[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fnYrYvFWPcTqf0DlZaBc8V5ie3ZEuTU9QOtzg6c8ilNY":3},{"article":4,"iocs":43},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":21,"category":22,"article_tags":26},"83786af5-4715-49c9-af97-2768383178fa","BGH - VI ZR 144\u002F23","bgh-vi-zr-144-23-3ae388","← Older revision Revision as of 06:54, 23 September 2026 Line 88: Line 88: }} }} The Federal Court of Justice held that a claim for injunctive relief under national law directed against the repeated transfer of personal data in violation of the GDPR cannot be rejected on the grounds that the provisions of EU law are exhaustive. The Federal Court of Justice held that the remedies under the GDPR are not exhaustive. Therefore, a claim for injunctive relief against the unlawful repeated transfer of personal data can be based on national law. == English Summary == == English Summary ==","The German Federal Court of Justice has ruled that claims for injunctive relief under national law against unlawful personal data transfers violating GDPR are permissible. The court overturned a lower court's decision, stating that GDPR remedies are not exhaustive and national legal avenues can be pursued. This decision allows individuals to seek injunctions against repeated data transfers to third parties, even without explicit GDPR opening clauses.","German Federal Court rules national law can supplement GDPR for data transfer injunctions.","Help BGH - VI ZR 144\u002F23: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 08:02, 22 September 2026 view sourceAv (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators189 edits Tag: Visual edit← Older edit Latest revision as of 06:54, 23 September 2026 view source Av (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators189 editsTag: Visual edit Line 88: Line 88: }}}} The Federal Court of Justice held that a claim for injunctive relief under national law directed against the repeated transfer of personal data in violation of the GDPR cannot be rejected on the grounds that the provisions of EU law are exhaustive.The Federal Court of Justice held that the remedies under the GDPR are not exhaustive. Therefore, a claim for injunctive relief against the unlawful repeated transfer of personal data can be based on national law. == English Summary ==== English Summary == Latest revision as of 06:54, 23 September 2026 BGH - VI ZR 144\u002F23 Court: BGH (Germany) Jurisdiction: Germany Relevant Law: Article 4 GDPR Article 17 GDPR Decided: 21.07.2026 Published: 14.09.2026 Parties: National Case Number\u002FName: VI ZR 144\u002F23 European Case Law Identifier: Appeal from: Appeal to: Not appealed Original Language(s): German Original Source: REWIS (in German) Initial Contributor: av The Federal Court of Justice held that the remedies under the GDPR are not exhaustive. Therefore, a claim for injunctive relief against the unlawful repeated transfer of personal data can be based on national law. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The operator of an online store (the controller) had embedded third-party features in its website. As a result of this practice, the data of users accessing the website (the data subjects) was stored on servers operated by third parties. A data subject who had ordered goods from the controller's online store argued that his name, address, IP address, and numerous pieces of usage data from the ordering process had been unlawfully transferred to third parties. The data subject filed a lawsuit requesting an injunction to stop these transfers of personal data. The court of first instance dismissed the lawsuit on the grounds that it was inadmissible due to a lack of specificity. It also held the lawsuit was without merit. The data subject appealed this decision. The court of appeals dismissed the data subject's claim in March 2023: it held that the provisions of the GDPR are exhaustive and that national law may only be invoked if an opening clause is provided for in the GDPR. There was no applicable opening clause concerning injunctive relief. The data subject subsequently appealed the case further to the Federal Court of Justice. Holding The Federal Court of Justice set the appealed decision aside and referred the case back to the court of appeals for a new hearing and decision. First, the court stated that the court of appeals had correctly found the lawsuit admissible. The requirement of sufficient specificity was met, as it was unambiguous which conduct of the controller was to be prohibited. The data subject was undoubtedly seeking legal protection to prohibit the controller from designing websites in a way that leads to unlawful transfers of personal data to third parties. Second, the court held that the claim for injunctive relief could not be denied on the merits. It found that the court of appeals had been incorrect in assuming that a claim for an injunction regarding the unlawful transfer of personal data was precluded under national law