Berlin's administrative court dismissed a solar installer's challenge to a data protection warning on May 28, 2026, ruling that a credit check performed before the first on-site appointment had no lawful basis. The decisive failure was not the consent language the regulator attacked, but a privacy notice the company had left unrevised after changing when it ran the check.

The 42nd Chamber of the Verwaltungsgericht Berlin decided case 42 K 56/25 on May 28, 2026, under ECLI:DE:VGBE:2026:0528.42K56.25.00. The action was dismissed in full. The plaintiff bears the costs of the proceedings, and the judgment is provisionally enforceable as to costs, with either party able to avert enforcement by posting security worth 110 percent of the enforceable amount. The court set the value of the matter in dispute at 5,000 euros and held that no ground for admitting an appeal under Section 124(2), numbers 3 or 4, of the Administrative Court Rules of Procedure was apparent. With the consent of both parties, the reporting judge decided the case in place of the full chamber under Section 87a(2) and (3) of those rules.

The legal basis for the contested measure is Article 58(2)(b) of the GDPR, which allows a supervisory authority to issue a warning to a controller whose processing has infringed the regulation. The authority in question was the Berlin Commissioner for Data Protection and Freedom of Information, competent under Article 55(1) GDPR read with Section 40(1) BDSG and Section 8(2) BlnDSG because the company is established in Berlin.

The funnel that produced the complaint

The plaintiff leases solar systems to end customers or sells them under an installment purchase model. Both routes involve long-term sales financing: 20 years under the lease model and up to 25 years under the installment purchase model. That financing exposure is the commercial reason the company screens prospects at all.

Its contract initiation process, according to the judgment, ran as follows and still does. Prospective customers enter their details on the website and book an appointment with an advisor. A first conversation, internally labelled Sales Call I, follows. If the prospect accepts the initial offer, an installation preparation appointment - the MVT in the company's internal shorthand - is scheduled. Before that first visit, an MVT application is sent to the prospect for signature. Once the signed application comes back, the company runs a credit check through Schufa and verifies ownership of the property with the land registry. If the project is technically feasible, a preliminary module plan is drawn up and discussed in a second conversation, Sales Call II.

The credit assessment is not a single-variable filter. The company's internal review department works to written guidelines. The prospect's Schufa score matters, and so does the score of a partner living at the property who countersigns the MVT application. Negative Schufa entries, home ownership status, and technical feasibility all feed the rejection decision.

The complainant expressed interest in April 2024. He held his Sales Call I on April 23, 2024, and signed the MVT application the same day. On May 24, 2024, the company told him that no contract could be concluded because of his Schufa score. No meeting to discuss project scope took place, and no preliminary module plan was ever produced. He then complained to the Berlin authority, arguing that the Schufa inquiry had been run without his agreement.

What the paperwork said

Directly above the signature field, the MVT application told the prospect that the company would assess technical feasibility and verify ownership status, and then, in bold, that the signatory grants power of attorney "to inspect the land registry and to obtain a credit report in preparation for drafting the contract."

The privacy policy in force at the time said something materially different about timing. Section 2.8 stated: "Your creditworthiness is assessed only after you have submitted an application to lease a solar system from J... and have received a preliminary module plan for your solar system. The legal basis is Article 6(1)(b) of the GDPR." Section 3.7 repeated that language and added an explanation of Schufa's role.

The gap is the whole case. The policy told prospects the check came after the preliminary module plan. In practice it came before the MVT, which itself precedes the module plan.

Necessity is a narrow test

The company's primary defence was Article 6(1)(b) GDPR, covering processing necessary for pre-contractual measures taken at the data subject's request. The court applied the standard the Court of Justice set in Meta Platforms, case C-252/21 of July 4, 2023: processing must be objectively indispensable to a purpose forming an integral part of the contractual performance, and the controller must show the main subject matter could not be delivered without it. Being mentioned in the contract, or merely useful, does not qualify. Recital 44 frames pre-contractual measures as processing necessary for the intended conclusion of a contract, with offer preparation and product reservation as the textbook examples.

