Skip to content
Case Law · Administrative Court Berlin ·42 K 73/25 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

The controller ran 29 outdoor swimming pools in Berlin

In summer 2023, the controller introduced expanded identity verification checks and video surveillance measures due to safety concerns, such as aggressive behaviour and verbal and physical attacks by potential customers (the data subjects). Swimmers aged 14 and older were only granted access to the outdoor pools upon presentation of a photo ID, and video surveillance was implemented in the entry and exit areas. The video footage was stored for 72 hours. The DPA issued the controller a reprimand in August 2025. It held that the identity checks and the video surveillance were not necessary to fulfil the controller’s duties set forth in national law or ensure safety at the swimming pools and found a violation of Article 5(1)(a) GDPR. The controller appealed the DPA decision in September 2025. Holding — The court annulled the DPA decision and held that the identity verification checks and video surveillance had been necessary for the performance of a task carried out in the public interest within the meaning of Article 6(1)(e) GDPR. First, the court pointed out that the processing operations must serve objectives in the public interest in order to be lawful under Article 6(1)(e) GDPR. The aim of both measures was to prevent criminal offences, restore safety at the outdoor swimming pools for swimmers and staff members, and to protect the lives, health, and freedom of these individuals. This requirement was therefore fulfilled. Second, the court held that the criterion of necessity was also satisfied regarding both processing operations. According to the court, there did not appear to be a less intrusive measure that would interfere less with the fundamental rights of the data subjects and improve safety at the pools just as effectively than requiring swimmers to present a photo ID upon entry. Similarly, video surveillance was deemed the only viable option to ensure safety in the exit and entry areas, where the staff were exposed to considerable danger of assaults and threats. The court deemed the restriction to the right of informational self-determination to be relatively minor, since video surveillance was only used in four pools where the risk was high, did not cover the entire pool area, and resulted in recordings that were only stored for 72 hours.

Judgment·ECLI:DE:VGBE:2026:0506.42K73.25.00

Holding

The court annulled the DPA decision and held that the identity verification checks and video surveillance had been necessary for the performance of a task carried out in the public interest within the meaning of Article 6(1)(e) GDPR. First, the court pointed out that the processing operations must serve objectives in the public interest in order to be lawful under Article 6(1)(e) GDPR. The aim of both measures was to prevent criminal offences, restore safety at the outdoor swimming pools for swimmers and staff members, and to protect the lives, health, and freedom of these individuals. This requirement was therefore fulfilled. Second, the court held that the criterion of necessity was also satisfied regarding both processing operations. According to the court, there did not appear to be a less intrusive measure that would interfere less with the fundamental rights of the data subjects and improve safety at the pools just as effectively than requiring swimmers to present a photo ID upon entry. Similarly, video surveillance was deemed the only viable option to ensure safety in the exit and entry areas, where the staff were exposed to considerable danger of assaults and threats. The court deemed the restriction to the right of informational self-determination to be relatively minor, since video surveillance was only used in four pools where the risk was high, did not cover the entire pool area, and resulted in recordings that were only stored for 72 hours.

From GDPRhub’s case note — a summary of the decision, not its own words. Read it in the text ↓

Full text 38 paragraphs

Machine translation of the decision, via GDPRhub — not the official text. Read the original

Paragraphs carrying a topic or an applied provision show those connections inline
§

Court: Berlin Administrative Court, 42nd Chamber Date of Decision: May 6, 2026 Case Number: 42 K 73/25 ECLI: ECLI:DE:VGBE:2026:0506.42K73.25.00 Document Type: Judgement Source: Legal Provisions: Art. 4(1) EUV 2016/679, Art. 6(1), sentence 1, letter e EUV 2016/679, Art. 58 (2)(b) del Reglamento General de Protección de Datos de la UE 2016/679, § 23 del Código de Bathing Facilities de Berlín (BäderAnstG BE), § 20(1) del Código de Protección de Datos de Berlín (DSG BE) ... más The decision of the Berlin Commissioner for Data Protection and Freedom of Information dated August 4, 2025, is set aside. The defendant shall bear the costs of the proceedings. The judgement is provisionally enforceable with respect to costs. The judgement is provisionally enforceable upon posting of security in the amount of 110% of the sum enforceable pursuant to the judgement. Facts 1 The plaintiff challenges a data protection warning issued by the Berlin Commissioner for Data Protection and Freedom of Information. 2 Among other things, the plaintiff operates 29 outdoor swimming pools in Berlin.

§

In 2023, there were several safety-related incidents at these pools, such as aggressive behavior, threats, and verbal and physical attacks by (potential) pool patrons against other patrons and against the plaintiff’s staff. There were three evacuations of pools. In some cases, outdoor pools were also closed because the plaintiff’s employees had called in sick following the incidents. 3 Consequently, the plaintiff implemented several new security measures at its outdoor pools. The package of measures comprised a total of 40 measures intended to improve overall safety at the summer swimming pools. These included the expansion of identity checks as well as video surveillance measures. 4 Starting on July 19, 2023, swimmers aged 14 and older were granted access to the summer pools only upon presentation of photo identification. Identification documents were verified at the entrances without storing any data.

§

If there was suspicion of a ban from the premises, the plaintiff’s employees or security staff would compare the identification document with the list of imposed bans. 5 Starting in August 2023, at the Neukölln, Pankow, Am Insulaner, and Kreuzberg outdoor pools, the entry and exit areas around the turnstiles—which must be passed through to enter or exit—were subject to surveillance using video cameras. The video data was stored for 72 hours. There was no live monitoring or unscheduled review — Page 1 of 12 — by the plaintiff in the lawsuit. The recordings were made available to the police upon their request. 6 Immediately after the measures were introduced, the defendant intervened and reviewed their admissibility under data protection law. In a letter dated February 22, February 2024, the defendant requested that the plaintiff not continue the requirement to present identification during the 2024 summer season.

§

Although the scope of the data processing was minimal, it constituted a borderline case regarding the applicability of data protection law. However, despite this, the measures constituted a not insignificant intrusion into personal rights. The plaintiff had not yet demonstrated the necessity of video surveillance under data protection law. 7 The plaintiff subsequently sent the defendant an evaluation report on the measures summer season of 2023. According to the report, the security situation had improved significantly as a result of the introduction of the new security measures. Evacuations of outdoor pools had been entirely avoided. Violent altercations had ceased to occur. The sense of security among bathers and the plaintiff’s employees had increased. 8 The plaintiff revised the security measures for the 2024 summer season. During this season, the requirement to present photo identification remained in effect.

§

Name checks were now conducted only when personalized tickets were used, if a person appeared familiar to security personnel and there was suspicion that they were subject to a ban from the premises, as well as for individuals exhibiting suspicious behavior. 9 By decision dated August 4, 2025, the defendant issued a warning to the plaintiff, following a hearing, for violations of the General Data Protection Regulation (GDPR). 10 By conducting identity checks in 2023 and 2024, the plaintiff violated the GDPR. This constituted the processing of personal data. The checks were not necessary to fulfill the plaintiff’s duties as set forth in the Act on the Public-Law Institution Berliner Bäder-Betriebe (Bäder-Anstaltsgesetz – BBBG), in particular to ensure safety at the summer swimming pools; in any case, the plaintiff had not demonstrated this. There was no need for a blanket check of whether visitors were carrying proof of identity.

§

Simply checking whether a visitor was carrying proof of identity could not identify any person subject to a ban from the premises. There is simply no routine comparison with the list of persons barred from the premises. The claim that security personnel are consistently familiar with the list of persons barred from the premises and that identification documents are compared “mentally” with the list is not plausible. If a person behaved suspiciously or if security personnel believed they might recognize that person, a random identity check would be sufficient. However, this had already been possible prior to the introduction of comprehensive identity checks. 11 The identity checks are not suitable for ensuring security at the summer swimming pools in the first place. According to the plaintiff, the checks serve merely to ensure that the data subject carries proof of identity so that, in the event of an incident, the data subject’s identity can be verified and the data subject can be added to the exclusion list if necessary.

§

However, the plaintiff overlooks the fact that the data subjects are not (contractually) obligated to cooperate with their identification by the plaintiff’s employees or to actually present their identification - Page 2 of 12 - . In case of doubt, this must be done by the police anyway. The number of exclusion orders issued with police assistance actually increased slightly in the 2024 season compared to 2023, despite the measures. To the extent that the absolute number of exclusion orders has increased, this could also be due to the fact that exclusion orders are now being issued more consistently, in accordance with the instructions given to the security service. Furthermore, it cannot be ruled out that this measure deters certain groups of people from visiting a summer swimming pool from the outset, because they might feel discriminated against by being required to present identification that also reveals their nationality. 12 Video surveillance also violates data protection regulations.

§

To the extent that the plaintiff argued that video surveillance has a deterrent effect, she failed to substantiate this claim. Moreover, the general assumption that video surveillance acts as a deterrent is not sufficient justification. Surveillance would be necessary only if it were proven that, in the past, there had been threats to guests or employees in the monitored areas and if it were demonstrated for the future that the situation had improved following the introduction of Surveillance. However, the plaintiff has not provided such evidence. She merely collected anecdotal accounts from employees after the fact and submitted three quotes from pool management. This is not sufficient as evidence . The notion that a person who is about to commit a crime within the summer swimming pool would, at that very moment, remember the video surveillance and then refrain from doing so due to the possibility of being identified through the video recordings is not plausible.

§

Nor had the plaintiff sufficiently demonstrated that the sharp increase in detected cases of fraudulently obtaining services was attributable specifically to video surveillance (and not, or not also, to identity checks). An increase in the sense of security among guests and employees is irrelevant to the assessment of necessity, as only the actual increase in security is relevant. 13 The plaintiff has also failed to demonstrate that video surveillance is necessary for (subsequent) identification by the police and, consequently, for the enforcement of the owner’s rights. After all, video footage had been transmitted to the police in only three cases. 14 Nor could the assessment be based on whether the totality of the measures taken had led to outcomes such as a reduction in criminal offenses or police response hours. The effectiveness of video surveillance can be determined on a case-by-case basis and can thus be assessed independently of other measures.

§

Given the small number of video transfers to the police, the effectiveness must be classified as minimal. 15 Consequently, a warning should be issued. No less severe measure is apparent, since the contested measures affected a large number of people who did not endanger safety at the summer swimming pools. These individuals could be deterred from visiting a summer swimming pool by the measures, even though the provision of this service serves the public interest. Identity checks would entail a risk of discrimination. Video surveillance would create a sense of being monitored among the data subjects. However, since this does not constitute data processing involving a high degree of intrusion, no further supervisory measures were taken. - Page 3 of 12 - 16 The plaintiff filed a lawsuit against the decision on September 2, 2025. 17 The identity checks were in compliance with data protection regulations and, in particular, were appropriate, necessary, and proportionate to ensuring safety at the swimming pools.

§

Within the scope of its right to manage its premises, it is entitled to control access to its summer swimming pools. Thus, it may also verify whether someone has a valid admission ticket. The intensity of the intrusion was minimal; after all, there was only a fleeting viewing of the data and no processing took place. The defendant itself stated that the checks constituted a borderline case. The swimmers were also not compelled to reveal their identity; they were merely denied access to the summer pools if they wished to remain anonymous. 18 Video surveillance also does not violate data protection law. The plaintiff had conducted a balancing of interests within the meaning of § 20(1) of the Act on the Protection Personal Data in the Berlin Administration (Berlin Data Protection Act—Bln- DSG) and had concluded that the video surveillance was proportionate, necessary, and appropriate; the rights and freedoms of the data subjects did not outweigh these considerations.

§

The surveillance was limited to areas where fully clothed individuals were present. The recordings were not stored and were only handed over to law enforcement authorities in clearly defined, albeit few, cases. Visitors and employees were informed comprehensively and transparently about the use of the system. The intrusions were reduced to an absolute minimum. The measure was appropriate, as the 2024 outdoor swimming season was noticeably more peaceful, which was specifically reflected in the figures. There were no less intrusive measures with the same level of effectiveness. The defendant did not sufficiently take into account that the fear of being identified in the event of misconduct also leads visitors to behave in accordance with the rules. However, this aspect cannot be proven. It goes too far to require the submission of statistics that clearly and in isolation demonstrate the effect of the individual measure.

§

If measures ensure that a certain type of behavior does not occur, it is precisely impossible to prove what would have happened if the measure had not been taken. Yet this is exactly what the defendant demands; the requirements for provability are completely excessive. She, too, had failed to propose a less restrictive alternative. 19 When the defendant demands that statistics and information be submitted separately for each swimming pool, it sets the bar too high and acts out of touch with reality. The defendant failed to take into account that the two measures are part of a package of measures that was developed with a sense of proportion and very minimal interference. It is in the nature of things that, in retrospect, it cannot be clearly determined which individual measure was decisive. 20 The plaintiff requests that 21 the decision of the Berlin Commissioner for Data Protection and Freedom of Information dated August 4, 2025, be set aside. 22 The defendant requests that 23 the lawsuit be dismissed. - Page 4 of 12 - 24 The defendant considers the lawsuit to be unfounded. 25 The identity checks violate Article 6 of the GDPR.

§

The collection of personal data constitutes data processing, at least when it is—as in the present case—intentional and targeted; this also follows from § 2(9) of the Berlin Data Protection Act (BlnDSG). Finally, it is not sufficient for the plaintiff merely to recognize that a person is carrying proof of identity; rather, it actually accesses the data. This creates the risk of discrimination, as well as the risk that the plaintiff’s employees or security personnel might memorize the data and use it for private purposes. The data subjects did not give their consent, as they had no free choice and were not in a position to refuse or withdraw consent without suffering disadvantages. The data subjects had no free choice, as the plaintiff holds a monopoly on summer swimming pools in Berlin. Refraining from visiting a summer swimming pool was not an equivalent alternative, as the summer swimming pools were part of essential public services due to their health and social impacts.

§

The identity checks were also unnecessary, as the data processing was not objectively indispensable. 26 Selective video surveillance also violates Article 6 of the GDPR. The statistics submitted did not adequately demonstrate the necessity of this measure, as they did not distinguish between monitored and unmonitored summer swimming pools. Although the plaintiff had demonstrated that, in principle, legal interests were being infringed at the summer swimming pools and that these infringements had decreased overall following the introduction of the security measures, However, it had not demonstrated that the risk situation in the monitored areas of the four outdoor swimming pools exceeded the general risk to life that exists at the entrances and exits of outdoor swimming pools. Accordingly, the suitability of the Surveillance has not been proven either. The fact that the plaintiff refrains from monitoring other areas, such as sunbathing lawns—which, incidentally, would be unlawful—does not affect the lawfulness of the Surveillance of the entrance and exit areas.

§

Furthermore, by providing comprehensive information to guests and employees, it is merely fulfilling its legal obligation; this cannot influence the balancing of interests. 27 The number of transfers to law enforcement authorities is indeed relevant, because if a review reveals that no transfer took place at a summer swimming pool, the necessity is no longer met. 28 Contrary to the plaintiff’s assertion, the defendant had indeed taken the deterrent effect into account. However, the plaintiff had simply not kept statistics for the areas under surveillance . It is not the defendant’s responsibility to devise possible evidence with which the plaintiff could fulfill its accountability obligation under Art. 5(2) of the GDPR. 29 For further details regarding the facts and the state of the dispute, reference is made to the contents of the case file and the administrative records. These were available and formed the basis of the oral hearing and the decision-making process.

§

Reasons for the Decision - Page 5 of 12 - 30 The admissible lawsuit is well-founded. The decision of the Berlin Commissioner for Data Protection and Freedom of Information dated August 4, 2025, is unlawful and infringes upon the plaintiff’s rights (see § 113(1), first sentence, VwGO). 31 The requirements for the legal basis applicable to the warning at issue—namely, The legal basis for Article 58(2)(b) of the GDPR was not met at the relevant time of the issuance of the warning (see Federal Administrative Court, judgement of March 27, March 2019—6 C 2.18—, juris para. 7). According to this provision, the defendant, as a supervisory authority, (see para 8(1) BlnDSG), has remedial powers that allow it to issue a warning to a controller or processor if that party has violated the GDPR through processing activities. However, in the years 2023 and 2024, the plaintiff did not violate the GDPR either through the identity checks (see section I below) or through video surveillance at four summer swimming pools (see section II below). 32 I. The identity checks at the plaintiff’s outdoor swimming pools in the years 2023 and 2024 were lawful.

§

The defendant wrongly assumed that this constituted a violation of Art. 5(1)(a) of the GDPR. 33 1. Under Article 5(1)(a) of the GDPR, personal data must be processed lawfully, with fairness, and in a manner that is transparent to the data subject. The lawfulness of data processing is determined by Article 6(1), first subparagraph, of the GDPR. This provision contains an exhaustive and definitive list of cases in which the processing of personal data may be considered lawful (CJEU, judgements of July 4, 2023 – C-252/21 – juris para. 90, Meta Platforms et al.; of September 12, 2024 – C-17 and 18/22 – juris para. 34, HTB Neunte Immobilien Portfolio geschlossene Investment UG & Co. KG; and of October 4, October 2024—C-200/23—juris para. 94, Agentsia po vpisvaniyata). If the data subjects have not validly consented to the processing of their personal data (Art. 6(1), para. 1, letter a of the GDPR in conjunction with Art. 4(11) of the GDPR), processing operations are lawful only if they are based on at least one of the grounds for processing set forth in Article 6(1), first subparagraph, letters b through f of the GDPR. 34 2.

§

The processing operations associated with identity verification checks may be based on Article 6(1), first subparagraph, 1(e) of the GDPR in conjunction with § 23 of the BBBG in the version dated October 12, 2020 (GVBl. p. 807), which was in effect from October 25, 2020, through April 15, 2026. 35 Pursuant to Article 6(1), para 1, letter e of the GDPR, processing is lawful if the processing is necessary for the performance of a task carried out in the public interest. Article 6(1), first subparagraph, letter e of the GDPR, according to the case law of the CJEU—which is authoritative for the interpretation of Union law—only acquires significance as a basis for lawfulness through the existence of implementing provisions under Member State or Union law. This is because the lawfulness of personal data processing on the basis of this provision requires not only that the authority perform a task in the public interest, but also that the processing of personal data for the performance of such a task is based on a legal basis within the meaning of Art. 6(3) GDPR (CJEU, judgement of October 20, 2022 – C- - Page 6 of 12 - 306/21 – juris para. 52; see also Federal Administrative Court (BVerwG), judgement of March 20, 2024 – 6 C 8.22 – juris para. 26).

§

Section 36 of § 23 of the Federal Civil Service Act (BBBG), as amended, constitutes the legal basis required by Art. 6(1), para 1(e), para. 3, sentence 1(b) of the GDPR, which requires the establishment of a legal basis for the processing of the plaintiff’s data in connection with identity checks . Under this provision, the processing of personal data was permissible if it was necessary to fulfill the tasks specified in the Spa and Institution Act. Conceived as a general clause, this provision constituted a legal basis compliant with Union law, at least for data processing involving a low level of intrusion—such as identity checks (see, regarding § 3 BDSG: BVerwG, judgement of March 20, 2024 – 6 C 8.22 – juris para. 29 et seq.). 37 The checks constituted processing of personal data within the meaning of the GDPR. 38 The information contained in the identification documents to be presented at the entrance to the summer swimming pools constitutes personal data.

§

According to Article 4(1) of the GDPR, personal data means any information relating to an identified or identifiable natural person; a natural person is considered identifiable if that person can be identified, directly or indirectly—in particular by association with an identifier such as a name, an identification number, location data, an online identifier, or or more specific characteristics that reflect the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person. This data includes the name, address, date of birth, and nationality (e.g., see Wolff/Brink/v. Ungern-Sternberg, BeckOK Data Protection Law, 55th Edition, as of February 1, 2026, Art. 4 DSG- Regulation, para. 3), which are contained in the identification documents to be presented. 39 The presentation of the identification documents constituted processing within the meaning of the GDPR.

§

Article 4(2) of the GDPR defines processing as any operation or set of operations performed with or without the aid of automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, retrieval, use, disclosure by transfer, dissemination, or any other form of making available. The definition is broad and abstract (Schild in: Wolff/Brink/v. Ungern-Sternberg, BeckOK Data Protection Law, 55th edition, as of February 1, 2026, Art. 4 GDPR, para. 7). It covers any handling of personal data (Gola in: Gola/Heckmann, GDPR BSDG, 3rd edition 2022, Art. 4 GDPR, para. 35), and thus also the review and mere inspection of identification documents at the entrance to the summer swimming pools. 40 The processing operations associated with the identity checks were necessary for the performance of a task carried out in the public interest, namely to ensure the safe operation of Berlin’s outdoor swimming pools 41 Processing is necessary for the performance of a task carried out in the public interest if it actually corresponds to the objectives of general interest without going beyond what is necessary to achieve those objectives.

§

This requirement of necessity is not met if the objective pursued in the general interest can be achieved just as effectively, by reasonable means, through other measures that interfere less with the fundamental rights of the data subjects - Page 7 of 12 - , whereby the exceptions and restrictions must be limited to what is absolutely necessary (see CJEU, Judgement of October 4, 2024 – C-200/23 – juris para. 110 f., Agentsia po vpisvaniyata; Heberlein in: Ehmann/Selmayr, GDPR, 3rd ed. 2024, Art. 6, para. 45). One must always consider equally suitable but less intrusive means (see Frenzel in: Paal/Pauly, GDPR BDSG, 4th ed. 2026, Art. 6 GDPR para. 23). This assessment is part of the principle of proportionality, which serves as the standard for the state’s actions in relation to the data subject (Frenzel in: Paal/Pauly, GDPR BDSG, 4th ed. 2026, Art. 6 GDPR, para. 23; Buchner/Petri in: Kühling/Buchner, GDPR BDSG, 4th ed. 2024, Art. 6 GDPR, para. 119).

