Customer (Data subject) – Court Ruling (Germany, 2024)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
A court ruled on a case involving a customer and their health insurance company about access to personal data. The court decided that the customer could request specific information about their insurance contributions, but not all documents they wanted. This is significant because it clarifies what types of documents can be requested under data access rights.
What happened
The court ruled that the customer could access specific personal data about their insurance contributions.
Who was affected
The customer who sought access to their personal data from the health insurance company.
What the authority found
The court confirmed that only specific documents related to the customer’s insurance could be requested, limiting the scope of access rights.
Why this matters
This ruling helps define the limits of data access requests, guiding both customers and companies on what information can be requested. Businesses should be clear about the data they provide in response to access requests.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
The data subject was in a dispute with a health insurance company (the controller) about premium adjustment issues in their insurance plan, and associated missed explanation obligations. The data subject repeatedly used their right to access information via Article 15 GDPR to obtain data about the contribution history of the insurance contract. The data subject's original access request sought extensive documentation (all correspondence and attachments). The controller refused such frequent and extensive requests, citing Article 12(5) GDPR, which allows a controller to refuse or charge a reasonable fee for excessive or repetitive requests. The court confirmed that only the personal data of the data subject falls within the scope of Article 15 GDPR. The mere fact that some documents like formal letters or appended documents in insurance correspondence exist does not mean the entire document collection is personal data if only parts of them relate to the data subject. The court explicitly stated that an access request may be repeated and the existence of prior disclosures does not extinguish the right to access further relevant personal data, so a controller cannot claim that a prior fulfillment of a request automatically precludes subsequent valid requests under Article 15 GDPR. The court further held that the broad set of documents originally requested by the data subject was too general and did not meet this requirement. Only specific documents about the data subject’s insurance relationship were treated as identifiable personal information. The court granted the data subject a more narrowly tailored access right to certain personal data, which requires the controller to provide a copy of specific personal information about the data subject’s contract for the years 2017 to 2019, including the dates and amounts of old and new insurance contributions, the dates of insurance plan changes and the dates when the insurance plans were terminated.
Outcome
Court Ruling
A ruling by a national court on a data-protection matter.
Related Cases (0)
No other cases found for Customer (Data subject) in DE
This is the only recorded case for this entity in this jurisdiction.
Details
About this data
Cite as: Cookie Fines. Customer (Data subject) - Germany (2024). Retrieved from cookiefines.eu
Last updated: