OLG München - 36 U 1054/25 e
Facts — The Data Subject had used a social network platform operated by the Controller, an Irish company, since 2013. The Controller provided “Business Tools” to third-party website operators and app providers. These tools enabled the Controller to obtain data concerning how users interacted with third-party websites and apps, including information about page visits, purchases and advertisements clicked. In November 2023, the Data Subject requested that the Controller recognize that the processing of his personal data was contrary to the parties’ contract, erase or anonymize the personal data, provide access to the personal data and pay compensation. The Data Subject subsequently brought an action before the Regional Court of Munich II, seeking a declaration that the parties’ user contract did not permit the processing, cessation of the processing of personal data collected through the Business Tools on third-party websites and apps, restriction of further processing, erasure or anonymization of previously collected data and at least €5,000 in non-material damages. The relevant data included direct and indirect identifiers, such as his name, contact details, IP address and internal identifiers, as well as website URLs, visit times, app names and information about his interactions with websites and apps. The Regional Court of Munich II dismissed the action, holding that the declaratory and erasure or anonymization claims were inadmissible, the cessation claims were legally unavailable and the damages claim had not been sufficiently substantiated. In relation to the damages claim, it found that the Data Subject had not identified specific third-party websites or apps through which his personal data had been processed. The Data Subject accordingly appealed to the Higher Regional Court of Munich. Holding — The Higher Regional Court of Munich partially upheld the appeal. First, the court held that the Controller processed the Data Subject’s personal data under Articles 4(1) and 4(2) GDPR by receiving data transmitted through its Business Tools, associating it with a user account and storing it. The Data Subject was not required to identify every website, app or individual transmission because the relevant information was principally within the Controller’s knowledge and it was sufficiently probable that he had been affected. Second, referring to CJEU C‑40/17 concerning the broad interpretation of “controller”, the court held that the Controller was a joint controller under Articles 4(7) and 26 GDPR for the collection and transmission of the personal data. It controlled the programming of the Business Tools and participated in determining the purposes and means of processing. Allocating certain obligations to third-party website and app operators did not remove its responsibility. Third, referring to CJEU C‑252/21, the court held that the Controller had not established a lawful basis for the processing of the personal data. The processing was not justified by consent under Article 6(1)(a), contractual necessity under Article 6(1)(b), a legal obligation under Article 6(1)(c), a public-interest task under Article 6(1)(e), or legitimate interests under Article 6(1)(f) GDPR. Accordingly, the court held that the controller's processing infringed Articles 5(1)(a), 5(1)(b), 5(1)(c) and 6 GDPR. Relying on CJEU C‑655/23, the court granted an injunction against future unlawful processing under German law. It also ordered restriction pending erasure under Article 18(1)(b) and erasure under Article 17(1)(d) GDPR. The court upheld the dismissal of the separate declaratory claim and also rejected anonymization of the website and app interaction data. Finally, relying on BGH VI ZR 10/24, the court awarded €1,500 under Article 82(1) GDPR for the Data Subject’s loss of control over his personal data.
Full text
Munich Higher Regional Court, Final Judgment of June 26, 2026 - 36 U 1054/25 e Source: openJur 2026, 7116 Rkr: AmtlSlg: Judgment and reformulated as follows: 1 I. Upon the plaintiff's appeal, the judgment of the Munich II Regional Court of February 27, 2025, Case No. 11 O 4629/23, is partially amended. 2 1. The defendant is ordered, under penalty of a fine to be determined by the court for each instance of non-compliance, up to €250,000.00, or alternatively, detention to be served on its legal representative or detention to be served on its legal representative for up to six months, and in the case of repeated offenses up to two years, to refrain from publishing the following personal data of the plaintiff on third-party websites and apps outside the defendant's networks: 3 a) on Personal data of the plaintiff generated by third-party websites and apps, whether transmitted directly or in hashed form, i.e., 4 - Plaintiff's email address 5 - Plaintiff's telephone number 6 - Plaintiff's first name 7 - Plaintiff's last name 8 - Plaintiff's date of birth 9 - Plaintiff's gender 10 - Plaintiff's city 11 - External IDs of other advertisers (referred to by M. Ltd. as "external ID") 12 - Client's IP address 13 - Client's user agent (i.e., collected browser information) 14 - M. Ltd.'s internal click ID 15 - M. Ltd.'s internal browser ID 16 - Subscription ID – Lead ID – anon id _ 17 and the following personal data of the plaintiff 18 b) on websites 19 - the URLs of the websites including their subpages 20 - the time of the visit 21 - the "referrer" (the website from which the user came to the current website), 22 - the buttons clicked by the plaintiff on the website, and 23 - other data referred to by M. as "Events," which document the plaintiff's interactions on the respective website 24 c) in third-party mobile apps 25 - the name of the app, and 26 - the time of the visit 27 - the buttons clicked by the plaintiff in the app, and 28 - the data referred to by M. as "Events," which document the plaintiff's interactions in the respective app 29 to be processed using M. Business Tools. 30 2. The defendant is ordered to cease further processing all personal data listed under point 1, which has already been processed by the defendant since May 25, 2018, under penalty of a fine of up to €250,000.00 to be determined by the court for each instance of non-compliance, or alternatively, imprisonment of up to six months, or in the case of repeated violations, up to two years, until the deletion claim is satisfied after the final and binding conclusion of the proceedings, and in particular, not to disclose this data to third parties. 31 3. The defendant is ordered to completely delete all personal data of the plaintiff that has already been stored since May 25, 2018, as described in point 1 a). The defendant is further ordered to refrain from further processing all personal data of the plaintiff that has already been stored since May 25, 2018, as described in point 1 a). 32 4. The defendant is ordered to pay the plaintiff €1,500.00 plus interest at a rate of 5 percentage points above the respective base interest rate since December 14, 2023. 33 II. The remainder of the claim is dismissed. 34 III. The plaintiff's further appeal is dismissed. 35 IV. The plaintiff shall bear 58% and the defendant 42% of the costs of the proceedings in both instances. 36 V. This judgment is provisionally enforceable. The defendant may avert enforcement by providing security in the amount of €4,000.00, unless the plaintiff provides security in this amount before enforcement. The plaintiff may avert enforcement by providing security in the amount of 110% of the amount enforceable under the judgment, unless the defendant provides security in the amount of 110% of the amount to be enforced before enforcement proceedings commence. 37 VI. Leave to appeal this judgment to the Federal Court of Justice is granted. 38 Decision 39 The value in dispute for the appeal proceedings is set at €9,000.00. Reasons 40 I. 41 In connection with the provision of so-called M. Business Tools by the defendant, the plaintiff asserts claims for declaratory judgment , injunctive relief , erasure, and damages due to a violation of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation; hereinafter: GDPR). 42 The decision is based on the following facts and legal arguments: 43 1. The defendant, which is based in Ireland and operated as "F. Ireland Ltd." until 27 October 2021, is the operator of the "I." network. 44 The plaintiff has been using the "I." network under the username "... " since 7 April 2013. 45 The defendant uses "M. Business Tools." With the help of these digital tools, the defendant is able to obtain data from website operators and app developers, including information on how users interact with the websites and apps of third-party companies (e.g., visits, purchases, clicked advertisements). Details regarding the specific application and the functionality of the Business Tools are disputed between the parties. 46 The defendant uses the Privacy Policy (Exhibit K1) and the Terms of Use (Exhibit B2) in its dealings with its users. Terms of Use (Exhibit B5) apply to the use of the Business Tools by third-party companies. 47 The Regional Court found it undisputed that the plaintiff, by letter from his attorney dated November 15, 2023, demanded, among other things, that the defendant acknowledge the breach of contract regarding the data processing, commit to deletion and anonymization, provide information, and pay damages (Exhibit K3). 48 2. In the first instance, the plaintiff ultimately requested, in summary, 49 1. a declaratory judgment that the parties' user agreement for the use of the network "I. " under the username " ... " does not permit the processing of the specifically listed personal data to the extent specified since May 25, 2018; 50 2. an order requiring the defendant to cease processing personal data pursuant to point 1 on third-party websites and apps outside the defendant's networks; 51 3. an order requiring the defendant to cease further processing of the personal data listed in point 1, in particular, not to disclose it to third parties, until the plaintiff requests the defendant to delete it, but no later than six months after the final and binding conclusion of the proceedings; 52 4. Order the defendant to completely delete the personal data of the plaintiff already stored pursuant to point 1. a) upon the plaintiff's request, but no later than six months after the final and binding conclusion of the proceedings, and to confirm the deletion and complete anonymization of the personal data already stored pursuant to points 1. b) and c); 53 5. Order the defendant to pay at least €5,000.00 plus interest from December 14, 2023; 54 6. Order the defendant to reimburse the plaintiff for pre-litigation legal fees in the amount of €1,295.43. 55 3. The Munich II Regional Court dismissed the action by final judgment of February 26, 2025. 56 The Regional Court dismissed the declaratory judgment action (point 1) as inadmissible because the plaintiff sought clarification of an abstract legal question, which cannot be the subject of a declaratory judgment action. The plaintiff had not presented any websites actually visited that could have provided a concrete basis for examination. The plaintiff was merely seeking an abstract interpretation of the terms of use, detached from any concrete impact on the plaintiff. Furthermore, the necessary legal interest was lacking, as the plaintiff could pursue the same objective with an action for performance, as he had done with the application for injunctive relief (point 2). The declaratory judgment action merely served as preparation for such an action. 57 The application for deletion and anonymization of the data named in point 1(a) (point 4) was also inadmissible. There was no concern about a refusal to perform, as the defendant had repeatedly declared its fundamental willingness to delete the data transmitted by third-party companies. With the "Delete previous activities" option, it offers a way to completely detach previous activity data from third parties that were linked to an F. account, thereby severing the identifying connection. The "Disconnect future activities" option prevents the storage of future connections. For deletion within the meaning of Article 17 GDPR, it is crucial that neither the controller nor a third party can access existing personal data. By "disconnecting" the activities, any reference to an identifiable natural person within the meaning of Article 4 No. 1 GDPR is removed. The plaintiff has not sufficiently demonstrated that the defendant is unwilling to delete data concerning him or that it can still identify him even after severing the data connection with the I. profile. The requested anonymization has no independent scope of application and cannot be demanded instead of deletion; it is merely a subset of deletion. 58 The Regional Court considered the plaintiff's applications for injunctive relief (points 2 and 3) to be unfounded. The court held that the injunction sought directly to prevent the defendant from processing and disclosing the data, or from disclosing the data already processed. As an application for an injunction against specific data processing operations, the application was no longer covered by the scope of protection of Article 17 GDPR, which only grants a right to erasure of personal data, but does not establish any further rights regarding the data processing operations themselves. Claims for injunctive relief under Sections 823 and 1004 of the German Civil Code (BGB) were therefore precluded.59 The Regional Court denied the claim for payment of non-pecuniary damages. A prerequisite under Article 82 GDPR or under Sections 280 Paragraph 1, 823 Paragraph 1, 253 of the German Civil Code (BGB) in conjunction with Article 2 Paragraph 1, Article 1 Paragraph 1 of the German Basic Law (GG) is that the defendant unlawfully collects or processes data from the plaintiff. The plaintiff's submissions regarding the processing of his data on third-party websites or third-party apps by the defendant were largely very general and showed little relevance to his specific situation. No conclusions could be drawn from this regarding the plaintiff's individual impact from the use of I. The plaintiff was unable to state during his informal hearing whether he had agreed to the terms of use and what he had deactivated in the settings. No specific use of particular websites on which M. Business Tools are used could be established. Whether a causal connection exists between the plaintiff's internet activities and the advertising displayed on I. cannot be verified. Furthermore, it is not clear whether the plaintiff, when visiting third-party websites, may have directly consented to data processing by those sites. The defendant bears no secondary burden of proof, as the plaintiff is aware of which websites he has used. No unlawful data transfer to unsafe third countries is apparent. Platforms I. and F. originate from the USA and, as global platforms, necessarily exchange data across borders. This should be sufficiently clear to every user of the platform. The plaintiff has no right to the storage and processing of data exclusively in Europe. The defendant's processing of data from third-party websites for the purpose of verifying the existence of consent is necessary for the pursuit of legitimate interests. 