Skip to Content
The text you are endorsing

Complaint to the European Commission

This is what your signature supports. Nothing is submitted in your name beyond what is written here. Read it before you sign — and do not sign if you disagree with any part of it.

To: European Commission — Secretariat-General, 1049 Brussels
Concerning: Failure of the Federal Republic of Germany to give full effect to Regulation (EU) 2016/679 (GDPR)
Underlying case: Lehder v. State of Baden-Württemberg (LfDI) — Administrative Court Stuttgart, 14 K 4946/26; joined party: Atruvia AG
Evidence: the authority’s own 767-page file, obtained by inspection on 25 June 2026. Its four letters to the citizen — 23 pages — are published in the original, redacted, at gericht.online. The file itself is not published.
Status: draft — to be filed once the signatures have been collected

I. What this complaint is about

Article 15 GDPR gives every person in the Union the right to know what is stored about them. That right is worth exactly as much as its enforcement. This complaint is not about a company. It is about the enforcement — and about a supervisory authority that, in the complainant’s submission, did the opposite of what it exists for.

A right that a citizen can only obtain by suing at their own cost, after fifteen months, against an authority that was supposed to protect them, is not a right. It is a privilege for those who can afford it.

II. The facts

All of the following is documented in the authority’s own administrative file and can be read there.

  1. 9 October 2024 — the complainant requests access to his data under Art. 15 GDPR, without giving reasons, as the law permits. He specifies the individual systems on 23 October 2024.
  2. 15 January 2025 — what he receives is essentially a personnel-file extract. The systems he named are missing.
  3. 5 December 2025 — instead of the paper copy he expressly requested, he is offered a download link, with the password to be posted to an address at which he no longer lives.
  4. 16 March 2026 — the authority closes the complaint procedure. It relies on a 43-page statement by the company dated 19 December 2025 which was never served on the complainant. It conducts no investigation of its own, imposes no measure, and refers him to the civil courts:
    “Finally, by way of a direct action against the respondent … an effective and reasonable remedy is available to you.”
  5. 1 April 2026 — only now does the substantive refusal arrive, containing the decisive facts for the first time. Among them: the paper copy is refused on the basis of a truncated rendering of the statutory text — Art. 15(3) sentence 3 GDPR is quoted without its final clause, the very clause that gives the data subject the choice.
  6. 19 December 2025 — the intimidation the authority kept in its drawer. In the same 43-page pleading, the company’s law firm informs the authority that damages of “at least a mid five-figure sum” are being examined “on account of the complainant’s excessive conduct” — that is, on account of his exercising the right of access. It adds that even his submissions to the authority itself may exceed the limits of legal privilege, and awaits “the further course of the proceedings with interest”.
    “The complainant may do what he cannot refrain from doing. […] our client is currently examining claims for damages of at least a mid five-figure sum on account of the complainant’s excessive conduct…”
    — official file, sheet 681
    Art. 12 GDPR and Recital 63 forbid any detriment arising from the exercise of a data subject’s right. The authority had this passage in its own file. It never served it on him, never assessed it, never objected — and closed the case in the company’s favour. He learned of it only on 25 June 2026, when he was finally allowed to inspect the file.
  7. 8 July 2026 — the authority states there is “no reason to assume” that data would be deleted — although it had itself told the complainant that data had been deleted, and had told the company on 16 September 2025 that deletion in view of a pending access request would be unlawful.

The company, for its part, concedes in the same file that securing the data was possible (“our client naturally also enables short-term processing … where deletion of the requested information is imminent”), that the pseudonymised user remains “reconstructable under the four-eyes principle”, and that the backups have merely “not been restored into production”. In other words: the data is not gone. It was simply not looked at.

III. The infringements alleged against the Member State

Art. 15 · Art. 23 GDPRNational law narrows a Union right

The refusal rests on § 34 and § 29(1) sentence 2 of the German Federal Data Protection Act (BDSG) — “disproportionate effort”, trade secrets, backup and archive copies. Article 23 GDPR permits restrictions only where they respect the essence of the right and are necessary and proportionate. We ask the Commission to examine whether these provisions, as applied here, still leave the essence of Art. 15 intact — or whether they turn a Union right into a national exception.

Art. 57(1)(f) · Art. 58 GDPRSupervision that does not supervise

A supervisory authority must handle complaints and investigate to the extent appropriate. Here it adopted the company’s account without examining it, held no file, ordered no measure, and closed the case — while the infringement continued.

Art. 77 · Art. 78 GDPR · Art. 47 CFRThe citizen is sent away

Referring a data subject to the civil courts instead of exercising supervisory powers empties Art. 77 of meaning. And where the reasons for a decision are disclosed only after the time limit to challenge it has started to run, the right to an effective remedy under Art. 47 of the Charter exists only on paper.

CJEU C-307/22A judgment taken note of — and rendered unusable

The Court of Justice has held that a data subject need not give reasons for an access request. The authority does not deny the ruling. It accepts it — and then accepts, as a legitimate ground for refusal, the company’s assertion that the request pursued “no genuine interest” and was “excessive”. A judgment that is formally recognised and practically disapplied is not a judgment. The binding force of the Court’s rulings in national law is what is at stake here.

IV. What we ask the Commission to do

  1. Examine whether Germany ensures effective supervision under Arts. 51, 52, 57 and 58 GDPR — in particular whether a supervisory authority may close a complaint without investigating it and refer the citizen to the civil courts instead.
  2. Review §§ 29(1) sentence 2 and 34 BDSG for compatibility with Arts. 15 and 23 GDPR, as applied. These are the provisions through which a Union right is narrowed by national law.
  3. Decide whether a Land’s own authority may supervise companies established in that same Land. Atruvia maintains one of its main sites, and a substantial part of its workforce, in Baden-Württemberg — and it is precisely that connection which founds the LfDI’s competence. The same economic weight that makes the authority responsible also makes it the authority of the company’s own region. Art. 52(1) GDPR demands complete independence; Art. 41 of the Charter demands that a citizen’s affairs be handled impartially. If proximity of this kind cannot be excluded as a factor, then the rule of competence itself produces the conflict — and the Commission should say so.
  4. Establish when a supervisory authority must hand a case over. The claimant applied for the case-handling officer to be excluded for bias. It was never decided — “a decision on this can be left open”. After seeing the file, he extended the motion to the entire authority and asked that the matter be assessed by a data protection authority of another federal state. There is currently no rule that says at what point the appearance of partiality — visible on the face of the authority’s own letters — obliges it to give up the file. There must be one. A citizen cannot be left to argue impartiality with the very body he is complaining about.
  5. Assess whether the practice described deprives Art. 77, Art. 78 GDPR and Art. 47 of the Charter of practical effect — including where the reasons for a decision are disclosed only after the time limit to challenge it has begun to run.
  6. Create a mechanism that guarantees the authority acts — without a court case. Art. 57(3) GDPR provides that the performance of a supervisory authority’s tasks shall be free of charge for the data subject. The complaint route was designed as the low-threshold, cost-free path; litigation was meant to be the exception. Here it is the exception that has become the only way. To obtain an investigation the authority owed him anyway, the claimant had to sue — and now bears the cost risk of two sets of proceedings that exist only because the authority did not investigate. The authority itself sent him to court, and then applied for his application to be dismissed with costs against him.

    Where an infringement is plain on the face of the file, there must be a binding duty to act, a deadline, and a remedy that does not put the citizen’s money at risk. A court procedure must not be an instrument that makes access to one’s own data harder and more dangerous. Otherwise Art. 57(3) is set aside and Art. 77 is decoration.
  7. Order a review of the past. If this reading of § 34 BDSG, and this practice of closing complaints without investigation, were applied here, they were applied before. Every complainant who was turned away on the same grounds must be identified and their case reopened. A wrong application of Union law does not become lawful because the person it was applied to gave up.
  8. Investigate whether this is one case or a system. How many complaints has this authority closed without investigating? How many people lacked the money, the information, or the stamina to insist — and therefore never appear in any statistic? That number is not known. It must be. If an authority is willing to go this far against someone who fights back, the question of how it treated those who could not is not rhetorical. And those people are owed a second chance under a new order.
  9. Rule on retaliation. A controller that answers an access request by announcing a five-figure damages claim because of that request — in a pleading addressed to the supervisory authority deciding the case — is punishing the exercise of a Union right. Art. 12 GDPR and Recital 63 forbid it. The Commission should state whether a supervisory authority that reads such a passage in its own file and does nothing has discharged its duty under Art. 57(1)(f). If intimidation is free, the right of access is free only in theory.
  10. Consider infringement proceedings against Germany under Art. 258 TFEU.

A judgment repairs one case. It does not repair an authority. That is why this is addressed to the Commission — and not only to a court.

V. What signing means — and what it does not

You are endorsing a request that the Commission examine this matter. You are not accusing anyone of a crime. No allegation of corruption is made, here or anywhere on this site. What is alleged is a failure to enforce Union law — documented, in the authority’s own words, in its own file.

Of your data, at most name, city and country are shown publicly — and only if you choose it. Your email address is never published; it serves solely to confirm that the signature is real. The Commission does not count anonymous clicks.

Back to the case — sign here

This page is published as reporting on the conduct of a public authority in a pending case (Art. 5 of the German Basic Law; Art. 85 GDPR). It reproduces facts from the official file. Where an assertion is disputed, this is stated. The proceedings are pending and undecided.