Data subjects versus Supervisory Authority – Court Ruling (Germany, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
A court ruled that a district shared personal data of individuals without proper authorization during administrative proceedings. This decision highlights the importance of protecting personal information in legal matters. Organizations must be cautious about sharing data with third parties.
What happened
The district shared personal data of individuals involved in unauthorized riverbank works with various parties.
Who was affected
The individuals whose personal data was shared without their consent were affected.
What the authority found
The supervisory authority found no clear GDPR violation, but the case raised concerns about unauthorized data sharing.
Why this matters
This case serves as a warning for organizations to handle personal data carefully, especially in legal contexts. Companies should ensure they have proper consent before sharing personal information.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
A district (the controller), acting as the lower water authority, initiated administrative proceedings after identifying unauthorised riverbank works and a private jetty on two riverside properties. One property belonged to a water utility company, while the other belonged to a municipality and was leased to the data subjects. During those proceedings, the controller shared the data subjects' personal data with various participants, including the owners of the affected properties, other public authorities and a lawyer who claimed to represent the data subjects. The data subjects lodged a complaint with the competent supervisory authority (LDI NRW), alleging that the controller had unlawfully processed and disclosed their personal data. They argued that their personal data had been shared with uninvolved third parties, that the controller had communicated with a lawyer whom they had not authorised, recorded a telephone conversation with an unknown person, and transmitted personal data by unencrypted email. The controller's data protection officer addressed each allegation and provided additional factual information concerning the disputed processing operations. The DPA initially informed the data subjects that no GDPR infringement was apparent, invited them to provide any additional factual information, and explained that it would obtain extracts from the controller's administrative file if there were concrete indications that it contained relevant facts not already available. The data subjects did not identify any additional facts and instead reiterated their legal position that the controller had breached its GDPR accountability obligations. The DPA rejected the complaint, concluding that no GDPR infringement could be established. The data subjects then brought an action before the Verwaltungsgericht Düsseldorf (Administrative Court Düsseldorf), seeking a fresh decision on their complaint on the basis that the DPA had failed to adequately investigate the complaint
Outcome
Court Ruling
A ruling by a national court on a data-protection matter.
Related Cases (0)
No other cases found for Data subjects versus Supervisory Authority in DE
This is the only recorded case for this entity in this jurisdiction.
Details
About this data
Cite as: Cookie Fines. Data subjects versus Supervisory Authority - Germany (2026). Retrieved from cookiefines.eu
Last updated: