SG Nürnberg - S 5 SF 65/24 DS
| SG Nürnberg - S 5 SF 65/24 DS | |
|---|---|
| Court: | SG Nürnberg (Germany) |
| Jurisdiction: | Germany |
| Relevant Law: | Article 4(7) GDPR Article 4(8) GDPR Article 4(10) GDPR Article 4(12) GDPR Article 5(1)(f) GDPR Article 24(1) GDPR Article 24(1) GDPR Article 26 GDPR Article 28 GDPR Article 32(1) GDPR Article 32(2) GDPR Article 82(1) GDPR Article 82(2) GDPR Article 85 GDPR § 183 SGG § 81b(1) SGB X |
| Decided: | 10.06.2026 |
| Published: | 18.06.2026 |
| Parties: | |
| National Case Number/Name: | S 5 SF 65/24 DS |
| European Case Law Identifier: | |
| Appeal from: | |
| Appeal to: | Unknown |
| Original Language(s): | German |
| Original Source: | sozialgerichtsbarkeit.de (in German) |
| Initial Contributor: | n/a |
A court dismissed a data subject's €3,000 damages claim against a health insurer and its processor, holding that a zero-day vulnerability, which led to a data breach, did not violate security requirements under Article 32 GDPR.
English Summary
Facts
The data subject (a child born in 2018), represented by her parents, was insured with the controller (a statutory health insurance provider) and participated in its digital bonus programme. The bonus programme was managed via an app. To handle the information technology operations of this programme, the controller hired the processor (an IT service provider), establishing a data processing agreement under Article 28 GDPR alongside specific information security guidelines.
To provide these services, the processor utilised "MOVEit Transfer," a market-leading file transfer software developed by Progress Software Corp.
On 31 May 2023, the software developer publicly announced a critical, previously unknown "zero-day" vulnerability in the software (later assigned CVE-2023-34362). At that exact moment, no security patch was available.
On the very same day, 31 May 2023, the processor – alongside thousands of other companies worldwide – became the victim of a global cyberattack carried out by the hacker group "Clop." The hackers exploited this zero-day vulnerability to install a "web-shell" backdoor (typically named human2.aspx), bypassing authentication to exfiltrate database records. The compromised data included the data subject's first and last name, health insurance number, bonus points balance, and a bank account number (IBAN) belonging to her mother. No medical, health, or social security data was exfiltrated.
On 1 June 2023, the developer released a security patch, which the processor installed immediately.
On 2 June 2023, the German Federal Office for Information Security (BSI) issued a formal IT security warning (No. 2023-240133-1100, Version 1.1). The BSI classified the IT threat level as "3 / Orange" (business-critical), confirming active exploitation with data exfiltration. The BSI recommended immediately blocking all HTTP and HTTPS traffic to MOVEit environments, checking for specific Indicators of Compromise (IoCs) in the web server directories, and applying the newly released patch before reconnecting systems to the network.
On 16 June 2023, the processor informed the controller about the incident.
On 17 June 2023, the controller issued a public press release confirming that its external service provider for the bonus programme had been targeted on 31 May 2023. The release stated that the security vulnerability had been closed, that there was never any connection to the controller's internal IT systems, and that relevant supervisory authorities had been notified. The controller subsequently notified the data subject's parents.
On 27 March 2024, the data subject, via legal counsel, sent a formal warning letter to the controller demanding an injunction, a declaration of liability for all potential future damages, and non-material damages of at least €3,000. Following the controller's refusal, the data subject filed a lawsuit with the Nuremberg Social Court (Sozialgericht Nürnberg), later expanding the claim to the processor as a joint defendant.
Holding
The Court dismissed the lawsuit as partly inadmissible and otherwise unfounded, establishing the following legal principles:
First, the Court held that a successful third-party cyberattack does not establish an irrebuttable presumption that a controller or processor failed to implement appropriate security measures under Article 32(1) GDPR and Article 5(1)(f) GDPR. To escape liability under Article 82(3) GDPR, an operator must prove they implemented robust baseline security controls (such as multi-factor authentication, encryption, and lockout policies) and applied a security patch immediately upon its release by the vendor, even if this occurred before formal alerts were issued by national IT security authorities.
Second, the Court held that a claim for non-material damages under Article 82(1) GDPR based on the fear or distress of future data misuse cannot be established if the data subject is a minor who has no subjective knowledge or cognitive awareness of the data breach. Furthermore, if the compromised financial data (such as an IBAN) does not belong to the data subject personally, there is no direct risk of financial harm to them, rendering the alleged fear of financial damage unfounded.
Third, the Court held that an injunction claim is inadmissible due to a lack of specificity if it merely demands that a controller stop making personal data accessible to third parties without implementing "state-of-the-art" security measures, without specifying the concrete technical or organisational measures the controller is required to take.
