The data subject (a child born in 2018), represented by her parents, was insured with the controller (a statutory health insurance provider) and participated in its digital bonus programme
The bonus programme was managed via an app.
To handle the information technology operations of this programme, the controller hired the processor (an IT service provider), establishing a data processing agreement under Article 28 GDPR alongside specific information security guidelines. To provide these services, the processor utilised "MOVEit Transfer," a market-leading file transfer software developed by Progress Software Corp. On 31 May 2023, the software developer publicly announced a critical, previously unknown "zero-day" vulnerability in the software (later assigned CVE-2023-34362). At that exact moment, no security patch was available. On the very same day, 31 May 2023, the processor – alongside thousands of other companies worldwide – became the victim of a global cyberattack carried out by the hacker group "Clop." The hackers exploited this zero-day vulnerability to install a "web-shell" backdoor (typically named human2.aspx), bypassing authentication to exfiltrate database records. The compromised data included the data subject's first and last name, health insurance number, bonus points balance, and a bank account number (IBAN) belonging to her mother. No medical, health, or social security data was exfiltrated. On 1 June 2023, the developer released a security patch, which the processor installed immediately. On 2 June 2023, the German Federal Office for Information Security (BSI) issued a formal IT security warning (No. 2023-240133-1100, Version 1.1). The BSI classified the IT threat level as "3 / Orange" (business-critical), confirming active exploitation with data exfiltration. The BSI recommended immediately blocking all HTTP and HTTPS traffic to MOVEit environments, checking for specific Indicators of Compromise (IoCs) in the web server directories, and applying the newly released patch before reconnecting systems to the network. On 16 June 2023, the processor informed the controller about the incident. On 17 June 2023, the controller issued a public press release confirming that its external service provider for the bonus programme had been targeted on 31 May 2023. The release stated that the security vulnerability had been closed, that there was never any connection to the controller's internal IT systems, and that relevant supervisory authorities had been notified. The controller subsequently notified the data subject's parents. On 27 March 2024, the data subject, via legal counsel, sent a formal warning letter to the controller demanding an injunction, a declaration of liability for all potential future damages, and non-material damages of at least €3,000. Following the controller's refusal, the data subject filed a lawsuit with the Nuremberg Social Court (Sozialgericht Nürnberg), later expanding the claim to the processor as a joint defendant. Holding — The Court dismissed the lawsuit as partly inadmissible and otherwise unfounded, establishing the following legal principles: First, the Court held that a successful third-party cyberattack does not establish an irrebuttable presumption that a controller or processor failed to implement appropriate security measures under Article 32(1) GDPR and Article 5(1)(f) GDPR. To escape liability under Article 82(3) GDPR, an operator must prove they implemented robust baseline security controls (such as multi-factor authentication, encryption, and lockout policies) and applied a security patch immediately upon its release by the vendor, even if this occurred before formal alerts were issued by national IT security authorities. Second, the Court held that a claim for non-material damages under Article 82(1) GDPR based on the fear or distress of future data misuse cannot be established if the data subject is a minor who has no subjective knowledge or cognitive awareness of the data breach. Furthermore, if the compromised financial data (such as an IBAN) does not belong to the data subject personally, there is no direct risk of financial harm to them, rendering the alleged fear of financial damage unfounded. Third, the Court held that an injunction claim is inadmissible due to a lack of specificity if it merely demands that a controller stop making personal data accessible to third parties without implementing "state-of-the-art" security measures, without specifying the concrete technical or organisational measures the controller is required to take. Fourth, the Court held that a declaratory claim for potential future material damages is inadmissible under national procedural law (§ 55(1) SGG) if there is no realistic probability of future financial harm, particularly because the compromised bank account belonged to a third party (the mother) and the software vulnerability was immediately patched.
