(1) GDPR and Article 5(1)(f) GDPR. To escape liability under Article 82(3) GDPR, an operator must prove they implemented robust baseline security controls (such as multi-factor authentication, encryption, and lockout policies) and applied a security patch immediately upon its release by the vendor, even if this occurred before formal alerts were issued by national IT security authorities.

Second, the Court held that a claim for non-material damages under Article 82(1) GDPR based on the fear or distress of future data misuse cannot be established if the data subject is a minor who has no subjective knowledge or cognitive awareness of the data breach. Furthermore, if the compromised financial data (such as an IBAN) does not belong to the data subject personally, there is no direct risk of financial harm to them, rendering the alleged fear of financial damage unfounded.

Third, the Court held that an injunction claim is inadmissible due to a lack of specificity if it merely demands that a controller stop making personal data accessible to third parties without implementing "state-of-the-art" security measures, without specifying the concrete technical or organisational measures the controller is required to take.

Fourth, the Court held that a declaratory claim for potential future material damages is inadmissible under national procedural law (§ 55(1) SGG) if there is no realistic probability of future financial harm, particularly because the compromised bank account belonged to a third party (the mother) and the software vulnerability was immediately patched.

Comment

This judgment is legally and technically flawed because the Court fundamentally misapplied the concept of the "state of the art" under Article 32(1) of the General Data Protection Regulation. By treating a classic SQL injection vulnerability as an unavoidable, force-majeure "zero-day" event, the Court collapsed the strict statutory requirement of the state of the art into a much weaker standard of mere "common market practice."

Under Article 32(1) GDPR, both controllers and processors are legally bound to ensure a level of security appropriate to the risk, explicitly taking into account the state of the art. As in commentary (e.g. Hansen, in: Simitis/Hornung/Spiecker gen. Döhmann, Datenschutzrecht, 2nd edition 2025, Article 32, Paragraphs 15–16), while Article 32 does not directly bind software manufacturers, it creates a strict indirect obligation for controllers and processors. They must carefully select, evaluate, and deploy only those products and services that actively enable them to fulfill their data protection obligations. Software with glaring, un-audited security gaps must not be deployed.

In modern software engineering, a secure software development lifecycle, which integrates automated static application security testing, dynamic application security testing, and software composition analysis, is the indisputable state of the art. SQL injection is one of the oldest, most thoroughly documented, and easily preventable vulnerability classes in existence. It can be entirely neutralized during the development phase through standardized automated tools. The fact that a commercial file transfer platform allowed unauthenticated database access through such a fundamental flaw demonstrates a systemic failure of secure-by-design principles at the development level.

The Court's reasoning creates a dangerous legal safe harbour that actively undermines the preventive purpose of Article 32 GDPR. Under the Court’s flawed logic, an operator is fully exculpated from liability under Article 82(3) GDPR simply by procuring a widely used, "market-leading" commercial product, regardless of how deficient that product's underlying security architecture is. This effectively shifts the entire risk of vendor-side engineering failures onto the data subjects. By failing to scrutinize whether the software itself complied with the secure software development lifecycle as the state of the art, the Court misapplied the law, transforming what should be a rigorous assessment of technical security into a superficial checklist of vendor popularity.

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the German original. Please refer to the German original for more details.

BASIC INFORMATION Case Reference / Case Number

S 5 SF 65/24 DS

Court

Social Court (SG) of Nuremberg

Category

Subject Area

Other Proceedings

Relationships 1st Instance

Court

Social Court of Nuremberg

Case Reference / Case Number

S 5 SF 65/24 DS

Date

10.06.2026

2nd Instance Court

Case Reference / Case Number Date 3rd Instance Court

Case Reference / Case Number Date DECISION TEXT I. The
action is dismissed. II. The Plaintiff shall bear the costs
of the proceedings as well as the necessary extrajudicial
expenses of both Defendants. III. The value in dispute is
set at EUR 10.000,00.

FACTS OF THE CASE: The parties are in dispute over the award
of compensation for damage due to an asserted data
protection violation following a hacker attack on
31.05.2023. In addition, the Plaintiff seeks a declaration
of liability for compensation for potential future damage in
principle, an injunction against the unauthorised disclosure
of personal data, and indemnification from pre-litigation
legal fees.