60 For further details of the facts and the legal arguments, reference is made to the factual findings of the contested judgment (Section 540, Paragraph 1, No. 1 of the German Code of Civil Procedure). Regarding the motions filed in the first instance, reference is made to the statement of facts therein. 61 4. The plaintiff appeals this judgment, having filed a timely and properly substantiated appeal. 62 The plaintiff's objective is to prevent the defendant from logging his browsing behavior in the future, i.e., the initial collection of identification and movement data by M. Business Tools, the forwarding of the data to the defendant's servers, and its initial storage there. A further objective is to have the extent of the data collection carried out to date disclosed and to have the data stored so far deleted. 63. The M. Business Tools recorded the clicks and text input of all visitors to the websites and apps in the background and sent this data to the defendant, even if the user had not given the defendant consent for this and, with regard to some data categories, even if the user had not given consent to the third-party websites (via cookie banners). Only after processing all user data by the defendant does it know to whom the data belongs and whether there are (or could be) legal grounds relating to the respective user. 64. The Munich II Regional Court misconstrued the facts. The defendant did not even deny that it collected and continues to collect the plaintiff's personal data using its business tools on third-party websites and apps, forwarded this data to its servers, and stored and further processed it there. Nor did it substantively deny further processing after storage for purposes other than displaying personalized advertising. 65 Since the plaintiff is not challenging individual, specific instances of data processing, but rather the general application of the software Business Tools to him as an individual and its default settings regarding the processing of his personal data, he does not need to describe the specific processing operations. The subject of the dispute is the abstract default settings and functions of the Business Tools with regard to the collection and forwarding of the plaintiff's personal data, as well as the (initial) storage and subsequent further processing of the received data on the defendant's servers. What is relevant to the decision is not what the defendant observed in the plaintiff, but rather that it reserves the right to monitor the plaintiff. 66 The plaintiff denies that the defendant has or had any security and/or integrity interests with regard to him and the data processing operations concerning him, that the processing of his data was necessary and appropriate to protect these alleged interests, and that in the absence of consent or a user account, the data processing is solely for "security and integrity purposes." The collection and logging of browsing behavior through the recording of personal and highly sensitive data on third-party websites and apps and its forwarding to the defendant's servers by M. Business Tools constitutes a serious infringement of his fundamental rights. The defendant is a private economic operator, is currently continuing this indiscriminate surveillance, and can create a comprehensive personality profile (communication profile) of the plaintiff. 67 The defendant violates the principles of lawfulness (Art. 5 para. 1 letter a) GDPR) and accountability (Art. 5 para. 2 GDPR). It cannot rely on the legal grounds for processing under Art. 6 para. 1 and Art. 9 para. 1 GDPR, as it does not or cannot verify whether its contractual partners obtain (proper) consent on third-party websites or apps. Furthermore, the defendant violates the principles of purpose limitation, data minimization, and storage limitation (Art. 5 para. 1 letters b), c), and e) GDPR), as it cannot specify concrete, identifiable processing purposes and potentially stores all personal data of its users without distinction as to type or sensitivity for an indefinite period. Furthermore, the defendant violates the principle of transparency (Art. 5 para. 1 lit. a) GDPR) because it does not inform users clearly and comprehensibly about the scope of data processing. 68 The declaratory judgment action (point 1) is admissible. The plaintiff's legitimate interest lies in being able to use the defendant's network in the future within the legally permissible framework without the defendant unlawfully processing his personal data. The declaratory judgment is particularly necessary to establish certainty about the currently existing legal relationship and to avoid a further judicial determination should further damages arise from it in the future. The specific legal relationship capable of being established by declaratory judgment consists of the rights arising from the parties' user agreement, i.e., the defendant's asserted rights, which it informs users about in its privacy policy and which it exercises in connection with the plaintiff's use of its service. Future damages resulting from further infringements of the plaintiff's informational self-determination pursuant to Section 823 Paragraph 1 of the German Civil Code (BGB) are clearly to be feared. No simpler or less expensive means is available to the plaintiff to achieve the objective of the application. 69 In any event, the declaratory judgment action is admissible as an interim declaratory judgment action pursuant to Section 256 Paragraph 2 of the German Code of Civil Procedure (ZPO). It is capable of being determined to what extent the plaintiff is obligated under the user agreement with the defendant to tolerate the processing of his personal data. The requested declaratory judgment need only be wholly or partially relevant to the decision on the main claim, here the injunction. A legitimate interest in obtaining a declaratory judgment is not required. 70 The claim for an injunction against future data processing (Point 2) arises primarily from Articles 17 and 79 of the GDPR. The right to erasure under Article 17 GDPR can only be used to address a data processing breach reactively, not preventively. Data processing can only be effectively prevented altogether if the data collection itself is omitted. Further legal bases for claims are Sections 1004(1) sentence 1 (analogous), 823(1) of the German Civil Code (BGB), and Sections 280(1) and 241(2) of the BGB. 71 The right to an injunction against further processing, among other things (point 3), arises from Article 18(1)(b) GDPR as well as from Section 1004(1) of the BGB (analogous) in conjunction with Article 2(1) and Article 1(1) of the German Basic Law (GG) and Sections 280(1), 241(2), and 242 of the BGB. The person affected by unlawful data processing may, instead of erasure, request the restriction of the use of their personal data. The defendant has not asserted any need for processing beyond the storage of the data. 72 The request for erasure and anonymization (point 4) is admissible. The Regional Court failed to recognize that the defendant does not offer erasure or anonymization. The "separation" of the data in the settings is clearly not erasure within the meaning of Art. 17 GDPR, since the data remains accessible even after this and could still be attributed to the plaintiff even if a different "ID" ("MID") is assigned. The defendant only performs data separation at the discretion of the authorities or not at all. Since the plaintiff has no concrete insight into the process, the defendant bears a secondary burden of proof. Anonymization is to be understood as a subcategory of erasure and not something different, since the components of the identifying data are irreversibly removed. The right to anonymization, moreover, follows from Article 18(1)(b) and (2) GDPR and from Sections 280(1), 241(2), and 242 of the German Civil Code (BGB). 73 The Regional Court wrongly rejected the claim for non-material damages (point 5). It is established that the defendant systematically processed the plaintiff's personal data through the use of M. Business Tools, that it continues to do so, and that this includes sensitive data within the meaning of Article 9 GDPR. It is irrelevant that the plaintiff is unable, without information from the defendant, to specify the concrete scope of the data processing or the individual websites affected. The plaintiff objects to the general application of the Business Tools to him as an individual and to the default settings regarding the processing of his personal data, which he cannot disable. The plaintiff argues that the constant risk of his digital private life being tracked and logged constitutes an infringement of his right to informational self-determination. The damage, as defined in Article 82 of the GDPR, consists of the plaintiff's complete loss of control. The defendant cannot invoke legitimate interests, as the plaintiff's interests and fundamental rights outweigh the defendant's interest in personalized advertising as a business model. General "security and integrity purposes" are insufficient.74 The claim for compensation is based on Section 823 of the German Civil Code (BGB) in conjunction with Article 2(1) and Article 1(1) of the German Basic Law (GG). Article 82 of the GDPR does not have a preclusive effect in light of Recital 146 of the GDPR. The significant infringement of the right to privacy is already established by the fact that, due to the way the business tools function, the plaintiff must continue to expect his browsing behavior to be recorded at any time and cannot know what the defendant has recorded about him and how it uses this information. Damage beyond the established infringement of fundamental rights is not required for this. Any identifiable pathological impairments are irrelevant. 75 The plaintiff requests, 76 1. It is declared that the parties' user agreement for the use of the network "I. " under the username " ... " does not permit the processing of the following personal data to the following extent since May 25, 2018: 77 a) personal data of the plaintiff generated on third-party websites and apps, whether transmitted directly or in hashed form, i.e. 78 - Plaintiff's email address 79 - Plaintiff's telephone number 80 - Plaintiff's first name 81 - Plaintiff's last name 82 - Plaintiff's date of birth 83 - Plaintiff's gender 84 - Plaintiff's city of residence 85 - External IDs of other advertisers (referred to by M, Ltd. as "external ID") 86 - Client's IP address 87 - Client's user agent (i.e., collected browser information) 88 - M, Ltd.'s internal click ID 89 - M, Ltd.'s internal browser ID 90 - Subscription ID 91 - Lead ID 92 - anon id _ 93 and the following personal data of the plaintiff 94 b) on websites 95 - the URLs of the websites, including their subpages 96 - the time of the visit 97 - the "referrer" (the website from which the user arrived at the current website), 98 - the buttons clicked by the plaintiff on the website, and 99 - other data referred to by M. "Events" that document the plaintiff's interactions on the respective website 100 c) in third-party mobile apps 101 - the name of the app, and 102 - the time of the visit 103 - the buttons clicked by the plaintiff in the app, and 104 - the data referred to by M. "Events" that document the plaintiff's interactions in the respective app. 105 2. The defendant is ordered, under penalty of a fine of up to €250,000.00 for each instance of non-compliance, or alternatively, imprisonment of up to six months, to be served on its legal representative, or imprisonment of up to two years, to be served on its legal representative, to refrain from processing personal data on third-party websites and apps outside the defendant's networks in accordance with application 1. 106 3. The defendant is ordered to cease further processing within the meaning of Article 4 No. 2 GDPR of all data referred to in application 1 a., b. and c. The defendant is ordered to refrain from further processing the personal data listed above, which has already been processed by the defendant since May 25, 2018, under penalty of a fine of up to €250,000.00 for each instance of non-compliance, or alternatively, imprisonment of its legal representative for up to six months, or up to two years in the case of repeated offenses, and in particular from disclosing this data to third parties, until the plaintiff requests the defendant to delete it, but no later than six months after the final and binding conclusion of the proceedings. 107 4. The defendant is ordered to completely delete all personal data of the plaintiff already stored since May 25, 2018, pursuant to application 1 a., upon the plaintiff's request, but no later than six months after the final and binding conclusion of the proceedings, and to confirm the deletion to the plaintiff, as well as all data pursuant to applications 1 b. and c. to completely anonymize personal data already stored since May 25, 2018. 108 5. The defendant is ordered to pay the plaintiff reasonable monetary compensation, the amount of which is left to the discretion of the court, but which shall be at least €5,000.00, plus interest at a rate of five percentage points above the base interest rate since December 14, 2023. 109 6. The defendant is ordered to reimburse the plaintiff for pre-litigation legal fees in the amount of €1,295.43. 110 The defendant requests that 111 the appeal be dismissed. 112 The defendant defends the decision of the Regional Court. The plaintiff has not yet decided whether to grant the defendant permission to use the information he collected about M. -products for advertising purposes or whether to subscribe to the ad-free plan. The defendant does not use any of his data to display advertising to him. Consequently, the defendant does not process business tool data to provide personalized advertising to the plaintiff. 