{"id":43192,"date":"2026-01-14T19:30:13","date_gmt":"2026-01-14T17:30:13","guid":{"rendered":"https:\/\/2b-advice.com\/?p=43192"},"modified":"2026-04-14T14:41:16","modified_gmt":"2026-04-14T12:41:16","slug":"failure-to-monitor-processors-bgh-extends-liability-of-the-responsible-party","status":"publish","type":"post","link":"https:\/\/2b-advice.com\/en\/2026\/01\/14\/unterlassene-kontrolle-von-auftragsverarbeiter-bgh-weitet-haftung-des-verantwortlichen-aus\/","title":{"rendered":"Failure to monitor processors: BGH extends liability of the controller"},"content":{"rendered":"<div data-elementor-type=\"wp-post\" data-elementor-id=\"43192\" class=\"elementor elementor-43192\" data-elementor-post-type=\"post\">\n\t\t\t\t<div class=\"elementor-element elementor-element-b9288e4 e-flex e-con-boxed e-con e-parent\" data-id=\"b9288e4\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-1f7dedc elementor-widget elementor-widget-author-box\" data-id=\"1f7dedc\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"author-box.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-author-box\">\n\t\t\t\t\t\t\t<a href=\"http:\/\/2b-advice.com\/en\/aristotelis-zervos\/\" class=\"elementor-author-box__avatar\">\n\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/2b-advice.com\/wp-content\/uploads\/2025\/09\/aristotelis-zervos-sq-300x300.jpg\" alt=\"Picture of Aristotelis Zervos\" loading=\"lazy\">\n\t\t\t\t<\/a>\n\t\t\t\n\t\t\t<div class=\"elementor-author-box__text\">\n\t\t\t\t\t\t\t\t\t<a href=\"http:\/\/2b-advice.com\/en\/aristotelis-zervos\/\">\n\t\t\t\t\t\t<h4 class=\"elementor-author-box__name\">\n\t\t\t\t\t\t\t Aristotelis Zervos\t\t\t\t\t\t<\/h4>\n\t\t\t\t\t<\/a>\n\t\t\t\t\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-author-box__bio\">\n\t\t\t\t\t\t<p>Aristotelis Zervos, Editorial Director at 2B Advice, combines legal and journalistic expertise in <a href=\"https:\/\/2b-advice.com\/en\/marcus-belke\/\">Data protection<\/a>IT compliance and AI regulation.<\/p>\n\t\t\t\t\t<\/div>\n\t\t\t\t\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-cca288c elementor-widget elementor-widget-text-editor\" data-id=\"cca288c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>A recent ruling by the Federal Court of Justice (BGH) provides clarity regarding non-material damages pursuant to Art. 82 GDPR in the event of a data leak at a former processor. The following article analyzes the key statements of the ruling.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f48c475 elementor-widget elementor-widget-heading\" data-id=\"f48c475\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Data leak from processor after contract ends<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-907e862 elementor-widget elementor-widget-text-editor\" data-id=\"907e862\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>In the so-called Deezer data leak, data from users of the music streaming service of the same name was stolen after the end of the contract with an external service provider and offered for sale on the darknet.<\/p><p>The specific facts of the case: The defendant, which is based in France, operates an online music streaming service. Until the end of the contract on December 1, 2019, the defendant's external processor was the company O. On November 30, 2019, it informed the defendant by email that its website and the data on it (\u201cyour site and all the data on the site\u201d) would be deleted the following day. Company O. first declared that this had actually happened in an email dated February 22, 2023, after it had become known that unknown hackers had been offering data from users of the defendant's service for sale on the darknet since November 2022. The data records were from 2019 and had not been deleted by the company O. immediately after the end of the order, as agreed with the defendant, but had been transferred from the production environment to a test environment by employees of the company O. and then either captured by hackers or passed on by employees of the company O. without authorization. The defendant informed the persons affected by the incident after it became known.<\/p><p>The plaintiff is a user of the defendant's service. His data is stored in the defendant's customer profile. The data record accessed in the incident at issue contained the plaintiff's first name, surname, gender, email address and language as well as the date of registration.<\/p><p>While the Regional Court and the Higher Regional Court initially dismissed the action, the BGH partially overturned the judgment and referred it back to the Higher Regional Court of Dresden for a new decision.