Data Protection Pulse – August 18, 2026: Everything You Need to Know Right Now
The most important data protection decisions and developments from the past two weeks.
I. Judgments
Man-in-the-Middle Scam When Buying a Car: Buyer Has to Pay Twice
Source: Oldenburg Higher Regional Court, Order of April 17, 2026 – 5 U 89/25 (Oldenburg Higher Regional Court)
A car buyer transferred just under 17,000 euros to an IBAN that had been manipulated through a man-in-the-middle attack—the money ended up in the hands of fraudsters instead of the car dealership. The Oldenburg Higher Regional Court ruled that the purchase price obligation was not thereby fulfilled, and the buyer must, in principle, pay again. (Oldenburg Higher Regional Court)
- No Performance: Payment to the scammers does not satisfy the obligation to pay the purchase price to the car dealership (Section 362 of the German Civil Code (BGB)). (Legal Tribune Online)
- No liability on the part of the car dealership: No special security procedures for email communication had been agreed upon; furthermore, the buyer’s daughter herself had initiated the transmission of the bank details via email. (Oldenburg Higher Regional Court)
- No GDPR damages either: It could not be established that the attack or manipulation was due to a data protection violation by the car dealership. (Oldenburg Higher Regional Court)
Osnabrück Administrative Court (7th Chamber), Court Order dated August 11, 2026 – 7 A 26/24 Regarding the Excessiveness of the Right to Information
Source: Osnabrück Administrative Court (7th Chamber), Court Order dated August 11, 2026 – 7 A 26/24
https://www.ra-kotz.de/datenauskunft-dsgvo-datenkopien.htm
The Osnabrück Administrative Court has significantly strengthened the right to information under Article 15 and set high standards for the “excessiveness” defense under Article 12(5) of the GDPR. However, the plaintiff was required to assert the additional claim for damages under Article 82 of the GDPR in the civil courts.
- Specific information instead of a standard form: A general privacy notice under Article 13 of the GDPR is not sufficient for Article 15. Data controllers must specifically identify the data actually processed, its categories, source, purposes, and the rights of data subjects.
- Even mere storage constitutes processing: Personal data is considered processed under the GDPR even if it is merely stored or retained and no one is currently actively working with it.
- A large number of requests for information does not necessarily constitute an abuse: The city was unable to prove that the plaintiff’s repeated requests were excessive or constituted an abuse of the law. Even parallel proceedings and additional claims for damages are not sufficient on their own to establish this.
Hidden camera under the desk: Mayor convicted
Source: Landsberg District Court – 7,200-euro fine for mayor who spied, beck-aktuell, August 4, 2026
A former mayor from Upper Bavaria secretly monitored his secretary for about a year using a camera installed under her desk, which allowed him to stream video and audio to his cell phone and, in some cases, record them. The Landsberg Local Court sentenced him to 90 daily fines of 80 euros each, totaling 7,200 euros; in addition, as part of a victim-offender mediation agreement, he agreed to pay 10,000 euros in compensation for pain and suffering.
- Extensive employee surveillance: The camera recorded not only the secretary but also visitors and phone calls in her office.
- Political motive: According to his own statement, the mayor wanted to find out whether his reception area was being used as a “meeting place for the opposition” because the staff member was supporting a political rival.
- Offender-victim mediation led to a reduced sentence: The court described the incident as “unbelievable”; according to the judge, without a confession, an apology, and the agreed-upon amount of compensation for pain and suffering, the fine would have been significantly higher.
II. Fines and Government Agencies: Transparency Requirements Under the AI Act Effective August 2, 2026 – AI-Generated Text and AI-Generated Images
References:
Art. 50 of the AI Act – Regulation (EU) 2024/1689 · European Commission: Guidelines on Art. 50 of the AI Act, July 20, 2026 · Code of Practice on Transparency of AI-Generated Content · European Commission: EU Icons for Labeling
The transparency requirements of Article 50 of the AI Act have been in effect since August 2, 2026. It is important to distinguish between the technical, machine-readable labeling provided by the provider of an AI system and the labeling visible to humans provided by the party publishing AI content—there is no general requirement to visibly label all AI-generated text and images as AI.
Deep Dive: When Must AI-Generated Text Be Labeled?
Article 50(4) of the AI Act requires visible labeling only for AI-generated or AI-manipulated texts that are published to inform the public about matters of public interest. The Commission broadly defines these matters to include, for example, politics, public administration, the judiciary, fundamental rights, public safety and health, consumer protection, as well as economic, financial, scientific, or cultural developments that may be the subject of public debate.
- Not every AI-generated text requires a disclosure. Internal texts or other texts that are not published to inform the public about matters of public interest are not subject to this specific disclosure requirement.
- Key exception: Human review. If the content of the text has been reviewed by a human or edited, and a natural person or legal entity assumes editorial responsibility, it does not need to be labeled as AI-generated. However, a mere spelling, grammar, or formatting check is expressly not sufficient.
- Practical example: Law firm/company—If ChatGPT generates a specialized article on data protection law, which is then reviewed by a knowledgeable attorney, revised as necessary, and for which the law firm assumes editorial responsibility prior to publication, there is generally no visible AI disclosure requirement under Article 50(4).
Source: Art. 50, para. 4 of the AI Act; Commission Guidelines on Art. 50; EU Commission FAQs on Art. 50.
