[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fb-7_n1zRSfRPhwrL4pOxw7G7HMZETtIz9JkNdkIcZ70":3},{"article":4,"iocs":40},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":23,"category":24,"article_tags":28},"94e23012-b4dd-418c-9181-d4c68f672f34","BGH - VI ZR 144\u002F23","bgh-vi-zr-144-23-c5fc75","Created page with \"{{COURTdecisionBOX |Jurisdiction=Germany |Court-BG-Color= |Courtlogo=Courts_logo1.png |Court_Abbrevation=BGH |Court_Original_Name=Bundesgerichtshof |Court_English_Name=Federal Court of Justice |Court_With_Country=BGH (Germany) |Case_Number_Name=VI ZR 144\u002F23 |ECLI= |Original_Source_Name_1=REWIS |Original_Source_Link_1=https:\u002F\u002Frewis.io\u002Fservice\u002Fpdf\u002Furteile\u002F9mq-21-07-2026-vi-zr-14423.pdf |Original_Source_Language_1=German |Original_Source_Language__Code_1=DE |Original_...\" New page {{COURTdecisionBOX |Jurisdiction=Germany |Court-BG-Color= |Courtlogo=Courts_logo1.png |Court_Abbrevation=BGH |Court_Original_Name=Bundesgerichtshof |Court_English_Name=Federal Court of Justice |Court_With_Country=BGH (Germany) |Case_Number_Name=VI ZR 144\u002F23 |ECLI= |Original_Source_Name_1=REWIS |Original_Source_Link_1=https:\u002F\u002Frewis.io\u002Fservice\u002Fpdf\u002Furteile\u002F9mq-21-07-2026-vi-zr-14423.pdf |Original_Source_Language_1=German |Original_Source_Language__Code_1=DE |Original_Source_Name_2= |Original_Source_Link_2= |Original_Source_Language_2= |Original_Source_Language__Code_2= |Date_Started= |Date_Decided=21.07.2026 |Date_Published=14.09.2026 |Year=2026 |GDPR_Article_1=Article 4 GDPR |GDPR_Article_Link_1=Article 4 GDPR |GDPR_Article_2=Article 17 GDPR |GDPR_Article_Link_2=Article 17 GDPR |GDPR_Article_3= |GDPR_Article_Link_3= |GDPR_Article_4= |GDPR_Article_Link_4= |EU_Law_Name_1= |EU_Law_Link_1= |EU_Law_Name_2= |EU_Law_Link_2= |National_Law_Name_1= |National_Law_Link_1= |National_Law_Name_2= |National_Law_Link_2= |Party_Name_1= |Party_Link_1= |Party_Name_2= |Party_Link_2= |Appeal_From_Body= |Appeal_From_Case_Number_Name= |Appeal_From_Status= |Appeal_From_Link= |Appeal_To_Body= |Appeal_To_Case_Number_Name= |Appeal_To_Status=Not appealed |Appeal_To_Link= |Initial_Contributor=av | }} The Federal Court of Justice held that a claim for injunctive relief under national law directed against the repeated transfer of personal data in violation of the GDPR cannot be rejected on the grounds that the provisions of EU law are exhaustive. == English Summary == === Facts === The operator of an online store (the controller) had embedded third-party features in its websites. As a result of this practice, the data of users accessing the website (the data subjects) was stored on servers operated by third parties. A data subject who had ordered goods from the controller's online store argued that his name, address, IP address, and numerous pieces of usage data from the ordering process had been unlawfully transferred to third parties. The data subject filed a lawsuit requesting an injunction to stop these transfers of personal data. The court of first instance dismissed the lawsuit on the grounds that it was inadmissible due to a lack of specificity. It also held the lawsuit was without merit. The data subject appealed this decision. The court of appeals dismissed the data subject's claim in March 2023: it held that the provisions of the GDPR are exhaustive and that national law may only be invoked if an opening clause is provided for in the GDPR. There was no applicable opening clause concerning injunctive relief. The data subject subsequently appealed the case further to the Federal Court of Justice. === Holding === The Federal Court of Justice set the appealed decision aside and referred the case back to the court of appeals for a new hearing and decision. First, the court stated that the court of appeals had correctly found the lawsuit admissible. The requirement of sufficient specificity was met, as it was unambiguous which conduct of the controller was to be prohibited. The data subject was undoubtedly seeking legal protection to prohibit the controller from designing websites in a way that leads to unlawful transfers of personal data to third parties. Second, the court held that the claim for injunctive relief could not be denied on the merits. It found that the court of appeals had been incorrect in assuming that a claim for an injunction regarding the unlawful transfer of personal data was precluded under national law because the provisions of the GDPR are exhaustive. The court referred to the CJEU's decision in the case C-655\u002F23 Quirin Privatbank, where the CJEU held that the GDPR does not