Data Protection HubCase Law

German Federal Administrative Court (BVerwG), judgment of 27 March 2019, 6 C 2/18

Article 6(1)(e) GDPR does not apply to private parties in the absence of an act conferring public authority; requirements for the national legal basis.

1 Overview

In this decision, the German Federal Administrative Court (BVerwG) made fundamental statements on the applicability of Article 6(1)(e) GDPR to private parties and on the requirements for national legal bases. The background was video surveillance operated by a dental practice.

Reference: BVerwG, judgment of 27 March 2019, 6 C 2.18, NJW 2019, 2556

2 Activity comparable to that of a public authority and act of conferral

Private parties may rely on Article 6(1)(e) GDPR only where the power to process personal data in the public interest or in the exercise of official authority has been conferred on them. That presupposes an act of conferral by the state, in whatever form it may take. The mere de facto pursuit of public interests is not sufficient.

National rules must be clear and precise. Article 6(1)(e) GDPR does not provide for an additional balancing against the interests of the data subjects; the national legislature may not make up for this by means of general catch-all clauses. The dividing line between the legal bases under points (c) and (e) on the one hand and the balancing of interests under point (f) on the other must not be blurred.

4 Consequences for § 4 of the German Federal Data Protection Act (BDSG)

The decision has the consequence that § 4 BDSG, in its former version, is not a tenable legal basis for private video surveillance of publicly accessible spaces. Private controllers must instead rely on Article 6(1)(f) GDPR and carry out the balancing of interests in the individual case.

About the author

About the author

This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.

Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.

Follow me on LinkedIn