Data Protection Pulse – 09/26/14: Everything You Need to Know Right Now
The most important data protection decisions and developments from the past two weeks.
I. Judgments
Federal Court of Justice: Photos in AI Datasets—Where Does the Freedom to Train End?
The First Civil Senate of the Federal Court of Justice (BGH) is deciding whether the reproduction of a photograph in the creation of an AI training dataset infringes on the copyright of the plaintiff photographer. The defendant is a nonprofit association that provides a publicly available, free dataset consisting of image-text pairs with hyperlinks to images accessible on the Internet. The lower courts dismissed the complaint. At the heart of the matter is the text and data mining exception under Section 44b of the German Copyright Act (UrhG). Although this is a purely copyright-related proceeding, the decision has far-reaching implications for AI training datasets containing images of individuals and, consequently, for questions of lawfulness under Article 6(1)(f) of the General Data Protection Regulation (GDPR).
- Landmark ruling on the scope of the text- and data-mining exception as it applies to AI training data.
- For AI developers using publicly available image data: Document rights holders’ restrictions on use in a machine-readable format (Section 44b(3) of the German Copyright Act (UrhG)) and monitor the outcome of legal proceedings.
Düsseldorf Administrative Court: No Proof Without a Confirmation Email – Double Opt-In Fails in Court
Source: Düsseldorf Administrative Court, 29th Chamber, Judgment of July 27, 2026, 29 K 9714/24
An online marketing company sent promotional emails, citing consent obtained via a double opt-in process. When the complainant disputed the consent, the company was only able to provide the email address, IP address, and timestamp. The Düsseldorf Administrative Court ruled that this information is insufficient to prove consent under Article 7 of the GDPR. There is no necessary connection between an IP address and an email address; an IP address only leads to the owner of the connection, not to the person using the device. If the controller cannot prove the lawfulness of the processing, the consent is deemed not to have been validly given. The court upheld the warning pursuant to Article 58(2)(b) of the GDPR.
- For email marketing: An IP address and timestamp from a double-opt-in process are not sufficient; complete, personalized documentation—including a confirmation email—is required.
- Risk of fines under Article 83(5)(a) of the GDPR; particularly relevant in the ongoing CEF 2026 regarding transparency obligations.
Munich Regional Court I: The NEINhorn Says No – Publisher Sues OpenAI
Source: Carlsen Verlag, press release dated August 19, 2026
On August 19, 2026, Carlsen Verlag, together with author Marc-Uwe Kling and illustrator Astrid Henn, filed a lawsuit against OpenAI Ireland Ltd., the operator of ChatGPT in Europe, in the Munich I Regional Court. The allegation: ChatGPT generates text and illustrations in response to simple queries that closely resemble the children’s book series “Das NEINhorn,” in some cases including a generated copyright notice with the authors’ names and a fake ISBN. The plaintiffs allege unlawful use of the works for training purposes and “memorization” of the works that remains within the model, and view this as unauthorized reproduction under Section 16 of the German Copyright Act (UrhG). They are seeking an injunction and damages.
- This is the latest in a growing number of lawsuits against AI providers for reproducing protected content, similar to the Federal Court of Justice (BGH) case I ZR 281/25 concerning AI training datasets.
- Relevant for clients in the publishing and media sectors: A successful lawsuit could limit the TDM exception for commercial AI providers
II. Fines and Government Agencies
CNIL / Autoriteit Persoonsgegevens (France/Netherlands): Lack of Human Review—Uber Fined Again
Sources: Autoriteit Persoonsgegevens, press release dated August 21, 2026; CNIL, press release dated August 24, 2026
The Dutch Autoriteit Persoonsgegevens was responsible for the investigation as the lead authority based on Uber’s headquarters in the Netherlands; however, the decision was issued as part of the consistency procedure under Article 60 of the GDPR in close coordination with the CNIL, which initiated the matter in 2020 following a complaint from 171 French drivers. The complaint alleged that, between 2018 and 2022, Uber temporarily or permanently deactivated driver accounts in cases of suspected fraud involving low customer ratings without conducting a human review of each individual case. This was classified as a fully automated individual decision within the meaning of Article 22 of the GDPR, for which there was no valid legal basis.
- This is already the third penalty in this series of proceedings, following a 10 million euro fine (December 11, 2023, regarding disclosure obligations) and a 290 million euro fine (July 22, 2024, regarding transfers to third countries); it demonstrates a pattern of escalating penalties in the event of continued violations by the same company.
- Significant risk of fines under Article 83(5)(b) of the GDPR for platform operators that use automated blocking or deactivation mechanisms without a documented option for human intervention.
