Court case S 5 SF 65/24 DS – Court Ruling (Germany, 2026)

Court Ruling
DPA10 June 2026Germany
final
Court Ruling

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

A court in Germany ruled on a case involving a child's data that was compromised during a cyberattack. The attack happened due to a security flaw in software used by a health insurance provider. This case highlights the importance of data security for companies handling sensitive information, especially when using third-party services.

What happened

A child's personal data was compromised during a cyberattack on an IT service provider used by a health insurance company.

Who was affected

The child, born in 2018, whose data was managed by a statutory health insurance provider and affected by the cyberattack.

What the authority found

The court found that the health insurance provider had established proper data processing agreements and security measures, thus not violating GDPR despite the data breach.

Why this matters

This ruling emphasizes the need for companies to have strong data protection practices, especially when relying on third-party service providers. It serves as a reminder for businesses to regularly assess their cybersecurity measures.

GDPR Articles Cited

AI-verified

Art. 26(GDPR)
Art. 28(GDPR)
Art. 4(7) GDPR
Art. 4(8) GDPR
Art. 5(1)(f) GDPR
Art. 85(GDPR)
Art. 24(1) GDPR
Art. 32(1) GDPR
Art. 32(2) GDPR
Art. 4(10) GDPR
Art. 4(12) GDPR
Art. 82(1) GDPR
Art. 82(2) GDPR
View original scraped data
Art. 4(7) GDPR
Art. 4(8) GDPR
Art. 4(10) GDPR
Art. 4(12) GDPR
Art. 5(1)(f) GDPR
Art. 24(1) GDPR
Art. 26(GDPR)
Art. 28(GDPR)
Art. 32(1) GDPR
Art. 32(2) GDPR
Art. 82(1) GDPR
Art. 82(2) GDPR
Art. 85(GDPR)

Original data from scraper before AI verification against source document.

National Law Articles

AI-identified

§ 183 SGG
§ 81b(1) SGB X
Decision AuthoritySG Nürnberg
Source verified 17 July 2026
articles corrected
national law identified
authority corrected
Full Legal Summary
Detailed

The data subject (a child born in 2018), represented by her parents, was insured with the controller (a statutory health insurance provider) and participated in its digital bonus programme. The bonus programme was managed via an app. To handle the information technology operations of this programme, the controller hired the processor (an IT service provider), establishing a data processing agreement under Article 28 GDPR alongside specific information security guidelines. To provide these services, the processor utilised "MOVEit Transfer," a market-leading file transfer software developed by Progress Software Corp. On 31 May 2023, the software developer publicly announced a critical, previously unknown "zero-day" vulnerability in the software (later assigned CVE-2023-34362). At that exact moment, no security patch was available. On the very same day, 31 May 2023, the processor – alongside thousands of other companies worldwide – became the victim of a global cyberattack carried out by the hacker group "Clop." The hackers exploited this zero-day vulnerability to install a "web-shell" backdoor (typically named human2.aspx), bypassing authentication to exfiltrate database records. The compromised data included the data subject's first and last name, health insurance number, bonus points balance, and a bank account number (IBAN) belonging to her mother. No medical, health, or social security data was exfiltrated. On 1 June 2023, the developer released a security patch, which the processor installed immediately. On 2 June 2023, the German Federal Office for Information Security (BSI) issued a formal IT security warning (No. 2023-240133-1100, Version 1.1). The BSI classified the IT threat level as "3 / Orange" (business-critical), confirming active exploitation with data exfiltration. The BSI recommended immediately blocking all HTTP and HTTPS traffic to MOVEit environments, checking for specific Indicators of Compromise (IoCs) in the web server directories, and applying

Outcome

Court Ruling

A ruling by a national court on a data-protection matter.

Related Cases (0)

No other cases found for Court case S 5 SF 65/24 DS in DE

This is the only recorded case for this entity in this jurisdiction.

Details

Ruling Date

10 June 2026

Authority

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Court case S 5 SF 65/24 DS - Germany (2026). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: