BGH - VI ZR 97/22
Facts — An employee of a private bank (the controller) erroneously sent a third party a message that was intended for a candidate in the controller’s staff selection process (the data subject) in October 2018. The message contained the data subject’s full name and information about their salary expectations. After the data subject was informed they were no longer considered for the position, they brought court proceedings requesting injunctive relief in order to prohibit the controller from processing the data subject’s personal data in connection with their job application. In addition, the data subject claimed non-material damages. The court of first instance granted the injunction and awarded the data subject € 1,000 in damages. The appellate court upheld the injunction but rejected the damages claim. The Federal Court of Justice (BGH) referred several questions to the CJEU regarding the interpretation of Article 82 GDPR. The CJEU rendered its judgment in September 2025. It held that Member States may provide for injunctive relief in national law in cases of unlawful processing. According to the CJEU, negative feelings caused by a loss of control over personal data can also constitute non-pecuniary damages. Holding — First, the Federal Court of Justice held that the data subject was entitled to non-material damages in accordance with Article 82 GDPR. The court confirmed the appellate court had correctly found that sending the message containing personal data to a third party had been unlawful due to the lack of a legal basis under Article 6(1) GDPR – the data subject had not consented to the processing. Furthermore, the controller had not argued that the processing would have been lawful under a different legal basis. The court also confirmed that the data subject had suffered non-material damage as a result of this GDPR violation. In the present case, the data subject’s concern that the recipient of the message might use the personal data contained in it for their own job applications already constituted loss of control of the data subject’s personal data and was therefore enough to establish a claim for damages under Article 82 GDPR. The court referred the case back to the appellate court so that it could determine the amount of non-material damages. Finally, the court held that the appellate court had erroneously upheld the data subject’s claim for injunctive relief: there was no risk of recurrence required for such a claim in German law. As the staff selection process in which the data subject had participated had already been completed, there was no likelihood whatsoever that such an infringement of the data subject’s rights would recur.
Full text
Federal Court of Justice VI ZR 97/22 June 23, 2026 rewis logo REWIS: LEGAL TECHNOLOGY Case Law Database Information provided without guarantee © REWIS UG (limited liability) URL: https://rewis.io/s/u/jRzc/ Federal Court of Justice 6th Civil Division 2 VI ZR 97/22 dated June 23, 2026 | rewis.io VI ZR 97/22 dated June 23, 2026 Judgement | Federal Court of Justice | 6th Civil Division Headnote 1. On the concept of non-pecuniary damage within the meaning of Art. 82 of the GDPR. 2. On the requirements for a claim for injunctive relief under national law directed against the repeated transfer of personal data in violation of the General Data Protection Regulation. Disposition Upon appeal by the plaintiff and the defendant, the judgement of the 13th Civil Division of the Higher Regional Court of Frankfurt am Main, with its seat in Darmstadt, dated March 2, 2022, is set aside. Upon the defendant’s appeal, the judgement of the Darmstadt Regional Court—13th Civil Chamber— dated May 26, 2020, is amended to the extent that it granted the plaintiff’s claim for an injunction. To that extent, the lawsuit is dismissed. In all other respects, the case is remanded to the appellate court for a new hearing and decision, including on the costs of the appeal proceedings. As a matter of law Facts of the Case 1 The plaintiff is filing a lawsuit against the defendant for the disclosure of personal data, seeking an injunction and compensation for non-pecuniary damages. 2 The plaintiff was in the process of applying for a position at the defendant’s private bank, which took place via the online portal Xing. In the course of this process, an employee of the defendant sent a message via the portal’s messenger service on October 23, 2018, via the portal’s messenger service, a message intended solely for the plaintiff to a third party who was not involved in the application process. The message read as follows: “Dear Mr. K [plaintiff’s last name], I hope you are well! Our manager—Mr. R[...]