Deep Dive: When Do AI-Generated Images Need to Be Labeled?
When it comes to images, perhaps the most important clarification is this: Not every AI-generated image must be visibly labeled as “AI-generated.” The deployer’s obligation to provide visible disclosure under Article 50(4) applies to so-called deepfakes in the context of images, audio, and video.
- A deepfake occurs when AI-generated or manipulated content depicts people, objects, places, institutions, or events and can falsely lead the viewer to believe that it is authentic or true. The key factors are similarity, context, the message conveyed by the image, and the audience’s expectations.
- Example: A realistic AI-generated image that depicts a real politician engaged in an action that never took place, or a real company building during a fabricated fire, must generally be disclosed. An obviously fantastical or recognizably fictional image, on the other hand, will generally not create the same impression of deception.
- The label must be clear and distinguishable no later than the first time the content is viewed. Hidden metadata is not sufficient for this purpose. The Commission now provides its own EU AI icons; their use is voluntary, whereas the legal disclosure requirement for deepfakes subject to labeling is not.
An exception applies to works that are clearly artistic, creative, satirical, or fictional: the disclosure may be made in a way that does not impair the presentation or enjoyment of the work.
Source: Art. 3, No. 60, and Art. 50, para. 4, of the AI Act; Commission Guidelines on Art. 50; European Commission: EU Icons for Labeling AI-Generated Content.
Important: The second level—invisible technical marking
This should be distinguished from Article 50(2) of the AI Act. Providers of generative AI systems must, as a general rule, ensure that generated or manipulated text, images, audio, and video content are marked in a machine-readable format and are technically identifiable as AI-generated content. This obligation therefore typically applies to the provider of the generative system and is distinct from the visible disclosure made by the company that subsequently publishes the content.
That is precisely why the same AI-generated image can have two distinct layers: In the background is a technical AI marker added by the provider; however, the publisher must include a notice visible to the viewer, especially if the image meets the criteria for a deepfake.
Risk of a fine
Violations of Article 50 of the AI Act may be punishable by a fine of up to 15 million euros or, in the case of companies, up to 3 percent of their global annual revenue. Enforcement is generally the responsibility of national market surveillance authorities; in addition, the AI Office and, for EU institutions, the European Data Protection Supervisor have specific responsibilities.
Source: Art. 99, para. 4, subpar. g of the AI Act; Commission Guidelines/Quick Facts on Art. 50 of the AI Act.
III. Laws and News
Meta Must Pay $567 Million Into a Children's Fund
Source: New Mexico: Meta Must Pay $567 Million to a Children's Fund – beck-aktuell, August 7, 2026
A court in New Mexico has ordered Meta to pay $567 million into a fund for children who have been harmed by social media use; $420 million of that amount is to be used for therapy services alone. This follows a lawsuit filed by the New Mexico Attorney General alleging insufficient protection of minors from sexual exploitation; a $375 million fine had already been imposed.
- Strict usage limits: In New Mexico, people under 18 will be allowed to use Facebook and Instagram for a maximum of 90 hours per month going forward.
- Protection Against Addictive Behaviors: Between 10 p.m. and 7 a.m., and on school days additionally between 8 a.m. and 3 p.m., minors should not receive push notifications; furthermore, like counts should no longer be displayed to them.
- Not yet final: Meta plans to appeal the decision; at the same time, the company is facing numerous other lawsuits in the U.S. regarding the protection of children and adolescents on its platforms.
Intelligence Law: Federal Government Seeks to Allow Use of AI and Longer Data Retention
Source: Federal Government, Cabinet Decision of August 12, 2026 – Intelligence Services Act to Be Reformed
On August 12, 2026, the federal government approved a comprehensive reform of the legal framework governing the Federal Intelligence Service (BND) and the Federal Office for the Protection of the Constitution. The draft legislation is intended, in particular, to enable the use of AI for data analysis, significantly longer data retention periods, and new active cyber defense powers.
- Use of AI: Intelligence agencies should be permitted to use AI applications to analyze large datasets more efficiently for relevant threats. (Federal Government)
- Longer Retention Periods: The BND is to be permitted to store telecommunications content for up to six months and traffic data—such as IP addresses and the time and duration of connections—for up to twelve months. (Federal Government)
- Active Cyber Defense: Under strict conditions, government agencies will be permitted to take action on their own in the future—for example, shutting down a foreign server from which an imminent cyberattack is originating. (Federal Government)
Federal Government: AI Is Becoming a Standard Tool for Public Administration
Source: German Bundestag, BT-Drs. 21/7443 – Response from the Federal Government on the Use of Generative AI
The federal government now explicitly refers to AI as a “standard work tool” of the federal administration—used, among other things, to draft speeches, articles, and other texts. However, human review and ultimate responsibility remain prerequisites: AI is intended to provide support, but responsibility for the content remains with humans.
- Human-in-the-Loop: AI-generated content is reviewed for technical accuracy and editorial quality before it is used further; with such human oversight, additional AI labeling is generally not necessary
- KIPITZ: For sensitive government data, the federal government operates the central AI platform KIPITZ in the ITZBund data centers. Data classified up to the “VS—FOR OFFICIAL USE ONLY” level can even be processed there.
- No sharing with external AI providers: According to the federal government, when using KIPITZ, the processed data is not transferred to external providers of AI systems.






