# VG München - M 32 E 26.3990

- Type: Case Law
- Source: Administrative Court Munich
- Date: 2026-08-11
- Original: https://gdprhub.eu/index.php?title=VG_München_-_M_32_E_26.3990
- Canonical: https://overview.legal/posts/353647

## Summary

Facts — The author of a manuscript (the data subject) submitted their text to an editorial office of a quarterly journal for review in November 2025. The journal was published by a private publishing company and overseen by several co-editors, including two professors at a Bavarian university (the alleged controller). The data subject received an email pointing out inconsistencies in the external review process in April 2026. On 7 May, the data subject submitted an access request under Article 15 GDPR to the university and requested a complete copy of their personal data processed in connection with the publishing process. The work email accounts of the two aforementioned university professors were explicitly identified as storage locations in the access request. The university rejected the access request in a decision dated 20 May 2026: it argued that it was not the controller within the meaning of Article 4(7) GDPR. According to the university, only the co-editors of the journal and the publishing company could be classified as controllers with regard to the storage of personal data in connection with publishing activities. On 26 May, the data subject filed a both a lawsuit and an application for a preliminary injunction before the Administrative Court Munich. In the application, they requested a preliminary injunction ordering the university to retain all the data subject's personal data until the main proceedings regarding the right to access would be legally concluded. As the data subject sought to secure their right of access with the application, they argued that their right to a preliminary injunction arose from Articles 5(2), 15, and 32 GDPR. Holding — The court rejected the data subject's application for a preliminary injunction: the requirements laid down in § 123(1)(1) of the German Code of Administrative Court Procedure (VwGO) were not fulfilled. First, the court held that the role of the university in the processing at issue could be left open in connection with the application for a preliminary injunction. Instead, it should be determined in the main proceedings whether the university was acting as a controller within the meaning of Article 4(7) GDPR. The court pointed out, however, that an employee using a work email account to process personal data in connection with their private activities generally determines the purpose and the means of the processing and is therefore acting as the sole controller. Second, the court concluded that the data subject did not have a right of access under Article 15 GDPR. The court weighed the data subject's right to access against the university professors' legitimate interests in maintaining the confidentiality of their communication and their general right to privacy. As the requested disclosure of information would constitute a significant infringement of the professors' right to privacy, the court held that the legitimate interests of the university professors prevailed over the data subject's right of access. According to the court, this conclusion was supported by Article 23(1)(i) GDPR and Article 10(2)3) of the Bavarian Data Protection Act (BayDSG), as these provisions restrict the right of access. The national provision states that information shall not be disclosed to the extent that personal data or the fact of its storage must be kept confidential to protect the data subject or due to the overriding legitimate interests of third parties. The court also referred to Article 15(4) GDPR to support its argumentation. Pursuant to this provision, the right to receive a copy of personal data processed shall not adversely affect the rights and freedoms of others. In addition, the court pointed out that Article 15 GDPR must be interpreted in light of the fundamental rights guaranteed in the EU Charter.