Fourth, the Court held that a declaratory claim for potential future material damages is inadmissible under national procedural law (§ 55(1) SGG) if there is no realistic probability of future financial harm, particularly because the compromised bank account belonged to a third party (the mother) and the software vulnerability was immediately patched.
Comment
This judgment is legally and technically flawed because the Court fundamentally misapplied the concept of the "state of the art" under Article 32(1) of the General Data Protection Regulation. By treating a classic SQL injection vulnerability as an unavoidable, force-majeure "zero-day" event, the Court collapsed the strict statutory requirement of the state of the art into a much weaker standard of mere "common market practice."
Under Article 32(1) GDPR, both controllers and processors are legally bound to ensure a level of security appropriate to the risk, explicitly taking into account the state of the art. As in commentary (e.g. Hansen, in: Simitis/Hornung/Spiecker gen. Döhmann, Datenschutzrecht, 2nd edition 2025, Article 32, Paragraphs 15–16), while Article 32 does not directly bind software manufacturers, it creates a strict indirect obligation for controllers and processors. They must carefully select, evaluate, and deploy only those products and services that actively enable them to fulfill their data protection obligations. Software with glaring, un-audited security gaps must not be deployed.
In modern software engineering, a secure software development lifecycle, which integrates automated static application security testing, dynamic application security testing, and software composition analysis, is the indisputable state of the art. SQL injection is one of the oldest, most thoroughly documented, and easily preventable vulnerability classes in existence. It can be entirely neutralized during the development phase through standardized automated tools. The fact that a commercial file transfer platform allowed unauthenticated database access through such a fundamental flaw demonstrates a systemic failure of secure-by-design principles at the development level.
The Court's reasoning creates a dangerous legal safe harbour that actively undermines the preventive purpose of Article 32 GDPR. Under the Court’s flawed logic, an operator is fully exculpated from liability under Article 82(3) GDPR simply by procuring a widely used, "market-leading" commercial product, regardless of how deficient that product's underlying security architecture is. This effectively shifts the entire risk of vendor-side engineering failures onto the data subjects. By failing to scrutinize whether the software itself complied with the secure software development lifecycle as the state of the art, the Court misapplied the law, transforming what should be a rigorous assessment of technical security into a superficial checklist of vendor popularity.
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the German original. Please refer to the German original for more details.
BASIC INFORMATION Case Reference / Case Number S 5 SF 65/24 DS Court Social Court (SG) of Nuremberg Category Subject Area Other Proceedings Relationships 1st Instance Court Social Court of Nuremberg Case Reference / Case Number S 5 SF 65/24 DS Date 10.06.2026 2nd Instance Court Case Reference / Case Number Date 3rd Instance Court Case Reference / Case Number Date DECISION TEXT I. The action is dismissed. II. The Plaintiff shall bear the costs of the proceedings as well as the necessary extrajudicial expenses of both Defendants. III. The value in dispute is set at EUR 10.000,00. FACTS OF THE CASE: The parties are in dispute over the award of compensation for damage due to an asserted data protection violation following a hacker attack on 31.05.2023. In addition, the Plaintiff seeks a declaration of liability for compensation for potential future damage in principle, an injunction against the unauthorised disclosure of personal data, and indemnification from pre-litigation legal fees. The Plaintiff, born in 2018, is statutorily health-insured with the Defendant under 1) and participates in its bonus programme, which is operated via an app. Under this programme, EUR 10,00 is paid out to the insured person for every 100 points collected. Points can be collected through regular participation in preventive medical check-ups as well as sports and leisure programmes. For the information technology processing of its bonus programme, the Defendant under 1) uses a processor, the Defendant under 2). The Defendant under 2) uses the program M-IT of the US company P-Corp. (hereinafter: "P.") to provide the contractually owed services. This is a software program for the exchange of data. The Defendant under 1) has concluded an agreement on processing with the Defendant under 2). The associated general framework conditions on "Information Security" regulate the technical and organisational measures to be complied with by the Defendant under 2) as processor. These include, among other things, requirements for infrastructure security and protection against malware. For example, the Defendant under 2) is required to have malware detection and repair software installed that corresponds to the state of the art and must reliably prevent the exfiltration of the controller's data. On 31.05.2023, the Defendant under 2), along with a large number of affected companies and public authorities worldwide, became the victim of a hacker attack by the hacker group C., in the course of which a data breach occurred, by which, inter alia, the Plaintiff was also affected. By uploading a so-called "web shell" onto the affected server of the Defendant under 2), the hackers succeeded in gaining access to its system and exfiltrating customer data – including that of the Plaintiff. The data affected by the hacker attack consists of first name, surname, health insurance number, premium amount (the