• Latest
  • Trending
District Court Frankfurt a.M. on the right to be forgotten

OVG Lüneburg on data minimization in online stores

17. May 2024
ChatGPT and lawyers: recordings of the Weblaw launch event

Private AI use in the company

24. October 2025
Lego brick still protected as a design patent

App purchases, in-app purchases and sales tax

21. October 2025
dsgvo 1

What belongs in a DPA? Data processing agreement in accordance with Art. 28 GDPR

17. October 2025
Smart contracts in the insurance industry: contract design and regulatory compliance for InsurTech start-ups

Contract for work vs. service contract in software, AI and games projects

15. October 2025

Influencer contract: performance profile, rights/buyouts, labeling and AI content

13. October 2025
AI content for subscription platforms

AI content for subscription platforms

29. September 2025
E-sports finally charitable? What the government draft of the Tax Amendment Act 2025 really brings

E-sports finally charitable? What the government draft of the Tax Amendment Act 2025 really brings

23. September 2025
Clubs, photos and minors: managing consent properly

Clubs, photos and minors: managing consent properly

22. September 2025
AI faces, voice clones and deepfakes in advertising: rules of the game under the EU AI Act and German law

AI faces, voice clones and deepfakes in advertising: rules of the game under the EU AI Act and German law

17. September 2025
Modding in EULAs and contracts – what applies legally in Germany?

Modding in EULAs and contracts – what applies legally in Germany?

8. September 2025
Arbitration agreements in EULAs and developer contracts

Arbitration agreements in EULAs and developer contracts

7. September 2025
Chain of title in game development: building a clean chain of rights

Chain of title in game development: building a clean chain of rights

6. September 2025
Fail-fast clauses in media productions – what are they actually?

Fail-fast clauses in media productions – what are they actually?

5. September 2025
Founder’s agreement vs. shareholder agreement: setting the course for startups at an early stage

Founder’s agreement vs. shareholder agreement: setting the course for startups at an early stage

12. August 2025
Cheat software without code intervention: What the BGH really decided in the Sony ./. Datel case (I ZR 157/21)

Cheat software without code intervention: What the BGH really decided in the Sony ./. Datel case (I ZR 157/21)

11. August 2025
Digital integrity as a (new) fundamental right: status in Germany and the EU in 2025

Digital integrity as a (new) fundamental right: status in Germany and the EU in 2025

10. August 2025
European Economic Interest Grouping (EEIG)

EU Digital Decade 2030: Data law, Data Act & eIDAS 2 – what needs to be implemented in 2025

8. August 2025
Upload filters between copyright and personal rights

Upload filters between copyright and personal rights

7. August 2025
On-demand transmission right in the digital space: streaming, Section 19a UrhG and licensing

On-demand transmission right in the digital space: streaming, Section 19a UrhG and licensing

6. August 2025
Q&A: Legal issues for game developers

5-day guide: Founding a game development studio

5. August 2025
  • Mehr als 3 Millionen Wörter Inhalt
  • |
  • info@itmedialaw.com
  • |
  • Tel: 03322 5078053
Kurzberatung
Rechtsanwalt Marian Härtel - ITMediaLaw

No products in the cart.

  • en English
  • de Deutsch
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
Rechtsanwalt Marian Härtel - ITMediaLaw

OVG Lüneburg on data minimization in online stores

17. May 2024
in Data protection Law
Reading Time: 2 mins read
0 0
A A
0
dsgvo 3589608 1280

Content Hide
1. Insight into the case
2. Legal assessment
3. Significance for practice
3.1. Author: Marian Härtel

Insight into the case

With its ruling (decision 14 LA 1/24), the Lüneburg Higher Administrative Court has made a landmark decision in the area of data protection. This case focused on an online pharmacy that required customers to provide their date of birth in the ordering process. This approach attracted the attention of the data protection authority, which classified the practice as incompatible with the applicable data protection regulations. This view was supported by both the Hanover Administrative Court and the Lüneburg Higher Administrative Court. The decision highlights the increasingly relevant issue of data minimization and data economy in the digital economy and underlines the importance of compliance with the General Data Protection Regulation (GDPR) in all aspects of online commerce.