The chamber conceded a great deal to the company before ruling against it. It accepted that verifying creditworthiness before granting 20 to 25 years of sales financing on a high-value system is a legitimate and economically significant interest. It accepted that running the check before the MVT is understandable, since a trained technician must travel to the site, inspect and photograph the roof, and write a report. It went further and held that the authority cannot, as a matter of principle, require the company to charge for MVTs, because offering a free preparation visit as part of customer acquisition falls within the core of entrepreneurial discretion.

None of that made the early check indispensable. The court pointed to the company's own history: before it restructured the process, the credit check came after the MVT. A practice the controller itself operated differently is difficult to describe as objectively necessary. The interest in moving the check earlier might, if properly structured, support processing under Article 6(1)(f), the judgment noted, but not under Article 6(1)(b).

A second obstacle stood independently. Article 6(1)(b) requires that pre-contractual measures be taken at the initiative of the data subject rather than the provider. The chamber recorded the academic dispute over whether provider-initiated credit reports can ever satisfy that condition, then resolved the case on its facts: given the privacy policy handed to the complainant when he signed, he could not have assumed a credit check would happen before the MVT, so the processing cannot be traced to a request of his.

Legitimate interest failed on disclosure

Article 6(1)(f) did not rescue the processing either. The court set out the three cumulative conditions the Court of Justice restated in CNIL, case C-394/23 of January 9, 2025: a legitimate interest, necessity to achieve it, and a balance that does not tip toward the data subject. Necessity is assessed alongside the data minimisation principle in Article 5(1)(c), and Recital 47 makes reasonable expectations central to the balancing exercise.

The company never got that far. Under Article 13(1)(d), a controller relying on legitimate interests must identify those interests when the data is collected, and the case law treats failure to do so as barring reliance on the basis altogether. The plaintiff had not adequately informed the complainant in advance of the interests it was pursuing. The balancing test would have gone against it in any event, the court added, because the conflicting privacy policy meant the complainant could not reasonably have expected his data to be processed for a credit check before receiving a module plan.

Where the court broke with the regulator

The warning's second limb concerned Article 25(1) read with Article 5(1)(a), variants two and three - fairness and transparency, implemented through data protection by design. Here the chamber rejected the authority's central argument.

The regulator had claimed that asking for a "power of attorney" created confusion about the legal basis, since the term is not standard in data protection and at best suggests consent under Article 4(11) that was never actually obtained. The court disagreed. The company genuinely needed a civil-law power of attorney to request a self-report from Schufa on the complainant's behalf, a point the authority did not dispute. The wording was therefore correct and contained no indication that consent to processing was being sought. The privacy policy expressly named Article 6(1)(b) as the basis, not consent. No data protection obligation required the company to state that the power of attorney was not consent, or that it was revocable.

The authority also argued, for the first time in its defence pleading, that the process design violated the balance of power between controller and data subject. The court refused to consider it. Interpreting the warning as a declaratory administrative act under Sections 133 and 157 of the Civil Code, what matters is the declared content as an objective recipient would understand it, with ambiguities read in the recipient's favour. Reasoning added after the fact does not become part of the measure.

What survived was narrower and, for anyone running a documented acquisition process, more instructive. Article 25(1) obliged the company to take organisational measures to update its customer-facing information before restructuring the timing of the credit check. By handing the complainant outdated text, it raised a false expectation that he could still withdraw his request before the check ran. That, the chamber held, is a failure to design the process fairly and transparently.

The court also settled a threshold question. Article 58(2)(b) speaks of infringements committed "through processing operations," which on a narrow reading might exclude organisational duties. Citing Brillen Rottler, case C-526/24 of March 19, 2026, and Meta Platforms Ireland, case C-757/22 of July 11, 2024, the chamber read the phrase broadly, holding that a narrow construction would undermine the practical effectiveness of supervisory remedies.

