All news
Case law August 21, 2026 5 min

Real employee data inside the test system: what loss of control is worth

The German Federal Labour Court awards two hundred euro for the fields transferred beyond the agreed list. And it confirms that a late Article 15 reply, on its own, compensates nothing

TL;DR for the DPO

Two judgments from the same German chamber draw the line: loss of control over data disclosed without a legal basis is compensable damage even when it is small; a delay in answering an access request is not. Anyone migrating an HR system has one thing to put in writing: why dummy data were not enough.

The case

A German employer, part of a group whose parent company sits in the United States, prepares the move to a single cloud HR system. Between 24 April and 18 May 2017 it uploads employee data from its own HR software to a parent-company area, in order to feed the new system for testing. On 3 July 2017 it signs a tolerance agreement with the works council listing exactly which fields may be transferred for test purposes: staff number, surname, first name, hire date, group entry date, place of work, company, business phone and business e-mail. Nine items. What was actually transferred also included salary, home address, date of birth, marital status, social security number and tax ID.

Testing with real data is not forbidden

"Processing personal data in order to test new HR software may be justified by the employer's legitimate interests under Article 6(1), first subparagraph, point (f), provided that depersonalised "dummy data" are not sufficient to achieve the test purpose."
— German Federal Labour Court, headnote of the judgment of 8 May 2025 (8 AZR 209/21)

This is the point almost every report skipped. The court did not say real data in a test environment are prohibited: it said the excess was not necessary. And it drew that from the agreement itself: if the parties settled on nine fields being enough to test, they wrote down that the tenth was not needed. The employer had already ruled out its own necessity argument.

Two hundred euro, and how they were calculated

Article 82 requires three cumulative conditions: an infringement, damage — including non-material damage — and a causal link between them. Here the damage is the loss of control over the data, which counts even when brief, provided the data subject proves it. The amount reflected the sensitivity of the data — below the Article 9 threshold — the circle of recipients, wider but confined to the group, and how long the loss of control lasted. The gravity of fault did not count: Article 82 has a compensatory function, and the court ruled out any increase for intent.

A delayed access reply, by contrast, pays nothing

In its judgment of 20 February 2025 (8 AZR 61/24) the same chamber rejected a claim based on a late Article 15 reply: the delay does not in itself produce a loss of control, only a postponement of the information. Discomfort or a negative emotional state are not enough; what is required is a concrete fear of misuse that a court can review. This is a distinction worth explaining to clients before the first request arrives: the right of access remains fully enforceable and authorities do sanction it — the Norwegian decision from January shows that clearly — but individual compensation runs on a different and narrower track.

A works agreement does not lower the GDPR floor

This part travels well beyond Germany, wherever collective agreements shape the processing of employee data. The court left section 26(1) of the German Federal Data Protection Act unapplied because it does not satisfy Article 88: a national employment rule counts as a more specific provision only if it adds suitable and specific measures safeguarding human dignity and fundamental rights, not if it repeats the Regulation. Failing that, processing in the employment context is governed directly by the GDPR.

What to do now, in practice

1) For every HR system migration, produce a note stating whether dummy data suffice and, if not, why: that note is the defence, not the agreement; 2) treat the transfer to the parent company as a disclosure to a third party, not an internal move; 3) the agreed field list becomes the ceiling: exceeding it rules out necessity before the balancing test even begins; 4) make sure Article 15 procedures meet the one-month deadline regardless of compensation: a regulatory fine and an individual claim are two separate risks.

Official source:German Federal Labour Court — judgment of 8 May 2025, 8 AZR 209/21 (ECLI:DE:BAG:2025:080525.U.8AZR209.21.0); judgment of 20 February 2025, 8 AZR 61/24; Court of Justice of the EU, 19 December 2024, C-65/23 (K GmbH)

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Case law
7i criteri di bilanciamento CEDU

You don't delete the article, you delete the name

On 5 August 2026 the CNIL clarified the boundaries of a right that is often exercised and widely misunderstood. Against a press organisation, objection and erasure remain available; access and rectification do not. And a refusal must be reasoned concretely: six generic formulas are named as inadmissible.

Aug 05, 2026New 4 min
Case law
3condizioni cumulative del test

Legitimate interest is not the fallback legal basis

In Case C-621/22 the Court of Justice held that a commercial interest can constitute a legitimate interest under Article 6(1)(f). Many people read only that line. The rest of the judgment recalls that the conditions remain three and cumulative, and that the third - the balancing against the data subject's reasonable expectations - is where the case at hand was lost. For the DPO the consequence is practical: legitimate interest exists only if it is written down somewhere.

Aug 12, 2026New 6 min
Case law
3elementi da provare, cumulativi

Damages under the GDPR: what a claimant actually has to prove

Regulatory fines make the headlines; civil claims pay the lawyers. Since 2023 the Court of Justice has held that compensation under Article 82 requires three cumulative elements - infringement, damage, causal link - with no threshold of seriousness. It has also held that a well-founded fear that your data has fallen into the wrong hands is already non-material damage. For the controller this moves the battleground: not the gravity of the harm, but proof of the measures in place.

Aug 11, 2026New 7 min