Key Facts
  • The Lüneburg Higher Administrative Court ruled that the collection of the date of birth is inadmissible.
  • The decision emphasizes the importance of data minimization in accordance with GDPR Art. 5 para. 1 lit. c.
  • Only the address and telephone number are required for identification.
  • Court referred to milder methods for determining legal capacity.
  • ruling calls on companies to continuously review their data processing procedures.
  • Responsible action strengthens customers' trust in data protection.
  • Regular review of login processes is recommended for SaaS and online stores.

Legal assessment

In its decision, the court emphasized that the collection of the date of birth by the online pharmacy constitutes a clear violation of the principle of data minimization as set out in Art. 5 para. 1 lit. c GDPR is specified. It was made clear that it is perfectly sufficient to provide an address and telephone number to identify a customer. This landmark decision emphasizes the essential importance of always checking exactly what information is actually necessary to fulfill the purpose of the data processing when collecting personal data. The court emphasized that the date of birth is not necessary for the purposes stated by the pharmacy – in particular the clear identification of the customer and the fulfillment of the obligation to provide advice and information. The court also pointed out that there are milder means of determining the legal capacity of customers, for example by simply asking whether they are of legal age. This interpretation shows that data protection is not only a question of compliance with legal requirements, but also a question of proportionality and the careful balancing of the company’s interest in data collection and the protection of customers’ privacy.

Significance for practice

This ruling by the OVG Lüneburg impressively underlines the need for companies to continuously review their data processing processes and consistently adapt them to the legal requirements, particularly in the area of data protection. It illustrates that comprehensive legal considerations are essential even for seemingly simple procedures such as a registration process. This decision serves as an important reminder that in the digital age, data protection plays a central role in every customer interaction and should always be a priority.

Companies are required not only to minimize legal risks, but also to strengthen their customers’ trust in the responsible handling of their data. At a time when data breaches are regularly making headlines, it is all the more important that companies take data protection seriously and see it as an integral part of their business practices.

In addition, it is advisable for companies, especially those that operate Software-as-a-Service (SaaS) solutions or online stores, to regularly review their login procedures from a data protection perspective. This includes not only compliance with legal requirements, but also ongoing evaluation and adaptation of processes to ensure the protection and security of user data. Such a proactive approach not only helps to avoid legal pitfalls, but also strengthens the trust of customers and users in the integrity of the company.

Marian Härtel
Author: Marian Härtel

Marian Härtel ist Rechtsanwalt und Fachanwalt für IT-Recht mit einer über 25-jährigen Erfahrung als Unternehmer und Berater in den Bereichen Games, E-Sport, Blockchain, SaaS und Künstliche Intelligenz. Seine Beratungsschwerpunkte umfassen neben dem IT-Recht insbesondere das Urheberrecht, Medienrecht sowie Wettbewerbsrecht. Er betreut schwerpunktmäßig Start-ups, Agenturen und Influencer, die er in strategischen Fragen, komplexen Vertragsangelegenheiten sowie bei Investitionsprojekten begleitet. Dabei zeichnet sich seine Beratung durch einen interdisziplinären Ansatz aus, der juristische Expertise und langjährige unternehmerische Erfahrung miteinander verbindet. Ziel seiner Tätigkeit ist stets, Mandanten praxisorientierte Lösungen anzubieten und rechtlich fundierte Unterstützung bei der Umsetzung innovativer Geschäftsmodelle zu gewährleisten.

Tags: CustomizationGDPRGeneral Data Protection RegulationJudgmentPrivacyReviewSaasserviceSicherheitSoftware

Weitere spannende Blogposts

Blockchain strategy of the German government: an insight into the legal aspects

Startup financing through tokenized profit participation rights and related financing options.
31. May 2023

Introduction: It has been a while since the German government published its position paper on blockchain strategy. This document, which...

Read moreDetails

Dealing with Fiverr, Upwork and other outsourcing platforms

Attention GoBD: Trap in the accounting of the self-employed
6. September 2019

I am always contacted by requests, such as how to deal with platforms such as Upwork, Fiverr, Freelancer.com, for example...

