• Areas of expertise
  • |
  • About me
  • |
  • Principles as a lawyer
  • Tel: 03322 5078053
  • |
  • info@itmedialaw.com
ITMediaLaw - Rechtsanwalt Marian Härtel
  • en English
  • de Deutsch
  • About lawyer Marian Härtel
    • About lawyer Marian Härtel
      • Ideal partner
      • About lawyer Marian Härtel
      • Video series – about me
      • Why a lawyer and business consultant?
      • Principles as a lawyer
      • Focus on start-ups
      • Nerd und Rechtsanwalt
      • Ideal partner
      • How can I help clients?
    • Über die Kanzlei
      • How clients benefit from my network of colleagues, partners and service providers
      • Quick and flexible access
      • Agile and lean law firm
      • Team: Saskia Härtel – WHO AM I?
      • Price overview
    • How can I help clients?
    • Sonstige Informationen
      • Einwilligungen widerrufen
      • Privatsphäre-Einstellungen ändern
      • Historie der Privatsphäre-Einstellungen
      • Privacy policy
    • Testimonials
    • Imprint
  • Leistungen
    • Focus areas of attorney Marian Härtel
      • Support with the foundation
      • Games law consulting
      • Advice in e-commerce
      • Support and advice of agencies
      • Legal advice in corporate law: from incorporation to structuring
      • Legal compliance and expert opinions
      • Streamers and influencers
      • Cryptocurrencies, Blockchain and Games
      • Outsourcing – for companies or law firms
    • Arbeitsschwerpunkte
      • Games and esports law
        • Esports. What is it?
      • Corporate law
      • IT/IP Law
      • Consulting for influencers and streamers
        • Influencer & Streamer
      • Contract review and preparation
      • DLT and Blockchain consulting
        • Blockchain Overview
      • Investment advice
      • AI and SaaS
  • Artikel/News
    • Langartikel / Guides
    • Law and computer games
    • Law and Esport
    • Law on the Internet
    • Blockchain and web law
    • Online retail
    • Data protection Law
    • Copyright
    • Competition law
    • Copyright
    • EU law
    • Law on the protection of minors
    • Labour law
    • Tax
    • Kanzlei News
    • Other
  • Videos/Podcasts
    • Videos
    • Podcast
      • ITMediaLaw Podcast
      • ITMediaLaw Kurz-Podcast
  • Knowledge base
  • Contact
Kurzberatung
  • About lawyer Marian Härtel
    • About lawyer Marian Härtel
      • Ideal partner
      • About lawyer Marian Härtel
      • Video series – about me
      • Why a lawyer and business consultant?
      • Principles as a lawyer
      • Focus on start-ups
      • Nerd und Rechtsanwalt
      • Ideal partner
      • How can I help clients?
    • Über die Kanzlei
      • How clients benefit from my network of colleagues, partners and service providers
      • Quick and flexible access
      • Agile and lean law firm
      • Team: Saskia Härtel – WHO AM I?
      • Price overview
    • How can I help clients?
    • Sonstige Informationen
      • Einwilligungen widerrufen
      • Privatsphäre-Einstellungen ändern
      • Historie der Privatsphäre-Einstellungen
      • Privacy policy
    • Testimonials
    • Imprint
  • Leistungen
    • Focus areas of attorney Marian Härtel
      • Support with the foundation
      • Games law consulting
      • Advice in e-commerce
      • Support and advice of agencies
      • Legal advice in corporate law: from incorporation to structuring
      • Legal compliance and expert opinions
      • Streamers and influencers
      • Cryptocurrencies, Blockchain and Games
      • Outsourcing – for companies or law firms
    • Arbeitsschwerpunkte
      • Games and esports law
        • Esports. What is it?
      • Corporate law
      • IT/IP Law
      • Consulting for influencers and streamers
        • Influencer & Streamer
      • Contract review and preparation
      • DLT and Blockchain consulting
        • Blockchain Overview
      • Investment advice
      • AI and SaaS
  • Artikel/News
    • Langartikel / Guides
    • Law and computer games
    • Law and Esport
    • Law on the Internet
    • Blockchain and web law
    • Online retail
    • Data protection Law
    • Copyright
    • Competition law
    • Copyright
    • EU law
    • Law on the protection of minors
    • Labour law
    • Tax
    • Kanzlei News
    • Other
  • Videos/Podcasts
    • Videos
    • Podcast
      • ITMediaLaw Podcast
      • ITMediaLaw Kurz-Podcast
  • Knowledge base
  • Contact
ITMediaLaw - Rechtsanwalt Marian Härtel
Home Data protection Law

