NEWSLETTER REGULATORY UPDATE

Health Data and the GDPR in Workplace Chats: When a Diagnosis Becomes “Information for Everyone”

A WhatsApp group for scheduling shifts, an annoyed comment about covering someone’s shift, and, right in the middle of it all, the diagnosis of a sick coworker: The Siegburg Labor Court views this as a violation of the GDPR that justifies an injunction and damages. The defendant must personally pay 1,000 euros, because a chat group does not become private simply because it was created as a private group.

Health Data and the GDPR in Workplace Chats: When a Diagnosis Becomes “Information for Everyone”

A WhatsApp group for scheduling shifts, an annoyed comment about covering someone’s shift, and, right in the middle of it all, the diagnosis of a sick coworker: The Siegburg Labor Court views this as a violation of the GDPR that justifies an injunction and damages. The defendant must personally pay 1,000 euros, because a chat group does not become private simply because it was created as a private group.

Teilen Sie diesen Beitrag:

Teilen Sie diesen Beitrag:

The Case: A Sick Note, a Chat Group, Two Diagnoses

At a hospital, there was a WhatsApp group called “Ärzte-AC” with nine members from the General Surgery Department. In addition to personal topics, the group was primarily used to coordinate vacation plans, sick leave, and shift coverage. The group was thus part of the workplace communication.

When a resident called in sick for his weekend shift after conducting an internal medicine examination in the emergency room, the ward physician in charge had to step in at short notice. Frustrated that her weekend getaway had been ruined, she posted a detailed message in the group chat two days later. She not only expressed her frustration but also shared her colleague’s lab results and diagnoses—including fatty liver associated with obesity—and smugly questioned whether he actually had a real medical condition at all.

The affected colleague demanded that further data transfers be stopped and sought damages. In the fall of 2025, he resigned from his position. The incident was cited as one of the contributing factors.

The Decision of the Siegburg Labor Court

The court largely ruled in favor of the plaintiff. The ward physician was prohibited from disclosing the plaintiff’s health data without his consent in the future. In addition, she must pay 1,000 euros in compensation for non-pecuniary damages; the amount sought was 2,000 euros. She is responsible for 78 percent of the litigation costs, while the plaintiff is responsible for 22 percent. The court set the amount in dispute at 4,500 euros.

Legally, the claim for an injunction is based on Section 1004(1) of the German Civil Code (BGB) by analogy in conjunction with Section 823(2) BGB and the GDPR as the protective statute; the claim for payment is based on Article 82(1) of the GDPR.

WhatsApp Groups, Privacy, and the Issue of Personal Use

The central issue was whether the GDPR applied to the chat group at all. The defendant had argued that the group was purely private—used for work purposes only for the sake of convenience—and thus constituted a privileged personal activity under Article 2(2)(c) of the GDPR. The household exception, the GDPR, and the professional connection are directly linked in this case. The exception applies only to processing carried out exclusively for personal or family purposes.

The court did not agree. The very name and composition of the group—which consisted exclusively of colleagues from a single department—suggested a professional connection. Furthermore, since—according to the defendant’s own statement—at least 30 percent of the content was work-related and the specific message itself had a clearly work-related context, the scope exception did not apply. Mixed processing for both private and professional purposes is not exempt.

Practical implication: A chat group does not become a private space simply because it was created privately or contains predominantly private content. The decisive factor is whether it actually serves the purposes of the company’s operations. This is typically the case with groups for work schedules, cover arrangements, and sick leave notifications, and therefore the General Data Protection Regulation applies.

Employee Data Protection and the Question of Who Is Responsible

The court also clearly addressed the issue of liability under data protection law. In the context of employee data protection, the principle applies that employees who process data as part of their work are not themselves data controllers within the meaning of Article 4(7) of the GDPR. That role is typically assumed by the employer.

However, anyone who uses their official position merely as a pretext to disclose sensitive health information—whether out of curiosity or to embarrass a colleague—is pursuing their own agenda and acting outside the scope of their assigned duties. In this so-called “excess,” the person acting becomes the data controller and is personally liable. The court found that the disclosure of the medical details was neither necessary nor reasonable. The phrase “just for everyone’s information” demonstrated the individual’s own motive.

