<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>DPL Consult Data Protection Agency</title>
	<atom:link href="https://www.dpl-consult.com/en/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.dpl-consult.com/en/</link>
	<description>Your data protection officer from Hamburg</description>
	<lastBuildDate>Tue, 16 Dec 2025 18:48:30 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updateperiod>
	hourly	</sy:updateperiod>
	<sy:updatefrequency>
	1	</sy:updatefrequency>
	<generator>https://wordpress.org/?v=7.1.2</generator>

<image>
	<url>https://www.dpl-consult.com/wp-content/uploads/2021/11/site-icon.png</url>
	<title>DPL Consult Data Protection Agency</title>
	<link>https://www.dpl-consult.com/en/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>On the responsibility of online marketplaces</title>
		<link>https://www.dpl-consult.com/en/uncategorised/on-the-responsibility-of-online-marketplaces/</link>
		
		<dc:creator><![CDATA[Arash Ekhlasi]]></dc:creator>
		<pubDate>Mon, 15 Dec 2025 20:16:30 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid ispermalink="false">https://www.dpl-consult.com/?p=5738</guid>

					<description><![CDATA[<p>Platform operators as data protection controllers: The ECJ requires proactive protective measures – simply reporting and deleting will no longer suffice in future.</p>
<p>Der Beitrag <a href="https://www.dpl-consult.com/en/uncategorised/on-the-responsibility-of-online-marketplaces/">Zur Verantwortlichkeit von Online-Marktplätzen</a> erschien zuerst auf <a href="https://www.dpl-consult.com/en">DPL Consult Datenschutzagentur</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph">The ECJ ruling of 2 December 2025 (case reference: C-492/23) initially sounds like a special problem for lawyers. In fact, however, it relates in very practical terms to how online marketplaces and platforms must deal with user adverts if they contain personal data - such as photos, telephone numbers or other details that make a person identifiable. The starting point was an ad on a Romanian online marketplace that was published without the consent of the person concerned and was particularly sensitive because it conveyed intimate, stigmatising content.&nbsp;</p>



<p class="wp-block-paragraph">At the heart of the case was the question of whether the platform operator is merely a „technical service provider“ that hosts third-party content, or whether it is itself responsible under data protection law? The ECJ's answer is clear: the operator of an online marketplace is the „controller“ within the meaning of the GDPR for the processing of personal data contained in user adverts. This applies in any case if the platform not only stores the data neutrally, but actively structures and commercially utilises the publication, for example by specifying the presentation, categorisation, duration and reach or through its own commercial purposes such as advertising. Precisely because the data is only „brought onto the Internet“ and made accessible to the public by the platform, it does not remain in a purely passive role.</p>



<p class="wp-block-paragraph">What the ECJ derives from this is particularly far-reaching: For platforms, a mere „report-and-delete“ is not sufficient if their service typically harbours the risk of users posting sensitive data. The ECJ emphasises that data controllers must ensure the principles of lawful data processing and must therefore design technical and organisational measures in such a way that data protection violations are prevented as far as possible before publication. For „special categories“ of personal data (colloquially: sensitive data, such as data relating to sexual life), this means that publication is generally prohibited unless explicit consent or another narrowly defined exception pursuant to Art. 9 para. 2 GDPR has been obtained. Accordingly, the operator must provide processes that reliably safeguard these requirements before publication.&nbsp;</p>



<p class="wp-block-paragraph">The ECJ links this to very specific compliance consequences. The judgement shows that the platform operator cannot simply close its eyes to the problem of consent in the case of an anonymous advertising system. If the platform and advertiser jointly enable publication, the platform operator must be able to collect the identity of the advertiser and verify it within a suitable framework in order to make the responsibilities and evidence (in particular regarding consent for sensitive data) practically manageable. Furthermore, the ECJ clarifies that the liability privileges of e-commerce law (and the logic of „no general monitoring obligation“) do not override the obligations arising from the GDPR. Responsibility under data protection law and the obligation to take appropriate protective measures exist independently of this.</p>



<p class="wp-block-paragraph">In practice, this is a paradigm shift: operators of classifieds portals, marketplaces and platforms with user-generated adverts need to rethink their product and moderation architecture, moving away from purely reactive processes towards risk-based precautions „by design“. The more likely a service is to be at risk of abuse (e.g. personals, personalised services, adult categories), the more likely it is that identity checks, pre-filters, staged approvals, consent workflows and robust verification processes will be required. At the same time, the risk of liability and fines increases because those affected can no longer only take action against the anonymous advertiser, but also directly against the platform operator under data protection law.&nbsp;</p><p>Der Beitrag <a href="https://www.dpl-consult.com/en/uncategorised/on-the-responsibility-of-online-marketplaces/">Zur Verantwortlichkeit von Online-Marktplätzen</a> erschien zuerst auf <a href="https://www.dpl-consult.com/en">DPL Consult Datenschutzagentur</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Disclosure of user data</title>
		<link>https://www.dpl-consult.com/en/blog/disclosure-of-user-data/</link>
		
		<dc:creator><![CDATA[Arash Ekhlasi]]></dc:creator>
		<pubDate>Mon, 15 Dec 2025 20:08:15 +0000</pubDate>
				<category><![CDATA[blog]]></category>
		<category><![CDATA[startpage slider]]></category>
		<guid ispermalink="false">https://www.dpl-consult.com/?p=5732</guid>

					<description><![CDATA[<p>Anonymity in online reviews strengthened: The Federal Court of Justice ruled that critical expressions of opinion alone do not trigger an obligation to identify users.</p>
<p>Der Beitrag <a href="https://www.dpl-consult.com/en/blog/disclosure-of-user-data/">Herausgabe von Nutzerdaten</a> erschien zuerst auf <a href="https://www.dpl-consult.com/en">DPL Consult Datenschutzagentur</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph">On 11 March 2025, the Federal Court of Justice (BGH, Ref.: VI ZB 79/23) ruled on whether and under what conditions operators of online review platforms can be obliged to disclose the identity of anonymous users if a company considers its rights to have been infringed by a review. The underlying legal dispute concerned an employer review platform on which a user had rated a law firm with only one star in the „superior behaviour“ category. This review contained harsh language, including criticism that former employees had only received their outstanding salaries or employment references after legal action had been taken. The law firm then sought a court order requiring the platform to disclose the identity of the user who had posted the review so that it could take legal action against him. As the basis for this claim to information, the law firm referred to Section 21 (2) of the Telecommunications Digital Services Data Protection Act (TDDDG). According to this, platform operators may be obliged to disclose inventory data under certain conditions if the content is relevant under criminal law.&nbsp;</p>



<p class="wp-block-paragraph">The Federal Court of Justice denied the law firm's right to information, thereby confirming the decisions of the lower courts. In the court's opinion, there was no „illegal content“ within the meaning of the relevant provision that would trigger an obligation to provide information. The decisive factor here was the distinction between statements of fact and value judgements: a criminal statement of fact requires that a statement be verifiable and provable and that it fulfils the elements of one of the criminal offences listed in Section 21 (2) TDDDG, such as insult, defamation or libel. The Federal Court of Justice found that the contested review in the present case could not be qualified as an objectively verifiable, factual statement, but rather as a subjective expression of opinion with a value judgement character. Insofar as it contained factual elements, these were inseparably linked to the evaluative impression that the user wanted to convey. In cases of ambiguous statements, the Federal Court of Justice ruled that, in case of doubt, the decision should be made in favour of freedom of expression.&nbsp;</p>



<p class="wp-block-paragraph">With this decision, the Federal Court of Justice has set the legal standards for determining when an operator of a digital platform is obliged to disclose a user's personal data. The court has made it clear that mere defamatory or subjective criticism alone is not sufficient to trigger an obligation to provide information. Only if there is clearly criminal content that fulfils the criteria set out in Section 21(2) of the TDDDG can the platform operator be obliged to disclose inventory data. As is usually the case, whether there is an obligation to disclose information is a question that must be decided on a case-by-case basis.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">In the past, the Federal Court of Justice (BGH) has already ruled that operators of review platforms are not obliged to delete content every time a complaint is made about defamatory content. With the current ruling, the BGH extends this case law to the identity of users. Their anonymity when rating companies is generally paramount, as long as the statements do not constitute any of the criminal offences listed in Section 21 (2) TDDDG. At the same time, the ruling also means that platform operators must establish legal review processes to assess complaints on a case-by-case basis to determine whether a review contains content that is relevant under criminal law. Operators should therefore, in their own interest, establish internal&nbsp;</p><p>Der Beitrag <a href="https://www.dpl-consult.com/en/blog/disclosure-of-user-data/">Herausgabe von Nutzerdaten</a> erschien zuerst auf <a href="https://www.dpl-consult.com/en">DPL Consult Datenschutzagentur</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The concept of an organisation in the GDPR</title>
		<link>https://www.dpl-consult.com/en/blog/the-definition-of-a-company-in-the-gdpr/</link>
		
		<dc:creator><![CDATA[Arash Ekhlasi]]></dc:creator>
		<pubDate>Mon, 15 Dec 2025 20:02:05 +0000</pubDate>
				<category><![CDATA[blog]]></category>
		<category><![CDATA[startpage slider]]></category>
		<guid ispermalink="false">https://www.dpl-consult.com/?p=5729</guid>