Read moreDetails

BGH decides on Facebook’s app center and data protection in games

GDPR: Download pairing with newsletter/registration?
30. October 2019

The Federal Court of Justice has to decide whether, in the way a game is offered there, in the way...

Read moreDetails

Designing your SaaS solution in compliance with data protection regulations as a US company!

Designing your SaaS solution in compliance with data protection regulations as a US company!
5. January 2021

In its judgment of July 16, 2020 (Case C311/18), the European Court of Justice declared the European Commission's Decision 2016/1250...

Read moreDetails

The IT Media Law Podcast – Law and technology explained in a relaxed way

Artificial intelligence and speaker rights: some legal thoughts
27. September 2024

In my IT Media Law Podcast, I focus on exciting topics relating to law, technology and digital transformation. So far,...

Read moreDetails

Who is affected by the new IT security guideline?

eacdf2e96129370b1608edb115f7bf58
13. August 2024

While vany entrepreneurs in the IT and startup-sector are struggling with the daily challengeschallenges of business developmentare preoccupied with thean...

Read moreDetails

BVerwG: Data protection authority can prohibit operation of a Facebook fan page

Facebook pages, data protection and August 1, 2019
21. November 2022

The operator of a fan page maintained on Facebook may be required to shut down its fan page if the...

Read moreDetails

Unity Media and WLAN hotspot: customers do not have to agree

Unity Media and WLAN hotspot: customers do not have to agree
7. November 2022

The First Civil Senate of the Federal Court of Justice, which is responsible among other things for claims under the...

Read moreDetails

Influencer jurisprudence: OLG Munich vs. the rest of Germany?

Frankfurt district court a.M. softens influencer jurisdiction
7. November 2022

Did Cathy Hummels advertise on her Instagram profile as an influencer? This question was addressed by the Munich Higher Regional...

Read moreDetails
ChatGPT and lawyers: recordings of the Weblaw launch event
Law on the Internet

Private AI use in the company

24. October 2025

Private accounts on ChatGPT & Co. for corporate purposes are a gateway to data protection breaches, leaks of secrets and...

Read moreDetails
Lego brick still protected as a design patent

App purchases, in-app purchases and sales tax

21. October 2025
dsgvo 1

What belongs in a DPA? Data processing agreement in accordance with Art. 28 GDPR

17. October 2025
Smart contracts in the insurance industry: contract design and regulatory compliance for InsurTech start-ups

Contract for work vs. service contract in software, AI and games projects

15. October 2025

Influencer contract: performance profile, rights/buyouts, labeling and AI content

13. October 2025

Podcastfolge

d00527fd01b1f807a4f80c0f202069e7

Legal basics for startup founders – how to start on the safe side!

9. November 2024

In this episode of the Itmedialaw podcast, lawyer and entrepreneur Marian Härtel takes you on a journey through the legal...

Read moreDetails
7c0b449a651fe0b81e5eec2e23515012 2

Copyright in the digital age

15. January 2025
8315f1ef298eb54dfeed2f5e55c8b9da 1

First test episode of the ITMediaLaw Podcast

26. August 2024
052c2ca5ca0421f0316b42073ce61791

Innovative business models – risk and opportunity at the same time

10. September 2024
8ffe8f2a4228de20d20238899b3d922e

Web3, blockchain and law – a critical review

26. September 2024

Video

My transparent billing

My transparent billing

10. February 2025

In this video, I talk a bit about transparent billing and how I communicate what it costs to work with...

Read moreDetails
Fascination between law and technology

Fascination between law and technology

10. February 2025
My two biggest challenges are?

My two biggest challenges are?

10. February 2025
What really makes me happy

What really makes me happy

10. February 2025
What I love about my job!

What I love about my job!

10. February 2025
  • Privacy policy
  • Imprint
  • Contact
  • About lawyer Marian Härtel
Marian Härtel, Rathenaustr. 58a, 14612 Falkensee, info@itmedialaw.com

Marian Härtel - Rechtsanwalt für IT-Recht, Medienrecht und Startups, mit einem Fokus auf innovative Geschäftsmodelle, Games, KI und Finanzierungsberatung.

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • en English
  • de Deutsch
Kostenlose Kurzberatung