proceeds from successful participation in the bonus programme) and bank details (IBAN). In this case, the bank details are not those of the Plaintiff, but of her mother. Furthermore, health data of the Plaintiff was not affected. No data was exfiltrated from the servers of the Defendant under 1) either. The actions of the group C. were, as far as is known, not directed against the respective data subjects, but against the companies affected by the attack in order to extort them. The hackers had succeeded in accessing this data via an unknown vulnerability in the program MOVEit. This was a so-called "zero-day exploit", i.e. a security vulnerability previously unknown to the software manufacturer and the Defendants. Still on 31.05.2023, the company P. issued a security warning. A corresponding warning, referencing the prior warning by P., was issued by the Federal Office for Information Security (BSI) on 02.06.2023 (security level 4 warning). One day after the vulnerability became known on 31.05.2023, P. provided the security patch to eliminate the threat, which was immediately installed by the Defendant under 2). The Defendant under 1) itself was, according to its submission, informed of the events on 16.06.2023 and issued a corresponding press release the following day. Subsequently, it also informed the Plaintiff's parents as her statutory representatives. By lawyer's letter dated 27.03.2024, the Plaintiff requested the Defendant under 1) to cease and desist, to pay compensation for non-material damage in an amount of at least EUR 3.000,00, and to agree to an obligation to compensate the Plaintiff for all future damage that might still arise for her as a result of the unauthorised access by third parties to the personal data. After the Defendant under 1) had rejected the Plaintiff's demands by letter dated 03.04.2024, the Plaintiff brought an action before the Social Court of Nuremberg – initially only against the Defendant under 1). By pleading dated 12.12.2024, she extended the action to the Defendant under 2). She claims to have become the victim of a data breach at the Defendant under 1) because the latter had taken insufficient technical measures to adequately protect personal data. Consequently, the personal data of the Plaintiff could be obtained by unauthorised persons. The IT forensic experts of K. had supposedly found indications that the hackers had already been aware of the vulnerability since the year 2021. Since then, they had most likely experimented on how best to abuse the gap. The MOVEit software had stood out for years due to such (SQL injection) vulnerabilities, and the IT security expert T. had also commented to this effect on X. He spoke in particular of the fact that the use of such software was to be assessed as "negligent". The Defendant under 1) should have taken the following protective measures in particular: pseudonymisation and/or encryption of the personal data, as well as a process for regularly testing, assessing and evaluating the effectiveness of the technical and organisational measures. If the Defendant had properly carried out these protective measures, the data breach would not have occurred and unauthorised persons would not have gained access to the Plaintiff's data. Even if the data breach had occurred "only" at the Defendant under 2), the Defendant under 1) would also be liable in this case. This is because, as the controller under data protection law, it must ensure that all of its contractual partners who process personal data of Barmer customers within the scope of processing also work in compliance with data protection law. To this end, the Defendant should have instructed and monitored the processor accordingly. Both Defendants are joint controllers under Art 26 of the General Data Protection Regulation (GDPR). The use of the MOVEit software at the time the data breach was exploited by the hacker group was grossly negligent. Through a more modern, albeit more expensive software, the data breach would have been avoided. The Defendant under 1) is obliged under Art 32 GDPR to implement appropriate and suitable technical and organisational measures (TOM) to ensure a level of security appropriate to the risk. The Defendant under 1) culpably failed to take and implement suitable technical and organisational measures to prevent a disclosure of personal data. The Defendant has therefore (also) infringed the requirements of Art 32 GDPR. Due to the ongoing loss of control over personal and sensitive data, the Plaintiff is entitled to a claim for non-material damages under Art 82 para 1 GDPR. The actual damage lies in the ongoing state of existing and distressing uncertainty regarding the unauthorised publication of the personal data. The Plaintiff is worried that her bank and/or securities account data will be hacked. It must be assumed that the Plaintiff's data is already being offered for sale on the so-called "darknet". Furthermore, it must be expected that the Plaintiff's data has been or will be used by criminals to obtain unauthorised access to bank accounts, online services, etc., in order to cause financial harm to the Plaintiff. The linking and downstream publication of personal data, such as at least the first name and surname as well as potentially other data, opens the floodgates to abuse. The loss of the social security number (note: this was not exfiltrated, see above) also significantly increases the risk of identity theft. In addition, the mere fact that the Plaintiff's data is available to an unknown number of unauthorised persons is frightening for her, as it is not yet known in what way it might be misused. Furthermore, the Defendant must bear the Plaintiff's pre-litigation legal fees, based on an amount in dispute of EUR 10.000,00. The Plaintiff requests that, 1. the Defendants be ordered as joint and several debtors to pay to the Plaintiff, as compensation for data protection violations, non-material damages, the amount of which is left to the discretion of the Court, but should not be less than EUR 3.000,00, plus interest in the amount of 5 percentage points above the respective base rate since lis pendens. 