
Dr. Sebastian Meyer, LL.M.
Lawyer and Notary in and for Bielefeld
Certified Specialized Attorney in information technology law (IT-Recht)
Data Protection Auditor (TÜV)
![[Translate to English:] Laptop](/fileadmin/_processed_/c/1/csm_referendare_guetersloh_f658b7d1e5.jpg)
Newsletter data protection 10/2026
In this month’s newsletter, we report on an interesting ruling by the Federal Court of Justice (BGH) concerning the relationship between the European General Data Protection Regulation and the national regulations of the Member States. The court had to determine whether a claim for an injunction could also arise from national regulations, or whether the General Data Protection Regulation contains exhaustive provisions in this regard. Furthermore, the Osnabrück Administrative Court addressed the issue of excessive requests for information and ruled that certain information obligations cannot be dispensed.
It is now almost impossible to imagine life without artificial intelligence, both in everyday life and in the workplace. Only 26 % of companies provided their employees with access to AI systems last year. It is therefore not uncommon for employees to resort to unauthorised AI systems – so-called shadow AI – to speed up their work and improve efficiency. Last year, 43 % of employees stated that they had disclosed sensitive business information whilst using shadow AI. However, various measures can help mitigate the resulting risk of data breaches and fines.
If you have any feedback on this newsletter or any questions regarding its topics, please email us at datenschutz@brandi.net. You can also find further contact details on our website.
Dr. Sebastian Meyer and the BRANDI Data Protection Team

Dr. Sebastian Meyer, LL.M.
Lawyer and Notary in and for Bielefeld
Certified Specialized Attorney in information technology law (IT-Recht)
Data Protection Auditor (TÜV)
Topic of the month / October 2026
Shadow AI

Artificial intelligence (AI) can help to speed up business processes and make them more effective. According to a survey1 commissioned by the digital association Bitkom, a quarter (26 %) of companies provided their staff with access to AI systems last year, whilst other companies are planning to introduce AI systems. The figures show that the need to use AI systems is growing not only in everyday life but also in the workplace. Where companies have not introduced AI systems, or where existing ones are regarded by staff as inadequate or slow, the risk of shadow AI increases. This refers to the unauthorised use of AI systems or AI tools by staff. In other words, there is a lack of authorisation or oversight by the IT department or management. In a survey2 conducted by Cybsafe Ltd. in 2025, just under half (43 %) of employees admitted to having already shared sensitive business information using AI tools without their employers authorisation. Companies then find themselves facing various risks, such as data breaches, data protection sanctions or reputational damage.
1 Bitkom e.V., press release dated 21.10.2025
2 Cybsafe Ltd., The Annual Cybersecurity Attitudes and Behaviors Report 2025-2026
A Claim for an Injunction May Arise under National Law
In a judgement of July 21, 2026, the Federal Court of Justice (BGH) addressed the question of whether, in the case of data protection breaches, a claim for an injunction may arise under national law or whether the GDPR contains an exhaustive provision in this regard. The Court ruled that a claim for an injunction may, in principle, arise under national law (BGH, decision dated 21.07.2026 – Ref. VI ZR 144/23).
The proceedings were based on a claim brought by a user against the operator of an online shop. The operator used third-party services on its website, whereby the data was stored not on the defendant’s servers but on the servers of the respective service providers. Consequently, when the website was accessed, the user’s IP address, amongst other things, was transmitted to the third-party providers. The claimant sought an injunction against such data transmission without his consent.
The Court of Appeal dismissed the claim, essentially on the grounds that no such right to an injunction arose from the GDPR and that it was not possible to rely on grounds for a claim under national law due to the GDPR’s primacy of application and its exhaustive nature. The claimant lodged an appeal against this judgement.
The BGH did not share this view. Referring to the case law of the European Court of Justice (ECJ) that had since been handed down, it stated that, whilst the GDPR itself does not provide for a preventive claim for an injunction, the Regulation does not prevent Member States from providing for such legal remedies in their national legal systems. Such claims do not undermine the objectives of the GDPR; on the contrary, they may even strengthen its practical effectiveness and promote the high level of protection it aims to achieve. A claim for an injunction could arise, in particular, by analogy from Section 1004 (1) of the German Civil Code (BGB), or from Section 823 (1) BGB in conjunction with Art. 1 (1) and Art. 2 (1) of the German Basic Law (GG). However, the BGH did not conclusively rule on whether the claimant is in fact entitled to a claim for an injunction in this specific case, but referred the matter back to the Higher Regional Court (OLG) for a new decision.

Classification of Microsoft under the DSA?
On September 2, 2026, the General Court of the European Union (EuG) upheld the European Commission’s decision not to designate Microsoft as a ‘gatekeeper’ for the Microsoft Edge internet browser, on the grounds that Microsoft Edge was not classified as a significant ‘gateway’ (EGC, decision dated 02.09.2026 – Ref. T-357/24).
Under Art. 3 of the Digital Markets Act (DMA), the Commission may designate companies that provide core platform services and meet certain thresholds as ‘gatekeepers’. For this to apply, the core platform service must serve as a key gateway for business users to reach end users. Designation as a gatekeeper entails specific obligations to ensure the contestability and fairness of the relevant markets. In a decision dated February 12, 2024, the Commission found that, despite meeting the thresholds, Microsoft Edge was not a key gateway and decided not to designate Microsoft as a gatekeeper. This decision was challenged in court by Opera Norway AS – the publisher of the Opera browser.
The General Court ultimately found the Commission’s decision to be free of error. The number of users was a relevant factor in assessing whether Microsoft Edge enables commercial users to reach their end users. The Commission was therefore entitled to rely on the low number of users compared with other browsers in its decision. Furthermore, the web browser is based on the Blink browser engine and does not allow Microsoft to independently control key aspects of the service. According to the Commission’s findings, its integration into the Microsoft ecosystem – including its pre-installation on Windows and other promotional measures – is not sufficient.

Credit Score without Payment History
In a judgement of August 12, 2026, the Supreme Court of Austria ruled that it is possible to determine a credit score without information on previous payment behaviour. However, personal data originally collected for marketing purposes may not be further processed for credit reference purposes under Art. 6 (4) of the GDPR (Austrian Supreme Court, decision dated 12.08.2026 – Ref. OGH 6 Ob 147/25y).
The action was brought against a credit reference agency that had purchased address data – including first name, surname, address and date of birth – from a directory publisher. The directory publisher also operated a direct marketing business and collected the data in the course of this activity. The credit reference agency used the address data to identify the claimants and provide information on their creditworthiness. In doing so, the defendant calculated a credit score based solely on the address data and thus without any data on previous payment behaviour.
Under the principle of purpose limitation, personal data may not be further processed in a manner incompatible with the purpose originally specified. Where personal data is processed for a purpose other than that for which it was originally collected, the strict conditions set out in Art. 6 (4) of the GDPR must be complied with. The Supreme Court assessed the credit reference agency’s use of the address data as a change of purpose, as the data originally collected for marketing purposes was now being processed for identification, scoring and the provision of information. In the Court’s view, there was no connection between the collection for marketing purposes and the further processing for credit assessment purposes, and the data subject would not have expected such further processing. Similarly, no business or other relationship could be established between the claimants and the credit reference agency. Although no categories of sensitive data were involved, the credit assessment could nevertheless lead to significant adverse consequences – for example, when concluding contracts or granting loans. According to the Supreme Court, the change of purpose was not legitimised under Art. 6 (4) of the GDPR.
Furthermore, the claimants objected to the calculation and disclosure of a credit score without taking into account information regarding their past payment history. In the Court’s view, however, the processing of personal data for the purpose of assessing creditworthiness serves not only the credit reference agency’s economic interests but also the interests of the enquiring companies in assessing the creditworthiness of their potential contractual partners, as well as the data subjects’ interest in protection against over-indebtedness. As information on past payment behaviour is available for only a small proportion of Austrian citizens, the existence of such data cannot be a prerequisite for the lawfulness of a credit report. The court therefore considered the assessment of creditworthiness without data on past payment behaviour to be necessary and did not identify any conflicting interests on the part of the claimants.