How it connects
References
- Art. 82
- Art. 24
- Art. 4(12)
- Art. 4(10)
- Art. 5(1)(f)
- Art. 32
- Art. 82(3)
- Art. 28
- Art. 32(1)
- Art. 82(1)
- ECLI:NL:RBROT:2025:9088 Rechtbank Rotterdam , 23-07-2025 / C/10/668332 / HA ZA 23-965
- VB v Natsionalna agentsia za prihodite
- Rb. Den Haag: Verstrekking persoonsgegevens door gemeente Leiden aan woningcorporatie is
- SG Nürnberg - S 5 SF 65/24 DS
- CJEU - C-667/21 - Krankenversicherung Nordrhein
Related across sources
Full text 33 paragraphs
2026 2nd Instance Court Case Reference / Case Number Date 3rd Instance Court Case Reference / Case Number Date DECISION TEXT I. The action is dismissed. II. The Plaintiff shall bear the costs of the proceedings as well as the necessary extrajudicial expenses of both Defendants. III. 000,00. 2023. In addition, the Plaintiff seeks a declaration of liability for compensation for potential future damage in principle, an injunction against the unauthorised disclosure of personal data, and indemnification from pre-litigation legal fees. The Plaintiff, born in 2018, is statutorily health-insured with the Defendant under 1) and participates in its bonus programme, which is operated via an app. Under this programme, EUR 10,00 is paid out to the insured person for every 100 points collected. Points can be collected through regular participation in preventive medical check-ups as well as sports and leisure programmes.
For the information technology processing of its bonus programme, the Defendant under 1) uses a processor, the Defendant under 2). The Defendant under 2) uses the program M-IT of the US company P-Corp. ") to provide the contractually owed services. This is a software program for the exchange of data. The Defendant under 1) has concluded an agreement on processing with the Defendant under 2). The associated general framework conditions on "Information Security" regulate the technical and organisational measures to be complied with by the Defendant under 2) as processor. These include, among other things, requirements for infrastructure security and protection against malware. For example, the Defendant under 2) is required to have malware detection and repair software installed that corresponds to the state of the art and must reliably prevent the exfiltration of the controller's data. , in the course of which a data breach occurred, by which, inter alia, the Plaintiff was also affected.
By uploading a so-called "web shell" onto the affected server of the Defendant under 2), the hackers succeeded in gaining access to its system and exfiltrating customer data – including that of the Plaintiff. The data affected by the hacker attack consists of first name, surname, health insurance number, premium amount (the proceeds from successful participation in the bonus programme) and bank details (IBAN). In this case, the bank details are not those of the Plaintiff, but of her mother. Furthermore, health data of the Plaintiff was not affected. No data was exfiltrated from the servers of the Defendant under 1) either. The actions of the group C. were, as far as is known, not directed against the respective data subjects, but against the companies affected by the attack in order to extort them. The hackers had succeeded in accessing this data via an unknown vulnerability in the program MOVEit.
e. a security vulnerability previously unknown to the software manufacturer and the Defendants. 2023, the company P. issued a security warning. 2023 (security level 4 warning). 2023, P. provided the security patch to eliminate the threat, which was immediately installed by the Defendant under 2). 2023 and issued a corresponding press release the following day. Subsequently, it also informed the Plaintiff's parents as her statutory representatives. 000,00, and to agree to an obligation to compensate the Plaintiff for all future damage that might still arise for her as a result of the unauthorised access by third parties to the personal data. 2024, the Plaintiff brought an action before the Social Court of Nuremberg – initially only against the Defendant under 1). 2024, she extended the action to the Defendant under 2). She claims to have become the victim of a data breach at the Defendant under 1) because the latter had taken insufficient technical measures to adequately protect personal data.
Consequently, the personal data of the Plaintiff could be obtained by unauthorised persons. The IT forensic experts of K. had supposedly found indications that the hackers had already been aware of the vulnerability since the year 2021. Since then, they had most likely experimented on how best to abuse the gap. The MOVEit software had stood out for years due to such (SQL injection) vulnerabilities, and the IT security expert T. had also commented to this effect on X. He spoke in particular of the fact that the use of such software was to be assessed as "negligent". The Defendant under 1) should have taken the following protective measures in particular: pseudonymisation and/or encryption of the personal data, as well as a process for regularly testing, assessing and evaluating the effectiveness of the technical and organisational measures. If the Defendant had properly carried out these protective measures, the data breach would not have occurred and unauthorised persons would not have gained access to the Plaintiff's data.
Even if the data breach had occurred "only" at the Defendant under 2), the Defendant under 1) would also be liable in this case. This is because, as the controller under data protection law, it must ensure that all of its contractual partners who process personal data of Barmer customers within the scope of processing also work in compliance with data protection law. To this end, the Defendant should have instructed and monitored the processor accordingly. Both Defendants are joint controllers under Art 26 of the General Data Protection Regulation (GDPR). The use of the MOVEit software at the time the data breach was exploited by the hacker group was grossly negligent. Through a more modern, albeit more expensive software, the data breach would have been avoided. The Defendant under 1) is obliged under Art 32 GDPR to implement appropriate and suitable technical and organisational measures (TOM) to ensure a level of security appropriate to the risk.
The Defendant under 1) culpably failed to take and implement suitable technical and organisational measures to prevent a disclosure of personal data. The Defendant has therefore (also) infringed the requirements of Art 32 GDPR. Due to the ongoing loss of control over personal and sensitive data, the Plaintiff is entitled to a claim for non-material damages under Art 82 para 1 GDPR. The actual damage lies in the ongoing state of existing and distressing uncertainty regarding the unauthorised publication of the personal data. The Plaintiff is worried that her bank and/or securities account data will be hacked. It must be assumed that the Plaintiff's data is already being offered for sale on the so-called "darknet". , in order to cause financial harm to the Plaintiff. The linking and downstream publication of personal data, such as at least the first name and surname as well as potentially other data, opens the floodgates to abuse.
The loss of the social security number (note: this was not exfiltrated, see above) also significantly increases the risk of identity theft. In addition, the mere fact that the Plaintiff's data is available to an unknown number of unauthorised persons is frightening for her, as it is not yet known in what way it might be misused. 000,00. The Plaintiff requests that, 1. 000,00, plus interest in the amount of 5 percentage points above the respective base rate since lis pendens. 2. 2023. 3. 000,00 for each case of infringement, or alternatively administrative detention to be executed on their statutory representative, or administrative detention of up to 6 months to be executed on their statutory representative, and in the event of repeated infringement up to 2 years, to refrain from making personal data of the Plaintiff, namely first name, surname, health insurance number, premium amount, as well as the bank details, accessible to third parties without implementing the security measures possible according to the state of the art and without the consent of the Plaintiff or a justification under the GDPR.
4. the Defendant under 1) be ordered to indemnify the Plaintiff from pre-litigation costs for legal representation in the amount of EUR 973,65 plus interest in the amount of 5 percentage points above the respective base rate since lis pendens. The Defendants request that, the action be dismissed. The Defendant under 1) submits that it is not known that any personal data of the Plaintiff has been published anywhere. It contends that in this case there is already a lack of any infringement of rights attributable to the Defendants. It argues that it is therefore exempt from liability (Art 82 para 3 GDPR). It submits that there has been no failure by the Defendant under 1) to comply with its obligations under the GDPR. It states that it used the Defendant under 2) to carry out certain processing of personal data within the framework of operating its bonus programme. It asserts that a proper agreement on processing in accordance with Art 28 GDPR was concluded with the Defendant under 2), under which the latter specifically committed itself to certain TOMs in order to meet the requirements of Art 32 GDPR.
It argues that Art 32 para 1 GDPR merely contains examples of measures that are to be taken "as appropriate". It contends that these are to be implemented – if at all – only to the extent and in the scope to which they are suitable and necessary to achieve an appropriate level of security. In particular, it submits that Art 32 para 1 GDPR itself does not determine when such measures are required. It argues that the GDPR does not demand absolute protection (which would also be impossible), but merely technical and organisational measures to ensure a level of security appropriate to the risk (Art 32 para 1 GDPR). It asserts that the fact that a hacker attack was successful in no way proves a lack of an appropriate level of security. It argues that the Plaintiff's submission claiming otherwise misunderstands the legal framework. 2023 at 10:17 am, the system was secured with a security patch provided by the manufacturer, so that further attacks and, in particular, the exfiltration of further data could be prevented.
Moreover, health data of the Plaintiff was not affected. It submits that it was not foreseeable for either of the two Defendants that the Defendant under 2), like several thousand other companies worldwide, would become the victim of a hacker attack by a group of apparently Russian criminals. Furthermore, it argues that the Plaintiff's submission does not demonstrate any damage that could be compensable. In this case, it contends that it is also impossible to rely on the fear of misuse of the data as non-material damage. This is because it would require that a misuse can actually be feared under the given circumstances and with regard to the data subject. On the one hand, it states that there is a complete lack of any submissions to this effect. On the other hand, it argues that this is also entirely improbable. It asserts that since the hacker attack on the processor of the Defendant under 1) in May 2023, to the knowledge of the Defendant, no data of data subjects has been misused.