prevent Member States from providing a legal remedy requiring the controller to refrain from further unlawful processing on a national level. (margin number 52). The court emphasised such remedies may improve the level of protection for data subjects. It could therefore not be ruled out that the plaintiff could be entitled to an injunction under national law. Moreover, it could not be assumed that the data subject could have achieved their objective of preventing unlawful transfers of their personal data to third parties by asserting any of the data subject rights provided for in the GDPR, particularly the right to erasure laid down in [[Article 17 GDPR|Article 17 GDPR]]. == Comment == ''Share your comments here!'' == Further Resources == ''Share blogs or news articles here!'' == English Machine Translation of the Decision == The decision below is a machine translation of the German original. Please refer to the German original for more details. Federal Court of Justice VI ZR 144\u002F23 July 21, 2026 rewis logo REWIS: LEGAL TECHNOLOGY Case Law Database Information provided without guarantee © REWIS UG (limited liability) URL: https:\u002F\u002Frewis.io\u002Fs\u002Fu\u002FA6Si\u002F Federal Court of Justice 6th Civil Division 2 VI ZR 144\u002F23 dated July 21, 2026 | rewis.io VI ZR 144\u002F23 dated July 21, 2026 Judgement | Federal Court of Justice | 6th Civil Division Headnote A claim for injunctive relief under national law directed against the repeated transfer of personal data in violation of the General Data Protection Regulation cannot, as a matter of principle, be rejected on the grounds that the provisions of Union law are exhaustive. Disposition Upon the plaintiff’s appeal, the judgement of the 16th Civil Division of the Higher Regional Court of Frankfurt am Main dated March 30, 2023, is set aside. The case is remanded to the appellate court for a new hearing and decision, including on the costs of the appeal proceedings. As a matter of law Facts 1 The plaintiff seeks an injunction against the defendant to prevent the transfer of personal data. 2 The defendant operates an online store with the websites www.z[...].com and www.de.z[...].com. These websites incorporate third-party functions such a way that the program data is not stored on the server on which the defendant’s websites are hosted, but rather the User (or the User’s browser) is redirected to websites operated by third parties, the service providers. In the process, the third-party server is provided with the current IP address of the current User of the website to enable data retrieval from there (a so-called cloud solution). 3 The plaintiff considers this practice to be impermissible and points, among other things, to the defendant’s ability to store user data on its own servers. He alleges that in 2020 he ordered goods from the defendant’s online store, providing his name and address. In doing so, in addition to 3 VI ZR 144\u002F23 dated July 21, 2026 | rewis.io his IP address, numerous usage data from the ordering process were also unlawfully transmitted to third parties. 4 In the first instance, the plaintiff filed a lawsuit seeking to order the defendant to refrain from “delivering” its websites z[...].com or de.z[...].com or, in each case, subdomains or subpages thereof to any of the services—specified in detail by the plaintiff —in such a way that, when the page is accessed, “personal data or data relating to the plaintiff—such as his IP address—” are transmitted to the respective operator of these services or to persons commissioned by them for this purpose, unless the plaintiff has previously consented to this within the meaning of Art. 4 No. 11 of the GDPR. 5 The Regional Court dismissed the lawsuit on the grounds that it was inadmissible due to a lack of specificity . Furthermore, it was also unfounded. The plaintiff filed an appeal against the Regional Court’s judgement and, in appeal proceedings, he amended his claim such that the primary claim replaces the previous wording “[...] that when the page is accessed, the plaintiff’s personal or personally identifiable data—such as his IP address— [...]” is replaced by the wording “[...] that when the page is accessed, any data pertaining to the plaintiff [...]”