Even an Excessive Request for Iformation Must Be Answered
In its judgement of August 19, 2026, the Osnabrück Administrative Court ruled that even in the case of an excessive request for information within the meaning of Art. 12 (5), second sentence, of the GDPR, the data controller must, at the very least, notify the data subject of the refusal to provide the information in the event of an initial failure to act (Osnabrück Administrative Court, decision dated 19.08.2026 – Ref. 7 A 170/24).
The claimant holds a hunting licence and was affected by a change in the competent authority for firearms in 2023/2024. In this context, he received a letter at his home address providing information on the processing of personal data by the new competent authority. The claimant objected to the use of his home address, provided a PO box address and requested the restriction of data processing pursuant to Art. 18 (1) (d) of the GDPR, together with confirmation thereof. The authority did not respond. Consequently, in a letter dated April 6, 2024, the claimant submitted a request for access to data under Art. 15 of the GDPR. As the authority still failed to respond, the claimant brought an action for a declaratory judgement on July 12, 2024, seeking a declaration that the authority had failed to provide the information within the prescribed one-month time limit.
Following the court order upholding the claim, the authority provided information which the claimant, in a further action, contested as incomplete. By letter dated August 21, 2024, the claimant submitted a new request for information and, on October 15, 2024, brought a further action seeking a declaration that this information had also not been provided within the prescribed time limit.
Under Art. 12 (3) of the GDPR, the controller must provide the data subject with information regarding the measures taken in response to their request without delay, and in any event within one month of receiving the request. This time limit also applies to requests for information.
In the view of the Administrative Court, the controller must at least provide information on the reasons for its failure to act and on the possibility of lodging a complaint with a supervisory authority or bringing a legal action. An excessive request for information within the meaning of Art. 12 (5), second sentence, of the GDPR merely entitles the controller to charge a reasonable fee or to refuse to provide the information. Even in the latter case, a negative decision is mandatory under Art. 12 (4) of the GDPR. According to the court, the objection that the obligation to state reasons creates an unnecessary burden and that the excessive applicant would thus still achieve their aim cannot be raised in the event of an initial refusal.

National claim for an injunction regarding Meta Business Tools
In its judgment of August 5, 2026, the Brandenburg Higher Regional Court ruled that the comprehensive and indiscriminate collection of personal data by infringes the principles of purpose limitation and data minimisation (Brandenburg Higher Regional Court, decision dated 05.08.2026 – Ref. 4 U 24/26).
A user of the social network Instagram had brought an action against the data processing carried out by the operator – Meta Platforms, Inc. – in connection with Meta Business Tools. Meta Business Tools can be integrated into third-party websites, whereby data from website visitors is automatically transferred to Meta and stored there. Furthermore, personalised advertising may be displayed when visiting websites that have integrated Meta Business Tools. The user sought an injunction against the processing of personal data located on third-party websites and apps outside Meta’s networks, as well as the erasure of all such data. The court held that the user, who bore the burden of proof and the duty to present the case, was not required to specify the exact websites and apps on which the Meta Business Tools were integrated.
In the court’s view, by storing users’ personal data generally and indiscriminately regarding their activities outside its own network, and thereby processing a potentially unlimited amount of personal data, the operator infringed the principles of purpose limitation and data minimisation (Art. 5 (1) (b) and (c) of the GDPR).
Meta was unable to put forward any grounds for justification; in particular, no consent had been obtained from the user. Even if consent had been given to third-party providers, this would not cover the subsequent data processing by Meta. The operator was unable to demonstrate to what extent the data could actually be used for security and integrity purposes, or whether such use was necessary for those purposes. Consequently, there was also no legitimate interest under Art. 6 (1) (f) of the GDPR.
The right to an injunction arises from Sections 280 (1), 241 (2), 823 and 1004 of the BGB. The GDPR does not preclude the provisions of national law. In doing so, the court draws on the case law of the ECJ (ECJ, decision dated 04.09.2025 – Ref. C-655/23). The Higher Regional Court argued that, given the defendant’s conduct in its defence before the court, it must be assumed that the Meta Business Tools are being maintained, and affirmed that there was a risk of repetition.
The request for erasure under Art. 17 (1) of the GDPR could not be fulfilled by a self-service tool provided by the operator offering the options ‘Clear previous activity’ or ‘Disconnect future activity’, as this merely separates the data from the user profile rather than deleting it. Furthermore, as the user had no control over what information Meta had stored regarding her usage behaviour or to what extent the company had created a personality profile, the court also awarded the user damages under Art. 82 (1) of the GDPR in the amount of 2,000 euros.