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-363cfa8 elementor-widget elementor-widget-heading\" data-id=\"363cfa8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Responsible party must be able to provide documented confirmation of deletion<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3173cf9 elementor-widget elementor-widget-text-editor\" data-id=\"3173cf9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The BGH clarifies that the controller remains the \u201emaster of data processing\u201c even after commissioning external processors and cannot simply pass on its data protection obligations to the service provider. In particular, at the end of the commissioned processing, the controller must actively ensure that no personal data remains with the former processor. It is therefore not sufficient to simply conclude a contract in accordance with Art. 28 GDPR and rely on the service provider's promise of erasure. Rather, concrete exit management measures are required. For example, it must be contractually regulated and practically verified that all data provided is returned or deleted and that any copies are also deleted.<\/p><p>According to the BGH, active deletion control is crucial: the controller must not be satisfied with mere contractual assurances, but must do what is necessary to ensure that the data is actually deleted.<\/p><p>In practice, this means obtaining an explicit and documented deletion confirmation from the service provider instead of just accepting a non-binding email announcement. This can be, for example, a deletion log, a written declaration or an audit certificate.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-fd9227f elementor-widget elementor-widget-heading\" data-id=\"fd9227f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Failure to monitor the processor leads to liability<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f215907 elementor-widget elementor-widget-text-editor\" data-id=\"f215907\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>In this case, the contract provided for confirmation of deletion within 21 days. The processor had only announced that it would delete the \u201ewebsite and all data\u201d. Completion was not confirmed at any time.<\/p><p>After the deadline expired at the latest, the person responsible failed to follow up.  Only years later and after the leak became known did he do so, far too late. In doing so, he violated the principles of storage limitation and security from Art. 5 para. 1 lit. e and Art. 32 GDPR, which are substantiated by Art. 28 para. 3 lit. g GDPR, as unauthorized continued storage by the processor took place.<\/p><p>The BGH considers this omission to be a breach of the GDPR on the part of the controller. According to Art. 82 para. 3 GDPR, the controller bears the burden of proof that it is not at fault. The defendant company could not exculpate itself here, as it could be accused of at least slight negligence in the deletion check. In particular, it did not help to point to the sole misconduct of the service provider or a hacker attack. It was precisely because the responsible party did not obtain confirmation of deletion in good time that the data remained available and could fall into the wrong hands in the first place. According to the court's findings, the data incident would very likely have been prevented if proper checks had been carried out. The responsible party is therefore also liable for the data leak, even if the direct attack was carried out by an outsider.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5d4650a elementor-widget elementor-widget-heading\" data-id=\"5d4650a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">No de minimis limit for non-material damages (Art. 82 GDPR)<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-891b7a4 elementor-widget elementor-widget-text-editor\" data-id=\"891b7a4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>When assessing the damages, the BGH refers to the case law of the ECJ on the interpretation of Art. 82 GDPR.<\/p><p>Firstly, the court confirms that a breach of the GDPR alone does not trigger a claim for damages. Damage must actually have occurred. However, the BGH also emphasizes that there is no \u201ede minimis limit\u201c. In other words: Neither national law nor the courts may require an additional materiality threshold for immaterial damage if European data protection law does not provide for such a threshold. Any demonstrable impairment such as annoyance, displeasure, worry or fear that arises as a result of a data protection breach can therefore be compensable, provided that it is not merely based on imagination or a purely hypothetical danger.<\/p><p>In its judgment of 4 May 2023 (Case C-300\/21), the ECJ expressly clarified that negative feelings such as anger, discomfort or fear can be recognized as non-material damage under Art. 82 (1) GDPR. There is no specific materiality threshold. Consequently, courts may not dismiss a claim on the grounds that it is only a matter of \u201eeveryday annoyance on the internet\u201c.<\/p><p>In this case, the court of appeal (Dresden Higher Regional Court) had argued in exactly the same way and dismissed the plaintiff's concerns as general risks of life. The BGH corrected this and made it unmistakably clear that a real loss of control and well-founded fears of misuse must be taken seriously. And this is irrespective of whether the plaintiff's data had already been compromised in previous incidents.<\/p><p>Reading tip: <a href=\"https:\/\/2b-advice.com\/en\/2024\/11\/18\/facebook-scraping-bgh-awards-users-damages\/\">Facebook scraping - BGH awards users damages<\/a><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-408e9b2 elementor-widget elementor-widget-heading\" data-id=\"408e9b2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Darknet data leak as an objective criterion for the occurrence of damage<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2d1f4fc elementor-widget elementor-widget-text-editor\" data-id=\"2d1f4fc\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>A central feature of the case was the publication of the data on the darknet. The BGH states that the offering of stolen personal data on the darknet is an objective indicator of the occurrence of damage. In concrete terms, this means If data remains with the service provider without authorization after the end of the order, is stolen there and then offered for sale on the darknet, this constitutes non-material damage within the meaning of Art. 82 para. 1 GDPR. The judges expressly state that this damage is not eliminated by the fact that the same data may have been disclosed earlier in another leak. Each new loss of control over personal data must therefore be regarded as an independent event that increases the risk for the data subject and can therefore be separately relevant to damages.<\/p><p>In the Deezer case, the plaintiff's email address had already appeared in previous data breaches. Nevertheless, the BGH assessed the 2019\/2022 incident as a new, independent breach: The specific leak at the processor made further information (name, gender, language, usage data) in connection with the email address public. This additional pool of data on the darknet creates a significant risk situation, as criminals can use it to create targeted profiles for phishing or identity theft. Previous hacks in no way exonerate those responsible. On the contrary: multiple leaks from the same person mean cumulative risks and a higher probability of future misuse. Companies can therefore not defend themselves by claiming that an affected person is not additionally burdened by another leak because their data was already in circulation anyway.<\/p><p>From the point of view of the BGH, a darknet leak thus marks a clear turning point: damage has occurred at the latest from the time of the illegal underground publication. In practice, courts will regularly affirm immaterial damages in such constellations. The sale of personal data on the darknet represents the \u201eworst case\u201c in terms of data breach.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-944c881 elementor-widget elementor-widget-heading\" data-id=\"944c881\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Loss of control and well-founded fears as immaterial damage<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-38093c3 elementor-widget elementor-widget-text-editor\" data-id=\"38093c3\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>In earlier proceedings, for example regarding Facebook data leaks, the Federal Court of Justice has already ruled that the mere loss of control over personal data can constitute immaterial damage. Even without concrete financial damage, the annoyance and feeling of being at the mercy of others following a data breach can justify compensation. In the current ruling, the BGH goes one step further and focuses on the personal fears of the person affected.<\/p><p>The plaintiff had claimed that he had been worried about identity theft, phishing and unsolicited advertising calls and emails since the leak became known. According to the BGH, such well-founded fears can \u201ein themselves\u201d constitute non-material damage, provided that the affected party can plausibly demonstrate their negative consequences. The decisive factor is that the fears are not purely hypothetical, but objectively comprehensible. This was precisely the case here: if the name and email address are traded on the darknet, it is very likely that they will be misused for fraudulent purposes (e.g. spam or phishing emails). The concerns felt by the plaintiff were therefore easily understandable and realistically justified from the perspective of a reasonable third party.