Published on 8 August 2026
A single misaddressed message can prove costly for a company – that much the Federal Court of Justice (BGH) made unmistakably clear in its ruling of 23 June 2026 (case no. VI ZR 97/22). A private bank had used the career network Xing to send a message containing application details and a specific salary offer to the wrong recipient. That recipient happened to be a former industry colleague of the applicant. The result: in principle, the applicant is entitled to compensation for non-material damage under Article 82 of the General Data Protection Regulation (GDPR). How much that compensation will amount to must now be determined by the Higher Regional Court (OLG) of Frankfurt am Main.
For small and medium-sized enterprises (SMEs) that manage applications digitally, this ruling is a wake-up call. It shows that it is not only the external hacker attack that poses a data protection risk, but also the entirely everyday careless mistake made by an employee. In this article, we explain exactly what happened, why the ruling is so significant, and what concrete changes you should now make to your applicant management (HR processes).
On 23 October 2018, an employee of a private bank sent a message via the messenger function of the Xing platform. Her intended target was an applicant to whom she wanted to convey details about the ongoing application process. But the message ended up with the wrong recipient – presumably due to a mix-up in the name auto-complete function.
The content of this misdirected message was sensitive. It contained the following personal data:
Particularly awkward: the wrong recipient was a former colleague of the applicant from the same industry. He took the message as an occasion to contact the applicant directly with a follow-up question. As a result, an uninvolved person from the applicant's professional circle learned that he was applying elsewhere – including his salary expectations.
It is important to understand: nothing was hacked here, no software vulnerability was exploited and no database was cracked. This was a data breach of a purely organisational nature – in technical jargon, this is referred to as "human error".
That is precisely what makes the case relevant to so many companies. The auto-completion of names in messenger services or email programs is a function everyone uses daily – and, for exactly that reason, it represents a constant source of error. One click on the wrong contact, and sensitive data is on its way to the wrong person.
The case took a long journey through the courts. On 26 May 2020, the Regional Court of Darmstadt initially awarded the applicant 1,000 euros in damages and a claim for injunctive relief. On 2 March 2022, however, the OLG Frankfurt overturned the damages award – on the grounds that there was no proven concrete damage. The BGH then referred the matter to the European Court of Justice (ECJ) to clarify key questions of interpretation.
On 4 September 2025, in case C-655/23, the ECJ decided a crucial question: a claim under Article 82 GDPR has no threshold of seriousness. In other words: there is no "de minimis limit" below which damage does not count.
"A claim under Article 82 GDPR has no threshold of seriousness; even negative feelings such as worry or anger can constitute non-material damage." – European Court of Justice (ECJ)
On this basis, the BGH ruled on 23 June 2026. The court saw the non-material damage already in the loss of control over the data as well as in the justified fear of its misuse. Specifically, the BGH made clear from what point at the latest damage exists:
"Non-material damage is to be assumed at the latest from the point at which the third party [...] took note of the message and used it as an occasion to contact the claimant [...] with a follow-up question." – Federal Court of Justice (BGH)
Two points are particularly important for companies:
The BGH, incidentally, rejected the claim for injunctive relief. The reason: after the conclusion of the application process, there was no longer any risk of repetition.
The short answer: virtually every company with HR processes and applicant management. Whether you employ two people or two hundred – as soon as you receive applications and communicate about them digitally, you bear the responsibility.
Particularly at risk are companies that use personal profiles on networks such as Xing or LinkedIn for applicant communication, instead of dedicated corporate accounts with regulated access rights. The quick emailing of acceptances and rejections without any checks is also a classic gateway for such errors.
Go through the following three steps to assess your own risk:
Since this is an organisational error and not a software vulnerability, there is no update or patch to install here. The solution lies solely in your processes and the training of your employees. We recommend the following concrete measures:
The ruling gives concrete substance to Article 82(1) GDPR, which governs the claim for compensation for non-material damage. The key message for companies: the mere loss of control over data and the justified fear of misuse are sufficient, without any threshold of seriousness having to be exceeded. In this way, the case law lowers the bar for affected persons to assert claims.
Attorney Dr Marc Maisch assesses the significance as follows:
"In his view, the BGH ruling shows how seriously courts now take even small data breaches in the application process. Companies should review their HR processes now." – Dr Marc Maisch, attorney
Attorney Guido Aßhoff also makes clear that the financial consequences are real:
"Even a single misdirected message can trigger a claim for non-material damages under Article 82 GDPR — and a damages amount of at least 1,000 to 2,500 euros is realistic." – Guido Aßhoff, attorney
Current statistics prove that data breaches are no marginal phenomenon:
Taken in isolation, these amounts seem manageable. But the risk lies in the multiplication: anyone who has a systematic process error can harm not just one but many affected persons. Add to this potential reputational damage and fines from the supervisory authorities. What appears to be a trivial case can thus quickly become a substantial burden.
The case of the misdirected Xing message shows how a moment of inattention can lead to a years-long legal dispute and a claim for damages. The BGH ruling of 23 June 2026 significantly strengthens the rights of affected persons: the loss of control over personal data and the justified concern about its misuse are sufficient to establish a claim – there is no de minimis limit.
For small and medium-sized enterprises, this means: data protection in the application process is not a "nice-to-have", but a tangible legal obligation with financial consequences. The good news is that the most effective protective measures are neither expensive nor complicated. A four-eyes principle when sending sensitive messages, trained employees, dedicated corporate accounts and a clear procedure for emergencies go a long way. Anyone who reviews their HR processes now protects not only the data of their applicants – but also their own company from costly surprises.