## Full text

Munich Administrative Court, Order of August 11, 2026 - M 32 E 26.3990 Citation openJur 2026, 8913 Legal Effect: Operative Part I. Prof. Dr. ... ... and Prof. Dr. ... ... are summoned to appear. II. The motion is denied. III. The petitioner shall bear the costs of the proceedings. IV. The amount in dispute is set at €2,500. Reasons I. In the present proceedings, the petitioner essentially seeks an order requiring the respondent to delete the data sets pertaining to a manuscript—submitted to the editorial office of a quarterly journal—from the emailmailboxes of specifically named university professors until the final resolution of the lawsuit pending before the Munich Administrative Court under case no. M 32 K 26.3986. On November 16, 2025, the petitioner submitted the manuscript “Bold Transformations: Forms of Virtuality and Processes of Transformation in German Literature around 1800” for review. The DVjs is published by Springer Nature and is overseen by several co-editors, including Prof. Dr. ... ... (Chair of Modern German Literature, ... ...) and Prof. Dr. ... ... (also ... ...). On April 22, 2026, the applicant received an email from Prof. Dr. ... pointing out “implausibilities” regarding the external review process. The sender’s email address is listed as: “...”. In a letter dated May 7, 2026, the applicant submitted an access request pursuant to Article 15 of the GDPR to the respondent. The subject of the request is the provision of information and the transmission of a complete copy of all of the applicant’s personal data processed within the respondent’s sphere of responsibility in the context of or in connection with the aforementioned matter. The letter explicitly identifies the work email accounts of Prof. Dr. ... and Prof. ... ... as relevant data storage locations. It covers all email correspondence in which the applicant is mentioned by name or in connection with the aforementioned manuscript or the procedural complaint dated April 23, 2026, all internal opinions, statements, file notes, and annotations, as well as the information specified in Article 15(1) of the GDPR regarding processing purposes, recipients, retention periods, and the origin of the data. In a decision dated May 20, 2026, issued by the respondent’s data protection officer, the respondent refused to provide the information on the grounds that it was not the controller within the meaning of Article 4(7) of the GDPR. On May 26, 2026, the petitioner filed a lawsuit against the respondent and simultaneously requested that that the respondent be ordered by way of a preliminary injunction to disclose all of the applicant’s personal data within the respondent’s sphere of responsibility in connection with the matter referred to in Claim A 2—including all versions stored in mailboxes, backup systems, archive folders, folders for deleted items and sent items, as well as other data storage locations—namely, the data sets in the work-provided email inboxes of university faculty members Prof. Dr. ... ... and Prof. ... ... ...—unchanged until the final and binding conclusion of the main proceedings. 2. The respondent is required to notify the relevant departments of its IT Services Division of this retention obligation and to provide the Court with proof of such notification within one week of service of the preliminary injunction. The basis for the order stems from the respondent’s documented refusal to comply with the petitioner’s right to access information, which sufficiently substantiates the risk of data manipulation during the period between the filing of the complaint and the decision on the merits. The right to an injunction arises from the right to access under Article 15 of the GDPR and the general security and accountability obligations of controllers under Article 5(2) and Article 32 of the GDPR. Under data protection law, the respondent is the controller of the applicant’s personal data processed in the matter at issue. According to Article 4(7) of the GDPR, the controller is the natural or legal person, public authority, agency, or other body that, alone or jointly with others, makes the decision regarding the purposes and means of the processing of personal data. According to established case law, the Court of Justice interprets this term broadly; the decisive factor is the actual influence exercised over the purposes and means of processing. In the present case, the respondent fulfills both elements of the definition. The respondent provides the email infrastructure, the mailboxes, the email storage, the backup systems, and the IT environment necessary for processing, in which the data processed in this case is stored. The respondent alone makes the decision on the technical design of these means, their security, their retention period, and the access regulations. Other entities, namely the Springer Nature Group or the DVjs editorial team, have no technical access to the ... IT infrastructure. In this sense, the means of processing are exclusively under ...’s control. The individuals processing the data in this matter—Prof. ... ... and Prof. ... ...