Germany: Unlawful Intra-Group Data Sharing Triggers Employee Compensation
Authors: Verena Braeckeler-Kogel, MAES (Basel) and Meike Christine Rehner
The German Federal Labour Court recently ruled that an employee was entitled to compensation under the EU General Data Protection Regulation (GDPR) after his employer unlawfully transferred his personal data to another company within the same corporate group during the testing of a new HR management system.
Background
The employer had entered into a works agreement with the works council, allowing the transfer of certain business-related data within the group for testing purposes of a new HR management system (Workday). However, the employer exceeded the scope of this agreement by also transferring sensitive personal information, including salary details, home addresses, and tax identifiers. The employee argued that this unauthorised transfer resulted in a loss of control over his personal data and claimed non-material damages.
While the claim was dismissed by lower courts, the Federal Labour Court ultimately awarded the employee a modest sum of EUR 200 in non-material damages after referring legal questions to the European Court of Justice. The court ruled that transferring data not covered by the works agreement was unjustified and breached the GDPR. The compensation was granted under Article 82(1) of the GDPR, which provides for damage claims in cases of unlawful data processing.
Key Issues
The court held that the employer had unlawfully transferred personal data beyond what was permitted under the applicable works agreement. This additional data transfer was not necessary for the intended purpose and therefore violated the principles of lawful data processing under the GDPR. As a result, the employee suffered non-material harm in the form of a loss of control over his personal information.
Practical Points
- The ruling confirms that, even within a corporate group, personal data may only be shared if the transfer is strictly necessary and/or explicitly authorised.
- Employees must be clearly informed about which data is being processed, its purpose, and the legal basis for processing it.
- Employers should keep clear records of their data processing activities and carry out regular risk assessments, particularly when introducing new systems or transferring data between different entities.