German Court Rules on Consent Verification Requirement for Email Marketing
Time 1 Minute Read

On November 3, 2009, the Higher Regional Court of Düsseldorf (OLG Düsseldorf, Az. I-20 U 137/09) ruled on the duty to verify consent for email marketing with respect to purchased email addresses. According to the Court, a company that purchases email addresses for marketing purposes must verify customer consent itself – the company cannot rely on a data broker’s statement that it obtained the necessary consents.

This decision came in an interim injunction proceeding to cease unsolicited email marketing. The Court ruled in favor of the claimant, finding that the company failed to take necessary measures to verify consent.  The claimant was able to obtain injunctive relief against the defendant under Sections 8 (1), (3), 3 (1) and 7 (2) No. 3 of the Unfair Competition Act.  The Court specified that the defendant did not have a duty to verify individual consents by phone, but could conduct verification by reviewing the stored data of each customer.  Since the law requires "explicit" customer consent to use email addresses for marketing, consents must be documented on a regular basis to be considered valid.

Tags: Email, Germany

You May Also Be Interested In

Time 2 Minute Read

On November 6, 2024, a Texas state district court jury found that a large e-discovery vendor violated Title 7, Chapter 33 of the Texas Penal Code, which provides that accessing a computer without its owner’s permission is a Class B misdemeanor. This case highlights the importance for e-discovery vendors of considering data privacy and security requirements in the course of discovery proceedings.

Time 1 Minute Read

On February 28, 2024, the European Data Protection Board (“EDPB”) announced the launch of its latest Coordinated Enforcement Framework action on the right of access. Through the course of 2024, 31 data protection authorities across the European Economic Area, including seven German state-level authorities, will take part in this initiative on the implementation of the right of access. The EDPB selected the right access for its third coordinated enforcement action as it is “at the heart of data protection,” is a right that is very frequently exercised by individuals, and one that is often the basis of complaints to authorities.

Time 2 Minute Read

On December 7, 2023, the Court of Justice of the European Union (“CJEU”) ruled that credit scoring constitutes automated decision-making, which is prohibited under Article 22 of the EU General Data Protection Regulation (“GDPR”) unless certain conditions are met. In a case stemming from consumer complaints against German credit bureau SCHUFA, the CJEU found that the company’s reliance on fully automated processes to calculate creditworthiness and extend credit constitutes automated decision-making which produces a legal or similarly significant effect within the meaning of Article 22 of the GDPR.

Time 4 Minute Read

National Labor Relations Board General Counsel Jennifer Abruzzo recently asked the National Labor Relations Board (“Board”) to overrule its decision in Caesars Entertainment d/b/a Rio All-Suites Hotel and Casino, 368 NLRB No. 143 (2019) (“Rio All-Suites”). The Rio All-Suites Board overruled the Board’s prior decision in Purple Communications, Inc., 361 NLRB 1050 (2014) (“Purple Communications”), which in turn overruled the Board’s decision in Register Guard, 351 NLRB 1110 (2007). All three cases deal with whether the National Labor Relations Act (“Act”) gives employees the right to use an employer’s email systems to engage in union and other protected concerted activities.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page