[Translate to English:] Laptop
Newsletter data protection

Newsletter data protection 07/2026

In this month’s newsletter, we report on an interesting ruling by the ECJ concerning the admissibility of evidence obtained in breach of data protection laws and introduced into court proceedings by the party presenting the case. The case arose from a company’s access to a former employee’s private eBay profile. Furthermore, the 26th Grand Criminal Chamber of the Berlin Regional Court I had to rule on a fine imposed on the property company Deutsche Wohnen, which was set in 2019 at a then-record amount of 14.5 million euros. Part of the court proceedings involved a landmark ruling by the ECJ. In addition, legal questions regarding end-to-end encryption of emails remained unresolved, which this time had to be addressed by the Regional Court of Karlsruhe.

In our current feature, we examine the data protection considerations employers must take into account when dealing with social media. For employers, the question arises not only as to which user profiles and posts may be taken into account in the decision-making process for a recruitment procedure, but also as to what rights and obligations employees have when managing a company profile or when making work-related posts on their private user profiles.

If you have any feedback on this newsletter or any questions regarding its topics, please email us at datenschutz@brandi.net. You can also find further contact details on our website.

Dr Sebastian Meyer and the BRANDI Data Protection Team

Dr. Sebastian Meyer, LL.M.

Lawyer and Notary in and for Bielefeld
Certified Specialized Attorney in information technology law (IT-Recht)
Data Protection Auditor (TÜV)

Information and contact

Topic of the month / July 2026

Social Media and Employee Data Protection

Social media is becoming increasingly popular amongst employers and is used both for recruitment and to enhance the company’s reputation and visibility. However, alongside the numerous opportunities, social media also entails many risks for employers, regardless of whether employees use it for work or personal purposes. This is because social media platforms have a wide reach; published information spreads quickly and is difficult to delete. The posts uploaded there predominantly contain personal data as defined in Article 4 (1) of the GDPR – whether names and locations, hobbies, the content of communications, personal opinions or photos featuring identifiable individuals. Employers must therefore ensure the protection of personal data in their activities on social media.

Other topics in this newsletter

ECJ

Use of Evidence collected in breach of Data Protection Rules

In its judgment of June 18, 2026, the Court of Justice of the European Union (ECJ) ruled that the collection of personal data in breach of data protection rules does not result in a prohibition on the use of such evidence if the party has no legitimate interest in the data processing that goes beyond merely proving the facts put forward (ECJ, decision dated 18.06.2026 – Ref.: C-484/24). 

According to the facts of the case, following the end of her employment with a heating and air-conditioning company, a former employee sold company equipment via the online sales platform eBay for a total of 13,217.09 euros. The company, which had become aware of the sales by accessing the former employee’s private user profile, brought legal proceedings against her. The company submitted this data, which had been collected in breach of data protection regulations, as evidence in the court proceedings.

The court has a legal duty to rule on the admissibility of the evidence submitted by the parties and to assess the admissible evidence when delivering its judgment. In this context, the ECJ clarifies that the processing of personal data by the court is carried out to safeguard the right to a fair trial under Article 47 of the Charter of Fundamental Rights and is therefore proportionate even if the personal data was collected in breach of data protection rules, provided that the party bearing the burden of proof’s interest in the data does not extend beyond the establishment of the facts. It is then the court’s responsibility, in the further proceedings, to uphold the data protection principles set out in Article 5 (1) of the GDPR when disclosing the data to parties or third parties.

We explain the requirements for a prohibition on the use of evidence in connection with employees’ user profiles on social media, and what employers must generally bear in mind when processing personal data on social media, in our current main topic.

 

Hamburg Administrative Court

Supervisory Authority may not oblige Google to filter Content

In its judgement of January 22, 2026, the Hamburg Administrative Court ruled that the Hamburg data protection authority was not entitled to oblige Google to remove certain search results that appeared when searching for the intervener’s name (Hamburg Administrative Court, decision dated 22.01.2026 – Ref.: 17 K 2480/23).

The court proceedings were preceded by a request from the intervener to have the results removed. She had initially contacted Google and subsequently the Hamburg Data Protection Supervisory Authority because pornographic, sexualised and other web spam content was displayed when searching for her name. After the intervener deemed the search engine operator’s efforts to be insufficient, and the discussions between Google and the supervisory authority also failed to produce the desired result, the supervisory authority formally prohibited Google from displaying the search results in question when searching for the intervener’s name. Google challenged this decision in court.

The Administrative Court (VG) of Hamburg deemed the supervisory authority’s decision to be unlawful, as, in the court’s view, the legal basis put forward by the supervisory authority under Article 58 (2) (f) and (g) of the GDPR was insufficient for this purpose. Under this provision, a supervisory authority may, in principle, require the erasure of personal data and the restriction of processing. However, in the court’s view, these powers do not allow it to impose an abstract and proactive filtering obligation on a search engine operator. The Hamburg Administrative Court refers in this regard to the case law of the European Court of Justice, according to which delisting can only be required in relation to specifically identified content. The Hamburg supervisory authority, however, had not limited its order to specifically named websites, but had instead described abstract generic characteristics. Google would therefore first have had to identify the websites in question itself. In the court’s view, the right to be delisted does not encompass precisely such a proactive obligation to delist. Accordingly, the supervisory authority was also unable to impose such an obligation. 

