The General Data Protection Regulation — Case Law
Complying with the General Data Protection Regulation (GDPR) is a major challenge for many businesses. Processes need to be questioned and optimized, staff need to be made aware of the requirements, and GDPR provisions must be followed. If the GDPR is not observed in day-to-day business operations, companies risk sanctions, fines, and a painful loss of reputation that can lead to financial losses.
The loss of reputation and the threat of fines imposed by supervisory authorities are, in particular, the “worst case” for companies. After the GDPR was introduced, supervisory authorities initially took a fairly cautious approach. Since companies have now had enough time to gather information and gain practical experience, fines in the millions are now possible and are intended to have a deterrent effect.
Individuals also have the right to claim damages after a GDPR violation. Of course, a single complaint filed by an individual against a data-processing company is usually financially negligible, since the resulting fines tend to be small. But in most cases, data protection violations don't affect just a single individual — they affect much larger data sets. If such a case becomes public and the violations accumulate, a dangerous scenario can quickly emerge.
A Selection of Rulings on Data Protection and the GDPR:
GDPR and Data Protection Ruling No. 1 - Munich Regional Court – Data Leak
A financing company reported a data leak. This leak included, among other things, ID and account data. In this case, the security of personal data processing was not ensured. The financing company had failed to implement organizational measures that could have prevented the data leak. The court concluded that if the organizational measures had been followed, no data would have leaked, and thus no possible identity misuse through leaked data would have occurred. The financing company was therefore fined 2,500 euros.
GDPR and Data Protection Ruling No. 2 -
Dresden Higher Regional Court – Incorrect Debt Collection Claim
In this case, a debt collection company had submitted a request for information to the residents' registration office. Using the data obtained, the company wrote to the wrong person who happened to share the same name. The debt collection company was sued because the claimant feared a negative Schufa credit entry. At the same time, the claimant requested information about the stored data and its deletion. Dresden Higher Regional Court found that the data had been processed without a legal basis and that the affected data had not been deleted. However, since no damage had occurred, no compensation was awarded in this case.
GDPR and Data Protection Ruling No. 3 - Essen Regional Court – USB Stick
A company sent an unencrypted USB stick by mail. The stick contained personal data and was lost in transit. In its ruling, the court did not order the defendant to pay damages, since a mere “uneasy feeling” on the part of the claimant was not sufficient to establish damage. As no negative consequences from the loss had occurred so far, the claim was dismissed.
GDPR and Data Protection Ruling No. 4 - Austrian Supreme Court (OGH) – Partial Judgment – Facebook
A privacy activist requested information about his stored data from the social network. The response was delayed and incomplete. In doing so, Facebook failed to comply with its disclosure obligation under Art. 15 GDPR. The result was a ruling awarding damages of 500 euros.
GDPR and Data Protection Ruling No. 5 -
Hamm Regional Labor Court – Disclosure of Stored Data / Employer
An employee requested that her employer provide a list of stored data, focusing on time-tracking records. Following this request, the employer did not fully comply with the demand for information. The result was damages of 1,000 euros, as the employer had violated its disclosure obligation under Art. 15 GDPR.
GDPR and Data Protection Ruling No. 6 -
Meiningen Regional Court – Disclosure of Health Data
Following a traffic accident, an insurance company passed on the health data of a policyholder — obtained from an expert report — to its law firm for use in ordinary court proceedings. In a separate case involving the same traffic accident, the law firm was also representing a different insurer. In that case, the firm represented the opposing party to the policyholder. During the proceedings, the expert report was cited without the policyholder having given his consent. The court found that disclosing the data constituted a violation of Art. 6(1)(f) GDPR, since in this case the interests of the data subject prevailed. The ruling awarded the claimant compensation of 10,000 euros.
GDPR and Data Protection Ruling No. 7 -
Hamburg-Bergedorf Local Court – Advertising Email
An advertising email was sent to an employee's work email address. The recipient had previously explicitly objected to receiving such emails. The court found this to be a violation of Art. 6(1)(1) GDPR. However, the court ruled out compensation, as the violation did not involve a legal infringement that constituted non-material damage. The resulting annoyance and individual inconvenience were not sufficient grounds for financial compensation in this case.
