Privacy TickerSeptember 2026 +++ FEDERAL COURT OF JUSTICE: CLAIMS FOR INJUNCTIVE RELIEF UNDER NATIONAL LAW POSSIBLE FOR GDPR INFRINGEMENTS +++ FEDERAL COURT OF JUSTICE: REFERRAL TO THE ECJ ON THE HOUSEHOLD EXEMPTION +++ IRELAND: EUR 403 MILLION FINE AGAINST GOOGLE FOR PROCESSING LOCATION DATA
 ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌   ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌  ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌  ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌   ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌   ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌   ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ 
 ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌   ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌  ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌  ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌   ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌   ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌   ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ 

Privacy Ticker

September 2026


+++ FEDERAL COURT OF JUSTICE: CLAIMS FOR INJUNCTIVE RELIEF UNDER NATIONAL LAW POSSIBLE FOR GDPR INFRINGEMENTS +++ FEDERAL COURT OF JUSTICE: REFERRAL TO THE ECJ ON THE HOUSEHOLD EXEMPTION +++ IRELAND: EUR 403 MILLION FINE AGAINST GOOGLE FOR PROCESSING LOCATION DATA +++ FEDERAL NETWORK AGENCY AND HAMBURG DATA PROTECTION AUTHORITY: DIFFERING ASSESSMENTS OF META SMART GLASSES +++

 

1. Case Law

+++ FEDERAL COURT OF JUSTICE: CLAIMS FOR INJUNCTIVE RELIEF UNDER NATIONAL LAW POSSIBLE FOR GDPR INFRINGEMENTS +++


The Federal Court of Justice has ruled that a claim for injunctive relief under national law against repeated transfer of personal data in violation of the GDPR cannot, as a general rule, be dismissed on the grounds that the GDPR exhaustively governs the legal consequences of data protection violations. The claimant had placed an order with an online shop whose website integrated third-party services in such a way that, when the website was accessed, the IP address was transmitted to external servers, among other data. The claimant sought to prohibit such transfers without his prior consent. In the court's view, the GDPR does not prevent Member States from providing for claims for injunctive relief under national law. In the case of unlawful data processing, claims under Sections 823 and 1004 of the German Civil Code would be particularly relevant. The Federal Court of Justice therefore overturned the appellate court's decision and remanded the case to the Higher Regional Court of Frankfurt am Main, which must now examine the additional requirements for a claim for injunctive relief.


To the judgment of the Federal Court of Justice (dated 21 July 2026, VI ZR 144/23, in German)


+++ FEDERAL COURT OF JUSTICE: REFERRAL TO THE ECJ ON THE HOUSEHOLD EXEMPTION +++


The Federal Court of Justice has referred questions concerning the so-called household exemption under Article 2(2)(c) GDPR to the European Court of Justice (ECJ) in two proceedings. In the first case, a private individual had forwarded confidential chat messages from a former friend to people in her professional environment; the data subject's employment was subsequently terminated. The second case concerned video surveillance in a family's shared kitchen and the disclosure of recordings to the police. In particular, the ECJ is being asked to clarify whether, when determining whether processing constitutes a purely personal or household activity, the purpose pursued by the processing and the fundamental rights interests involved must be taken into account. It is also being asked to clarify whether a professional connection on the part of the data subject or the recipient of the data can preclude application of the household exemption. In the video surveillance proceedings, the Federal Court of Justice additionally asks about the significance of the information obligations under Article 13 GDPR and of unlawful data collection for the lawfulness of subsequent processing.


To the press release of the Federal Court of Justice (dated 17 September 2026, I ZR 256/25 and I ZR 289/25, in German)


+++ HIGHER LABOUR COURT OF BADEN-WÜRTTEMBERG: SALARY DATA FROM GROSS PAYROLL LISTS MAY BE ADMISSIBLE IN INDIVIDUAL PROCEEDINGS +++


The Higher Labour Court of Baden-Württemberg has ruled on the admissibility of salary data in litigation concerning gender-based pay discrimination where a works council member had obtained the data from a gross payroll list accessible to the works council. The claimant introduced the compensation of a top earner as a comparator in her individual proceedings. In the court's view, she was permitted to use the salary data in the court proceedings. The processing was necessary for the exercise of her rights in the employment relationship and for the conduct of the judicial proceedings (Section 26(1) of the Federal Data Protection Act in conjunction with Article 6(1)(c), (3) and (4) GDPR). Furthermore, the fact that the works council is only permitted to inspect gross payroll lists and does not receive them for its own use (Section 80(2) of the Works Constitution Act) does not automatically preclude the use of information obtained from them in individual litigation. In particular, an exclusion of submissions or evidence does not follow solely from the fact that the salary data may have been obtained in breach of data protection requirements. The court thus follows the principles established by the ECJ on the use of personal data in judicial proceedings (see Privacy Ticker June 2026).


To the judgment of the Higher Labour Court of Baden-Württemberg (dated 18 August 2026, 2 Sa 14/24, in German)


+++ ADMINISTRATIVE COURT OF OSNABRÜCK: EVEN EXCESSIVE ACCESS REQUESTS MUST NOT BE LEFT UNANSWERED +++


The Administrative Court of Osnabrück has determined that even a request for information that may be excessive must be processed within the statutory one-month time limit. A citizen had once again requested information from a public authority under Article 15 GDPR. The authority considered the request to be repetitive and an abuse of the law, but failed to respond within one month. In the court’s opinion, where a request is manifestly unfounded or excessive, the controller may, under Article 12(5) GDPR, charge a reasonable fee or refuse to process the request. However, such a refusal does not relieve the controller of the obligation under Article 12(4) GDPR to inform the data subject, within one month at the latest, of the decision not to act, the reasons for it, and the available avenues for complaint and legal redress.