<\/p><p>The OLG had argued against the plaintiff that he had not changed his email address despite the incidents, which argued against serious incrimination. The BGH rejected this argument as a misguided approach that amounts to an inadmissible materiality threshold. This is because even without external reactions such as an email change, a person can be under considerable internal stress. The decisive factor is demonstrable psychological effects (e.g. persistent anxiety, sleep disorders, stress). As a result, the BGH has clarified that the loss of control over one's own data in conjunction with the justified fear of misuse in the specific case constitutes compensable immaterial damage. The lower court's assessment to the contrary was therefore legally incorrect.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-41ee35e elementor-widget elementor-widget-heading\" data-id=\"41ee35e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Interest in declaratory judgment for possible future damages<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-cadcace elementor-widget elementor-widget-text-editor\" data-id=\"cadcace\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>In addition to the damages themselves, the plaintiff's application for a declaratory judgment was also important in the proceedings. He wanted the court to declare that the defendant company was also liable for any future material damage resulting from the data leak. The background to this is the uncertainty as to whether stolen data may only lead to financial losses years later, for example if it is used for fraud on the darknet. The Higher Regional Court of Dresden denied a legitimate interest in such a finding, stating, among other things, that a lot of time had passed and that it could be difficult to prove causality at a later date.<\/p><p>However, the BGH takes a different view and criticizes the lower court's rejection of the interest in a declaratory judgment. It points out that in the event of a violation of absolute rights (such as the right to data protection, Art. 8 CFR), the mere possibility of a future occurrence of damage is sufficient to affirm an interest in a declaratory judgment. A high probability of occurrence is not required. Even if several years have passed since the incident, this does not rule out the possibility of the data being misused at a later date. In particular, the existence of personal data on the darknet objectively justifies the possibility of future damage, for example through identity fraud, even years after the leak.<\/p><p>The BGH clarifies that considerations regarding a decreasing probability of occurrence or difficulties in providing evidence in the future only affect the prospects of success of a subsequent action for performance, but not the admissibility of the declaratory action. In other words, whether the affected party will be able to prove the specific damage in the future is of secondary importance in declaratory proceedings. Rather, it is important to give them the opportunity to secure their rights in the event of damage occurring. Consequently, the BGH deemed the application for a declaratory judgment in the Deezer case to be admissible and instructed the Higher Regional Court to make a new decision in this regard.<\/p><p>For those affected, this means that they do not have to wait until material damage actually occurs after a data leak. As a precautionary measure, they can have a court declare that the responsible party is liable for any future damages.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-acf9ea0 elementor-widget elementor-widget-heading\" data-id=\"acf9ea0\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Strengthening compliance measures increasingly important<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6e39a9f elementor-widget elementor-widget-text-editor\" data-id=\"6e39a9f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The BGH ruling on the Deezer data leak has significant practical consequences. Responsible bodies are required to strengthen their compliance measures in the area of data protection and order processing. In particular, the focus is shifting to exit management for service providers: companies must ensure that all personal data is properly deleted or returned when a processor is offboarded. A documented confirmation of deletion from the service provider is mandatory and not an option. Failures in this area can lead to liability cases years later.