ON
← Back to feed
In the case of the applicant, the Court of Justice of the European Union has ruled in favour of the applicant.
Germany🏛️ PoliticsCenter7 days ago

In the case of the applicant, the Court of Justice of the European Union has ruled in favour of the applicant.

Ein Urteil des Bundesgerichtshofs (BGH) bestätigt, dass ein Bewerber Schadenersatz aus der DSGVO beanspruchen kann, wenn vertrauliche Bewerberdaten versehentlich an einen fremden Empfänger gelangen. Der Fall geht zurück auf Oktober 2018, als eine Mitarbeiterin der Quirin-Bank über Xing ein Bewerbungsverfahren durchführte und eine vertrauliche Nachricht versehentlich an einen Dritten weiterleitete. Die Nachricht enthielt sensible Informationen, darunter ein Gehaltsvorschlag von 80.000 Euro. Der BGH verwies auf eine Entscheidung des Europäischen Gerichtshofs (EuGH), wonach immaterielle Schäden wie Sorge oder Ärger ausreichend sind, um Schadenersatz zu rechtfertigen. Die Entscheidung klärt, wann ein Kontrollverlust im Datenschutz tatsächlich zum Schaden führt.

A German court has ruled that a job candidate who received a confidential application message via the social network Xing due to an error is entitled to compensation under the European Union's General Data Protection Regulation (GDPR). The Federal Court of Justice (BGH) confirmed this in its decision dated September 2025, rejecting the claim for an injunction against further data misuse, however. The case dates back to October 2018, when an employee of Quirin-Bank mistakenly sent a private message containing sensitive information to a third party through the Xing platform. The incident occurred during a recruitment process conducted over Xing. The employee intended to send a message exclusively to the candidate but accidentally forwarded it to another individual not involved in the hiring process. The content of the message was far from trivial. It included the candidate’s surname, gender, and indicated that a hiring process was underway. Additionally, it outlined how the bank evaluated the candidate’s profile and mentioned a potential salary of 80,000 euros plus variable compensation. The unintended recipient was not a stranger, he had previously worked with the candidate within the same holding company. He relayed the message to the candidate and directly asked whether he was currently looking for a new position. In court, the private bank initially argued that no personal data in the sense of GDPR had been transferred because the surname alone did not allow clear identification. However, the BGH rejected this argument. The sixth civil chamber affirmed that the message contained typical identifying characteristics, sufficient for the definition of personal data under GDPR. It emphasized that the regulation does not require unique identification, merely that the person can be identified. This holds true even if the recipient already possessed additional knowledge about the individual. The BGH’s ruling builds upon guidance provided by the European Court of Justice (ECJ) in September 2025. At the request of the BGH, the ECJ clarified that GDPR does not demand specific material damage or a threshold of significance for compensation claims. Concerns, distress, or justified fears of abuse following a data breach are enough to warrant damages. This paved the way for recognizing non-material disadvantages, which the BGH now applies practically in its decision. The BGH’s judgment significantly impacts the interpretation of non-material damage under Article 82 of GDPR. Earlier courts had dismissed the plaintiff’s claim, arguing that the complainant had described a data protection violation but not a concrete harm. The BGH corrected this stance, stating that the concept of damage under EU law must be interpreted broadly. According to the ruling, a mere violation does not automatically lead to a right to compensation. Independent proof of legal infringement, damage, and causality must be established. However, the damage in this case became evident when the third party read the message and contacted the complainant. This constituted abusive use of the data, making the loss of control over the information consequential rather than harmless. Furthermore, the court confirmed that justified concerns about future misuse can constitute non-material damage. Given that the recipient operated in the same industry, the complainant’s fear of data sharing or competitive disadvantage appeared reasonable. The third party’s inquiry transformed an abstract risk into a concretely verifiable effect. This reinforces the BGH’s approach: a claim requires that the damage is clearly linked to the data breach and that there is a direct causal relationship between the breach and the harm suffered.

Go to the primary sources (1)

The official sources this coverage is built on. Read them directly to bypass framing.

1 reports

heise online logoheise onlineIndependentCenterFactual 95Objective 937 days ago
In the case of the applicant, the Court of Justice of the European Union has ruled in favour of the applicant.

Ein Urteil des Bundesgerichtshofs (BGH) bestätigt, dass ein Bewerber Schadenersatz aus der DSGVO beanspruchen kann, wenn vertrauliche Bewerberdaten versehentlich an einen fremden Empfänger gelangen. Der Fall geht zurück auf Oktober 2018, als eine Mitarbeiterin der Quirin-Bank über Xing ein Bewerbungsverfahren durchführte und eine vertrauliche Nachricht versehentlich an einen Dritten weiterleitete. Die Nachricht enthielt sensible Informationen, darunter ein Gehaltsvorschlag von 80.000 Euro. Der BGH verwies auf eine Entscheidung des Europäischen Gerichtshofs (EuGH), wonach immaterielle Schäden wie Sorge oder Ärger ausreichend sind, um Schadenersatz zu rechtfertigen. Die Entscheidung klärt, wann ein Kontrollverlust im Datenschutz tatsächlich zum Schaden führt.

Bias read (Center): Die Berichterstattung bleibt sachlich und legt die rechtlichen Grundlagen nahe, ohne eine politische Richtung zu favorisieren. Es wird keine parteipolitische Einordnung gegeben, sondern lediglich die rechtliche Bewertung des Falls. Die Quelle ist eine offizielle Entscheidung des BGH, was den Neutral

Why factuality (95): The article provides specific details about the case including the year (2018), the company involved (Quirin-Bank), the platform used (Xing), and the court decision (BGH, Az.: VI ZR 97/22). These facts align with what would be expected from a reputable German news outlet covering a legal ruling. The

Why objectivity (93): The article presents the facts neutrally, describing both sides of the argument before the court and the outcome without apparent bias. It uses formal language typical of legal reporting and avoids emotionally charged terms. The only slight deviation from perfect neutrality is the phrase 'Das Schick

How each side covered it

The same event, grouped by the political lean of the outlets covering it.

How each side covered it

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Covered around the world

The same event as reported in other countries.

Covered around the world

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Claims check

Key factual claims, and how many sources assert vs dispute each.

Claims check

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Keep the news honest.

ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €4/month.

Become a Supporter

Related stories