It argues that the objective of the attack was also recognisably in no way the misuse of the data of data subjects, but rather the extortion of the Defendant under 1) as controller and the Defendant under 2) as processor. In addition, the Defendant under 1) submits that it is not a "joint controller" with the Defendant under 2) under Art 26 GDPR. It argues that there is instead a relationship of processing under Art 28 GDPR. The Defendant under 2) submits that it never had access to the source code of the MOVEit application. It states that for security reasons, this is kept strictly confidential by the manufacturer. It argues that all bug fixes must therefore be provided by the manufacturer. It contends that the critical vulnerability of the MOVEit application was no exception to this. Its correction was only possible for the manufacturer. It states that the mobile number and the email address of the Plaintiff were precisely not exfiltrated.
With regard to the bank details, it argues that damage can easily be prevented by changing the account. It asserts that at the time of the data protection incident, taking into account the state of the art, the MOVEit application was a secure application and was considered insurmountable. The Defendant under 2) submits that it was entitled to assume that the software corresponded to the state of the art. , actively supports the MOVEit application and regularly provides updates with bug fixes. It argues that this was also the case at the time of the cyberattack. As the handling of the cyberattack shows, the support provided by P. was also highly professional. 2023 became known, P. made the security patch available to eliminate the threat. Reference is made to the numerous certifications of P. 2025. Reference is made to this pleading. The Defendant under 2) further submits that prior to the data breach in 2023, it had in any event no knowledge whatsoever of any critical vulnerabilities in the software used.
It argues that if liability under data protection law were to exist for the Defendants for using software of a carefully selected software manufacturer solely because a vulnerability in the software became apparent, the exploitation of which could by its nature not be prevented by properly implemented accompanying security measures, liability under data protection law would escalate into pure strict liability for the use of software. It contends that liability under data protection law under Article 82 GDPR was not designed as such, as this would exclude any exculpation for any software user. It states that the Plaintiff is free to hold P. liable as the manufacturer. 2025, the Defendant under 1) submitted a decision of the Federal Commissioner for Data Protection and Freedom of Information addressed to another insured person regarding the hacker attack in dispute. ). Even the fact that third parties can gain unauthorised access to personal data does not in itself mean that the technical and organisational measures taken were not 'appropriate'.
). " In the course of the oral hearing, the Chamber examined the Plaintiff's father for information purposes. He stated that the affected account is the account of the Plaintiff's mother. He explained that the account still exists, although a second current account has since been set up. He added that most transactions now run through his own account. According to his statements, there are no indications that the account of the Plaintiff's mother has been hacked. He further stated that he does not know whether the data is appearing or being offered on the darknet. He explained that the Plaintiff herself "has no knowledge of the entire process surrounding the data breach". With regard to the further details of the state of the facts and the dispute, reference is made to the court file and the mutual pleadings. REASONS FOR THE DECISION: The action, which is admissible with regard to the claims under numbers 1 and 4, is unfounded.
Insofar as the Plaintiff brought an action for a declaration in objective joinder of claims under number 2 and seeks an injunction under number 3 of her statement of claim, these actions are already inadmissible. ) Venue and Jurisdiction The legal venue of the social jurisdiction is established. The Plaintiff alleges an infringement of the GDPR. For actions brought by the data subject against a controller or a processor on the grounds of an infringement of this Regulation, the legal venue before the courts of the social jurisdiction is established according to the explicit wording of § 81b para 1 of Book X of the German Social Code (SGB X) (cf. on compensation also Federal Social Court - BSG - decision dated 6 March 2023 - B 1 SF 1/22 R - juris). 000,00, the action proves to be unfounded. Pursuant to Art 82 para 1 GDPR, any person who has suffered material or non-material damage as a result of an infringement of this Regulation shall have the right to receive compensation from the controller or processor for the damage suffered.
Pursuant to Art 82 para 3 GDPR, the controller or processor shall be exempt from liability if it proves that it is not in any way responsible for the event giving rise to the damage. Pursuant to Art 82 para 4 GDPR, both the controller – here the Defendant under 1) pursuant to Art 4 no 7 GDPR – and the processor – here the Defendant under 2) pursuant to Art 4 no 8 GDPR – shall be held liable as joint and several debtors for any damage caused. The requirements for a claim for compensation under Art 82 para 1 GDPR are not met. The Chamber could not satisfy itself of a culpable infringement of the GDPR by the Defendants. Furthermore, there is a lack of any non-material damage. ) Pursuant to Art 5 para 1 lit f GDPR, personal data must be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical and organisational measures.