					<description><![CDATA[<p>Group-wide liability for GDPR violations: The ECJ clarifies that fines can be calculated based on the group's total global turnover.</p>
<p>Der Beitrag <a href="https://www.dpl-consult.com/en/blog/the-definition-of-a-company-in-the-gdpr/">Der Unternehmensbegriff der DSGVO</a> erschien zuerst auf <a href="https://www.dpl-consult.com/en">DPL Consult Datenschutzagentur</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph">The two decisions of the European Court of Justice (ECJ) of 5 December 2023 (Case C-807/21) and 8 February 2025 (Case C-383/23) are among the most important rulings on the law on fines under the General Data Protection Regulation (GDPR). They concern a question that is of enormous practical importance for companies: Who is actually considered an „undertaking“ under data protection law - just the individual company or the entire group - and what consequences does this have for data protection fines?</p>



<p class="wp-block-paragraph">The judgement of 5 December 2023 concerned a very high fine imposed by the Berlin data protection authority on a large real estate company. The point of contention was not so much the underlying data protection offence as the legal basis for the sanction. Under German administrative offences law, the principle has long applied that a legal entity can only be fined if culpable conduct can be proven on the part of a specific manager. The ECJ has clearly rejected this view. It found that the GDPR's system of fines is autonomous under EU law and cannot be made dependent on national attribution rules. Rather, the decisive factor is whether an „undertaking“ within the meaning of EU law has committed a data protection offence. This concept of an undertaking is to be understood functionally and originates from EU antitrust law. It covers any economic entity, regardless of how many legally independent companies it consists of. A corporate group as a whole can therefore be the addressee of a fine without the need to prove individual fault on the part of a specific natural person.</p>



<p class="wp-block-paragraph">This also touched on a second question that is particularly relevant in practice: What does the GDPR's fine limit of up to two or four per cent of annual global turnover refer to? The ECJ has clarified that this percentage can refer to the turnover of the entire company in a functional sense, i.e. the group turnover. The judgement of 2023 has thus opened the door to significantly higher fines and brought data protection sanctions law closer to antitrust law.</p>



<p class="wp-block-paragraph">The ECJ ruling of 8 February 2025 follows on from this line and clarifies it further. This also concerned the interpretation of the term „undertaking“ in connection with the calculation of GDPR fines. The ECJ has confirmed its case law from December 2023 that the economic entity is decisive for determining the statutory upper limit. What is new is that the Court has made it even clearer that this approach follows from the GDPR itself, in particular from Recital 150, which states that the supervisory authorities have no discretion to limit the scope of fines to the individual subsidiary only if it is a group company. The functional concept of an undertaking is a binding standard, not merely an option.</p>



<p class="wp-block-paragraph">The two judgements have significant practical consequences. Under the GDPR, it is not possible to isolate data protection risks to individual subsidiaries or to „outsource“ them organisationally. Violations at an operational level can have financial consequences that affect the entire group. This increases the pressure to establish group-wide data protection compliance structures, define clear responsibilities and enforce uniform standards.&nbsp;</p><p>Der Beitrag <a href="https://www.dpl-consult.com/en/blog/the-definition-of-a-company-in-the-gdpr/">Der Unternehmensbegriff der DSGVO</a> erschien zuerst auf <a href="https://www.dpl-consult.com/en">DPL Consult Datenschutzagentur</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Compensation for damages in the case of „scraping“</title>
		<link>https://www.dpl-consult.com/en/startpage-slider/damages-for-scraping/</link>
		
		<dc:creator><![CDATA[Arash Ekhlasi]]></dc:creator>
		<pubDate>Mon, 15 Dec 2025 19:54:57 +0000</pubDate>
				<category><![CDATA[blog]]></category>
		<category><![CDATA[startpage slider]]></category>
		<guid ispermalink="false">https://www.dpl-consult.com/?p=5725</guid>

					<description><![CDATA[<p>The Federal Court of Justice strengthens the rights of data subjects: even the mere loss of control over personal data can justify claims for damages under the GDPR.</p>
<p>Der Beitrag <a href="https://www.dpl-consult.com/en/startpage-slider/damages-for-scraping/">Schadensersatz bei „Scraping“</a> erschien zuerst auf <a href="https://www.dpl-consult.com/en">DPL Consult Datenschutzagentur</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph">In its ruling of 18 November 2024, the Federal Court of Justice (BGH, Ref.: VI ZR 10/24) made a fundamental decision on compensation for data protection violations in the context of so-called „scraping“. The case concerned mass data access to Facebook user profiles, in which personal information such as telephone numbers, names and other data was automatically accessed by third parties and later published on the Internet. The plaintiff affected by this data access complained that the scraping had resulted in his personal data falling into the hands of unauthorised persons and asserted claims for damages, declaratory relief and injunctive relief, among other things, based on the General Data Protection Regulation (GDPR).</p>



<p class="wp-block-paragraph">In this ruling, the Federal Court of Justice clarified in particular that intangible damage may already exist if a data subject loses control over their personal data, even if this data has not been misused or no specific material disadvantage has occurred. This means that even the „mere and temporary“ loss of control over one's own data, for example because it is collected and published through scraping, can justify a claim for damages under Article 82 GDPR. The protection of personal data is an independent legal interest, the violation of which is considered worthy of protection regardless of any specific consequences. The focus in the assessment of claims for damages is therefore more on the protection of informational self-determination than on classic material consequences.&nbsp;</p>