<\/p><p>At the same time, the ruling makes it clear that darknet-related data leaks represent a significantly increased liability risk. If stolen data appears on the darknet, the BGH believes that this almost inevitably results in compensable immaterial damage. Affected parties can invoke loss of control and understandable fears of misuse without the responsible party being able to dismiss these as mere trifles. Companies should therefore regularly review their security measures in accordance with Art. 32 GDPR as a preventative measure, consider darknet monitoring by specialized services if necessary and have prepared incident response plans, including a communication strategy and how to deal with Art. 82 claims, in case of an emergency.<\/p><p>Finally, the decision shows that even previous data breaches do not provide carte blanche. Each new incident can give rise to independent claims and increases the cumulative risk of misuse. Those responsible would do well to take known multiple leaks seriously and assume an increased risk potential instead of hoping for exoneration. They must also expect that those affected will assert a claim for declaratory judgment for future damages in addition to specific damages. In practice, this means that long-term risk management and, if necessary, financial precautions (provisions, cyber insurance) are becoming increasingly important.<\/p><p>Source: <a href=\"https:\/\/www.bundesgerichtshof.de\/SharedDocs\/Entscheidungen\/DE\/Zivilsenate\/VI_ZS\/2024\/VI_ZR_396-24.pdf?__blob=publicationFile&amp;v=1\" target=\"_blank\" rel=\"noopener\">BGH ruling from 11.11.2025 - VI ZR 396\/24<\/a><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-0f21c30 elementor-widget elementor-widget-heading\" data-id=\"0f21c30\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Would you like to make your order processing \u201eBGH-proof\u201c, especially for offboarding?<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-69d6f7c elementor-widget elementor-widget-text-editor\" data-id=\"69d6f7c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>This is precisely where data mishaps often occur in practice: Confirmations of deletion are missing, there are copies in test\/staging environments, responsibilities are unclear and evidence is incomplete.<\/p><p>Ailance supports you in managing your AV landscape in a structured manner: from the selection and evaluation of service providers to the audit-proof exit checklist, including verification of complete deletion.<\/p><p>2B Advice provides you with legal and operational support: We review and optimize your order processing contracts (Art. 28 GDPR), develop practical technical and organizational measures (TOM) and offboarding processes, support you in incident response (including communication, data subject and authority management) and help you to minimize the risk of claims under Art. 82 GDPR.<\/p><p>Get started now: Let's have a quick appointment to check where your greatest risk lies in the vendor and offboarding setup and how you can quickly achieve a resilient level with clear controls, robust deletion confirmations and clean documentation.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-18656cf e-con-full e-flex e-con e-child\" data-id=\"18656cf\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-cc9f1ba elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"cc9f1ba\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-894b74a elementor-widget elementor-widget-text-editor\" data-id=\"894b74a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><em>Aristotelis Zervos is Editorial Director at 2B Advice, a lawyer and journalist with profound expertise in data protection, GDPR, IT compliance and AI governance. He regularly publishes in-depth articles on AI regulation, GDPR compliance and risk management. You can find out more about him on his <a id=\"menur29rv\" class=\"fui-Link ___1q1shib f2hkw1w f3rmtva f1ewtqcl fyind8e f1k6fduh f1w7gpdv fk6fouc fjoy568 figsok6 f1s184ao f1mk8lai fnbmjn9 f1o700av f13mvf36 f1cmlufx f9n3di6 f1ids18y f1tx3yz7 f1deo86v f1eh06m1 f1iescvh fhgqx19 f1olyrje f1p93eir f1nev41a f1h8hb77 f1lqvz6u f10aw75t fsle3fq f17ae5zn\" title=\"https:\/\/2b-advice.com\/de\/aristotelis-zervos\/\" href=\"https:\/\/2b-advice.com\/en\/aristotelis-zervos\/\" rel=\"noreferrer noopener\" aria-label=\"Link author profile page.\"><strong>Author profile page<\/strong><\/a>.