Data Protection HubCase Law

CJEU, judgment of 25 November 2021, C-102/20, StWL Städtische Werke Lauf a.d. Pegnitz

Concept of direct marketing under the ePrivacy Directive; advertising displayed in an email inbox in the guise of messages constitutes direct marketing and requires consent.

1 Overview

A competitor of Städtische Werke Lauf a.d. Pegnitz placed advertising in the inboxes of a free-of-charge email service which visually resembled emails but was designed as an inbox insert. The German Federal Court of Justice (BGH) referred questions to the CJEU on the classification of that form of advertising under Article 13(1) of the ePrivacy Directive 2002/58/EC.

2 Headnotes

Advertising is to be classified as direct marketing within the meaning of Article 13(1) of the ePrivacy Directive where it pursues a commercial purpose and is directed at a consumer directly and individually (paras. 47 et seq.).

It is irrelevant whether the advertising is addressed to an individually determined person or is sent out in bulk to a large number of recipients (para. 50).

Advertising displayed in the guise of messages in the private email inbox of a user of an advertising-financed, free-of-charge email service constitutes direct marketing within the meaning of Article 13(1) of the ePrivacy Directive and requires prior consent (paras. 50 et seq.). The list of means of communication set out in Article 13(1) and in Recital 40 is not exhaustive.

3 Significance

The decision extends the concept of direct marketing to modern forms of online advertising. It is at the same time a building block for the application of Article 6(1)(f) GDPR in the advertising context: where the ePrivacy Directive requires consent, point (f) is as a rule no longer available for the underlying data processing.

About the author

About the author

This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.

Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.

Follow me on LinkedIn