Ailance Alt TM Logo
Ailance Alt TM Logo

Data protection damages and tax evader CD

Data protection tax evader CD

Does the agency have to comply with data protection regulations regarding the tax evader CD?

Imagine the following hypothetical scenario: German federal agencies purchase a CD containing personal data on actual and/or alleged tax evaders.

The seller, for example, is a bank employee who unlawfully stored personal banking data from the bank’s systems and offered it for sale to the tax authorities. Based on this data, criminal tax proceedings are later initiated and back taxes are assessed. Under data protection law, the general rule is that the collection, Processing and the use of personal data only within the scope of a narrow Earmarking is permissible (§ 28 BDSG).

The Transmission and while the use of such data for another purpose is permitted for the purpose of Criminal offenses In principle, this is also permissible. However, criminal prosecution is subject to formal proceedings. Therefore, if there is reasonable initial suspicion, a formal investigation is usually initiated.

Earmarking Funds from the Tax Evader CD?

However, this was not the case for the individuals whose data was included in the database. The data was therefore not purchased as part of a specific criminal investigation, so that the Transmission and the use of the data would be impermissible. The impermissible collection or use of personal data renders the responsible However, the agency is liable for damages (Section 7 of the Federal Data Protection Act).

This means that any financial disadvantages suffered by the Affected parties – in this case, the bank customer – as a result of the unauthorized collection of data, -processing or use constitutes compensable damage. If multiple parties, such as a bank or bank employees, have acted unlawfully, they are jointly and severally liable. In this regard, the question arises as to whether affected Tax evaders may be able to hold the tax authorities—as the purchaser of the data CD—liable for damages, since fiscal interests do not constitute a valid reason under § 28(3) of the Federal Data Protection Act (BDSG) for the strict Earmarking of the acquired bank data.

In addition to procedural costs and fines, compensation for pain and suffering may also need to be considered as a form of damages, as provided for in various state data protection laws. Affected parties and consultants will not overlook the data protection aspects when it comes to defending against claims or establishing grounds for recourse. Companies take appropriate measures early on to protect themselves against data theft and are aware of the risk of data misuse by employees. Some companies maintain data sets that are used for Third are of interest and whose sale could be a major temptation for employees. Even in the event of a data breach, a company must expect claims from those affected if it has not taken appropriate security measures.

Federal Constitutional Court: Information from Purchased Tax CDs May Be Used

The assessment of the purchase of so-called „tax CDs“ under data protection law must also be considered in light of subsequent case law. The Federal Constitutional Court has with Decision of November 9, 2010 (Case No. 2 BvR 2101/09) ruled that the use of bank data obtained unlawfully by private individuals may, in principle, be admissible in criminal tax proceedings.

In the court’s view, the unlawful collection of data by a private informant does not automatically result in a prohibition on the use of that evidence. What is particularly decisive is that the government authorities did not themselves obtain the data unlawfully or instigate the informant’s actions.

The decision shows that a distinction must be made between the lawfulness of data collection under data protection law, on the one hand, and the admissibility of the information obtained in criminal proceedings, on the other. Even if the original data collection was unlawful, this does not necessarily mean that the data is inadmissible or that there is a claim for damages against the tax authorities.

Update 2026: Damages under Article 82 of the GDPR

Since the entry into force of the GDPR Under data protection law, damages are primarily determined in accordance with Article 82 GDPR. According to this, both property damage and non-property damage may be eligible for compensation. A mere Infringement against the GDPR However, this is not sufficient to establish a claim for damages. What is required is a Infringement against the GDPR, actual damage, and a causal link between the two. The European Court of Justice has also clarified that, in the case of non-pecuniary damages, there is no specific threshold of materiality that must be met.

The loss of control over personal data or a well-founded fear of future abuse may, in principle, constitute non-pecuniary damage. A merely hypothetical fear, however, is not sufficient; the affected A person must be able to demonstrate that actual damage has occurred.

What significance do „tax evader CDs“ still have today?

The practical significance of traditional tax CDs has changed considerably since 2010. Germany now participates in the automatic international exchange of information on financial accounts under the Common Reporting Standard (CRS). Since the 2016 reporting period, German financial institutions have been submitting the account information required by law to the Federal Central Tax Office, which exchanges this information with participating countries. More than 100 countries now participate in this process.

Nevertheless, the central question raised in that article remains relevant today: What are the consequences if personal data obtained unlawfully and subsequently used by authorities or courts? In June 2026, the European Court of Justice once again clarified that personal data are not automatically excluded as evidence merely because they were originally obtained unlawfully. Although the specific case involved labor court proceedings rather than tax data, the decision underscores the necessary distinction between the legality of data collection under data protection law and the admissibility of evidence in court proceedings.

Picture of Marcus Belke

Marcus Belke

Marcus Belke is the CEO of 2B Advice GmbH. He drives innovation in data protection compliance and risk management and is responsible for the further development of Ailance, the next-generation compliance platform.

Share this post:

Data protection damages and tax evader CD