[Translate to English:] Laptop
Newsletter data protection

Newsletter data protection 08/2026

In this month’s newsletter, we report on a ruling by the ECJ concerning the requirements for data processing for journalistic purposes. The legal dispute arose in the context of public disclosure of criminal convictions. In addition, the BGH considered a claim for damages arising from the transfer of personal data to SCHUFA and recognised non-material damage. The Higher Regional Court of Frankfurt am Main ruled on whether AI-generated photomontages also fall within the scope of the right to one’s own image.

On June 29, 2026, the US Supreme Court handed down its judgement in the case of Trump v. Slaughter (2026) concerning the President’s power to dismiss FTC commissioners. In our special feature, we explain the potential data protection implications of the judgement and the issues surrounding the transfer of personal data, particularly to the US. As well as looking at the development of this transatlantic relationship to date, we discuss the extent to which the current legal situation might change following the ruling.

If you have any feedback on this newsletter or any questions regarding its topics, please email us at datenschutz@brandi.net. You can also find further contact details on our website.

Dr. Sebastian Meyer and the BRANDI Data Protection Team

Dr. Sebastian Meyer, LL.M.

Lawyer and Notary in and for Bielefeld
Certified Specialized Attorney in information technology law (IT-Recht)
Data Protection Auditor (TÜV)

Information and contact

Topic of the month / August 2026

Data Transfers to the US – Past and Present Developments

In day-to-day business operations, the use of a wide range of online applications involves the transfer of personal data to other countries. This regularly includes the integration of cloud and email services, the use of analytics tools, or the use of a business partner’s systems. It is not uncommon for companies to use external service providers based in the United States of America (USA) or to collaborate with other group companies based there. Data protection in the USA is less strictly regulated than in the European Union (EU). Instead of a uniform federal data protection law, there are only state- or sector-specific laws governing the protection of consumer data. It is important for European companies to know what additional security measures must be taken when transferring data to the USA and what implications the recent US Supreme Court ruling in the case of Trump v. Slaughter (2026) has for data protection law. 

Other topics in this newsletter

ECJ

No Journalistic Privilege — Database Must Comply with GDPR Requirements

In a judgment of July 9, 2026, the European Court of Justice (ECJ) examined in detail the requirements for data processing for journalistic purposes within the meaning of Art. 85 (2) of the GDPR and ruled that the public disclosure of criminal convictions can only be regarded as such if its purpose is to disseminate information or opinions to the public in accordance with editorial principles and following verification (ECJ, decision dated 09.07.2026 – Case No. C-199/24). 

In the main proceedings, the operator of a Swedish database – which, amongst other things, enables searches for individuals and companies against whom criminal proceedings had been brought before a Swedish court – was the defendant. The claimant had previously been convicted of a criminal offence, and this conviction was accessible via the database. Although the claimant had submitted a request for the erasure of his personal data, the conviction remained accessible in the database until it was deleted on the basis of an internal data retention policy. The claimant subsequently claimed damages for a breach of the GDPR.

In response to the question referred for a preliminary ruling concerning the interpretation of Art. 85 (1) and (2) of the GDPR, which, under an enabling clause, grant Member States the right to adopt derogations in favour of processing for, amongst other things, journalistic purposes (subsection 2), and which contain the obligation to reconcile the requirements of the GDPR with the right to freedom of expression (subsection 1), the ECJ has now ruled: It is clear from the wording of the provisions that the permissibility of exceptions set out in subsection 2 applies only to the purposes specified therein, whilst subsection 1 allows Member States to adopt regulations without this resulting in the adoption of exceptions or derogations from the GDPR. 

Furthermore, whilst the concept of ‘journalistic purposes’ must be interpreted broadly in order to give sufficient effect to the right to freedom of expression and freedom of information, a distinction must be made between journalistic and other forms of expression when publishing information and opinions. Journalism therefore presupposes that editorial processing or decision-making takes place, that factual claims are verified, and that the activity is subject to the general professional and ethical standards of the journalistic profession. Publication on the internet or the provision of such content for a fee does not preclude this; however, the provision of public documents relating to criminal convictions clearly requires neither editorial revision nor adaptation. The GDPR therefore applies.

EGC

Classification of Apple Under the DMA Is Lawful

On July 8, 2026, the General Court of the European Union (EGC) dismissed several actions for annulment brought by Apple in connection with the classification of Apple services as gatekeepers under Art. 3 of the Digital Markets Act (DMA) (EGC, decision dated 08.07.2026 – Case No. T-1079/23, T-1080/23 and T-214/24). 