<p class="wp-block-paragraph">At the same time, the Federal Court of Justice addressed the issue of calculating damages and clarified that, in individual cases, damages must be determined in accordance with the provisions on estimating damages (Section 287 of the German Code of Civil Procedure) , taking into account the special function of Article 82 GDPR as a compensation and indemnification standard. In similar cases, courts have considered compensation in the order of approximately €100 to be appropriate if the loss of control is purely technical and has no further serious consequences.</p>



<p class="wp-block-paragraph">This ruling has significant implications for platform operators, social networks and digital service providers. Operators must be aware that data protection violations can result not only in administrative fines, but also in a multitude of civil law claims for damages, even if the data concerned has not been misused. This applies in particular to cases in which third parties can automatically read data due to vulnerabilities in the platform or insufficiently secured interfaces. Operators should therefore review and, if necessary, improve their security and data protection measures in order to prevent scraping attacks or similar data access and thus reduce the risk of claims for damages. For affected users, the decision strengthens their rights: the Federal Court of Justice expressly recognises that the mere loss of control over personal data can constitute damage that must be compensated under European law.&nbsp;</p><p>Der Beitrag <a href="https://www.dpl-consult.com/en/startpage-slider/damages-for-scraping/">Schadensersatz bei „Scraping“</a> erschien zuerst auf <a href="https://www.dpl-consult.com/en">DPL Consult Datenschutzagentur</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Artificial intelligence - risks and opportunities for data protection</title>
		<link>https://www.dpl-consult.com/en/blog/damages-and-payments-for-pain-in-case-of-violations-against-dsgvo-2/</link>
		
		<dc:creator><![CDATA[Arash Ekhlasi]]></dc:creator>
		<pubDate>Wed, 27 Sep 2023 13:00:41 +0000</pubDate>
				<category><![CDATA[blog]]></category>
		<category><![CDATA[startpage slider]]></category>
		<guid ispermalink="false">https://www.dpl-consult.com/?p=5558</guid>

					<description><![CDATA[<p>Artificial intelligence influences data protection through new opportunities, but also poses significant risks.</p>
<p>Der Beitrag <a href="https://www.dpl-consult.com/en/blog/damages-and-payments-for-pain-in-case-of-violations-against-dsgvo-2/">Künstliche Intelligenz – Risiken und Chancen für den Datenschutz</a> erschien zuerst auf <a href="https://www.dpl-consult.com/en">DPL Consult Datenschutzagentur</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph">AI is now one of the most important technologies of our time. It enables innovations in many areas such as health, education, mobility and security. At the same time, however, AI also raises ethical and legal questions, particularly with regard to the protection of users' privacy and personal data.</p>



<ol class="wp-block-list" type="1">
<li><strong><strong>What data protection challenges arise when using AI?</strong></strong><br><br>AI is based on large volumes of data that are analysed, processed or used to recognise patterns, make predictions or support decisions. This can also involve personal data such as name, address, health status or preferences. This harbours various risks for data protection:<br>
<ul class="wp-block-list">
<li>Lack of transparency: AI users often do not know what data is collected about them, how their data is processed or who has access to it. This makes it difficult for them to exercise their rights to information, rectification or erasure or to withdraw their consent. <br></li>



<li>Lack of control: Users generally have little influence on the type of data processing and its consequences. This is particularly problematic if the user data is used for a purpose other than that originally intended or if the data processing is contrary to the user's own interests. Discrimination and disadvantages can also occur due to faulty or biased algorithms. <br></li>



<li>Lack of security: User data can be affected by hacking, theft or manipulation due to cyber attacks or human error. In the worst case scenario, this can lead to identity theft, blackmail or other damage to those affected.<br><br></li>
</ul>
</li>



<li><strong><strong>What opportunities can AI have for data protection?</strong></strong><br><br>In addition to data protection risks, the use of AI also harbours opportunities for data protection. AI can help to improve and strengthen data protection in the future.<br>
<ul class="wp-block-list">
<li>Development of data protection-friendly technologies: There are various approaches to incorporating data protection into the development and application of AI. These include, for example, pseudonymisation, anonymisation, encryption, differential privacy or federated learning. These technologies can prevent the identifiability of data, increase data minimisation or strengthen user control.<br></li>



<li>Early prevention of data protection breaches: AI can be used to recognise potential data protection risks at an early stage and take appropriate countermeasures. For example, algorithms can be checked to see whether they generate discriminatory or unfair results. Or warning systems can be set up to indicate suspicious activities in good time.<br></li>