The Plaintiff, born in 2018, is statutorily health-insured
with the Defendant under 1) and participates in its bonus
programme, which is operated via an app. Under this
programme, EUR 10,00 is paid out to the insured person for
every 100 points collected. Points can be collected through
regular participation in preventive medical check-ups as
well as sports and leisure programmes. For the information
technology processing of its bonus programme, the Defendant
under 1) uses a processor, the Defendant under 2). The
Defendant under 2) uses the program M-IT of the US company
P-Corp. (hereinafter: "P.") to provide the contractually
owed services. This is a software program for the exchange
of data. The Defendant under 1) has concluded an agreement
on processing with the Defendant under 2). The associated
general framework conditions on "Information Security"
regulate the technical and organisational measures to be
complied with by the Defendant under 2) as processor. These
include, among other things, requirements for infrastructure
security and protection against malware. For example, the
Defendant under 2) is required to have malware detection and
repair software installed that corresponds to the state of
the art and must reliably prevent the exfiltration of the
controller's data.

On 31.05.2023, the Defendant under 2), along with a large
number of affected companies and public authorities
worldwide, became the victim of a hacker attack by the
hacker group C., in the course of which a data breach
occurred, by which, inter alia, the Plaintiff was also
affected. By uploading a so-called "web shell" onto the
affected server of the Defendant under 2), the hackers
succeeded in gaining access to its system and exfiltrating
customer data – including that of the Plaintiff. The data
affected by the hacker attack consists of first name,
surname, health insurance number, premium amount (the
proceeds from successful participation in the bonus
programme) and bank details (IBAN). In this case, the bank
details are not those of the Plaintiff, but of her mother.
Furthermore, health data of the Plaintiff was not affected.
No data was exfiltrated from the servers of the Defendant
under 1) either. The actions of the group C. were, as far as
is known, not directed against the respective data subjects,
but against the companies affected by the attack in order to
extort them. The hackers had succeeded in accessing this
data via an unknown vulnerability in the program MOVEit.
This was a so-called "zero-day exploit", i.e. a security
vulnerability previously unknown to the software
manufacturer and the Defendants. Still on 31.05.2023, the
company P. issued a security warning. A corresponding
warning, referencing the prior warning by P., was issued by
the Federal Office for Information Security (BSI) on
02.06.2023 (security level 4 warning). One day after the
vulnerability became known on 31.05.2023, P. provided the
security patch to eliminate the threat, which was
immediately installed by the Defendant under 2). The
Defendant under 1) itself was, according to its submission,
informed of the events on 16.06.2023 and issued a
corresponding press release the following day. Subsequently,
it also informed the Plaintiff's parents as her statutory
representatives.

By lawyer's letter dated 27.03.2024, the Plaintiff requested
the Defendant under 1) to cease and desist, to pay
compensation for non-material damage in an amount of at
least EUR 3.000,00, and to agree to an obligation to
compensate the Plaintiff for all future damage that might
still arise for her as a result of the unauthorised access
by third parties to the personal data.

After the Defendant under 1) had rejected the Plaintiff's
demands by letter dated 03.04.2024, the Plaintiff brought an
action before the Social Court of Nuremberg – initially only
against the Defendant under 1). By pleading dated
12.12.2024, she extended the action to the Defendant under
2). She claims to have become the victim of a data breach at
the Defendant under 1) because the latter had taken
insufficient technical measures to adequately protect
personal data. Consequently, the personal data of the
Plaintiff could be obtained by unauthorised persons. The IT
forensic experts of K. had supposedly found indications that
the hackers had already been aware of the vulnerability
since the year 2021. Since then, they had most likely
experimented on how best to abuse the gap. The MOVEit
software had stood out for years due to such (SQL injection)
vulnerabilities, and the IT security expert T. had also
commented to this effect on X. He spoke in particular of the
fact that the use of such software was to be assessed as
"negligent". The Defendant under 1) should have taken the
following protective measures in particular:
pseudonymisation and/or encryption of the personal data, as
well as a process for regularly testing, assessing and
evaluating the effectiveness of the technical and
organisational measures. If the Defendant had properly
carried out these protective measures, the data breach would
not have occurred and unauthorised persons would not have
gained access to the Plaintiff's data. Even if the data
breach had occurred "only" at the Defendant under 2), the
Defendant under 1) would also be liable in this case. This
is because, as the controller under data protection law, it
must ensure that all of its contractual partners who process
personal data of Barmer customers within the scope of
processing also work in compliance with data protection law.
To this end, the Defendant should have instructed and
monitored the processor accordingly. Both Defendants are
joint controllers under Art 26 of the General Data
Protection Regulation (GDPR). The use of the MOVEit software
at the time the data breach was exploited by the hacker
group was grossly negligent. Through a more modern, albeit
more expensive software, the data breach would have been
avoided. The Defendant under 1) is obliged under Art 32 GDPR
to implement appropriate and suitable technical and
organisational measures (TOM) to ensure a level of security
appropriate to the risk. The Defendant under 1) culpably
failed to take and implement suitable technical and
organisational measures to prevent a disclosure of personal
data. The Defendant has therefore (also) infringed the
requirements of Art 32 GDPR. Due to the ongoing loss of
control over personal and sensitive data, the Plaintiff is
entitled to a claim for non-material damages under Art 82
para 1 GDPR. The actual damage lies in the ongoing state of
existing and distressing uncertainty regarding the
unauthorised publication of the personal data. The Plaintiff
is worried that her bank and/or securities account data will
be hacked. It must be assumed that the Plaintiff's data is
already being offered for sale on the so-called "darknet".
Furthermore, it must be expected that the Plaintiff's data
has been or will be used by criminals to obtain unauthorised
access to bank accounts, online services, etc., in order to
cause financial harm to the Plaintiff. The linking and
downstream publication of personal data, such as at least
the first name and surname as well as potentially other
data, opens the floodgates to abuse. The loss of the social
security number (note: this was not exfiltrated, see above)
also significantly increases the risk of identity theft. In
addition, the mere fact that the Plaintiff's data is
available to an unknown number of unauthorised persons is
frightening for her, as it is not yet known in what way it
might be misused. Furthermore, the Defendant must bear the
Plaintiff's pre-litigation legal fees, based on an amount in
dispute of EUR 10.000,00.