§

Since the Berlin state legislature, through § 23 BBBG (old version), made use of the discretion afforded to it by Art. 6(3) GDPR, the application of Art. 6(1)( (1)(e) of the GDPR in conjunction with § 23 BBBG (old version) must be assessed against the standard of the fundamental rights enshrined in the Basic Law. For, according to the case law of the Federal Constitutional Court, domestic law and its application— where it falls within the scope of Union law but is not, as in this case, fully determined by it—must be measured against the standards of the Basic Law (BVerfG, Decision of November 6, 2019 – 1 BvR 16/13 – para. 42 – Right to be forgotten I; see, regarding a provision of the Bavarian State Data Protection Act based on Art. 6(3), first sentence, letter b of the GDPR: BVerwG, Order of May 2, 2024 – 6 B 66.23 – juris para. 10). 42 The plaintiff performs tasks in the public interest.

§

As an institution under public law, it is responsible for the operation, maintenance, and administration of the swimming pools in Berlin (see para 1, para 3, first sentence, BBBG). In particular, the swimming pools are made available for physical activity, recreation, and relaxation for members of all segments of the population (Section 3(1), second sentence, first clause, of the BBBG). This naturally also includes ensuring the safe and hazard-free use of the swimming pools by the plaintiff in the lawsuit. 43 The legitimate purpose of the identity checks was thus to restore safety in the summer swimming pools for bathers and for the staff employed by the plaintiff, as well as to protect the lives, health, and liberty of these individuals. This safety was no longer guaranteed in July 2023. There were incidents of aggressive behavior, threats, and verbal and physical attacks by (potential) bathers against other bathers and staff.

§

As a result, three pools had to be evacuated. In some cases, pools were closed because staff called in sick due to these circumstances. 44 The identity checks during the 2023 summer season were, as part of the package of measures devised by the plaintiff in light of these incidents, in the Chamber’s view necessary to achieve the stated purpose. The focus here was on the necessity at the time the measure was taken, since security incidents with such serious consequences as the evacuation and closure of summer swimming pools had not occurred before that time. The purpose of the checks was to ensure that individuals who had been banned from the summer swimming pools due to past behavior that posed a security risk would no longer enter the pools and would not endanger safety. For this reason, the plaintiff’s staff, upon suspecting a ban or in the event of conspicuous behavior by an individual, would cross-check the person’s identification with the list of imposed bans.

§

In the event of a ban, the person in question was denied entry. Furthermore, the identity checks were intended to serve the purpose of - Page 8 of 12 - issuing bans in the event of behavior that posed a security risk. Verifying the identity of individuals and entering their data into the exclusion list was made easier because it was ensured that all individuals at the summer swimming pools carried proof of identity, and individuals who did not carry proof of identity or refused to present it were permitted to be denied entry. 45 In the Chamber’s view, the measure was appropriate for improving safety at the pools following the aforementioned security-related incidents. Because all individuals were required to present identification at the entrance, the plaintiff’s staff could verify their identity at any time and, if necessary—because a person was behaving suspiciously or because they seemed familiar to the staff, compare the information with the banned persons list and, if necessary, deny access to the summer pool.

§

In the past, such a clear verification had not always been possible, since individuals were not required to carry identification. Even if the individuals provided their names upon request so that they could be checked against the banned persons list, residual doubts about their identity still remained. These doubts were eliminated by the presentation of identification. 46 No less restrictive but equally suitable means is apparent. The mere inspection of identification documents and comparison with the exclusion list when necessary already constitutes a very minor intrusion into the right to informational self-determination, which cannot be made any less intrusive without thereby limiting the suitability of the measure. 47 In the Chamber’s view, the data protection risks cited by the defendant with regard to the data subjects are not valid. The argument that someone might be discriminated against by presenting an identification document and having their nationality identified therein is no more convincing than the claim that security personnel could use the identifiable data to contact the person privately.