— finds your sales representative profile very interesting. However, we cannot meet your salary expectations 3 VI ZR 97/22 dated June 23, 2026 | rewis.io meet your salary expectations. He can offer 80k + variable compensation. Would this still be of interest to you under these circumstances? I look forward to hearing from you and wish you a great start to your Tuesday. Best regards, I[...] J[...]" 3 The third party, who had worked with the plaintiff some time ago at the same holding company and therefore knew him, forwarded the message to the plaintiff and asked whether it was intended for the plaintiff and whether he was looking for a job. 4 After the defendant informed the plaintiff that he would no longer be considered for the application process, the plaintiff objected to the sending of the message dated October 23, 2018, to the third party. In a letter from his attorney dated February 25, 2019, the plaintiff filed a lawsuit against the defendant and demanded that the defendant issue a cease-and-desist declaration subject to a penalty, provide information regarding data processing, pay damages, and reimburse legal costs . The defendant subsequently issued a declaration of cessation subject to a penalty—which specifically referred to the repeated dissemination of the message dated October 23, 2018, in its exact wording—and rejected the remaining claims. 5 The plaintiff asserts that his—non-pecuniary—damage does not lie in the abstract loss of control over the disclosed data, but rather in the fact that at least one additional person who knows the plaintiff and potential as well as former employers—is now aware of circumstances that are subject to confidentiality. There is reason to fear that the third party, who works in the same industry, may have disclosed the data contained in the message or, by virtue of this knowledge, may gain an advantage as a competitor in any job applications . Furthermore, he considers the “defeat” in the salary negotiations to be a humiliation that he would not have disclosed to third parties—especially not to potential competitors. The plaintiff has requested that the defendant be ordered to refrain in the future from processing or having processed personal data regarding the plaintiff that is related to his job application, if this occurs as in the message sent via the Xing portal to Mr. F. W. on October 23, 2018, and to pay the plaintiff non-pecuniary damages of at least €2,500 plus interest, as well as pre-trial attorney’s fees plus interest. 6 The Regional Court ordered the defendant, as requested, to cease and desist and to pay the sum of €1,000 plus interest, as well as to reimburse pre-trial attorneys’ fees plus interest. In all other respects, it dismissed the lawsuit. Upon the defendant’s appeal, the Higher Regional Court amended the Regional Court’s judgement with respect to the asserted claim for non-pecuniary damages and dismissed the lawsuit in that regard, while dismissing the appeal in all other respects. It dismissed the plaintiff’s joinder appeal challenging the amount of the awarded compensation. The plaintiff challenges this decision with his appeal to the Federal Court of Justice, which was admitted by the appellate court, and in which he continues to pursue his claims in full. 4 VI ZR 97/22 of June 23, 2026 | rewis.io In its appeal—and, in the alternative, by way of a cross-appeal—the defendant seeks the complete dismissal of the lawsuit. 7 By order dated September 26, 2023 (VI ZR 97/22, VersR 2024, 582), the Senate stayed the proceedings and referred questions to the Court of Justice of the European Union (hereinafter “the Court of Justice”) regarding the interpretation of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with respect to the processing of personal data, on the free flow of data, and repealing Directive 95/46/EC (General Data Protection Regulation, GDPR, OJ EU L 119 of May 4, 2016, p. 1) for a a preliminary ruling. The Court of Justice made a decision on the referral in its judgement of September 4, 2025 (Case C-655/23, NJW 2025, 3137). Reasons for the Decision I. 8 In support of its decision, published inter alia in WRP 2022, 628 , that the plaintiff is entitled to a claim against the defendant under Article 17(1) of the GDPR for an injunction against the processing of his personal data, provided that such processing takes place in the form of the message at issue. By transmitting the message, the defendant disclosed the plaintiff’s personal data—namely, his last name, his gender as inferred from the form of address, the fact of an ongoing job application process with the defendant, and his salary expectations—to a third party. Even if several people on the Xing platform share the plaintiff’s last name, this does not preclude the plaintiff’s identifiability, since not all information necessary for identification need be in the possession of a single person. By