<li>Promoting data protection awareness: AI can also help to raise awareness of data protection among all stakeholders and create a data protection-friendly culture. Chatbots or virtual assistants can inform users about their rights or give them tips on how to protect their privacy. Data protection knowledge can be imparted through training or games.</li>
</ul>
</li>
</ol>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">(Note: This blog post was written by an AI)</p><p>Der Beitrag <a href="https://www.dpl-consult.com/en/blog/damages-and-payments-for-pain-in-case-of-violations-against-dsgvo-2/">Künstliche Intelligenz – Risiken und Chancen für den Datenschutz</a> erschien zuerst auf <a href="https://www.dpl-consult.com/en">DPL Consult Datenschutzagentur</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Damages and compensation for pain and suffering in the event of breaches of the GDPR</title>
		<link>https://www.dpl-consult.com/en/blog/damages-and-compensation-for-pain-and-suffering-in-the-event-of-breaches-of-the-gdpr/</link>
		
		<dc:creator><![CDATA[Jörg Smid]]></dc:creator>
		<pubDate>Sun, 20 Nov 2022 18:22:24 +0000</pubDate>
				<category><![CDATA[blog]]></category>
		<category><![CDATA[startpage slider]]></category>
		<guid ispermalink="false">https://www.dpl-consult.com/?p=5425</guid>

					<description><![CDATA[<p>In the event of data protection violations, you as a company may be liable to pay damages to those affected or you may have to pay compensation for pain and suffering.</p>
<p>Der Beitrag <a href="https://www.dpl-consult.com/en/blog/damages-and-compensation-for-pain-and-suffering-in-the-event-of-breaches-of-the-gdpr/">Schadensersatz und Schmerzensgeld bei Verstößen gegen die DSGVO</a> erschien zuerst auf <a href="https://www.dpl-consult.com/en">DPL Consult Datenschutzagentur</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph">In the case of data protection violations, you as a company may be liable to pay damages to the data subjects or you may have to pay non-material damages, similar to compensation for pain and suffering. The conditions for liability are regulated by Article 82 of the GDPR. You are threatened with a monetary payment to the data subject if the data breach has caused damage to the data subject and you as a company cannot exonerate yourself from the accusation of faulty data processing.</p>



<ol class="wp-block-list" type="1">
<li><strong>For which infringements am I liable?<br></strong><br>It is sufficient for a data protection breach if your company stores, forwards, uses or otherwise processes data unlawfully. If your employee accidentally sends a message containing personal data of the data subject to the wrong person, this can lead to liability for damages.<br><br>According to a ruling by the Cologne Higher Regional Court, the violation of data subjects' rights, such as the late provision of data information, can lead to liability if it causes a psychologically stressful situation for the data subject. Other courts, however, have rejected liability for damages due to delayed data disclosure.<br><br></li>



<li><strong>For which damages am I liable?<br></strong><br>When it comes to compensation for material damage, the data subject must prove that he or she has suffered concrete damage. Such damage may be, for example, that a loan was not granted to him or her because of the data breach. If, in addition to or instead of concrete damage, the data protection breach leads to discrimination, loss of confidentiality, damage to reputation or other comparable social disadvantages, the payment of non-material damages, similar to compensation for pain and suffering, may also be considered. <br><br></li>



<li><strong>Does any "bad feeling" about the data breach already trigger liability?</strong><br><br>In its judgment of 4 May 2023 (C-300/21), the European Court of Justice (ECJ) ruled that the mere breach of the provisions of the General Data Protection Regulation is not in itself sufficient to give rise to a claim for damages. Rather, damage must have been suffered, whereby the ECJ left open what this may consist of. The concept of damage, in particular that of "non-material damage" within the meaning of Art. 82 GDPR, had to be given an autonomous and uniform Union law definition in view of the absence of any reference to the domestic law of the Member States. It follows from the recitals of the GDPR that "[t]he concept of damage ... shall be interpreted broadly in the light of the case-law of the Court of Justice in a manner fully consistent with the objectives of this Regulation". The ECJ concludes in its judgment of 4 May 2023 that the broad understanding of the term 'damage' chosen by the Union legislator would be contradicted if that term were limited to damage of a certain materiality. Contrary to some decisions of German courts, national rules which make compensation for non-material damage within the meaning of the GDPR dependent on the damage suffered by the data subject having reached a certain degree of materiality are not compatible with Union law. <br><br>As far as the amount of non-material damages is concerned, there has not been a clear classification by the courts so far. The Higher Regional Court of Cologne awarded a plaintiff a compensation claim in the amount of €500 because she was psychologically burdened with "stress and worry" about her economic position in a traffic accident case due to the delayed disclosure of data by her lawyer (judgment of 14 July 2022 - 15 U 137/21). The Regional Court of Darmstadt awarded the plaintiff damages for pain and suffering in the amount of €1000 for the accidental forwarding of job application data to a third party (judgment of 26.5.2020 - 13 O 244/19). The Regional Court of Cologne held that the one-time sending of a bank statement to an incorrect recipient was not sufficiently incriminating and dismissed the action (Regional Court of Cologne, judgment of 7.10.2020 - 28 O 71/20). </li>
</ol>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">As a rule of thumb, if concrete damage has occurred, the responsible party is liable unless he or she can exonerate him or herself. In the case of immaterial damage, the more the individual is affected by the data protection breach, the more likely it is that compensation for pain and suffering will be due.</p><p>Der Beitrag <a href="https://www.dpl-consult.com/en/blog/damages-and-compensation-for-pain-and-suffering-in-the-event-of-breaches-of-the-gdpr/">Schadensersatz und Schmerzensgeld bei Verstößen gegen die DSGVO</a> erschien zuerst auf <a href="https://www.dpl-consult.com/en">DPL Consult Datenschutzagentur</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Tasks and duties of data protection officers</title>
		<link>https://www.dpl-consult.com/en/blog/tasks-and-duties-of-data-protection-officers/</link>
		