Berlin Regional Court I

Fine against Deutsche Wohnen SE reduced to € 900,000

In its judgement of June 9, 2026, the Berlin Regional Court I reduced a fine of 14,500,000 euros imposed by the Berlin Data Protection Commissioner (Bln BDI) on the housing association Deutsche Wohnen SE to 900,000 euros (Berlin Regional Court I, decision dated 09.06.2026 – Ref.: 526 OWiG LG 1/20, press release of 09.06.2026).

In 2019, the Berlin Data Protection Authority (Bln BDI) imposed a fine of 14,500,000 euros on Deutsche Wohnen SE – the highest GDPR fine at the time – as the property group was using an archiving system that contravened data protection regulations – in which tenants’ personal data was stored despite the processing purpose no longer applying – and which had already been criticised by the authority in 2017. The amount of the fine was justified on the grounds that, despite the two-year transition period leading up to the GDPR coming into force on May 25, 2018 and the protracted supervisory proceedings, Deutsche Wohnen SE had failed to adapt the group’s IT system in good time. We reported on the fine notice at the time in our December 2019 newsletter.

As expected, the property group lodged an appeal against the fine notice. After the proceedings before the Regional Court were discontinued by order of February 18, 2021 due to a procedural obstacle, the Berlin Court of Appeal referred the case to the ECJ on appeal, asking whether a company’s liability for a fine requires culpable misconduct on the part of a specifically identified individual and whether such liability is based on fault. In its judgment of December 5, 2023, the ECJ ruled that a principle of imputation is unknown in European data protection law and answered the first question referred in the negative (ECJ, decision dated 05.12.2023 – Ref.: C-807/21). However, it held that liability is fault-based.

The case was therefore referred back to the Regional Court, which subsequently found that Deutsche Wohnen SE was at fault with regard to the breach of the principles of data minimisation and storage limitation. After all, it would have been technically possible and reasonable for the property group to delete the sensitive data of former tenants in good time. However, when calculating the fine, account must be taken of the fact that the company had engaged external auditors, consultants and IT specialists to adapt its IT systems, and that the data protection infringements were limited in time of the introductory phase of the GDPR.

Following the pronouncement of the judgement, the property group’s legal representatives remarked “that it is possible to successfully defend oneself in court against decisions by data protection authorities and other supervisory authorities under the EU Digital Rights Acts”.

The judgement is not yet final.

Karlsruhe Regional Court

No Obligation for End-to-End Encryption in the B2B Sector

In a judgement dated May 20, 2026, the Karlsruhe Regional Court ruled that, in principle, there is no obligation to use end-to-end encryption in business email correspondence (Karlsruhe Regional Court, decision dated 20.05.2026 – Ref.: 8 O 266/25).

The claim was brought by a married couple who had entered into a contract of sale for gold bars with the defendant. The claimants initially received an invoice by email which, whilst visually similar to the original invoice subsequently sent by post, had been altered in key respects. In particular, the bank details and the IBAN to which payment was to be made had been changed. The plaintiffs therefore transferred the purchase price to an account that did not belong to the defendant. Consequently, the gold bars were not delivered. It was agreed that the details on the invoice had been falsified. It remained unclear at what stage the invoice had been tampered with: possibilities included alteration by a third party in the defendant’s IT system, in the recipients’ postbox, or during the communication process. The claimants continued to demand delivery of the gold bars; in the alternative, they sought damages for breach of an ancillary obligation under the sales contract and under Article 82 of the GDPR. In the claimants’ view, the invoice should only have been transmitted in encrypted form.

The Regional Court dismissed not only the claim for delivery but also the claims for damages asserted. A contractual claim for damages was ruled out simply because there was no agreement between the parties on the use of end-to-end encryption. Nor, in the court’s view, was there a claim for damages under data protection law arising from Article 82 of the GDPR. Firstly, the scope of application of the GDPR did not apply, as no personal data relating to the claimants had been processed. Only the defendant’s bank details, which did not relate to a natural person, had been altered and thus processed. In the court’s view, the protective purpose of Article 82 (1) of the GDPR was therefore not affected in this case. Furthermore, no general obligation to use end-to-end encryption could be inferred from the GDPR. It is true that, under Article 24 of the GDPR, the controller must implement appropriate security measures. However, when weighing up the relevant factors, the security expectations of the business community must also be taken into account. End-to-end encryption is not generally expected in business transactions due to the associated effort involved and has not become widely established.

The Regional Court of Karlsruhe has thus reached a different conclusion to the Higher Regional Court of Schleswig, which, in a separate case, had held that there was an obligation to use end-to-end encryption. We had already discussed that ruling in the main topic of our newsletter issued in June last year.

Lower Saxony Data Protection Commissioner publishes FAQs on the AI Regulation

The State Data Protection Commissioner for Lower Saxony has published FAQs on artificial intelligence (FAQs on Artificial Intelligence, as at March 2026). These FAQs highlight the legal aspects that must be taken into account when using AI. In addition to data protection requirements, the FAQs also address the provisions of the AI Regulation.

