Back to Feed
PolicyJul 28, 2026

OLG München - 36 U 1054/25 e

Court orders social network operator to stop unlawful data processing and pay €1,500 in damages.

Summary

A German court has ruled that an Irish social network operator unlawfully processed personal data collected via its business tools on third-party websites and apps. The court ordered the company to cease this processing, erase existing data, and pay the data subject €1,500 in non-material damages, finding no lawful basis for the data collection and processing.

Full text

Help OLG München - 36 U 1054/25 e: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 06:34, 27 July 2026 view sourceShravan (talk | contribs)40 edits Tag: submission [1.0] Latest revision as of 13:27, 28 July 2026 view source Av (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators103 editsTag: Visual edit (One intermediate revision by the same user not shown)Line 76: Line 76: }}}} A court held that a social network platform operator unlawfully processed personal data collected through its business tools on third-party websites and apps, and ordered it to cease the processing, erase existing personal data and pay the data subject €1,500 in non-material damages.A court held that the operator of a social media platform unlawfully processed personal data collected through its business tools on third-party websites and apps, and ordered it to cease the processing, erase existing personal data and pay the data subject €1,500 in non-material damages. == English Summary ==== English Summary == === Facts ====== Facts === The Data Subject had used a social network platform operated by the Controller, an Irish company, since 2013. The Controller provided “Business Tools” to third-party website operators and app providers. These tools enabled the Controller to obtain data concerning how users interacted with third-party websites and apps, including information about page visits, purchases and advertisements clicked. The data subject had used a social media platform operated by the controller, an Irish company, since 2013. The controller provided “Business Tools” to third-party website operators and app providers. These tools enabled the controller to obtain data concerning how users interacted with third-party websites and apps, including information about page visits, purchases and advertisements clicked. In November 2023, the Data Subject requested that the Controller recognize that the processing of his personal data was contrary to the parties’ contract, erase or anonymize the personal data, provide access to the personal data and pay compensation. In November 2023, the data subject requested that the controller recognize that the processing of his personal data was contrary to the parties’ contract, erase or anonymize the personal data, provide access to the personal data and pay compensation. The Data Subject subsequently brought an action before the Regional Court of Munich II, seeking a declaration that the parties’ user contract did not permit the processing, cessation of the processing of personal data collected through the Business Tools on third-party websites and apps, restriction of further processing, erasure or anonymization of previously collected data and at least €5,000 in non-material damages. The relevant data included direct and indirect identifiers, such as his name, contact details, IP address and internal identifiers, as well as website URLs, visit times, app names and information about his interactions with websites and apps. The data subject subsequently brought an action before the Regional Court of Munich II, seeking a declaration that the parties’ user contract did not permit the processing, cessation of the processing of personal data collected through the Business Tools on third-party websites and apps, restriction of further processing, erasure or anonymization of previously collected data and at least €5,000 in non-material damages. The relevant data included direct and indirect identifiers, such as his name, contact details, IP address and internal identifiers, as well as website URLs, visit times, app names and information about his interactions with websites and apps. The Regional Court of Munich II dismissed the action, holding that the declaratory and erasure or anonymization claims were inadmissible, the cessation claims were legally unavailable and the damages claim had not been sufficiently substantiated. In relation to the damages claim, it found that the Data Subject had not identified specific third-party websites or apps through which his personal data had been processed. The Data Subject accordingly appealed to the Higher Regional Court of Munich.The Regional Court of Munich II dismissed the action, holding that the declaratory and erasure or anonymization claims were inadmissible, the cessation claims were legally unavailable and the damages claim had not been sufficiently substantiated. In relation to the damages claim, it found that the data subject had not identified specific third-party websites or apps through which his personal data had been processed. The data subject accordingly appealed to the Higher Regional Court of Munich. === Holding ====== Holding === The Higher Regional Court of Munich partially upheld the appeal.The Higher Regional Court of Munich partially upheld the appeal. First, the court held that the Controller processed the Data Subject’s personal data under Articles 4(1) and 4(2) GDPR by receiving data transmitted through its Business Tools, associating it with a user account and storing it. The Data Subject was not required to identify every website, app or individual transmission because the relevant information was principally within the Controller’s knowledge and it was sufficiently probable that he had been affected.First, the court held that the Controller processed the data subject’s personal data under [[Article 4 GDPR|Articles 4(1)]] and [[Article 4 GDPR|4(2) GDPR]] by receiving data transmitted through its Business Tools, associating it with a user account and storing it. The data subject was not required to identify every website, app or individual transmission because the relevant information was principally within the controller’s knowledge and it was sufficiently probable that he had been affected. Second, referring to CJEU C‑40/17 concerning the broad interpretation of “controller”, the court held that the Controller was a joint controller under Articles 4(7) and 26 GDPR for the collection and transmission of the personal data. It controlled the programming of the Business Tools and participated in determining the purposes and means of processing. Allocating certain obligations to third-party website and app operators did not remove its responsibility.Second, referring to [[CJEU - C-40/17 - Fashion ID|CJEU C‑40/17]] concerning the broad interpretation of “controller”, the court held that the controller was a joint controller under [[Article 4 GDPR|Articles 4(7)]] and [[Article 26 GDPR|26 GDPR]] for the collection and transmission of the personal data. It controlled the programming of the Business Tools and participated in determining the purposes and means of processing. Allocating certain obligations to third-party website and app operators did not remove its responsibility. Third, referring to CJEU C‑252/21, the court held that the Controller had not established a lawful basis for the processing of the personal data. The processing was not justified by consent under Article 6(1)(a), contractual necessity under Article 6(1)(b), a legal obligation under Article 6(1)(c), a public-interest task under Article 6(1)(e), or legitimate interests under [[Article 6 GDPR#1f|Article 6(1)(f) GDPR]]. Accordingly, the court held that the controller's processing infringed Articles 5(1)(a), 5(1)(b), 5(1)(c) and 6 GDPR.Third, referring to [[CJEU - C-252/21 - Meta Platforms and Others (General terms of use of a social network)|CJEU C‑252/21]], the court held that the controller had not established a lawful basis for the processing of the personal data. The processing was not justified by consent under [[Article 6 GDPR|Article 6(1)(a)]], contractual necessity under [[Article 6 GDPR|Article 6(1)(b)]], a legal obligation under [[Article 6 GDPR|Article 6(1)(c)]], a public-interest task under [[Article 6 GDPR|Article 6(1)(e)]], or legitimate interests under [[Article 6 GDPR#1f|Article 6(1)(f) GDPR]]. According

Entities

Irish social network operator (vendor)Business Tools (product)