2. it be declared that the Defendants are obliged to compensate the Plaintiff for all future material damage that has arisen and/or will yet arise for the Plaintiff as a result of the unauthorised access by third parties to the Defendants' data archive containing the personal data of the Plaintiff, which, according to current information, occurred on 31.05.2023. 3. the Defendants be ordered, under penalty of a court-established administrative fine of up to EUR 250.000,00 for each case of infringement, or alternatively administrative detention to be executed on their statutory representative, or administrative detention of up to 6 months to be executed on their statutory representative, and in the event of repeated infringement up to 2 years, to refrain from making personal data of the Plaintiff, namely first name, surname, health insurance number, premium amount, as well as the bank details, accessible to third parties without implementing the security measures possible according to the state of the art and without the consent of the Plaintiff or a justification under the GDPR. 4. the Defendant under 1) be ordered to indemnify the Plaintiff from pre-litigation costs for legal representation in the amount of EUR 973,65 plus interest in the amount of 5 percentage points above the respective base rate since lis pendens. The Defendants request that, the action be dismissed. The Defendant under 1) submits that it is not known that any personal data of the Plaintiff has been published anywhere. It contends that in this case there is already a lack of any infringement of rights attributable to the Defendants. It argues that it is therefore exempt from liability (Art 82 para 3 GDPR). It submits that there has been no failure by the Defendant under 1) to comply with its obligations under the GDPR. It states that it used the Defendant under 2) to carry out certain processing of personal data within the framework of operating its bonus programme. It asserts that a proper agreement on processing in accordance with Art 28 GDPR was concluded with the Defendant under 2), under which the latter specifically committed itself to certain TOMs in order to meet the requirements of Art 32 GDPR. It argues that Art 32 para 1 GDPR merely contains examples of measures that are to be taken "as appropriate". It contends that these are to be implemented – if at all – only to the extent and in the scope to which they are suitable and necessary to achieve an appropriate level of security. In particular, it submits that Art 32 para 1 GDPR itself does not determine when such measures are required. It argues that the GDPR does not demand absolute protection (which would also be impossible), but merely technical and organisational measures to ensure a level of security appropriate to the risk (Art 32 para 1 GDPR). It asserts that the fact that a hacker attack was successful in no way proves a lack of an appropriate level of security. It argues that the Plaintiff's submission claiming otherwise misunderstands the legal framework. Furthermore, it states that already on 02.06.2023 at 10:17 am, the system was secured with a security patch provided by the manufacturer, so that further attacks and, in particular, the exfiltration of further data could be prevented. Moreover, health data of the Plaintiff was not affected. It submits that it was not foreseeable for either of the two Defendants that the Defendant under 2), like several thousand other companies worldwide, would become the victim of a hacker attack by a group of apparently Russian criminals. Furthermore, it argues that the Plaintiff's submission does not demonstrate any damage that could be compensable. In this case, it contends that it is also impossible to rely on the fear of misuse of the data as non-material damage. This is because it would require that a misuse can actually be feared under the given circumstances and with regard to the data subject. On the one hand, it states that there is a complete lack of any submissions to this effect. On the other hand, it argues that this is also entirely improbable. It asserts that since the hacker attack on the processor of the Defendant under 1) in May 2023, to the knowledge of the Defendant, no data of data subjects has been misused. It argues that the objective of the attack was also recognisably in no way the misuse of the data of data subjects, but rather the extortion of the Defendant under 1) as controller and the Defendant under 2) as processor. In addition, the Defendant under 1) submits that it is not a "joint controller" with the Defendant under 2) under Art 26 GDPR. It argues that there is instead a relationship of processing under Art 28 GDPR. The Defendant under 2) submits that it never had access to the source code of the MOVEit application. It states that for security reasons, this is kept strictly confidential by the manufacturer. It argues that all bug fixes must therefore be provided by the manufacturer. It contends that the critical vulnerability of the MOVEit application was no exception to this. Its correction was only possible for the manufacturer. It states that the mobile number and the email address of the Plaintiff were precisely not exfiltrated. With regard to the bank details, it argues that damage can easily be prevented by changing the account. It asserts that at the time of the data protection incident, taking into account the state of the art, the MOVEit application was a secure application and was considered insurmountable. The Defendant under 2) submits that it was entitled to assume that the software corresponded to the state of the art. It states that the manufacturer of the software, the company P., actively supports the MOVEit application and