[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fDkEXcv1FY-Q3bosOfbM-3kS4wQR84qxMdVj58wBhccs":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"87aae46a-7e49-4995-a8e7-24baccc09249","german-court-rules-military-vaccination-certificate-inspection-violated-gdpr","d5c925c2-697f-4392-847e-986589097181","German Court Rules Military Vaccination Certificate Inspection Violated GDPR","The German Federal Administrative Court determined that requiring soldiers to present COVID-19 vaccination certificates constituted unlawful processing of personal health data under GDPR Article 9. The court found that non-medical personnel lacked authorization to inspect such sensitive health information, and that less intrusive verification methods should have been employed. This ruling highlights that even government and military organizations must comply with strict data protection requirements when handling personal health data, and that convenience cannot override legal requirements for data processing justification.","**Immediate actions:**\n- Conduct legal review of all current health data collection and processing activities\n- Suspend any health data inspections by non-authorized personnel until proper safeguards are implemented\n- Train supervisors on GDPR requirements for special category personal data\n\n**Long-term improvements:**\n- Establish clear policies defining who can access and process health-related personal data\n- Implement privacy-by-design principles requiring assessment of less intrusive alternatives before collecting sensitive data\n- Create documented legal basis assessments for all personal data processing activities\n\n**Compliance measures:**\n- Regular audits of data processing activities against GDPR Article 9 requirements\n- Implement data protection impact assessments for any new health data collection processes",[12,13,14,15,16],"GDPR Article 9","GDPR Article 6","NIST Privacy Framework PR.AC-1","ISO 27001 A.18.1.4","CIS Control 3","published","2026-06-09T10:20:45.15428+00:00","2026-06-09T10:20:45.076+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=BVerwG_-_Az._1_WRB_1.25&diff=51841&oldid=51840","bverwg-az-1-wrb-1-25-a94d47","BVerwG - Az. 1 WRB 1.25",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":32,"name":33,"slug":34,"description":35,"color":36},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]