OLG München - 36 U 1054/25 e
German court rules social media platform unlawfully processed user data via Business Tools, orders €1,500 damages.
Summary
The Higher Regional Court of Munich (OLG München) partially upheld a data subject's appeal against a social media platform operator for unlawful processing of personal data collected through Business Tools deployed on third-party websites and apps. The court held that the platform's processing of the data subject's personal data (including IP addresses, identifiers, visit times, and interaction data) violated the GDPR and the user contract, ordering cessation of processing, data erasure, and €1,500 in non-material damages. The ruling clarifies that data subjects need not identify every specific third-party website or app where their data was processed to substantiate GDPR violation claims.
Full text
Help OLG München - 36 U 1054/25 e: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 13:27, 28 July 2026 view sourceAv (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators105 editsTag: Visual edit← Older edit Latest revision as of 14:07, 29 July 2026 view source Sfl (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators523 editsm Tag: Visual edit Line 63: Line 63: |Party_Link_3=|Party_Link_3= |Appeal_From_Body=Landgericht München II|Appeal_From_Body=Landgericht München II (Germany) |Appeal_From_Case_Number_Name=11 O 4629/23|Appeal_From_Case_Number_Name=11 O 4629/23 |Appeal_From_Status=|Appeal_From_Status= Latest revision as of 14:07, 29 July 2026 OLG München - 36 U 1054/25 e Court: OLG München (Germany) Jurisdiction: Germany Relevant Law: Article 4 GDPR Article 5 GDPR Article 6 GDPR Article 17 GDPR Article 18 GDPR Article 26 GDPR Article 82 GDPR §§ 1004(1), 823(1) German Civil Code (BGB) Decided: 26.06.2026 Published: Parties: Data Subject versus Social Media Platform Operator National Case Number/Name: 36 U 1054/25 e European Case Law Identifier: Appeal from: Landgericht München II (Germany)11 O 4629/23 Appeal to: Unknown Original Language(s): German Original Source: OpenJur (in German) Initial Contributor: Shravan A court held that the operator of a social media platform unlawfully processed personal data collected through its business tools on third-party websites and apps, and ordered it to cease the processing, erase existing personal data and pay the data subject €1,500 in non-material damages. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The data subject had used a social media platform operated by the controller, an Irish company, since 2013. The controller provided “Business Tools” to third-party website operators and app providers. These tools enabled the controller to obtain data concerning how users interacted with third-party websites and apps, including information about page visits, purchases and advertisements clicked. In November 2023, the data subject requested that the controller recognize that the processing of his personal data was contrary to the parties’ contract, erase or anonymize the personal data, provide access to the personal data and pay compensation. The data subject subsequently brought an action before the Regional Court of Munich II, seeking a declaration that the parties’ user contract did not permit the processing, cessation of the processing of personal data collected through the Business Tools on third-party websites and apps, restriction of further processing, erasure or anonymization of previously collected data and at least €5,000 in non-material damages. The relevant data included direct and indirect identifiers, such as his name, contact details, IP address and internal identifiers, as well as website URLs, visit times, app names and information about his interactions with websites and apps. The Regional Court of Munich II dismissed the action, holding that the declaratory and erasure or anonymization claims were inadmissible, the cessation claims were legally unavailable and the damages claim had not been sufficiently substantiated. In relation to the damages claim, it found that the data subject had not identified specific third-party websites or apps through which his personal data had been processed. The data subject accordingly appealed to the Higher Regional Court of Munich. Holding The Higher Regional Court of Munich partially upheld the appeal. First, the court held that the Controller processed the data subject’s personal data under Articles 4(1) and 4(2) GDPR by receiving data transmitted through its Business Tools, associating it with a user account and storing it. The data subject was not required to identify every website, app or individual transmission because the relevant information was principally within the controller’s knowledge and it was sufficiently probable that he had been affected. Second, referring to CJEU C‑40/17 concerning the broad interpretation of “controller”, the court held that the controller was a joint controller under Articles 4(7) and 26 GDPR for the collection and transmission of the personal data. It controlled the programming of the Business Tools and participated in determining the purposes and means of processing. Allocating certain obligations to third-party website and app operators did not remove its responsibility. Third, referring to CJEU C‑252/21, the court held that the controller had not established a lawful basis for the processing of the personal data. The processing was not justified by consent under Article 6(1)(a), contractual necessity under Article 6(1)(b), a legal obligation under Article 6(1)(c), a public-interest task under Article 6(1)(e), or legitimate interests under Article 6(1)(f) GDPR. Accordingly, the court held that the controller's processing infringed Articles 5(1)(a), 5(1)(b), 5(1)(c) and 6 GDPR. Relying on CJEU C‑655/23, the court granted an injunction against future unlawful processing under German law. It also ordered restriction pending erasure under Article 18(1)(b) and erasure under Article 17(1)(d) GDPR. The court upheld the dismissal of the separate declaratory claim and also rejected anonymization of the website and app interaction data. Finally, relying on BGH VI ZR 10/24, the court awarded €1,500 in non-material damages under Article 82(1) GDPR for the data subject’s loss of control over his personal data. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the German original. Please refer to the German original for more details. Munich Higher Regional Court, Final Judgment of June 26, 2026 - 36 U 1054/25 e Source: openJur 2026, 7116 Rkr: AmtlSlg: Judgment and reformulated as follows: 1 I. Upon the plaintiff's appeal, the judgment of the Munich II Regional Court of February 27, 2025, Case No. 11 O 4629/23, is partially amended. 2 1. The defendant is ordered, under penalty of a fine to be determined by the court for each instance of non-compliance, up to €250,000.00, or alternatively, detention to be served on its legal representative or detention to be served on its legal representative for up to six months, and in the case of repeated offenses up to two years, to refrain from publishing the following personal data of the plaintiff on third-party websites and apps outside the defendant's networks: 3 a) on Personal data of the plaintiff generated by third-party websites and apps, whether transmitted directly or in hashed form, i.e., 4 - Plaintiff's email address 5 - Plaintiff's telephone number 6 - Plaintiff's first name 7 - Plaintiff's last name 8 - Plaintiff's date of birth 9 - Plaintiff's gender 10 - Plaintiff's city 11 - External IDs of other advertisers (referred to by M. Ltd. as "external ID") 12 - Client's IP address 13 - Client's user agent (i.e., collected browser information) 14 - M. Ltd.'s internal click ID 15 - M. Ltd.'s internal browser ID 16 - Subscription ID – Lead ID – anon id _ 17 and the following personal data of the plaintiff 18 b) on websites 19 - the URLs of the websites including their subpages 20 - the time of the visit 21 - the "referrer" (the website from which the user came to the current website), 22 - the buttons clicked by the plaintiff on the website, and 23 - other data referred to by M. as "Events," which document the plaintiff's interactions on the respective website 24 c) in third-party mobile apps 25 - the name of the app, and 26 - the time of the visit 27 - the buttons clicked by the plaintiff in the app, and 28 - the data referred to by M. as "Events," which document the plaintiff's interactions in the respective app 29 to be p