.In addition, he filed several alternative claims. The Higher Regional Court dismissed the plaintiff’s lawsuit. With his lawsuit to the Federal Court of Justice, which was granted by the Senate, the plaintiff continues to pursue his request for an injunction . Reasons for the Decision I. 6 The appellate court stated in support of its decision that the lawsuit was inadmissible as filed in the first instance due to a lack of sufficient specificity, because the term “personal data or personally identifiable data of the plaintiff” were legal concepts whose application required a legal classification that should not be left to the enforcement proceedings. However, with the motion filed in the appellate instance , the lawsuit is admissible. To the extent that the plaintiff, in his amended (primary) claim, seeks an injunction preventing “any of the plaintiff’s data from being transmitted to the operators of the services when the page is accessed,” this is sufficiently specific. This is because the defendant would thereby be prohibited from transmitting all data received when its website is accessed to the specified services. The term “data,” with its meaning of “information about a person or a thing,” which is attributed to it both in Art. 4(1) of the GDPR and in everyday language, has a sufficiently clear core meaning, such that its application can be left to the enforcement proceedings. 7 4 VI ZR 144\u002F23 dated July 21, 2026 | rewis.io However, the lawsuit is unfounded. The General Data Protection Regulation does not establish an individual right to enjoin the transfer of data to third parties if the plaintiff—as in this case—does not simultaneously demand the erasure of the data. It is not possible to rely on legal grounds outside the General Data Protection Regulation, in particular German national law. The provisions of the General Data Protection Regulation constitute an exhaustive, fully harmonized European framework regarding the consequences of violations of rules governing the processing of personal data. Due to this priority of application of the Union-wide exhaustively harmonized data protection law, national law may be invoked only if a corresponding enabling clause arises from the General Data Protection Regulation. This is not the case with respect to the claim for injunctive relief asserted by the plaintiff. II. 8 These arguments do not withstand review on appeal in their entirety. 9 1. The appellate court correctly affirmed the admissibility of the lawsuit. In particular, the claim—which must also be examined ex officio in the appeal proceedings (see, e.g., the Senate’s judgment of March 9, 2021—VI ZR 73\u002F20, NJW 2021, 1756 para. 15 with further references)—is sufficiently specific. 10 a) Pursuant to § 253(2)(2) of the Code of Civil Procedure (ZPO), a claim for injunctive relief may not be formulated so vaguely that the subject matter of the dispute and the scope of the court’s authority to review and decision-making authority of the Court (Section 308(1) of the German Code of Civil Procedure (ZPO)) are not clearly delineated, so that the defendant cannot mount an exhaustive defense and the decision regarding what the defendant is prohibited from doing is ultimately left to the enforcement court. Sufficient specificity is generally met when there is a reference to the specific infringing act or the specific form of infringement at issue is the subject matter of the complaint, and the relief sought, at least by reference to the statement of claims, unambiguously indicates in which aspects of the contested conduct the basis and the connecting factor for the alleged alleged infringement and thus the injunction (see Senate judgment of October 14, 2025—VI ZR 431\u002F24, VersR 2026, 235, para. 23, with further references). The use of terms requiring interpretation is permissible only if, on the one hand, further specification is not possible or reasonable for the plaintiff, and, on the other hand, there is no doubt among the parties as to their content, so that the scope of the claim and the judgement is established (see Senate judgment of March 31, 2026—VI ZR 157\u002F24, NJW 2026, 1578, para. 20, with further references). 11 b) In any event, the most recent (primary) lawsuit filed by the plaintiff meets these requirements. According to this lawsuit, the defendant is to be prohibited from 5 VI ZR 144\u002F23 dated July 21, 2026 | rewis.io from designing the web pages of its online store in such a way that, when accessed by the plaintiff, data is transmitted from his computer to the services specified in the lawsuit without the plaintiff’s consent. In the plaintiff’s view, all data originating from him—simply by virtue of its transfer together with his IP address—constitutes personal data. This unambiguously clarifies which conduct of the defendant is to be prohibited. 