AI and Processing of Personal Data: the Ruling of the Cologne Court of Appeal

On 23 May 2025, the Cologne Court of Appeal ruled on the lawfulness of using personal data published on social media platforms for the purpose of training an AI system.

In this context, the German judge, in light of national and European Union law, reached conclusions that could be relevant for future disputes on the matter.

The Case

The claimant, a non-profit association dedicated to the collective protection of consumer interests, filed a lawsuit against a company controlled by Meta Platforms Inc., the well-known U.S. company that manages the world’s most widely used social platforms.

Specifically, in April 2025, the defendant announced that starting the following month, it would begin training an AI model using data published by registered users on Facebook and Instagram, including users’ interactions with an AI system.

The claimant argued a violation of Article 6(1)(f) GDPR, claiming that the data processing was neither necessary nor proportionate. It also raised an alleged violation of Article 9(1) GDPR, relating to the processing of special categories of data, and of Article 5(2) of the Digital Markets Act (DMA), which prohibits the combination of personal data from multiple services without the explicit consent of the data subject.

The claimant thus requested a ban on the processing of users’ personal data by the defendant, along with the imposition of a financial or custodial penalty.

The defendant, on the other hand, sought the dismissal of the claim, arguing that no equally suitable but less invasive data processing alternatives were available for the training of its AI model.

According to the defendant, the measures adopted regarding the data used were adequate to mitigate the interference with data subjects’ rights to such an extent that the processing was justified under Article 6(1)(f) GDPR. The planned AI training would also not violate Article 9(1) GDPR. Furthermore, the defendant argued that the inclusion of data obtained from Facebook and Instagram into a single training dataset did not constitute a “combination” of data under Article 5(2) DMA.

The Decision

The Cologne Court of Appeal dismissed the claim, finding it unfounded. In particular, it held that the defendant’s processing of personal data for the training of the AI system was lawful under Article 6(1)(f) GDPR. Moreover, it found no violation of Article 9(1) GDPR or Article 5(2) DMA.

Indeed, the Court found that the mitigation measures adopted by the defendant were sufficient to reduce the intensity of the interference with the data subjects’ rights.

The Court also determined that users had been adequately informed about the processing of their data on the respective platforms and about their right to object to such processing. The German judge therefore found that the data subjects’ rights did not override the defendant’s interest, also in light of the reduced risk of actual harm, since the data in question was public.

Furthermore, the opinion of the Data Protection Commissioner of the Land of Baden-Württemberg confirmed that in large datasets used for AI training, personal identification is highly unlikely.

Finally, the Court referred to the regulatory context of the AI Act, which aims to make the EU a leader in the development of trustworthy, safe, and ethical AI. Therefore, an interpretation of the GDPR that would prevent the use of large datasets would render this goal unattainable.

The European legislator, while providing exceptions for targeted training with sensitive data, did not prohibit the unintentional processing of such data, nor did it consider it generally unlawful.

Conclusions

By rejecting the claim, the Cologne Court of Appeal found that the use of publicly accessible personal data for AI system training is lawful, provided the processing is not targeted, risk mitigation measures are adopted, and transparency and the right to object are guaranteed to users.

The ruling provides important interpretative clarification, establishing that the unintentional processing of sensitive data in large-scale datasets can be compatible with the GDPR, if justified by a legitimate interest and if no equivalent alternatives exist.

This decision is therefore in line with the objectives set by the AI Act, promoting a balance between technological innovation and individual rights, and serves as a relevant precedent in the European context.