collecting, recording, organizing, storing, and disclosing the data to third parties as part of the job application process, the defendant is processing this data. The required risk of repetition or risk of a first-time violation exists. As long as the defendant does not take sufficient measures to prevent unintentional errors of the Art type with the necessary certainty in the future, there remains a risk of corresponding data protection violations. The cease-and-desist declaration submitted is limited to the exact wording of the message and does not provide sufficient protection against new acts of infringement. Furthermore, the defendant continues to maintain that the incident at issue did not constitute a data protection violation. 9 On the other hand, the plaintiff has no claim for damages under Art. 82 of the GDPR, since, in any case, there is no evidence that the plaintiff suffered any damage . Although there was a violation of the General Data Protection Regulation through the transfer of personal data to an uninvolved third party, as well as 5 VI ZR 97/22 of June 23, 2026 | rewis.io there was also a violation of Article 34(1) of the GDPR. However, beyond the established violation, a prerequisite for monetary compensation is the proof of specific—including non-pecuniary—damage, which includes anxiety, stress, and losses in terms of convenience and time. The plaintiff has not demonstrated such damage. His arguments are limited to the allegation of a data protection violation. Even assuming “humiliation” had occurred, it should not be classified as non-pecuniary damage, since the plaintiff had not even specified the salary range he had been aiming for or whether the amount offered was associated with any discrediting of his reputation. 10 Finally, the plaintiff is entitled to reimbursement of pre-trial attorney’s fees based on the value in dispute of the validly asserted claim for injunctive relief. II. 11 The plaintiff’s admissible appeal is well-founded. Contrary to the assessment of the court of appeals, the plaintiff is entitled in principle to a claim for damages against the defendant pursuant to Art. 82(1) of the GDPR. Under this provision, any person who has suffered material or non-material damage as a result of a violation of the General Data Protection Regulation is entitled to compensation from the controller or the processor. These requirements are met in the present case. 12 1. The temporal (Art. 99(2) GDPR) and territorial (Art. 3(1) GDPR) scope of application of the General Data Protection Regulation is established. 13 2. The Regulation is also applicable ratione materiae (Art. 2(1) GDPR). The contested message contained personal data by stating the plaintiff’s last name, his gender as inferred from his title, the fact that the job application process, and the defendant’s position regarding the plaintiff’s application and his salary expectations—which were indirectly disclosed in terms of their magnitude— personal data within the meaning of Art. 4(1) GDPR. This information related to a natural person identified by the defendant (as the controller within the meaning of Article 4(7) of the GDPR), who had the plaintiff’s contact information and resume on file. Viewed as a whole, the information—contrary to the Beklagten - den Kläger auch für dritte Personen als bestimmungsgemäßen Empfänger der Nachricht identifizierbar, jedenfalls soweit diesen der Kläger und dessen beruflicher Werdegang bekannt war. Dafür spricht neben dem Umstand, dass die Nachricht schon durch die Namensnennung und Bezeichnung des gender (see Art. 4 No. 1 GDPR)—is also supported by the fact that the person, who was not involved in the application process but had worked with the plaintiff at the same holding company and therefore knew him, was able, upon receiving the message at issue, to specifically address the 6 VI ZR 97/22 of June 23, 2026 | rewis.io plaintiff regarding his application. The fact that additional information may be required to identify the person in question does not preclude classifying the data in question as personal data (see CJEU, Judgement of March 7, 2024—C-479/22, K&R 2024, 333, paras. 45, 47–49, 55, 60 with further references). Nor is this precluded in the present case by the fact that the contact was initiated by the third party by way of a follow-up inquiry. The data subject is not required to prove that he or she was actually identified (see CJEU, Judgement of March 7, 2024—C-479/22, loc. cit., para. 61). 