Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

First Decision Applying the GDPR Issued by the Regional Court of Bonn (Germany)

By Ana Hadnes Bruder & Dr. Ulrich Worm on June 20, 2018
Email this postTweet this postLike this postShare this post on LinkedIn

On 29 May 2018, only five days after the GDPR became applicable, the Regional Court of Bonn issued the first ruling applying the GDPR in Europe (file no. 10 O 171/18). The dispute involved the Internet Corporation for Assigned Names and Numbers (ICANN) and the ICANN-accredited registrar EPAG Domainservices GmbH (EPAG).

Facts of the Case

ICANN is a non-profit company that coordinates the assignment of domain names and ensures that website names are not duplicated on the network. By means of an agreement between the parties, EPAG is authorized by ICANN to assign Second Level Domains to interested parties (so-called registrants).

For each domain name assigned, ICANN requires registrars to collect and further process not only the name and contact details of the registrant of the domain name, but also the name and contact details of a technical contact and of an administrative contact within the registrant. This personal data becomes public through publication on the WHOIS website platform. With the GDPR becoming applicable on 25 May 2018, EPAG argued that there was no legal basis for the processing of the personal data of the technical and administrative contacts of registrants and therefore, based on the GDPR, informed ICANN that it would no longer process such personal data. ICANN then filed an application for interim relief with the Regional Court of Bonn aiming at forcing EPAG to continue obtaining this information from registrants and making it available to ICANN.

Legal Assessment

According to Article 5 (1) (b) and (c) of the GDPR, personal data may only be collected for specified, explicit and legitimate purposes (purpose limitation principle), and must be adequate, relevant and limited to what is necessary for the purposes for which the personal data is processed (data minimization principle). Moreover, pursuant to Article 25 (1) of the GDPR, companies must take appropriate organizational and technical measures to implement the GDPR principles, such as purpose limitation and data minimization.

Relying on this, EPAG held the view that the processing of the name and contact details of one responsible person within the registrant of a domain name should be deemed sufficient for the purpose of identifying the registrant and allowing  contact by third parties, and therefore no legal basis existed for the processing of name and contact details of a technical and an administrative contact of registrants.

ICANN opposed that the identification of a technical contact person is necessary to find solutions to technical problems, and that the processing of personal data of a technical and administrative contact of registrants is also necessary for security and criminal prosecution purposes; Prosecutors and trademark representatives are particularly interested in such additional information.

Decision
The Regional Court of Bonn denied ICANN’s request and decided that processing personal data of a technical and an administrative contact persons of registrants violates Article 5 (1) (b) and (c) of the GDPR. The specified, explicit and legitimate purpose of processing personal data in the context of assigning domain names shall be the identification of the registrant, which in turn is sufficient to address ICANN’s concerns regarding the security of the network. The owner of the domain name is the only person responsible for the content of the website and therefore only the processing of their personal data shall be deemed necessary for this purpose.

Take away

Interestingly, the discussion did not focus on the lawfulness of processing (Article 6 of the GDPR), but rather on the implementation of the GDPR principles of purpose limitation and data minimization. Nonetheless, the central issue was the necessity of data processing, which is one of the foundations of the GDPR, reflected both in the GDPR principles and in their concretization through the grounds for processing.

The Court did briefly address Article 6 of the GDPR though. One fact that caught the Court’s attention in particular was that the registration of a domain name has always been possible even if a technical and an administrative contact were not made available by the registrant. This was considered by the Court as a clear sign that such personal data is not necessary for the purposes of the processing of personal data. As such, registrants should be free to decide if they want to provide such additional contact details or not, based on Article 6 (1) (a) of the GDPR (consent). They shall not, however, be forced to provide such data, there is no other legal ground for their processing.

This rationale will probably be used by other Courts when applying the necessity test, so companies should analyze carefully whether they really need the personal data they are processing, and if not, take measures to assure that their processing is lawful based on another GDPR legal ground.

 

This article was originally published on AllAboutIP – Mayer Brown’s  blog on relevant developments in the fields of intellectual property and unfair competition law. For intellectual property-themed videos, Mayer Brown has launched a dedicated channel available here.

Photo of Ana Hadnes Bruder Ana Hadnes Bruder

Ana Hadnes Bruder is a partner in Mayer Brown’s Frankfurt office and an active member of the global Cybersecurity & Data Privacy practice. She is also a member of the firm’s Intellectual Property practice. Ana advises clients on data privacy and cybersecurity matters…

Ana Hadnes Bruder is a partner in Mayer Brown’s Frankfurt office and an active member of the global Cybersecurity & Data Privacy practice. She is also a member of the firm’s Intellectual Property practice. Ana advises clients on data privacy and cybersecurity matters, including preparing for and reacting to cyber-attacks, assessing and making required data breach notifications, analyzing data protection implications of new products and tools and providing strategic advice with a focus on cross-border data processing. Ana further advises on Technology Transactions including cloud services, data and software licensing agreements, SaaS agreements, software development projects, e-commerce, and related Cybersecurity & Data Privacy questions.

Ana is a registered lawyer in Germany and Brazil and has ten years of international experience as legal counsel in Brazil, France and Germany. Ana started her career at Mayer Brown in the Dispute Resolution practice where she represented clients in litigation and arbitration proceedings involving complex commercial, intellectual property and liability matters.

Before joining Mayer Brown, Ana gained experience representing foreign clients in judicial proceedings in Brazil and also worked as in-house counsel for a leading French company in Paris.

Read full bio

Read more about Ana Hadnes BruderEmail
Show more Show less
Photo of Dr. Ulrich Worm Dr. Ulrich Worm

Ulrich Worm is a partner in the Frankfurt office of Mayer Brown and heads the German Intellectual Property practice. His practice focuses on technology related advice.

Ulrich advises clients in IP related matters, including patent, trade secrets, design right, trademark and copyright matters…

Ulrich Worm is a partner in the Frankfurt office of Mayer Brown and heads the German Intellectual Property practice. His practice focuses on technology related advice.

Ulrich advises clients in IP related matters, including patent, trade secrets, design right, trademark and copyright matters as well as on licensing, co-operation and other technology transfer agreements. He represents clients in patent infringement and nullity proceedings and in trade secrets litigation cases before courts in Germany. In addition to litigating IP cases before German courts, he coordinates pan-European and cross-Atlantic litigation cases. Further to his IP litigation practice, Ulrich advises on patent related matters such as patent license and other technology transfer agreements and is experienced in fighting counterfeiting of patent, design right and trademark protected products.

His practice further covers IT-related matters, including advising on cloud services, software licensing agreements, SaaS agreements, software development projects, e-commerce, and related data protection and privacy questions.

Read Ulrich’s full bio.

Read more about Dr. Ulrich WormEmail
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    All About IP
  • Organization:
    Mayer Brown

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo