• Latest
  • Trending
District Court Frankfurt a.M. on the right to be forgotten

Caution when forwarding business e-mails to private addresses

24. September 2024
ChatGPT and lawyers: recordings of the Weblaw launch event

Private AI use in the company

24. October 2025
Lego brick still protected as a design patent

App purchases, in-app purchases and sales tax

21. October 2025
dsgvo 1

What belongs in a DPA? Data processing agreement in accordance with Art. 28 GDPR

17. October 2025
Smart contracts in the insurance industry: contract design and regulatory compliance for InsurTech start-ups

Contract for work vs. service contract in software, AI and games projects

15. October 2025

Influencer contract: performance profile, rights/buyouts, labeling and AI content

13. October 2025
AI content for subscription platforms

AI content for subscription platforms

29. September 2025
E-sports finally charitable? What the government draft of the Tax Amendment Act 2025 really brings

E-sports finally charitable? What the government draft of the Tax Amendment Act 2025 really brings

23. September 2025
Clubs, photos and minors: managing consent properly

Clubs, photos and minors: managing consent properly

22. September 2025
AI faces, voice clones and deepfakes in advertising: rules of the game under the EU AI Act and German law

AI faces, voice clones and deepfakes in advertising: rules of the game under the EU AI Act and German law

17. September 2025
Modding in EULAs and contracts – what applies legally in Germany?

Modding in EULAs and contracts – what applies legally in Germany?

8. September 2025
Arbitration agreements in EULAs and developer contracts

Arbitration agreements in EULAs and developer contracts

7. September 2025
Chain of title in game development: building a clean chain of rights

Chain of title in game development: building a clean chain of rights

6. September 2025
Fail-fast clauses in media productions – what are they actually?

Fail-fast clauses in media productions – what are they actually?

5. September 2025
Founder’s agreement vs. shareholder agreement: setting the course for startups at an early stage

Founder’s agreement vs. shareholder agreement: setting the course for startups at an early stage

12. August 2025
Cheat software without code intervention: What the BGH really decided in the Sony ./. Datel case (I ZR 157/21)

Cheat software without code intervention: What the BGH really decided in the Sony ./. Datel case (I ZR 157/21)

11. August 2025
Digital integrity as a (new) fundamental right: status in Germany and the EU in 2025

Digital integrity as a (new) fundamental right: status in Germany and the EU in 2025

10. August 2025
European Economic Interest Grouping (EEIG)

EU Digital Decade 2030: Data law, Data Act & eIDAS 2 – what needs to be implemented in 2025

8. August 2025
Upload filters between copyright and personal rights

Upload filters between copyright and personal rights

7. August 2025
On-demand transmission right in the digital space: streaming, Section 19a UrhG and licensing

On-demand transmission right in the digital space: streaming, Section 19a UrhG and licensing

6. August 2025
Q&A: Legal issues for game developers

5-day guide: Founding a game development studio

5. August 2025
  • Mehr als 3 Millionen Wörter Inhalt
  • |
  • info@itmedialaw.com
  • |
  • Tel: 03322 5078053
Kurzberatung

No products in the cart.

  • en English
  • de Deutsch
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact

Caution when forwarding business e-mails to private addresses

24. September 2024
in Data protection Law
Reading Time: 3 mins read
0 0
A A
0
dsgvo 3589608 1280

The Munich Higher Regional Court clarified in its ruling of 31.07.2024 under file number 7 U 351/23 that forwarding work emails to private email addresses without the consent of the person concerned can constitute a serious breach of data protection law. The case impressively shows how quickly managers and employees can find themselves in legal gray areas if they handle personal data carelessly. Young start-ups in particular often do not take these requirements and problems seriously enough, but appearances are deceptive: even in the agile start-up world, problems lurk from a purely formal legal perspective if data protection is neglected. It is high time to familiarize yourself with the legal principles and rethink how you handle personal data. After all, ignorance is no defense against punishment, and the consequences can threaten the existence of a young company.

Content Hide
1. The facts of the case: Management Board systematically forwards business emails to private account
2. The decision of the OLG Munich: Violation of the GDPR
3. The significance of the ruling for startups
4. Conclusion:
4.1. Author: Marian Härtel
Key Facts
  • The ruling of the Munich Higher Regional Court concerns the unauthorized forwarding of business e-mails to private e-mail addresses.
  • The decision shows possible data protection violations by managers in start-ups and the importance of the GDPR.
  • Personal data may only be processed with consent, even in business contexts.
  • An awareness of the sensitivity of personal data is crucial in order to minimize legal risks.
  • Clear rules and sensitization of employees are necessary to avoid legal consequences.
  • A data protection breach can threaten the existence of start-ups, including warnings and fines.
  • The Munich Higher Regional Court ruling serves as a wake-up call to take data protection seriously in the startup world.

