Back to Feed
PolicySep 22, 2026

BGH - VI ZR 144/23

German court rules GDPR doesn't preclude national injunctions for unlawful data transfers.

Summary

A German Federal Court of Justice (BGH) decision clarifies that the GDPR does not prevent member states from offering national legal remedies, such as injunctions, to prohibit unlawful personal data transfers to third parties. This ruling stems from a case where an online store operator embedded third-party features, leading to user data being transferred. The court found that a data subject could pursue an injunction under national law, even if GDPR rights alone might not suffice.

Full text

Help BGH - VI ZR 144/23: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 07:57, 22 September 2026 view sourceAv (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators188 edits Tag: Decisions [1.0] Latest revision as of 08:02, 22 September 2026 view source Av (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators188 edits Tag: Visual edit Line 93: Line 93: === Facts ====== Facts === The operator of an online store (the controller) had embedded third-party features in its websites. As a result of this practice, the data of users accessing the website (the data subjects) was stored on servers operated by third parties. A data subject who had ordered goods from the controller's online store argued that his name, address, IP address, and numerous pieces of usage data from the ordering process had been unlawfully transferred to third parties. The data subject filed a lawsuit requesting an injunction to stop these transfers of personal data.The operator of an online store (the controller) had embedded third-party features in its website. As a result of this practice, the data of users accessing the website (the data subjects) was stored on servers operated by third parties. A data subject who had ordered goods from the controller's online store argued that his name, address, IP address, and numerous pieces of usage data from the ordering process had been unlawfully transferred to third parties. The data subject filed a lawsuit requesting an injunction to stop these transfers of personal data. The court of first instance dismissed the lawsuit on the grounds that it was inadmissible due to a lack of specificity. It also held the lawsuit was without merit. The data subject appealed this decision. The court of first instance dismissed the lawsuit on the grounds that it was inadmissible due to a lack of specificity. It also held the lawsuit was without merit. The data subject appealed this decision. Line 105: Line 105: First, the court stated that the court of appeals had correctly found the lawsuit admissible. The requirement of sufficient specificity was met, as it was unambiguous which conduct of the controller was to be prohibited. The data subject was undoubtedly seeking legal protection to prohibit the controller from designing websites in a way that leads to unlawful transfers of personal data to third parties.First, the court stated that the court of appeals had correctly found the lawsuit admissible. The requirement of sufficient specificity was met, as it was unambiguous which conduct of the controller was to be prohibited. The data subject was undoubtedly seeking legal protection to prohibit the controller from designing websites in a way that leads to unlawful transfers of personal data to third parties. Second, the court held that the claim for injunctive relief could not be denied on the merits. It found that the court of appeals had been incorrect in assuming that a claim for an injunction regarding the unlawful transfer of personal data was precluded under national law because the provisions of the GDPR are exhaustive. The court referred to the CJEU's decision in the case C-655/23 Quirin Privatbank, where the CJEU held that the GDPR does not prevent Member States from providing a legal remedy requiring the controller to refrain from further unlawful processing on a national level. (margin number 52). The court emphasised such remedies may improve the level of protection for data subjects.Second, the court held that the claim for injunctive relief could not be denied on the merits. It found that the court of appeals had been incorrect in assuming that a claim for an injunction regarding the unlawful transfer of personal data was precluded under national law because the provisions of the GDPR are exhaustive. The court referred to the CJEU's decision in the case [[CJEU - C-655/23 - Quirin Privatbank|C-655/23 ''Quirin Privatbank'']]'','' where the CJEU held that the GDPR does not prevent Member States from providing a legal remedy requiring the controller to refrain from further unlawful processing on a national level<ref>See [[CJEU - C-655/23 - Quirin Privatbank|CJEU - C-655/23 - ''Quirin Privatbank'']], margin number 52.</ref>. The court emphasised such remedies may improve the level of protection for data subjects. It could therefore not be ruled out that the plaintiff could be entitled to an injunction under national law. Moreover, it could not be assumed that the data subject could have achieved their objective of preventing unlawful transfers of their personal data to third parties by asserting any of the data subject rights provided for in the GDPR, particularly the right to erasure laid down in [[Article 17 GDPR|Article 17 GDPR]].It could therefore not be ruled out that the plaintiff could be entitled to an injunction under national law. Moreover, it could not be assumed that the data subject could have achieved their objective of preventing unlawful transfers of their personal data to third parties by asserting any of the data subject rights provided for in the GDPR, particularly the right to erasure laid down in [[Article 17 GDPR]]. == Comment ==== Comment == Latest revision as of 08:02, 22 September 2026 BGH - VI ZR 144/23 Court: BGH (Germany) Jurisdiction: Germany Relevant Law: Article 4 GDPR Article 17 GDPR Decided: 21.07.2026 Published: 14.09.2026 Parties: National Case Number/Name: VI ZR 144/23 European Case Law Identifier: Appeal from: Appeal to: Not appealed Original Language(s): German Original Source: REWIS (in German) Initial Contributor: av The Federal Court of Justice held that a claim for injunctive relief under national law directed against the repeated transfer of personal data in violation of the GDPR cannot be rejected on the grounds that the provisions of EU law are exhaustive. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The operator of an online store (the controller) had embedded third-party features in its website. As a result of this practice, the data of users accessing the website (the data subjects) was stored on servers operated by third parties. A data subject who had ordered goods from the controller's online store argued that his name, address, IP address, and numerous pieces of usage data from the ordering process had been unlawfully transferred to third parties. The data subject filed a lawsuit requesting an injunction to stop these transfers of personal data. The court of first instance dismissed the lawsuit on the grounds that it was inadmissible due to a lack of specificity. It also held the lawsuit was without merit. The data subject appealed this decision. The court of appeals dismissed the data subject's claim in March 2023: it held that the provisions of the GDPR are exhaustive and that national law may only be invoked if an opening clause is provided for in the GDPR. There was no applicable opening clause concerning injunctive relief. The data subject subsequently appealed the case further to the Federal Court of Justice. Holding The Federal Court of Justice set the appealed decision aside and referred the case back to the court of appeals for a new hearing and decision. First, the court stated that the court of appeals had correctly found the lawsuit admissible. The requirement of sufficient specificity was met, as it was unambiguous which conduct of the controller was to be prohibited. The data subject was undoubtedly seeking legal protection to prohibit the controller from designing websites in a way that leads to unlawful transfers of personal data to third parties. Second, the court held that the claim for injunctive relief could not be denied on the merits. It found that the court of appeals had been incorrect in assuming that a claim for an injunction regarding the un

Entities

GDPR (product)Quirin Privatbank (product)