[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f9_CydcYHapX4edt7YHa90nVFo4ZXlSAR2mpUyh6hgRg":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"caf46db3-eea8-4a59-894f-cd92f341f993","german-court-awards-gdpr-damages-after-bank-discloses-applicants-data-to-wrong-party","25b1f3f2-309e-43b9-9447-64d9ef3e43c8","German Court Awards GDPR Damages After Bank Discloses Applicant's Data to Wrong Party","A German bank mistakenly disclosed a job applicant's personal data — including sensitive salary expectations — to an unauthorized third party, violating GDPR's core principles of data minimization and accuracy. Germany's Federal Court of Justice (BGH) confirmed that even the applicant's subjective concern about potential misuse of their data constitutes sufficient 'non-material damage' to warrant compensation under GDPR Article 82. This ruling reinforces that organizations cannot treat accidental disclosures as harmless administrative errors — any unauthorized sharing of personal data carries real legal and financial consequences. The case highlights how internal data handling workflows, particularly during recruitment processes, must be tightly controlled to prevent misdirected communications.","**Immediate actions:**\n- Audit all recruitment and HR data workflows to identify points where personal data could be misdirected to unauthorized recipients.\n- Implement mandatory recipient verification steps (e.g., double-entry confirmation) before transmitting any personal data externally.\n\n**Long-term improvements:**\n- Deploy a Data Loss Prevention (DLP) solution to detect and block unauthorized transmission of personal or sensitive data via email and file sharing.\n- Establish a formal data classification policy that clearly tags recruitment data as sensitive and restricts its handling to authorized personnel only.\n- Integrate privacy-by-design principles into HR systems so that applicant data is compartmentalized and accessible only on a need-to-know basis.\n\n**Detection & response measures:**\n- Create an incident response playbook specifically for personal data misdisclosure events, including mandatory GDPR breach notification timelines.\n- Implement logging and monitoring on all outbound communications containing personal data to enable rapid detection and evidence gathering after a disclosure incident.",[12,13,14,15,16,17,18,19,20,21,22],"GDPR Article 5(1)(f) — Integrity and confidentiality","GDPR Article 82 — Right to compensation and liability","GDPR Article 32 — Security of processing","GDPR Article 33 — Notification of a personal data breach to the supervisory authority","NIST SP 800-53 AC-3 — Access Enforcement","NIST SP 800-53 SI-12 — Information Management and Retention","NIST SP 800-53 IR-6 — Incident Reporting","CIS Control 3 — Data Protection","CIS Control 14 — Security Awareness and Skills Training","ISO\u002FIEC 27001 Annex A.8.2 — Information Classification","ISO\u002FIEC 27001 Annex A.18.1.4 — Privacy and protection of personally identifiable information","published","2026-07-28T10:21:09.082372+00:00","2026-07-28T10:21:08.956+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=BGH_-_VI_ZR_97\u002F22&diff=52508&oldid=0","bgh-vi-zr-97-22-e176b6","BGH - VI ZR 97\u002F22",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":38,"name":39,"slug":40,"description":41,"color":42},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":44,"name":45,"slug":46,"description":47,"color":48},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]