The facts of the case: Management Board systematically forwards business emails to private account

In the case decided by the Munich Higher Regional Court, a board member of an AG had forwarded business emails with sensitive content such as salary statements, employee commission claims, contracts with customers and compliance matters to his private email address in at least 9 cases. According to the Management Board, this was done in consultation with the former CEO. The Supervisory Board of the AG then revoked the appointment of the Management Board member and terminated his Management Board employment contract without notice. What at first glance sounds like an internal matter turned out to be a serious breach of data protection. Even if the forwarding may have been done without malicious intent, the Executive Board should have first obtained the consent of the persons concerned. Especially in start-ups, where there is often a relaxed culture of communication and hierarchies are flat, the temptation to neglect data protection regulations is great. However, this case makes it clear that extreme caution is required. Even if you think you are acting in the interests of the company, careless forwarding can have serious consequences.

The decision of the OLG Munich: Violation of the GDPR

The Munich Higher Regional Court ruled in favor of the Supervisory Board. The forwarding of the emails to the private account of the Management Board constituted a breach of the General Data Protection Regulation (GDPR). According to Art. 4 No. 1 GDPR, personal data is any information relating to an identified or identifiable natural person. The forwarding and storage of emails containing such data on private servers is therefore only permitted with the consent of the data subject or if there is a legal basis for permission. The court clarified that it does not matter whether the forwarding takes place in a professional or private context. The only decisive factor is that personal data was processed without justification. For many start-ups, this interpretation may seem strict, but it is in line with the spirit of the GDPR, which focuses on the protection of personal data. Founders and their employees must therefore be aware of their responsibility and handle data with care.

The significance of the ruling for startups

The ruling makes it clear that the handling of personal data requires the utmost caution. Many founders and employees in start-ups are not aware of the data protection relevance of seemingly harmless forwarding of business emails to private addresses. But everyone should be aware of this by now at the latest: Even a single email can contain sensitive personal data, the unauthorized processing of which can have serious legal consequences. Especially in the startup context, it is important to always ask yourself whether you are authorized to forward an email to private accounts. Even if you believe you are acting in the interests of the company, careless forwarding can be seen as a breach of data protection. It is therefore important to raise awareness of the sensitivity of personal data and, if in doubt, it is better to ask too many questions. After all, the consequences of a data protection breach can be life-threatening, especially for a young company. Everything is conceivable, from warnings and claims for damages to severe fines.

Conclusion:

Before forwarding a business email to a private email address, you should always ask yourself whether you are authorized to do so. If in doubt, it is better to ask too many questions than risk a data protection breach. As this case shows, even a careless forwarding or the mere inclusion of a private email address in CC can be expensive. Startups are well advised to sensitize their employees to this issue and to establish clear rules for handling personal data. This is the only way to prevent supposedly harmless actions from having far-reaching legal consequences. Especially in times when data protection is becoming increasingly important, it is essential to familiarize yourself with the applicable regulations and to live by them in your day-to-day work. Only by handling data responsibly can legal risks be minimized and the trust of customers and business partners strengthened. In this sense, the ruling of the Munich Higher Regional Court should be seen as a wake-up call to take data protection obligations seriously and to exercise the utmost care when handling personal data. Especially in the agile start-up world.

 

Marian Härtel
Author: Marian Härtel

Marian Härtel ist Rechtsanwalt und Fachanwalt für IT-Recht mit einer über 25-jährigen Erfahrung als Unternehmer und Berater in den Bereichen Games, E-Sport, Blockchain, SaaS und Künstliche Intelligenz. Seine Beratungsschwerpunkte umfassen neben dem IT-Recht insbesondere das Urheberrecht, Medienrecht sowie Wettbewerbsrecht. Er betreut schwerpunktmäßig Start-ups, Agenturen und Influencer, die er in strategischen Fragen, komplexen Vertragsangelegenheiten sowie bei Investitionsprojekten begleitet. Dabei zeichnet sich seine Beratung durch einen interdisziplinären Ansatz aus, der juristische Expertise und langjährige unternehmerische Erfahrung miteinander verbindet. Ziel seiner Tätigkeit ist stets, Mandanten praxisorientierte Lösungen anzubieten und rechtlich fundierte Unterstützung bei der Umsetzung innovativer Geschäftsmodelle zu gewährleisten.

