CJEU, judgment of 4 October 2024, C-21/23, Lindenapotheke
Order data relating to pharmacy-only medicinal products are data concerning health within the meaning of Article 9(1) GDPR; admissibility of national rules conferring standing on competitors under unfair competition law.
1 Overview
The judgment clarifies two central questions concerning the processing of sensitive data in online commerce: first, under what conditions order data in the trade in medicinal products constitute data concerning health within the meaning of Article 9(1) GDPR; second, whether national law may confer on competitors standing to bring proceedings against data protection infringements on the basis of the principles of unfair competition law.
Reference: CJEU, judgment of 4 October 2024, C-21/23, Lindenapotheke
2 Facts
The operator of the "Lindenapotheke" pharmacy sold medicinal products that are pharmacy-only but not subject to prescription via the Amazon marketplace. A competing pharmacist brought proceedings against that distribution on the basis of the principles of unfair competition law, arguing that the order data contained data concerning health and were processed without the requisite consent.
3 Decision
3.1 Data concerning health also in the case of pharmacy-only medicinal products not subject to prescription
The Court holds that order data are to be classified as data concerning health within the meaning of Article 9(1) GDPR. The combination of identification data (name, delivery address) and the pharmacy-only medicinal products ordered makes it possible (by mental association or inference) to establish a link to the person's state of health. What is decisive is that the product points to therapeutic indications which permit conclusions to be drawn as to the ordering customer's health situation.
That classification applies irrespective of whether the supply of the medicinal product requires a medical prescription. Preparations that are freely available but pharmacy-only may likewise have to be treated as data concerning health where their therapeutic classification permits the conclusions described.
3.2 Consequences for online shops selling pharmacy-only medicinal products
It follows from that classification that order data may be processed only under the conditions laid down in Article 9(2) GDPR. In practice, point (b) (performance of a contract) is ruled out for want of a parallel provision in the list in Article 9(2) GDPR; as a rule, only the following come into consideration:
- Article 9(2)(a): explicit consent, purpose-specific and informed,
- Article 9(2)(h): in so far as there is individual health care and the personnel-related requirements of Article 9(3) (obligation of professional secrecy) are complied with.
3.3 Standing of competitors
The Court holds that the GDPR does not preclude national rules conferring on competitors standing under unfair competition law to bring proceedings against infringements of data protection law. The German Act against Unfair Competition (UWG) may therefore operate as an additional avenue of enforcement alongside enforcement of the GDPR by the supervisory authorities and by individuals asserting their own rights.
4 Significance
The judgment has far-reaching consequences for mail-order and online trade in pharmacy-only medicinal products:
- Consent requirement: online pharmacies must obtain explicit, informed consent under Article 9(2)(a) GDPR before they process order data, in so far as point (h) does not apply.
- Documentation obligations: the heightened requirements under Article 9 GDPR, combined with the documentation and DPIA obligations (Articles 30 and 35 GDPR), also apply to electronic commerce in freely available medicinal products.
- Enforcement by competitors: the range of actors exercising control expands, because competitors can challenge infringements of data protection law as unfair commercial practices under competition law.
The judgment thus forms a central building block of the case law on the scope of Article 9(1) GDPR in the case of data-driven business models in the health sector.
About the author
About the author
This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.
Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.
According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.
Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.
His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.
For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.
CJEU, judgment of 4 October 2024, C-446/21, Schrems/Meta
Scope of the concept of sensitive data under Article 9 GDPR in the context of advertising on social networks; restrictive interpretation of Article 9(2)(e) and obligation to impose a time limit on the processing.
CJEU, judgment of 7 December 2023, C-634/21, SCHUFA Holding (Scoring)
Automated decisions and profiling under Article 22 GDPR; limits of Member State implementation under Article 22(2)(b) GDPR; the balancing of interests must not be pre-empted.