The controller (Art 4 no 7 GDPR) – in this case the Defendant under 1) – must demonstrate compliance with this, cf. Art 5 para 2 GDPR. Pursuant to Art 24 para 1 sentence 1 GDPR, taking into account the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation. Pursuant to Art 24 para 2 GDPR, those measures shall include the implementation of appropriate data protection policies by the controller, where proportionate in relation to processing activities. Furthermore, Art 32 para 1 GDPR provides that the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.
This shall be done taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons. 2023 - C-340/21 - juris, lays down the essential principles. In this regard, it states (underlining added): "The reference in Articles 32(1) and (2) of the GDPR to 'a level of security appropriate to the risk' and to 'an appropriate level of security' shows that that regulation establishes a risk management system and in no way claims to eliminate the risk of personal data breaches" (cf. ECJ, loc. , para 29). On this basis, the ECJ also assumes that there can be no absolute protection in a digital world – just as in an analogue world – but rather that a risk management system is the meaning and purpose of Art 32 GDPR. Subsequently, the ECJ states that it follows from the wording of Articles 24 and 32 GDPR that those provisions merely require the controller to adopt technical and organisational measures designed to prevent any personal data breach as far as possible.
The suitability of such measures must be assessed in a concrete manner, by examining whether the controller adopted those measures taking into account the various criteria laid down in those articles and the data protection needs specifically linked to the processing in question and the risks presented by the latter (cf. ECJ, loc. , para 30). The ECJ then explicitly states (underlining added): "Consequently, Articles 24 and 32 of the GDPR cannot be understood as meaning that an unauthorised disclosure of or unauthorised access to personal data by a third party is sufficient to conclude that the measures adopted by the controller for the processing in question were not appropriate within the meaning of those provisions, without even allowing the controller to provide proof to the contrary. Such an interpretation is all the more necessary given that Article 24 of the GDPR expressly provides that the controller must be able to demonstrate that the measures implemented by him or her are compliant with the GDPR, an opportunity of which he or she would be deprived if an irrebuttable presumption were accepted", cf.
ECJ, loc. , para 31 et seq. The burden of proving that personal data is processed in a manner that ensures appropriate security of that data within the meaning of Art 5 para 1 lit f and Art 32 GDPR lies with the controller for the processing in question (cf. ECJ, loc. , para 52). ) a personal data breach within the meaning of Article 4(12) of the GDPR was committed by cybercriminals, and therefore by 'third parties' within the meaning of Article 4(10) thereof, that breach can be imputed to the controller only if he or she made that breach possible by failing to comply with an obligation under the GDPR, in particular the data protection obligation imposed on him or her under Article 5(1)(f), Article 24 and Article 32 of that regulation. Thus, in the event of a personal data breach by a third party, the controller may exempt himself or herself from liability under Article 82(3) of the GDPR by proving that there is no causal link between the breach of the data protection obligation potentially committed by him or her and the damage suffered by the natural person", cf.
ECJ, loc. , para 71 et seq. Accordingly, while hacker attacks do not per se exempt a party from liability, especially not if the controller or its processor implemented insufficient protective measures (cf. to this effect also ECJ, loc. , para 74), the controller may nevertheless prove that it is not in any way responsible for the event giving rise to the damage in question. Taking these principles into account, the deciding Chamber could not satisfy itself of any responsibility on the part of the Defendants. Indeed, the Defendants have demonstrated in a substantiated and comprehensive manner that, at the time of the incident in dispute, the MOVEit application was established in the market as one of the market-leading applications in the field of managed file transfer software. P. and its software were certified accordingly. 2025, the Defendant under 2) comprehensively set out its own measures, in particular: Access to the MOVEit application only upon authentication by means of a user account, whereby the creation of user accounts was carried out in a stringent process preceded by an application, approval, and identity verification.