12 2. However, based on the reasoning of the appellate court, the asserted claim for injunctive relief cannot be denied on the merits. The Appellate Court erred in assuming that a claim for injunctive relief regarding the unlawful transfer of personal data is excluded from the outset under national law because the provisions of the General Data Protection Regulation constitute an exhaustive regulation in this regard. 13 The Court of Justice of the European Union (hereinafter “the Court”) stated in its judgement of September 4, 2025—which was issued after the appellate court’s decision— September 2025 in Case C-655\u002F23, the Court of Justice of the European Union (hereinafter: the Court) held that the provisions of the General Data Protection Regulation are to be interpreted as providing, in favor of the data subject affected by the unlawful processing of personal data, in the event that such a person—like the plaintiff in the present case—does not request the erasure of their data, do not provide for a judicial remedy that would enable them to obtain, as a preventive measure, an order requiring the controller to refrain from refrain from any further unlawful processing in the future. However, they do not prevent Member States from providing for such a legal remedy in their respective legal systems (see CJEU, NJW 2025, 3137, para. 52). The possibility for the data subject to bring a lawsuit against the controller seeking a future injunction against a violation of the substantive provisions of the General Data Protection Regulation does not undermine its objectives, but rather may strengthen the practical effectiveness of these provisions and thereby enhance the high level of protection sought by this Regulation for data subjects with respect to the processing of their personal data (ibid., para. 50). Accordingly, in the present case, an order requiring the defendant to cease and desist under national law, as sought in the complaint, cannot be denied on the grounds that the provisions of Union law are exhaustive. 14 3. Nor is the appellate judgment accurate for any other reasons. Based on the findings made, it cannot be ruled out that the plaintiff is entitled to a claim for injunctive relief under national law. 15 According to the supreme court case law issued prior to the entry into force of the General Data Protection Regulation, in the case of a violation of the general right of personality caused by unlawful data processing, 6 VI ZR 144\u002F23 of July 21, 2026 | rewis.io in its manifestation as the right to informational self-determination, the injured party is generally entitled to claims under the analogous application of § 1004(1), § 823 (1) of the German Civil Code (BGB) in conjunction with Art. 1(1) and Art. 2(1) of the German Basic Law (GG) (on the claim for injunctive relief pursuant to § 1004(1), first sentence, BGB by analogy, see the Senate’s judgment of March 16, 2010—VI ZR 176\u002F09, VersR 2010, 677, para. 11 et seq.; regarding the claim for remedy of consequences pursuant to § 1004(1), sentence 2 BGB, see Senate judgment of May 22, 1984—VI ZR 105\u002F82, BGHZ 91, 233, 239 et seq., juris para. 21 et seq.; Federal Court of Justice (BGH), judgement of July 7, 1983—III ZR 159\u002F82, NJW 1984, 436). In the event of a violation of a data protection provision that qualifies as a protective statute, claims may also arise by analogy under Section 1004(1), second para, and Section 823(2) of the German Civil Code (BGB) (see, regarding the claim for injunctive relief in the case of an unlawful data transfer under §§ 4, 29 BDSG (old version) , Senate judgments of July 24, 2018—VI ZR 330\u002F17, ZIP 2019, 1172, para. 53; of February 27, 2018—VI ZR 489\u002F16, BGHZ 217, 350, para. 42; February 20, 2018—VI ZR 30\u002F17, BGHZ 217, 340, para. 21 et seq.). These bases for claims must also be considered in the event of unlawful data protection under the General Data Protection Regulation General Data Protection Regulation (see Senate judgments of June 23, 2026 – VI ZR 97\u002F22, juris para. 26; of May 12, 2026 – VI ZR 375\u002F24, juris para. 29 et seq.). 