The Plaintiff requests that,

1. the Defendants be ordered as joint and several debtors to
   pay to the Plaintiff, as compensation for data protection
   violations, non-material damages, the amount of which is
   left to the discretion of the Court, but should not be
   less than EUR 3.000,00, plus interest in the amount of 5
   percentage points above the respective base rate since
   lis pendens.
2. it be declared that the Defendants are obliged to
   compensate the Plaintiff for all future material damage
   that has arisen and/or will yet arise for the Plaintiff
   as a result of the unauthorised access by third parties
   to the Defendants' data archive containing the personal
   data of the Plaintiff, which, according to current
   information, occurred on 31.05.2023.
3. the Defendants be ordered, under penalty of a
   court-established administrative fine of up to EUR
   250.000,00 for each case of infringement, or
   alternatively administrative detention to be executed on
   their statutory representative, or administrative
   detention of up to 6 months to be executed on their
   statutory representative, and in the event of repeated
   infringement up to 2 years, to refrain from making
   personal data of the Plaintiff, namely first name,
   surname, health insurance number, premium amount, as well
   as the bank details, accessible to third parties without
   implementing the security measures possible according to
   the state of the art and without the consent of the
   Plaintiff or a justification under the GDPR.
4. the Defendant under 1) be ordered to indemnify the
   Plaintiff from pre-litigation costs for legal
   representation in the amount of EUR 973,65 plus interest
   in the amount of 5 percentage points above the respective
   base rate since lis pendens.

The Defendants request that,

the action be dismissed.

The Defendant under 1) submits that it is not known that any
personal data of the Plaintiff has been published anywhere.
It contends that in this case there is already a lack of any
infringement of rights attributable to the Defendants. It
argues that it is therefore exempt from liability (Art 82
para 3 GDPR). It submits that there has been no failure by
the Defendant under 1) to comply with its obligations under
the GDPR. It states that it used the Defendant under 2) to
carry out certain processing of personal data within the
framework of operating its bonus programme. It asserts that
a proper agreement on processing in accordance with Art 28
GDPR was concluded with the Defendant under 2), under which
the latter specifically committed itself to certain TOMs in
order to meet the requirements of Art 32 GDPR. It argues
that Art 32 para 1 GDPR merely contains examples of measures
that are to be taken "as appropriate". It contends that
these are to be implemented – if at all – only to the extent
and in the scope to which they are suitable and necessary to
achieve an appropriate level of security. In particular, it
submits that Art 32 para 1 GDPR itself does not determine
when such measures are required. It argues that the GDPR
does not demand absolute protection (which would also be
impossible), but merely technical and organisational
measures to ensure a level of security appropriate to the
risk (Art 32 para 1 GDPR). It asserts that the fact that a
hacker attack was successful in no way proves a lack of an
appropriate level of security. It argues that the
Plaintiff's submission claiming otherwise misunderstands the
legal framework. Furthermore, it states that already on
02.06.2023 at 10:17 am, the system was secured with a
security patch provided by the manufacturer, so that further
attacks and, in particular, the exfiltration of further data
could be prevented. Moreover, health data of the Plaintiff
was not affected. It submits that it was not foreseeable for
either of the two Defendants that the Defendant under 2),
like several thousand other companies worldwide, would
become the victim of a hacker attack by a group of
apparently Russian criminals. Furthermore, it argues that
the Plaintiff's submission does not demonstrate any damage
that could be compensable. In this case, it contends that it
is also impossible to rely on the fear of misuse of the data
as non-material damage. This is because it would require
that a misuse can actually be feared under the given
circumstances and with regard to the data subject. On the
one hand, it states that there is a complete lack of any
submissions to this effect. On the other hand, it argues
that this is also entirely improbable. It asserts that since
the hacker attack on the processor of the Defendant under 1)
in May 2023, to the knowledge of the Defendant, no data of
data subjects has been misused. It argues that the objective
of the attack was also recognisably in no way the misuse of
the data of data subjects, but rather the extortion of the
Defendant under 1) as controller and the Defendant under 2)
as processor. In addition, the Defendant under 1) submits
that it is not a "joint controller" with the Defendant under
2) under Art 26 GDPR. It argues that there is instead a
relationship of processing under Art 28 GDPR.