Every user receives a unique, personalised, user-specific identifier. Within the MOVEit application, after 5 unsuccessful login attempts within a time window of 6 minutes, the user account is automatically locked for 30 minutes. In addition, the MOVEit Transfer platform blocks the IP address of a terminal device if repeated failed attempts are detected from that address within a time window of 5 minutes. The unblocking of an IP address can only be performed by the competent IT department of the Defendant under 2) and requires a prior review of the event. 2025). Communication with the MOVEit Transfer platform is permitted only via secure protocols (FTPS, SFTP, HTTPS, AS2). During file transfer, MOVEit uses SSL or SSH to encrypt communication. 39) was in use and complied with the manufacturer's security specifications at that time. 2025. The mere fact that a hacker attack was successful does not prove that the technical and organisational measures in advance were insufficient (cf.
2021 - 9 U 34/21 - juris para 54), especially since, according to the Plaintiff's submission, the hackers had been trying to penetrate the system since approximately 2021. Thus, assuming this to be correct, they required approximately two years to get into the system. It is precisely this length of time until a successful attack at the end of May 2023 that also proves the security of the software. Insofar as the Plaintiff argues that the Defendants could have taken further technical measures, of which she lists several, this does not give rise to any duty of implementation, the non-compliance with which could constitute a data protection violation. The Defendants are merely obliged to implement suitable measures designed to prevent a data protection breach as far as possible (cf. 2025 - 3 O 93/24 -, juris, para 30, with further references). The Chamber fully shares the view of the Regional Court of Krefeld regarding the hacker attack in dispute.
It states: "The TOMs described by the Defendants would only be insufficient if concrete indications of the error-proneness of the G. application – which was the market leader at the time of the incident – had previously arisen. In this regard, the Plaintiff's allegations are generalized and lack detailed substance. She refers to an unyielding public post as well as to so-called CVE entries in a vulnerability database. However, this does not show whether the Defendants specifically perceived these circumstances before the cyberattack or ought to have perceived them, as the latter source in particular rather suggests that the program was and is regularly reviewed and further developed in terms of security by the manufacturer. The assumption that the Defendants ought to have had corresponding doubts is countered by the fact that approximately 2,500 companies and institutions worldwide fell victim to this – in this respect unforeseen – so-called 'zero-day exploit'.
", cf. Regional Court of Krefeld, loc. , para 30. " – could have detected the vulnerability in the software. The Regional Court of Trier furthermore states: "Furthermore, a software program was responsible for the exfiltration of data which was developed neither by the Defendant nor by its intervener, but by P.. ", cf. 2025 - 2 O 85/24 - juris, para 53. If at all, a charge of negligent conduct can therefore be made against the manufacturer, but not against the Defendants, who relied entirely on the software of a global market leader. Likewise, no culpable error on the part of the Defendant under 1) can be established regarding the selection decision of the Defendant under 2) as a processor. Accordingly, there is no (attributable) infringement of the GDPR by the Defendants. ) Furthermore, in the present case, there is a lack of any compensable non-material damage. In this regard, the Plaintiff submits in her pleadings that the actual damage lies in the ongoing state of existing and distressing uncertainty regarding the unauthorised publication of the personal data.
Moreover, it is argued that the circumstances have led to worries and anxieties on the part of the Plaintiff. The Plaintiff is also said to be worried that her bank and/or securities account data will be hacked. It is asserted that it must be assumed that the Plaintiff's data is already being offered for sale on the so-called "darknet". , in order to cause financial harm to the Plaintiff. The linking and downstream publication of personal data, such as at least the first name and surname as well as potentially other data, is said to open the floodgates to abuse. The loss of the social security number (note: this was not exfiltrated, see above) also allegedly increases the risk of identity theft significantly. In addition, the mere fact that the Plaintiff's data is available to an unknown number of unauthorised persons is stated to be frightening for her, as it is not yet known in what way it might be misused.
The Plaintiff's submission regarding the alleged damage is largely unsubstantiated. While the compensation of non-material damage is not dependent on exceeding a certain threshold of gravity (cf. 2023 - C-300/21 - juris) and, according to Recital 85 GDPR, a personal data breach may result in physical, material or non-material damage for natural persons, such as loss of control over personal data or identity theft, this does not alter the fact that a corresponding examination of the existence of damage must always be carried out in the specific individual case to be decided. Indeed, the loss of control may merely constitute damage, but does not necessarily have to do so. 2023, loc. , paras 84 et seq. ). " Accordingly, it is incumbent upon the Chamber to examine whether the Plaintiff's fears can be regarded as well founded. In this connection, it must be taken into account that the Plaintiff, who is currently 8 years old and was 5 years old at the time of the hacker attack, has, according to the statements of her father during the oral hearing, no knowledge whatsoever of the events surrounding the loss of her data.
