BGH: GDPR Damages for Misdirected Applicant Data

Short & clear answers
Frequently asked questions about this incident
Does this ruling affect my small business?
Practically every company with HR processes and applicant management is affected, regardless of size. As soon as you receive applications digitally and communicate about them (e.g. via Xing, LinkedIn or email), you carry the responsibility. Businesses using personal staff profiles instead of dedicated company accounts are at particular risk.
What do I need to do now to protect myself?
Introduce a four-eyes principle before sending sensitive messages (e.g. salary offers, rejections) and train your HR staff on the risk of auto-complete and the principle of data minimisation. Also establish a data-breach protocol and use dedicated company accounts with defined access rights. Since this is an organisational error, there is no software update – the solution lies entirely in your processes.
How high can the damages be for a misdirected message?
In the specific case, at least 2,500 euros were demanded; the Darmstadt Regional Court initially awarded 1,000 euros. According to lawyer Aßhoff, a figure of 1,000 to 2,500 euros is realistic. The final amount in the BGH case must now be determined by the Frankfurt Higher Regional Court.
Does the affected person have to prove a financial loss?
No, an actual economic disadvantage does not have to be proven – the loss of control over the data and the well-founded fear of misuse are sufficient. There is no minimum or materiality threshold. However, the affected person must still concretely demonstrate the non-material damage; in this case the recipient's follow-up query provided that proof.
Do I have to report a misdirected email containing applicant data?
Yes, in the event of a data breach the reporting obligations under Art. 33 GDPR (notification to the supervisory authority) and Art. 34 GDPR (notification of the affected individuals) apply. These must be assessed within the 72-hour deadline. A fixed data-breach protocol helps you record misdirected messages immediately and respond in time.
More security news
You might also be interested in
Critical Elementor Pro Flaw: Attackers Can Fully Take Over WordPress Sites
A file upload bug in Elementor Pro up to 4.2.1 allows RCE without login. Version 4.2.2 fixes the flaw – update now!
Pods Plugin: Critical Flaw Enables Admin Takeover, No Login
A critical flaw in the WordPress plugin Pods lets attackers overwrite admin passwords without login. Over 100,000 sites are affected.
miniOrange SAML SSO: Critical Bypass Turns Attackers Into Admins
Two critical auth bypasses in the miniOrange SAML SSO plugin allow forged SAML assertions—up to full WordPress admin access.