113 The plaintiff objects solely to the processing of business tool data for the provision of personalized advertising as the only processing purpose he has specified. He has not challenged any other specific processing purposes. Therefore, the plaintiff's claim that he did not consent to the data processing is also irrelevant, since the defendant does not rely on consent for every processing purpose, but rather on various legal bases. 114 It is incorrect that a user's data is automatically collected and transmitted to the defendant via the business tools, irrespective of his consent, as soon as a third-party company has implemented them. Rather, third-party companies only transmit data about a person's activities on their website or app to the defendant via the business tools if that person actually interacts with a third-party company that uses one of the business tools. These third-party companies would have to make all necessary disclosures and obtain all rights and permissions in accordance with the Business Tool Terms of Use before they could share Business Tool data with the defendant. 115 The user could then choose via the website or app's cookie banner whether or not to consent to the placement of non-essential cookies on their device. Without consent, no HTTP request would be made and no standard technical data would be transmitted. For this purpose, the third-party companies could use either M. Pixel or a Conversion API. The third-party companies could choose whether to share event data (personal information on websites, apps, or shops) and contact information (information in hashed form that personally identifies individuals) with the defendant via the Business Tools. 116 The user could influence the purposes for which the defendant processes a user's Business Tool data (if any) via their user settings. F. and I. users must explicitly consent to allow "M. "cookies on other apps and websites." If a third-party provider transmits business tool data to the defendant and the defendant associates this information with an account that has not consented to the placement of optional "M. cookies on other apps and websites," the defendant's systems are designed by default to prevent the event from being stored or processed by normal downstream systems, instead dropping it upon capture, which can take up to approximately three hours. The defendant may "create strictly necessary technical/operational records of the event processing" which cannot be used to identify any natural person, but serve only to operate and secure the service. 117 There is a narrow exception to this, which applies to only a small portion of the incoming event data. For users who have not given their consent, the defendant uses data collected via cookies and similar technologies on other apps and websites only for security and integrity purposes. This includes – but is not limited to – the detection of anomalous activity that may be intended to disrupt the defendant's services (atypical patterns in reception rates, anomalous device/network activity), the detection of hostile actors whose actions may violate the defendant's policies (hacking activities, manipulation measures including coordinated fake behavior, security risks, especially for minors, potential criminal activities of dangerous organizations, data from prohibited sources), as well as troubleshooting and operational data collection. The scope and nature of the processing by the defendant for security and integrity purposes are determined by the behavior and decisions of third parties – both attackers and victims. If the defendant were required to exclude data from users who have not allowed cookies on third-party websites and apps from security and integrity checks, this could lead to distributed denial-of-service attacks, the use of fake accounts, or account hacking. The defendant processes personal data, including business tool data, across various M. services for users who are legally competent, for the performance of contracts (Art. 6 para. 1 lit. b) GDPR), and for users under the age of majority based on a legitimate interest (Art. 6 para. 1 lit. f) GDPR). Data is generally stored for up to 90 days, and longer if investigations continue or violations are discovered. 118 The plaintiff must provide detailed information about which third-party websites or apps he visited and when, which of these used the business tools in dispute at the time of the visit, whether he consented to the placement of non-essential cookies, and what data the third-party website or app transmitted to the defendant via the business tools. Only in this way will the defendant be able to adequately defend itself against the plaintiff's allegations. The plaintiff only needs to check his browser history for this purpose. The defendant has no secondary burden of proof. 119 The plaintiff must further explain how the processing of the data transmitted via the business tools could be unlawful, on what basis he feels a "loss of control" or "fear of misuse," and how the actions of the defendant could have caused these feelings. 120 The claims are unclear. The data for which the plaintiff seeks an injunction, erasure, anonymization, and damages are only vaguely described. 121 The declaratory judgment claim (point 1) is already inadmissible because it is too vague. There is no legitimate interest in obtaining a declaratory judgment. Furthermore, the claim does not meet the requirements of Section 256 Paragraph 1 of the German Code of Civil Procedure (ZPO). Reinterpretation as an action for an interim declaratory judgment pursuant to Section 256 Paragraph 2 of the ZPO is not possible. 122 The injunction application (point 2) is inadmissible because the plaintiff fails to specify which processing purpose is allegedly unlawful and which processing purposes, beyond the processing of business tool data for the provision of personalized advertising, are to be prohibited. A comprehensive prohibition of the processing of all data to be collected in the future is inadmissible. The defendant uses the data obtained via the business tools, among other things, for the aforementioned security purposes. Furthermore, the injunction application is vague because it does not name any specific data processing purposes or processes. Moreover, it is a disguised action for the performance of a specific action, since the third-party companies decide on the transmission of data to the defendant, and the defendant would therefore have to make changes to the programming of the business tools. Article 17 GDPR does not provide a legal basis for the claim. The requirements of Sections 823(1) and 1004 of the German Civil Code (BGB) have not been demonstrated. The processing of business tool data for the provision of personalized advertising is lawful, and the general right of personality is in no way infringed. The plaintiff's interests do not outweigh the defendant's interests, for example, with regard to the freedom to pursue a profession and the secure provision of services. No risk of recurrence has been demonstrated. The defendant does not process business tool data for the provision of personalized advertising at all for the plaintiff. Granting the injunction would lead to the cessation of the business tools' operation. If all data processing were to cease, the defendant would be unable to process the data obtained via the business tools to determine whether it constitutes personal data of the plaintiff. At least some processing is necessary to identify whether the data belongs to the plaintiff before the defendant can then decide, based on the user's settings, whether or not to take further action with regard to this specific data. Before receiving certain event data, the defendant cannot know whether it can be attributed to the plaintiff. 123 The further injunction request (point 3) is too broad and, with the plaintiff's theoretical request for deletion, contains an inadmissible extrajudicial condition. Article 18(1)(b) GDPR provides no basis for this. Moreover, the request is contradictory to the request to cease processing the plaintiff's data. 124 The request for deletion and anonymization (point 4) is inadmissible, contradicts the aforementioned injunction request, and is vague. The GDPR does not provide for a right to anonymization. The plaintiff can himself disconnect the information about activities previously shared by third-party companies from his I. account by setting a setting, even for the future. Anonymization is not a subset of deletion, as it requires data processing. Furthermore, the plaintiff can delete his I. account himself at any time. The event data may then be stored for a maximum of two years. The defendant may retain account data if necessary, e.g., for legal reasons. 125 The plaintiff has no claim for damages under Article 82 GDPR (paragraph 5). There is no breach of the GDPR provisions by the defendant. The plaintiff has not demonstrated any actual damage. There has been no "loss of control," especially since the plaintiff can control the processing of the data via the settings. Unauthorized third parties have not accessed the plaintiff's data. The defendant does not process any special categories of the plaintiff's personal data. The third-party companies are not permitted to pass on sensitive data to the defendant via the business tools. National law is not applicable due to the blocking effect; the requirements of Section 823 Paragraph 1 of the German Civil Code (BGB) are not met. The requirements of Article 2 Paragraph 1 and Article 1 Paragraph 1 of the Basic Law are not met. Punitive damages are foreign to German civil law. 126 For further details of the facts and the legal arguments, reference is made to the exchanged written submissions, in particular those of July 28, 2025, August 28, 2025, October 31, 2025, March 5, 2026, March 9, 2026, and April 7, 2026, including attachments, as well as to the minutes of the oral hearing. The unpermitted written submissions of March 17, 2026, April 7, 2026 (received April 29, 2026), and June 12, 2026, were considered without prompting a reopening of the proceedings. 127 II. 128 The Higher Regional Court of Munich has international jurisdiction over the proceedings pursuant to Articles 79(2), second sentence, and 82(6) GDPR and, pursuant to Articles 6(1), 6(2), and 3(1) of the Rome I Regulation, must apply German law. 129 1. Article 79(2), second sentence, GDPR grants the data subject the right to bring an action against a controller or processor not acting in an official capacity before the courts of the Member State in which the data subject has their habitual residence. 130 Article 82(6) GDPR provides for the jurisdiction of the courts that have jurisdiction under the laws of the Member State referred to in Article 79(2) GDPR for the exercise of the right to compensation. 131 The plaintiff, as the data subject, has their habitual residence in Germany. 132 The material, territorial, and temporal scope of the GDPR is established. 133 According to Article 2(1) GDPR, the Regulation applies to the wholly or partly automated processing of personal data as well as to the non-automated processing of personal data which are stored or are intended to be stored in a filing system. It is undisputed that the information stored by the defendant contains personal data of the plaintiff, which is collected and stored. 134 Article 3(1) GDPR declares the Regulation applicable to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, irrespective of whether the processing takes place in the Union. The defendant is based in Ireland. 135 According to Article 99(2) GDPR, the Regulation applies from 25 May 2018. Regarding the temporal applicability, the decisive factor is not the time of registration of a user account in the defendant's social network, but rather the time of the data-relevant incident (cf. Federal Court of Justice, judgment of November 18, 2024, VI ZR 10/24, NJW 2025, 298, juris para. 19 on scraping). 136 2. Pursuant to Article 6(1)(a) of Regulation (EC) No 593/2008 of the European Parliament and of the Council of 17 June 2008 on the law applicable to contractual obligations (Rome I Regulation), a contract concluded by a natural person for a purpose which is not attributable to their professional or commercial activity (“consumer”) with another person acting in the course of their professional or commercial activity (“trader”) is governed by the law of the State in which the consumer has their habitual residence, provided that the trader carries out their professional or commercial activity in the State in which the consumer has their habitual residence. Therefore, German law applies. The plaintiff is a consumer within the meaning of this provision. 137 Furthermore, the defendant's terms of use for the “dispute resolution” contain the agreement within the meaning of the above. Article 6 paragraphs 2 and 3(1) of the Rome I Regulation stipulate that a user who uses the defendant's service as a consumer may have any claim or dispute resolved by any competent court in the country of their habitual residence and that the laws of that country will apply without regard to conflict of laws rules. 138 III. 139 The admissible appeal is successful to the extent stated in the judgment. 140 1. The plaintiff is a user of the "I." network. 141 The Regional Court treated the plaintiff's assertion that he is a user of "I." as disputed. In fact, the defendant did not substantively contest this assertion. In particular, during the oral hearing of January 22, 2025, the defendant did not contradict the plaintiff's statements regarding his user relationship made during his informal hearing before the Regional Court, but rather addressed them and pointed out that he must have agreed to the terms of use during registration. The Senate therefore assumes as undisputed that a user agreement existed between the parties. 142 2. The application for a declaratory judgment that the parties' user agreement does not permit the processing of specifically identified personal data to the specified extent since May 25, 2018 (point 1) is inadmissible. There is neither a legal relationship capable of being established by declaratory judgment nor a legitimate interest in such a judgment within the meaning of Section 256 of the German Code of Civil Procedure (ZPO). Treating the application as an interlocutory declaratory judgment action within the meaning of Section 256 Paragraph 2 of the ZPO is not possible. 143 a) According to Section 256 Paragraph 1 of the Code of Civil Procedure, an action may be brought, among other things, to establish the existence or non-existence of a legal relationship if the plaintiff has a legitimate interest in having the legal relationship established by judicial decision as soon as possible.144 aa) A legal relationship is understood to be a specific, legally regulated relationship between a person and other persons or between a person and a thing. This can also include individual rights and obligations based on a more comprehensive legal relationship, but not mere elements or preliminary questions of a legal relationship, abstract legal questions, pure facts, or, for example, the validity of declarations of intent or the unlawfulness of conduct (cf. BGH, Judgment of March 7, 2013, VII ZR 223/11, NJW 2013, 1744, juris para. 16; BGH, Judgment of April 19, 2000, XII ZR 332/97, NJW 2000, 2280, juris para. 12; BGH, Judgment of April 20, 2018, V ZR 106/17, NJW 2018, 3441, juris para. 13; BGH, Default Judgment of March 27, 2015, V ZR 296/13, NJW-RR 2015, 915, juris para. 7; BGH, Judgment of June 7, 2001, I ZR 21/99, NJW 2001, 3789, juris para. 15 et seq. 145 The plaintiff's declaratory judgment action is not directed at establishing the existence or non-existence of the contract for the use of the defendant's network, nor at specific claims or obligations of the parties arising from this contract, or at establishing the scope of the defendant's performance obligations. The wording "... that the usage agreement ... does not permit ..." suggests at first glance that the plaintiff seeks a declaration that the defendant is not entitled to a right derived from and invoked by the defendant under this contract (cf. OLG Munich, Judgment of December 18, 2025, 14 U 1068/25, K&R 2026, 264, juris para. 238; Higher Regional Court of Stuttgart, Judgment of April 29, 2026, 4 U 372/24, juris para. 107). 146 However, such an interpretation, based solely on the wording, overlooks the fact that the legal relationship between the parties is not governed solely by the user agreement, but is significantly influenced by the provisions of the GDPR. It is not without reason that both parties rely decisively on the GDPR to justify their respective applications, as the GDPR, which, as an implementation of the Charter of Fundamental Rights of the European Union, can have an impact on private law (cf. Federal Constitutional Court, Decision of November 6, 2019, 1 BvR 276/17, NJW 2020, 314, juris paras. 95 et seq. regarding the Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, which came into force on 24 May 2018). The finding of "non-authorization" sought by the plaintiff is therefore not to be assessed solely on the basis of the contract, but must be examined in light of the provisions of the GDPR. Even in procedural law, the interpretation must not adhere to the literal meaning of the expression, but must ascertain the true intention of the party. In doing so, the principle must be observed that, in case of doubt, the intended meaning is that which is reasonable according to the standards of the legal system and corresponds to the well-understood interests of the parties (Federal Court of Justice, Judgment of 4 July 2014, V ZR 298/13, NJW 2014, 3314, juris para. 15; Federal Court of Justice, Default Judgment of March 27, 2015, V ZR 296/13, NJW-RR 2015, 915, juris para. 8; Federal Court of Justice (BGH), Judgment of August 1, 2013, VII ZR 268/11, NJW 2014, 155, juris para. 30; Federal Court of Justice (BGH), Judgment of June 7, 2001, I ZR 21/99, NJW 2001, 3789, juris para. 17). The plaintiff himself argues decisively that the defendant, with its actions, violates various provisions of the GDPR and that it cannot rely on the justifications provided for by the GDPR. Thus, the plaintiff seeks not merely to have the defendant's actions declared unlawful, but rather to establish the illegality of the specifically listed actions. Data processing operations (“… not permitted”). However, the decision regarding the legality or illegality of an action within the framework of a contractual relationship cannot be the subject of Section 256 Paragraph 1 of the German Code of Civil Procedure (ZPO). 147 bb) A legitimate interest in a declaratory judgment within the meaning of Section 256 Paragraph 1 of the German Code of Civil Procedure (ZPO) exists if the specific right affected by the declaratory judgment action of the plaintiff is threatened by a present danger of uncertainty and the desired declaratory judgment is suitable to eliminate this danger. However, the legitimate interest in a declaratory judgment is lacking if the plaintiff can achieve the same objective with an action for performance and this is possible and reasonable because, in the interest of better legal protection, the plaintiff can clarify the subject matter of the dispute in one proceeding. A declaratory judgment action is permissible despite the possibility of bringing an action for performance, however, if conducting the declaratory judgment proceedings leads to a sensible and appropriate resolution of the disputed issues from the perspective of procedural economy (Federal Court of Justice, Judgment of November 9, 2022, VIII ZR 272/20, NJW 2023, 1567, juris para. 30; Federal Court of Justice, Judgment of June 2, 2022, VII ZR 160/21, HFR 2022, 1180, juris para. 11; Federal Court of Justice, Judgment of October 5, 2021, VI ZR 136/20, NJW-RR 2022, 23, juris para. 15; Federal Court of Justice, Judgment of June 17, 1994, V ZR 34/92, NJW-RR 1994, 1272, juris para. 15; BGH, default judgment of March 27, 2015, V ZR 296/13, NJW-RR 2015, 915, juris para. 8). 148 The plaintiff himself points out that a "performance action" is available to him to achieve his claim. For the past, the plaintiff demands quantified damages and the deletion or anonymization of the data already collected; for the future, the plaintiff formulates an injunction. Within the scope of these claims, the lawfulness of the data processing by the defendant or any breaches of duty by the defendant in the context of data processing must be clarified as preliminary issues anyway. The claims for performance thus exhaust his legal objective. Therefore, there is no room for a separate declaratory judgment action. 149 Furthermore, in light of the defendant's objections, it can be ruled out that the requested declaratory judgment could lead to a final resolution of the disputed issues. The plaintiff cannot enforce a mere declaratory judgment for legal reasons, whereas the enforcement of any injunction is possible. 150 cc) On an ongoing development of damages, where part of the damage has already occurred at the time the lawsuit is filed, but the occurrence of further damages is still to be expected (cf. Federal Court of Justice, Judgment of November 18, 2024, VI ZR 10/24, NJW 2025, 298, juris para. 48; Federal Court of Justice, Judgment of October 5, 2021, VI ZR 136/20, NJW-RR 2022, 23, juris para. 25; Federal Court of Justice, Judgment of May 2, 2022, VIa ZR 122/21, WM 2022, 1077, juris para. 15; Federal Court of Justice, Judgment of June 2, 2022, VII ZR 160/21, HFR 2022, 1180, juris para. 25), the plaintiff cannot rely on this because the declaratory judgment action does not extend to a declaration of any further liability for damages on the part of the defendant. 151 b) The declaratory judgment action cannot be reinterpreted as an interlocutory declaratory judgment action. 152 Pursuant to Section 256 para. 2 of the German Code of Civil Procedure (ZPO), the plaintiff may, until the conclusion of the oral hearing on which the judgment is based, request by amending the statement of claim that a legal relationship that has become disputed during the course of the proceedings, on whose existence or non-existence the decision of the legal dispute depends in whole or in part, be established by judicial decision. 153 An interlocutory declaratory judgment action does not require a special interest in obtaining a declaratory judgment. The prerequisite is that the determination of the legal relationship is a preliminary step for the decision in the legal dispute (Federal Court of Justice, Judgment of June 17, 1994, V ZR 34/92, NJW-RR 1994, 1272, juris para. 13). However, an action for a declaratory judgment cannot be directed at establishing the illegality or inadmissibility of conduct (Federal Court of Justice, Judgment of April 20, 2018, V ZR 106/17, NJW 2018, 3441, juris para. 13). 154 As already stated, the plaintiff expressly seeks a declaration that the user agreement—and, according to the Senate's interpretation, the GDPR—does not authorize the defendant to carry out specific data processing operations with regard to certain data. The plaintiff cannot achieve this declaratory judgment by filing a motion under Section 256 para. 2 of the German Code of Civil Procedure. 155 3. The application for an injunction against the processing of personal data pursuant to point 1 of the application outside the defendant's networks is admissible and well-founded. on third-party websites and apps 156 a) It should be noted at the outset that the Senate interprets the application as the plaintiff seeking an injunction against the future processing of personal data collected on third-party websites and apps outside the defendant's networks using the Business Tools and forwarded to the defendant. The plaintiff has made the objective of his action unequivocally clear. He wishes to prevent the future logging of his browsing behavior by the defendant. In this context, he has expressly listed the collection of his data by the Business Tools, the forwarding of the data to the defendant's servers, and the (initial) storage there as procedures that he considers objectionable. The plaintiff's claim is therefore not to prohibit the defendant from processing data on third-party websites and apps outside its networks, as the wording of the application might suggest. The defendant has stated that it is neither the owner, administrator, nor operator of third-party websites or apps. The plaintiff is thus challenging the processing of data relating to him collected on third-party websites and apps outside the defendant's networks and transmitted to the defendant. Since the plaintiff, according to his submissions, assumes that data collected via third-party websites or apps will be transmitted to the defendant even if he has not given his consent via the cookie request, the application must be interpreted as unrestricted. 157 b) The application for an injunction is admissible. 158 aa) The application is sufficiently specific within the meaning of Section 253 Paragraph 2 No. 2 of the German Code of Civil Procedure (ZPO). The statement of claim must then contain a specific description of the subject matter and the grounds of the claim, as well as a specific request. 159 (1) It is not necessary whether the relevant facts of the case have already been fully described in the statement of claim or whether the claim has been presented in a coherent or substantiated manner. Rather, in accordance with the purpose of bringing an action, which is to make clear to the debtor the creditor's intention to enforce his claims, it is generally sufficient if the claim as such is identifiable (Federal Court of Justice, Judgment of 18 July 2000, X ZR 62/98, NJW 2000, 3492, juris para. 17; Federal Court of Justice, Judgment of 11 February 2004, VIII ZR 127/03, NJW-RR 2005, 216, juris para. 6). 160 The plaintiff must, within the scope of the admissibility of the application, specify individual concrete data processing operations, i.e. h. on which website or app they occurred, at what time, etc., are not specified. The plaintiff has sufficiently clarified his claim in conjunction with his statement of claim. 161 (2) A statement of claim is sufficiently specific if it concretely identifies the claim being asserted, thereby defining the scope of the court's decision-making authority (§ 308 of the Code of Civil Procedure), reveals the content and extent of the res judicata effect of the requested decision (§ 322 of the Code of Civil Procedure), does not shift the risk of the plaintiff losing the case to the defendant through avoidable imprecision, and allows for enforcement of the judgment without further litigation in enforcement proceedings. The requirements for the specificity of the claim must therefore be determined by weighing the defendant's legitimate interest in being able to mount a comprehensive defense against the claim, as well as their interest in legal clarity and certainty regarding the effects of the decision, against the plaintiff's equally legitimate interest in effective legal protection. In the case of an injunction, this means in particular that it must not be formulated so vaguely that the decision as to what is prohibited for the defendant ultimately remains with the enforcement court. Sufficient specificity is usually given in an injunction application if reference is made to the specific infringing act or the specific form of infringement being challenged is the subject of the application, and the claim, at least in conjunction with the plaintiff's submissions, makes it unambiguously clear which characteristics of the challenged conduct are the basis and the point of reference for the infringement and thus for the injunction (Federal Court of Justice, Judgment of November 18, 2024, VI ZR 10/24, NJW 2025, 298, juris para. 52 et seq.; Federal Court of Justice, Judgment of March 9, 2021, VI ZR 73/20, NJW 2021, 1756, juris para. 15; Federal Court of Justice, Judgment of June 2, 2022, I ZR 140/15, NJW 2022, 2980, juris para. 26; Federal Court of Justice (BGH), Judgment of July 28, 2022, I ZR 205/20, NJW-RR 2022, 1417, juris para. 12; Federal Court of Justice (BGH), Judgment of March 31, 2026, VI ZR 157/24, juris para. 20; Federal Court of Justice (BGH), Judgment of January 15, 2019, VI ZR 506/17, NJW 2019, 781, juris para. 12). Federal Court of Justice (BGH), Judgment of July 28, 2022, I ZR 205/20, NJW-RR 2022, 1417, juris para. 12. 162 The use of terms requiring interpretation is appropriate if further specification is not possible or reasonable for the plaintiff, and there is no doubt between the parties as to their content, so that the scope of the application and the judgment is clear (Federal Court of Justice, Judgment of 31 March 2026, VI ZR 157/24, juris para. 20). Furthermore, the use of terms requiring interpretation in the statement of claim is permissible if there is no dispute between the parties regarding their meaning and objective criteria for differentiation exist, or if the plaintiff describes the term requiring interpretation with sufficient specificity and, if necessary, provides examples or bases their claim on the specific infringement (Federal Court of Justice, Judgment of November 18, 2024, VI ZR 10/24, NJW 2025, 298, juris para. 53; Federal Court of Justice, Judgment of June 2, 2022, I ZR 140/15, NJW 2022, 2980, juris para. 26). An application formulation that requires interpretation may, moreover, be accepted if this is necessary to guarantee effective legal protection (Federal Court of Justice, Judgment of July 28, 2022, I ZR 205/20, NJW-RR 2022, 1417, juris para. 12). 163 Measured against these requirements, the plaintiff's application is – in the Senate's interpretation – sufficiently specific. The injunction application, taking into account the plaintiff's submissions, specifies the alleged infringement, namely the alleged unlawful processing of data obtained by the defendant via business tools. The personal data, the processing of which he seeks to prevent, has been sufficiently identified by linking it to point 1 of the claim. The reference to third-party websites and third-party apps does not preclude specificity. The injunction application clearly covers all third-party websites and third-party apps on which a business tool of the defendant is implemented. 164 The fact that the plaintiff uses the term "processing," a term from the GDPR, does not render the application vague. According to Article 4 No. 2 GDPR, "processing" means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction. With regard to the legal definition, both parties are therefore clear about the content of the application. 165 bb) The injunction application is not lacking in standing. 166 (1) The need for legal protection is lacking if an action or application is objectively pointless, i.e., if the plaintiff cannot under any circumstances obtain any legitimate benefit from their procedural request. This is the case, for example, if there is a simpler or cheaper way to achieve the objective of legal protection or if the plaintiff has no legitimate interest in the requested decision. However, strict standards apply. The need for legal protection is lacking (or ceases to exist) only if pursuing the proceedings is clearly contrary to their purpose and constitutes an abuse of the administration of justice. The plaintiff may also not be referred to a procedurally uncertain course of action (Federal Court of Justice, Judgment of September 29, 2022, I ZR 180/21, NJW-RR 2023, 66, juris para. 10, 16; Federal Court of Justice, Judgment of November 18, 2024, VI ZR 10/24, NJW 2025, 298, juris para. 66 et seq.). 167 (2) While the defendant correctly points out that the plaintiff can easily delete his account with the defendant, the result achieved thereby does not correspond to the plaintiff's objective of legal protection, who wishes to use the defendant's network but does not want to be permanently "monitored" by it. When the defendant offers its products on the European market, it submits to the provisions of the GDPR. Recital 78 of the GDPR prioritizes the protection of the rights and freedoms of natural persons with regard to the processing of personal data and requires controllers to establish internal strategies and implement measures that comply, in particular, with the principles of data protection by design and by default. The recital cites as examples minimizing the processing of personal data, pseudonymizing personal data as quickly as possible, and ensuring transparency regarding the functions and processing of personal data. The GDPR guarantees citizens a uniform and high level of data protection with regard to all applications authorized on the European market, including social media platforms (see Higher Regional Court of Dresden, Judgment of February 3, 2026, 4 U 292/25, juris para. 144). If the plaintiff could be required to delete his account with the defendant, the protective purpose of the GDPR would be undermined, as the plaintiff would then be obligated to protect himself. 168 (3) The reference to the plaintiff's option to restrict processing via the settings under "Your activities outside M. Technologies" also does not render the injunction application inadmissible. 169 "Disconnect certain activities" means that activities from apps and websites that the user must select are no longer stored in his accounts. "Delete past activities" means that information about activities shared by third-party companies is removed from the user's account. "Unlink with future activities" means that information that companies and organizations transmit to the defendant about interactions with the user will no longer be linked in the future. The transfer of personal data from third-party companies to the defendant remains unaffected (Higher Regional Court of Dresden, judgment of February 3, 2026, 4 U 292/25, juris para. 144). 170 c) The application is also well-founded. The plaintiff is entitled to the requested injunction pursuant to § 1004 para. 1 sentence 2 of the German Civil Code (BGB) by analogy, § 823 para. 1 BGB in conjunction with Art. 2 para. 1, Art. 1 para. 2 of the German Basic Law (GG), Art. 6 GDPR due to the violation of his general right of personality. 171 (aa) The GDPR itself does not contain any provisions that expressly or implicitly provide that the data subject has a right to preventively demand, by way of legal action, that the controller of personal data be obliged to refrain from any future infringement of the provisions of the GDPR, in particular in the form of repeating unlawful processing. However, Member States are not prevented from providing for such a preventive remedy with the aim of requiring the controller to refrain from any further infringement of the rights under the GDPR (ECJ, Judgment of 4 September 2025, C-655/23, NJW 2025, 3137, juris paras. 43, 46). 172 It is therefore necessary to resort to the general provisions of civil law, here §§ 1004 para. 1 sentence 2 of the German Civil Code (BGB) by analogy, § 823 para. 1 BGB. The claim for injunctive relief requires that there be a concrete risk (in the sense of a risk of initial infringement or repetition) that the defendant is currently processing the plaintiff's personal data collected via the business tools, that the defendant is the controller for this processing, and that it fails to demonstrate and prove a justification pursuant to Art. 6 GDPR for this data processing. The risk of repetition required for the claim for injunctive relief is indicated by the established infringing conduct (Higher Regional Court of Dresden, Judgment of February 3, 2026, 4 U 292/25, juris para. 146). 173 bb) The plaintiff was not required to name specific websites or apps on which the defendant's business tools are implemented and through which the plaintiff's personal data was made available to the defendant in order to substantiate his claim for injunctive relief. 174 (1) While, in principle, the claimant must assert and prove all the facts from which his claim is derived, the burden of proof for the claim for injunctive relief rests with the plaintiff. The principle of good faith requires however, a secondary burden of proof on the opposing party if the party bearing the burden of proof is outside the sequence of events it must present and has no knowledge of the relevant facts, while the opposing party can reasonably provide more detailed information given the different levels of information available to both parties (Federal Court of Justice, Judgment of October 5, 2023, III ZR 216/22, NJW 2023, 3794, juris para. 31). Within the scope of this secondary burden of proof, the opposing party is also obligated to undertake reasonable investigations. If the opposing party fails to meet its secondary burden of proof, the claimant's assertion is deemed admitted pursuant to Section 138 Paragraph 3 of the German Code of Civil Procedure (BGH, default judgment of February 4, 2021, III ZR 7/20, NJW 2021, 1759, juris para. 19; BGH, judgment of June 28, 2016, VI ZR 559/14, NJW 2016, 3244, juris para. 18). 175 (2) The defendant does not dispute that numerous websites (in the areas of news, media, and shopping) use its business tools. As part of its business model, it must even have a significant interest in ensuring the widest possible distribution of its business tools, since the user data collected in this way enables not only third-party companies, but also the defendant itself, to display personalized advertising to the user on the platforms it operates, including "I." , provided the user has consented. Furthermore, the defendant cites its own security and integrity interests, which also necessitate extensive data collection and processing if the defendant wants to achieve all the objectives it has listed in this context. An average internet user who regularly shops online or frequently uses various websites or apps to access news, weather, or political information cannot be expected to disclose which of the websites or apps they visit use the defendant's business tools. Given the easy availability of information on the internet and the commonplace use of the internet for a wide variety of tasks, it is unreasonable to expect a user to permanently log and archive their entire browsing behavior in order to prove, in the event of a dispute, when they accessed which websites or apps. An obligation to do so cannot be justified by the plaintiff's primary burden of proof for an injunction. The permanent "self-monitoring" of a user and the retention of all data about their browsing behavior is not required, as this would require them to disclose their entire internet usage, which would clearly contradict the purpose of the GDPR (see Higher Regional Court of Dresden, Judgment of February 3, 2026, 4 U 292/25, juris para. 142). 176 In addition, the plaintiff submitted lists of websites with Exhibits K2, K13, and K14 on which, according to him, the business tool "M. Pixel" is implemented. These include websites of well-known newspapers and banks. The defendant did not substantively dispute this, but merely objected that the plaintiff had not demonstrated which of the listed websites he had visited and when, and that—with regard to Exhibit K2—there was no evidence that the websites used the business tools in question. However, the defendant can easily ascertain the latter. In any case, the defendant did not deny the widespread use of its business tools. Moreover, it remains unclear how the plaintiff is supposed to determine which of the defendant's business tools were active on which of the websites he visited and what data was transmitted to the defendant as a result. The fact that a window opens when a website is accessed and consent to cookies is requested is not, from the user's perspective, a reliable indicator that the defendant is behind it. It is therefore sufficient if it is established with some probability that the plaintiff, as an internet user, has been and is being affected by the data processing in dispute (see Higher Regional Court of Dresden, judgment of February 3, 2026, 4 U 292/25, juris para. 142). This is the case here. 177 cc) The defendant has processed the plaintiff's personal data in the past, even though the plaintiff has not given his consent to the use of his information collected via business tools for advertising purposes. 178 (1) In view of the comprehensive concept of processing in Article 4(2) GDPR, which includes any operation or set of operations performed on personal data, whether or not by automated means (see ECJ, Judgment of 24 February 2022, C-175/20, K & R 2022, 260, juris para. 35), this already constitutes processing. 179 The defendant collects, records, and stores data using the Business Tools. How the defendant further processes the information it collects depends in part on the privacy settings of the respective user. According to its own submissions, the defendant first receives the Business Tool data transmitted by third-party providers and checks whether the account holder has given consent under "M. Cookies on other apps and websites." However, this check is only possible for the defendant if it personalizes the received data and links it to a user account. If the user does not permit the use of cookies and similar technologies in third-party apps and websites, the data collected there will not be used to generate and display personalized advertising. Nevertheless, the defendant still receives and uses the data, even if, as it claims, it discards it after up to three hours. If the defendant considers security and integrity interests to be affected, it will even use the data beyond this period without regard to consent. The plaintiff, therefore, cannot completely prevent the collection, transmission, and storage of personal data via the business tools, regardless of their consent. 180 (2) According to Article 4 No. 1 GDPR, “personal data” means any information relating to an identified or identifiable natural person; A natural person is considered identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person. 181 The term "identifiable" is to be interpreted broadly, given the expression "all information." It is not limited to sensitive or private information, but potentially encompasses all types of information, both objective and subjective, in the form of opinions or assessments, provided that it is information "about" the person in question. This condition is met if the information, due to its content, purpose, or effects, is linked to a specific person (ECJ, Judgment of 20 December 2017, C-434/16, NJW 2018, 767, juris para. 34 et seq., regarding the similarly worded Article 2(a) of Directive 95/46/EC; ECJ, Judgment of 4 May 2023, C-487/21, NJW 2023, 2253, juris para. 23 et seq.; German Federal Court of Justice, Judgment of 18 December 2025, I ZR 115/25, MDR 2026, 174, juris para. 22). 182 The data listed by the plaintiff in claim no. 1, which is the subject of his claim for injunctive relief, falls under this definition. The defendant herself admits that she compares the data transmitted by third-party providers to determine whether it can be associated with a user account. According to Recital 26, sentence 1 of the GDPR, to determine whether a natural person is identifiable, all means which are reasonably likely to be used by the controller or another person to identify the natural person directly or indirectly, such as discrimination, should be taken into account. 183 dd) The defendant is a controller within the meaning of Article 4, no. 7, first half-sentence of the GDPR. According to this provision, a "controller" is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. 184 With regard to the GDPR's objective of ensuring a high level of protection of the fundamental freedoms and rights of natural persons, in particular their privacy, with regard to the processing of personal data, the term "controller" is to be interpreted broadly. Moreover, the term does not necessarily refer to a single entity and can refer to several actors involved in this processing, each of whom is then subject to data protection regulations. Any natural or legal person who, out of self-interest, influences the processing of personal data and thus participates in the decision-making regarding the purposes and means of this processing can be considered a controller. The joint controllership of several actors for the same processing does not require that each of them has access to the personal data in question. Various actors may be involved in the processing of personal data at different stages and to varying degrees, so that the degree of responsibility of each of them must be assessed taking into account all the relevant circumstances of the individual case (ECJ, Judgment of 29 July 2019, C-40/17, NJW 2019, 2755, juris para. 65 et seq. on the predecessor regulation 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and the identically worded Article 2(d), first sentence).185 The defendant cannot therefore rely on the fact that the third-party providers may only transmit the data if the user has given their consent in the cookie banner and that they have instructed the third-party providers accordingly. For two or more controllers, Article 26(1) GDPR stipulates that they are joint controllers if they jointly determine the purposes and means of processing. An agreement should transparently specify which of them fulfills which obligation under the GDPR, in particular with regard to exercising the rights of the data subject, and which fulfills which information obligations under Articles 13 and 14 GDPR, insofar as the respective tasks of the controllers are not already defined by Union or Member State law to which the controllers are subject. The defendant is not relieved of its responsibility by agreements with third-party providers or by reference to their own data protection obligations, since it retains control over the programming of the business tools and continues to co-decide which data is collected and transmitted. By offering its business tools to third-party companies, with the help of which it indisputably intends to obtain as much data as possible from users of third-party websites for its own purposes, the defendant also becomes a joint controller within the meaning of Article 26 GDPR for the data collection on third-party websites. 186 Accordingly, the defendant has assumed joint responsibility for the collection and transmission of data in the terms of use of the M. Business Tools (see Exhibit B 5). 187 ee) The defendant cannot rely on any legal justification for the processing of personal data. 188 (1) The burden of proof that personal data are processed in accordance with Article 5 GDPR lies with the controller (ECJ, Judgment of 4 July 2023, C-252/21, NJW 2023, 2997, juris para. 95; ECJ, Judgment of 24 February 2022, C-175/20, K&R 2022, 260, juris para. 77; ECJ, Judgment of 11 July 2024, C-757/24, NJW 2024, 2523, juris para. 52). This leads to a reversal of the burden of proof in the sense that the data subject does not have to prove that the controller has not acted lawfully and has not implemented the appropriate technical and organizational measures to implement the principles, but rather the controller must prove that the processing complies with the GDPR principles (Ehmann/Selmayr/Heberlein, DatenschutzGrundverordnung, 3rd edition 2024, Art. 5 para. 43). 189 (2) According to Art. 5 para. 1 letter a) GDPR, personal data must be processed lawfully, fairly and in a transparent manner in relation to the data subject. Lawfulness refers to Art. 6 para. 1 GDPR. GDPR 190 - According to Article 6(1)(a) GDPR, processing is lawful if the data subject has given consent to the processing of their personal data for one or more specific purposes. 191 This condition is not met. It is irrelevant whether the plaintiff gave or refused consent to the collection of data by the business tools within the meaning of Article 6(1)(a) GDPR via the cookie banner on the websites or apps. 192 The defendant itself admitted that there are processing purposes for which it does not rely on consent from the outset because it does not consider this legally required. These are, in particular, data that the defendant uses for security and integrity purposes and which are transmitted to it even if a user refuses consent. Furthermore, the defendant primarily considers the third-party companies to be responsible for correctly implementing the business tools, making all necessary disclosures, and obtaining the required rights and permissions before transferring business tool data to the defendant. The third-party companies that have integrated the business tools into their websites or apps can choose whether to share event data and contact information with the defendant. This means that there is no automatic consent-based mechanism for whether or not data is transferred to the defendant; rather, this depends on each individual third-party company. Likewise, the defendant does not verify whether the third-party companies have transferred the data based on consent. Therefore, the defendant cannot determine the lawfulness of the processing in every case. 193 - According to Article 6(1)(b) GDPR, processing is lawful if it is necessary for the performance of a contract to which the data subject is a party or in order to take steps at the request of the data subject prior to entering into a contract. 194 The defendant's argument that its actions are necessary for users with legal capacity under this provision is not convincing. For the processing of personal data to be considered necessary for the performance of a contract within the meaning of this provision, it must be objectively essential to achieve a purpose that is a necessary component of the contractual service provided to the data subject. The controller must therefore be able to demonstrate how the main subject matter of the contract could not be fulfilled without the processing in question. The mere fact that such processing is mentioned in the contract or is merely useful for its performance is irrelevant in this respect. The decisive factor for the application of the justification ground is that the processing of personal data by the controller is essential for the proper performance of the contract concluded between the controller and the data subject, and that therefore no practicable and less intrusive alternatives exist (ECJ, Judgment of 4 July 2023, C-252/21, NJW 2023, 2997, juris para. 98 et seq.). 195 Insofar as the defendant receives and stores business tool data in order to compare it with whether the identifiable user has given consent to be shown personalized advertising on this basis, this processing operation is not necessary for providing the user with the services of the social network. Furthermore, the defendant's arguments extend to the overall functionality of I. without demonstrating why the data processing is specifically indispensable for the contract with the plaintiff. 196 Article 6(1)(c) GDPR requires that processing be lawful if it is necessary for compliance with a legal obligation to which the controller is subject. 197 According to Article 6(3) GDPR, the legal basis for this processing is determined either by Union law or by the law of the Member State to which the controller is subject. The legal basis must pursue an objective in the public interest and be proportionate to the legitimate aim pursued, and the processing must be limited to what is strictly necessary (ECJ, Judgment of 4 July 2023, NJW 2023, 2997, C-252/21, juris para. 138). 198 The defendant has not identified any such legal basis. The mere reference to the possibility of detecting potential criminal offenses or preventing offenses is not sufficient to justify the storage of personal data, as the defendant does, citing security and integrity interests. The defendant is a private company that has not been assigned any law enforcement tasks. It is not legally obligated to collect and store personal data in advance in order to respond to requests from national authorities for user data. Ultimately, the defendant only highlights this aspect as one of several, but prioritizes the functionality of its social network model as worthy of protection, which is insufficient within the meaning of Article 6(1)(d) GDPR. 199 - According to Article 6(1)(e) GDPR, processing must be necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. 200 In this respect, the same applies as above. This exception is also not met, particularly with regard to the "necessity" requirement. A task in the public interest exists, for example, with regard to research for the benefit of society or the promotion of protection, integrity, and security. However, given the nature and essentially economic and commercial character of the defendant's activity as a private economic operator, it is not apparent that such a task has been assigned to it (see ECJ, Judgment of 4 July 2023, NJW 2023, 2997, C-252/21, juris para. 133). Article 6(1)(f) GDPR provides that processing must be necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child. 202 First, the controller or a third party must pursue a legitimate interest; second, the processing of personal data must be necessary for the purposes of the legitimate interest; and third, the interests or fundamental rights and freedoms of the data subject whose data are to be protected must not override the legitimate interests of the controller or a third party (ECJ, Judgment of 4 July 2023, NJW 2023, 2997, C-252/21, juris para. 106).203 Recital 47 states, among other things, that the existence of a legitimate interest must be carefully weighed, taking into account whether a data subject, at the time the personal data are collected and in light of the circumstances under which they are collected, can reasonably foresee that processing for this purpose may occur. In particular, where personal data are processed in situations where a data subject cannot reasonably expect further processing, the interests and fundamental rights of the data subject may outweigh the controller's interest. The recital cites the prevention of fraud as a potential legitimate interest of the controller in processing personal data to the extent strictly necessary. Recital 49 refers to the potential legal interest of, among others, operators of electronic communication networks and services in ensuring network and information security, i.e., insofar as the processing of personal data ensures the ability of a network or information system to reliably prevent disruptions or unlawful or malicious interference that could impair the availability, authenticity, completeness, and confidentiality of stored or transmitted personal data, as well as the security of related services offered or accessible via these networks or information systems. Examples include preventing unauthorized access to electronic communication networks and the dissemination of malicious code, as well as defending against attacks such as targeted server overload ("denial-of-service" attacks) and damage to computer and electronic communication systems. 204 Although the defendant invokes the protection of minors, its statements make it clear that its primary concern is to identify potential sources of disruption to the functioning of its network. The defendant remains vague, failing to specify which concrete data it processes and for what purpose, and also clarifies that it cannot provide a comprehensive list of reasons for retaining users' personal data for 90 days or longer. The defendant thus claims discretionary power that precludes a balancing of interests with the fundamental rights of users and an assessment of whether the defendant has a legitimate interest in data processing. In any case, indiscriminate mass surveillance cannot be justified by the interest in tracking down individual criminals (cf. Higher Regional Court of Hamm, Judgment of March 9, 2026, 8 U 21/25, juris para. 136). Overall, the defendant fails to present the factual basis that is supposed to support the necessity of the data processing, although this must be examined before the actual balancing of interests (BeckOK Datenschutzrecht/Albers/Veit, as of February 1, 2026, Art. 6 GDPR, para. 69; cf. Higher Regional Court of Stuttgart, judgment of April 29, 2026, 4 U 372/24, juris para. 173 et seq.). 205 The Senate therefore already considers Art. 5 para. 1 letter a) GDPR to be infringed, apart from the fact that the defendant's explanations as to when it considers processes to be security-relevant and therefore stores the corresponding data for a longer period do not meet the transparency requirement. 206 (3) Furthermore, the defendant has also violated Art. 5 para. 1 letter b), first half-sentence. Article 1 of the GDPR, which stipulates that personal data must be collected for specified, explicit, and legitimate purposes and may not be further processed in a manner incompatible with those purposes. Furthermore, it violated the principle of data minimization in Article 5(1)(c) of the GDPR, according to which personal data must be adequate, relevant, and limited to what is necessary for the purposes for which they are processed. The foregoing considerations apply accordingly. 207 et seq.) The preceding unlawful infringement establishes a factual presumption of a risk of recurrence. 208 4. The injunction sought to prevent further processing of personal data until a request for erasure or the expiry of a period of six months from the date the decision becomes legally binding (point 3) is also admissible and well-founded. 209 a) The Senate interprets the plaintiff's application, in conjunction with the request for erasure and anonymization in point 4, as meaning that he wishes to restrict the processing of his personal data, which the defendant currently still holds and which it has not already erased due to the expiry of retention periods, etc., until the erasure claim is satisfied. 