		<dc:creator><![CDATA[Arash Ekhlasi]]></dc:creator>
		<pubDate>Tue, 21 Dec 2021 11:47:21 +0000</pubDate>
				<category><![CDATA[blog]]></category>
		<category><![CDATA[startpage slider]]></category>
		<guid ispermalink="false">https://www.dpl-consult.com/?p=4371</guid>

					<description><![CDATA[<p>The data protection officer occupies a special position as the interface between company management and data protection concerns.</p>
<p>Der Beitrag <a href="https://www.dpl-consult.com/en/blog/tasks-and-duties-of-data-protection-officers/">Aufgaben und Pflichten von Datenschutzbeauftragten</a> erschien zuerst auf <a href="https://www.dpl-consult.com/en">DPL Consult Datenschutzagentur</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph">The data protection officer occupies a special position as the interface between the company management and the company's data protection concerns.</p>



<p class="wp-block-paragraph">The designation <em>Data Protection Officer </em>is not a job title. Rather, the data protection officer is the body that monitors data protection in the company and points out deficiencies in data protection law to the company management or makes recommendations for legally compliant data protection. The tasks of the data protection officer are defined in the <strong>GDPR (Article 39) </strong>expressly regulated:</p>



<p class="wp-block-paragraph"><strong>Tasks of data protection officers at a glance</strong></p>



<ul class="wp-block-list"><li>The Data Protection Officer<strong>&nbsp;informs the company management about current data protection regulations and decisions of the supervisory authorities.</strong>&nbsp;</li><li>To the&nbsp;<strong>Central tasks of a data protection officer</strong>&nbsp;includes the long-term and regular monitoring of compliance with data protection regulations. It must be involved at an early stage in all issues relevant to data protection law.&nbsp;</li><li>The Data Protection Officer is available to data subjects and employees of the company in matters of data protection law. You can consult the data protection officer on all data protection issues.</li><li>The Data Protection Officer is the contact person&nbsp;<strong>for supervisory authorities</strong>.</li></ul><p>Der Beitrag <a href="https://www.dpl-consult.com/en/blog/tasks-and-duties-of-data-protection-officers/">Aufgaben und Pflichten von Datenschutzbeauftragten</a> erschien zuerst auf <a href="https://www.dpl-consult.com/en">DPL Consult Datenschutzagentur</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>International data protection: What do companies have to consider when transferring data internationally?</title>
		<link>https://www.dpl-consult.com/en/blog/international-data-protection-what-international-companies-need-to-consider/</link>
		
		<dc:creator><![CDATA[Arash Ekhlasi]]></dc:creator>
		<pubDate>Tue, 21 Dec 2021 11:46:48 +0000</pubDate>
				<category><![CDATA[blog]]></category>
		<category><![CDATA[startpage slider]]></category>
		<guid ispermalink="false">https://www.dpl-consult.com/?p=4369</guid>

					<description><![CDATA[<p>Processing knows no national borders: In our internationally networked world, personal data records are relevant to everyone.</p>
<p>Der Beitrag <a href="https://www.dpl-consult.com/en/blog/international-data-protection-what-international-companies-need-to-consider/">Internationaler Datenschutz: Was müssen Unternehmen beim internationalen Datentransfer beachten?</a> erschien zuerst auf <a href="https://www.dpl-consult.com/en">DPL Consult Datenschutzagentur</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph">Data processing is international: in our internationally networked world, personal data is relevant to everyone. Export and import companies that also operate outside Germany therefore need expert advice that keeps track of the complex international data world. Generally speaking, anyone who conducts business inside and outside the European Union (EU) or the European Economic Area (EEA), <strong>must ensure that the European level of data protection also applies in the so-called third countries that do not belong to the EU or the EEA</strong>. </p>



<p class="wp-block-paragraph">The General Data Protection Regulation allows the transfer of personal data to third countries under certain conditions. Thus, a data transfer to so-called safe third countries is permitted. In particular, these are countries for which the European Commission has adopted a so-called adequacy decision. These countries must have legal regulations that guarantee a level of data protection equivalent to that in the EU.</p>



<p class="wp-block-paragraph"><strong>Which third countries are considered safe?</strong></p>



