Court case M 32 E 26.3990 – Court Ruling (Germany, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
A German court ruled on a case involving a manuscript author who wanted access to their personal data held by a university. The court's decision matters because it clarifies who is responsible for data requests in publishing processes. This ruling can help authors understand their rights regarding personal data access.
What happened
The court addressed a lawsuit where an author sought access to their personal data from a university involved in the publishing process.
Who was affected
The author of the manuscript, who wanted to know how their personal data was handled, was affected.
What the authority found
The court found that the university was not the responsible party for the data request, as it did not qualify as the controller under GDPR.
Why this matters
This ruling highlights the complexities of data access requests in collaborative publishing environments. It informs authors about the importance of identifying the right entities to contact for data access.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
National Law Articles
The author of a manuscript (the data subject) submitted their text to an editorial office of a quarterly journal for review in November 2025. The journal was published by a private publishing company and overseen by several co-editors, including two professors at a Bavarian university (the alleged controller). The data subject received an email pointing out inconsistencies in the external review process in April 2026. On 7 May, the data subject submitted an access request under Article 15 GDPR to the university and requested a complete copy of their personal data processed in connection with the publishing process. The work email accounts of the two aforementioned university professors were explicitly identified as storage locations in the access request. The university rejected the access request in a decision dated 20 May 2026: it argued that it was not the controller within the meaning of Article 4(7) GDPR. According to the university, only the co-editors of the journal and the publishing company could be classified as controllers with regard to the storage of personal data in connection with publishing activities. On 26 May, the data subject filed a both a lawsuit and an application for a preliminary injunction before the Administrative Court Munich. In the application, they requested a preliminary injunction ordering the university to retain all the data subject's personal data until the main proceedings regarding the right to access would be legally concluded. As the data subject sought to secure their right of access with the application, they argued that their right to a preliminary injunction arose from Articles 5(2), 15, and 32 GDPR. The court rejected the data subject's application for a preliminary injunction: the requirements laid down in [https://www.gesetze-im-internet.de/vwgo/ § 123(1)(1) of the German Code of Administrative Court Procedure (VwGO)] were not fulfilled. First, the court held that the role of the university in the processing at issu
Outcome
Court Ruling
A ruling by a national court on a data-protection matter.
Related Cases (0)
No other cases found for Court case M 32 E 26.3990 in DE
This is the only recorded case for this entity in this jurisdiction.
Details
About this data
Cite as: Cookie Fines. Court case M 32 E 26.3990 - Germany (2026). Retrieved from cookiefines.eu
Last updated: