
Assignment of the
right to access
Under the GDPR.
Assignment of the
right to access
Under the GDPR.
of
Does the right to access information under data protection law automatically transfer to a company that purchases claims from consumers? And does it help if this company, as an alternative, invokes a power of attorney to assert the claim in its own name?
A Swiss company is requesting information from a health insurance provider
The plaintiff in this case is a stock corporation based in Switzerland whose business model consists of having consumers assign their claims against their contractual partners to the company through the purchase of receivables, in order to subsequently assert those claims in its own name.
In 2021, the plaintiff entered into identical contracts with six policyholders. These policyholders held corresponding policies with the defendant, a provider of private health and long-term care insurance. In the plaintiff’s view, the defendant had invalidly increased the premiums on multiple occasions in the past. The contracts between the plaintiff and the policyholders expressly distinguished between two types of claims. On the one hand, the policyholders assigned to the plaintiff “all claims for reimbursement and damages” in connection with overpaid premiums. On the other hand, they merely authorized the plaintiff to assert all claims for information and data transfer necessary for enforcement, while only the claims for damages arising in the event of non-fulfillment of these claims were separately assigned. As a purely alternative measure, the policyholders also authorized the plaintiff to enforce the aforementioned claims in its own name.
What the parties were disputing in court
On this contractual basis, the plaintiff initially requested information regarding the amount of premium revenue generated by the respective health insurance plans for the six policyholders for various years between 2010 and 2018. In bringing its action, the Swiss company proceeded by way of a staged lawsuit, meaning it first sought information in order to subsequently claim a specific amount. The aim was to establish that certain premium increases were invalid and to enforce a claim for payment, the exact amount of which was yet to be determined.
The Regional Court dismissed the action for disclosure as unfounded and ruled that some of the additional claims were inadmissible. The Hamm Higher Regional Court upheld this ruling and dismissed the plaintiff’s appeal. For the appeal to the Federal Court of Justice, the Hamm Higher Regional Court allowed only the question of whether the plaintiff is entitled to a right to information under the GDPR.
The decision of the Federal Court of Justice
The Federal Court of Justice dismissed the plaintiff’s appeal in its ruling of February 24, 2026—Case No. VI ZR 430/24. The Federal Court of Justice ultimately confirmed that the plaintiff has no right to information under the GDPR, neither by virtue of an assigned right nor by way of a so-called “voluntary representative action.” This refers to a situation in which a person asserts another person’s claim in court in their own name based on a power of attorney.
Why the Right to Information Is Not Merely an Ancillary Right
A central argument of the Federal Court of Justice concerns the legal nature of the right to information itself. Under the German Civil Code, the assignment of a claim entails not only the transfer of the claim itself, but also certain ancillary rights necessary for its enforcement, such as classic claims to information and accounting. The plaintiff argued that the right to information under data protection law is such an ancillary right and therefore automatically passed to her along with the assigned claims for reimbursement and damages.
The Federal Court of Justice has rejected this view. The right to information under data protection law serves a different purpose than traditional ancillary rights, which are intended solely to determine the subject matter and amount of a principal claim.
The right under Article 15 of the GDPR was not established to enable the data subject to enforce a (primary) claim, but rather to ensure that the data subject is aware of the processing of their data and can verify its lawfulness.
In practice, this means that the purpose of the right to access—namely, to provide the data subject with transparency regarding the processing of their own data—cannot be achieved if an outside third party requests the information. In the Senate’s view, the nature of the disclosure would be altered if the request were made not by the data subject themselves, but by a company not involved in the data processing.
Why the Contract Wording Did Not Cover an Assignment
Regardless of this general consideration, the plaintiff’s claim failed already on the basis of the specific interpretation of the contracts. The contracts expressly distinguished between the two types of claims mentioned. According to the wording, only the claims for reimbursement and damages were assigned. With regard to the claims for information and data transfer, however, the plaintiff was merely authorized to assert them.
The appellate court had not made any findings of its own on this matter but had merely assumed that the rights to information had been assigned. The Federal Court of Justice therefore interpreted the contract itself and reached an unambiguous conclusion. According to the clear wording of the agreement, there is no apparent reason why the rights to information under data protection law should also be covered by the assignment, even though the contract elsewhere clearly and deliberately treats these rights differently from claims for reimbursement and damages.
Nor did the power of attorney to act as a representative in litigation have any bearing on the matter.
Since an assignment was ruled out, the Federal Court of Justice examined, as an alternative, whether the plaintiff could in any event assert the right to information in her own name by way of a discretionary representative in litigation, based on the contractual power of attorney. The Senate rejected this as well. According to the structure of the agreement, the wording stating that the plaintiff had been authorized “purely as a matter of convenience” to enforce claims in her own name referred exclusively to the assigned claims for reimbursement and damages. The concept of “enforcement” appeared in the contract only in connection with these claims, not in connection with the claims for information and data transfer.
The Senate also pointed out an internal contradiction. It would be difficult to understand why, on the one hand, the plaintiff would be authorized to assert claims for information on behalf of another party, while, on the other hand, she would be authorized—without any apparent prerequisite—to assert the same claims once again in her own name. No condition under which this alternative authorization would apply could be inferred from the agreement.
What does this mean in practice?
What is important is what the Federal Court of Justice expressly left open. The decision does not state that the right to access information under data protection law is, as a matter of principle, non-transferable. The Senate left this question open due to its irrelevance to the decision and merely noted that the Federal Administrative Court had ruled against transferability in another decision. Nor did the Federal Court of Justice rule that arbitrary standing to sue is generally precluded under data protection law. The decision is based on the specific, narrowly worded contractual provisions in this particular case.
For companies that themselves are the recipients of requests for information under assignment-based legal tech or debt collection models, the ruling thus provides a checklist, not a blank check. As we have already shown in an earlier post on abusive GDPR requests, it is worth taking a close look at the claimant’s standing before disclosing any information.
Conclusion
A careful reading of the agreement made it quite clear that such a vaguely worded contractual clause would not hold up in court. Nevertheless, the ruling is a major setback for the plaintiff’s specific business model because it simultaneously precludes two potential grounds for a claim.
This decision is particularly beneficial for companies that are subject to data protection-related requests for information from assignment companies. It provides them with an additional, court-confirmed line of defense.
The fundamental question remains as to whether the right to access information under data protection law is assignable at all, and whether a representative action could be valid in data protection law in cases phrased differently.
We’d be happy to
you on
Data protection law!







