Skip to content
Case Law · BGH EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

VI ZR 144/23

The Federal Court of Justice held that a claim for injunctive relief under national law directed against the repeated transfer of personal data in violation of the GDPR cannot be rejected on the grounds that the provisions of EU law are exhaustive. English Summary. Facts. The operator of an online store (the controller) had embedded third-party features in its websites. As a result of this practice, the data of users accessing the website (the data subjects) was stored on servers operated by thi

BGH

How it connects

Guidelines 8/2022 identifying a controller or processor's lead supervisory authority Guidelines for identifying a controller or processor’s lead supervisory authority Guidelines ·EDPB Apr 17, 2023 Supervision Controllers Supervisory Authorities
Garante · 10286417 Holding. Holding First, the DPA held that the software allowed the operator only to exclude a document from publication (opt-out) instead of selecting the documents to be… 10286417 ·Italy Sep 16, 2026 Personal Data Affirmative Action and Opt-In Requirements for Consent Consent Validity Requirements and Conditions
613/2026 The DPA underscored that the controller sent no follow up with the data subject’s request, and in combination with the fact that the controller only acted after the DPA reached… 613/2026 ·Italy ·Garante Sep 16, 2026 Personal Data Supervisory Authorities Controllers
Garante · 616/2026 Facts. Facts The DPA received a complaint from a data subject concerning the processing operations of the University Health Agency of Friuli Centrale’s (the controller) electronic… 616/2026 ·Italy Sep 16, 2026 Health Data Personal Data Access Controls

Full text

The Federal Court of Justice held that a claim for injunctive relief under national law directed against the repeated transfer of personal data in violation of the GDPR cannot be rejected on the grounds that the provisions of EU law are exhaustive. English Summary. Facts. The operator of an online store (the controller) had embedded third-party features in its websites. As a result of this practice, the data of users accessing the website (the data subjects) was stored on servers operated by third parties. A data subject who had ordered goods from the controller's online store argued that his name, address, IP address, and numerous pieces of usage data from the ordering process had been unlawfully transferred to third parties. The data subject filed a lawsuit requesting an injunction to stop these transfers of personal data. The court of first instance dismissed the lawsuit on the grounds that it was inadmissible due to a lack of specificity. It also held the lawsuit was without m