[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fXc0nHg5zoQ_rFt9jKpinUQtsCyWGhxYrNhhCF4lEgbU":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"a6fbf9aa-d954-4701-8ff5-7face2765cb2","german-federal-court-expands-gdpr-enforcement-national-injunctions-now-permissible-for-unlawful-data","83786af5-4715-49c9-af97-2768383178fa","German Federal Court Expands GDPR Enforcement: National Injunctions Now Permissible for Unlawful Data Transfers","The German Federal Court of Justice (BGH) ruled that individuals can pursue injunctive relief under national law against unlawful personal data transfers, even where GDPR does not explicitly provide for such a remedy. This decision clarifies that GDPR's enforcement mechanisms are not exhaustive, meaning organizations now face an expanded legal landscape of liability beyond direct GDPR sanctions. Companies transferring personal data to third parties without a lawful basis risk not only regulatory fines but also civil injunctions brought by affected individuals. This ruling matters because it significantly raises the stakes for non-compliant data sharing practices, particularly in cross-border or third-party transfer scenarios. Organizations that have relied on GDPR compliance alone as their legal shield must now reassess their exposure to national civil law claims.","**Immediate actions:**\n- Conduct an urgent audit of all third-party personal data transfer agreements to verify lawful bases under GDPR Articles 6 and 44-49.\n- Establish a legal review process for any new or ongoing data sharing arrangements to assess exposure under both GDPR and applicable national civil law.\n\n**Long-term improvements:**\n- Implement a comprehensive data mapping program to maintain a living record of all personal data flows, recipients, and legal justifications.\n- Develop and enforce a formal Third-Party Data Transfer Policy that includes contractual safeguards, Data Processing Agreements (DPAs), and Standard Contractual Clauses (SCCs) where required.\n- Embed privacy-by-design principles into product and service development to minimize unnecessary personal data transfers to third parties.\n\n**Detection & response measures:**\n- Establish a Privacy Incident Response Plan that specifically addresses scenarios involving unlawful data transfers and potential injunctive relief claims.\n- Monitor legal developments across EU member states to ensure compliance programs adapt to evolving national interpretations of GDPR obligations.",[12,13,14,15,16,17,18,19,20],"GDPR Article 6 – Lawfulness of Processing","GDPR Articles 44-49 – Transfers of Personal Data to Third Countries","GDPR Article 79 – Right to an Effective Judicial Remedy Against a Controller or Processor","GDPR Article 82 – Right to Compensation and Liability","NIST Privacy Framework PR.DS-P1 – Data Processing Policies","NIST SP 800-53 PT-1 – Privacy Policy and Procedures","CIS Control 3 – Data Protection","ISO\u002FIEC 27701:2019 – Privacy Information Management","ITIL Service Value Chain – Governance and Risk Management","published","2026-09-23T08:21:45.346486+00:00","2026-09-23T08:21:44.988+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=BGH_-_VI_ZR_144\u002F23&diff=53165&oldid=53132","bgh-vi-zr-144-23-3ae388","BGH - VI ZR 144\u002F23",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":36,"name":37,"slug":38,"description":39,"color":40},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":42,"name":43,"slug":44,"description":45,"color":46},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]