• Latest
  • Trending
E-invoicing obligation from 2025: BMF specifies requirements

Schleswig-Holstein Higher Regional Court: Liability for falsified e-mails with invoices

5. February 2025
ChatGPT and lawyers: recordings of the Weblaw launch event

Private AI use in the company

24. October 2025
Lego brick still protected as a design patent

App purchases, in-app purchases and sales tax

21. October 2025
dsgvo 1

What belongs in a DPA? Data processing agreement in accordance with Art. 28 GDPR

17. October 2025
Smart contracts in the insurance industry: contract design and regulatory compliance for InsurTech start-ups

Contract for work vs. service contract in software, AI and games projects

15. October 2025

Influencer contract: performance profile, rights/buyouts, labeling and AI content

13. October 2025
AI content for subscription platforms

AI content for subscription platforms

29. September 2025
E-sports finally charitable? What the government draft of the Tax Amendment Act 2025 really brings

E-sports finally charitable? What the government draft of the Tax Amendment Act 2025 really brings

23. September 2025
Clubs, photos and minors: managing consent properly

Clubs, photos and minors: managing consent properly

22. September 2025
AI faces, voice clones and deepfakes in advertising: rules of the game under the EU AI Act and German law

AI faces, voice clones and deepfakes in advertising: rules of the game under the EU AI Act and German law

17. September 2025
Modding in EULAs and contracts – what applies legally in Germany?

Modding in EULAs and contracts – what applies legally in Germany?

8. September 2025
Arbitration agreements in EULAs and developer contracts

Arbitration agreements in EULAs and developer contracts

7. September 2025
Chain of title in game development: building a clean chain of rights

Chain of title in game development: building a clean chain of rights

6. September 2025
Fail-fast clauses in media productions – what are they actually?

Fail-fast clauses in media productions – what are they actually?

5. September 2025
Founder’s agreement vs. shareholder agreement: setting the course for startups at an early stage

Founder’s agreement vs. shareholder agreement: setting the course for startups at an early stage

12. August 2025
Cheat software without code intervention: What the BGH really decided in the Sony ./. Datel case (I ZR 157/21)

Cheat software without code intervention: What the BGH really decided in the Sony ./. Datel case (I ZR 157/21)

11. August 2025
Digital integrity as a (new) fundamental right: status in Germany and the EU in 2025

Digital integrity as a (new) fundamental right: status in Germany and the EU in 2025

10. August 2025
European Economic Interest Grouping (EEIG)

EU Digital Decade 2030: Data law, Data Act & eIDAS 2 – what needs to be implemented in 2025

8. August 2025
Upload filters between copyright and personal rights

Upload filters between copyright and personal rights

7. August 2025
On-demand transmission right in the digital space: streaming, Section 19a UrhG and licensing

On-demand transmission right in the digital space: streaming, Section 19a UrhG and licensing

6. August 2025
Q&A: Legal issues for game developers

5-day guide: Founding a game development studio

5. August 2025
  • Mehr als 3 Millionen Wörter Inhalt
  • |
  • info@itmedialaw.com
  • |
  • Tel: 03322 5078053
Kurzberatung
Rechtsanwalt Marian Härtel - ITMediaLaw

No products in the cart.

  • en English
  • de Deutsch
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
Rechtsanwalt Marian Härtel - ITMediaLaw

Schleswig-Holstein Higher Regional Court: Liability for falsified e-mails with invoices

5. February 2025
in Law on the Internet
Reading Time: 5 mins read
0 0
A A
0
e rechnungspflicht ab 2025 bmf konkretisiert vorgaben

Recently, I have been working on a large number of cases involving hacked email servers and relevant financial amounts. Invoices are often manipulated so that payments are made to false accounts. These cases are particularly sensitive, as there is often a lack of clear precedents and technical expertise and careful legal analysis are crucial. I have already referred to the problem of fake invoices and false IBAN transfers in previous articles, in particular in the articles Fake invoices and false IBAN transfers and Fake invoices with a false IBAN – What to do if you have fallen for fraudsters?