The Defendant under 2) submits that it never had access to
the source code of the MOVEit application. It states that
for security reasons, this is kept strictly confidential by
the manufacturer. It argues that all bug fixes must
therefore be provided by the manufacturer. It contends that
the critical vulnerability of the MOVEit application was no
exception to this. Its correction was only possible for the
manufacturer. It states that the mobile number and the email
address of the Plaintiff were precisely not exfiltrated.
With regard to the bank details, it argues that damage can
easily be prevented by changing the account. It asserts that
at the time of the data protection incident, taking into
account the state of the art, the MOVEit application was a
secure application and was considered insurmountable. The
Defendant under 2) submits that it was entitled to assume
that the software corresponded to the state of the art. It
states that the manufacturer of the software, the company
P., actively supports the MOVEit application and regularly
provides updates with bug fixes. It argues that this was
also the case at the time of the cyberattack. As the
handling of the cyberattack shows, the support provided by
P. was also highly professional. Already one day after the
vulnerability exploited on 31.05.2023 became known, P. made
the security patch available to eliminate the threat.
Reference is made to the numerous certifications of P. It
states that it has itself also taken comprehensive TOMs,
which the Defendant under 2) lists in its pleading dated
19.02.2025. Reference is made to this pleading. The
Defendant under 2) further submits that prior to the data
breach in 2023, it had in any event no knowledge whatsoever
of any critical vulnerabilities in the software used. It
argues that if liability under data protection law were to
exist for the Defendants for using software of a carefully
selected software manufacturer solely because a
vulnerability in the software became apparent, the
exploitation of which could by its nature not be prevented
by properly implemented accompanying security measures,
liability under data protection law would escalate into pure
strict liability for the use of software. It contends that
liability under data protection law under Article 82 GDPR
was not designed as such, as this would exclude any
exculpation for any software user. It states that the
Plaintiff is free to hold P. liable as the manufacturer.

By pleading dated 17.01.2025, the Defendant under 1)
submitted a decision of the Federal Commissioner for Data
Protection and Freedom of Information addressed to another
insured person regarding the hacker attack in dispute. The
decision states: "Art 32 GDPR merely obliges the
implementation of a risk management system, but does not
prescribe that controllers must eliminate the risk of data
protection violations altogether (...). Even the fact that
third parties can gain unauthorised access to personal data
does not in itself mean that the technical and
organisational measures taken were not 'appropriate'. (...).
A data protection violation on the part of BARMER does not
therefore exist."

In the course of the oral hearing, the Chamber examined the
Plaintiff's father for information purposes. He stated that
the affected account is the account of the Plaintiff's
mother. He explained that the account still exists, although
a second current account has since been set up. He added
that most transactions now run through his own account.
According to his statements, there are no indications that
the account of the Plaintiff's mother has been hacked. He
further stated that he does not know whether the data is
appearing or being offered on the darknet. He explained that
the Plaintiff herself "has no knowledge of the entire
process surrounding the data breach".

With regard to the further details of the state of the facts
and the dispute, reference is made to the court file and the
mutual pleadings.

REASONS FOR THE DECISION:

The action, which is admissible with regard to the claims
under numbers 1 and 4, is unfounded. Insofar as the
Plaintiff brought an action for a declaration in objective
joinder of claims under number 2 and seeks an injunction
under number 3 of her statement of claim, these actions are
already inadmissible.

I.) Venue and Jurisdiction The legal venue of the social
jurisdiction is established. The Plaintiff alleges an
infringement of the GDPR. For actions brought by the data
subject against a controller or a processor on the grounds
of an infringement of this Regulation, the legal venue
before the courts of the social jurisdiction is established
according to the explicit wording of § 81b para 1 of Book X
of the German Social Code (SGB X) (cf. on compensation also
Federal Social Court - BSG - decision dated 6 March 2023 - B
1 SF 1/22 R - juris).

II.) Compensation for Damage Insofar as the Plaintiff seeks
compensation for an asserted non-material damage of at least
EUR 3.000,00, the action proves to be unfounded. Pursuant to
Art 82 para 1 GDPR, any person who has suffered material or
non-material damage as a result of an infringement of this
Regulation shall have the right to receive compensation from
the controller or processor for the damage suffered.
Pursuant to Art 82 para 3 GDPR, the controller or processor
shall be exempt from liability if it proves that it is not
in any way responsible for the event giving rise to the
damage. Pursuant to Art 82 para 4 GDPR, both the controller
– here the Defendant under 1) pursuant to Art 4 no 7 GDPR –
and the processor – here the Defendant under 2) pursuant to
Art 4 no 8 GDPR – shall be held liable as joint and several
debtors for any damage caused.  

The requirements for a claim for compensation under Art 82
para 1 GDPR are not met. The Chamber could not satisfy
itself of a culpable infringement of the GDPR by the
Defendants. Furthermore, there is a lack of any non-material
damage.

1.) Pursuant to Art 5 para 1 lit f GDPR, personal data must
be processed in a manner that ensures appropriate security
of the personal data, including protection against
unauthorised or unlawful processing and against accidental
loss, destruction or damage, using appropriate technical and
organisational measures. The controller (Art 4 no 7 GDPR) –
in this case the Defendant under 1) – must demonstrate
compliance with this, cf. Art 5 para 2 GDPR. Pursuant to Art
24 para 1 sentence 1 GDPR, taking into account the nature,
scope, context and purposes of processing as well as the
risks of varying likelihood and severity for the rights and
freedoms of natural persons, the controller shall implement
appropriate technical and organisational measures to ensure
and to be able to demonstrate that processing is performed
in accordance with this Regulation. Pursuant to Art 24 para
2 GDPR, those measures shall include the implementation of
appropriate data protection policies by the controller,
where proportionate in relation to processing activities.
Furthermore, Art 32 para 1 GDPR provides that the controller
and the processor shall implement appropriate technical and
organisational measures to ensure a level of security
appropriate to the risk. This shall be done taking into
account the state of the art, the costs of implementation
and the nature, scope, context and purposes of processing as
well as the risk of varying likelihood and severity for the
rights and freedoms of natural persons.  

The European Court of Justice (ECJ), in its judgment dated
14.12.2023 - C-340/21 - juris, lays down the essential
principles. In this regard, it states (underlining added):

"The reference in Articles 32(1) and (2) of the GDPR to 'a
level of security appropriate to the risk' and to 'an
appropriate level of security' shows that that regulation
establishes a risk management system and in no way claims to
eliminate the risk of personal data breaches" (cf. ECJ, loc.
cit., para 29). On this basis, the ECJ also assumes that
there can be no absolute protection in a digital world –
just as in an analogue world – but rather that a risk
management system is the meaning and purpose of Art 32 GDPR.
Subsequently, the ECJ states that it follows from the
wording of Articles 24 and 32 GDPR that those provisions
merely require the controller to adopt technical and
organisational measures designed to prevent any personal
data breach as far as possible. The suitability of such
measures must be assessed in a concrete manner, by examining
whether the controller adopted those measures taking into
account the various criteria laid down in those articles and
the data protection needs specifically linked to the
processing in question and the risks presented by the latter
(cf. ECJ, loc. cit., para 30). The ECJ then explicitly
states (underlining added): "Consequently, Articles 24 and
32 of the GDPR cannot be understood as meaning that an
unauthorised disclosure of or unauthorised access to
personal data by a third party is sufficient to conclude
that the measures adopted by the controller for the
processing in question were not appropriate within the
meaning of those provisions, without even allowing the
controller to provide proof to the contrary. Such an
interpretation is all the more necessary given that Article
24 of the GDPR expressly provides that the controller must
be able to demonstrate that the measures implemented by him
or her are compliant with the GDPR, an opportunity of which
he or she would be deprived if an irrebuttable presumption
were accepted", cf. ECJ, loc. cit., para 31 et seq.