because the provisions of the GDPR are exhaustive. The court referred to the CJEU's decision in the case C-655\u002F23 Quirin Privatbank, where the CJEU held that the GDPR does not prevent Member States from providing a legal remedy requiring the controller to refrain from further unlawful processing on a national level[1]. The court emphasised such remedies may improve the level of protection for data subjects. It could therefore not be ruled out that the plaintiff could be entitled to an injunction under national law. Moreover, it could not be assumed that the data subject could have achieved their objective of preventing unlawful transfers of their personal data to third parties by asserting any of the data subject rights provided for in the GDPR, particularly the right to erasure laid down in Article 17 GDPR. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the German original. Please refer to the German original for more details. Federal Court of Justice VI ZR 144\u002F23 July 21, 2026 rewis logo REWIS: LEGAL TECHNOLOGY Case Law Database Information provided without guarantee © REWIS UG (limited liability) URL: https:\u002F\u002Frewis.io\u002Fs\u002Fu\u002FA6Si\u002F Federal Court of Justice 6th Civil Division 2 VI ZR 144\u002F23 dated July 21, 2026 | rewis.io VI ZR 144\u002F23 dated July 21, 2026 Judgement | Federal Court of Justice | 6th Civil Division Headnote A claim for injunctive relief under national law directed against the repeated transfer of personal data in violation of the General Data Protection Regulation cannot, as a matter of principle, be rejected on the grounds that the provisions of Union law are exhaustive. Disposition Upon the plaintiff’s appeal, the judgement of the 16th Civil Division of the Higher Regional Court of Frankfurt am Main dated March 30, 2023, is set aside. The case is remanded to the appellate court for a new hearing and decision, including on the costs of the appeal proceedings. As a matter of law Facts 1 The plaintiff seeks an injunction against the defendant to prevent the transfer of personal data. 2 The defendant operates an online store with the websites www.z[...].com and www.de.z[...].com. These websites incorporate third-party functions such a way that the program data is not stored on the server on which the defendant’s websites are hosted, but rather the User (or the User’s browser) is redirected to websites operated by third parties, the service providers. In the process, the third-party server is provided with the current IP address of the current User of the website to enable data retrieval from there (a so-called cloud solution). 3 The plaintiff considers this practice to be impermissible and points, among other things, to the defendant’s ability to store user data on its own servers. He alleges that in 2020 he ordered goods from the defendant’s online store, providing his name and address. In doing so, in addition to 3 VI ZR 144\u002F23 dated July 21, 2026 | rewis.io his IP address, numerous usage data from the ordering process were also unlawfully transmitted to third parties. 4 In the first instance, the plaintiff filed a lawsuit seeking to order the defendant to refrain from “delivering” its websites z[...].com or de.z[...].com or, in each case, subdomains or subpages thereof to any of the services—specified in detail by the plaintiff —in such a way that, when the page is accessed, “personal data or data relating to the plaintiff—such as his IP address—” are transmitted to the respective operator of these services or to persons commissioned by them for this purpose, unless the plaintiff has previously consented to this within the meaning of Art. 4 No. 11 of the GDPR. 5 The Regional Court dismissed the lawsuit on the grounds that it was inadmissible due to a lack of specificity . Furthermore, it was also unfounded. The plaintiff filed an appeal against the Regional Court’s judgement and, in appeal proceedings, he amended his claim such that the primary claim replaces the previous wording “[...] that when the page is accessed, the plaintiff’s personal or personally identifiable data—such as his IP address— [...]” is replaced by the wording","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=BGH_-_VI_ZR_144\u002F23&diff=53165&oldid=53132","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002F4\u002F4c\u002FCourts_logo1.png","2026-09-23T06:54:13+00:00","2026-09-23T08:00:09.411889+00:00",7,[18],{"name":19,"type":20},"GDPR","product","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":21,"icon":23,"name":24,"slug":25},null,"Policy","policy",[27,31,36,41],{"category":28},{"id":29,"icon":23,"name":19,"slug":30},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","gdpr",{"category":32},{"id":33,"icon":23,"name":34,"slug":35},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":37},{"id":38,"icon":23,"name":39,"slug":40},"614132b8-5837-4952-b8b5-c6c9a32a1d85","Privacy","privacy",{"category":42},{"id":21,"icon":23,"name":24,"slug":25},[]]