regularly provides updates with bug fixes. It argues that this was also the case at the time of the cyberattack. As the handling of the cyberattack shows, the support provided by P. was also highly professional. Already one day after the vulnerability exploited on 31.05.2023 became known, P. made the security patch available to eliminate the threat. Reference is made to the numerous certifications of P. It states that it has itself also taken comprehensive TOMs, which the Defendant under 2) lists in its pleading dated 19.02.2025. Reference is made to this pleading. The Defendant under 2) further submits that prior to the data breach in 2023, it had in any event no knowledge whatsoever of any critical vulnerabilities in the software used. It argues that if liability under data protection law were to exist for the Defendants for using software of a carefully selected software manufacturer solely because a vulnerability in the software became apparent, the exploitation of which could by its nature not be prevented by properly implemented accompanying security measures, liability under data protection law would escalate into pure strict liability for the use of software. It contends that liability under data protection law under Article 82 GDPR was not designed as such, as this would exclude any exculpation for any software user. It states that the Plaintiff is free to hold P. liable as the manufacturer. By pleading dated 17.01.2025, the Defendant under 1) submitted a decision of the Federal Commissioner for Data Protection and Freedom of Information addressed to another insured person regarding the hacker attack in dispute. The decision states: "Art 32 GDPR merely obliges the implementation of a risk management system, but does not prescribe that controllers must eliminate the risk of data protection violations altogether (...). Even the fact that third parties can gain unauthorised access to personal data does not in itself mean that the technical and organisational measures taken were not 'appropriate'. (...). A data protection violation on the part of BARMER does not therefore exist." In the course of the oral hearing, the Chamber examined the Plaintiff's father for information purposes. He stated that the affected account is the account of the Plaintiff's mother. He explained that the account still exists, although a second current account has since been set up. He added that most transactions now run through his own account. According to his statements, there are no indications that the account of the Plaintiff's mother has been hacked. He further stated that he does not know whether the data is appearing or being offered on the darknet. He explained that the Plaintiff herself "has no knowledge of the entire process surrounding the data breach". With regard to the further details of the state of the facts and the dispute, reference is made to the court file and the mutual pleadings. REASONS FOR THE DECISION: The action, which is admissible with regard to the claims under numbers 1 and 4, is unfounded. Insofar as the Plaintiff brought an action for a declaration in objective joinder of claims under number 2 and seeks an injunction under number 3 of her statement of claim, these actions are already inadmissible. I.) Venue and Jurisdiction The legal venue of the social jurisdiction is established. The Plaintiff alleges an infringement of the GDPR. For actions brought by the data subject against a controller or a processor on the grounds of an infringement of this Regulation, the legal venue before the courts of the social jurisdiction is established according to the explicit wording of § 81b para 1 of Book X of the German Social Code (SGB X) (cf. on compensation also Federal Social Court - BSG - decision dated 6 March 2023 - B 1 SF 1/22 R - juris). II.) Compensation for Damage Insofar as the Plaintiff seeks compensation for an asserted non-material damage of at least EUR 3.000,00, the action proves to be unfounded. Pursuant to Art 82 para 1 GDPR, any person who has suffered material or non-material damage as a result of an infringement of this Regulation shall have the right to receive compensation from the controller or processor for the damage suffered. Pursuant to Art 82 para 3 GDPR, the controller or processor shall be exempt from liability if it proves that it is not in any way responsible for the event giving rise to the damage. Pursuant to Art 82 para 4 GDPR, both the controller – here the Defendant under 1) pursuant to Art 4 no 7 GDPR – and the processor – here the Defendant under 2) pursuant to Art 4 no 8 GDPR – shall be held liable as joint and several debtors for any damage caused. The requirements for a claim for compensation under Art 82 para 1 GDPR are not met. The Chamber could not satisfy itself of a culpable infringement of the GDPR by the Defendants. Furthermore, there is a lack of any non-material damage. 1.) Pursuant to Art 5 para 1 lit f GDPR, personal data must be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical and organisational measures. The controller (Art 4 no 7 GDPR) – in this case the Defendant under 1) – must demonstrate compliance with this, cf. Art 5 para 2 GDPR. Pursuant to Art 24 para 1 sentence 1 GDPR, taking into account the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation. Pursuant to Art 24 para 2 GDPR, those measures shall include the implementation of appropriate data protection policies by the controller, where proportionate in relation to processing activities. Furthermore, Art 32 para 1 GDPR provides that the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. This shall be done taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons. The European Court of Justice (ECJ), in its judgment dated 14.12.2023 - C-340/21 - juris, lays down the essential principles. In this regard, it states (underlining added): "The reference in Articles 32(1) and (2) of the GDPR to 'a level of security appropriate to