The burden of proving that personal data is processed in a
manner that ensures appropriate security of that data within
the meaning of Art 5 para 1 lit f and Art 32 GDPR lies with
the controller for the processing in question (cf. ECJ, loc.
cit., para 52). Regarding cases of cybercrime, the ECJ
states (underlining added): "Where (...) a personal data
breach within the meaning of Article 4(12) of the GDPR was
committed by cybercriminals, and therefore by 'third
parties' within the meaning of Article 4(10) thereof, that
breach can be imputed to the controller only if he or she
made that breach possible by failing to comply with an
obligation under the GDPR, in particular the data protection
obligation imposed on him or her under Article 5(1)(f),
Article 24 and Article 32 of that regulation. Thus, in the
event of a personal data breach by a third party, the
controller may exempt himself or herself from liability
under Article 82(3) of the GDPR by proving that there is no
causal link between the breach of the data protection
obligation potentially committed by him or her and the
damage suffered by the natural person", cf. ECJ, loc. cit.,
para 71 et seq.

Accordingly, while hacker attacks do not per se exempt a
party from liability, especially not if the controller or
its processor implemented insufficient protective measures
(cf. to this effect also ECJ, loc. cit., para 74), the
controller may nevertheless prove that it is not in any way
responsible for the event giving rise to the damage in
question.

Taking these principles into account, the deciding Chamber
could not satisfy itself of any responsibility on the part
of the Defendants. Indeed, the Defendants have demonstrated
in a substantiated and comprehensive manner that, at the
time of the incident in dispute, the MOVEit application was
established in the market as one of the market-leading
applications in the field of managed file transfer software.
P. and its software were certified accordingly. Furthermore,
in its pleading dated 19.02.2025, the Defendant under 2)
comprehensively set out its own measures, in particular:

Access to the MOVEit application only upon authentication by
means of a user account, whereby the creation of user
accounts was carried out in a stringent process preceded by
an application, approval, and identity verification.

Every user receives a unique, personalised, user-specific
identifier.

Within the MOVEit application, after 5 unsuccessful login
attempts within a time window of 6 minutes, the user account
is automatically locked for 30 minutes. In addition, the
MOVEit Transfer platform blocks the IP address of a terminal
device if repeated failed attempts are detected from that
address within a time window of 5 minutes. The unblocking of
an IP address can only be performed by the competent IT
department of the Defendant under 2) and requires a prior
review of the event.

Comprehensive requirements for the password to be defined
(for details on this, see the pleading dated 19.02.2025).

Communication with the MOVEit Transfer platform is permitted
only via secure protocols (FTPS, SFTP, HTTPS, AS2). During
file transfer, MOVEit uses SSL or SSH to encrypt
communication.

At the time of the attack, version 2021.1 (13.1.0.39) was in
use and complied with the manufacturer's security
specifications at that time. Reference is made to the
further measures outlined in the pleading dated 19.02.2025.
The mere fact that a hacker attack was successful does not
prove that the technical and organisational measures in
advance were insufficient (cf. Higher Regional Court (OLG)
of Stuttgart, judgment dated 31.03.2021 - 9 U 34/21 - juris
para 54), especially since, according to the Plaintiff's
submission, the hackers had been trying to penetrate the
system since approximately 2021. Thus, assuming this to be
correct, they required approximately two years to get into
the system. It is precisely this length of time until a
successful attack at the end of May 2023 that also proves
the security of the software. Insofar as the Plaintiff
argues that the Defendants could have taken further
technical measures, of which she lists several, this does
not give rise to any duty of implementation, the
non-compliance with which could constitute a data protection
violation. The Defendants are merely obliged to implement
suitable measures designed to prevent a data protection
breach as far as possible (cf. Regional Court (LG) of
Krefeld, judgment dated 06.11.2025 - 3 O 93/24 -, juris,
para 30, with further references). The Chamber fully shares
the view of the Regional Court of Krefeld regarding the
hacker attack in dispute. It states: "The TOMs described by
the Defendants would only be insufficient if concrete
indications of the error-proneness of the G. application –
which was the market leader at the time of the incident –
had previously arisen. In this regard, the Plaintiff's
allegations are generalized and lack detailed substance. She
refers to an unyielding public post as well as to so-called
CVE entries in a vulnerability database. However, this does
not show whether the Defendants specifically perceived these
circumstances before the cyberattack or ought to have
perceived them, as the latter source in particular rather
suggests that the program was and is regularly reviewed and
further developed in terms of security by the manufacturer.
The assumption that the Defendants ought to have had
corresponding doubts is countered by the fact that
approximately 2,500 companies and institutions worldwide
fell victim to this – in this respect unforeseen – so-called
'zero-day exploit'. The Defendant under 1) had no reason for
increased monitoring of the Defendant under 2); doubts
regarding the suitability of the Defendant under 2) as a
processor were not submitted.", cf. Regional Court of
Krefeld, loc. cit., para 30. In this regard as well, it is
not apparent to the deciding Chamber how the Defendants –
rather than, if anyone, the manufacturer "P." – could have
detected the vulnerability in the software. The Regional
Court of Trier furthermore states: "Furthermore, a software
program was responsible for the exfiltration of data which
was developed neither by the Defendant nor by its
intervener, but by P.. Until the incident in dispute, the
software was (undisputedly) established in the market as a
market-leading application acting as a data security and
data protection compliant exchange platform, which was also
demonstrated by the potential affection of approximately
2,500 companies and public bodies by the cyberattack.", cf.
Regional Court of Trier, judgment dated 04.04.2025 - 2 O
85/24 - juris, para 53. If at all, a charge of negligent
conduct can therefore be made against the manufacturer, but
not against the Defendants, who relied entirely on the
software of a global market leader. Likewise, no culpable
error on the part of the Defendant under 1) can be
established regarding the selection decision of the
Defendant under 2) as a processor.

