Aristotelis Zervos
Aristotelis Zervos, Editorial Director at 2B Advice, combines legal and journalistic expertise in Data protection, IT-Compliance and AI regulation.
A recent ruling by the Federal Court of Justice (BGH) provides clarity with regard to non-material damages pursuant to Art. 82 GDPR in the event of a data leak at a former processor. The following article analyzes the key statements of the ruling.
Data leak from processor after contract ends
In the so-called Deezer data leak, data from users of the music streaming service of the same name was stolen after the end of the contract with an external service provider and offered for sale on the darknet.
The specific facts of the case: The defendant, which is headquartered in France, operates an online music streaming service. Until the contract ended on December 1, 2019, the defendant’s external data processor was the company O. On November 30, 2019, O. notified the defendant by email that its website and the data stored there (“your site and all the data on the site”) would be deleted the following day. Company O. first confirmed that this had in fact occurred in an email dated February 22, 2023. It had previously come to light that, since November 2022, unknown hackers had been offering data from users of the defendant’s service for sale on the dark web. The data records dated back to 2019. They had not been deleted by Company O. immediately after the end of the contract, as agreed with the defendant, but had been transferred by employees of Company O. from the production environment to a test environment and subsequently either stolen by hackers or disclosed without authorization by employees of Company O. The defendant notified the individuals affected by the incident after it came to light.
The plaintiff is a user of the defendant’s service. His data is stored in the defendant’s customer profile. The data record accessed during the incident at issue contained the plaintiff’s first name, last name, gender, email address, and language, as well as the registration date.
While the Regional Court and the Higher Regional Court initially dismissed the lawsuit, the Federal Court of Justice (BGH) partially overturned the ruling and remanded the case to the Dresden Higher Regional Court for a new decision.
The person responsible must be able to provide documented confirmation of deletion
The BGH clarifies that the Responsible persons even after engaging external processors, the organization remains the „data controller“ and cannot simply shift its data protection obligations onto the service provider. In particular, at the end of the Order processing he must actively ensure that the former processor no longer retains any personal data. It is therefore not sufficient to merely conclude a contract in accordance with Art. 28 GDPR and rely on the service provider's promise of deletion. Instead, specific exit management measures are required. For example, it must be contractually regulated and practically verified that all transferred data is returned or deleted and that any copies are also deleted.
According to the Federal Court of Justice, an active deletion check is crucial: The Responsible persons must not be satisfied with mere contractual assurances, but must take the necessary steps to ensure that the data is actually deleted.
In practice, this means obtaining an explicit and documented confirmation of deletion from the service provider, rather than simply accepting a non-binding email notification. This could be, for example, a deletion log, a written statement, or a Audit-proof.
Failure to Supervise the Data Processor Results in Liability
In this case, the contract required confirmation of deletion within 21 days. The data processor had merely stated that it would delete the „website and all data.” The completion of this action was never confirmed.
At the latest upon the expiration of the deadline, the Responsible persons to follow up. Only years later and after the leak became known did he do so, far too late. In doing so, he violated the principles of storage limitation and security from Art. 5 para. 1 lit. e and Art. 32 GDPR, which is governed by Art. 28 para. 3 lit. g GDPR be concretized, since an inadmissible continued storage at the processor took place.
The Federal Court of Justice (BGH) considers this failure to act to be a separate GDPR-Infringement of the controller. Because, pursuant to Article 82(3) GDPR carries the Responsible persons the burden of proof that it was not at fault. The defendant company was unable to exonerate itself in this case, as it could be accused of at least slight negligence in its deletion checks. In particular, it did not help to point to misconduct on the part of the service provider alone or to a hacker attack. Precisely because the Responsible persons failed to obtain timely confirmation of deletion, the data remained accessible and was able to fall into the wrong hands in the first place. According to the court’s findings, the data breach would most likely have been prevented had proper controls been in place. The Responsible persons is therefore also liable for the data breach, even if the direct attack was carried out by an outsider.
No de minimis threshold for compensation for non-pecuniary damages (Art. 82 of the GDPR)
When assessing damages, the BGH refers to the case law of the ECJ on the interpretation of Art. 82 GDPR to.
First, the court confirms that a Infringement against the GDPR alone does not give rise to a claim for damages. Damage must actually have occurred. However, the BGH also emphasizes that there is no „de minimis limit“. In other words: Neither national law nor the courts may require an additional materiality threshold for immaterial damage if European data protection law does not provide for such a threshold. Any demonstrable impairment such as annoyance, displeasure, worry or fear that arises as a result of a data protection breach can therefore be compensable, provided that it is not merely based on imagination or a purely hypothetical danger.
In its judgment of May 4, 2023 (Case C-300/21), the ECJ expressly clarified that negative feelings such as anger, discomfort or fear under Art. 82 para. 1 GDPR can be recognized as immaterial damage. There is no specific materiality threshold. Consequently, courts may not dismiss a claim on the grounds that it is merely a matter of „everyday annoyance on the internet“.
In the present case, the appellate court (OLG Dresden) had argued exactly that way and dismissed the plaintiff’s concerns as general life risks. The Federal Court of Justice (BGH) corrected this and made it unmistakably clear that an actual loss of control and well-founded fears of misuse must be taken seriously—regardless of whether the plaintiff’s same data had already been compromised in previous incidents.
Reading tip: Facebook Scraping – Federal Court of Justice Awards Damages to Users
Darknet Data Breach as an Objective Criterion for the Occurrence of Damage
A central feature of the case was the publication of the data on the darknet. The BGH states that the offering of stolen personal data on the darknet is an objective indicator of the occurrence of damage. In concrete terms, this means If data remains with the service provider without authorization after the end of the order, is stolen there and then offered for sale on the darknet, this constitutes non-material damage within the meaning of Art. 82 para. 1 GDPR before. The judges expressly state that this damage does not disappear because the same data may have been disclosed earlier in another leak. Any new loss of control over personal data is therefore to be regarded as an independent event that increases the risk for the affected person and can therefore be separately relevant to damage.
In the Deezer case, the plaintiff’s email address had indeed already appeared in previous data breaches. Nevertheless, the Federal Court of Justice (BGH) considers the 2019/2022 incident to be a new, separate breach: As a result of the specific leak at the data processor, additional information (name, gender, language, Usage data) were made public in connection with the email address. This additional data pool on the darknet creates a considerable risk situation, as criminals can use it to create targeted profiles for Phishing or identity theft. Previous hacks in no way exonerate the person responsible. On the contrary: multiple leaks from the same data subject mean cumulative risks and a higher probability of future misuse. Companies can therefore not defend themselves by claiming that an affected person is not additionally burdened by another leak because their data was already in circulation anyway.
From the Federal Court of Justice’s perspective, a darknet leak thus marks a clear turning point: Damage has occurred at the latest upon the illegal publication on the dark web. In practice, courts will regularly award compensation for non-pecuniary damages in such cases. The sale of personal data on the darknet represents the „worst-case scenario“ in terms of data breaches.
Loss of control and well-founded fears as non-pecuniary damages
In previous cases—such as those involving Facebook data breaches—the Federal Court of Justice (BGH) has already ruled that the mere loss of control over personal data may constitute non-pecuniary damage. Even in the absence of specific financial loss, the distress and sense of vulnerability following a data breach may justify compensation. In this latest ruling, the Federal Court of Justice (BGH) goes one step further and places the focus on the personal fears of the affected individual.
The plaintiff had claimed that he had been worried about identity theft since the leak became known, Phishing and unsolicited advertising calls and emails. In the opinion of the BGH, such justified fears can „in themselves” constitute non-material damage, provided that the Affected parties which plausibly outlines their negative consequences. The key point is that these fears are not purely hypothetical, but objectively verifiable. That was precisely the case here: If a name and email address are traded on the dark web, it is very likely that they will be used for fraudulent purposes (e.g., spam or Phishing(e-mails). From the perspective of a reasonable third party, the plaintiff’s concerns were therefore entirely understandable and based on realistic grounds.
The Higher Regional Court had argued against the plaintiff, stating that he had not changed his email address despite the incidents, which suggested that he was not experiencing serious distress. The Federal Court of Justice rejected this argument as a flawed approach that amounts to an impermissible threshold of materiality. This is because even without outward reactions such as changing an email address, an affected individual may experience significant internal distress. What is decisive are verifiable psychological effects (e.g., persistent anxiety, sleep disturbances, stress). In conclusion, the BGH clarified that the loss of control over one’s own data, combined with a well-founded fear of misuse, constitutes compensable non-pecuniary damage in this specific case. The lower court’s contrary assessment was therefore legally erroneous.