Content Hide
1. Background to the case
2. Liability under the GDPR and BGB
3. Safety measures and practice
4. Conclusion and recommendation for action
4.1. Author: Marian Härtel
Key Facts
  • Manipulated invoices often result in payments to false accounts, which leads to complex legal challenges.
  • The Higher Regional Court of Schleswig-Holstein ruled that payments to false accounts do not constitute performance if the invoice was altered without authorization.
  • Companies must demonstrate sufficient security measures to protect personal data, especially in the case of financial risks.
  • End-to-end encryption is seen as a necessary measure for the protection of e-mail traffic.
  • A breach of the GDPR requires proof and evidence of the security measures taken by the controller.
  • Customers must check invoices; contributory negligence can reduce claims for damages.
  • The ruling serves as an important precedent for the liability of companies in the event of digital manipulation.

Background to the case

In a recent ruling, the Higher Regional Court of Schleswig-Holstein decided that the payment of an amount to an incorrect account does not constitute fulfilment of the payment obligation if the invoice has been altered without authorization. However, the customer can assert a claim for damages that may arise from Art. 82 GDPR if the company has breached its obligations under the GDPR. In addition to the GDPR, a claim for damages under Section 280 of the German Civil Code (BGB) can often also be considered, as this may involve a breach of contractual obligations.

The Higher Regional Court corrected the judgment of the Regional Court by stating that the payment to the wrong account did not have a fulfillment effect. This is due to the fact that the creditor did not receive the amount for free disposal. Performance by payment to a third party pursuant to Section 362 (2) of the German Civil Code (BGB) is only given if the creditor is legally authorized by the creditor to receive the payment in his own name. As this was not the case, the payment obligation remained in place.

A central point of the decision is the question of whether the company has taken sufficient security measures to protect the personal data from unauthorized access. The court emphasizes that pure transport encryption is not sufficient when sending emails containing personal data, especially where there is a high financial risk. Instead, end-to-end encryption is recommended as an appropriate measure. Companies must prove that they have taken appropriate security measures to protect personal data in accordance with the level of security required by the GDPR.

The Higher Regional Court found that a breach of the provisions of the GDPR cannot be assumed simply because unauthorized access to personal data has taken place. Rather, the controller must demonstrate and prove that the security measures taken were suitable to protect the personal data from unauthorized access. The requirements for the security measures depend on the risks associated with the processing and must be assessed individually.

In this case, the Higher Regional Court ruled that the plaintiff had substantiated that it had taken sufficient minimum protection measures in the form of SMTP via TLS for email traffic with contractual partners. However, this submission was disputed by the defendant. However, the court did not see sufficient evidence of a breach of duty by the plaintiff that would have been causal for the defendant’s damage. However, contributory negligence on the part of the customer could be relevant if the manipulated invoice differed from previous invoices.

The Higher Regional Court’s decision underlines the importance of appropriate security measures in digital business transactions. Companies must ensure that they take sufficient measures to protect personal data, especially when it comes to sensitive information such as bank details. Failure to do so may result in claims for damages under the GDPR or the German Civil Code.

Liability under the GDPR and BGB

A claim for damages under Art. 82 GDPR presupposes that the processing of personal data culpably violated the provisions of the GDPR, the data subject suffered damage and there is a causal link between the unlawful processing and the damage. In addition to the GDPR, Section 280 of the German Civil Code (BGB) may also be relevant if the company has breached its contractual obligations by failing to provide sufficient protection against manipulation.

The decision of the Higher Regional Court shows that liability under the GDPR is not automatically given if unauthorized access to personal data takes place. Rather, the controller must prove that it has taken all reasonable measures to protect the data. End-to-end encryption is considered the standard for protecting personal data in email traffic.

A claim for damages under Section 280 BGB requires that the company has breached a contractual obligation and that this breach was causal for the damage. In cases of invoice manipulation, this may mean that the company did not provide sufficient protection against unauthorized access to emails. The burden of proof for a breach of duty generally lies with the injured party, unless there are indications that the company was at fault.