For employees, this has clear consequences. Anyone who uses work-related channels to disseminate personal information about coworkers is personally liable in case of doubt, regardless of whether the employer is aware of it or has approved it.

Health Data, the GDPR, and the Prohibition Subject to Permission under Article 9 of the GDPR

In this case, there was a clear violation of Article 9(1) of the GDPR. Diagnoses and laboratory test results constitute health data within the meaning of Article 4(15) of the GDPR and thus fall under the category of data that the GDPR designates as special categories of personal data. A general prohibition on processing applies to them, subject to specific exceptions. Processing is permitted only if one of the narrowly defined exceptions under Article 9(2) of the GDPR applies. None of these exceptions were met in this case. There was neither consent from the data subject, nor was the disclosure necessary for medical treatment, nor had the data subject apparently made the information public himself. The fact that he had announced his sick leave in the same group did not change this, because a sick leave notice does not constitute disclosure of the underlying diagnosis. This highlights the core of the issue: health data, the GDPR, and the legal basis. It is not sensitivity alone that makes the difference, but the absence of a legal basis for processing.

GDPR Damages under Article 82 of the GDPR

For GDPR damages under Article 82 of the GDPR, the court held that the loss of control over one’s own health data was sufficient. The disclosure of the data to seven unauthorized third parties was sufficient; no additional proof of tangible negative consequences was required. In addition, the plaintiff suffered a loss of standing among his colleagues due to the insinuation that he was not truly unable to work.

Compensation for non-economic damages, the GDPR, and calculation: Two factors had opposing effects on the determination of the 1,000-euro amount.

  • This is compounded by the particularly sensitive nature of the diagnoses and lab results, as well as the credible account of the stress that contributed to the termination.
  • Mitigating factors include the limited number of recipients—seven people—and the fact that only individual pieces of information were disclosed, rather than complete medical records.

The decision is thus in line with recent case law. Not every violation automatically results in damages, but the loss of control over particularly sensitive data can, in and of itself, constitute a claim for damages.

Injunction, GDPR, and Risk of Repetition

The reasoning behind the claim for injunctive relief is noteworthy. Although the plaintiff had left the clinic and the chat group, the court affirmed the existence of the required risk of recurrence, in part because the defendant continues to work as a doctor at the hospital and could treat the plaintiff there again. Another decisive factor was that she remained unrepentant throughout the proceedings and continued to believe her conduct was lawful.

This sends a clear signal for legal practice. A lack of remorse following a data protection incident significantly weakens one’s own position, and a claim for injunctive relief may still exist even if the specific circumstances no longer exist.

Health Data, Employers, and Sick Leave in Everyday Work Life

This case draws attention to a question that constantly arises in everyday work life: What health information is an employer actually allowed to know? The principle is clear: When reporting sick leave, it is sufficient to provide information about the inability to work and its expected duration. Diagnoses, medical findings, and lab results are not included. When it comes to sick leave, data protection, and scheduling, the statement “unavailable” is therefore sufficient, and the medical reason is irrelevant.

Where health data and employers inevitably intersect—such as in workplace reintegration management, occupational health examinations, or workplace health management—there must be clearly defined responsibilities, a legal basis, and a restricted group of recipients. An open group chat does not meet any of these requirements.

Data Protection, Hospitals, Employees: What Needs to Be Addressed Now

Data protection, hospitals, and employees are a particularly sensitive combination. In day-to-day hospital operations, employees come across health data on a daily basis, and informal communication via messaging apps is particularly widespread in this setting because it is fast and convenient. Here are six points worth considering.

  • Establish clear guidelines regarding which channels may be used to exchange work-related information and what types of content are not permitted there.
  • Organize absences and cover arrangements through a system or a designated office, not through open groups.
  • Do not include diagnoses in distribution lists. Make it clear that diagnoses, lab results, and treatment information are to be exchanged exclusively among the professionals responsible for them.
  • Training and awareness-raising. Use this case as a training example, as it is illustrative and makes personal liability tangible.
  • Define how an incident is reported internally and who conducts the assessment in accordance with Articles 33 and 34 of the GDPR.
  • Document guidelines, training records, and incident responses, because in the event of a dispute, this serves as proof of organizational diligence.