ICO (United Kingdom): 758,000 calls made without consent – Fine imposed on Elderly Aids Ltd
Source: ICO, press release dated August 27, 2026
The ICO imposed a fine of 190,000 pounds on Elderly Aids Ltd because the company made 758,053 unsolicited sales calls between May 2024 and February 2025 to individuals registered with the Telephone Preference Service. The company specifically targeted older adults, selling them call blockers under the pretext of protecting them from nuisance calls, while its own calls were aggressive, misleading, and in some cases made without disclosing the caller’s identity. The legal basis for the decision is the Privacy and Electronic Communications Regulations (PECR), the British equivalent of the ePrivacy Directive.
- The ICO will continue to focus its enforcement efforts on unauthorized telemarketing, particularly targeting vulnerable groups.
- No direct connection to the GDPR, but relevant for clients with a telemarketing component related to the UK.
Datatilsynet (Norway): Obstruction of the Supervisory Authority – Datatilsynet Imposes Sanctions on Lab Pharma AS
Source: Datatilsynet, press release dated August 17, 2026
The proceedings stem from a complaint filed in 2023 alleging that Lab Pharma AS used an individual’s name and photographs for marketing purposes, presumably without a legal basis. During the investigation of this complaint, Lab Pharma AS threatened employees of Datatilsynet in an attempt to have the investigation discontinued. Datatilsynet deemed this a violation of the obligation to cooperate with the supervisory authority under Article 31 of the GDPR in conjunction with Article 57(1) of the GDPR and therefore imposed a fine of 205,000 NOK. The sanction was thus not directed at the marketing practice that was originally the subject of the complaint, but rather at the company’s conduct during the ongoing supervisory proceedings.
- The sanction was not imposed for the original data breach, but for threatening the supervisory authority during the investigation.
- Uncooperative behavior constitutes a separate basis for a fine.
III. Laws and News
German Bundestag: Statement by the Federal Government on the Bundesrat’s Draft Bill to Amend the Federal Data Protection Act
Source: German Bundestag, Printed Paper 21/7732
On July 10, 2026, the Bundesrat adopted a draft bill to amend the Federal Data Protection Act. The central provision: The Data Protection Conference (DSK) is to be enshrined in law for the first time (new § 18 BDSG-E); in addition, a lead supervisory authority is to be responsible for corporate groups and cross-state research projects in the future. The Federal Government issued a statement on this matter on August 26, 2026: While it supports the goal of more uniform application of the law, it sees risks under constitutional law and EU law, particularly regarding the independence of supervisory authorities guaranteed under Article 52 of the GDPR, as well as the prohibition on impermissible joint administration by the federal and state governments. It announced that it would present its own reform proposal.
- The bill has not yet been passed; the legislative process is still underway. The federal government has taken a critical stance, so the outcome remains uncertain.
- This is relevant for clients with corporate groups operating nationwide or across state lines, as a future “one-stop-shop” regulation at the national level would alter the structure of jurisdiction.
BfDI: Call for Centralized Cookie Managers
Source: BfDI, press release dated August 18, 2026
The current Federal Data Protection Commissioner, Prof. Dr. Louisa Specht-Riemenschneider, called on the press for a uniform, Europe-wide solution regarding cookie consent. This call is based on a representative survey conducted as part of the BfDI’s “Data Barometer” project: Only 43 percent of respondents know exactly what cookies are, while 60 percent reject cookies across the board as soon as they can do so with a single click. The BfDI proposes that, in the ongoing proceedings regarding the EU Digital Omnibus, binding, machine-readable data protection preferences and centralized services for managing consent be enshrined, modeled after the German Consent Management Regulation.
- Not politically binding and with an uncertain outcome, as the Digital Omnibus is still going through the EU legislative process; it is expected to be adopted by the end of 2026.
- Relevant for companies that operate websites: A binding EU regulation on centralized cookie managers would fundamentally change the current decentralized consent banner model and require technical adjustments.
BSI: Social Bots Are Hard to Detect – BSI Calls for Transparency Requirements
Source: BSI, Cybernation Blog, August 27, 2026, "Social Bots: Digital Communication Needs More Transparency"
The BSI, together with the Federal Network Agency, took a stance on the inadequate practical enforcement of transparency obligations for automated accounts (social bots) under the Digital Services Act (DSA). Of particular legal relevance is Article 25 of the DSA, which stipulates that providers of online platforms may not design or organize their online interfaces in such a way as to deceive or manipulate users, as well as the labeling requirements for automated communication, insofar as they arise from the platforms’ own terms of use and, supplementarily, from Section 18(3) of the Telemedia Act or its successor provisions in the Digital Services Act. In the BSI’s assessment, these requirements are not being applied consistently enough by the platforms in question.
- The BSI has not announced any supervisory measures of its own; the Federal Network Agency is responsible for this (Section 12 of the Digital Services Act).
- There is no immediate risk of a fine, but bot labeling is likely to become more important to the DSA supervisory authority in the future.
- This is particularly relevant given the transparency requirements for AI chatbots and social bots under Article 50 of the EU AI Act, which took effect on August 2, 2026.