—are university faculty members of the respondent and, in this capacity, members of ... within the meaning of Para 2(1) of the ... User Guidelines for Information Processing Systems. Their official email accounts (... or ... or comparable addresses under the ... domain) constitute the respondent’s institutional infrastructure. The processing thus takes place, at least in part, in pursuit of the institutional purposes set forth in Articles 2 and 3 of the Bavarian Higher Education Innovation Act, to the extent that the activity—as peer review and editorial work—is attributable to the respondent’s academic self-governance. Even if the respondent does not wish to attribute the pursuit of the DVjs’ editorial and publishing purposes exclusively to its own institutional purposes, there is in any case joint liability under Article 26 of the GDPR. According to the case law of the CJEU, it is sufficient that an entity makes a substantial contribution to the purposes or means of the processing. The respondent makes such a contribution—it provides the means and overlaps the purposes with its institutional tasks—and is therefore, in any event, a joint controller. In cases of joint controllers, the obligations of both controllers exist independently (Article 26(3) of the GDPR). The data subject may expressly assert his or her rights with and against each individual controller. The respondent’s obligation to provide information therefore exists independently of any further responsibility on the part of the Springer Nature Group or other entities. The claim for an order arises from the right to access under Article 15 of the GDPR and the general security and accountability obligations of the controllers under Article 5(2) and Article 32 of the GDPR. The applicant’s right to access would be thwarted if the data at issue, which falls within the respondent’s sphere of responsibility, were to be altered or removed—through erasure, overwritten, moved, or otherwise manipulated. The retention of this data in its unaltered form is therefore a necessary prerequisite for the subsequent fulfillment of the main claim. In a letter dated June 10, 2026, the respondent moved to dismiss the motion. In support of this motion, the respondent argued that the petitioner had not established a credible claim for an injunction. The respondent is neither the owner of the publishing house, nor the publisher, nor a contractual partner, nor a processor. There is no collaborative or contractual relationship whatsoever between the respondent and the publishing house Springer-Nature-Verlag or the editorial staff of the DVjs. The activity as editor for the publishing editorial department is not based on any statutory or contractual power of representation of the editors on behalf of the respondent, nor on the assumption of joint data protection liability between the respondent and the publisher or the editors pursuant to Art. 26 GDPR. In this respect, the editors of the DVjs do not perform any official duties for the University of … or the Free State of Bavaria. Their work as editors is carried out neither as a primary nor as a secondary occupation and is independent of the respondent. The mere use of an email address with the domain “...” by a publisher for correspondence between the publisher, the publishing house, and the petitioner does not, on that basis alone, make the respondent a controller within the meaning of Article 4(7) of the GDPR. Rather, this use is equivalent to the use of email addresses with domains from other email providers. The email address with the domain “...” merely indicates membership in the ...; however, this does not allow for any inference regarding jurisdiction or controller responsibility under data protection law for data processing in connection with the publication of a manuscript by the DVjs and the related procedural complaint. The respondent has no authority whatsoever to make a decision on or participate in this matter, not even in a subordinate capacity. The editors or the publisher would make their own decisions on whether and which technical tools to use. Contrary to the applicant’s assertions, the context at issue in this dispute also does not fall within the respondent’s jurisdiction or statutory duties. It is neither a matter of state nor a matter concerning a public body. Nor does the situation constitute what the petitioner refers to as “academic self-governance.” Accordingly, the respondent is under no obligation to provide information pursuant to Article 15 of the GDPR. In response, the petitioner argued that the right under Article 15 of the GDPR requires only that the respondent process the petitioner’s personal data. This requirement is independent of the content, purpose, and legal classification of the process in connection with which the data was collected, and it requires no further justification. The sole determining factor is who processes the applicant’s personal data in the mailboxes at issue here. The respondent alone makes the decision on the means of this processing—operation of the email system, determination of access rights, retention, archiving, and erasure. The respondent is therefore the controller of the data stored in its mailboxes within the meaning of Art. 4(7) of the GDPR, regardless of who made the editorial decision. Prof. ... ... consistently acts in this matter under his official capacity (address of the ... ..., Institute of German Philology, ..., official secretarial phone number, and official ...de email address). An activity carried out via the official email account and a publicly funded university secretariat