The decision of the Higher Regional Court also emphasizes that contributory negligence on the part of the customer can be taken into account in accordance with Section 254 BGB if the customer has not sufficiently checked the manipulated invoice. This can significantly reduce the claim for damages.

Safety measures and practice

The Higher Regional Court emphasizes that pure transport encryption is not sufficient when sending emails with personal data, especially if there is a high financial risk. End-to-end encryption is recommended as an appropriate measure. Companies must prove that they have taken appropriate security measures to protect personal data from unauthorized access.

The decision underlines the importance of adequate security measures in digital business transactions and serves as an important precedent for the liability of companies in such cases. Companies should regularly review and adapt their security measures to ensure that they comply with the requirements of the GDPR.

In practice, this means that companies should not only rely on transport encryption, but must also ensure that the entire communication chain is secured. This can be achieved by implementing end-to-end encryption solutions that ensure that only the authorized recipient can read the message.

In addition, companies should conduct regular training for their employees to ensure that they are familiar with the security measures and know how to react to suspicious emails. A well-thought-out security concept can help to minimize liability in the event of manipulation.

Conclusion and recommendation for action

The decision of the Schleswig-Holstein Higher Regional Court underlines the importance of appropriate security measures in digital business transactions. Companies are obliged to take suitable measures to protect their customers from manipulation. Failure to do so may result in claims for damages under the GDPR or the German Civil Code (BGB). This decision serves as an important precedent for the liability of companies in such cases, with many affected parties referring to the judgment of the Karlsruhe Higher Regional Court of July 27, 2023 (19 U 83/22), which is not always applicable. Such cases often reveal a lack of technical knowledge on the part of judges, who do not fully grasp the complexity of digital security measures. It is therefore crucial that those affected consult a lawyer who has both legal and technical expertise.

If you have paid a counterfeit invoice and are now being asked to pay again because the first payment did not have a fulfillment effect, you should contact me. With my experience and access to technical experts, I can ensure that all relevant aspects are taken into account to effectively represent your rights. Together, we can successfully assert your claims and ensure that you receive the compensation to which you are entitled. Do not hesitate to contact me to protect your interests in the best possible way.

 

Marian Härtel
Author: Marian Härtel

Marian Härtel ist Rechtsanwalt und Fachanwalt für IT-Recht mit einer über 25-jährigen Erfahrung als Unternehmer und Berater in den Bereichen Games, E-Sport, Blockchain, SaaS und Künstliche Intelligenz. Seine Beratungsschwerpunkte umfassen neben dem IT-Recht insbesondere das Urheberrecht, Medienrecht sowie Wettbewerbsrecht. Er betreut schwerpunktmäßig Start-ups, Agenturen und Influencer, die er in strategischen Fragen, komplexen Vertragsangelegenheiten sowie bei Investitionsprojekten begleitet. Dabei zeichnet sich seine Beratung durch einen interdisziplinären Ansatz aus, der juristische Expertise und langjährige unternehmerische Erfahrung miteinander verbindet. Ziel seiner Tätigkeit ist stets, Mandanten praxisorientierte Lösungen anzubieten und rechtlich fundierte Unterstützung bei der Umsetzung innovativer Geschäftsmodelle zu gewährleisten.

Weitere spannende Blogposts

Esport Teams, “Freelancers” and the Federal Labor Court

Artikel zu welchen Themen sind interessant?
7. November 2022

In line with my article from yesterday regarding possible reclaim claims from clients against contractors, I received an inquiry from...

Read moreDetails

New law firm page

New law firm page
7. November 2022

The past year was more than exciting and full of changes. A lot has changed, both privately and corporately. In...

Read moreDetails

LG Hamburg on Influencer Advertising and “Sponsored Content”

Brief reminder: Influencer as target of warning letters
24. May 2019

The problem of influencer sneaking advertising The District Court of Hamburg agrees with the rulings on influencers and sneaky advertising....

Read moreDetails

Landmark court case: AI training vs. copyright

Landmark court case: AI training vs. copyright
13. August 2024

Introduction: A precedent with far-reaching consequences The case of Robert Kneschke against LAION e.V. marks a milestone in the legal...

Read moreDetails

Program your own shopping area: Beware the fallacy of independence!

Program your own shopping area: Beware the fallacy of independence!
3. July 2023

Today I'd like to share an insight that just caught my eye while I was working. As a lawyer involved...

Read moreDetails

Webinar on DE-minimis computer game promotion

Webinar on DE-minimis computer game promotion
7. November 2022

On June 14, the Federal Ministry of Transport and Digital Infrastructure will offer a webinar on de minimis funding from...

Read moreDetails

Accessibility Reinforcement Act: What start-ups, self-employed people and online stores need to know

law 447487 1280
20. December 2024

The Accessibility Strengthening Act (BFSG), which comes into force on June 28, 2025, brings with it significant legal obligations for...

Read moreDetails

Is the unpredictability of AI outcomes a legal time bomb?

shutterstock 1889907112 scaled
12. August 2023

Through two recent mandates and some conversations in the last few days, I became aware of a fascinating legal issue...

Read moreDetails

Reporting obligations under the Foreign Trade and Payments Act (AWG): A guide for startups and blockchain companies

Reporting obligations under the Foreign Trade and Payments Act (AWG): A guide for startups and blockchain companies
4. June 2023

Introduction Recently, an interesting issue was brought to my attention by a tax accountant friend. Over a cup of coffee,...

Read moreDetails
ChatGPT and lawyers: recordings of the Weblaw launch event
Law on the Internet

Private AI use in the company

24. October 2025

Private accounts on ChatGPT & Co. for corporate purposes are a gateway to data protection breaches, leaks of secrets and...

Read moreDetails
Lego brick still protected as a design patent

App purchases, in-app purchases and sales tax

21. October 2025
dsgvo 1

What belongs in a DPA? Data processing agreement in accordance with Art. 28 GDPR

17. October 2025
Smart contracts in the insurance industry: contract design and regulatory compliance for InsurTech start-ups

Contract for work vs. service contract in software, AI and games projects

15. October 2025

Influencer contract: performance profile, rights/buyouts, labeling and AI content

13. October 2025

Podcastfolge

092def0649c76ad70f0883df970929cb

Influencers and gaming: legal challenges in the digital entertainment world

26. September 2024

In this captivating episode, lawyer Marian Härtel takes listeners on an exciting journey through the dynamic world of influencers and...

Read moreDetails
238a909c26a0302cbd4792cbd18e4922

Global challenges for start-ups – A legal guide

10. October 2024
7c0b449a651fe0b81e5eec2e23515012 2

Copyright in the digital age

15. January 2025
86fe194b0c4a43e7aef2a4773b88c2c4

On the dark side? A lawyer in the field of tension of innovative start-ups

26. September 2024
247f58c28882e230e982fa3a32d34dea

Digital sovereignty: Europe’s path to a self-determined digital future

8. December 2024

Video

My transparent billing

My transparent billing

10. February 2025

In this video, I talk a bit about transparent billing and how I communicate what it costs to work with...

Read moreDetails
Fascination between law and technology

Fascination between law and technology

10. February 2025
My two biggest challenges are?

My two biggest challenges are?

10. February 2025
What really makes me happy

What really makes me happy

10. February 2025
What I love about my job!

What I love about my job!

10. February 2025
  • Privacy policy
  • Imprint
  • Contact
  • About lawyer Marian Härtel
Marian Härtel, Rathenaustr. 58a, 14612 Falkensee, info@itmedialaw.com

Marian Härtel - Rechtsanwalt für IT-Recht, Medienrecht und Startups, mit einem Fokus auf innovative Geschäftsmodelle, Games, KI und Finanzierungsberatung.

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • en English
  • de Deutsch
Kostenlose Kurzberatung