To the court order of the Administrative Court of Osnabrück (dated 19 August 2026, 7 A 170/24, in German)


 

2. Regulatory Investigations and Enforcement Actions

+++ IRELAND: EUR 403 MILLION FINE AGAINST GOOGLE FOR PROCESSING LOCATION DATA +++


The Irish data protection authority, the Data Protection Commission (DPC), has imposed fines totaling EUR 403 million on Google Ireland Limited. The investigation concerned the processing of location data in the “Web & App Activity,” “Location History,” and “Location Accuracy” features between 25 May 2018 and 4 February 2020. The DPC objected in particular to the lawfulness and fairness of the processing in the first two features, infringements of accountability and transparency obligations, and the excessive retention of location data. Google was ordered to bring the processing operations at issue into compliance with the GDPR within six months.


To the DPC press release (dated 21 September 2026)


+++ ITALY: EUR 5.5 MILLION FINE FOR ADVERTISING DESPITE OBJECTION +++


The Italian data protection authority Garante per la Protezione dei Dati Personali (GPDP) has fined Banco Bilbao Vizcaya Argentaria Italia more than EUR 5.5 million. A customer had objected to the processing of his data for advertising purposes in the app and repeated his objection to customer service. Due to inadequate synchronization between the company's systems and the marketing communications platform, he nevertheless continued to receive marketing messages for more than seven months. In the GPDP's view, it is not sufficient to record an objection in only one system. The company must ensure that the objection is effectively implemented across all systems and processing activities involved. In addition, the bank had failed to respond properly to the customer's request and had provided partly inaccurate information about its internal processing activities.


To the GPDP announcement (dated 11 September 2026, in Italian)


To the GPDP decision (dated 3 September 2026, in Italian)


 

3. Opinions

+++ EDPB: GUIDELINES ON THE RELATIONSHIP BETWEEN FINES AND OTHER CORRECTIVE MEASURES +++


The European Data Protection Board (EDPB) has published guidelines on deciding whether a fine should be imposed in addition to, or instead of, other corrective measures in the event of a GDPR violation. The guidelines supplement the existing guidance on calculating the amount of the fine and provide for a five-step assessment. The first step is to determine whether the established infringement is subject to a fine, who may be held responsible for it, and whether the infringement was committed intentionally or negligently. The aggravating and mitigating factors under Article 83(2) GDPR should then be examined, as well as the question of whether the violation was only minor, in which case a warning might suffice instead of a fine. The guidelines are open for public consultation until 13 November 2026.


To EDPB Guidelines 04/2026 (dated 17 September 2026)


To the EDPB public consultation (open until 13 November 2026)


+++ FEDERAL NETWORK AGENCY AND HAMBURG DATA PROTECTION AUTHORITY: DIFFERING ASSESSMENTS OF META SMART GLASSES +++


The Federal Network Agency currently considers a ban on the sale of Ray-Ban Meta Smart Glasses under Section 8 TDDDG unnecessary. The provision covers telecommunications equipment that is disguised as an everyday object or is specifically intended to record images or non-publicly spoken words without being noticed. According to the Federal Network Agency's assessment reported to date, the recording function of the tested glasses is sufficiently apparent to third parties because of the integrated LED. The authority is therefore not currently conducting formal prohibition proceedings, but continues to monitor the market. The Hamburg Commissioner for Data Protection and Freedom of Information reaches a stricter assessment in a technical and data protection review report. Depending on distance, viewing angle and lighting conditions, the LED is only of limited visibility and, by itself, is not sufficient to transparently inform data subjects about the processing. Users must provide additional notice, for example by means of pictograms or a verbal notification. In the data protection authority's view, recordings of people outside a close circle of friends and family are therefore generally unlawful, except in rare circumstances where legitimate interests may provide a legal basis. As a rule, there is also no legal basis for Meta to use the recordings for AI training.


To the Hamburg authority's final report (dated 10 September 2026, in German)


To the heise.de report on the Federal Network Agency's assessment (dated 15 August 2026, in German)


print version

Beiten Burkhardt Rechtsanwaltsgesellschaft mbH is a member of ADVANT, an association of independant law firms. Each Member Firm is a separate and legally distinct entity, and is liable only for its own acts or omissions. This privacy ticker was created in cooperation with the ADVANT partner law firms Nctm and Altana.

EDITOR IN CHARGE
Susanne Klein, LL.M. | Rechtsanwältin
©Beiten Burkhardt
Rechtsanwaltsgesellschaft mbH
BB-Datenschutz-Ticker@advant-beiten.com
www.advant-beiten.com

Your contacts at the Privacy Team

 

Please note: If you no longer wish to receive information, you can unsubscribe at any time.

Imprint

Beiten Burkhardt Rechtsanwaltsgesellschaft mbH
Ganghoferstraße 33, 80339 München
Registered unter HR B 155350 at the Regional Court Munich / VAT Reg. No. DE-811218811

Tel.: +49 89 35065-0, Fax: +49 89 35065-123 | E-Mail: munich@advant-beiten.com
Here you will find our complete imprint: www.advant-beiten.com/imprint 
and our privacy policy: www.advant-beiten.com/en/privacy-protection.


View in Browser