<\/em><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>","protected":false},"excerpt":{"rendered":"<p>A recent ruling by the Federal Court of Justice (BGH) provides clarity regarding non-material damages pursuant to Art. 82 GDPR in the event of a data leak at a former processor. <\/p>","protected":false},"author":2,"featured_media":43200,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[441,72],"tags":[493,51,109,167,494,153],"class_list":["post-43192","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-aristotelis-zervos","category-datenschutz-in-deutschland","tag-avv","tag-dsgvo","tag-dsgvo-bussgelder","tag-dsgvo-verstoss","tag-schadensersatz","tag-verarbeitungsverzeichnis-vvt"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Unterlassene Kontrolle von Auftragsverarbeiter: BGH weitet Haftung des Verantwortlichen aus - Ailance<\/title>\n<meta name=\"description\" content=\"Der BGH schafft Klarheit bez\u00fcglich des immateriellen Schadensersatzes nach Art. 82 DSGVO im Falle eines Datenlecks bei einem ehemaligen Auftragsverarbeiter.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/2b-advice.com\/en\/2026\/01\/14\/failure-to-monitor-processors-bgh-extends-liability-of-the-responsible-party\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Unterlassene Kontrolle von Auftragsverarbeiter: BGH weitet Haftung des Verantwortlichen aus - Ailance\" \/>\n<meta property=\"og:description\" content=\"Der BGH schafft Klarheit bez\u00fcglich des immateriellen Schadensersatzes nach Art. 82 DSGVO im Falle eines Datenlecks bei einem ehemaligen Auftragsverarbeiter.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/2b-advice.com\/en\/2026\/01\/14\/failure-to-monitor-processors-bgh-extends-liability-of-the-responsible-party\/\" \/>\n<meta property=\"og:site_name\" content=\"Ailance\" \/>\n<meta property=\"article:published_time\" content=\"2026-01-14T17:30:13+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-04-14T12:41:16+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/2b-advice.com\/wp-content\/uploads\/2026\/01\/BGH_Datenleak_Auftragsverarbeiter.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1536\" \/>\n\t<meta property=\"og:image:height\" content=\"1024\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Aristotelis\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Aristotelis\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"10 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/2026\\\/01\\\/14\\\/unterlassene-kontrolle-von-auftragsverarbeiter-bgh-weitet-haftung-des-verantwortlichen-aus\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/2026\\\/01\\\/14\\\/unterlassene-kontrolle-von-auftragsverarbeiter-bgh-weitet-haftung-des-verantwortlichen-aus\\\/\"},\"author\":{\"name\":\"Aristotelis\",\"@id\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/#\\\/schema\\\/person\\\/dec1524f23a48487067598ae938bc8eb\"},\"headline\":\"Unterlassene Kontrolle von Auftragsverarbeiter: BGH weitet Haftung des Verantwortlichen aus\",\"datePublished\":\"2026-01-14T17:30:13+00:00\",\"dateModified\":\"2026-04-14T12:41:16+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/2026\\\/01\\\/14\\\/unterlassene-kontrolle-von-auftragsverarbeiter-bgh-weitet-haftung-des-verantwortlichen-aus\\\/\"},\"wordCount\":2431,\"publisher\":{\"@id\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/2026\\\/01\\\/14\\\/unterlassene-kontrolle-von-auftragsverarbeiter-bgh-weitet-haftung-des-verantwortlichen-aus\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/2b-advice.com\\\/wp-content\\\/uploads\\\/2026\\\/01\\\/BGH_Datenleak_Auftragsverarbeiter.jpg\",\"keywords\":[\"AVV\",\"DSGVO\",\"DSGVO-Bu\u00dfgelder\",\"DSGVO-Versto\u00df\",\"Schadensersatz\",\"Verarbeitungsverzeichnis VVT\"],\"articleSection\":[\"Artikel von Aristotelis Zervos\",\"Datenschutz in Deutschland\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/2026\\\/01\\\/14\\\/unterlassene-kontrolle-von-auftragsverarbeiter-bgh-weitet-haftung-des-verantwortlichen-aus\\\/\",\"url\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/2026\\\/01\\\/14\\\/unterlassene-kontrolle-von-auftragsverarbeiter-bgh-weitet-haftung-des-verantwortlichen-aus\\\/\",\"name\":\"Unterlassene Kontrolle von Auftragsverarbeiter: BGH weitet Haftung des Verantwortlichen aus - Ailance\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/2026\\\/01\\\/14\\\/unterlassene-kontrolle-von-auftragsverarbeiter-bgh-weitet-haftung-des-verantwortlichen-aus\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/2026\\\/01\\\/14\\\/unterlassene-kontrolle-von-auftragsverarbeiter-bgh-weitet-haftung-des-verantwortlichen-aus\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/2b-advice.com\\\/wp-content\\\/uploads\\\/2026\\\/01\\\/BGH_Datenleak_Auftragsverarbeiter.jpg\",\"datePublished\":\"2026-01-14T17:30:13+00:00\",\"dateModified\":\"2026-04-14T12:41:16+00:00\",\"description\":\"Der BGH schafft Klarheit bez\u00fcglich des immateriellen Schadensersatzes nach Art. 82 DSGVO im Falle eines Datenlecks bei einem ehemaligen Auftragsverarbeiter.