§

Nor does the Chamber find it convincing that individuals might be deterred from visiting a summer swimming pool due to the very minor intrusion involved. Visiting swimming pools near one’s place of residence should be open to all segments of the population for recreation and physical activity. Even if the plaintiff holds a monopoly on outdoor swimming pools, a minimum level of control over who visits the pools is permissible. There is no right to anonymous use of such public facilities. 48 Without this being decisive—since, correctly, an assessment of the necessity of a measure must be based on the time it was implemented— the plaintiff has demonstrated, even after the end of the 2023 summer season, that identity checks were necessary as an essential part of the package of measures. The Chamber finds this necessity to be evident from the evaluation report prepared by the plaintiff covering the entire package of measures for the 2023 summer season.

§

The Chamber considers it necessary to compare the figures from 2023 with the available figures from 2019. The data contained in the evaluation report for the years 2020 through 2022 is not particularly suitable for this purpose. During those years, Germany was affected by the coronavirus. Visits to the summer swimming pools were not possible or only possible to a limited extent during this period. A comparison of the data for 2023 with the data for 2019 is clear. Violations of the facility and pool rules fell from 59 to 44, the number of insults from 69 to 25, the number of physical assaults from 38 to 8, the number of threats from 21 to 4, and the number of sexual offenses from 8 to 7 cases, as well as the number of bans from 257 to 144 and the number of criminal complaints from 195 to - Page 9 of 12 - 35. There have been no further evictions from the pools. Against this backdrop, the plaintiff reasonably concluded that the security situation had significantly improved and that the summer pools had once again become safe and peaceful recreational facilities . 49 The interference with the fundamental right of bathhouse visitors to informational self-determination associated with identity checks is therefore also proportionate in the stricter sense. 50 The continuation of identity checks during the 2024 summer season was also necessary in the sense outlined above.

§

This was done against the backdrop that the evaluation had concluded that the checks, as part of the package of measures, had increased security. To prevent the security-related incidents from 2023 from recurring, the plaintiff, in a manner the Chamber finds reasonable, maintained the package of measures and, in particular, the requirement to present proof of identity. 51 II. Nor did the plaintiff violate the GDPR through its processing activities by conducting video surveillance in the entrance areas of four outdoor swimming pools in 2023 and 2024. The defendant also wrongly assumed in this regard that this constituted a violation of Art. 5(1)(a) of the GDPR. 52 The processing operations associated with the video surveillance could be based on the legal basis of Article 6(1), first subparagraph, letter e of the GDPR in conjunction with § 20(1) of the Berlin DSG in the version dated June 13, 2018 (GVBl. p. 418). § 20(1) Bln- DSG in the aforementioned version fulfilled the requirement set forth in Art. 6(1), para 1(e) and para 3 , first sentence, letter b of the GDPR.

§

According to this provision, the processing of personal data in publicly accessible areas using optical-electronic devices (video surveillance) was permissible to the extent that it was necessary to fulfill a task carried out in the public interest or to exercise property rights, and there were no indications that the legitimate interests of the data subjects outweighed these. 53 These conditions were met. Video surveillance of the turnstiles at the entrance and exit areas of the four summer swimming pools was, in accordance with the above-mentioned criteria, necessary to fulfill the task in the public interest of ensuring the smooth operation of the summer swimming pools. 54 Video surveillance is deemed necessary if it is suitable for achieving the desired purpose. Next, it must be examined whether there are other equally suitable measures that, however, interfere less significantly with the personal rights of the data subjects than the planned video surveillance (see Nguyen in: Smoltc- zyk, BlnDSG, 1st ed. 2023, § 20, note 8).

§

Less intrusive alternatives include labor-intensive operational concepts that focus on the preventive as well as repressive effects on individuals present. Particularly with regard to the preventive effect, the presence of a public official may constitute a less severe intrusion compared to continuously recording video surveillance. Furthermore, while the official may collect personal data, he or she cannot store and analyze it to the same extent as video surveillance technology; which is, in this respect, more data-protection-friendly (see Frenzel in: Paal/Pau- ly, GDPR BDSG, 4th ed. 2026, § 4 BDSG, margin note 18). However, the alternative equally - Page 10 of 12 - suitable means, such as the deployment of personnel, must be objectively and economically reasonable for the controller (see: Buchner in Kühling/Buchner, GDPR BDSG, 4th ed. 2024, § 4 BDSG, margin note 8, with further references).