is the opposite of an independent private matter and demonstrates the respondent’s control over the means of processing. In response, the respondent stated that the publishers had used the IT infrastructure of the University of ... for their publishing and editorial purposes. As part of their editorial responsibilities, the publishers would make independent and responsible decisions about which data they process for which purposes within the scope of their editorial and publishing activities, and which means they employ. They did not act in the exercise of their official or professional duties, but rather in a part-time capacity as editors of a journal. For this activity, the editors themselves determine which data is processed (author data, manuscripts, etc.), for what purpose (publication of the journal), and which resources are used (communication, editorial work, and, if applicable, platforms). Accordingly, they could also use other technical tools, such as other email providers or IT service providers. The client has no decision-making authority or say in the matter, not even to a minor extent. Responsibility for the storage of their data in connection with publishing activities also lies solely with the publishers or the publishing house, but not with the respondent. The respondent has no right to use that data for its own purposes. It does not make a decision on the purpose and means of the specific data processing nor does it bear organizational responsibility for it. This is further supported by the fact that the respondent has no say whatsoever in the publication, the communication does not serve the performance of official duties, and the use of the official email address is merely a technical means of communication. The mere use of a “government email address” does not automatically make a government agency the data controller under data protection law. The publishers had openly presented themselves to the petitioner in their respective roles and functions, and not as employees of the respondent acting in their representation of the respondent within the scope of their official duties. It was evident that the petitioner’s concern was the publication of his manuscript in a journal that, undisputedly, was neither (co-)published by nor on behalf of the respondent. In this regard, he had communicated not with the respondent, but with the editors or the publisher. Just as the respondent is neither competent nor responsible for the process surrounding the publication of the applicant’s article and the associated “complaint procedure” vis-à-vis the editorial board or the publisher, so too is the respondent not the data controller with respect to the applicant under data protection law. The petitioner is neither a member, employee, student, nor any other contractual partner of LMU. Furthermore, the respondent did not collect any personal data from the petitioner. In a letter dated June 29, 2026, the petitioner stated that the requests previously filed were maintained. Additionally, the petitioner requested that 1. to order the respondent, by way of a preliminary injunction, to retain all personal data concerning the petitioner in the email accounts and systems operated by the respondent—including archive, backup, and sent items—in their original form for the duration of the proceedings and to exempt such data from any erasure; 2. to order the respondent to disclose the measures taken to safeguard this data. Following further correspondence, the respondent supplemented its previous statements to the effect that it was not possible for it to search the name-based email accounts of professors without a work-related connection. The applicant’s access request is in no way related to any official activity or public duty of the respondent. In a letter dated July 17, 2026, the respondent informed the petitioner, in response to his request for additional information, among other things, that the …, as the data controller pursuant to Article 4(7) of the GDPR, does not process any personal data pertaining to him. There was no employment relationship, no student status, no other membership or contractual relationship involving the applicant, nor any data collection concerning him by the University ... The data that the petitioner had provided to the respondent in his request for information was being processed for the purpose of fulfilling accountability obligations under data protection law pursuant to Article 5(2) of the GDPR. It would be deleted no later than three years after the final conclusion of the proceedings. Any data processing related to the manuscript that the petitioner submitted to the “Editorial Board of the Deutsche Vierteljahresschrift für Literaturwissenschaft und Geistesgeschichte” remains unaffected. In this regard, the case is pending before the Bavarian Administrative Court in Munich, and a decision has yet to be rendered. By order dated July 15, 2026, the legal dispute was referred to a single judge for a decision. For further details, reference is made to the court file and the submitted administrative file. II. 1. The joinder of the co-editors of the DVjs named by the petitioner, Prof. Dr. ... and Prof. Dr. ..., was required under § 65(2) VwGO because the Court’s decision affects their legal interests. 