The submission in the Plaintiff's pleadings, according to which "distressing uncertainty" over the unauthorised publication or anxieties and worries exist, therefore proves to be completely unsubstantiated due to the Plaintiff's lack of knowledge of the events. Where and insofar as it is argued that the Plaintiff is worried that her bank details might be hacked, it must be observed that it was not her account that was affected, but that of her mother. In this respect, the question arises why the Plaintiff – quite apart from her lack of knowledge – claims to have anxieties when her own account is not even affected. Furthermore, there are no indications whatsoever that the data is being misused on the darknet or otherwise, especially since the hacker attack aimed at extorting the affected companies. 2024 - VI ZR 10/24 - juris. Under that judgment as well, a "well-founded fear" on the part of the data subject is required and this fear, along with its negative consequences, must be "properly proven" (cf.
juris para 32). The BGH also states that the "mere assertion of a fear without proven negative consequences" is just as insufficient as a "purely hypothetical risk of misuse by an unauthorised third party" (cf. juris para 32). On this basis, and even taking this decision of the BGH into account, no damage can have arisen in the present case, since assertions are made in the pleadings regarding supposed anxieties of the Plaintiff which she, logically, cannot have due to her lack of knowledge of the loss of data. Furthermore, after more than three years since the hacker attack, there are not the slightest indications that the Plaintiff's data has been misused. According to the case-law of the BGH, the purely hypothetical risk of misuse is precisely not sufficient to establish non-material damage. Accordingly, there is also a lack of any compensable damage. The action proves to be unfounded in this respect.
) Declaration of Future Damage Insofar as the Plaintiff seeks a declaration that the Defendants are obliged to compensate her for all future material damage, there is already a lack of a legal interest in a declaration within the meaning of § 55 para 1 of the Social Court Act (SGG). An interest in obtaining a declaration of liability for compensation for future damage of a purely material nature depends on the probability of the pending damage occurring. If, on the other hand, based on a reasonable assessment of the individual case, the occurrence of future damage is not to be expected, even such a possibility must be denied, cf. Regional Court (LG) of Krefeld, loc. , para 36 with further references. In the present case, there are no circumstances apparent that make the occurrence of future damage probable beyond a mere theoretical fear. Quite apart from the fact that it was not the Plaintiff's bank details (but those of her mother) that were affected, with the consequence that no damage of a material nature can arise for the Plaintiff, it must be observed that the security vulnerability was remedied immediately after the hacker attack.
Since then, no damage of a material nature has occurred. Furthermore, such a possibility steadily diminishes with the progressive passage of time (Regional Court of Krefeld, loc. , para 36 with further references). It is therefore a matter of a mere theoretical fear, which is incapable of establishing a legal interest in a declaration. ) Injunction Insofar as the Plaintiff seeks an injunction, the action proves to be inadmissible. The Plaintiff requests – similarly to the plaintiff in the proceedings before the Regional Court of Trier, loc. cit. " The application is too indefinite. Thus, it does not become clear which cases of "making accessible to third parties" are intended to be covered and which security measures will correspond to the "state of the art" in the future. In this respect, the deciding Chamber joins the accurate legal reasoning of the Regional Court of Trier, loc. , after its own examination, and makes reference to it.
) Legal Fees In the absence of a claim under the statements of claim under numbers 1) to 3), there is also no claim for indemnification from pre-litigation legal fees. Accordingly, the action must therefore be dismissed. The decision on costs is based on § 197a para 1 of the Social Court Act (SGG) in conjunction with § 154 para 1 of the Rules of the Administrative Courts (VwGO). In particular, the Plaintiff is not involved in the proceedings in her capacity as a beneficiary under § 183 SGG, and compensation for damage or the declarations and injunctions sought in this connection do not constitute benefits within the meaning of § 183 SGG (cf. 2024 - B 7 AS 15/23 R - juris with further references). The determination of the value in dispute is based on § 197a para 1 sentence 1 half-sentence 1 SGG in conjunction with § 52 paras 1 and 3 of the Court Costs Act (GKG). 000,00. 000,00.