RAK Training Courses Only with Consent?
In a judgement dated August 21, 2026, the Karlsruhe Local Court addressed the question of whether a Bar Association is liable for sending advertising to a lawyer, and ruled that it is not (Karlsruhe Local Court, decision dated 21.08.2026 – Ref. 1 C 1332/24, press release dated 14.09.2026).
A Bar Association sent advertising for an online seminar to its members by email. In response, a lawyer stated that he did not wish to receive advertising and demanded a cease-and-desist declaration subject to a penalty payment. After the Bar Association again sent advertising for a further online seminar to the lawyer’s email address and failed to provide a cease-and-desist declaration even after being requested to do so once more, the lawyer brought a claim.
The court deemed the emails sent by the defendant containing offers relating to further training to constitute advertising within the meaning of Section 2 (1) (2) of the German Unfair Competition Act (UWG). Contact via email was made without the lawyer’s consent and, in the court’s view, was also not covered by any justification under Art. 6 (1) of the GDPR. In particular, there was neither consent nor a necessity for the performance of a contract. The lawyer had provided his email address to the Bar Association in the context of changing law firms, but this was not to be construed as consent to the sending of promotional emails. Although the organisation of continuing professional development courses forms part of a bar association’s public duties, the Local Court held that the processing of the email address was not necessary for the fulfilment of this duty. The court regarded the refusal to sign the cease-and-desist declaration as indicating a risk of repetition and upheld the claim for an injunction. The Local Court rejected a claim for damages under Art. 82 (1) of the GDPR on the grounds that the lawyer’s personal data had not been made available to third parties. Furthermore, the causal link was deemed doubtful; the lawyer had been annoyed by the sending of advertising and not by the use of his email address in breach of data protection regulations.

Final Report on Ray-Ban Meta AI Glasses
This month, the Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI) published its final report on the technical and data protection investigation into the Ray-Ban Meta AI Glasses.
The Ray-Ban Meta AI Glasses are a pair of spectacles fitted with a camera, speakers, several microphones and an AI assistant. They come with a Meta AI app. In the authority’s view, responsibility under data protection law for the personal data of third parties lies with the wearer of the glasses.
According to the HmbBfDI, the legal basis for the data processing associated with the use of the glasses may be consent under Art. 6 (1) (a) of the GDPR or a legitimate interest under Art. 6 (1) (f) of the GDPR. In particular, the authority considers that the creation and publication of photographs and video recordings, as well as their transmission to Meta AI, can in principle be based on consent. With regard to the use of Meta AI, the authority considers that a legitimate interest in navigation, translation or information gathering outweighs the interests of the data subjects.
In its report, however, the authority criticises in particular the difficulties regarding compliance with the principle of transparency. Whether on the basis of consent or a legitimate interest, comprehensive information must be provided prior to data processing. According to the authority, this is not feasible in practice. In particular, the externally facing LED light cannot provide sufficient information about the data processing and does not meet the transparency requirements.
An exception to the scope of the GDPR arises under Art. 2 (2) (c) of the GDPR if only family members or close friends are filmed.

