Data Protection Case Law in Mecklenburg-Vorpommern: Structural Lessons for DACH Controllers

5 min readLast updated By Philipp Staiger

Procedural context: administrative court review in MV

In Mecklenburg-Vorpommern, decisions of the State Commissioner for Data Protection and Freedom of Information (LfDI MV) are challenged at first instance before the Administrative Court of Schwerin and on appeal before the Higher Administrative Court of Mecklenburg-Vorpommern in Greifswald. Based on the published decision text, the administrative courts have in recent years repeatedly taken position on the scope of supervisory orders under Art. 58(2) GDPR.

Dr. M. Hofstetter classifies these proceedings within the broader context of German administrative case law. Unlike with preliminary references pending directly before the CJEU, the national administrative courts develop the GDPR in interplay with the supervisory authorities. As at the time of publication, proceedings on technical and organisational measures under Art. 32 GDPR, on the reach of the accountability principle under Art. 5(2) GDPR and on the proportionality of supervisory orders are of particular practical relevance. A systematic presentation of the underlying duties is set out in our GDPR guide.

Fine, order and decision: terminological precision

German administrative case law places value on a precise distinction between the supervisory instruments. The fine under Art. 83 GDPR covers the administrative fine and is imposed by way of a fine notice (Bussgeldbescheid); under the German Administrative Offences Act (OWiG) an objection lies to the competent local court (Amtsgericht). The order under Art. 58(2)(d) GDPR is a corrective measure; it is issued by way of administrative act and can be challenged before the competent Higher Administrative Court (OVG). The decision as a generic term covers the administrative act in its entirety, including the reasoning and the information on legal remedies.

For controllers this distinction is not a legal detail but determines the correct remedy and the time limit for bringing an action. Controllers that confuse a fine notice with an order and pursue the wrong procedural route risk the contested measure becoming final. The proceedings in Mecklenburg-Vorpommern confirm that the courts review the jurisdictional boundaries strictly.

Technical and organisational measures under Art. 32 GDPR

A recurring focus of review concerns the appropriateness of the technical and organisational measures under Art. 32(1) GDPR. The administrative courts regularly examine whether the controller has carried out a documented risk analysis and, on its basis, derived concrete measures. A blanket reference to the state of the art is not sufficient; the measures must be justified in a risk-adequate manner.

A. Brunner classifies this line from the perspective of an ISO 27001 lead auditor. In practice, a two-tier architecture has proved effective. First, a data protection impact assessment under Art. 35 GDPR documents the risks of the respective processing. Second, the information security management system under ISO/IEC 27001 translates the derived measures into an auditable control set, in particular taking into account Annex A of ISO/IEC 27001:2022. This integration creates the evidentiary basis regularly required in administrative court proceedings. For further detail see our ISO 27001 guide.

Accountability and the documentation burden

The accountability principle under Art. 5(2) GDPR in conjunction with Art. 24(1) GDPR allocates the burden of proof for conformity to the controller. The administrative courts have confirmed in several proceedings that, while the supervisory authority must investigate under its duty of clarification pursuant to Art. 57(1)(h) GDPR, the controller carries active evidentiary duties.

Three documentation levels are practically relevant. First, the Records of Processing Activities (ROPA) under Art. 30 GDPR, which set out the processing purposes, legal bases, categories of recipients and retention periods. Second, the data protection impact assessments under Art. 35 GDPR for high-risk processing. Third, the data processing agreements under Art. 28 GDPR, including the technical and organisational measures agreed therein. Controllers that maintain these three levels in a current and consistent state have a considerable advantage in supervisory proceedings.

Proportionality of supervisory orders

A central level of review by the administrative courts is the proportionality of supervisory orders. Orders under Art. 58(2) GDPR must be suitable, necessary and appropriate. The courts examine in particular whether milder means would have been available and whether the implementation deadline set is realistic.

For controllers this review level opens up concrete defence strategies. Anyone who, in the hearing procedure under Section 28 VwVfG, sets out in substantiated form which measures have already been implemented and which deadlines are required for further implementation can significantly influence the subsequent order. Blanket denials are regularly unpromising. The proceedings from Mecklenburg-Vorpommern confirm that a cooperative but substantiated conduct of the proceeding is the most effective protection against overreaching orders.

What this means for Swiss companies

K. Aebischer brings the perspective of a Swiss SME CISO. Swiss controllers are affected in two constellations. First, where they fall within the scope of the GDPR under Art. 3(2) GDPR and are responsible for processing activities in Germany. In this case the lead supervisory authority under Art. 56 GDPR may be the competent German state authority, in the case of Mecklenburg-Vorpommern the LfDI MV. Second, where they act as processors for a German controller and are drawn into the scope via the contractual chain.

In parallel, the Swiss DSG (Federal Act on Data Protection / FADP), which entered into force on 1 September 2023, applies. Art. 8 DSG requires appropriate technical and organisational measures; Art. 22 DSG governs the data protection impact assessment; Art. 12 DSG requires Records of Processing Activities. These duties are largely congruent with the GDPR requirements but differ in detail. A comparative overview is provided in our DSG guide (German-language pillar).

Implementation duties for DACH clients

Four concrete implementation duties for DACH clients can be derived from the administrative court proceedings in Mecklenburg-Vorpommern. First, controllers should review their ROPA under Art. 30 GDPR for completeness at least annually and document changes in versioned form. Second, data protection impact assessments should not be treated as one-off documents but as living documents that are updated on material changes to the processing.

Third, technical and organisational measures should be documented along a recognised framework such as ISO/IEC 27001 or the BSI Grundschutz, so that the controller can refer to an auditable structure in proceedings. Fourth, an escalation plan for supervisory proceedings should exist, governing the hearing under Section 28 VwVfG, the deadlines for legal remedies and the internal allocation of responsibility. N. Köhler notes that a concise, precise submission in the hearing procedure often achieves more than an extensive but imprecise account.

How SIDD supports you

SIDD supports controllers in preparing for supervisory proceedings and in audit-ready documentation of data protection compliance. In our mandate as external DPO under GDPR Art. 37 we take responsibility for the ongoing monitoring of conformity and the communication with the German state supervisory authorities. In our mandate as Swiss data protection advisor under Art. 10 DSG we manage the parallel Swiss duties under the DSG.

For controllers without an establishment in the Union we provide the EU Representative under Art. 27 GDPR. This function is especially relevant in proceedings of German state authorities, since reachability of the responsible entity in the Union is a central criterion for communication with the authority. A comparative consideration of the roles DPO and CISO is set out in our overview DPO vs. CISO; on the question of the EU Representative see our comparison EU vs. UK Representative.

Data Protection Case Law in Mecklenburg-Vorpommern: Structural Lessons for DACH Controllers

INSIGHT

All
13 May 2026
Philipp Staiger
Administrative court proceedings between controllers and supervisory authorities in Mecklenburg-Vorpommern concretise the requirements for GDPR implementation. The article situates the structural lessons and transfers them to DACH practice.

Subscribe to our newsletter for free here

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.