[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fLZeRz7a5uFZdEDdRy52WPqJ0Mdtfup-Pf40r9QHVQgQ":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":19,"created_at":20,"published_at":21,"article":22,"tags":26,"podcasts":39},"f4c96b96-d90a-4962-8fa3-e2befa4b3a4f","german-court-rules-against-social-media-giant-for-gdpr-violations","33d99bb0-a809-4817-be11-d995deafde7d","German Court Rules Against Social Media Giant for GDPR Violations","The OLG Jena court found a major social media platform systematically violated fundamental GDPR principles by failing to respond properly to data access requests, processing personal data without legal basis through Business Tools, and unlawfully cross-linking sensitive browsing data to user profiles. The company also refused to honor users' erasure rights, demonstrating a complete disregard for data subject rights. This case highlights how inadequate data governance and privacy controls can lead to court-ordered remediation and significant legal exposure.","**Immediate actions:**\n- Audit all data processing activities to ensure valid legal basis under GDPR Article 6\n- Implement automated systems to handle data subject access requests within 30-day timeframes\n- Cease all sensitive data processing that lacks explicit consent or other lawful basis\n\n**Long-term improvements:**\n- Establish comprehensive data mapping to track all personal data flows and cross-linking activities\n- Implement privacy-by-design principles in all business tools and tracking systems\n- Create regular GDPR compliance audits with external legal review\n\n**Governance measures:**\n- Train all staff on data subject rights and proper response procedures\n- Establish clear data retention and erasure policies with automated enforcement\n- Implement privacy impact assessments for all new data processing activities",[12,13,14,15,16,17,18],"GDPR Article 6","GDPR Article 9","GDPR Article 15","GDPR Article 17","GDPR Article 25","NIST Privacy Framework","CIS Control 3","published","2026-04-14T13:08:11.714108+00:00","2026-04-14T13:08:11.366+00:00",{"id":7,"url":23,"slug":24,"title":25},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=OLG_Jena_-_3_U_31\u002F25&diff=51269&oldid=51260","olg-jena-3-u-31-25-c6ab96","OLG Jena - 3 U 31\u002F25",[27,33],{"id":28,"name":29,"slug":30,"description":31,"color":32},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":34,"name":35,"slug":36,"description":37,"color":38},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]