When people visit an online store, they usually think about products, prices, and shipping costs. However, a lot more is happening behind the scenes: Websites load fonts, analytics tools, payment services, and other technical features from third-party providers. In the process, information about the visitor may be sent to third-party servers.
A case that ultimately reached the Federal Court of Justice (BGH) centered precisely on this type of data transfer. The central question may sound technical at first, but it has practical implications for a great many Internet users: What options does an individual have if they wish to prevent their personal data from being transferred to third parties in the future?
The Federal Court of Justice (BGH) has provided an important clarification on this point: The General Data Protection Regulation (GDPR) is not necessarily the final word. Under certain conditions, the general rules of German law may also be applied.
Online shopping and data that keeps moving in the background
It all started with an everyday occurrence. A man ordered some items from an online store. However, he was bothered by the website's technical design.
The online store used features provided by third-party vendors. As a result, certain content was not loaded exclusively from the store operator's server. Instead, the customer's browser communicated with servers operated by other companies.
In the process, the user's IP address, among other things, may be transmitted. The customer believed that his IP address and other usage data were being improperly disclosed to third parties in this manner.
He therefore wanted to ensure that the company would refrain from disclosing his data in this manner without his consent in the future.
He was initially unsuccessful in his efforts before the Regional Court and subsequently before the Higher Regional Court in Frankfurt am Main. The case was eventually referred to the Federal Court of Justice.
What exactly is the GDPR?
Before discussing the Federal Court of Justice’s ruling, it is worth taking a brief look at the basis of the dispute. The General Data Protection Regulation—GDPR for short—is the central set of rules governing the handling of personal data in the European Union.
Simply put, personal data is information that can be linked to a specific person or that can be used to identify a person. This includes obvious details such as name, address, or email address. However, technical information may also fall under this category. For example, an IP address may be considered personal data.
Among other things, the GDPR specifies the conditions under which companies may collect, store, use, or disclose such data. At the same time, it grants data subjects various rights. For example, they may request information about what data is stored about them, demand its deletion under certain conditions, or object to unlawful processing.
Since it went into effect in 2018, the GDPR has shaped data protection in Europe. However, this does not automatically mean that every dispute involving personal data is resolved exclusively under this set of rules. This is precisely where the recent decision by the Federal Court of Justice (BGH) becomes interesting.
The GDPR is not the only possible legal basis
Behind this procedure lies a fundamental question: Does the GDPR regulate all of a data subject’s rights so comprehensively that there is no longer any room for German regulations?
The Federal Court of Justice answers this question by making an important distinction.
According to the decision of the Sixth Civil Division dated June 21, 2026 (Case No. VI ZR 144/23), the GDPR does not provide a comprehensive and exhaustive framework for claims intended to prevent data transfers in the future.
This is relevant because the European Court of Justice had previously specified the requirements for such a claim directly under the GDPR. According to its decision of September 4, 2025 (Case No. C-655/23), a request of this kind under the GDPR may be contingent on the data subject simultaneously requesting the erasure of their data.
This raised another question: What happens if the conditions for a claim directly under the GDPR are not met? Is the data subject then automatically left with no other options?
According to the Federal Court of Justice's ruling, the answer is: not necessarily.
German law may open a second door
The Federal Court of Justice makes it clear that, in addition to the GDPR, provisions of the German Civil Code may continue to apply.
This pertains in particular to Sections 823 and 1004 of the German Civil Code (BGB). Put simply, under certain conditions, these provisions can be used to stop unlawful interference and prevent it from recurring.
For consumers, the specific number assigned to a section of the law is less important. What matters far more is the underlying principle: Just because a claim cannot be enforced directly under the GDPR does not mean that every possibility of preventing future data transfers has been exhausted.
German law can therefore provide an additional basis.
However, the Federal Court of Justice (BGH) has not definitively ruled that the plaintiff actually has a claim against the online store in this specific case. The case is being remanded to the Higher Regional Court of Frankfurt am Main, where it must now be determined whether the requirements under German law are in fact met.
This is an important distinction: The Federal Court of Justice did not simply rule in the plaintiff’s favor. It made it clear that his claim must be examined from another legal perspective.
Why This Decision Is Important for Website Owners
The decision addresses an issue that goes far beyond a single online store.
Modern websites often consist of numerous external services. Analytics tools, videos, maps, fonts, payment features, and other services may be integrated in such a way that connections to other servers are established when a page is loaded.
Companies should therefore not only pay attention to what data they store themselves. Equally important is the question of what information is automatically transmitted to other providers as a result of their website’s technical design.
The Federal Court of Justice (BGH) ruling highlights something even more fundamental: A data protection review does not necessarily end with the GDPR. Even if a specific prohibition cannot be directly derived from European data protection regulations, provisions of German law may still be relevant.
This places greater demands on operators of digital services. Integrating an external service into a website can be done quickly from a technical standpoint. However, the question of what data is transmitted in the process and on what basis this occurs should naturally be part of the planning as well.
More technology also means more responsibility
This case illustrates quite clearly how far the Internet has come from the concept of a simple website. A user sees an online store. Technically speaking, their browser may be communicating with several other companies at the same time in the background. For the average visitor, it’s almost impossible to know what information is being sent where.
An important point of the ruling is that the Federal Court of Justice (BGH) does not artificially limit the protection of personal data to a single set of rules. At the same time, this should not give the impression that any connection to a third-party server is automatically unlawful. The decisive factors remain what data is transmitted, why it is transmitted, and whether the transmission is legally permissible.
For companies, the message is quite clear: Data protection shouldn’t only become an issue once a warning letter or lawsuit is on the table. Anyone who integrates external services into a website should know what data these services receive and why. “Our plugin does that automatically” may be a valid technical explanation. But in the long run, that’s not enough to ensure the responsible handling of customer data.