€ 825 Million Fine Imposed on Uber for Fully Automated Decision-making
On August 21, 2026, the Dutch Data Protection Authority (AP) imposed a fine of 824,990,000 euros on Uber B.V. and Uber Technologies Inc. for automated decisions concerning drivers (press release of 21.08.2026).
Uber is a platform for arranging taxi journeys and car hire, based in the Netherlands. Between 2018 and 2022, the platform used software to monitor drivers’ behaviour and customer reviews; this software automatically deactivated the accounts of affected drivers in cases of suspected fraud or poor customer reviews. The AP’s investigations were launched in collaboration with the French data protection authority (CNIL) following a complaint from the French human rights organisation Ligue des droits de l’Homme (LDH).
Under Art. 22 of the GDPR, data subjects have the right not to be subject to a decision based solely on automated processing which produces legal effects concerning them or similarly significantly affects them. The decision had legal effects insofar as the deactivation resulted in the drivers losing their income. No human assessment took place at any stage. Furthermore, the authority found that Uber had not adequately informed the drivers about the automated decision.
This is not the first fine imposed on the ride-hailing platform. Back in 2018, the Data Protection Authority imposed a fine of 600,000 euros, followed by a fine of 10,000,000 euros in 2023 and a fine of 290,000,000 euros in 2024. Uber is currently contesting the fines from 2024 and 2026.

Fine of € 5.5 Million for Sending Promotional Messages Despite an Objection
On September 3, 2026, the Italian Data Protection Authority (GPDP) imposed a fine of 5,508,000 euros on Banco Bilbao Vizcaya Argentaria (BBVA) for sending advertising messages despite an objection (press release dated 03.09.2026).
The Italian branch of BBVA operates a banking app. A user of the app received commercial in-app messages, even though this setting had been deactivated by the user and the user had expressed their objection. According to the company, due to a technical fault, the deactivation in the app had not been synchronised with the database. This confirmed to the authority that the user’s objection had not been processed. Furthermore, no technical or organisational measures had been put in place to implement the user’s withdrawal of consent.
The user sent an additional email containing the objection to customer services rather than to the email address provided for data protection matters. However, in the authority’s view, this was irrelevant, as the data subject was not obliged to use specific communication channels, provided that the request reached the controller. After all, under Art. 12 (2) of the GDPR, it is the duty of the controller to facilitate the exercise of data subjects’ rights. Furthermore, by interacting with the app’s settings, the user had already followed the company’s instructions for exercising his right to object. The email sent was merely a confirmation. In contrast, BBVA had not provided the user with any information regarding the status of the request.

€ 403 Million Fine Imposed on Google for Processing Location Data
On September 21, 2026, the Irish Data Protection Commission (DPC) imposed a fine of 403,000,000 euros on Google Ireland Ltd. for the unlawful collection of location data (press release dated 21.09.2026).
Google operates a web search engine with various functions that process users’ location data. By activating the ‘Web & App Activity’ feature, Google can process information about account holders’ user activities – including browser and search history, as well as location data. The ‘Location History’ feature tracks users’ location data, including the places visited, the route between these places and their activities; this data is also recorded even when no Google service is currently being used. With ‘Location Accuracy’, users of Android devices can achieve more precise location detection. The supervisory authority’s investigations were carried out following several complaints from European consumer organisations and cover the period from the entry into force of the GDPR on May 25, 2018 until February 4, 2020.
The supervisory authority criticised the lack of lawfulness and fairness in the processing of location data. In particular, users had not been adequately informed about the data processing and were unable to understand the purpose for which their location data was being processed. Furthermore, Google was unable to demonstrate that the data processing complied with data protection regulations and was therefore in breach of its accountability obligations. The retention period also exceeded what was necessary.
In addition to the fine of 403,000,000 euros, Google was ordered to bring its data processing into line with the provisions of the GDPR within six months.
