Court case 19 O 147/22 – Court Ruling (Germany, 2023)

Court Ruling
DPA LGBielefeld10 March 2023Germany
final
Court Ruling

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

A German court ruled that Facebook did not violate privacy rules when a user's phone number, which they chose to make public, was scraped and used for spam. The court found that Facebook provided options to hide the number, so it wasn't responsible for the misuse. This case highlights the importance of understanding privacy settings on social media platforms.

What happened

A user's phone number was scraped from Facebook and used for spam, but the court found Facebook not responsible.

Who was affected

Facebook users who make their phone numbers publicly visible on their profiles.

What the authority found

The court decided Facebook did not breach its duty to protect personal data because users had the option to hide their phone numbers.

Why this matters

This ruling emphasizes the responsibility of users to manage their privacy settings on social media. It suggests that companies may not be held liable if users choose to make their information public.

GDPR Articles Cited

Art. 24 GDPR
Art. 32 GDPR
Art. 33 GDPR
Art. 82 GDPR
Art. 25(2) GDPR

National Law Articles

§ 1004 BGB
§ 823 BGB
Decision AuthorityLG Bielefeld
Full Legal Summary
Detailed

The data subject was a computer scientist and Facebook user. While using Facebook's social media services, the data subject provided several mandatory personal data, including their first name, last name and sex.. These data points, including the system generated "Facebook ID", were publicly visible by default on the user profile. In addition the data subject added his mobile phone number. The mobile phone number was also visible by default but the user could change the visibility in the settings. The data subject limited the visibility to the "target group search“ setting, but left the searchability option for his mobile phone number visible. In 2021, unknown “third parties” published data, that has been scraped from the website in 2019. The data subject lamented that since then he received anonymous calls and spam emails. This entailed negative psychological consequences for him. Thus, the data subject asked for €500 in non-material damages under Article 82 GDPR. The controller replied that data scraping - which is not hacking - does not entail a violation of the GDPR by the controller, as no mandatory security measures where circumvented and the plaintiff made an informed decision to voluntarily share their phone number on the site. The court rejected the request for damages under Article 82 GDPR. The court held that there was no breach of duty by the controller that could trigger damages. The publication of the mobile phone number wasn‘t mandatory and the data subject had the (unused) option to hide the phone number on their profile. The court was of the opinion, that the controller did not breach its duty to adequately protect the personal data of users in accordance with Article 32 GDPR. The controller was not obliged to take protective measures to prevent the collection of already publicly accessible information. The controller also did not violate the principle of "privacy by default" enshrined in Articles 24 and 25(2) GDPR. It was undisputed that only th

Outcome

Court Ruling

A ruling by a national court on a data-protection matter.

Related Cases (0)

No other cases found for Court case 19 O 147/22 in DE

This is the only recorded case for this entity in this jurisdiction.

Details

Ruling Date

10 March 2023

Authority

DPA LGBielefeld

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Court case 19 O 147/22 - Germany (2023). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: