The WhatsApp Leak Case Now Before Germany's Federal Court of Justice
Germany's Federal Court of Justice (BGH) has begun hearing a case that could determine when forwarding a private WhatsApp conversation violates the EU's General Data Protection Regulation (GDPR). The dispute stems from a medical practice employee who was dismissed after messages she sent to a friend — complaining about her boss — were passed on without her consent.
The messages were exchanged about three years ago. After the friendship ended, they reached the boss's wife, who handled administrative work at the practice, and the employee was dismissed shortly afterwards. The woman is seeking €7,500 in compensation plus legal costs, arguing that the GDPR's exemption for purely personal or household data processing does not apply to her case.
The case has split lower courts. Frankfurt's Regional Court initially ordered the friend who forwarded the chats to pay €7,500, saying the forwarding was at least partly tied to the employer's commercial interests because the messages were deliberately sent to someone close to the employer. Frankfurt's Higher Regional Court then reversed that ruling, holding that the GDPR did not apply because the defendant's forwarding had no professional or economic purpose — even if it was intended to provoke a dismissal.
The BGH took up the case on 30 July. Lawyers and legal observers say the court may refer the question to the Court of Justice of the European Union (CJEU), which has never ruled on the GDPR in the context of messaging apps. Related proceedings are not expected to be decided before September.
What the GDPR's Private-Life Exception Means for Employers and Chat Users
Two Legal Tests for One Set of Messages
The case turns on how the GDPR's private-life exception should be read. As Niko Härting of the German Bar Association put it, the central question is whether judges should consider only the motive of the person who forwards a chat, or whether it is enough that the recipient could use the messages in a professional context. The first-instance court effectively chose the recipient test: because the messages reached the employer's wife, the forwarding was linked to an economic activity. The appeal court chose the sender test: the friend acted in a private dispute, so the GDPR's household exemption applied. Each reading leads to a different answer on compensation.
Why a Referral to the CJEU Would Matter
Härting notes there is little case law from either the BGH or the CJEU on this exemption. The CJEU's 2014 ruling on a surveillance camera that also captured a public pavement touched on the boundary of private processing, and a pending case about a mother filmed with a hidden camera deals with the same area. A referral in the WhatsApp case would give the EU's highest court its first chance to interpret the GDPR in the context of chat apps, setting a standard for all member states rather than leaving the question to national courts.
What Employers Stand to Learn
If the BGH follows the first-instance reasoning, private messages with even a partial link to an employer's interests could fall under the GDPR. That would make the person who forwards such chats potentially liable for damages — the €7,500 award shows the scale a court may set. Employers would also face more uncertainty about when leaked conversations count as work-related data, particularly in small practices like the one in this case, where the recipient of the messages handled administration.
Compensation Remains an Open Question
The second-instance court did not deny that the forwarding was unlawful and intentional; it said the interference was not serious enough to justify damages and that an existing declaration not to repeat the conduct was sufficient. That leaves unresolved how EU courts should value non-material harm under the GDPR, an issue the BGH or the CJEU may clarify if the case proceeds.
What to Watch as the BGH and Possibly the CJEU Rule on Private Messages
For employers, employees and anyone who forwards private chats, the case is a reminder that the legal boundaries are still being drawn. The points below are tied to the court record so far:
- Employers in Germany and across the EU should watch whether the BGH refers the case to the CJEU. A binding ruling on the GDPR's private-life exemption would determine when a forwarded message counts as data processing tied to an economic activity.
- Workers should treat complaints about managers in written chats as potentially discoverable material: in this case, the messages reached the boss's wife and the employee was dismissed soon after. Under the first-instance reasoning, the person who forwards such chats can face a €7,500 damages award.
- Companies running family-based or small practices — where an owner's spouse or relative handles administration — should review how work-related information can flow through personal devices, since the recipient's role was central to the split between the two lower courts.
- Legal teams should track the CJEU's pending hidden-camera case and any referral from the BGH; both touch the same GDPR boundary and are not expected to be decided before September.
Risk & Opportunity Assessment
| Commercial Risk | Medium | A ruling that extends GDPR to privately forwarded chats with a workplace link could create damages exposure for individuals and, indirectly, employers; the first-instance award was €7,500 plus legal costs. |
| Competitive Risk | Low | The case does not change market positions; its main effect would be on compliance obligations rather than on competition between companies. |
| Regulatory Risk | High | The BGH may ask the CJEU to interpret the GDPR's private-life exemption for the first time in a messaging-app context, and the two lower courts have already reached opposite conclusions. |
| Reputation Risk | Medium | Private complaints by a dismissed employee became known to the employer's family, and the case publicly links the employer to leaked messages, highlighting reputational exposure where personal and professional circles overlap. |
| Technology Disruption | Low | WhatsApp and similar apps are not directly at risk, but a CJEU ruling would set the first GDPR precedent for messaging-app data and could force compliance changes for platforms and employers. |
| Commercial Opportunity | Low | Data protection advisers and compliance tooling could see added demand if the ruling clarifies GDPR duties for private messaging, but no direct commercial upside is visible in this dispute. |
Comments 0