• Home
  • Imprint
  • Privacy policy
  • Terms
  • Agile and lean law firm
  • Ideal partner
  • Contact
  • Videos
ITMediaLaw - Rechtsanwalt Marian Härtel
  • en English
  • de Deutsch
  • About lawyer Marian Härtel
    • About lawyer Marian Härtel
      • Ideal partner
      • About lawyer Marian Härtel
      • Video series – about me
      • Why a lawyer and business consultant?
      • Principles as a lawyer
      • Focus on start-ups
      • Nerd und Rechtsanwalt
      • Ideal partner
      • How can I help clients?
    • Über die Kanzlei
      • How clients benefit from my network of colleagues, partners and service providers
      • Quick and flexible access
      • Agile and lean law firm
      • Team: Saskia Härtel – WHO AM I?
      • Price overview
    • How can I help clients?
    • Sonstige Informationen
      • Einwilligungen widerrufen
      • Privatsphäre-Einstellungen ändern
      • Historie der Privatsphäre-Einstellungen
      • Privacy policy
    • Testimonials
    • Imprint
  • Leistungen
    • Focus areas of attorney Marian Härtel
      • Support with the foundation
      • Games law consulting
      • Advice in e-commerce
      • Support and advice of agencies
      • Legal advice in corporate law: from incorporation to structuring
      • Legal compliance and expert opinions
      • Streamers and influencers
      • Cryptocurrencies, Blockchain and Games
      • Outsourcing – for companies or law firms
    • Arbeitsschwerpunkte
      • Games and esports law
        • Esports. What is it?
      • Corporate law
      • IT/IP Law
      • Consulting for influencers and streamers
        • Influencer & Streamer
      • Contract review and preparation
      • DLT and Blockchain consulting
        • Blockchain Overview
      • Investment advice
      • AI and SaaS
  • Artikel
    • Langartikel / Guides
    • Law and computer games
    • Law and Esport
    • Law on the Internet
    • Blockchain and web law
    • Online retail
    • Data protection Law
    • Copyright
    • Competition law
    • Copyright
    • EU law
    • Law on the protection of minors
    • Labour law
    • Tax
    • Kanzlei News
    • Other
  • Videos/Podcasts
    • Videos
    • Podcast
      • ITMediaLaw Podcast
      • ITMediaLaw Kurz-Podcast
  • Knowledge base
  • Contact
  • E-Books
  • Vertragsmuster
  • Kostenlose Vertragsmuster
Kurzberatung
  • About lawyer Marian Härtel
    • About lawyer Marian Härtel
      • Ideal partner
      • About lawyer Marian Härtel
      • Video series – about me
      • Why a lawyer and business consultant?
      • Principles as a lawyer
      • Focus on start-ups
      • Nerd und Rechtsanwalt
      • Ideal partner
      • How can I help clients?
    • Über die Kanzlei
      • How clients benefit from my network of colleagues, partners and service providers
      • Quick and flexible access
      • Agile and lean law firm
      • Team: Saskia Härtel – WHO AM I?
      • Price overview
    • How can I help clients?
    • Sonstige Informationen
      • Einwilligungen widerrufen
      • Privatsphäre-Einstellungen ändern
      • Historie der Privatsphäre-Einstellungen
      • Privacy policy
    • Testimonials
    • Imprint
  • Leistungen
    • Focus areas of attorney Marian Härtel
      • Support with the foundation
      • Games law consulting
      • Advice in e-commerce
      • Support and advice of agencies
      • Legal advice in corporate law: from incorporation to structuring
      • Legal compliance and expert opinions
      • Streamers and influencers
      • Cryptocurrencies, Blockchain and Games
      • Outsourcing – for companies or law firms
    • Arbeitsschwerpunkte
      • Games and esports law
        • Esports. What is it?
      • Corporate law
      • IT/IP Law
      • Consulting for influencers and streamers
        • Influencer & Streamer
      • Contract review and preparation
      • DLT and Blockchain consulting
        • Blockchain Overview
      • Investment advice
      • AI and SaaS
  • Artikel
    • Langartikel / Guides
    • Law and computer games
    • Law and Esport
    • Law on the Internet
    • Blockchain and web law
    • Online retail
    • Data protection Law
    • Copyright
    • Competition law
    • Copyright
    • EU law
    • Law on the protection of minors
    • Labour law
    • Tax
    • Kanzlei News
    • Other
  • Videos/Podcasts
    • Videos
    • Podcast
      • ITMediaLaw Podcast
      • ITMediaLaw Kurz-Podcast
  • Knowledge base
  • Contact
  • E-Books
  • Vertragsmuster
  • Kostenlose Vertragsmuster
ITMediaLaw - Rechtsanwalt Marian Härtel

ITMediaLaw - Rechtsanwalt Marian Härtel > Data protection Law > Employer must prohibit employees from using customer data on private communication devices

Employer must prohibit employees from using customer data on private communication devices

29. August 2023
in Data protection Law
Reading Time: 3 mins read
0 0
A A
0
dsgvo 3669706 1280
Key Facts
  • On 24.08.2023, the Baden-Baden Regional Court handed down an etatist ruling on GDPR and data processing.
  • A customer received a claim for information about the names of employees who processed her data privately.
  • The court found that private use of customer data violated company guidelines.
  • Employees are not considered recipients within the meaning of the GDPR if they follow instructions.
  • The customer can assert claims against the employees in order to verify the legality of the data processing.
  • The company was obliged to prohibit the use of personal data on private devices.
  • No appeal was allowed against the ruling, so the case is closed.