Tags: ComplianceData protection LawE‑mailEmployeesGDPRGeneral Data Protection RegulationJudgmentMailMunich Higher Regional CourtNatural personolgPersonal dataPrivacyrightStartups

Weitere spannende Blogposts

The legal protection of a business plan

5b698c02ae6e02ed43d05d01c467b658
10. July 2024

A business plan is an indispensable strategic document for start-ups and company founders. It serves as a roadmap for business...

Read moreDetails

Why startups should be careful with high investments: 5 reasons pro and contra

Why startups should be careful with high investments: 5 reasons pro and contra
10. May 2023

Five reasons against rash, high investments As a lawyer and consultant, I would first like to point out to young...

Read moreDetails

Fake invoices with a false IBAN – what to do if you have fallen for fraudsters?

Fake invoices with a false IBAN – what to do if you have fallen for fraudsters?
14. June 2024

My law firm is seeing an increasing number of cases in which clients have become victims of bank transfer fraud...

Read moreDetails

Dual holding structure: Does it make sense for startups?

75e587bf074ffac7562428e0a31d365b
13. August 2024

Start-ups and young companies are often faced with the question of the optimal corporate structure. One option that can offer...

Read moreDetails

Liability risks when deploying APIs: What you need to know

Liability risks when deploying APIs: What you need to know
11. September 2023

Introduction In my daily work, I experience how APIs, also known as Application Programming Interfaces, are much more than just...

Read moreDetails

Demolition hunters on eBay not necessarily abused by law

Taxes on regular eBay sales
11. July 2019

The Federal Court of Justice recently delivered an interesting verdict on an old phenomenon, the so-called demolition hunters. In the...

Read moreDetails

How compliance creates a win-win situation for customers and providers

How compliance creates a win-win situation for customers and providers
21. December 2022

What is compliance and why is it important? Compliance is the adherence to legal requirements and guidelines. This includes, among...

Read moreDetails

Google delisting due to data privacy?

BGH considers Uber Black to be anti-competitive
7. November 2022

On June 16, 2020, at 9:30 a.m., the German Federal Court of Justice will rule in two cases on whether...

Read moreDetails

Hamburg data protectors take action against Google Assistant

GDPR: Download pairing with newsletter/registration?
7. November 2022

The use of automated voice assistants from providers such as Google, Apple and Amazon is proving to be highly risky...

Read moreDetails
ChatGPT and lawyers: recordings of the Weblaw launch event
Law on the Internet

Private AI use in the company

24. October 2025

Private accounts on ChatGPT & Co. for corporate purposes are a gateway to data protection breaches, leaks of secrets and...

Read moreDetails
Lego brick still protected as a design patent

App purchases, in-app purchases and sales tax

21. October 2025
dsgvo 1

What belongs in a DPA? Data processing agreement in accordance with Art. 28 GDPR

17. October 2025
Smart contracts in the insurance industry: contract design and regulatory compliance for InsurTech start-ups

Contract for work vs. service contract in software, AI and games projects

15. October 2025

Influencer contract: performance profile, rights/buyouts, labeling and AI content

13. October 2025

Podcastfolge

3c671c5134443338a4e0c30412ac3270

“Digital law decoded” with lawyer Marian Härtel

26. September 2024

In this exciting 30-minute podcast, lawyer Marian Härtel decodes the complex world of digital law for the self-employed, start-ups and...

Read moreDetails
247f58c28882e230e982fa3a32d34dea

Digital sovereignty: Europe’s path to a self-determined digital future

8. December 2024
c9c5d7fd380061a8018074c2ca5a81bf

Startups and innovation in Germany – challenges and opportunities

26. September 2024
d5e1e6cad87cb839a9e23af79034bd94

AI in the legal system: Towards a digital future of justice

16. October 2024
7c0b449a651fe0b81e5eec2e23515012 2

Copyright in the digital age

15. January 2025

Video

My transparent billing

My transparent billing

10. February 2025

In this video, I talk a bit about transparent billing and how I communicate what it costs to work with...

Read moreDetails
Fascination between law and technology

Fascination between law and technology

10. February 2025
My two biggest challenges are?

My two biggest challenges are?

10. February 2025
What really makes me happy

What really makes me happy

10. February 2025
What I love about my job!

What I love about my job!

10. February 2025
  • Privacy policy
  • Imprint
  • Contact
  • About lawyer Marian Härtel
Marian Härtel, Rathenaustr. 58a, 14612 Falkensee, info@itmedialaw.com

Marian Härtel - Rechtsanwalt für IT-Recht, Medienrecht und Startups, mit einem Fokus auf innovative Geschäftsmodelle, Games, KI und Finanzierungsberatung.

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • en English
  • de Deutsch
Kostenlose Kurzberatung