16 Whether, as the defendant contends, an injunction under national law may be precluded by the fact that there is no need for such an order—does not require a decision in the context of the review to be conducted here pursuant to § 561 ZPO. Based on the findings made, it cannot be assumed that the plaintiff has asserted his claim for legal protection (prevention of the unlawful transfer of his personal data to third parties) by asserting one of the rights provided for by the General Data Protection Regulation—in particular, Article 17 of the GDPR (right to erasure). III. 17 The contested judgement was therefore to be set aside (Section 562(1) of the German Code of Civil Procedure (ZPO)) and the case remanded to the appellate court for a new hearing and decision (Section 563(1), first sentence, ZPO). Seiters Oehler Allgayer Böhm Linder","The German Federal Court of Justice has ruled that national laws can provide remedies for unlawful personal data transfers, even if the GDPR is considered exhaustive. This decision overturns a lower court's ruling that national law could only be used if explicitly permitted by the GDPR. The court emphasized that such national remedies can enhance data subject protection.","German Federal Court of Justice rules national law can supplement GDPR for data transfer injunctions.","Help BGH - VI ZR 144\u002F23: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 07:57, 22 September 2026 view source Av (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators188 edits Tag: Decisions [1.0]Newer edit → (No difference) Revision as of 07:57, 22 September 2026 BGH - VI ZR 144\u002F23 Court: BGH (Germany) Jurisdiction: Germany Relevant Law: Article 4 GDPR Article 17 GDPR Decided: 21.07.2026 Published: 14.09.2026 Parties: National Case Number\u002FName: VI ZR 144\u002F23 European Case Law Identifier: Appeal from: Appeal to: Not appealed Original Language(s): German Original Source: REWIS (in German) Initial Contributor: av The Federal Court of Justice held that a claim for injunctive relief under national law directed against the repeated transfer of personal data in violation of the GDPR cannot be rejected on the grounds that the provisions of EU law are exhaustive. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The operator of an online store (the controller) had embedded third-party features in its websites. As a result of this practice, the data of users accessing the website (the data subjects) was stored on servers operated by third parties. A data subject who had ordered goods from the controller's online store argued that his name, address, IP address, and numerous pieces of usage data from the ordering process had been unlawfully transferred to third parties. The data subject filed a lawsuit requesting an injunction to stop these transfers of personal data. The court of first instance dismissed the lawsuit on the grounds that it was inadmissible due to a lack of specificity. It also held the lawsuit was without merit. The data subject appealed this decision. The court of appeals dismissed the data subject's claim in March 2023: it held that the provisions of the GDPR are exhaustive and that national law may only be invoked if an opening clause is provided for in the GDPR. There was no applicable opening clause concerning injunctive relief. The data subject subsequently appealed the case further to the Federal Court of Justice. Holding The Federal Court of Justice set the appealed decision aside and referred the case back to the court of appeals for a new hearing and decision. First, the court stated that the court of appeals had correctly found the lawsuit admissible. The requirement of sufficient specificity was met, as it was unambiguous which conduct of the controller was to be prohibited. The data subject was undoubtedly seeking legal protection to prohibit the controller from designing websites in a way that leads to unlawful transfers of personal data to third parties. Second, the court held that the claim for injunctive relief could not be denied on the merits. It found that the court of appeals had been incorrect in assuming that a claim for an injunction regarding the unlawful transfer of personal data was precluded under national law because the provisions of the GDPR are exhaustive. The court referred to the CJEU's decision in the case C-655\u002F23 Quirin Privatbank, where the CJEU held that the GDPR does not prevent Member States from providing a legal remedy requiring the controller to refrain from further unlawful processing on a national level. (margin number 52). The court emphasised such remedies may improve the level of protection for data subjects. It could therefore not be ruled out that the plaintiff could be entitled to an injunction under national law. Moreover, it could not be assumed that the data subject could have achieved their objective of preventing unlawful transfers of their personal data to third parties by asserting any of the data subject rights provided for in the GDPR, particularly the right to erasure laid down in Article 17 GDPR. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the German original. Please refer to the German original for more details. Federal Court of Justice VI ZR 144\u002F23 July 21, 2026 rewis logo REWIS: LEGAL TECHNOLOGY Case Law Database Information provided without guarantee © REWIS UG (limited liability) URL: https:\u002F\u002Frewis.io\u002Fs\u002Fu\u002FA6Si\u002F Federal Court of Justice 6th Civil Division 2 VI ZR 144\u002F23 dated July 21, 2026 | rewis.io VI ZR 144\u002F23 dated July 21, 2026 Judgement | Federal Court of Justice | 6th Civil Division Headnote A claim for injunctive relief under national law directed against the repeated transfer of personal data in violation of the General Data Protection Regulation cannot, as a matter of principle, be rejected on the grounds that the provisions of Union law are exhaustive. Disposition Upon the plaintiff’s appeal, the judgement of the 16th Civil Division of the Higher Regional Court of Frankfurt am Main dated March 30, 2023, is set aside. The case is remanded to the appellate court for a new hearing and decision, including on the costs of the appeal proceedings. As a matter of law Facts 1 The plaintiff seeks an injunction against the defendant to prevent the transfer of personal data. 2 The defendant operates an online store with the websites www.z[...].com and www.de.z[...].com. These websites incorporate third-party functions such a way that the program data is not stored on the server on which the defendant’s websites are hosted, but rather the User (or the User’s browser) is redirected to websites operated by third parties, the service providers. In the process, the third-party server is provided with the current IP address of the current User of the website to enable data retrieval from there (a so-called cloud solution). 3 The plaintiff considers this practice to be impermissible and points, among other things, to the defendant’s ability to store user data on its own servers. He alleges that in 2020 he ordered goods from the defendant’s online store, providing his name and address. In doing so, in addition to 3 VI ZR 144\u002F23 dated July 21, 2026 | rewis.io his IP address, numerous usage data from the ordering process were also unlawfully transmitted to third parties. 4 In the first instance, the plaintiff filed a lawsuit seeking to order the defendant to refrain from “delivering” its websites z[...].com or de.z[...].com or, in each case, subdomains or subpages thereof to any of the services—specified in detail by the plaintiff —in such a way that, when the page is accessed, “personal data or data relating to the plaintiff—such as his IP address—” are transmitted to the respective operator of these services or to persons commissioned by them for this purpose, unless the plaintiff has previously consented to this within the meaning of Art. 4 No. 11 of the GDPR. 5 The Regional Court dismissed the lawsuit on the grounds that it was inadmissible due to a lack of specificity . Furthermore, it was also unfounded. The plaintiff filed an appeal against the Regional Court’s judgement and, in appeal proceedings, he amended his claim such that the primary claim replaces the previous wording “[...] that when the page is accessed, the plaintiff’s personal or personally identifiable data—such as his IP address— [...]” is replaced by the wording “[...] that when the page is accessed, any data pertaining to the plaintiff [...]”.In addition, he filed several alternative claims. The Higher Regional Court dismissed the plaintiff’s lawsuit. With his lawsuit to the Federal Court of Justice, which was granted by the Senate, the plaintiff continues to pursue his request for an injunction . Reasons for the Decision I. 6 The appellate court stated in support of its decision that the lawsuit was inadmissible as filed in the first instance due to a lack of sufficient specificity, because the term “personal data or personally identifiable data of the plaintiff” were legal concepts whose","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=BGH_-_VI_ZR_144\u002F23&diff=53131&oldid=0","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002F4\u002F4c\u002FCourts_logo1.png","2026-09-22T07:57:07+00:00","2026-09-22T08:00:11.757944+00:00",7,[18,21],{"name":19,"type":20},"GDPR","product",{"name":22,"type":20},"CJEU","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":23,"icon":25,"name":26,"slug":27},null,"Policy","policy",[29,33,38],{"category":30},{"id":31,"icon":25,"name":19,"slug":32},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","gdpr",{"category":34},{"id":35,"icon":25,"name":36,"slug":37},"614132b8-5837-4952-b8b5-c6c9a32a1d85","Privacy","privacy",{"category":39},{"id":23,"icon":25,"name":26,"slug":27},[]]