An interesting ruling that could affect startups in particular, which often work with “bring your own device” policies, was just issued by the Baden-Baden Regional Court.

In a judgment dated August 24, 2023 (Case No. 3 S 13/23), the court ordered a company to disclose to a customer the names of its employees who had privately processed customer data collected by the company. In addition, the company has been ordered to prohibit its employees from continuing to use the personal customer data on their private communication devices.

In its reasoning, the Regional Court stated that the General Data Protection Regulation (GDPR) provides for the customer’s right to information pursuant to Art. 15 Par. 1 lit. c) GDPR, which in the present case also extended to the plaintiff customer’s employees of the defendant as recipients within the meaning of Art. 4 para. 9 GDPR to whom the applicant’s personal data have been disclosed and who have processed them privately, for example because they have used them on a private account of a social network. It is true that employees of a data controller are in principle not to be regarded as recipients. However, according to the case law of the European Court of Justice (ECJ, judgment of June 22, 2023, C-579/21, para. 75), this only applies if they process the data under the supervision of the controller and in accordance with its instructions. In contrast, in the case to be decided, at least one employee of the defendant had established contact with a customer on her own authority via her private account in order to clarify questions in connection with the purchase of a television. Since it is necessary for the customer to name the employees in order to verify the lawfulness of the processing of her personal data and, if necessary, to be able to assert further claims against the employees to which she is entitled under the GDPR, there is a right to information on the naming of the employees in the present case. A balancing of the rights and freedoms of the customer on the one hand and the employees on the other to be carried out leads to the fact that the use of the customer data on private accounts was carried out unauthorized by the employee of the defendant contrary to the instructions and the usual practices of the company, so that the interest of the employees to remain anonymous is not worthy of protection and has to take a back seat to the interests of the customer to assert her claims under the GDPR.

In addition, the customer is entitled to claim damages pursuant to §§ 823 para. 2, 1004 BGB analogous in conjunction with Art. 1 GDPR, the defendant company is entitled to prohibit the continued use of the plaintiff’s personal data collected by the defendant on private communication devices. The defendant is responsible as an indirect tortfeasor and is obligated to require the defendant’s employees who are subject to its instructions to refrain from the continued use of the customer’s personal data collected in the company in violation of instructions.

The district court did not allow an appeal against the judgment of August 24, 2023. There is therefore no right of appeal against the judgment.

To the background:

The customer had purchased a TV and a wall mount from the defendant company in June 2022. In this context, her name and address were recorded. A few days later, she returned the wall mount, and was inadvertently refunded the much higher purchase price for the TV.

When the oversight was noticed at the company, an employee of the company wrote a message to the customer via her private account on a social network on the same day, drawing attention to the oversight and asking for feedback. In addition, the customer also received another message via Instagram that same day, asking her to contact the Instagram user’s “boss” about this.

In her action against the company, the customer sought information on the employees of the defendant to whom her personal data had been disclosed or transmitted and also requested that the defendant be ordered to prohibit the employees from using the customer’s personal data on private communication devices.

The defendant company has countered the claim.

The district court dismissed the action. In its reasoning, it stated, among other things, that the right to information does not exist because employees of a company are not “recipients” within the meaning of Art. 15 Para. 1 lit. c) GDPR, Art. 4 No. 9 GDPR. The requested order to prohibit the defendant’s employees from using the customer’s personal data on her private communication devices was not justified.

The plaintiff’s appeal was directed against this, in which it continued to pursue its first-instance claims.

Tags: Competition lawPrivacy

Beliebte Beträge

Data leak in startup practice: GDPR reporting and damage limitation

dsgvo
29. April 2025

Young start-ups and solopreneurs often focus on agile development and rapid growth - but a data leak can put an...

Read moreDetails

Data protection, anonymity and third-party chatter: GDPR risks and solutions for OnlyFans Creator

Data protection, anonymity and third-party chatter: GDPR risks and solutions for OnlyFans Creator
12. May 2025

OnlyFans has revolutionized the income opportunities for adult content creators - but with success comes legal challenges. In particular, data...

Read moreDetails

Data protection and anonymity for OnlyFans creators, agencies, brokers and chatter agencies

Data protection and anonymity for OnlyFans creators, agencies, brokers and chatter agencies
10. May 2025

OnlyFans and similar platforms for erotic content are booming - but as their popularity grows, so do the data protection...

Read moreDetails

Legally compliant archiving of emails: legal requirements and practical implementation

Legally compliant archiving of emails: legal requirements and practical implementation
14. March 2025

It is impossible to imagine modern corporate communication without e-mail. It is not only used for the rapid exchange of...