Accordingly, there is no (attributable) infringement of the
GDPR by the Defendants.

2.) Furthermore, in the present case, there is a lack of any
compensable non-material damage. In this regard, the
Plaintiff submits in her pleadings that the actual damage
lies in the ongoing state of existing and distressing
uncertainty regarding the unauthorised publication of the
personal data. Moreover, it is argued that the circumstances
have led to worries and anxieties on the part of the
Plaintiff. The Plaintiff is also said to be worried that her
bank and/or securities account data will be hacked. It is
asserted that it must be assumed that the Plaintiff's data
is already being offered for sale on the so-called
"darknet". Furthermore, it is claimed that it must be
expected that the Plaintiff's data has been or will be used
by criminals to obtain unauthorised access to bank accounts,
online services, etc., in order to cause financial harm to
the Plaintiff. The linking and downstream publication of
personal data, such as at least the first name and surname
as well as potentially other data, is said to open the
floodgates to abuse. The loss of the social security number
(note: this was not exfiltrated, see above) also allegedly
increases the risk of identity theft significantly. In
addition, the mere fact that the Plaintiff's data is
available to an unknown number of unauthorised persons is
stated to be frightening for her, as it is not yet known in
what way it might be misused.

The Plaintiff's submission regarding the alleged damage is
largely unsubstantiated. While the compensation of
non-material damage is not dependent on exceeding a certain
threshold of gravity (cf. ECJ, judgment dated 04.05.2023 -
C-300/21 - juris) and, according to Recital 85 GDPR, a
personal data breach may result in physical, material or
non-material damage for natural persons, such as loss of
control over personal data or identity theft, this does not
alter the fact that a corresponding examination of the
existence of damage must always be carried out in the
specific individual case to be decided. Indeed, the loss of
control may merely constitute damage, but does not
necessarily have to do so. In this regard, the ECJ states in
its judgment dated 14.12.2023, loc. cit., paras 84 et seq.
(underlining added): "However, it must be pointed out that a
person affected by a personal data breach which has had
negative consequences for him or her must demonstrate that
those consequences constitute non-material damage within the
meaning of Article 82 of the GDPR (...). In particular,
where a person seeking compensation on that basis relies on
the fear that his or her personal data will be misused in
the future as a result of such a breach, the national court
seised must examine whether that fear can be regarded as
well founded, in the light of the specific circumstances and
with regard to the data subject."

Accordingly, it is incumbent upon the Chamber to examine
whether the Plaintiff's fears can be regarded as well
founded. In this connection, it must be taken into account
that the Plaintiff, who is currently 8 years old and was 5
years old at the time of the hacker attack, has, according
to the statements of her father during the oral hearing, no
knowledge whatsoever of the events surrounding the loss of
her data. The submission in the Plaintiff's pleadings,
according to which "distressing uncertainty" over the
unauthorised publication or anxieties and worries exist,
therefore proves to be completely unsubstantiated due to the
Plaintiff's lack of knowledge of the events. Where and
insofar as it is argued that the Plaintiff is worried that
her bank details might be hacked, it must be observed that
it was not her account that was affected, but that of her
mother. In this respect, the question arises why the
Plaintiff – quite apart from her lack of knowledge – claims
to have anxieties when her own account is not even affected.
Furthermore, there are no indications whatsoever that the
data is being misused on the darknet or otherwise,
especially since the hacker attack aimed at extorting the
affected companies.

