
Dr. Sebastian Meyer, LL.M.
Lawyer and Notary in and for Bielefeld
Certified Specialized Attorney in information technology law (IT-Recht)
Data Protection Auditor (TÜV)
![[Translate to English:] Laptop](/fileadmin/_processed_/c/1/csm_referendare_guetersloh_f658b7d1e5.jpg)
Newsletter data protection 09/2026
last month brought some interesting developments regarding the AI Regulation (AI-Act). In parallel with the entry into force of the new transparency obligations for labelling AI systems, the European Commission, together with the national supervisory authorities, has begun to enforce the AI Regulation. In addition, two administrative courts have addressed the validity of consents. The Düsseldorf Administrative Court dealt with the requirements for evidence and documentation, whilst the Berlin Administrative Court dealt with the specificity of consent. After the ECJ had referred a case concerning the mistaken sending of a Xing message back to the BGH, the latter has now ruled that the claimant is not entitled to an injunction due to the absence of a request for deletion and the lack of a risk of repetition.
The new Pay Transparency Directive (ETRL) should have been implemented by June 7, 2026 through a reform of the German Pay Transparency Act. The disclosure of information on pay for the same or equivalent work may, in some cases, be traced back to specific employees and therefore gives rise to a conflict with the GDPR. In our current main topic, we examine how the GDPR and the ETRL, as European legal acts, are to be interpreted and applied in harmony with one another.
If you have any feedback on this newsletter or any questions regarding its topics, please email us at datenschutz@brandi.net. You can also find further contact details on our website.
Dr. Sebastian Meyer and the BRANDI Data Protection Team

Dr. Sebastian Meyer, LL.M.
Lawyer and Notary in and for Bielefeld
Certified Specialized Attorney in information technology law (IT-Recht)
Data Protection Auditor (TÜV)
Topic of the month / September 2026
How Pay Transparency and Data Protection Can Be Implemented Together
The principle of equality under Art. 3 (2) of the Basic Law (GG) requires the state to promote the effective enforcement of equal rights for women and men and to work towards the elimination of existing disadvantages. This includes equal pay. On June 6, 2023, a Pay Transparency Directive was adopted, which should already have been transposed into national law but has yet to be implemented in Germany. The aim of pay transparency is to enforce the requirement of equal pay for women and men for the same or equivalent work. However, if information about a specific person’s salary can be traced back to that individual, this also brings the scope of the GDPR into play, which requires the protection of personal data. Employers are then faced with the task of disclosing information about pay for the same or equivalent work whilst at the same time protecting their employees’ salary data. In this main topic, we explain how pay transparency and data protection can be implemented together.
A Doping Offence Without Specifying the Active Substance Does Not Constitute Health Data
In its judgement of July 14, 2026, the European Court of Justice (ECJ) ruled that the online publication of the names, suspension periods and reasons relating to professional sportspeople following breaches of anti-doping regulations is, in principle, compatible with the GDPR. (ECJ, decision dated 14.07.2026 – Ref. C-474/24).
The legal dispute arose from the suspension of four Austrian athletes by the Austrian Anti-Doping Legal Commission (ÖADR). The ÖADR and the National Anti-Doping Agency Austria GmbH (NADA Austria) then published a notice on their websites, in accordance with Austrian anti-doping regulations, regarding the suspensions imposed – including the athletes’ names, the sport, the breach of anti-doping rules and the sanction. Following an unsuccessful request for erasure, the athletes lodged a complaint with the Austrian Data Protection Authority (DSB). After the complaint was rejected by the DSB, the athletes brought an action before the Federal Administrative Court (Austria), which referred the matter to the ECJ in the subsequent proceedings.
According to the case law of the ECJ, for data to be classified as health data under Art. 9 (1) of the GDPR, it is sufficient if, on the basis of the available data, conclusions can be drawn – through mental combination or deduction – regarding the data subject’s past, present or future physical or mental state of health. In the Court’s view, such an inference is only possible if the name or category of the prohibited substance or method in question is made public.
Furthermore, the Court pointed out that the publication must comply with the Austrian anti-doping regulations set out in Section 5 (6) (4) and Section 21 (3) of the ADBG and is therefore justified under Art. 6 (1) (c) of the GDPR. It also held that the fight against doping is in the public interest and promotes the European objective of fairness in sporting competitions. Consequently, the publication was proportionate.

