Incorrect SCHUFA entry: When is you entitled to damages under the GDPR?


Can an early or unfounded SCHUFA entry lead to a claim for damages?
The Federal Court of Justice (BGH) has ruled in a principle decision: Yes, if the entry causes demonstrable disadvantages or the loss of control over one’s own data has already occurred. The ruling of May 13, 2025 (Case No.: VI ZR 67/23) lowers the hurdles for those affected and significantly increases the liability risk for reporting companies.
The case: Premature SCHUFA notification with serious consequences
An enforcement agency reported a titled claim to the SCHUFA, even though the debtor’s right of appeal was still running. The affected person claimed that the resulting negative SCHUFA entry had massive economic consequences for him, including the loss of credit cards and the failure of a real estate financing. He sued for 5,000 euros in damages under Art. 82 GDPR. After the Higher Regional Court of Koblenz had dismissed his claim, he appealed to the BGH.
The BGH's decision: Loss of control over data is already damage
The BGH reversed the decision of the Koblenz Higher Regional Court and made clear that the requirements for an intangible GDPR damage cannot be set too high. The BGH’s key findings are groundbreaking:
- Damage does not have to be „serious“, but specifically: The plaintiff had sufficiently substantiated the loss of his credit cards and the impending termination of business relationships with concrete disadvantages. A high materiality threshold, as the Higher Regional Court set it, is not required.
- The „loss of control“ over data is a separate type of damage: This is the crucial point of the judgment. The BGH emphasized that the mere fact that personal data were unlawfully disclosed to third parties (here, SCHUFA) can constitute immaterial damage in the form of „loss of control.“ Therefore, affected individuals do not necessarily have to prove that a loan has been lost. The unlawful disclosure in itself is the damage.
Implications for companies
SCHUFA record & GDPR damages compensation – What you need to know
Conclusion: BGH strengthens consumer rights and increases pressure on companies
The BGH’s ruling is a clear signal: careless or flawed handling of data reporting to credit bureaus will no longer be tolerated. Recognizing „loss of control“ as a separate form of damage opens the door to a new wave of GDPR damages claims. For companies, this means that compliance with strict reporting requirements and accurate process documentation are more important than ever.
FAQ
Can a false or premature SCHUFA entry trigger a claim for damages under the GDPR?
Yes. According to the judgment of the Federal Court of Justice described in the article, a claim for damages can be made if the unlawful disclosure caused concrete disadvantages or a loss of control over personal data has already occurred.
What does „loss of control“ over personal data mean?
It refers to the unlawful transfer of personal data to third parties, which results in the affected person losing control over its use. According to the article, even this loss of control can constitute immaterial damage within the meaning of Article 82 GDPR.
Do the affected individuals have to prove particularly serious damage?
No. According to the decision outlined in the article, a high materiality threshold is not required. However, the damage must be specifically demonstrated. In the underlying case, the loss of credit cards and the impending disadvantages in business relationships were cited, among other things.
Who is liable for an unlawful report to the SCHUFA?
Under the article, the reporting company is generally responsible for unlawful transmission as the data protection controller. This can, for example, apply to banks, telecommunications companies, energy providers, or online retailers.
When is an open claim to SCHUFA to be reported?
The requirements are strict. The article specifically states that the claim must be undisputed in principle, the debtor must have been repeatedly warned, and certain time requirements must be met. Before making any report, the legal requirements should be carefully examined.
What should companies take into account organizationally when dealing with SCHUFA reports?
Companies should establish clear review and approval processes and document each notification in a comprehensible manner. Before submitting any information, it is essential to verify that all legal requirements are met and that the underlying claim can actually be reported.
- Can an early or unfounded SCHUFA entry lead to a claim for damages?
- The case: Premature SCHUFA notification with serious consequences
- The BGH's decision: Loss of control over data is already damage
- Implications for companies
- SCHUFA record & GDPR damages compensation – What you need to know
- Check the mandatory fields – step by step in the webinar
- FAQ
- Can a false or premature SCHUFA entry trigger a claim for damages under the GDPR?
- What does „loss of control" over personal data mean?
- Do the affected individuals have to prove particularly serious damage?
- Who is liable for an unlawful report to the SCHUFA?
- When is an open claim to SCHUFA to be reported?
- What should companies take into account organizationally when dealing with SCHUFA reports?
- FAQ