14 The sending of the message by an employee of the defendant via the messaging service of an online portal to a third party constitutes (partially) automated processing of personal data in the form of disclosure by transmission, as exemplified in Art. 4 No. 2 of the GDPR (see, regarding the unanimous—and broad—understanding of the concept of automated processing within the meaning of Art. 2(1) of the GDPR, e.g., Bäcker in BeckOK Datenschutzrecht, as of August 1, August 2023, Art. 2 GDPR, para. 2; Zerdick in Ehmann/Selmayr, GDPR, 3rd ed., Art. 2 margin note 3; Kühling/Raab in Kühling/Buchner, GDPR BDSG, 4th ed., Art. 2 GDPR, margin note 15; Ernst in Paal/Pauly, GDPR and BDSG, 4th ed., Art. 2 GDPR, para. 5). 15 3. The defendant violated provisions of the General Data Protection Regulation . The appellate court correctly found that the contested processing of the plaintiff’s personal data by the defendant pursuant to Art. 6(1) GDPR was unlawful; in particular, it was not based on the plaintiff’s consent. Nor does the defendant argue that the processing would have been lawful under this provision. Whether the defendant also— as assumed by the appellate court—violated Article 34 of the GDPR because it failed to notify the plaintiff without delay of the unlawful data transfer can be left open. This is because the plaintiff does not claim that he suffered non-pecuniary damages as a result of the failure to notify or the delayed notification. Since the plaintiff was informed of the incident by the third party on the very day the message was transmitted to that third party, as evidenced by the chat history referred to by the appellate court, there are no grounds for such a claim. 16 4. Contrary to the assessment of the Court of Appeals, the existence of non-pecuniary damage caused by the violation of the provisions of the General Data Protection Regulation within the meaning of Art. 82(1) GDPR must also be affirmed. 17 a) In the absence of a reference in Article 82(1) of the GDPR to the domestic law of the Member States within the meaning of that provision, the concept of “non-pecuniary damage” must be defined autonomously under Union law (established case law; see, e.g., CJEU, judgments of March 19, 2026—C-526/24, WRP 2026, 596, para. 57; of September 4, 2025—C-655/23, NJW 2025, 3137, para. 55; Senate judgments of November 11, 2025—VI 7 VI ZR 97/22 of June 23, 2026 | rewis.io ZR 396/24, GRUR 2026, 95, para. 25; dated November 18, 2024—VI ZR 10/24, BGHZ 242, 180, para. 28; each with further references; Federal Court of Justice (BGH), judgement of December 18, 2025—I ZR 97/25, NJW 2026, 845, para. 56). According to Recital 146, third sentence, of the GDPR, the concept of damage is to be interpreted broadly, in a manner that fully complies with the objectives of this Regulation. However, according to the case law of the Court of Justice, a mere violation of the provisions of the General Data Protection Regulation are not sufficient, according to the case law of the Court of Justice, to establish a claim for damages; rather, in addition—as a separate element of the claim—the occurrence of damage (resulting from that violation) (established case law; see CJEU, judgements of March 19, 2026—C-526/24, WRP 2026, 596, para. 59 et seq.; September 4, 2025—C-655/23, NJW 2025, 3137, para. 56; Senate judgments of November 11, 2025—VI ZR 396/24, GRUR 2026, 95, para. 25; of November 18, 2024—VI ZR 10/24, BGHZ 242, 180, para. 28; each with further references; Federal Court of Justice (BGH), judgement of December 18, 2025 – I ZR 97/25, NJW 2026, 845, para. 56). 18 Furthermore, the Court of Justice held that Article 82(1) of the GDPR precludes a national rule or practice that makes compensation for non-pecuniary damage within the meaning of that provision contingent upon the damage suffered by the data subject has reached a certain degree of severity or significance (see CJEU, judgements of March 19, 2026—C-526/24, WRP 2026, 596, para. 62; of September 4, 2025—C-655/23, NJW 2025, 3137, para. 58; of June 20, 2024—C-590/22, DB 2024, 1676, para. 26; of April 11, 2024—C-741/21, NJW 2024, 1561, para. 36; dated May 4, 2023 – C-300/21, VersR 2023, 920, para. 51). However, the Court has also held that, under Article 82(1) of the GDPR, such a person is required to prove that they have actually suffered harm. The rejection of a materiality threshold does not mean that a person affected by a violation of the General Data Protection Regulation that has had negative consequences for them would be exempt from proving that these consequences constitute non-pecuniary damage within the meaning of Article 82 of that Regulation (see CJEU, judgments of March 19, 2026—C-526/24, WRP 2026, 596, para. 62; of October 4, 2024—C-200/23, DB 2024, 2952, para. 142; of June 20, 2024—C-590/22, DB 2024, 1676, para. 27; April 11, 2024—C-741/21, NJW 2024, 1561, para. 36). 