§

If the use of video surveillance is intended to save costs on security personnel, data protection cannot, in principle, be invoked as an objection (on the GDPR: Schulz in: Gola/Heckmann, GDPR BDSG, 3rd ed. 2022, Art. 6 GDPR, para. 124; Federal Administrative Court (BVerwG), judgement of January 25, 2012 – 6 C 9.11 – juris para. 46). If one defines the possibility of analysis—which generally requires storage—as an essential characteristic, the deployment of personnel is already not as suitable as video surveillance with storage (Frenzel in: Paal/Pauly, GDPR BDSG, 4th ed. 2026, § 4 GDPR para. 20). 55 In the present case, video surveillance during the 2023 summer season was suitable for achieving preventive purposes. The aim was to prevent assaults, threats, and other criminal offenses in the areas subject to surveillance—where tensions had been high in the past and where many assaults and criminal offenses had occurred—as well as in the swimming pools themselves.

§

Individuals prone to committing criminal offenses were to be deterred by the surveillance system. Surveillance and the possibility of detection from committing such acts. 56 Contrary to the defendant’s view, the notion that a person who, while in the monitored area or even afterward while at the pool, is about to commit a criminal at that very moment and, due to the possibility of being identified through the video recordings, refrains from doing so, is plausible. The recorded and stored video footage allows criminal offenses to be detected and perpetrators to be identified. The open nature of the Surveillance measure can effectively deter potential offenders (regarding police video surveillance on the Reeperbahn: Federal Administrative Court, Judgement of January 25, 2012 – 6 C 9.11 –, ju- ris para. 45; see also Bavarian Higher Administrative Court, judgement of May 30, 2023 – 5 BV 20.2104 –, juris para. 26). 57 In the Chamber’s view, increased staffing at the checkpoints would ultimately not have been equally suitable because the possibility of analyzing the footage would not have existed.

§

Nor would it have been reasonable to expect the plaintiff to do so, because there had been attacks on the security personnel. Security personnel were exposed to considerable personal danger in the areas under video surveillance. To prevent these assaults and still achieve the stated purpose, video surveillance was the only viable option; potential high costs and the cost-effectiveness of a large staff deployment are irrelevant. 58 In assessing necessity, it must also be taken into account that the plaintiff did not implement video surveillance across the entire facility, but only in four pools with a particularly high risk. Furthermore, the surveillance did not extend to the entire outdoor pool facility but was limited to the turnstile areas. In those areas, there had been frequent instances of fare evasion and physical assaults in the past. 59 Furthermore, the infringement on the right of the recorded individuals to informational self-determination was comparatively very minor, because recording and storage lasted only 72 hours, no live monitoring took place, and the recordings were transmitted to law enforcement authorities only upon request, - Page 11 of 12 - which, in turn, occurred only in a few cases.

§

The aforementioned rights to life and health, on the other hand, carried significant weight. 60 The interests worthy of protection of the data subjects affected by video surveillance do not outweigh the public interest in video surveillance. In particular, the infringement on the fundamental right of bathhouse visitors to informational self-determination associated with video surveillance is also proportionate in the strict sense. 61 Like the identity checks, video surveillance was also necessary during the 2024 summer season for the plaintiff to perform tasks in the public interest. In this regard, reference is made to the improvement in the security situation resulting from the evaluation report for the 2023 summer season following the introduction of the package of measures. 2023. Although this is irrelevant—since, as explained above, the relevant time is when the measure was implemented—retrospective data collection also confirms that the plaintiff’s assumption that the security situation would improve was correct.

§

For the four swimming pools where video surveillance was implemented, the number of criminal incidents fell from 88 in 2023 (see Berlin House of Representatives, Drs. 19/16786, Annex 2 therein) to 66 in 2024 (see Berlin House of Representatives, Drs. 19/20495, Table for Question 2 therein). 62 The decision on costs is based on § 154(1) VwGO. The decision on provisional enforceability is based on § 167 VwGO in conjunction with § 709, para 1 and 2, ZPO. Accordingly, the judgement regarding costs is provisionally enforceable upon the posting of security in the amount of 110% of the amount enforceable pursuant to the judgement. 63 Leave to appeal pursuant to § 124a(1), first sentence, VwGO need not be granted. There is no apparent ground for granting leave to appeal under § 124(2), No. 3 or No. 4, VwGO. This is a decision in an individual case based on sufficiently clarified legal requirements, which essentially requires an assessment of the necessity of specific measures to ensure the (safe) operation of Berlin’s summer swimming pools.

How it connects

35 of 38 paragraphs apply legislation or carry a topic — see them in the full text ↓