<p class="wp-block-paragraph">For the following third countries, for example, the EU Commission has adopted adequacy decisions so that data transfers to these countries are considered secure:</p>



<ul class="wp-block-list">
<li>Argentina</li>



<li>Canada (commercial organisations only)</li>



<li>Israel</li>



<li>New Zealand</li>



<li>Switzerland</li>



<li>South Korea</li>



<li>Japan</li>



<li>United Kingdom</li>



<li>USA (to certified companies)</li>
</ul>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"><strong>A transfer of personal data to third countries without an adequacy decision, on the other hand, is only permissible under further conditions. </strong></p>



<p class="wp-block-paragraph">This includes the prior precise analysis of the level of data protection in the respective third country as well as the conclusion of data protection contracts with the data recipients in the third country to ensure that the protection of the personal data transferred is guaranteed. The European Commission has provided so-called standard contractual clauses for this purpose. We advise you on the determination of the level of data protection in the third country and on the drafting of the standard contractual clauses that enable you to transfer personal data to third countries without an adequacy decision. </p><p>Der Beitrag <a href="https://www.dpl-consult.com/en/blog/international-data-protection-what-international-companies-need-to-consider/">Internationaler Datenschutz: Was müssen Unternehmen beim internationalen Datentransfer beachten?</a> erschien zuerst auf <a href="https://www.dpl-consult.com/en">DPL Consult Datenschutzagentur</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Data protection breakdown in the company - how can entrepreneurs protect themselves?</title>
		<link>https://www.dpl-consult.com/en/blog/data-protection-breach-in-the-company-how-can-entrepreneurs-protect-themselves/</link>
		
		<dc:creator><![CDATA[Arash Ekhlasi]]></dc:creator>
		<pubDate>Tue, 21 Dec 2021 11:46:06 +0000</pubDate>
				<category><![CDATA[blog]]></category>
		<category><![CDATA[startpage slider]]></category>
		<guid ispermalink="false">https://www.dpl-consult.com/?p=4367</guid>

					<description><![CDATA[<p>Companies without sufficient IT protection can easily become the target of hacker attacks.</p>
<p>Der Beitrag <a href="https://www.dpl-consult.com/en/blog/data-protection-breach-in-the-company-how-can-entrepreneurs-protect-themselves/">Datenschutzpanne im Unternehmen – wie können Unternehmer sich schützen?</a> erschien zuerst auf <a href="https://www.dpl-consult.com/en">DPL Consult Datenschutzagentur</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph">Data protection breaches do not always result from negligence or the unlawful disclosure of data: Companies without sufficient IT protection can easily become the target of hacker attacks. Such<strong>&nbsp;Data mishaps can be expensive</strong>if they are associated with a risk for the data subjects and are not immediately reported to the supervisory authority responsible for data protection. For this reason, companies should always be advised by professional IT specialists and data protection officers in order to avoid unknowing breaches of the data protection regulation and the associated sanctions.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Duty of cooperation of responsible persons</strong></p>



<p class="wp-block-paragraph">If personal data is stolen or destroyed, this must be reported to the competent supervisory authority without delay, at the latest within 72 hours (Article 33 (2) of the GDPR). As the data protection officer, we advise you on how to write the report and on the measures to be taken. </p>



<p class="wp-block-paragraph"><strong>Damage to reputation in the event of data protection violations</strong></p>



<ul class="wp-block-list"><li>The loss of customer data can lead to considerable damage, e.g. in the case of identity theft.&nbsp;<strong>Claims for damages</strong>&nbsp;of the customers are possible (Art. 82 GDPR).</li><li>Far more devastating can be the damage to reputation after&nbsp;<strong>Disclosure of a covered-up data breach&nbsp;</strong>fail. Customers lose trust in companies if the whereabouts of their data are not openly communicated.</li><li>Basically&nbsp;<strong>no security system is 100 % protected against hacker attacks.</strong>&nbsp;If sensitive data is misused by hackers, this will affect the company's reputation even after it has been properly reported.</li><li>This makes it all the more important for a positive image of the company to communicate to the outside world that all possibilities are being exhausted in the IT and data protection area,&nbsp;<strong>to protect customer data and track breaches by hackers.</strong></li></ul>



<p class="wp-block-paragraph"><strong>Do customers have to be informed about a data breach?</strong></p>



<p class="wp-block-paragraph">If, due to data loss, a <strong>Particularly high risk for the persons concerned</strong> arises, the aggrieved parties must be informed of the data breach according to Art. 34 GDPR.</p>



<p class="wp-block-paragraph"><strong>Examples of sensitive personal customer data</strong></p>



<ul class="wp-block-list"><li>Data on the state of health</li><li>Data on ethnic origin</li><li>Data on criminal convictions</li><li>Authentication data for e-mail box etc.</li></ul>



<p class="wp-block-paragraph"><strong>How do I report a data breach by hackers?</strong></p>



