BGH - VI ZR 144/23
German Federal Court of Justice rules national law can supplement GDPR for data transfer injunctions.
Summary
The German Federal Court of Justice has ruled that national laws can provide remedies for unlawful personal data transfers, even if the GDPR is considered exhaustive. This decision overturns a lower court's ruling that national law could only be used if explicitly permitted by the GDPR. The court emphasized that such national remedies can enhance data subject protection.
Full text
Help BGH - VI ZR 144/23: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 07:57, 22 September 2026 view source Av (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators188 edits Tag: Decisions [1.0]Newer edit → (No difference) Revision as of 07:57, 22 September 2026 BGH - VI ZR 144/23 Court: BGH (Germany) Jurisdiction: Germany Relevant Law: Article 4 GDPR Article 17 GDPR Decided: 21.07.2026 Published: 14.09.2026 Parties: National Case Number/Name: VI ZR 144/23 European Case Law Identifier: Appeal from: Appeal to: Not appealed Original Language(s): German Original Source: REWIS (in German) Initial Contributor: av The Federal Court of Justice held that a claim for injunctive relief under national law directed against the repeated transfer of personal data in violation of the GDPR cannot be rejected on the grounds that the provisions of EU law are exhaustive. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The operator of an online store (the controller) had embedded third-party features in its websites. As a result of this practice, the data of users accessing the website (the data subjects) was stored on servers operated by third parties. A data subject who had ordered goods from the controller's online store argued that his name, address, IP address, and numerous pieces of usage data from the ordering process had been unlawfully transferred to third parties. The data subject filed a lawsuit requesting an injunction to stop these transfers of personal data. The court of first instance dismissed the lawsuit on the grounds that it was inadmissible due to a lack of specificity. It also held the lawsuit was without merit. The data subject appealed this decision. The court of appeals dismissed the data subject's claim in March 2023: it held that the provisions of the GDPR are exhaustive and that national law may only be invoked if an opening clause is provided for in the GDPR. There was no applicable opening clause concerning injunctive relief. The data subject subsequently appealed the case further to the Federal Court of Justice. Holding The Federal Court of Justice set the appealed decision aside and referred the case back to the court of appeals for a new hearing and decision. First, the court stated that the court of appeals had correctly found the lawsuit admissible. The requirement of sufficient specificity was met, as it was unambiguous which conduct of the controller was to be prohibited. The data subject was undoubtedly seeking legal protection to prohibit the controller from designing websites in a way that leads to unlawful transfers of personal data to third parties. Second, the court held that the claim for injunctive relief could not be denied on the merits. It found that the court of appeals had been incorrect in assuming that a claim for an injunction regarding the unlawful transfer of personal data was precluded under national law because the provisions of the GDPR are exhaustive. The court referred to the CJEU's decision in the case C-655/23 Quirin Privatbank, where the CJEU held that the GDPR does not prevent Member States from providing a legal remedy requiring the controller to refrain from further unlawful processing on a national level. (margin number 52). The court emphasised such remedies may improve the level of protection for data subjects. It could therefore not be ruled out that the plaintiff could be entitled to an injunction under national law. Moreover, it could not be assumed that the data subject could have achieved their objective of preventing unlawful transfers of their personal data to third parties by asserting any of the data subject rights provided for in the GDPR, particularly the right to erasure laid down in Article 17 GDPR. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the German original. Please refer to the German original for more details. Federal Court of Justice VI ZR 144/23 July 21, 2026 rewis logo REWIS: LEGAL TECHNOLOGY Case Law Database Information provided without guarantee © REWIS UG (limited liability) URL: https://rewis.io/s/u/A6Si/ Federal Court of Justice 6th Civil Division 2 VI ZR 144/23 dated July 21, 2026 | rewis.io VI ZR 144/23 dated July 21, 2026 Judgement | Federal Court of Justice | 6th Civil Division Headnote A claim for injunctive relief under national law directed against the repeated transfer of personal data in violation of the General Data Protection Regulation cannot, as a matter of principle, be rejected on the grounds that the provisions of Union law are exhaustive. Disposition Upon the plaintiff’s appeal, the judgement of the 16th Civil Division of the Higher Regional Court of Frankfurt am Main dated March 30, 2023, is set aside. The case is remanded to the appellate court for a new hearing and decision, including on the costs of the appeal proceedings. As a matter of law Facts 1 The plaintiff seeks an injunction against the defendant to prevent the transfer of personal data. 2 The defendant operates an online store with the websites www.z[...].com and www.de.z[...].com. These websites incorporate third-party functions such a way that the program data is not stored on the server on which the defendant’s websites are hosted, but rather the User (or the User’s browser) is redirected to websites operated by third parties, the service providers. In the process, the third-party server is provided with the current IP address of the current User of the website to enable data retrieval from there (a so-called cloud solution). 3 The plaintiff considers this practice to be impermissible and points, among other things, to the defendant’s ability to store user data on its own servers. He alleges that in 2020 he ordered goods from the defendant’s online store, providing his name and address. In doing so, in addition to 3 VI ZR 144/23 dated July 21, 2026 | rewis.io his IP address, numerous usage data from the ordering process were also unlawfully transmitted to third parties. 4 In the first instance, the plaintiff filed a lawsuit seeking to order the defendant to refrain from “delivering” its websites z[...].com or de.z[...].com or, in each case, subdomains or subpages thereof to any of the services—specified in detail by the plaintiff —in such a way that, when the page is accessed, “personal data or data relating to the plaintiff—such as his IP address—” are transmitted to the respective operator of these services or to persons commissioned by them for this purpose, unless the plaintiff has previously consented to this within the meaning of Art. 4 No. 11 of the GDPR. 5 The Regional Court dismissed the lawsuit on the grounds that it was inadmissible due to a lack of specificity . Furthermore, it was also unfounded. The plaintiff filed an appeal against the Regional Court’s judgement and, in appeal proceedings, he amended his claim such that the primary claim replaces the previous wording “[...] that when the page is accessed, the plaintiff’s personal or personally identifiable data—such as his IP address— [...]” is replaced by the wording “[...] that when the page is accessed, any data pertaining to the plaintiff [...]”.In addition, he filed several alternative claims. The Higher Regional Court dismissed the plaintiff’s lawsuit. With his lawsuit to the Federal Court of Justice, which was granted by the Senate, the plaintiff continues to pursue his request for an injunction . Reasons for the Decision I. 6 The appellate court stated in support of its decision that the lawsuit was inadmissible as filed in the first instance due to a lack of sufficient specificity, because the term “personal data or personally identifiable data of the plaintiff” were legal concepts whose