Data Privacy Compliance in the Cloud
Made Easy

Understand Cloud and Data Protection Law in only 4 easy steps. Plus highly relevant legal information for 33 countries. Provided by EuroCloud and 53 European lawyers.

Is a violation of a GDPR rule at the same time a violation of competition law?

16.01.2019

According to the Oberlandesgericht Hamburg (Higher Regional Court Hamburg) violations of data protection rules can also mean a violation of German competition law and can therefore be actionable by competitors in accordance with the German Unfair Competition Act (Gesetz gegen den unlauteren Wettbewerb).

In a judgement from 25.10.2018, the Oberlandesgericht Hamburg concluded, that violations of the GDPR are principally actionable by competitors. However, this only applies, if the violated GDPR rule’s additional purpose is also to protect market behavior.

The competitor’s right of action

With its decision, the Court affirms the competitor’s right of action in accordance with German unfair competition law in regard of the Data Protection Directive as well as in regard of the GDPR. The Court states that the Data Protection Directive obviously does not contain an exhaustive sanctionative system that prohibits actions against data protection violations according to civil law. Although the Data Protection Directive aimed at full harmonization of data protection law within the European Union, the Directive does not contain an exhaustive system of remedies.

With a view to the GDPR, the Court ruled that the GDPR, like the Data Protection Directive, does not contain an exhaustive sanctionative system that excludes competitors’ actions in accordance with competition law.

In the Court’s opinion, the provisions of the GDPR do not limit civil actions against GDPR violations to the data subject whose personal data was processed by the controller. According to the judges, the GDPR only defines a minimum level of remedies and is open to other remedies and sanctions that are not explicitly regulated within the GDPR. 

The Landgericht Würzburg (District Court Würzburg) arrived at the same conclusion in its court decision from 13.09.2018. However, the District Court did not provide any legal opinion for the conclusion.

In another case from 07.08.2018, the Landgericht Bochum (District Court Bochum) held a different view. Here the Court was of the opinion that the provisions in Artt. 77 to 84 GDPR have to be seen as an exhaustive rule that conclusively determines the entitled categories of possible claimants. Therefore, actions beyond those provisions by a competitor are not possible, because with the provisions in the GDPR the European legislator expressed his intention not to extend the categories of possible claimants. 

The Landgericht Wiesbaden (District Court Wiesbaden) comes to the same conclusion, adding in its decision from 05.11.2018 that because of the exhaustive provisions in Artt. 77 to 84 GDPR there is no gap in legal protection that needs to be closed by competition law.

Additional purpose of GDPR rule must be to protect market behavior

The Oberlandesgericht Hamburg also ruled that violations of the GDPR do not necessarily result in an injunctive relief in accordance with competition law. The question whether an injunctive relief is justified, depends on the violated GDPR rule. If the rule also has the purpose to protect market behavior, than a competitor’s injunctive relief is justified. This has to be legally examined on a case-by-case basis.

Summary

In Germany the discussion, whether competitors can prosecute data protection violations remains an open discussion. With the decision of the Oberlandesgericht Hamburg, there is now one Higher Regional Court that allows claims with regard to competition law. However, this ruling is not binding to other courts in Germany and remains in discussion until the Bundesgerichtshof (Federal Supreme Court) delivers a final judgement.

 

Article provided by: Jens Eckhardt & Nils Steffen (Derra, Meyer & Partner Rechtsanwälte PartGmbB)

 

Discover more about the Cloud Privacy Check(CPC) / Data Privacy Compliance(DPC) project

Director CPC project: Dr. Tobias Höllwarthtobias.hoellwarth@eurocloud.org

VIEW PROJECT

WHAT IS THE DPC/CPC PROJECT?

53 lawyers from 33 countries are contributing to the project “Cloud Privacy Check (CPC)” in 26 different languages.

Understanding the complexity of current European data protection laws and regulations is already difficult enough for an IT engineer, buyer, or business user. In combination with the often small but nevertheless significant differences between various EU member states, however, it can become an almost insurmountable challenge without proper juristic accompaniment from the very start... Read More

 

CPC MISSION & VISION STATEMENT

The CPC is a trusted, not-for-profit international network of qualified professionals who deliver simplified and straight-forward guidance to help navigate the legal and regulatory environment relating to privacy and the cloud. This is done through collective know-how, research and market analysis gained from pan-European industry activity, collaboration and experience. Our mission is to provide authoritative views, information and practical solutions to two principal stakeholders: industry professionals and public authorities.