the risk' and to 'an appropriate level of security' shows that that regulation establishes a risk management system and in no way claims to eliminate the risk of personal data breaches" (cf. ECJ, loc. cit., para 29). On this basis, the ECJ also assumes that there can be no absolute protection in a digital world – just as in an analogue world – but rather that a risk management system is the meaning and purpose of Art 32 GDPR. Subsequently, the ECJ states that it follows from the wording of Articles 24 and 32 GDPR that those provisions merely require the controller to adopt technical and organisational measures designed to prevent any personal data breach as far as possible. The suitability of such measures must be assessed in a concrete manner, by examining whether the controller adopted those measures taking into account the various criteria laid down in those articles and the data protection needs specifically linked to the processing in question and the risks presented by the latter (cf. ECJ, loc. cit., para 30). The ECJ then explicitly states (underlining added): "Consequently, Articles 24 and 32 of the GDPR cannot be understood as meaning that an unauthorised disclosure of or unauthorised access to personal data by a third party is sufficient to conclude that the measures adopted by the controller for the processing in question were not appropriate within the meaning of those provisions, without even allowing the controller to provide proof to the contrary. Such an interpretation is all the more necessary given that Article 24 of the GDPR expressly provides that the controller must be able to demonstrate that the measures implemented by him or her are compliant with the GDPR, an opportunity of which he or she would be deprived if an irrebuttable presumption were accepted", cf. ECJ, loc. cit., para 31 et seq. The burden of proving that personal data is processed in a manner that ensures appropriate security of that data within the meaning of Art 5 para 1 lit f and Art 32 GDPR lies with the controller for the processing in question (cf. ECJ, loc. cit., para 52). Regarding cases of cybercrime, the ECJ states (underlining added): "Where (...) a personal data breach within the meaning of Article 4(12) of the GDPR was committed by cybercriminals, and therefore by 'third parties' within the meaning of Article 4(10) thereof, that breach can be imputed to the controller only if he or she made that breach possible by failing to comply with an obligation under the GDPR, in particular the data protection obligation imposed on him or her under Article 5(1)(f), Article 24 and Article 32 of that regulation. Thus, in the event of a personal data breach by a third party, the controller may exempt himself or herself from liability under Article 82(3) of the GDPR by proving that there is no causal link between the breach of the data protection obligation potentially committed by him or her and the damage suffered by the natural person", cf. ECJ, loc. cit., para 71 et seq. Accordingly, while hacker attacks do not per se exempt a party from liability, especially not if the controller or its processor implemented insufficient protective measures (cf. to this effect also ECJ, loc. cit., para 74), the controller may nevertheless prove that it is not in any way responsible for the event giving rise to the damage in question. Taking these principles into account, the deciding Chamber could not satisfy itself of any responsibility on the part of the Defendants. Indeed, the Defendants have demonstrated in a substantiated and comprehensive manner that, at the time of the incident in dispute, the MOVEit application was established in the market as one of the market-leading applications in the field of managed file transfer software. P. and its software were certified accordingly. Furthermore, in its pleading dated 19.02.2025, the Defendant under 2) comprehensively set out its own measures, in particular: Access to the MOVEit application only upon authentication by means of a user account, whereby the creation of user accounts was carried out in a stringent process preceded by an application, approval, and identity verification. Every user receives a unique, personalised, user-specific identifier. Within the MOVEit application, after 5 unsuccessful login attempts within a time window of 6 minutes, the user account is automatically locked for 30 minutes. In addition, the MOVEit Transfer platform blocks the IP address of a terminal device if repeated failed attempts are detected from that address within a time window of 5 minutes. The unblocking of an IP address can only be performed by the competent IT department of the Defendant under 2) and requires a prior review of the event. Comprehensive requirements for the password to be defined (for details on this, see the pleading dated 19.02.2025). Communication with the MOVEit Transfer platform is permitted only via secure protocols (FTPS, SFTP, HTTPS, AS2). During file transfer, MOVEit uses SSL or SSH to encrypt communication. At the time of the attack, version 2021.1 (13.1.0.39) was in use and complied with the manufacturer's security specifications at that time. Reference is made to the further measures outlined in the pleading dated 19.02.2025. The mere fact that a hacker attack was successful does not prove that the technical and organisational measures in advance were insufficient (cf. Higher Regional Court (OLG) of Stuttgart, judgment dated 31.03.2021 - 9 U 34/21 - juris para 54), especially since, according to the Plaintiff's submission, the hackers had been trying to penetrate the system since approximately 2021. Thus, assuming this to be correct, they required approximately two years to get into the system. It is precisely this length of time until a successful attack at the end of May 2023 that also proves the security of the software. Insofar as the Plaintiff argues that the Defendants could have taken further technical