Non-pecuniary Damages and a Claim for an Injunction Following the Mistaken Sending of a Message
In a judgement of June 23, 2026, the Federal Court of Justice (BGH) ruled that the recipient of an incorrectly sent email is entitled to compensation under the GDPR, but not to an injunction (BGH, decision dated 23.06.2026 – Ref. VI ZR 97/22).
The claimant was involved in a recruitment process with the defendant, during which, in the course of salary negotiations, an email intended for the claimant was sent to third parties. The claimant subsequently sought an injunction preventing any further dissemination of his personal data of this kind, as well as compensation for non-pecuniary damage suffered as a result of the disclosure of the data, in particular due to the publicised and humiliating defeat in the salary negotiations.
The BGH had in the meantime stayed the proceedings and referred a number of questions to the ECJ, in particular regarding a possible right to an injunction under EU law, which the ECJ, however, ruled out (as reported in Newsletter 10/2025). Referring to the case law of the ECJ, the BGH now points out that, in the event that the claimant does not simultaneously request the erasure of his data, a preventative claim for an injunction would not arise under the GDPR, but only under national law. However, for such a claim based on an infringement of the claimant’s general right of personality – in its manifestation as the right to informational self-determination, by analogy with Section 1004 (1), second sentence, Section 823 (1) of the German Civil Code (BGB) in conjunction with Art. 1 (1) and Art. 2 (1) of the GG, there is, however, no risk of repetition of such infringements once the application process has been concluded.
Contrary to the view of the Court of Appeal, however, the BGH upheld the claimant’s claim for damages under Art. 82 (1) of the GDPR. The defendant’s erroneous transmission of the data was undisputedly unlawful under Art. 6 (1) of the GDPR. In accordance with the now extensive case law of the ECJ on the requirements for (non-pecuniary) damage, the claimant had suffered non-pecuniary damage at the latest at the point in time when the unauthorised recipient of the data contacted the claimant with enquiries regarding his application. This constituted a misuse of the data, in which the loss of control resulting from the erroneous transmission became a reality. Furthermore, the claimant’s fear that third parties operating in the same sector might use the data against him and exploit it as a competitive advantage was confirmed.

Invalidity of Consent in the Absence of Adequate Proof
In its judgement of July 27, 2026, the Düsseldorf Administrative Court ruled that an IP address with a timestamp alone is not sufficient proof of consent and consequently means that the consent must be regarded as not having been (validly) given (Düsseldorf Administrative Court, decision dated 27.07.2026 – Ref. 29 K 9714/24).
Following the receipt of unsolicited promotional emails, an individual lodged a complaint, stating that they had never given their consent to the sender – an online marketing company. The company was unable to produce a declaration of consent or a confirmation email, but could only provide an IP address with a timestamp. According to the company’s own statements, however, it had implemented a double opt-in procedure, whereby, following a newsletter subscription, all confirmation emails were sent in BCC to a dedicated email address set up by the company for this purpose and stored there.
If the processing is based on consent, the controller must, pursuant to Art. 7 (1) of the GDPR, be able to demonstrate that the data subject has consented to the processing of their personal data. The burden of proof and presentation therefore lies with the controller. The Administrative Court concluded that the company had failed to provide this evidence. The IP address is assigned to a technical device and provides no information about the user who was active on the device at the time in question. In the absence of a link between the email address and the IP address, the latter is therefore not suitable as evidence. Furthermore, the company’s description of its double opt-in procedure suggests that there is in fact no confirmation email.

