Fear, Data

Fear of a Data Breach Is Now Enough to Claim Damages, Germany’s Top Court Rules

Published on 07/24/2026 at 04:52 | Redaktion boerse-global.de

Germany's top civil court rules job applicants can claim damages for reasonable fear of data misuse, not just actual harm, reshaping GDPR employment law.

German Court Widens GDPR Compensation for Data Fear Without Misuse
Fear of a Data Breach Is Now Enough to Claim Damages, Germany’s Top Court Rules Illustration mit AI erstellt übermittelt durch boerse-global.de

Germany’s highest civil court has dramatically widened the grounds for compensation under European data protection law, ruling that workers and job applicants can claim damages even if their personal data was never actually misused — as long as they had a reasonable fear that it might be.

The decision, handed down by the Federal Court of Justice (BGH) on 23 June 2026, marks a significant shift in how the General Data Protection Regulation (GDPR) is interpreted in employment and recruitment contexts. In the case at hand (file number VI ZR 97/22), a bank accidentally sent a job applicant’s name and salary expectations to an unrelated third party. The BGH found that the applicant’s justified anxiety about potential misuse of that information was sufficient grounds for non-material damages. No special severity of harm is required, the court said. The claimant was awarded 1,000 euros.

A parallel case now before the BGH could push the boundaries even further. It involves a data leak at a recruiter on the professional network Xing, where confidential information was sent to the wrong user. The BGH has referred questions to the European Court of Justice asking whether mere worry or annoyance — without any concrete harm — can constitute a compensable injury under the GDPR.

When workplace surveillance crosses the line

The BGH ruling is part of a broader tightening of employee privacy protections across multiple jurisdictions. In Brazil, the Supreme Labour Court’s First Chamber ruled on 20 July 2026 that evidence obtained by accessing a supervisor’s WhatsApp Web account without authorisation was inadmissible. The data was extracted during a routine computer maintenance session without the employee’s consent. The court called it an invasion of privacy and reversed the dismissal.

Advertisement

As privacy rules tighten, employers need to ensure their own compliance paperwork is airtight. A free Health & Safety Toolkit provides ready-to-use risk assessments and checklists that help UK businesses meet their legal duties under the Health & Safety at Work Act 1974. Download the free Health & Safety Toolkit

Germany’s own regional labour courts have drawn nuanced lines. In August 2025, the Schleswig-Holstein State Labour Court dealt with a case involving a tasteless joke shared in a private WhatsApp group. The employer issued an immediate dismissal, but the court ruled it invalid. While the employee had committed a breach of duty, a formal warning would have sufficed — the video remained within a closed circle and had no external impact.

What bosses can and cannot check on company messengers

Employment law specialists point out that the rules for monitoring workplace chat tools are strictly defined. Employers can ban private use of company messengers outright. If such a ban is in place, the company is entitled to check compliance. But if private use is permitted, surveillance is only allowed when there is a concrete suspicion of a criminal act or a serious breach of duty. Any monitoring must be proportionate, involve the data protection officer, and be conducted in the employee’s presence.

EU extends voluntary chat control — with limits

On the policy front, EU member states have agreed to extend the so-called voluntary chat control regime until April 2028. A formal decision was expected on 23 July 2026. Following amendments by the European Parliament, the scheme will apply only to unencrypted messages. Client-side scanning of encrypted content on end devices is off the table. German supporters argue the measure is necessary for law enforcement, while civil liberties groups denounce it as suspicionless mass surveillance.

Meta halts internal worker tracking program

Technology companies are also feeling the pressure. Meta has suspended its “Model Capability Initiative” (MCI), an internal program that collected detailed data on employee work behaviour — including mouse movements, clicks, and keyboard inputs — to train artificial intelligence models. After concerns emerged that sensitive information might have been visible to other staff, the company is now reviewing the program for compliance with the GDPR and national labour law restrictions.

Advertisement

Staying compliant with UK health and safety law is about more than just data — it’s about protecting your entire workforce. Over 37,000 UK businesses already use a free toolkit with risk assessments and checklists that cover everything from fire safety to COSHH. Get the free Health & Safety at Work Act 1974 Toolkit

Disclaimer regarding our articles: No investment advice, no buy or sell recommendation. Information on prices, companies, and markets is provided without guarantee; changes are possible at any time. Stock market transactions can lead to substantial losses. Our articles are created and reviewed in whole or in part automatically with the support of AI.

en | boerse | 69856960 |