German Court Rejects DPA’s Appeal, Finds Irish Law Applicable to Facebook in Germany
Time 2 Minute Read

On April 22, 2013, the higher administrative court of Schleswig issued two decisions rejecting an appeal by the data protection authority of Schleswig-Holstein (“Schleswig DPA”) that sought to challenge a lower court’s earlier rulings in Facebook’s favor.

These decisions provide useful clarification regarding how national data protection law applies when an international business maintains several legal entities in different EU member states. The end result is that Facebook’s German operations need only comply with Irish data protection law – the company’s German marketing and advertising business (which is incorporated as a separate German legal entity) was not considered a sufficient presence to warrant the application of German data protection law.

The proceedings focused primarily on whether Irish or German national data protection laws apply to Facebook’s operations in Germany. In December 2012, the Schleswig DPA issued orders against Facebook Inc. in the U.S. and Facebook Ltd. in Ireland, in which the DPA demanded that Facebook allow its German users to use pseudonyms. In the orders (and subsequent challenges), the Schleswig DPA advanced six separate arguments as to why German data protection law applied to Facebook’s operations in Germany such that Facebook must allow the use of pseudonyms in accordance with German data protection law.

Facebook won its first challenge to these orders in the regional administrative court of Schleswig, then successfully defeated the Schleswig DPA’s appeal to the higher administrative court of Schleswig to overturn the lower court’s decisions.

You May Also Be Interested In

Time 2 Minute Read

On February 23, 2026, a Joint Statement on AI-Generated Imagery was published by 61 data protection authorities. The Joint Statement addresses concerns regarding AI systems capable of generating realistic images and videos depicting identifiable individuals without their knowledge or consent.

Time 6 Minute Read

On February 9, 2026, trade association NetChoice filed a lawsuit challenging South Carolina’s newly passed Age-Appropriate Code Design (“SC AACD”) on First and Fourteenth Amendment grounds. The SC AACD was signed into law on February 5, 2026, making South Carolina the fifth U.S. state to enact such a law, following California, Maryland, Nebraska and Vermont.

Time 4 Minute Read

On January 20, 2026, the European Commission proposed a comprehensive new cybersecurity package aimed at strengthening the EU’s cybersecurity resilience and enhancing its capacity to manage evolving threats.

Time 5 Minute Read

On November 19, 2025, the European Commission unveiled the much-anticipated digital omnibus legislative package (the “Digital Omnibus”), setting the stage for a new era of digital governance and regulatory simplification across the European Union. According to the Commission, this initiative is designed to enable European businesses to devote more energy to innovation and growth, rather than navigating complex compliance landscapes.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page