Warning for Insufficiently Specific Consent to Data Disclosure is Lawful
In its judgement of May 28, 2026, the Berlin Administrative Court ruled that the transfer of personal data to third parties without sufficiently specific consent contravenes the GDPR and justifies a data protection warning (Berlin Administrative Court, decision dated 28.05.2026 – Ref. 42 K 98/26).
The proceedings were based on a complaint by a prospective customer who had enquired about a photovoltaic system from a solar company. The company offered to pass on his contact details to partner firms that could carry out the installation. Although the prospective customer had objected to the data transfer and requested that his data be deleted, his details were nevertheless passed on to a regional installation firm, which subsequently contacted him by telephone and email.
The competent data protection supervisory authority subsequently issued a warning pursuant to Art. 58 (2) (b) of the GDPR.
The Berlin Administrative Court confirmed the lawfulness of this measure. The data transfer could not be based on either valid consent under Art. 6 (1) (a) of the GDPR or legitimate interests under Art. 6 (1) (f) of the GDPR. Under Art. 4 (11) of the GDPR, consent must be given for the specific case and in an informed manner. This requirement is not met if data subjects cannot sufficiently ascertain, prior to giving their consent, to which companies their data will be disclosed. The mere statement that a transfer may take place to ‘regional installation companies’ is not sufficient for this purpose.
In its reasoning, the court refers in particular to the principle of transparency set out in Art. 5 (1) (a) of the GDPR. According to this, the data subject must be able to understand how their personal data is being processed. If the recipients have already been determined or can be identified in more detail on the basis of available information, they must, where possible, be specifically named or, at the very least, sufficiently narrowed down.
In the court’s view, the reliance on legitimate interests also failed. The claimant had not set out the interests it was pursuing with sufficient transparency. Furthermore, the data subject could not reasonably have expected their data to be passed on to a tradesman’s business unknown to them.
Finally, the court also upheld the decision to issue a warning as a remedial measure. Where a breach of the GDPR has been established, regulatory intervention is generally required. The warning constitutes the mildest remedial measure provided for in Art. 58 (2) of the GDPR and is proportionate even in the case of first-time breaches.

Enforcement of the AI Regulation and New Transparency Obligations
In August 2026, the European Commission, together with the national authorities, began enforcing the European Regulation on Artificial Intelligence (AI-Act) (press release of 31.07.2026). The enforcement measures initially concern the provisions applicable to providers of general-purpose AI (GPAI) models.
Furthermore, the phased implementation of the Regulation has reached the next stage. Since last month, companies have been obliged to disclose whether content has been created or modified by an AI system, or whether users are interacting with an AI – for example, a chatbot. Texts must be labelled if they are intended to inform the public about matters of public interest. However, this does not apply if a human has reviewed the texts and assumes editorial responsibility. The labelling requirement also covers, in particular, deepfakes – that is, image, video and audio material that could appear genuine or misleading. In most cases, the new transparency requirements can be implemented through simple and clear labelling and are intended to reduce deception and manipulation.

Fine of € 2,000,000 for the Sale of Personal Data
On July 27, 2026, the Italian Data Protection Authority (GPDP) imposed a fine of two million euros on Lusha Systems Inc. for the sale of personal data (press release of 14.05.2026).
The company, based in the United States of America, operates a platform on which personal data – including job titles, email addresses and telephone numbers – can be accessed for a fee.
The GDPD confirmed that the GDPR applies despite the company being based in a third country, as personal data from Europe is collected, updated and verified. Furthermore, the data processing was not legitimised by the legitimate interest under Art. 6 (1) (f) of the GDPR. The information available regarding the data processing was also difficult for data subjects to access. The authority issued a ban on the processing of personal data relating to individuals residing in Italy and ordered the deletion of the data.

€ 158,000 Fine Imposed on Character.AI for Failing to Protect Minors
On July 9, 2026, the GPDP imposed a fine of 158,000 euros on Character Technologies Inc. for failing to protect minors in the operation of the chatbot ‘Character.AI’ (press release of 09.07.2026).
The US company Character Technologies Inc. operates the chatbot ‘Character.AI’, which allows users to create virtual characters and communicate with them.
The authority deemed the associated privacy policy to be incomplete, and neither a data protection impact assessment nor the appointment of a representative in the European Union had been carried out in a timely manner. In view of the risks associated with the use of generative AI by minors, the GPDP considered that insufficient safeguards had been implemented to verify age. The authority called on the company to put in place safeguards to prevent minors – whose accounts had been blocked – from re-registering, and to set the default privacy settings for minors’ accounts to ‘Private’. The company must now provide evidence that these measures have been implemented within 120 days.

Fine of € 1,715,600 for Inadequate Security Checks
On May 14, 2026, the Italian Data Protection Authority (GPDP) imposed a fine of 1,715,600 euros on Wind Tre S.p.A. for inadequate security checks (press release of 14.05.2026).
Staff at two separate sales outlets granted hackers access to the company’s systems after the hackers posed as technical support staff. This enabled the hackers to extract personal data from over 365,000 customers. In addition to contact details, this also included sensitive financial data in some cases.
During its investigations, the GPDP identified inadequate access authorisations and digital certificates. Furthermore, the company’s own security checks had mistakenly failed to identify any vulnerabilities. In calculating the fine, the timely reporting of the data protection incident, the protective measures taken subsequently and the company’s cooperation were taken into account as mitigating factors.