measures, of which she lists several, this does not give rise to any duty of implementation, the non-compliance with which could constitute a data protection violation. The Defendants are merely obliged to implement suitable measures designed to prevent a data protection breach as far as possible (cf. Regional Court (LG) of Krefeld, judgment dated 06.11.2025 - 3 O 93/24 -, juris, para 30, with further references). The Chamber fully shares the view of the Regional Court of Krefeld regarding the hacker attack in dispute. It states: "The TOMs described by the Defendants would only be insufficient if concrete indications of the error-proneness of the G. application – which was the market leader at the time of the incident – had previously arisen. In this regard, the Plaintiff's allegations are generalized and lack detailed substance. She refers to an unyielding public post as well as to so-called CVE entries in a vulnerability database. However, this does not show whether the Defendants specifically perceived these circumstances before the cyberattack or ought to have perceived them, as the latter source in particular rather suggests that the program was and is regularly reviewed and further developed in terms of security by the manufacturer. The assumption that the Defendants ought to have had corresponding doubts is countered by the fact that approximately 2,500 companies and institutions worldwide fell victim to this – in this respect unforeseen – so-called 'zero-day exploit'. The Defendant under 1) had no reason for increased monitoring of the Defendant under 2); doubts regarding the suitability of the Defendant under 2) as a processor were not submitted.", cf. Regional Court of Krefeld, loc. cit., para 30. In this regard as well, it is not apparent to the deciding Chamber how the Defendants – rather than, if anyone, the manufacturer "P." – could have detected the vulnerability in the software. The Regional Court of Trier furthermore states: "Furthermore, a software program was responsible for the exfiltration of data which was developed neither by the Defendant nor by its intervener, but by P.. Until the incident in dispute, the software was (undisputedly) established in the market as a market-leading application acting as a data security and data protection compliant exchange platform, which was also demonstrated by the potential affection of approximately 2,500 companies and public bodies by the cyberattack.", cf. Regional Court of Trier, judgment dated 04.04.2025 - 2 O 85/24 - juris, para 53. If at all, a charge of negligent conduct can therefore be made against the manufacturer, but not against the Defendants, who relied entirely on the software of a global market leader. Likewise, no culpable error on the part of the Defendant under 1) can be established regarding the selection decision of the Defendant under 2) as a processor. Accordingly, there is no (attributable) infringement of the GDPR by the Defendants. 2.) Furthermore, in the present case, there is a lack of any compensable non-material damage. In this regard, the Plaintiff submits in her pleadings that the actual damage lies in the ongoing state of existing and distressing uncertainty regarding the unauthorised publication of the personal data. Moreover, it is argued that the circumstances have led to worries and anxieties on the part of the Plaintiff. The Plaintiff is also said to be worried that her bank and/or securities account data will be hacked. It is asserted that it must be assumed that the Plaintiff's data is already being offered for sale on the so-called "darknet". Furthermore, it is claimed that it must be expected that the Plaintiff's data has been or will be used by criminals to obtain unauthorised access to bank accounts, online services, etc., in order to cause financial harm to the Plaintiff. The linking and downstream publication of personal data, such as at least the first name and surname as well as potentially other data, is said to open the floodgates to abuse. The loss of the social security number (note: this was not exfiltrated, see above) also allegedly increases the risk of identity theft significantly. In addition, the mere fact that the Plaintiff's data is available to an unknown number of unauthorised persons is stated to be frightening for her, as it is not yet known in what way it might be misused. The Plaintiff's submission regarding the alleged damage is largely unsubstantiated. While the compensation of non-material damage is not dependent on exceeding a certain threshold of gravity (cf. ECJ, judgment dated 04.05.2023 - C-300/21 - juris) and, according to Recital 85 GDPR, a personal data breach may result in physical, material or non-material damage for natural persons, such as loss of control over personal data or identity theft, this does not alter the fact that a corresponding examination of the existence of damage must always be carried out in the specific individual case to be decided. Indeed, the loss of control may merely constitute damage, but does not necessarily have to do so. In this regard, the ECJ states in its judgment dated 14.12.2023, loc. cit., paras 84 et seq. (underlining added): "However, it must be pointed out that a person affected by a personal data breach which has had negative consequences for him or her must demonstrate that those consequences constitute non-material damage within the meaning of Article 82 of the GDPR (...). In particular, where a person seeking compensation on that basis relies on the fear that his or her personal data will be misused in the future as a result of such a breach, the national court seised must examine whether that fear can be regarded as well founded, in the light of the specific circumstances and with regard to the data subject." Accordingly, it is incumbent upon the Chamber to examine whether the Plaintiff's fears can be regarded as well founded. In this connection, it must be taken into account that