<p class="wp-block-paragraph">Data protection breaches must be reported to the competent GDPR supervisory authority in Hamburg or in the federal state where the breach occurred. Most authorities provide online forms for breach notifications. Pursuant to Art. 33 (3) of the GDPR, the following must be reported <strong>at least the following information</strong> be made:</p>



<ul class="wp-block-list"><li>How many people are affected?</li><li>What category of data is involved?</li><li>Contact details of the data protection officer</li><li>What consequences could the data loss have for your customers?</li><li>What measures have been taken to address the problem?</li></ul>



<p class="wp-block-paragraph"><strong>Do not do without professional support</strong></p>



<p class="wp-block-paragraph">Companies that work with sensitive customer data cannot do without IT partners and data protection officers. At the latest at the first sign of a data breach, entrepreneurs should urgently consult an expert. The reputation of companies is only as good as their IT protection!</p><p>Der Beitrag <a href="https://www.dpl-consult.com/en/blog/data-protection-breach-in-the-company-how-can-entrepreneurs-protect-themselves/">Datenschutzpanne im Unternehmen – wie können Unternehmer sich schützen?</a> erschien zuerst auf <a href="https://www.dpl-consult.com/en">DPL Consult Datenschutzagentur</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Tracking cookies pros and cons: blessing or curse for entrepreneurs?</title>
		<link>https://www.dpl-consult.com/en/blog/tracking-cookies-advantages-and-disadvantages-blessing-or-curse-for-entrepreneurs/</link>
		
		<dc:creator><![CDATA[Arash Ekhlasi]]></dc:creator>
		<pubDate>Mon, 29 Nov 2021 15:10:55 +0000</pubDate>
				<category><![CDATA[blog]]></category>
		<category><![CDATA[startpage slider]]></category>
		<guid ispermalink="false">https://www.dpl-consult.com/?p=1119</guid>

					<description><![CDATA[<p>Today, no serious website can do without cookies. The server log files are automatically generated by the website server or the user's browser and stored there.</p>
<p>Der Beitrag <a href="https://www.dpl-consult.com/en/blog/tracking-cookies-advantages-and-disadvantages-blessing-or-curse-for-entrepreneurs/">Tracking-Cookies Vor- und Nachteile: Segen oder Fluch für Unternehmer?</a> erschien zuerst auf <a href="https://www.dpl-consult.com/en">DPL Consult Datenschutzagentur</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph">Today, hardly any website can do without cookies. The server log files are automatically generated by the website server or the user's browser and stored there. So-called cookies are critical in terms of data protection law.&nbsp;<strong>Third-party tracking cookies</strong>which not only inform website operators about user behaviour on their own website, but also provide information about the entire online behaviour of customers. We advise our clients on the proper embedding of cookies on their websites.</p>



<p class="wp-block-paragraph"><strong>What information can be collected via tracking cookies?</strong></p>



<ul class="wp-block-list">
<li>Third-party providers use tracking cookies to determine which websites users visit and how they behave there.</li>



<li>These information profiles are&nbsp;<strong>useful for shop providers</strong>In this way, companies define their target group and pursue their interests.</li>



<li>The data serve as&nbsp;<strong>Basis for personalised advertising</strong>, which in turn can generate further sales and revenue.</li>
</ul>



<p class="wp-block-paragraph"><strong>Data collectors in everyday life</strong></p>



<p class="wp-block-paragraph">The use of tracking cookies by third parties is widespread on the modern internet. For example <a href="https://www.heise.de/newsticker/meldung/Websites-hebeln-Anti-Cookie-Massnahmen-aus-1288914.html">97 % of all commercial websites</a> use Google cookies, for example.  If personal data is collected in the process, users must be informed of this (Article 13 GDPR). In addition, the Act on Data Protection and the Protection of Privacy in Telecommunications and Digital Services (Telecommunications Digital Services Data Protection Act - TDDDG) stipulates that<strong> Users must give their consent before technically unnecessary cookies are set. </strong>We check your privacy policy for completeness and accuracy.</p>



<p class="wp-block-paragraph"><strong>Conclusion: What you should bear in mind when setting tracking cookies</strong></p>



<p class="wp-block-paragraph">The embedding and use of tracking cookies is permissible if the user has consented and is informed about the collection of personal data in accordance with Article 13 of the GDPR. Even with "simple" cookies, this can involve quite a bit of effort: In order to&nbsp;<strong>Always keep your privacy policy up to date on your website</strong>the information on the cookies used must be correct. We support our customers in this.</p><p>Der Beitrag <a href="https://www.dpl-consult.com/en/blog/tracking-cookies-advantages-and-disadvantages-blessing-or-curse-for-entrepreneurs/">Tracking-Cookies Vor- und Nachteile: Segen oder Fluch für Unternehmer?</a> erschien zuerst auf <a href="https://www.dpl-consult.com/en">DPL Consult Datenschutzagentur</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>