210 b) The plaintiff is entitled to an injunction pursuant to Article 18(1)(b) GDPR. This states that the data subject has the right to request from the controller the restriction of processing where the processing is unlawful and the data subject objects to the erasure of the personal data and instead requests the restriction of its use. 211 The right to restriction of processing can also be invoked in connection with a request for erasure. Although Article 18(1) GDPR, according to its wording, grants the data subject a choice between restriction of processing and erasure, The Senate does not consider a phased approach to asserting the right to erasure, as in the present case, to be precluded. In both cases, the data subject has a legitimate interest in the controller not processing the data in question without restriction while examining whether a right to erasure actually exists (Simitis/Hornung/Spieker/Dix, Datenschutzrecht [Data Protection Law], 2nd edition 2025, Art. 18 GDPR, para. 3). The right to restriction of processing pursuant to Art. 18 para. 1 letter b) GDPR therefore applies for the period until the data is erased at the data subject's request. Thus, the data subject is not prevented from later exercising their right to erasure by exercising their right to choose restriction (Ehmann/Selmayr/Kamann/Braun, Datenschutz-Grundverordnung [General Data Protection Regulation], 3rd edition 2024, Art. 18, para. 17). The right to restriction of processing pursuant to Art. 18 para. 1 letter b) GDPR therefore applies for the period until the data is erased at the data subject's request. 212 The requirements of the provision are met, as the processing of the plaintiff's personal data by the defendant was unlawful. Reference is made to the above. 213 c) The Senate has adjusted the operative part of the judgment in accordance with the interpretation of the application and has refrained from including the plaintiff's request or the expiry of six months after the judgment becomes final as the end dates for the requested injunction. 214 5. The plaintiff is entitled to the erasure of the data listed in point 1. a), but not to the anonymization of the data listed in points 1. b) and c) (point 4). 215 a) The application is not admissible in its entirety. 216 aa) The application is sufficiently specific. The plaintiff refers again to the list in point 1 of the statement of claim and distinguishes between the personal data to be erased (point 1. a) and the data to be anonymized (points 1. b) and c). It can therefore remain open whether a request for optional deletion or anonymization would be sufficiently specific (cf. Higher Regional Court of Munich, judgment of December 18, 2025, 14 U 2300/25, juris para. 222). 217 bb) The action is directed at future performance within the meaning of Section 259 of the German Code of Civil Procedure (ZPO) and requires that, under the circumstances, there is a justified concern that the debtor will evade timely performance. For this concern to exist, it suffices that the debtor seriously disputes the claim or the obligation to perform. Bad faith or even malicious intent is not required (Munich Commentary on the German Code of Civil Procedure/Becker-Eberhard, 7th edition 2025, Section 259 para. 13). The defendant denies its obligation to delete personal data, at least insofar as it considers itself entitled to continue storing some of the data for security and integrity reasons. This is sufficient for an action for future performance. 218 The plaintiff's request for confirmation of the deletion is inadmissible. 219 This request is based on Article 15(1) GDPR, since deletion, according to Article 4(2) GDPR, constitutes a form of data processing. This includes the negative confirmation that no personal data is (or is no longer) being processed (BeckOK Data Protection Law/Worms, as of November 1, 2024, Article 17 GDPR, para. 89). Article 12(3), sentence 1 of the GDPR stipulates that the controller must provide the data subject with information about the measures taken in response to a request pursuant to Articles 15 to 22 of the GDPR without undue delay, and in any event within one month of receipt of the request. However, the requirements of Section 259 of the German Code of Civil Procedure (ZPO) are not met in this regard. It is not apparent that the defendant will refuse to provide the corresponding information. 220 cc) The fact that the plaintiff makes the request subject to a suspensive condition does not render it inadmissible. The request is nevertheless sufficiently specific. The events to which the plaintiff links the deletion or anonymization are easily ascertainable. These are the plaintiff's request, which can be reliably established prior to enforcement proceedings. In addition, the plaintiff has specified an end date for the activities to be carried out, which can be easily calculated. 221 b) The request for erasure is based on Article 17(1)(d) GDPR. According to this provision, the data subject has the right to request from the controller the erasure of personal data concerning him or her without undue delay, and the controller is obliged to erase personal data without undue delay where the personal data have been unlawfully processed.222 Regarding the lack of legality, reference is made above. 223 However, insofar as the plaintiff links the deletion to a request by him, with a specifically determinable date at the latest, this is not covered by Article 17 GDPR. The plaintiff is invoking a right to determine performance within the meaning of Section 315 Paragraph 1 of the German Civil Code (BGB), which is not granted to him. According to the wording of the law, the deletion must be carried out without undue delay within the meaning of Section 121 of the German Civil Code (BGB). Article 12 Paragraph 3 Sentence 1 GDPR supplements the requirement of without undue delay by setting a period of one month as an absolute time limit for the decision on the request for rectification and the notification thereof to the data subject. The deadline can be extended by two months in complex cases (Ehmann/Selmayr/Kamann/Braun, General Data Protection Regulation, 3rd edition 2024, Art. 17 para. 42). If the defendant is thus legally ordered to delete the plaintiff's personal data, the deadlines stipulated in the GDPR come into effect. Therefore, there is no basis for a separate request from the plaintiff, especially since, by choosing a deadline of six months from the date the judgment becomes legally binding, he makes it clear that he reserves the right not to issue a request. Moreover, the plaintiff has no apparent need for legal protection as to why the data, whose deletion he fundamentally seeks, should remain beyond the statutory deadline. The plaintiff's limitations in the wording of the application are irrelevant, since, as explained, the timing of the deletion is not at his discretion. 224 c) The plaintiff cannot, however, derive a claim to anonymization from Article 17 GDPR, since this article only regulates erasure. 225 A broad interpretation of the provision, such that the term erasure also includes anonymization, is not permissible. The European legislator differentiates between erasure (Article 4 No. 2 GDPR), destruction (Article 4 No. 2 GDPR), anonymization (Recital 26 GDPR), and pseudonymization (Article 4 No. 5 GDPR) of data, defining only the term pseudonymization. Despite this differentiation, the legal basis in Article 17(1)(d) GDPR is limited to erasure. The purpose of erasure is to ensure that the data is permanently unusable, irreversibly unreadable, and no longer processable. Erasure applies to the entire data set. Data anonymization, on the other hand, is a procedure in which some of the data is retained, but the data subject can no longer be identified based on the remaining data. This can involve considerably more effort than deletion; however, the remaining part of the data can still be used despite the anonymization. Therefore, anonymization is not a lesser form of deletion, but rather something different (Higher Regional Court of Hamm, Judgment of March 9, 2026, 8 U 21/25, juris para. 143; Higher Regional Court of Stuttgart, Judgment of April 29, 2026, 4 U 372/24, juris para. 220). Article 18(1)(b) GDPR cannot serve as a legal basis for anonymization. The data subject then has the right to request from the controller the restriction of processing if the processing is unlawful and the data subject objects to the erasure of the personal data and instead requests the restriction of its use. However, this does not correspond to the plaintiff's objective, who, through anonymization, seeks to have personal data concerning him and identifying him rendered unrecognizable by the defendant. The defendant should no longer be permitted to use this data in relation to the plaintiff at all, which goes beyond a mere restriction of use. 227 6. The plaintiff is entitled to non-material damages in the amount of €1,500.00 pursuant to Article 82(1) GDPR due to the data processing at issue. 228 a) The plaintiff asserts a single claim for compensation for non-material damage, which is based on several data protection breaches by the defendant but stems from a single event. This is permissible (Federal Court of Justice, Judgment of November 18, 2024, VI ZR 10/24, NJW 2025, 298, juris para. 16; Higher Regional Court of Hamm, Judgment of March 9, 2026, 8 U 21/25, juris para. 149). 229 b) A claim for damages within the meaning of Article 82(1) GDPR requires a breach of the General Data Protection Regulation, the existence of material or non-material damage, and a causal link between the damage and the breach, these three requirements being cumulative. The burden of proof for these requirements lies with the person claiming compensation for (non-material) damage under Article 82(1) GDPR (Federal Court of Justice, Judgment of November 18, 2024, VI ZR 10/24, NJW 2025, 298, juris para. 21; European Court of Justice, Judgment of October 4, 2024, C-507/23, NJW 2025, 141, juris para. 24; European Court of Justice, Judgment of April 11, 2024, C-741/21, NJW 2024, 1561, juris paras. 34 et seq.; European Court of Justice, Judgment of January 25, 2024, C-687/21, NJW 2024). 2009, juris para. 58; ECJ, Judgment of 21 December 2023, C-667/21, K & R 2024, 114, juris para. 82; ECJ, Judgment of 4 May 2023, C-300/21, NJW 2023, 1930, juris para. 32; ECJ, Judgment of 14 December 2023, C-340/21, NJW 2024, 1091, juris para. 77). 230 The GDPR does not refer to the law of the Member States for the meaning and scope of the terms contained in Article 82, in particular with regard to the terms "material or non-material damage" and "compensation". It follows that these terms are to be regarded as autonomous terms of Union law for the application of the GDPR, which must be interpreted uniformly in all Member States (ECJ, Judgment of 4 May 2023, C-300/21, NJW 2023, 1930, juris para. 30; ECJ, Judgment of 14 December 2023, C-456/22, K & R 2024, 112, juris para. 15). According to Recital 146, sentence 3 of the GDPR, the concept of damage should be interpreted broadly in a manner that fully complies with the objectives of the GDPR, namely the objective of ensuring a uniform and high level of protection of natural persons with regard to the processing of personal data within the Union (Federal Court of Justice, Judgment of 28 January 2025, VI ZR 183/22, NJW 2025, 1059, juris para. 9; European Court of Justice, Judgment of 14 December 2023, C-456/22, K&R 2024, 112, juris paras. 19 et seq.). 231 c) Regarding the defendant's infringement of the GDPR, reference is made to the above. 232 d) The plaintiff has sufficiently demonstrated that he suffered damage as a result of the defendant's breach of data protection regulations. 233 aa) The mere breach of the provisions of the General Data Protection Regulation (GDPR) is not sufficient to establish a claim for damages. Damage is not presumed simply because of a breach of the GDPR (ECJ, Judgment of 20 June 2024, NJW 2024, 2599, C-182/22, juris para. 42). The occurrence of damage in the context of unlawful processing of personal data is merely a potential, not an automatic, consequence of such processing. Furthermore, a breach of the GDPR does not necessarily lead to damage. Finally, a causal link must exist between the infringement in question and the damage suffered by the data subject (ECJ, Judgment of 4 October 2024, C-507/23, NJW 2025, 141, juris para. 27; ECJ, Judgment of 4 May 2023, C-300/21, NJW 2023, 1930, juris para. 37). 234 Therefore, in addition to an infringement of the GDPR, it is necessary – as an independent requirement for a claim – for actual damage (caused by this infringement) to have occurred, which the data subject must prove. On the other hand, compensation for non-material damage may not be made dependent on the damage suffered by the affected person reaching a certain degree of severity or significance (Federal Court of Justice, Judgment of 18 November 2024, VI ZR 10/24, NJW 2025, 298, juris para. 28 et seq.; European Court of Justice, Judgment of 25 January 2024, C-687/21, NJW 2024, 2009, juris para. 59 et seq.; European Court of Justice, Judgment of 11 April 2024, C-741/21, NJW 2024, 1561, juris para. 36; European Court of Justice, Judgment of 4 May 2023, C-300/21, NJW 2023, 1930, juris). Paragraph 46; ECJ, Judgment of 20 June 2024, C-590/22, VersR 2024, 1302, juris paragraph 28). 235 Therefore, even the – albeit temporary – loss of control over personal data can constitute non-material damage, without this concept of “non-material damage” requiring proof of additional tangible negative consequences such as the misuse of the data to the detriment of the data subject (German Federal Court of Justice, Judgment of 18 November 2024, VI ZR 10/24, NJW 2025, 298, juris paragraph 30; ECJ, Judgment of 4 October 2014, C-200/23, juris paragraph 145). The damage suffered as such, i.e., The affected party must, however, prove the loss of control. Once established, this loss itself constitutes the non-material damage, and no further specific fears or anxieties of the affected person are required; these would only be likely to further deepen or increase the non-material damage already incurred (Federal Court of Justice, Judgment of November 18, 2024, VI ZR 10/24, NJW 2025, 298, juris para. 31; European Court of Justice, Judgment of June 20, 2024, C-590/22, K&R 2024, 503, juris para. 33). 