Among other things, it answers fundamental questions, such as those concerning the risk levels set out in the AI Regulation for AI systems or the distinction between providers and operators of AI systems. The FAQ also contains practical guidance, for example on how to prevent data published on websites from being used to train AI models, or how to ensure that the use of AI does not breach the ban on automated decision-making.

Withdrawal from Online Contracts

Since June 19, 2026, businesses that conclude distance contracts with consumers via websites, online forms, booking pages or apps must provide a digital withdrawal function (‘Withdrawal Button’, Section 356a of the German Civil Code (BGB)). The aim of the new regulation is to make it just as easy for consumers to withdraw from an online contract as it is to conclude one.

The key requirements include, amongst others:

  • Clearly visible labelling of the function
  • Ease of location and accessibility on the online user interface
  • Constant availability throughout the withdrawal period
  • Implementation of a two-step procedure:
    • Collection or confirmation of the information required for withdrawal
    • Submission via a clearly labelled confirmation function
  • Immediate transmission of an acknowledgement of receipt, including the content of the withdrawal and the date and time, via the communication channel chosen by the consumer.

In addition to the technical implementation, the withdrawal policy must also be amended. Consumers must be informed of the existence and location of the withdrawal function. If the withdrawal function is not provided correctly, the standard withdrawal period is extended from 14 days to 12 months and 14 days. Furthermore, fines and warnings may be imposed in the future. Companies that conclude online contracts with consumers therefore need to take action to implement the new requirements in good time. Where data processing in connection with the new cancellation button goes beyond existing functions or serves new purposes, the privacy policies on websites may also need to be amended. The Brandi Team will be happy to advise and assist with the implementation of the new requirements as required.

Italy

€ 12.5 Million Fine imposed on the Italian Postal Service for App Monitoring

On April 17, 2026, the Italian Data Protection Authority (GPDP) imposed fines totalling 12,501,000 euros on the companies Poste Italiane S.p.A. and PostePay S.p.A. This was due to the use, in breach of data protection regulations, of a security solution in apps operated by the companies within the group, which, in particular, processed information relating to apps installed on or running on users’ devices (press release of 17.04.2026).

Users – customers of the postal companies – were asked to grant access to their device’s usage data in order to detect potentially harmful software. If permission was not granted, restrictions on app usage were threatened. The GPDP regarded this as a significant intrusion, as installed or running apps could potentially reveal information about sensitive aspects of users’ lives, such as health, finances, political or religious beliefs, or sexual orientation. 

The authority did not accept the reference to requirements concerning the security of payment services and fraud prevention as sufficient justification. In the GPDP’s view, there was no legal basis under Article 6 of the GDPR for the specific processing in question; furthermore, it criticised breaches of transparency obligations, ‘privacy by design’, the obligation to carry out a data protection impact assessment, as well as requirements relating to data processing on behalf of others, security and storage limits. 

Croatia

Fine of € 100,000 for Lack of Staff Training

On February 19, 2026, the Croatian Data Protection Authority (AZOP) imposed a fine of 100,000 euros on a property agency because, amongst other things, staff had received insufficient training in the handling of personal data. No harm to data subjects was established (press release of 19.02.2026).

In the authority’s view, the estate agency had failed to implement adequate training and supervisory measures for its staff and, consequently, had not put in place sufficient technical and organisational measures in accordance with Article 32 (4) of the GDPR. Under this provision, controllers must ensure that their staff, who have access to personal data, process it only on the controller’s instructions. Although the estate agency had carried out staff training, this was done irregularly and to an insufficient extent.

Furthermore, 11,887 agreements containing customers’ personal data from the years 2010 to 2019 were stored in the company’s archive, even though the purpose of processing no longer applied; the authority regarded this as a breach of Article 5 (1) (e) of the GDPR. In connection with these agreements, 914 copies of identity documents and bank cards were retained without a legal basis under Article 6 (1) of the GDPR. The AZOP regarded the managing director’s statement that no copies of bank cards were made as indicative of a lack of oversight over the estate agency’s processing activities, as well as insufficient awareness and a lack of training among staff.

France

Fine of € 5 Million for inadequate Protection of Health Data

Due to inadequate protection of health data, the French data protection authority (CNIL) has imposed a fine of five million euros on IQVIA OPERATIONS FRANCE (press release of 28.05.2026).

The company conducts studies focusing on specific diseases or treatment methods, for which it draws on two health databases. The health databases were authorised by the CNIL and subject to several conditions designed to minimise the data protection risks for data subjects and to safeguard their rights. Following several complaints, the CNIL carried out investigations and concluded that the personal data had only been pseudonymised – and not anonymised. As each patient had been assigned an individual identifier, it was possible to trace their medical history. Overall, the CNIL deemed the risk that data subjects could be identified to be too high.

Given the sensitive nature of the health data and the fact that tens of millions of individuals were affected, the fine was set at 5,000,000 euros. Furthermore, the authority ordered that remedial measures must be taken within six months, with a fine of 10,000 euros for each day of delay.