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/2026\\\/01\\\/14\\\/unterlassene-kontrolle-von-auftragsverarbeiter-bgh-weitet-haftung-des-verantwortlichen-aus\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/2b-advice.com\\\/en\\\/2026\\\/01\\\/14\\\/unterlassene-kontrolle-von-auftragsverarbeiter-bgh-weitet-haftung-des-verantwortlichen-aus\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/2026\\\/01\\\/14\\\/unterlassene-kontrolle-von-auftragsverarbeiter-bgh-weitet-haftung-des-verantwortlichen-aus\\\/#primaryimage\",\"url\":\"https:\\\/\\\/2b-advice.com\\\/wp-content\\\/uploads\\\/2026\\\/01\\\/BGH_Datenleak_Auftragsverarbeiter.jpg\",\"contentUrl\":\"https:\\\/\\\/2b-advice.com\\\/wp-content\\\/uploads\\\/2026\\\/01\\\/BGH_Datenleak_Auftragsverarbeiter.jpg\",\"width\":1536,\"height\":1024,\"caption\":\"Bei einem Datenleck beim Auftragsverarbeiter haftet der Verantwortliche.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/2026\\\/01\\\/14\\\/unterlassene-kontrolle-von-auftragsverarbeiter-bgh-weitet-haftung-des-verantwortlichen-aus\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/2b-advice.com\\\/de\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Unterlassene Kontrolle von Auftragsverarbeiter: BGH weitet Haftung des Verantwortlichen aus\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/\",\"name\":\"2B Advice\",\"description\":\"By 2B Advice\",\"publisher\":{\"@id\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/#organization\",\"name\":\"2B Advice GmbH\",\"url\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/2b-advice.com\\\/wp-content\\\/uploads\\\/2024\\\/02\\\/Ailance_Logo_Yellow_White_large_RGB.png\",\"contentUrl\":\"https:\\\/\\\/2b-advice.com\\\/wp-content\\\/uploads\\\/2024\\\/02\\\/Ailance_Logo_Yellow_White_large_RGB.png\",\"width\":287,\"height\":401,\"caption\":\"2B Advice GmbH\"},\"image\":{\"@id\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/2b-advice-group\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/#\\\/schema\\\/person\\\/dec1524f23a48487067598ae938bc8eb\",\"name\":\"Aristotelis\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Failure to monitor processors: BGH extends liability of the controller - Ailance","description":"The BGH provides clarity regarding non-material damages under Art. 82 GDPR in the event of a data leak at a former processor.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/2b-advice.com\/en\/2026\/01\/14\/failure-to-monitor-processors-bgh-extends-liability-of-the-responsible-party\/","og_locale":"en_US","og_type":"article","og_title":"Unterlassene Kontrolle von Auftragsverarbeiter: BGH weitet Haftung des Verantwortlichen aus - Ailance","og_description":"Der BGH schafft Klarheit bez\u00fcglich des immateriellen Schadensersatzes nach Art. 82 DSGVO im Falle eines Datenlecks bei einem ehemaligen Auftragsverarbeiter.","og_url":"https:\/\/2b-advice.com\/en\/2026\/01\/14\/failure-to-monitor-processors-bgh-extends-liability-of-the-responsible-party\/","og_site_name":"Ailance","article_published_time":"2026-01-14T17:30:13+00:00","article_modified_time":"2026-04-14T12:41:16+00:00","og_image":[{"width":1536,"height":1024,"url":"https:\/\/2b-advice.com\/wp-content\/uploads\/2026\/01\/BGH_Datenleak_Auftragsverarbeiter.jpg","type":"image\/jpeg"}],"author":"Aristotelis","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Aristotelis","Est. reading time":"10 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/2b-advice.com\/en\/2026\/01\/14\/unterlassene-kontrolle-von-auftragsverarbeiter-bgh-weitet-haftung-des-verantwortlichen-aus\/#article","isPartOf":{"@id":"https:\/\/2b-advice.com\/en\/2026\/01\/14\/unterlassene-kontrolle-von-auftragsverarbeiter-bgh-weitet-haftung-des-verantwortlichen-aus\/"},"author":{"name":"Aristotelis","@id":"https:\/\/2b-advice.com\/en\/#\/schema\/person\/dec1524f23a48487067598ae938bc8eb"},"headline":"Unterlassene Kontrolle von Auftragsverarbeiter: BGH weitet Haftung des Verantwortlichen aus","datePublished":"2026-01-14T17:30:13+00:00","dateModified":"2026-04-14T12:41:16+00:00","mainEntityOfPage":{"@id":"https:\/\/2b-advice.com\/en\/2026\/01\/14\/unterlassene-kontrolle-von-auftragsverarbeiter-bgh-weitet-haftung-des-verantwortlichen-aus\/"},"wordCount":2431,"publisher":{"@id":"https:\/\/2b-advice.com\/en\/#organization"},"image":{"@id":"https:\/\/2b-advice.com\/en\/2026\/01\/14\/unterlassene-kontrolle-von-auftragsverarbeiter-bgh-weitet-haftung-des-verantwortlichen-aus\/#primaryimage"},"thumbnailUrl":"https:\/\/2b-advice.com\/wp-content\/uploads\/2026\/01\/BGH_Datenleak_Auftragsverarbeiter.jpg","keywords":["AVV","DSGVO","DSGVO-Bu\u00dfgelder","DSGVO-Versto\u00df","Schadensersatz","Verarbeitungsverzeichnis VVT"],"articleSection":["Artikel von Aristotelis Zervos","Datenschutz in Deutschland"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/2b-advice.com\/en\/2026\/01\/14\/unterlassene-kontrolle-von-auftragsverarbeiter-bgh-weitet-haftung-des-verantwortlichen-aus\/","url":"https:\/\/2b-advice.com\/en\/2026\/01\/14\/unterlassene-kontrolle-von-auftragsverarbeiter-bgh-weitet-haftung-des-verantwortlichen-aus\/","name":"Failure to monitor processors: BGH extends liability of the controller - Ailance","isPartOf":{"@id":"https:\/\/2b-advice.