236 bb) The plaintiff has sufficiently demonstrated that the defendant's breach of the GDPR had negative consequences for him, constituting non-material damage. Even according to the procedure last described by the defendant – which was disputed by the plaintiff – it accepts the data transmitted by the third-party providers without checking whether these providers have correctly implemented the business tools, whether they have properly informed their users, whether they have obtained the users' consent to data collection in accordance with the requirements, or whether they actually respect a lack of consent. The defendant then assigns this (personal) data to a user account. Thus, user data is initially stored on the defendant's servers.The defendant further claims to delete the data after up to three hours if it determines that the user has not given consent to the provision of personalized advertising. On the other hand, it retains certain data if it deems this appropriate for security and integrity purposes, without any clear regulation indicating which data the defendant subjects to the categories it lists and for what reason. The Senate considers this approach to constitute a loss of control for the plaintiff. 237 The plaintiff has not proven any further damages. 238 e) The defendant is liable under Article 82(1) GDPR. It has not rebutted the presumption of fault under Article 82(3) GDPR. 239 Article 82 GDPR provides for liability for presumed fault. Thus, in the context of a claim for damages under Article 82(1) GDPR, it is not the data subject who has to prove fault on the part of the controller, but rather the burden of proof lies with the controller under Article 82(3) GDPR (Federal Court of Justice, Judgment of 18 November 2024, VI ZR 10/24, NJW 2025, 298, juris para. 21; European Court of Justice, Judgment of 11 April 2024, C-741/21, NJW 2024, 1561, juris para. 46; European Court of Justice, Judgment of 21 December 2023, C-667/21, K&R 2024, 114, juris para. 103). According to Article 82(3) GDPR, the controller or processor is exempt from liability under Article 82(2) GDPR if they prove that they are in no way responsible for the circumstances that caused the damage. 240 The defendant is the "publisher" of the business tools and controls their programming. The fact that third-party providers integrate them into their apps or websites does not absolve the defendant of responsibility, even though it may be their responsibility to obtain users' consent to cookies, etc. The defendant's aim is to generate as much data as possible, either to provide the third-party providers with the service promised by the business tools or to display personalized advertising to its own users. Even if users have not consented, the defendant stores the transmitted data at least temporarily, and even for a medium or long term if it considers security and integrity interests to be affected. 241 f) Damages in the amount of €1,500.00 appear appropriate and sufficient. 242 aa) The GDPR does not contain any provision regarding the calculation of damages owed under Article 82 GDPR. Consequently, for the purpose of this assessment, national courts must, in accordance with the principle of procedural autonomy, apply the national provisions of the individual Member States concerning the scope of financial compensation, provided that the EU law principles of equivalence and effectiveness defined by the CJEU are observed (CJEU, Judgment of 11 April 2024, C-741/21, NJW 2024, 1561, para. 58; CJEU, Judgment of 4 October 2024, C-507/23, NJW 2025, 141, para. 32; CJEU, Judgment of 25 January 2024, C-687/21, NJW 2024, 2009, para. 53; CJEU, Judgment of 21 December 2023, C-667/21, K & R 2024, 114, juris para. 83; ECJ, Judgment of 4 May 2023, C-300/21, NJW 2023, 1930, juris para. 54; ECJ, Judgment of 20 June 2024, NJW 2024, 2599, C-182/22, juris para. 27). 243 It must be taken into account that the right to compensation laid down in Article 82(1) GDPR has exclusively a compensatory function. It does not serve a deterrent or even punitive function, which is why the existence of several infringements relating to the same processing operation does not lead to an increase in damages (Federal Court of Justice, Judgment of 18 November 2024, VI ZR 10/24, NJW 2025, 298, juris para. 18; European Court of Justice, Judgment of 11 April 2024, C-741/21, NJW 2024, 1561, juris paras. 59 et seq., 64 et seq.; European Court of Justice, Judgment of 25 January 2024, C-687/21, NJW 2024, 2009, juris para. 47; European Court of Justice, Judgment of 21 December 2023, C-667/21, K & R 2024, 114). juris para. 85; BGH, Judgment of January 28, 2025, VI ZR 183/22, NJW 2025, 1059, juris para. 10; ECJ, Judgment of June 20, 2024, NJW 2024, 2599, C-182/22, juris para. 23). 244 This has the consequence, among others, that the severity of such an infringement must not affect the amount of damages awarded, and that the damages must not be set at a level that exceeds the full compensation of the damage (ECJ, Judgment of 4 October 2024, C-507/23, NJW 2025, 141, juris para. 43; ECJ, Judgment of 11 April 2024, C-741/21, NJW 2024, 1561, juris para. 60; ECJ, Judgment of 25 January 2024, C-687/21, NJW 2024, 2009, juris paras. 48, 52; ECJ, Judgment of 21 December 2023, C-667/21, K & R 2024, 114, juris para. 86; ECJ, Judgment of 20 June 2024, C-590/22, VersR 2024, 1302, juris para. 41). Furthermore, Article 82 GDPR does not require that the degree of fault on the part of the controller be taken into account when determining the amount of damages (ECJ, Judgment of 21 December 2023, C-667/21, K & R 2024, 114, juris para. 103; BGH, Judgment of 28 January 2025, VI ZR 183/22, NJW 2025, 1059, juris para. 11; ECJ, Judgment of 20 June 2024, NJW 2024, 2599, C-182/22, juris para. 28). Furthermore, it is not relevant that a violation of the GDPR also entails a violation of national regulations relating to the protection of personal data, but which do not aim to clarify the provisions of the GDPR (ECJ, Judgment of 20 June 2024, C-590/22, VersR 2024, 1302, juris para. 48). Likewise, the attitude and motives of the controller are not taken into account, at least not if this is intended to grant the data subject compensation that is less than the actual damage suffered (ECJ, Judgment of 4 October 2024, C-507/23, NJW 2025, 141, juris para. 45). 245 Therefore, in view of its compensatory function, financial compensation based on Article 82 GDPR is to be regarded as “full and effective” if it makes it possible to fully compensate for the actual damage suffered as a result of the infringement of that Regulation, without such full compensation requiring the imposition of punitive damages. (ECJ, Judgment of 11 April 2024, C-741/21, NJW 2024, 1561, juris para. 60 et seq.; ECJ, Judgment of 4 October 2024, C-507/23, NJW 2025, 141, juris para. 34, 40; ECJ, Judgment of 21 December 2023, C-667/21, K & R 2024, 114, juris para. 84) ECJ, Judgment of 4 May 2023, C-300/21, NJW 2023, 1930, juris para. 58; BGH, Judgment of 28 January 2025, VI ZR 183/22, NJW 2025, 1059, juris para. 11; ECJ, Judgment of 20 June 2024, C-590/22, VersR 2024, 1302, juris para. 42). Indications include, among other things, the potential sensitivity of the specific personal data affected (cf. Art. 9 para. 1 GDPR) and its typical intended use, the nature of the loss of control (limited/unlimited group of recipients), the duration of the loss of control, and the possibility of regaining control (Federal Court of Justice, Judgment of November 18, 2024, VI ZR 10/24, NJW 2025, 298, juris para. 99). 246 bb) Based on this, the Senate assesses the damage caused by the loss of control at €1,500.00. The violation of the GDPR affects the plaintiff's personal sphere. The plaintiff could not oversee which data the defendant, according to its own statements, discards after up to three hours (assuming this assertion is accurate) and which data it retains for security and integrity purposes. The defendant's actions are likely to give the plaintiff the feeling that his private life is being continuously monitored without him being able to exert any significant influence over it. It is not impossible that the data processing also included sensitive information (email addresses, IP addresses, name, health data, etc.) that was not even remotely necessary for the purposes of the contract. 247 In this respect, once his data came under the defendant's control, the plaintiff no longer had any means of control. The duration of the breach depends on the defendant's assessment of whether it needs the data to maintain the functionality of its service. The defendant has practiced this since the GDPR came into force, i.e., for several years. 248 The Senate considers the €750.00 awarded by the Higher Regional Court of Munich (judgment of 18 December 2025, 14 U 2300/25) and the €500.00 awarded by the Higher Regional Court of Stuttgart (judgment of 29 April 2026, 4 U 353/24) to be insufficient, while simultaneously considering the €3,000.00 awarded by the Higher Regional Court of Jena (judgment of 2 March 2026, 3 U 31/25) to be excessive. The Senate is guided by the decisions of the Higher Regional Court of Hamm (judgment of March 9, 2026, 8 U 13/25, €1,500.00), the Higher Regional Court of Dresden (judgment of February 3, 2026, 4 U 292/25, €1,500.00), and the Higher Regional Court of Saxony-Anhalt (judgment of February 5, 2026, 9 U 44/25, €1,250.00) and considers damages in this area appropriate in the present case as well. 249 g) The plaintiff has no further claim for damages due to violation of the general right of personality under Section 823 Paragraph 1 of the German Civil Code (BGB) in conjunction with Article 2 Paragraph 1 and Article 1 Paragraph 1 of the German Basic Law (GG). 250 A culpable violation of the general right of personality can indeed give rise to a claim for monetary compensation if it is a serious infringement and the impairment cannot be adequately remedied in any other way. Whether such a serious infringement of the right of personality exists that the payment of monetary compensation is necessary can only be assessed based on all the circumstances of the individual case. In this regard, the significance and scope of the infringement, as well as the occasion and motive of the person acting and the degree of their culpability, must be taken into account. The granting of monetary compensation under the aforementioned conditions is justified by the principle that the right to privacy would otherwise remain without sufficient protection against serious infringements, with the consequence that the legal protection of personality would be weakened (Federal Court of Justice, Judgment of March 12, 2024, VI ZR 1370/20, NJW 2024, 2836, juris para. 70; Federal Court of Justice, Judgment of September 15, 2015, IV ZR 175/14, NJW 2016, 789, juris para. 38).251 The Senate is of the opinion, however, that the plaintiff's infringement can be satisfactorily remedied by awarding an appropriate amount pursuant to Article 82 GDPR. 252 h) The award of interest is based on Sections 280(1) and 286(1) of the German Civil Code (BGB). 253 By letter from his attorney dated November 15, 2023, the plaintiff demanded payment of €5,000.00 from the defendant by December 6, 2023 (Exhibit K3). Although the defendant (again) argued in the appeal proceedings that she had not received the pre-litigation letter from the plaintiff's attorneys, the Regional Court had already established this fact in its undisputed statement of facts. No correction has been made. Although the claim is higher than the amount awarded, it is not so excessive as to preclude it from being treated as a formal demand for payment. ... 254 7. The plaintiff is not entitled to reimbursement of pre-litigation legal fees under Article 82(1) GDPR on the grounds of necessary costs of appropriate legal action. 255 The costs of legal action, and therefore also the costs of a lawyer involved in the case, are generally considered part of the damages recoverable for a tort, insofar as they were necessary and appropriate for the exercise of rights (Federal Court of Justice, Judgment of November 17, 2015, VI ZR 492/14, NJW 2016, 1245, juris para. 9). Necessity is a genuine prerequisite for a claim, which must be demonstrated and proven by the injured party, and not merely a circumstance relevant under Section 254 of the German Civil Code (BGB), which limits the liability for damages and thus falls under the burden of proof and demonstration of the tortfeasor. The question of whether this requirement is met cannot be answered generally, but only by considering the specific circumstances of the individual case (Federal Court of Justice [BGH], Judgment of July 27, 2010, VI ZR 261/09, NJW 2010, 3035, juris para. 14, 26 et seq.; cf. Federal Court of Justice [BGH], Judgment of June 22, 2021, VI ZR 353/20, NJW-RR 2021, 1070, juris para. 6; Federal Court of Justice [BGH], Judgment of January 22, 2019, VI ZR 403/17, juris para. 11). 256 The plaintiff has not demonstrated why it was necessary to demand performance again separately from the defendant, who, as is known to the court, is defending herself against any and all claims, in a separate, pre-litigation demand. 257 IV. 258 The decision on costs is based on Sections 91(1) and 92(1) of the German Code of Civil Procedure (ZPO) for the first instance, and additionally on Section 97(1) ZPO for the appeal. 259 The decision on provisional enforceability follows from Sections 708 No. 10, 711, and 709 ZPO. 260 The determination of the value in dispute is based on Sections 47(1) Sentence 1 and 48(1) Sentence 1 of the German Court Costs Act (GKG) in conjunction with Section 3 ZPO. According to Section 40 GKG, the relevant point in time for assessing the value in dispute for the purposes of calculating court fees is the time of filing the application that initiates the proceedings, i.e., in the appeal proceedings, the filing of the appeals. 261 The Senate assesses the applications as follows: 262 Item 1 a): 263 €500.00 264 Item 1 b): 265 €500.00 266 Item 1 c): 267 €500.00 268 Item 2: 269 €1,000.00 270 Item 3: 271 €1,000.00 272 Item 4: 273 €500.00 274 Item 5: 275 €5,000.00 276 The application for payment of the costs of pre-litigation legal proceedings does not increase the value in dispute (Federal Court of Justice, decision of September 25, 2007, VI ZB 22/07, NJW-RR 2008, 374, juris) Paragraph 4 et seq.). 277 V. 278 The Senate has granted leave to appeal pursuant to Section 543 Paragraph 1 No. 1, Paragraph 2 Sentence 1 No. 2 of the Code of Civil Procedure. Ensuring uniform jurisprudence is necessary in view of the large number of pending proceedings and the differing approaches of the courts.