19 With reference to Recital 85, the Court has also repeatedly pointed out that the EU legislature intended the concept of harm to “encompass” even the “mere loss of control” over one’s own personal data as a result of a violation of the General Data Protection Regulation, even if no actual misuse of the data in question (CJEU, judgements of March 19, 2026—C-526/24, WRP 2026, 596, para. 61; September 4, 2025—C-655/23, NJW 2025, 3137, para. 60; October 4, 2024—C-200/23, DB 2024, 2952, para. 145; dated December 14, 2023 – C-340/21, NJW 2024, 1091, para. 82). Similarly, the judgement of the Court of Justice of April 11, 2024—C-741/21, NJW 2024, 1561, para. 42—states that the 85th Recital of the GDPR expressly “counts” the “loss of control” among the 8 VI ZR 97/22 of June 23, 2026 | rewis.io damages “that may be caused by a breach of personal data.” . In the same judgement (ibid.) as well as in its judgement of June 20, 2024 — C-590/22, ZD 2024, 519, para. 33—the Court of Justice held that even brief—loss of control over personal data may “constitute” (English version: “constitute,” French version: “constituer”) non-pecuniary damage within the meaning of Art. 82(1) GDPR, which entitles the data subject to compensation, provided that the data subject proves that he or she has in fact “suffered such damage”—however minor it may be— . 20 Finally, the case law of the Court of Justice has clarified that the (perceived) fear of a data subject, triggered by a violation of the General Data Protection Regulation, that their personal data might misused by third parties as a result of a violation of the General Data Protection Regulation may, “in and of itself,” constitute non-pecuniary damage within the meaning of Article 82(1) of the GDPR, provided that this fear, together with its negative consequences, is duly proven (see CJEU, judgements of September 4, 2025—C-655/23, NJW 2025, 3137, para. 61; of October 4, October 2024—C-200/23, DB 2024, 2952, para. 143 et seq.; of June 20, 2024—C-590/22, ZD 2024, 519, paras. 32, 35, 36; dated January 25, 2024 – C-687/21, CR 2024, 160, para. 65; Senate judgments of May 13, 2025—VI ZR 186/22, CR 2025, 585, para. 28; of November 18, November 2024—VI ZR 10/24, BGHZ 242, 180, para. 32). By contrast, the mere assertion of a fear without proven negative consequences is just as as a purely hypothetical risk of misuse by an unauthorized third party (see CJEU, judgements of June 20, 2024 – C-590/22, loc. cit., para. 35; of January 25, 2024—C-687/21, loc. cit., para. 68; Senate judgments of May 13, 2025—VI ZR 186/22, loc. cit., para. 29; of November 18, 2024—VI ZR 10/24, loc. cit.). The fear must, under the specific circumstances at hand and with regard the data subject, be regarded as “well-founded” (see CJEU, judgements of March 19, 2026—C-526/24, WRP 2026, 596, para. 63; October 4, 2024 — C-200/23, loc. cit., para. 143 with further references; December 14, 2023 — C-340/21, NJW 2024, 1091 para. 85; Senate judgment of May 13, 2025 - VI ZR 186/22, loc. cit.). Just as in the case of loss of control, however, it is not necessary that the use of the data actually occur (see Senate judgment of November 11, 2025—VI ZR 396/24, GRUR 2026, 95, para. 37). The negative consequences associated with a well-founded fear of improper data use may include negative emotions such as worry and annoyance, even if these may be part of the general risk of life (see CJEU, judgement of September 4, 2025 – C-655/23, loc. cit., para. 62, 64). 21 b) According to these standards, in the present case, non-pecuniary damage to the plaintiff within the meaning of Art. 82 GDPR is to be presumed at the latest from the time the third party to whom the defendant had unlawfully transferred the plaintiff’s personal data became aware of it and used it as a basis for contacting the plaintiff regarding his application with the defendant 9 VI ZR 97/22 of June 23, 2026 | rewis.io inquiries regarding the plaintiff’s application to the defendant, as this in itself constituted a misuse of the data, such that the loss of control associated with its transmission to the third party did not remain without consequences for the plaintiff. It can undoubtedly be inferred from the case law of the Court of Justice that, in any event, in such a case, non-pecuniary damage within the meaning of Art. 82 GDPR exists (see, for further details, Senate judgment of November 11, 2025—VI ZR 396/24, GRUR 2026, 95, para. 32, with further references). Furthermore, the plaintiff feared that the third party, who operates in the same industry as he does, had disclosed the data contained in the message at issue or, as a competitor, might have gained an advantage in any job applications based on knowledge of the information transmitted during the application process . Given that the third party, after becoming aware of the plaintiff’s personal data transmitted to him, inquired about the plaintiff’s application, this fear was also sufficiently well-founded. III. 22 The defendant’s appeal is also successful. 