Employer must prohibit employees from using customer data on private communication devices

29. August 2023
in Data protection Law
Reading Time: 3 mins read
0 0
A A
0
dsgvo 3669706 1280
Key Facts
  • On 24.08.2023, the Baden-Baden Regional Court handed down an etatist ruling on GDPR and data processing.
  • A customer received a claim for information about the names of employees who processed her data privately.
  • The court found that private use of customer data violated company guidelines.
  • Employees are not considered recipients within the meaning of the GDPR if they follow instructions.
  • The customer can assert claims against the employees in order to verify the legality of the data processing.
  • The company was obliged to prohibit the use of personal data on private devices.
  • No appeal was allowed against the ruling, so the case is closed.

An interesting ruling that could affect startups in particular, which often work with “bring your own device” policies, was just issued by the Baden-Baden Regional Court.

In a judgment dated August 24, 2023 (Case No. 3 S 13/23), the court ordered a company to disclose to a customer the names of its employees who had privately processed customer data collected by the company. In addition, the company has been ordered to prohibit its employees from continuing to use the personal customer data on their private communication devices.

In its reasoning, the Regional Court stated that the General Data Protection Regulation (GDPR) provides for the customer’s right to information pursuant to Art. 15 Par. 1 lit. c) GDPR, which in the present case also extended to the plaintiff customer’s employees of the defendant as recipients within the meaning of Art. 4 para. 9 GDPR to whom the applicant’s personal data have been disclosed and who have processed them privately, for example because they have used them on a private account of a social network. It is true that employees of a data controller are in principle not to be regarded as recipients. However, according to the case law of the European Court of Justice (ECJ, judgment of June 22, 2023, C-579/21, para. 75), this only applies if they process the data under the supervision of the controller and in accordance with its instructions. In contrast, in the case to be decided, at least one employee of the defendant had established contact with a customer on her own authority via her private account in order to clarify questions in connection with the purchase of a television. Since it is necessary for the customer to name the employees in order to verify the lawfulness of the processing of her personal data and, if necessary, to be able to assert further claims against the employees to which she is entitled under the GDPR, there is a right to information on the naming of the employees in the present case. A balancing of the rights and freedoms of the customer on the one hand and the employees on the other to be carried out leads to the fact that the use of the customer data on private accounts was carried out unauthorized by the employee of the defendant contrary to the instructions and the usual practices of the company, so that the interest of the employees to remain anonymous is not worthy of protection and has to take a back seat to the interests of the customer to assert her claims under the GDPR.

In addition, the customer is entitled to claim damages pursuant to §§ 823 para. 2, 1004 BGB analogous in conjunction with Art. 1 GDPR, the defendant company is entitled to prohibit the continued use of the plaintiff’s personal data collected by the defendant on private communication devices. The defendant is responsible as an indirect tortfeasor and is obligated to require the defendant’s employees who are subject to its instructions to refrain from the continued use of the customer’s personal data collected in the company in violation of instructions.

The district court did not allow an appeal against the judgment of August 24, 2023. There is therefore no right of appeal against the judgment.

To the background:

The customer had purchased a TV and a wall mount from the defendant company in June 2022. In this context, her name and address were recorded. A few days later, she returned the wall mount, and was inadvertently refunded the much higher purchase price for the TV.