This is not contradicted by the decision of the Federal
Court of Justice (BGH) dated 18.11.2024 - VI ZR 10/24 -
juris. Under that judgment as well, a "well-founded fear" on
the part of the data subject is required and this fear,
along with its negative consequences, must be "properly
proven" (cf. juris para 32). The BGH also states that the
"mere assertion of a fear without proven negative
consequences" is just as insufficient as a "purely
hypothetical risk of misuse by an unauthorised third party"
(cf. juris para 32). On this basis, and even taking this
decision of the BGH into account, no damage can have arisen
in the present case, since assertions are made in the
pleadings regarding supposed anxieties of the Plaintiff
which she, logically, cannot have due to her lack of
knowledge of the loss of data. Furthermore, after more than
three years since the hacker attack, there are not the
slightest indications that the Plaintiff's data has been
misused. According to the case-law of the BGH, the purely
hypothetical risk of misuse is precisely not sufficient to
establish non-material damage.

Accordingly, there is also a lack of any compensable damage.
The action proves to be unfounded in this respect.

III.) Declaration of Future Damage Insofar as the Plaintiff
seeks a declaration that the Defendants are obliged to
compensate her for all future material damage, there is
already a lack of a legal interest in a declaration within
the meaning of § 55 para 1 of the Social Court Act (SGG). An
interest in obtaining a declaration of liability for
compensation for future damage of a purely material nature
depends on the probability of the pending damage occurring.
If, on the other hand, based on a reasonable assessment of
the individual case, the occurrence of future damage is not
to be expected, even such a possibility must be denied, cf.
Regional Court (LG) of Krefeld, loc. cit., para 36 with
further references.

In the present case, there are no circumstances apparent
that make the occurrence of future damage probable beyond a
mere theoretical fear. Quite apart from the fact that it was
not the Plaintiff's bank details (but those of her mother)
that were affected, with the consequence that no damage of a
material nature can arise for the Plaintiff, it must be
observed that the security vulnerability was remedied
immediately after the hacker attack. Since then, no damage
of a material nature has occurred. Furthermore, such a
possibility steadily diminishes with the progressive passage
of time (Regional Court of Krefeld, loc. cit., para 36 with
further references). It is therefore a matter of a mere
theoretical fear, which is incapable of establishing a legal
interest in a declaration.

IV.) Injunction Insofar as the Plaintiff seeks an
injunction, the action proves to be inadmissible. The
Plaintiff requests – similarly to the plaintiff in the
proceedings before the Regional Court of Trier, loc. cit. –
that the Defendants refrain from "making personal data of
the Plaintiff (...) accessible to third parties without
implementing the security measures possible according to the
state of the art and without the consent of the Plaintiff or
a justification under the GDPR."

The application is too indefinite. Thus, it does not become
clear which cases of "making accessible to third parties"
are intended to be covered and which security measures will
correspond to the "state of the art" in the future. In this
respect, the deciding Chamber joins the accurate legal
reasoning of the Regional Court of Trier, loc. cit., paras
34 et seq., after its own examination, and makes reference
to it.

V.) Legal Fees In the absence of a claim under the
statements of claim under numbers 1) to 3), there is also no
claim for indemnification from pre-litigation legal fees.

Accordingly, the action must therefore be dismissed.

The decision on costs is based on § 197a para 1 of the
Social Court Act (SGG) in conjunction with § 154 para 1 of
the Rules of the Administrative Courts (VwGO). In
particular, the Plaintiff is not involved in the proceedings
in her capacity as a beneficiary under § 183 SGG, and
compensation for damage or the declarations and injunctions
sought in this connection do not constitute benefits within
the meaning of § 183 SGG (cf. on the whole: Federal Social
Court (BSG), judgment dated 24.09.2024 - B 7 AS 15/23 R -
juris with further references).

The determination of the value in dispute is based on § 197a
para 1 sentence 1 half-sentence 1 SGG in conjunction with §
52 paras 1 and 3 of the Court Costs Act (GKG). The value in
dispute is composed of the principal claim of EUR 3.000,00.
Added to this are the claims for a declaration and an
injunction, each to be assessed with a similar value
corresponding to their importance for the Plaintiff, and the
requested pre-litigation quantifiable legal fees, resulting
in a rounded value in dispute of EUR 10.000,00.