What Those Affected Can Do

Anyone who learns that their personal health data has been disclosed without authorization may demand that such disclosure cease and, if appropriate harm has been caused, claim compensation for non-pecuniary damages under the GDPR. It is advisable to document the incident—for example, by taking timestamped screenshots that specify the recipients—and to raise the issue with your employer or the data protection officer. Additionally, you may file a complaint with the competent supervisory authority under Article 77 of the GDPR.

Conclusion

The ruling is not yet final. It remains to be seen whether the defendant will file an appeal with the Cologne Regional Labor Court. Regardless, the takeaway for everyday practice is clear: Health data does not belong in colleague chats. For organizations in the healthcare sector, it is worthwhile not to leave informal communication channels to chance, but rather to clearly regulate, train staff on, and document them.

FAQ: Frequently Asked Questions About the GDPR and Health Data

According to Article 4(15) of the GDPR, health data refers to any personal data related to a person’s physical or mental health that reveals information about their state of health. This includes diagnoses, laboratory results, medical findings, and treatment information. These constitute special categories of personal data and are subject to the processing prohibition under Article 9 of the GDPR.

No. To report sick, it is sufficient to provide information about your inability to work and its expected duration. The diagnosis is not required and does not have to be disclosed even if requested. The principle of data minimization applies to health data, employer information, and sick leave reports.

The household exception applies only if a group serves exclusively personal or family purposes (GDPR, Art. 2(2)(c)). As soon as a group serves even partially for business purposes—such as scheduling shifts or reporting sick leave—the General Data Protection Regulation applies. In the case at hand, approximately 30 percent of the group’s content was work-related.

As a general rule, the employer is the responsible party. However, if an employee acts for their own purposes outside the scope of their assigned duties—for example, to humiliate a colleague—this constitutes an abuse of authority. In such cases, the employee who acted becomes the controller under Article 4(7) of the GDPR and is personally liable for injunctive relief and damages.

The amount is determined on a case-by-case basis. In the case at hand, it was 1,000 euros for a claim of 2,000 euros. For non-pecuniary damages (GDPR, Art. 82), the court considered the loss of control over the health data to be sufficient grounds. The humiliation served as an aggravating factor, while the small group of recipients and the limited scope of the information disclosed served as mitigating factors.

A claim for injunctive relief requires unlawful data processing and a risk of recurrence. It may also exist even if the specific situation no longer exists. In the case at hand, the court affirmed the risk of recurrence even though the plaintiff had left the clinic and the chat group, because the defendant continued to consider its conduct lawful.

Document the incident, contact your employer or the data protection officer, and explore your options for seeking injunctive relief and damages. In addition, you may file a complaint with the relevant supervisory authority under Article 77 of the GDPR.

This must be assessed on a case-by-case basis. If there has been a breach of personal data protection within the employer’s sphere of responsibility and there is a risk to the data subject, the reporting obligation under Article 33 of the GDPR applies within 72 hours. In cases of high risk, the data subject must also be notified in accordance with Article 34 of the GDPR. If an employee acts in excess of their duties and outside the scope of business purposes, liability must be carefully assessed. The data protection officer should conduct this assessment and document it.

Contact Us

Are you planning to bring a medical device to market and looking for an experienced authorized manufacturer? Contact us for a no-obligation consultation. Together, we’ll develop the right strategy for your medical device.

More exciting news for you

  • 24. June 2026

    The End of Article 82 of the MDR? Why AI and Software Are Now Taking Center Stage

  • 24. June 2026

    MDR and Medical Devices with Indirect Clinical Benefits: Why a More Nuanced Assessment of Evidence Is Needed

  • 17. April 2026

    The right to treatment with artificial intelligence and access to smart medical devices – potential challenges