the Plaintiff, who is currently 8 years old and was 5 years old at the time of the hacker attack, has, according to the statements of her father during the oral hearing, no knowledge whatsoever of the events surrounding the loss of her data. The submission in the Plaintiff's pleadings, according to which "distressing uncertainty" over the unauthorised publication or anxieties and worries exist, therefore proves to be completely unsubstantiated due to the Plaintiff's lack of knowledge of the events. Where and insofar as it is argued that the Plaintiff is worried that her bank details might be hacked, it must be observed that it was not her account that was affected, but that of her mother. In this respect, the question arises why the Plaintiff – quite apart from her lack of knowledge – claims to have anxieties when her own account is not even affected. Furthermore, there are no indications whatsoever that the data is being misused on the darknet or otherwise, especially since the hacker attack aimed at extorting the affected companies. This is not contradicted by the decision of the Federal Court of Justice (BGH) dated 18.11.2024 - VI ZR 10/24 - juris. Under that judgment as well, a "well-founded fear" on the part of the data subject is required and this fear, along with its negative consequences, must be "properly proven" (cf. juris para 32). The BGH also states that the "mere assertion of a fear without proven negative consequences" is just as insufficient as a "purely hypothetical risk of misuse by an unauthorised third party" (cf. juris para 32). On this basis, and even taking this decision of the BGH into account, no damage can have arisen in the present case, since assertions are made in the pleadings regarding supposed anxieties of the Plaintiff which she, logically, cannot have due to her lack of knowledge of the loss of data. Furthermore, after more than three years since the hacker attack, there are not the slightest indications that the Plaintiff's data has been misused. According to the case-law of the BGH, the purely hypothetical risk of misuse is precisely not sufficient to establish non-material damage. Accordingly, there is also a lack of any compensable damage. The action proves to be unfounded in this respect. III.) Declaration of Future Damage Insofar as the Plaintiff seeks a declaration that the Defendants are obliged to compensate her for all future material damage, there is already a lack of a legal interest in a declaration within the meaning of § 55 para 1 of the Social Court Act (SGG). An interest in obtaining a declaration of liability for compensation for future damage of a purely material nature depends on the probability of the pending damage occurring. If, on the other hand, based on a reasonable assessment of the individual case, the occurrence of future damage is not to be expected, even such a possibility must be denied, cf. Regional Court (LG) of Krefeld, loc. cit., para 36 with further references. In the present case, there are no circumstances apparent that make the occurrence of future damage probable beyond a mere theoretical fear. Quite apart from the fact that it was not the Plaintiff's bank details (but those of her mother) that were affected, with the consequence that no damage of a material nature can arise for the Plaintiff, it must be observed that the security vulnerability was remedied immediately after the hacker attack. Since then, no damage of a material nature has occurred. Furthermore, such a possibility steadily diminishes with the progressive passage of time (Regional Court of Krefeld, loc. cit., para 36 with further references). It is therefore a matter of a mere theoretical fear, which is incapable of establishing a legal interest in a declaration. IV.) Injunction Insofar as the Plaintiff seeks an injunction, the action proves to be inadmissible. The Plaintiff requests – similarly to the plaintiff in the proceedings before the Regional Court of Trier, loc. cit. – that the Defendants refrain from "making personal data of the Plaintiff (...) accessible to third parties without implementing the security measures possible according to the state of the art and without the consent of the Plaintiff or a justification under the GDPR." The application is too indefinite. Thus, it does not become clear which cases of "making accessible to third parties" are intended to be covered and which security measures will correspond to the "state of the art" in the future. In this respect, the deciding Chamber joins the accurate legal reasoning of the Regional Court of Trier, loc. cit., paras 34 et seq., after its own examination, and makes reference to it. V.) Legal Fees In the absence of a claim under the statements of claim under numbers 1) to 3), there is also no claim for indemnification from pre-litigation legal fees. Accordingly, the action must therefore be dismissed. The decision on costs is based on § 197a para 1 of the Social Court Act (SGG) in conjunction with § 154 para 1 of the Rules of the Administrative Courts (VwGO). In particular, the Plaintiff is not involved in the proceedings in her capacity as a beneficiary under § 183 SGG, and compensation for damage or the declarations and injunctions sought in this connection do not constitute benefits within the meaning of § 183 SGG (cf. on the whole: Federal Social Court (BSG), judgment dated 24.09.2024 - B 7 AS 15/23 R - juris with further references). The determination of the value in dispute is based on § 197a para 1 sentence 1 half-sentence 1 SGG in conjunction with § 52 paras 1 and 3 of the Court Costs Act (GKG). The value in dispute is composed of the principal claim of EUR 3.000,00. Added to this are the claims for a declaration and an injunction, each to be assessed with a similar value corresponding to their importance for the Plaintiff, and the requested pre-litigation quantifiable legal fees, resulting in a rounded value in dispute of EUR 10.000,00.