23 1. The defendant’s appeal is, in any event, admissible as a cross-appeal. It was filed in a timely manner, namely within the one-month period specified in § 554(2), second sentence, of the German Code of Civil Procedure (ZPO) . As required by the case law of the Federal Court of Justice (see, e.g., Senate judgment of July 23, 2024—VI ZR 427/23, MDR 2024, 1333 para. 22 with further references; Federal Court of Justice, judgement of November 22, 2007—I ZR 74/05, BGHZ 174, 244, para. 38 et seq.)—a direct legal or economic connection between the subject matter of the cross-appeal (claim for injunctive relief) and the subject matter of the plaintiff’s appeal (claim for compensation for non-economic damages). The legal connection lies in the fact that both claims can only be well-founded if the data transfer at issue was carried out in violation of the General Data Protection Regulation. It can therefore be left open whether the appellate court, in the operative part of the appeals judgment—the unrestricted admission of the appeal—in the reasons for the decision to the asserted claim for damages. 24 2. The defendant’s appeal is also well-founded. The appellate court wrongly upheld the asserted claims for injunctive relief and reimbursement of the extrajudicial legal costs incurred in pursuing the claim for injunctive relief. 25 a) The plaintiff is not entitled to the asserted claim against the defendant for an injunction against the processing of his personal data. 26 In its judgement of September 4, 2025, in Case C-655/23, the Court of Justice held that the provisions of the General Data Protection Regulation are10 VI ZR 97/22 of June 23, 2026 | rewis.io be interpreted as meaning that, in favor of the data subject affected by the unlawful processing of personal data, in the event that such a person—as the plaintiff in the present case—does not request the erasure of their data, they do not provide for a judicial remedy enabling the data subject to obtain, as a preventive measure, an order requiring the controller to refrain from any further unlawful processing in the future. However, they do not prevent Member States from providing for such a remedy in their respective legal systems (NJW 2025, 3137, para. 52). Consequently, in the present case, due to the transfer of the plaintiff’s personal data in violation of Article 6 of the GDPR, , the defendant may be ordered to cease the requested conduct under national law by analogy with § 1004(1), para 2, and § 823(1) of the German Civil Code (BGB) in conjunction with Art. 1(1) and Art. 2(1) of the Basic Law (GG), due to the violation of the plaintiff’s general right of personality— as manifested in the right to informational self-determination—caused by the unlawful data processing, in its manifestation as the right to informational self-determination or, by analogy pursuant to § 1004(1), second sentence, and § 823(2) of the German Civil Code (BGB) in conjunction with Art. 6 of the GDPR (see regarding the claim for injunctive relief in the case of an unlawful transfer under § 29 of the Federal Data Protection Act (BDSG) (old version), see the Senate’s judgments of February 27, 2018—VI ZR 489/16, BGHZ 217, 350 para. 42; of February 20, 2018—VI ZR 30/17, BGHZ 217, 340, para. 21 et seq.) may be considered. Whether—as the defendant contends—a ruling ordering the defendant to refrain from such conduct is precluded under national law because there is no need for such a ruling due to the data subject’s right to erasure of his or her personal data—can be left open. This is because the prerequisite for the existence of a claim for injunctive relief under national law is, in any case, that (further) infringements of the rights of the claimant must be anticipated in the future, para 1, second sentence, BGB. This requirement is not met here. The appellate court wrongly affirmed the risk of repetition with respect to the asserted claim for injunctive relief. 27 aa) The assessment of whether and to what extent there is a risk of repetition with respect to a contested conduct is, in essence, a factual matter. It is subject to only limited review in appeal proceedings to determine whether the appellate court based its decision on accurate legal principles and did not disregard any material facts (see, regarding § 1004 BGB, Senate decisions of November 16, November 2021—VI ZR 1241/20, NJW 2022, 940, para. 33; of April 27, 2021—VI ZR 166/19, NJW 2021, 3334, para. 22; dated June 4, 2019—VI ZR 440/18, VersR 2019, 1375 para. 22; dated December 4, 2018 – VI ZR 128/18, NJW 2019, 1142, para. 8; regarding § 97 UrhG see Federal Court of Justice (BGH), judgement of September 22, 2021 – I ZR 83/20, NJW 2022, 775, para. 34; in each case with further references). 