2. To the extent that the petitioner seeks, by way of a preliminary injunction to secure his request for information, to compel the respondent apart from any data processing related to the manuscript he submitted to the editorial office of the *Deutsche Vierteljahresschrift für Literaturwissenschaft und Geistesgeschichte*, in particular the email correspondence concerning the petitioner between Prof. ... and ...—all other personal data concerning the petitioner in the email accounts and systems operated by ... —including archive, backup, and sent items—to be retained unchanged for the duration of the proceedings and exempted from any erasure, and to order the respondent to disclose the measures taken to safeguard this data, his motion is already inadmissible due to a lack of standing. The respondent most recently informed the petitioner in a letter dated July 16, 2026, that—notwithstanding any data processing in connection with the manuscript the petitioner submitted to the editorial office of the *Deutsche Vierteljahresschrift für Literaturwissenschaft und Geistesgeschichte* —aside from the data provided by the petitioner in his access request and the internal correspondence regarding the processing of that request—“no employment relationship, no student status, no other membership or contractual relationship with the university, nor any data collection regarding him by the University of Munich, and that no personal data pertaining to the applicant was being processed.” In light of this disclosure, the demand for further data preservation—which goes beyond the original request—to enforce a request for information is therefore without merit. 3. Insofar as a preliminary injunction is sought to compel the respondent to to retain, unchanged, all of the applicant’s personal data within the respondent’s sphere of responsibility—which is related to the manuscript submitted by the applicant to the editorial office of the DVjs published, among others, by Professors ... and …—in particular, the data stored in the work-related email accounts of these university professors—the motion is admissible but unfounded. Pursuant to § 123(1), first sentence, of the Administrative Court Rules of Procedure (VwGO), the Court may, upon request, issue a preliminary injunction regarding the subject matter of the dispute even before a lawsuit is filed, if there is a risk that a change in the existing situation could prevent or significantly impede the enforcement of a right of the petitioner. An applicant must demonstrate both the necessity of a provisional measure—the so-called “ground for the order”—and the existence of a right to be safeguarded—the “claim for the order”—(Section 123 VwGO in conjunction with Section 920(2) ZPO). In the present case, the petitioner has not demonstrated a credible claim to information that requires protection. In particular, the request for information—the enforceability of which is to be secured in this case—cannot be based on Article 15 of the GDPR. 3.1. Pursuant to Article 15 of the GDPR, the data subject has the right to request confirmation from the controller as to whether personal data concerning him or her is being processed; if so, the data subject has the right to access such personal data and to receive the information specified in Article 15(1)(a)–(h). A prerequisite for a right of access against the respondent is therefore the processing of personal data concerning the applicant by the respondent in its capacity as the controller. According to Article 4(1) of the GDPR, personal data is any information relating to an identified or identifiable natural person. Thus, email correspondence containing the applicant’s name falls under this provision. The fact that this personal data is “processed” when used in emails within the meaning of Article 4(2) follows from the definition of “processing.” This includes any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transfers, dissemination, or any other form of making available, as well as the alignment or combination, restriction, erasure, or destruction of personal data. The sole issue in dispute is whether the respondent is the “controller” within the meaning of Article 4(7) of the GDPR with respect to the processing of this personal data. According to the definition in Article 4(7) of the GDPR, “controller” means the natural or legal person, public authority, agency, or other body that, alone or jointly with others, makes the decision regarding the purposes and means of the processing of personal data. If two or more controllers jointly determine the purposes and means of processing, they are joint controllers (Article 26(1), first sentence, of the GDPR). With regard to the respondent’s liability under data protection law, it is argued that the term should be interpreted broadly. The only decisive factor is who makes the decision on both the purposes and the means of processing. In the present case, this is the respondent. In contrast, it is argued that the respondent cannot be regarded as a controller within the meaning of Art. 4(7) of the GDPR, since the use of the email address with the domain ....de has no connection in this case to the official or professional activities of the university faculty members, but rather relates to a part-time role as the publisher of a journal over which the respondent has no influence whatsoever—due to a lack of decision-making authority or say—and for which the respondent bears no organizational responsibility. The use of the work email address serves merely as a technical means of communication. It is equivalent to the use of email addresses with domains from other email providers and does not make a public authority the data controller under data protection law. Whether the respondent is thus to be regarded in the present case as the controller within the meaning of Art. 4(7) GDPR in connection with the permitted private use of a work-provided email account has not been clarified by the higher courts. Even in the case of unauthorized use of a work-provided email account—a so-called “employee overreach”—different views are expressed in the legal literature —as well as by data protection supervisory authorities and in case law—hold differing views on who should be regarded as the controller within the meaning of Article 4(7) of the GDPR. There is certainly no clear trend in case law regarding who is to be considered the controller in the case of authorized private use of a work-provided email account. In the opinion of the single judge, however, upon summary review, the assessment of data protection controller liability does not depend on whether the employee’s private use of a work-provided email account was authorized—as in the present case—or whether the employee engaged in such use without authorization. This is because, in both cases, the employee in question determines both the purpose and the means of the processing he or she carries out privately—as the respondent explained in its briefs in the present proceedings—and is therefore the (sole) controller within the meaning of Article 4(7) of the GDPR. A more in-depth discussion of this issue —which would be more appropriately addressed in main proceedings—are not required in the present proceedings, since the present motion for interim relief must be denied regardless of the assessment of who is to be regarded as the controller within the meaning of Article 4(7) of the GDPR. 3.2.1. If the respondent is not considered the controller within the meaning of Article 4(7) of the GDPR, there is no right to the requested disclosure of information in the absence of any other legal basis for the claim. 3.2.2. However, even if the respondent’s status as a controller within the meaning of Article 4(7) of the GDPR is affirmed, the applicant’s request for information (and thus also the present motion for summary relief) fails in any event due to the legitimate interests of university faculty members in the confidentiality of their communication data—namely, regarding whether, when, to whom, from whom, and the content of the communication—which must be regarded as outweighing the right to access information, specifically the professors’ general right to privacy. 3.2.2.1. Although the wording of Article 15 of the GDPR contains no indication that the data subject’s right of access under Article 15(1) of the GDPR is restricted, Pursuant to Article 15(4) of the GDPR, only the right to receive a copy under para 3 may not infringe upon the rights and freedoms of others. However, the prevailing view in the scholarly literature is that the right of access under Article 15(1) of the GDPR is already limited by the rights and freedoms of others within the General Data Protection Regulation itself (see Federal Court of Justice [BGH], judgment of Feb. 22, 2022, VI ZR 14/21, juris para. 17 with further references). In this regard, the BGH judgement of February 22, 2022—VI ZR 14/21—juris para. 18 et seq. states the following: “In view of the fact that Art. 15 of the GDPR must be interpreted in light of the fundamental rights guaranteed by the Charter of Fundamental Rights of the European Union (hereinafter: the Charter), in particular Art. 7 (right to respect for private life) and Article 8 of the Charter (right to the protection of personal data) (see CJEU, judgements of March 9, 2017 – C-398/15, BB 2017, 652, para. 39 et seq., and of May 13, 2014—C-131/12, NJW 2014, 2257, para. 68 et seq., regarding the provisions of Directive 95/46/EC; on the primacy of the fundamental rights enshrined in the Charter, see BVerfGE 152, 216, para. 42 et seq. – Right to be Forgotten II), that the General Data Protection Regulation, pursuant to Art. 1(2) GDPR, protects the fundamental rights and freedoms of natural persons and, in particular, their right to the protection of personal data, and that, according to Recital 63, fifth sentence, the rights and freedoms of others are not to be prejudiced by the disclosure of information, it would be virtually impossible to justify the assumption that the right of access is granted without restriction under Article 15(1) of the GDPR—including, and particularly, with regard to the origin of data under para 1, second clause, subparagraph (g). Pursuant to Article 8(2), first sentence, of the Charter, personal data may be processed only with fairness, for specified purposes, and with the consent of the data subject or on another legitimate basis provided for by law. Pursuant to Article 8(2), second sentence, of the Charter, every person has the right to obtain information about the data collected concerning them and to have such data rectified. Consequently, the right to the protection of personal data may be invoked not only by the data subject pursuant to Article 15(1) of the GDPR, but also by anyone whose data would be disclosed through a transfer in the context of the right of access under Article 15(1), second clause, subparagraph (g) of the GDPR. Such disclosure through transmission would constitute processing of personal data (Art. 4(2) of the GDPR), which would be lawful only under the conditions set forth in Art. 6(1), first subparagraph, of the GDPR (prohibition subject to authorization). If the data subject affected by the disclosure of the origin of the data does not consent to the transfer of their data (Art. 6(1), first subparagraph, lit. a GDPR), only the basis for lawfulness under Art. 6(1), first subparagraph, 1(f) of the GDPR. Accordingly, the transfer of personal data would be lawful if it were necessary to protect the legitimate interests of the controller (here: the defendant) or a third party (here: the plaintiff with regard to his right of access), provided that the interests or fundamental rights and freedoms of the data subject (here: the whistleblower), which require the protection of personal data, do not prevail. Article 6(1), para 1(f) of the GDPR thus requires a balancing of the respective conflicting rights and interests, in the context of which the significance of the relevant rights arising from Articles 7 and 8 of the Charter, must be taken into account (see CJEU, Judgement of May 13, 2014—C-131/12, NJW 2014, 2257, para. 74 on Art. 7(f) of Directive 95/46/EC). Thus, Art. 6(1), subpara. 1(f) of the GDPR the possibility of balancing conflicting fundamental rights of private individuals under Union law (Buchner/Petri in Kühling/Buchner, GDPR BDSG, 3rd ed., Art. 6 GDPR, para. 141; on the fact that the fundamental rights of the Charter also guarantee protection in private-law disputes, see BVerfGE 152, 216, para. 95, 96, 111 with further references—Right to be Forgotten II—regarding Directive 95/46/EC). The same considerations would apply if the restriction of the right of access by the rights and freedoms of third parties did not already follow directly from the General Data Protection Regulation (see Bäcker in Kühling/Buchner, GDPR BDSG, 3rd ed., Art. 15 GDPR, para. 33). In any event, in such a case, Art. 23(1)(i) GDPR provides, under certain conditions, for the possibility of restricting the right of access by a law that ensures the “protection of the rights and freedoms of others.” Article 10(2)(3) of the Bavarian Data Protection Act (BayDSG) contains such a provision. According to this provision, access to information shall be denied to the extent that personal data or the fact of its storage must be kept confidential to protect the data subject or due to the overriding legitimate interests of third parties. Whether a duty of confidentiality exists in a specific case is thus determined by a balancing of interests on a case-by-case basis, whereby the legitimate interests of the third party must prevail. 3.2.2.3. In the present case, the requested disclosure of information regarding the email accounts of the aforementioned professors would constitute a significant infringement of their general right of personality, which is protected under Article 2, para. 1, in conjunction with Article 1, para. 1, of the Basic Law. This right encompasses the right to the protection of one’s private and intimate sphere and the right to the confidentiality and integrity of information technology systems (BVerfG NJW 2008, 822). It protects against intrusion into one’s personal sphere of life as well as against the prying into that sphere. Messages sent to the professors’ personal email accounts and those composed by them via these accounts therefore fall—just like letters—within the scope of protection of the general right of personality as part of their individual communication. This also encompasses all circumstances related to the use of the email accounts in connection with the DVjs (nature and frequency of use, recipients, senders, content of the communication, etc.). This right far outweighs the petitioner’s interest in obtaining the requested information, especially since the professors’ email accounts, insofar as they are used in connection with the DVjs, are used by Users are not used in the course of official duties for the respondent, for a government matter, or for a corporate matter, but exclusively for non-official use by the professors, who could just as easily have used email addresses with domains from other email providers for this purpose. In view of the professors’ overwhelmingly greater interest in refusing to disclose the information sought by the petitioner, and in the absence of an enforceable claim for disclosure in the main proceedings, there is no claim in the present interim proceedings for the retention of this data until the final and binding conclusion of the main proceedings. The motion for interim relief was therefore denied. The decision on costs is based on § 154(1) VwGO; the determination of the value in dispute is based on § 53(2)(1) and § 52(2) GKG in conjunction with No. 1.5 of the Schedule of Values in Dispute for Administrative Jurisdiction. Permalink: https://openjur.de/u/2553648.html (https://oj.is/2553648) Full Text Print View PDF Download Citations3 Cited0 References0 Keywords Transparent Civil Society Initiative Imprint Data Protection Terms of Use English openJur e.V.

---
Generated by overview.legal · https://overview.legal/posts/353647 · 2026-09-03