GDPR and Data Protection Ruling No. 8 -
Pforzheim Local Court – Health Data
A psychotherapist had disclosed health data he had stored about a patient to a lawyer. The data included information on diagnosis, alcohol consumption, and further psychiatric treatment. The lawyer intended to use the information in child custody proceedings. The court found this to be a clear violation of Art. 9(1) GDPR, involving a low degree of fault, since no commercial interests were at play. Nevertheless, the defendant was ordered to pay damages intended to serve a deterrent and compensatory function. The court ordered a payment of 4,000 euros.
GDPR and Data Protection Ruling No. 9 -
Lübeck Labor Court – Employee Photo
A company had published a photo of an employee on the company website, along with his name and job title. The photo originally came from the employee's Facebook profile. The employee had previously objected to the publication after initially giving consent. The court found a “sufficient likelihood” of a GDPR violation under Art. 6(1) GDPR. The employer was found to bear a low degree of fault, as the required deletion of the published data had not been carried out. At the same time, the court found only minor non-material damage that did not amount to a serious violation of personal rights. Damages in this case were set at 1,000 euros.
GDPR and Data Protection Ruling No. 10 -
Bavarian State Office for Data Protection Supervision – Denial of Access
The competent supervisory authority wanted to carry out an on-site inspection at a Bavarian company and, during an unannounced inspection, demanded access to the business premises and, in particular, to the data processing systems. The company refused the authority's staff the requested access, even though supervisory authorities are entitled to carry out such inspections under Art. 58(1)(f) GDPR. As a consequence, the Bavarian State Office for Data Protection Supervision imposed a fine of 20,000 euros. The company appealed the fine, which was subsequently reduced to 7,000 euros.
GDPR and Data Protection Ruling No. 11 -
Lower Saxony Supervisory Authority – Online Shop
A data breach notification concerning the operator of an online shop was reported to the Lower Saxony supervisory authority. During the subsequent investigation, the authority found that the shop system in use was running an outdated version. The software vendor had not supplied the online shop with the required security updates since 2014, posing a significant security risk to users. Without proper security updates, it was entirely possible for unauthorized individuals to read out webshop customers' passwords in plain text. In this case, the shop operator had breached its duty to secure the shop through technical and organizational measures and to achieve the required level of protection. Customers' personal data was not adequately protected in the shop from a security standpoint. As a result, the Lower Saxony data protection authority held the shop operator responsible, and it was fined 65,500 euros.
GDPR and Data Protection Ruling No. 12 -
Hildesheim Local Court – Hard Drive Formatting
A company sold a computer without first formatting the hard drive, as required. As a result, third parties were able to access data — including a tax return, invoices with contact details, and photos — that could be attributed to the previous user. The court found causal non-material damage attributable to the controller's negligence. The court set damages at 800 euros.
FAQ
What consequences do GDPR violations have for companies beyond regulatory fines?
What consequences do GDPR violations have for companies beyond regulatory fines?
Beyond often substantial fines imposed by supervisory authorities, companies face serious reputational damage and loss of customer trust. In addition, affected individuals have the right under Art. 82 GDPR to claim material or non-material damages. Since data breaches usually affect not just individual cases but large sets of customer or employee data, damage claims can quickly add up to an existentially threatening sum.
What did the Regional Court of Munich I decide in the case of a financing company's data leak?
What did the Regional Court of Munich I decide in the case of a financing company's data leak?
A financing company suffered a data leak that exposed sensitive information such as bank details and ID data. The Regional Court of Munich ruled that the company had breached its obligation to implement appropriate technical and organizational measures (TOMs) for data security. With proper precautions, the leak could have been prevented, which is why the affected individuals were awarded damages.
Why isn't claiming "disproportionate effort" enough to ward off claims for damages?
Why isn't claiming "disproportionate effort" enough to ward off claims for damages?
Courts require companies to provide concrete proof that all legally required protective measures were implemented in line with the state of the art (accountability under Art. 5(2) GDPR). The blanket argument that proportionate security precautions would have been too expensive or too complex doesn't protect against liability and damage payments in the event of a data leak.
How can companies minimize the risk of liability and damages claims?
How can companies minimize the risk of liability and damages claims?
Companies must embed data protection as a continuous process. This includes:
- Complete implementation and documentation of technical and organizational measures (TOMs)
- Regular awareness-raising and training of employees
- Establishing clear processes for responding quickly to data breaches and data subject requests
- Working with a data protection officer to continuously review compliance