28 bb) As a matter of law, the appellate court correctly assumed that, if an infringement has already occurred—as is the case here— there is a factual presumption of the existence of a risk of repetition. However, it However, it did not sufficiently take into account that this presumption can be rebutted, and that strict requirements must be met for such rebuttal.11 VI ZR 97/22 of June 23, 2026 | rewis.io It can be left open whether, in the present case, the cease-and-desist declaration with a penalty clause submitted by the defendant precludes a finding of a risk of recurrence. This is because the rebuttal of the factual presumption regarding the existence of a risk of repetition may, in exceptional cases, also be assumed even if the infringement was caused by a one-time, exceptional situation (see Regarding § 1004 of the German Civil Code (BGB): Senate rulings of April 27, 2021—VI ZR 166/19, NJW 2021, 3334, para. 23; dated June 4, 2019—VI ZR 440/18, VersR 2019, 1375, para. 36; dated November 14, 2017—VI ZR 534/15, ZUM 2018, 440, para. 17; dated February 8, 1994—VI ZR 286/93, VersR 1994, 570, juris para. 27). 29 This is the case here. The plaintiff has requested that the defendant be ordered to refrain in the future from processing or having personal data about the plaintiff that is related to his job application processed, if this occurs as it did in the message sent via the Xing portal to Mr. F. W. on October 23, 2018. His request for an injunction is thus limited to the repetition of the infringement already committed in its specific form, which is characterized by the fact is characterized by the fact that, in the course of the ongoing application process, a message intended for the plaintiff as an applicant and containing personal data relating to him was unintentionally sent to a third party. However, since the application process in which the plaintiff participated has since been completed, there is no likelihood of a recurrence of such an infringement of the plaintiff’s rights. 30 cc) The plaintiff does not assert a preventive claim for injunctive relief, which would depend on the existence of a risk of a first infringement. As already stated, the lawsuit—which the Senate, as the court of appeal, is free to discretion (see Senate judgment of June 18, 1996—VI ZR 325/95, MDR 1997, 94, 95, juris para. 11; Senate Order of April 19, 2005—VI ZB 47/03, NJW-RR 2005, 955, juris para. 9; each with further references; Federal Court of Justice (BGH), Judgement of February 21, 2012 – X ZR 111/09, NJW-RR 2012, 872, para. 24) – solely to the cessation of the repetition of the infringing act already committed. 31 b) In connection with the lawsuit for injunctive relief, which the appellate court erroneously upheld, the plaintiff consequently cannot claim reimbursement of pre-trial attorneys’ fees. IV. 32 The contested judgement was therefore set aside (Section 562(1) of the German Code of Civil Procedure (ZPO)). Even though the defendant’s liability for damages under Article 82(1) of the GDPR is, based on the forgoing, established on the merits, the matter is not yet ready for a final decision with respect to the relevant claim is not ready for a final decision and must therefore be remanded to the court of appeals for a new hearing and decision (Para 563 (1), first sentence, of the German Code of Civil Procedure (ZPO)). The determination of the amount of the claim for non-pecuniary damages under Art. 82 of the GDPR is reserved for the trial court pursuant to § 287 of the ZPO12 VI ZR 97/22 of June 23, 2026 | rewis.io (regarding survivors’ benefits, see Senate judgment of December 6, 2022—VI ZR 73/21, BGHZ 235, 254, para. 23; regarding compensation for pain and suffering, see the Senate’s judgment of February 15, 2022 — VI ZR 937/20, NJW 2022, 1953, para. 29, with further references). For the standards to be applied , reference is made to the Senate judgment of November 18, 2024—VI ZR 10/24 (BGHZ 242, 180, para. 93 et seq.) as well as to the Court of Justice’s answers in its judgement of September 4, 2025, in Case C-655/23 regarding Questions 5 and 6 referred for a preliminary ruling (NJW 2025, 3137, paras. 73, 83). With regard to the claim for reimbursement of pre-trial attorneys’ fees, the case was also to be remanded to the appellate court for a new hearing and decision, as it was not yet ready for a decision. 33 With regard to the asserted claim for injunctive relief, however, the Senate may make a decision on the merits of the case itself, because in this respect the reversal is based solely on a violation of law in the application of the statute to the established facts , and further factual findings that could be relevant to the existence of the risk of recurrence are neither necessary nor to be expected (Section 563(3) of the German Code of Civil Procedure (ZPO)). Seiters Oehler Klein Böhm Linder