Artwork

Innehåll tillhandahållet av Eli Atanasov. Allt poddinnehåll inklusive avsnitt, grafik och podcastbeskrivningar laddas upp och tillhandahålls direkt av Eli Atanasov eller deras podcastplattformspartner. Om du tror att någon använder ditt upphovsrättsskyddade verk utan din tillåtelse kan du följa processen som beskrivs här https://sv.player.fm/legal.
Player FM - Podcast-app
Gå offline med appen Player FM !

E03: W48 BGH Rules on Facebook Data Breach Case: Loss of Data Control Qualifies as GDPR Damage

17:32
 
Dela
 

Manage episode 452133840 series 3613966
Innehåll tillhandahållet av Eli Atanasov. Allt poddinnehåll inklusive avsnitt, grafik och podcastbeskrivningar laddas upp och tillhandahålls direkt av Eli Atanasov eller deras podcastplattformspartner. Om du tror att någon använder ditt upphovsrättsskyddade verk utan din tillåtelse kan du följa processen som beskrivs här https://sv.player.fm/legal.

On November 18, 2024, the German Federal Court of Justice (BGH) ruled on a case related to the 2021 Facebook data scraping incident, where personal data of 533 million users was exposed. The plaintiff claimed Facebook’s weak security measures caused a loss of control over their data and sought compensation under Article 82(1) GDPR.

Initially, the Regional Court of Bonn awarded €250 in damages to the plaintiff. However, the Higher Regional Court of Cologne overturned the decision, dismissing the case due to insufficient proof of harm. Upon appeal, the BGH partially reversed the Cologne court’s decision, stating that even a temporary loss of control over personal data constitutes immaterial damage under GDPR, without requiring proof of emotional distress or misuse of the data.

The court emphasized that Facebook’s default privacy setting, which allowed profiles to be searchable by phone numbers, likely breached GDPR principles of data minimization and data protection by design and default. The BGH instructed the appellate court to reassess the case, examining whether the plaintiff had been adequately informed about the default settings and whether valid consent was given for the data processing.

The BGH also provided guidance on assessing non-material damages under GDPR, suggesting that €100 could be a reasonable amount for cases involving loss of data control without further harm. However, higher compensation could be justified if psychological or other impacts are demonstrated.

The case was sent back to the Higher Regional Court of Cologne for further proceedings in line with these findings.

See the decision in german here.

Find all resources from this episode at: https://conformally.com/privacy-navigator
Learn more about Conformally at https://conformally.com

  continue reading

7 episoder

Artwork
iconDela
 
Manage episode 452133840 series 3613966
Innehåll tillhandahållet av Eli Atanasov. Allt poddinnehåll inklusive avsnitt, grafik och podcastbeskrivningar laddas upp och tillhandahålls direkt av Eli Atanasov eller deras podcastplattformspartner. Om du tror att någon använder ditt upphovsrättsskyddade verk utan din tillåtelse kan du följa processen som beskrivs här https://sv.player.fm/legal.

On November 18, 2024, the German Federal Court of Justice (BGH) ruled on a case related to the 2021 Facebook data scraping incident, where personal data of 533 million users was exposed. The plaintiff claimed Facebook’s weak security measures caused a loss of control over their data and sought compensation under Article 82(1) GDPR.

Initially, the Regional Court of Bonn awarded €250 in damages to the plaintiff. However, the Higher Regional Court of Cologne overturned the decision, dismissing the case due to insufficient proof of harm. Upon appeal, the BGH partially reversed the Cologne court’s decision, stating that even a temporary loss of control over personal data constitutes immaterial damage under GDPR, without requiring proof of emotional distress or misuse of the data.

The court emphasized that Facebook’s default privacy setting, which allowed profiles to be searchable by phone numbers, likely breached GDPR principles of data minimization and data protection by design and default. The BGH instructed the appellate court to reassess the case, examining whether the plaintiff had been adequately informed about the default settings and whether valid consent was given for the data processing.

The BGH also provided guidance on assessing non-material damages under GDPR, suggesting that €100 could be a reasonable amount for cases involving loss of data control without further harm. However, higher compensation could be justified if psychological or other impacts are demonstrated.

The case was sent back to the Higher Regional Court of Cologne for further proceedings in line with these findings.

See the decision in german here.

Find all resources from this episode at: https://conformally.com/privacy-navigator
Learn more about Conformally at https://conformally.com

  continue reading

7 episoder

Alla avsnitt

×
 
Loading …

Välkommen till Player FM

Player FM scannar webben för högkvalitativa podcasts för dig att njuta av nu direkt. Den är den bästa podcast-appen och den fungerar med Android, Iphone och webben. Bli medlem för att synka prenumerationer mellan enheter.

 

Snabbguide

Lyssna på det här programmet medan du utforskar
Spela