When the oversight was noticed at the company, an employee of the company wrote a message to the customer via her private account on a social network on the same day, drawing attention to the oversight and asking for feedback. In addition, the customer also received another message via Instagram that same day, asking her to contact the Instagram user’s “boss” about this.

In her action against the company, the customer sought information on the employees of the defendant to whom her personal data had been disclosed or transmitted and also requested that the defendant be ordered to prohibit the employees from using the customer’s personal data on private communication devices.

The defendant company has countered the claim.

The district court dismissed the action. In its reasoning, it stated, among other things, that the right to information does not exist because employees of a company are not “recipients” within the meaning of Art. 15 Para. 1 lit. c) GDPR, Art. 4 No. 9 GDPR. The requested order to prohibit the defendant’s employees from using the customer’s personal data on her private communication devices was not justified.

The plaintiff’s appeal was directed against this, in which it continued to pursue its first-instance claims.

Tags: Competition lawPrivacy

Beliebte Beträge

Legally compliant archiving of emails: legal requirements and practical implementation

Legally compliant archiving of emails: legal requirements and practical implementation
14. March 2025

It is impossible to imagine modern corporate communication without e-mail. It is not only used for the rapid exchange of...

Read moreDetails

Risks when hosting personal data on US cloud servers

Risks when hosting personal data on US cloud servers
18. February 2025

Hosting personal data on cloud servers from US providers poses significant risks for European companies, particularly with regard to compliance...

Read moreDetails

SaaS contract for marketing tools

da785cff1bca5b6897d0d4cacf7359ff
15. November 2024

When I helped set up CPMStar, one of the first major gaming marketing agencies in Germany, a few years ago,...

Read moreDetails

BGH ruling on damages for data protection breaches

BGH: Women also gamble on first-person shooters
8. December 2024

The ruling by the German Federal Court of Justice (BGH) on November 18, 2024 has put an abrupt end to...

Read moreDetails

New cookie regulation: a step towards simplifying digital consent?

Esport: Sports Committee of the BT meets Wednesday
8. December 2024

On September 4, 2024, the Federal Government adopted the Consent Management Ordinance (EinwV). This new ordinance is based on Section...

Read moreDetails

Multi-tenant architectures in the SaaS sector: data separation and compliance requirements

6e405ef66c83bf9de2066fb73a1deafc
9. November 2024

Multi-tenant architectures are the backbone of modern SaaS solutions, as they enable efficient use of resources and scalability. However, they...

Read moreDetails

Federal Court of Justice plans landmark decision on Facebook data scandal

BGH considers Uber Black to be anti-competitive
9. November 2024

The Federal Court of Justice (BGH) has announced that it intends to issue a landmark ruling in the form of...

Read moreDetails

Legally compliant integration of biometric authentication systems: Data protection and security requirements for FinTech start-ups

Legally compliant integration of biometric authentication systems: Data protection and security requirements for FinTech start-ups
21. October 2024

Biometric authentication systems are revolutionizing the way FinTech start-ups ensure security and user-friendliness. However, the integration of this technology also...

Read moreDetails

Legally compliant integration of biometric authentication systems: Data protection and security requirements for FinTech start-ups

Legally compliant integration of biometric authentication systems: Data protection and security requirements for FinTech start-ups
21. October 2024

Biometric authentication systems are revolutionizing the way FinTech start-ups ensure security and user-friendliness. However, the integration of this technology also...

Read moreDetails

5.0 60 reviews

  • Avatar Mikael Hällgren ★★★★★ vor einem Monat
    I got fantastic support from Marian Härtel. He managed to get my wrongfully suspended Instagram account restored. He was … Mehr incredibly helpful the whole way until the positive outcome. Highly recommended!
  • Avatar Lennart Korte ★★★★★ vor 2 Monaten
    Ich kann Herrn Härtel als Anwalt absolut weiterempfehlen! Sein Service ist erstklassig – schnelle Antwortzeiten, effiziente … Mehr Arbeit und dabei sehr kostengünstig, was für Startups besonders wichtig ist. Er hat für mein Startup einen Vertrag erstellt, und ich bin von seiner professionellen und zuverlässigen Arbeit überzeugt. Klare Empfehlung!
  • Avatar R.H. ★★★★★ vor 3 Monaten
    Ich kann Hr. Härtel nur empfehlen! Er hat mich bei einem Betrugsversuch einer Krypto Börse rechtlich vertreten. Ich bin sehr … Mehr zufrieden mit seiner engagierten Arbeit gewesen. Ich wurde von Anfang an kompetent, fair und absolut transparent beraten. Trotz eines zähen Verfahrens und einer großen Börse als Gegner, habe ich mich immer sicher und zuversichtlich gefühlt. Auch die Schnelligkeit und die sehr gute Erreichbarkeit möchte ich an der Stelle hoch loben und nochmal meinen herzlichsten Dank aussprechen! Daumen hoch mit 10 Sternen!
  • Avatar P! Galerie ★★★★★ vor 4 Monaten
    Herr Härtel hat uns äusserst kompetent in einen lästigen Fall mit META betreut. Er war effizient, beharrlich, aber auch mit … Mehr uns geduldig. Menschlich top, bis wir am Ende Dank ihm erfolgreich zum Ziel gekommen sind. Können wir wärmstens empfehlen. Und nochmals danke. P.H.
  • Avatar Mosaic Mask Studio ★★★★★ vor 5 Monaten
    Die Kanzlei ist immer ein verlässlicher Partner bei der Sichtung und Bearbeitung von Verträgen in der IT Branche. Es ist … Mehr stets ein professioneller Austausch auf Augenhöhe.
    Die Ergebnisse sind auf hohem Niveau und haben die interessen unsers Unternehmens immer bestmöglich wiedergespiegelt.
    Vielen Dank für die sehr gute Zusammenarbeit.
  • Avatar Philip Lucas ★★★★★ vor 8 Monaten
    Wir haben Herrn Härtel für unser Unternehmen konsultiert und sind äußerst zufrieden mit seiner Arbeit. Von Anfang an hat … Mehr er einen überaus kompetenten Eindruck gemacht und sich als ein sehr angenehmer Gesprächspartner erwiesen. Seine fachliche Expertise und seine verständliche und zugängliche Art im Umgang mit komplexen Themen haben uns überzeugt. Wir freuen uns auf eine langfristige und erfolgreiche Zusammenarbeit!
  • Avatar Doris H. ★★★★★ vor 10 Monaten
    Herr Härtel hat uns bezüglich eines Telefonvertrags beraten und vertreten. Wir waren mit seinem Service sehr zufrieden. Er … Mehr hat stets schnell auf unsere E-mails und Anrufe reagiert und den Sachverhalt einfach und verständlich erklärt. Wir würden Herrn Härtel jederzeit wieder beauftragen.Vielen Dank für die hervorragende Unterstützung
  • Avatar Philipp Skaar ★★★★★ vor 8 Monaten
    Als kleines inhabergeführtes Hotel sehen wir uns ab und dann (bei sonst weit über dem Durchschnitt liegenden Bewertungen) … Mehr der Herausforderung von aus der Anonymität heraus agierenden "Netz-Querulanten" gegenüber gestellt. Herr Härtel versteht es außerordentlich spür- und feinsinnig, derartige - oftmals auf Rufschädigung ausgerichtete - Bewertungen bereits im Keim, also außergerichtlich, zu ersticken und somit unseren Betrieb vor weiteren Folgeschäden zu bewahren. Seine Umsetzungsgeschwindigkeit ist beeindruckend, seine bisherige Erfolgsquote = 100%.Ergo: Unsere erste Adresse zur Abwehr von geschäftsschädigenden Angriffen aus dem Web.
  • ●
  • ●
  • ●
  • ●

Video-Galerie

Welcome to "6 questions for lawyer Marian Härtel"!
Welcome to “6 questions for lawyer Marian Härtel”!
Taxing esports tournament winnings correctly - players and organizers need to pay attention to this
Taxing esports tournament winnings correctly – players and organizers need to pay attention to this
Multi-tenant architectures: legal certainty for SaaS start-ups 🔒 Legal insights for tech entrepreneurs and developers
Multi-tenant architectures: legal certainty for SaaS start-ups 🔒 Legal insights for tech entrepreneurs and developers
signatures download clipart 29

Electronic signature

29. March 2025

Definition and types of electronic signature The electronic signature is a digital procedure for ensuring the authenticity of electronic declarations...

Read moreDetails
European Company / Societas Europaea (SE)

European Company / Societas Europaea (SE)

1. July 2023

Injunction

24. June 2023
Loss deduction

Loss deduction

16. October 2024
2ff9b43c700f55bc255bfbeeab460be6

Money Laundering Act (GwG)

9. November 2024

Podcast Folgen

Rechtliche Beratung für Startups – Investitionen, die sich lohnen

Rechtliche Beratung für Startups – Investitionen, die sich lohnen

17. November 2024

In dieser Episode des ITmedialaw.com Podcasts dreht sich alles um die Bedeutung rechtlicher Beratung für Startups. Host Marian Härtel spricht...

KI im Rechtssystem: Auf dem Weg in eine digitale Zukunft der Justiz

KI im Rechtssystem: Auf dem Weg in eine digitale Zukunft der Justiz

13. October 2024

In dieser faszinierenden Podcastfolge tauchen wir tief in die Welt der künstlichen Intelligenz (KI) und ihre Auswirkungen auf unser Rechtssystem...

Rechtliche Risiken bei langen Entwicklungszeiten und der Stornierung von Crowdfundingspielen

Rechtliche Risiken bei langen Entwicklungszeiten und der Stornierung von Crowdfundingspielen

20. April 2025

In dieser Episode erörtern wir die rechtlichen Herausforderungen, denen Spieleentwickler bei der Finanzierung durch Crowdfunding gegenüberstehen. Wir beleuchten die Verpflichtungen...

Rechtskette beim Spieleentwickler

Rechtskette beim Spieleentwickler

19. April 2025

In dieser kurzen Episode diskutieren Anna und Max die Bedeutung der Rechtekette im Game Development – ein zentraler Aspekt für...

  • Home
  • Imprint
  • Privacy policy
  • Terms
  • Agile and lean law firm
  • Ideal partner
  • Contact
  • Videos
Marian Härtel, Rathenaustr. 58a, 14612 Falkensee, info@itmedialaw.com

Marian Härtel - Rechtsanwalt für IT-Recht, Medienrecht und Startups, mit einem Fokus auf innovative Geschäftsmodelle, Games, KI und Finanzierungsberatung.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • Contact
  • Leistungen
    • Support with the foundation
    • Focus areas of attorney Marian Härtel
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Games law consulting
    • Support and advice of agencies
    • Legal advice in corporate law: from incorporation to structuring
    • Cryptocurrencies, Blockchain and Games
    • Investment advice
    • Booking as speaker
    • Legal compliance and expert opinions
    • Legal advice in corporate law: from incorporation to structuring
    • Contract review and preparation
  • About lawyer Marian Härtel
    • About lawyer Marian Härtel
    • Agile and lean law firm
    • Focus on start-ups
    • Principles as a lawyer
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Why a lawyer and business consultant?
    • Focus on start-ups
    • How can I help clients?
    • Team: Saskia Härtel – WHO AM I?
    • Testimonials
    • Imprint
  • Videos
    • Video series – about me
    • Information videos – about Marian Härtel
    • Videos on services
    • Blogpost – individual videos
    • Shorts
    • Third-party videos
    • Podcast format
    • Other videos
  • Knowledge base
  • Podcast
  • Blogposts
    • Lange Artikel / Ausführungen
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Labour law
    • EU law
    • Corporate
    • Competition law
    • Copyright
    • Tax
    • Internally
    • Other
  • en English
  • de Deutsch
Kostenlose Kurzberatung