Interest in a declaratory judgment regarding potential future damages
In addition to the damages themselves, the plaintiff’s motion for a declaratory judgment was a key issue in the proceedings. He sought a court ruling that the defendant company would also be liable for any future financial losses resulting from the data breach. The background to this is the uncertainty as to whether stolen data might lead to financial losses years later—for example, if it is used for fraud on the dark web. The Dresden Higher Regional Court ruled that there was no legitimate interest in such a declaration, noting, among other things, that a considerable amount of time had passed and that proving causation at a later date could be difficult.
The Federal Court of Justice (BGH), however, takes a different view and criticizes the lower court’s rejection of the interest in a declaratory judgment. It points out that in cases involving the violation of absolute rights (such as the right to data protection, Art. 8 of the Charter of Fundamental Rights of the European Union), the mere possibility of future harm is sufficient to establish an interest in a declaratory judgment. A high probability of such harm occurring is not required. Even if several years have passed since the incident, this does not rule out the possibility of subsequent misuse of the data. In particular, the presence of personal data on the dark web objectively establishes the possibility of future harm—for example, through identity theft—even years after the leak.
The BGH clarifies that considerations of decreasing probability of occurrence or difficulties of proof in the future affect at most the prospects of success of a later action for performance, but not the admissibility of the declaratory action. In other words: Whether the Affected parties The question of whether the claimant will be able to prove the specific damage in the future is of secondary importance in the declaratory proceedings. Rather, it is important to give him the opportunity to secure his rights now in the event of damage occurring. Consequently, the BGH deemed the application for a declaratory judgment in the Deezer case to be admissible and instructed the Higher Regional Court to make a new decision in this regard.
For Affected parties This means that they do not have to wait until material damage actually occurs after a data leak. As a precautionary measure, you can have a court declare that the Responsible persons is liable for any future damages.
Strengthening Compliance Measures Is Becoming Increasingly Important
The BGH ruling on the Deezer data leak has significant practical consequences. Responsible persons Organizations are encouraged to Compliance-Measures related to data protection and Order processing to strengthen. In particular, exit management for service providers is coming into focus: Companies must ensure that, when a data processor is deactivated, all personal data is properly deleted or returned. A documented confirmation of deletion from the service provider is mandatory, not optional. Failures in this area can lead to liability issues years later.
At the same time, the ruling makes it clear that darknet-related data leaks represent a significantly increased liability risk. If stolen data appears on the darknet, the BGH believes that this almost inevitably results in compensable immaterial damage. Affected parties can invoke loss of control and understandable fears of abuse without the Responsible persons can dismiss these as mere trifles. Companies should therefore take preventive security measures in accordance with Art. 32 GDPR regularly, consider darknet monitoring by specialized services if necessary and have prepared incident response plans, including a communication strategy and how to deal with Art. 82 claims, in case of an emergency.
Ultimately, the ruling shows that even past data breaches do not provide a free pass. Each new incident can give rise to separate claims and increases the cumulative risk of misuse. Responsible persons would do well to take known multiple leaks seriously and assume an increased risk potential instead of hoping for relief. They must also expect that Affected parties in addition to specific damages, also assert a declaratory claim for future damages. In practice, this means that long-term risk management and, if necessary, financial precautions (provisions, cyber insurance) are becoming increasingly important.
Source: Federal Court of Justice (BGH) Decision of November 11, 2025 – VI ZR 396/24
Would you like to ensure that your data processing operations are „BGH-compliant,“ particularly during the offboarding process?
This is exactly where data breaches often occur in practice: there are no deletion confirmations, copies remain in test/staging environments, responsibilities are unclear, and documentation is incomplete.
Ailance supports you in managing your AV landscape in a structured manner: from the selection and evaluation of service providers to the audit-proof exit checklist, including verification of the complete AV landscape. Deletion.
2B Advice provides you with legal and operational support: We review and optimize your order processing contracts (Art. 28 GDPR), develop practical Technical and organizational measures (TOM) and offboarding processes, support you in incident response (incl. communication, management of affected parties and authorities) and help you to minimize the risk of claims under Art. 82 GDPR.
Get started now: Let’s schedule a brief meeting to identify where your biggest risks lie in your vendor and offboarding processes and how you can address them with clear controls, reliable deletion confirmations, and clean Documentation quickly reach a resilient level.
Aristotelis Zervos is Editorial Director at 2B Advice, a lawyer and journalist with profound expertise in data protection, GDPR, IT-Compliance and AI governance. He regularly publishes in-depth articles on AI regulation, GDPR-Compliance and risk management. You can learn more about him on his Author profile page.