Art. 3 of the Digital Markets Act provides that, subject to certain criteria and following classification based on thresholds, key platform services are to be designated as so-called gatekeepers by the Commission. This status as a gatekeeper then gives rise to specific obligations for the services. Apple was designated as a gatekeeper by the Commission by decision of September 5, 2023 in respect of the iOS App Store, the iOS operating system, Safari and iMessage, whereupon the company brought an action for annulment against that decision and all other decisions of the Commission in the proceedings.

Among other things, Apple criticised the classification of the app stores, which are differentiated by device (iOS App Store, iPad App Store, macOS App Store, etc.), as a single service. The court, however, concluded that an app store constitutes an online intermediation service within the meaning of the DMA and that this classification is independent of the device and operating system on which the service is offered. Furthermore, the court held that arguments against the classification of iMessage as a number-independent interpersonal communications service were unfounded, as this classification does not give rise to any obligations or legal consequences for the company and is therefore no longer open to challenge in the action for annulment.

Federal Court of Justice

Unjustified SCHUFA Report May Give Rise to Non-material Damage

In a judgement dated May 12, 2026, the Federal Court of Justice (BGH) ruled that the unlawful transmission of personal data to SCHUFA in relation to an allegedly outstanding debt may give rise to non-material damage (BGH, decision dated 12.05.2026 – Ref.: VI ZR 275/24).

The i.-Energie GmbH terminated its contract with a customer – the claimant – on the grounds of late payment. After the claimant rejected the final invoice for 529.16 euros as excessive and failed to pay it, a debt collection agency commissioned by the electricity supplier arranged two negative entries relating to the debt to be made with SCHUFA Holding AG, which adversely affected the claimant’s credit score.

The BGH ruled that there was no legitimate interest under Article 6 (1) (f) of the GDPR in the transfer of the claimant’s personal data. Credit reference agencies generally serve the interests of credit institutions and the commercial sector in protecting against fraud, as well as the borrower’s interest in not exceeding their financial capacity. However, the reports submitted by the debt collection agency related to a claim that had not been established by a court order, was disputed and for which the amount had not been plausibly substantiated. In the court’s view, the reports were therefore not suitable for enabling a reliable assessment of creditworthiness and were not conducive to the intended purposes of processing.

The BGH then found that the negative entries had damaged the claimant’s economic reputation and constituted non-material damage. Subsequently, several attempts to enter into contracts had failed. The claim for damages under Article 82 (1) of the GDPR is not subject to a materiality threshold. It is therefore not necessary for the concerns of potential contractual partners to be based solely or predominantly on the SCHUFA entries. Furthermore, the risk that the data may be disclosed to an indefinite number of third parties – through SCHUFA enquiries – is sufficient to constitute non-material damage.

Nuremberg Social Court

No Compensation for a Cyberattack Where Security Measures Were Objectively Sufficient

In its judgement of June 10, 2026, the Nuremberg Social Court ruled that there is neither fault nor a claim for damages if a company has taken sufficient technical and organisational measures (Nuremberg Social Court, decision dated 10.06.2026 – Ref.: S 5 SF 65/24 DS).

The claimant took part in an app bonus scheme run by the defendant health insurance provider, BARMER. Following a cyberattack, an unknown and unpatched security vulnerability in the app bonus programme was exploited, resulting in the plaintiff’s name, health insurance number, premium payment and IBAN being obtained. The IBAN in question was not the plaintiff’s, but that of her mother. Health data was not affected. 

In its judgement, the Social Court clarified that the GDPR does not require absolute protection of personal data, but merely the technical and organisational measures necessary to ensure a level of protection appropriate to the risk. A successful cyberattack does not prove the absence of an adequate level of protection. The court did not find a culpable breach of the GDPR in the present case. Nor was there any compensable non-material damage within the meaning of Art. 82 of the GDPR. A well-founded fear and the negative consequences would have to be duly proven.

Frankfurt am Main Higher Regional Court

The Right to One’s Own Image Also Covers AI-generated Photomontages

In a ruling dated June 16, 2026, the Higher Regional Court of Frankfurt am Main clarified that AI-generated photomontages are also covered by the right to one’s own image (Higher Regional Court of Frankfurt am Main, court order dated 16.06.2026 – Ref.: 16 U 21/26). When publishing edited images and AI-generated photomontages, Sections 22 and 23 of the German Artistic Copyright Act (KUG) must therefore be observed. In the court’s view, it is not decisive whether an original photograph of the person concerned was used. Rather, what is decisive is the recognisable reference to the person and the deceptively lifelike resemblance of the depiction.

There had previously been legal disputes between the defendant, a Vietnamese human rights and democracy activist, and the claimant, a Vietnamese entrepreneur and managing director of a corporate group. In the context of these disputes, the defendant used AI-generated photomontages to satirise the claimant. However, in the opinion of the Higher Regional Court, the depictions lacked a sufficient factual connection to the previous disputes. Of particular significance was the highly disparaging and mocking effect of the photomontages within the claimant’s cultural context.