Read moreDetails

Risks when hosting personal data on US cloud servers

Risks when hosting personal data on US cloud servers
18. February 2025

Hosting personal data on cloud servers from US providers poses significant risks for European companies, particularly with regard to compliance...

Read moreDetails

SaaS contract for marketing tools

da785cff1bca5b6897d0d4cacf7359ff
15. November 2024

When I helped set up CPMStar, one of the first major gaming marketing agencies in Germany, a few years ago,...

Read moreDetails

BGH ruling on damages for data protection breaches

BGH: Women also gamble on first-person shooters
8. December 2024

The ruling by the German Federal Court of Justice (BGH) on November 18, 2024 has put an abrupt end to...

Read moreDetails

New cookie regulation: a step towards simplifying digital consent?

Esport: Sports Committee of the BT meets Wednesday
8. December 2024

On September 4, 2024, the Federal Government adopted the Consent Management Ordinance (EinwV). This new ordinance is based on Section...

Read moreDetails

Multi-tenant architectures in the SaaS sector: data separation and compliance requirements

6e405ef66c83bf9de2066fb73a1deafc
9. November 2024

Multi-tenant architectures are the backbone of modern SaaS solutions, as they enable efficient use of resources and scalability. However, they...

Read moreDetails
New OLG rulings on product descriptions in online trade

Triple damage calculation

26. June 2023

Introduction In the field of intellectual property and information technology, the calculation of damages is an important aspect when it...

Read moreDetails
Security token

Security token

2. July 2023
a09de67fc6112c69eb5361af00dc73f2

Art Copyright Act (KUG)

10. November 2024
Right of First Offer (ROFO)

Right of First Offer (ROFO)

16. October 2024
Provider liability

Limitation of liability in contracts

11. April 2025

Podcast Folgen

Rechtliche Basics für Startup-Gründer – So startest du auf der sicheren Seite!

Rechtliche Basics für Startup-Gründer – So startest du auf der sicheren Seite!

1. November 2024

In dieser Episode des Itmedialaw Podcasts nimmt euch Rechtsanwalt und Unternehmer Marian Härtel mit auf eine Reise durch den rechtlichen...

Rechtskette beim Spieleentwickler

Rechtskette beim Spieleentwickler

19. April 2025

In dieser kurzen Episode diskutieren Anna und Max die Bedeutung der Rechtekette im Game Development – ein zentraler Aspekt für...

Rechtliche Beratung für Startups – Investitionen, die sich lohnen

Rechtliche Beratung für Startups – Investitionen, die sich lohnen

17. November 2024

In dieser Episode des ITmedialaw.com Podcasts dreht sich alles um die Bedeutung rechtlicher Beratung für Startups. Host Marian Härtel spricht...

Die Romantisierung des Prinzips ‘Fail Fast’ in Startups – Wann wird Scheitern zur Täuschung gegenüber Beteiligten?

Die Romantisierung des Prinzips ‘Fail Fast’ in Startups – Wann wird Scheitern zur Täuschung gegenüber Beteiligten?

20. April 2025

In diese Episode wird die komplexe Beziehung zwischen dem 'Fail Fast'-Prinzip und den Verantwortlichkeiten der Gründer gegenüber Investoren und Mitarbeitern...

  • Home
  • Imprint
  • Privacy policy
  • Terms
  • Agile and lean law firm
  • Ideal partner
  • Contact
  • Videos
Marian Härtel, Rathenaustr. 58a, 14612 Falkensee, info@itmedialaw.com

Marian Härtel - Rechtsanwalt für IT-Recht, Medienrecht und Startups, mit einem Fokus auf innovative Geschäftsmodelle, Games, KI und Finanzierungsberatung.

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • Contact
  • Leistungen
    • Support with the foundation
    • Focus areas of attorney Marian Härtel
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Games law consulting
    • Support and advice of agencies
    • Legal advice in corporate law: from incorporation to structuring
    • Cryptocurrencies, Blockchain and Games
    • Investment advice
    • Booking as speaker
    • Legal compliance and expert opinions
    • Legal advice in corporate law: from incorporation to structuring
    • Contract review and preparation
  • About lawyer Marian Härtel
    • About lawyer Marian Härtel
    • Agile and lean law firm
    • Focus on start-ups
    • Principles as a lawyer
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Why a lawyer and business consultant?
    • Focus on start-ups
    • How can I help clients?
    • Team: Saskia Härtel – WHO AM I?
    • Testimonials
    • Imprint
  • Videos
    • Video series – about me
    • Information videos – about Marian Härtel
    • Videos on services
    • Blogpost – individual videos
    • Shorts
    • Third-party videos
    • Podcast format
    • Other videos
  • Knowledge base
  • Podcast
  • Blogposts
    • Lange Artikel / Ausführungen
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Labour law
    • EU law
    • Corporate
    • Competition law
    • Copyright
    • Tax
    • Internally
    • Other
  • en English
  • de Deutsch
Kostenlose Kurzberatung