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/2b-advice.com\/en\/2026\/01\/14\/unterlassene-kontrolle-von-auftragsverarbeiter-bgh-weitet-haftung-des-verantwortlichen-aus\/#primaryimage"},"image":{"@id":"https:\/\/2b-advice.com\/en\/2026\/01\/14\/unterlassene-kontrolle-von-auftragsverarbeiter-bgh-weitet-haftung-des-verantwortlichen-aus\/#primaryimage"},"thumbnailUrl":"https:\/\/2b-advice.com\/wp-content\/uploads\/2026\/01\/BGH_Datenleak_Auftragsverarbeiter.jpg","datePublished":"2026-01-14T17:30:13+00:00","dateModified":"2026-04-14T12:41:16+00:00","description":"The BGH provides clarity regarding non-material damages under Art. 82 GDPR in the event of a data leak at a former processor.","breadcrumb":{"@id":"https:\/\/2b-advice.com\/en\/2026\/01\/14\/unterlassene-kontrolle-von-auftragsverarbeiter-bgh-weitet-haftung-des-verantwortlichen-aus\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/2b-advice.com\/en\/2026\/01\/14\/unterlassene-kontrolle-von-auftragsverarbeiter-bgh-weitet-haftung-des-verantwortlichen-aus\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/2b-advice.com\/en\/2026\/01\/14\/unterlassene-kontrolle-von-auftragsverarbeiter-bgh-weitet-haftung-des-verantwortlichen-aus\/#primaryimage","url":"https:\/\/2b-advice.com\/wp-content\/uploads\/2026\/01\/BGH_Datenleak_Auftragsverarbeiter.jpg","contentUrl":"https:\/\/2b-advice.com\/wp-content\/uploads\/2026\/01\/BGH_Datenleak_Auftragsverarbeiter.jpg","width":1536,"height":1024,"caption":"Bei einem Datenleck beim Auftragsverarbeiter haftet der Verantwortliche."},{"@type":"BreadcrumbList","@id":"https:\/\/2b-advice.com\/en\/2026\/01\/14\/unterlassene-kontrolle-von-auftragsverarbeiter-bgh-weitet-haftung-des-verantwortlichen-aus\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/2b-advice.com\/de\/"},{"@type":"ListItem","position":2,"name":"Unterlassene Kontrolle von Auftragsverarbeiter: BGH weitet Haftung des Verantwortlichen aus"}]},{"@type":"WebSite","@id":"https:\/\/2b-advice.com\/en\/#website","url":"https:\/\/2b-advice.com\/en\/","name":"2B Advice","description":"By 2B Advice","publisher":{"@id":"https:\/\/2b-advice.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/2b-advice.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/2b-advice.com\/en\/#organization","name":"2B Advice GmbH","url":"https:\/\/2b-advice.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/2b-advice.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/2b-advice.com\/wp-content\/uploads\/2024\/02\/Ailance_Logo_Yellow_White_large_RGB.png","contentUrl":"https:\/\/2b-advice.com\/wp-content\/uploads\/2024\/02\/Ailance_Logo_Yellow_White_large_RGB.png","width":287,"height":401,"caption":"2B Advice GmbH"},"image":{"@id":"https:\/\/2b-advice.com\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/2b-advice-group\/"]},{"@type":"Person","@id":"https:\/\/2b-advice.com\/en\/#\/schema\/person\/dec1524f23a48487067598ae938bc8eb","name":"Aristotle"}]}},"_links":{"self":[{"href":"https:\/\/2b-advice.com\/en\/wp-json\/wp\/v2\/posts\/43192","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/2b-advice.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/2b-advice.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/2b-advice.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/2b-advice.com\/en\/wp-json\/wp\/v2\/comments?post=43192"}],"version-history":[{"count":21,"href":"https:\/\/2b-advice.com\/en\/wp-json\/wp\/v2\/posts\/43192\/revisions"}],"predecessor-version":[{"id":43698,"href":"https:\/\/2b-advice.com\/en\/wp-json\/wp\/v2\/posts\/43192\/revisions\/43698"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/2b-advice.com\/en\/wp-json\/wp\/v2\/media\/43200"}],"wp:attachment":[{"href":"https:\/\/2b-advice.com\/en\/wp-json\/wp\/v2\/media?parent=43192"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/2b-advice.com\/en\/wp-json\/wp\/v2\/categories?post=43192"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/2b-advice.com\/en\/wp-json\/wp\/v2\/tags?post=43192"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}