Although the Frankfurt Higher Regional Court’s decision focuses primarily on the right to one’s own image, the case also highlights the preventive function of data protection law. The creation and publication of AI-generated depictions that can be attributed to a real person generally constitutes the processing of personal data. An early assessment of the necessity, proportionality and legal basis of the processing could have reduced the risk of a subsequent infringement of the right to privacy. 

The Federal Government’s Reform Plans

Data protection law is also mentioned in the reform package ‘for economic recovery and employment’ presented by the Federal Government at the beginning of July (published on 03.07.2026).

The plan is to simplify national data protection law, for example by consolidating supervisory structures under the Federal Data Protection Commissioner (BfDI) and reducing the number of in-house data protection officers in small and medium-sized enterprises. In addition, a unified data code is to be created, as was already announced in the coalition agreement (Coalition Agreement 2025, marg. no. 2241 et seq.). It is hoped that a coherent regulatory framework will harmonise and simplify data protection, although it remains to be seen to what extent this objective can be achieved. Key regulations in the digital and data protection sectors originate at European level, with increasing recourse being made to directly applicable regulations, which leave Member States scope for action only where this is expressly granted.

The Federal Government also wishes to take action at European level to achieve an adjustment to the scope of the GDPR with regard to small and medium-sized enterprises and non-commercial organisations.

Another point in the reform plan concerns the amendment of the Freedom of Information Act (IFG). The IFG grants a low-threshold right of access to official information held by federal authorities. In future, this right is to be restricted to natural persons who have a legitimate interest in the information. The announced amendment has met with widespread criticism on the grounds that it restricts press coverage and excludes NGOs (see, for example, a statement by FragDenStaata press release from the DJV, and a statement by Abgeordnetenwatch). 

Ireland

Fine of € 300,000 for GDPR Breaches Relating to Data Security, Data Processing on Behalf of Others and Information Obligations

On June 15, 2026, the Irish Data Protection Commission (DPC) imposed a fine of 300,000 euros on the Midlands Regional Hospital Tullamore for numerous breaches of the GDPR.

Following a ransomware attack on November 14, 2018 on the hospital’s laboratory information system, which stored laboratory results and diagnoses for around 84,000 patients, the DPC investigated the hospital’s technical and organisational measures.

In the course of this investigation, the DPC identified several security gaps. Firstly, insufficient technical and organisational measures had been implemented to protect the integrity and confidentiality of patient data. Although data processing agreements had been concluded, these did not sufficiently oblige the hospital’s data processors to implement protective measures in accordance with the GDPR. Furthermore, at the time of the attack, there was no complete record of processing activities in accordance with Article 30 of the GDPR, and the data subjects were not informed of the attack. Finally, the risk associated with the processing of patient data was not taken into account when selecting the technical and organisational measures. 

Spain

€ 500,000 Fine Imposed on FC Barcelona for Failing to Carry Out a Data Protection Impact Assessment for Biometric Data

On July 1, 2026, the Spanish Data Protection Authority (AEPD) imposed a fine of 500,000 euros on the Spanish Futbol Club Barcelona (FCB) for collecting biometric data without first carrying out a data protection impact assessment (press release of 01.07.2026).

As part of an update to its membership register in 2023, FCB collected biometric data in accordance with Art. 9 (1) of the GDPR, including facial and voice recordings.

According to the club, a risk analysis it carried out had concluded that there was no high risk. After all, the recordings were not stored but were merely compared with the photo on the membership card. After several members lodged complaints with the AEPD, the data protection authority launched an investigation and reached a different conclusion. The register comprises approximately 143,000 members, which means that the authentication procedure involves the processing of biometric data on a large scale. Consequently, a data protection impact assessment under Article 35 of the GDPR should have been carried out in advance; the internal risk analysis was not sufficient.

Spain

Fine of € 1.05 Million Imposed on Vodafone for Inadequate Identity Verification

On June 17, 2026, the AEPD imposed a fine of 1,050,000 euros on Vodafone for disclosing customer data to a third party due to inadequate identity verification (press release of 17.06.2026).

After a third party contacted Vodafone’s customer service and answered their security questions, they received a copy of an invoice containing the customer’s personal data – including her name, address and ID number – at their email address. In the AEPD’s view, the use of security questions as an authentication procedure was insufficient, for which a fine of 750,000 euros was imposed.

Furthermore, a second mobile phone subscription had been registered in the customer’s name. The customer had never provided this personal data herself, which is why the processing was not based on a legal basis under Art. 6 of the GDPR. In this regard, the AEPD imposed a fine of 300,000 euros.