Why a warning, and nothing lighter

The company argued the authority had treated the warning as an automatic consequence and ignored milder options: a simple notice, or an instruction under Article 58(2)(d).

Neither worked. Where a violation is established, supervisory authorities enjoy a presumptive discretion in favour of corrective action, and refraining is reserved for exceptional cases. A simple notice is not among the measures listed in Article 58(2). The warning under Article 58(2)(a) applies only where unlawful processing is intended rather than completed, which was not the position here. An instruction under Article 58(2)(d) is not milder at all, since it creates an enforceable obligation whose breach can trigger a fine.

Mitigation was recorded and did not change the outcome. This was a first violation. The company cooperated, revised its privacy notice promptly, and had already aligned it with practice by the time the warning issued. The court noted the correction was legally required anyway under Article 13(1)(c). It also observed that the warning carries no immediate tangible consequence beyond the finding itself and the disapproval expressed, though it could ground more severe measures, including a fine, on repetition.

A date that does not reconcile

One inconsistency runs through the text. Paragraphs 14 and 26 date the contested warning to May 23, 2025, and the lawsuit to June 16, 2025. Paragraph 36, in the reasoning, refers instead to "the defendant's warning of February 12, 2026." The document under review is a machine translation of the German original, and the discrepancy is not resolved anywhere in the text. The 2025 dates are consistent with the case number 42 K 56/25 and with the procedural chronology; the February 2026 reference is not.

What it means for acquisition teams

The commercial reading of this judgment has little to do with solar panels. It concerns any funnel where a signed form triggers automated enrichment or scoring before a human has done anything expensive.

Two operational points carry across. First, timing is a substantive compliance variable, not a scheduling detail. The same Schufa inquiry, run after the MVT, would probably have survived. Run before it, and after a policy told prospects otherwise, it failed. Second, the artefact that decided the case was the privacy notice, not the terms. Marketing operations teams routinely reorder qualification steps to cut cost per qualified lead. This ruling attaches a documentation duty to that reordering, and locates it in Article 25(1) rather than in the transparency articles alone.

The reasonable expectations standard has been tightening across European enforcement. The European Data Protection Board's case digest on Article 6(1)(f) documented how routinely controllers fail the three-condition test, with consumer finance and credit checks recurring throughout the cross-border decisions. In the Zalando cases the digest describes, credit checks were accepted only once a shopper had actively selected invoice payment at checkout - a far later trigger than a signed preparation form.

German credit data has been under sustained judicial pressure. A Wiesbaden court ordered Schufa to give individualised explanations of the factors behind a score, while the Federal Court of Justice permitted telecoms to transmit positive contract data to Schufa on fraud prevention grounds. Austrian regulators found fully automated scoring unlawful under Article 22 and required greater disclosure of scoring logic. This Berlin judgment adds a different axis: not what the bureau must explain, but when the business asking is allowed to ask.

For advertisers and lead generation operators, the enforcement context is not abstract. European authorities issued more than 1.1 billion euros in fines during 2025, and warnings of the kind upheld here sit at the bottom of a catalogue that escalates quickly on repetition.

Timeline

Summary

Who: The 42nd Chamber of the Verwaltungsgericht Berlin, a Berlin-based solar leasing and installment sales company acting as plaintiff, and the Berlin Commissioner for Data Protection and Freedom of Information as defendant, following a complaint from an individual prospect whose application was rejected on creditworthiness grounds.

What: A judgment dismissing the company's action to annul a data protection warning issued under Article 58(2)(b) GDPR. The court held that running a Schufa credit check between the first sales call and the installation preparation appointment lacked any lawful basis under Article 6(1)(b) or 6(1)(f), and that failing to update the privacy notice before changing the timing of that check breached Article 25(1) read with Article 5(1)(a). The chamber rejected the regulator's separate argument that the phrase "power of attorney" in the signature form was itself a transparency failure.

When: The judgment was issued on May 28, 2026. The underlying processing occurred between April 23 and May 24, 2024. The warning was issued on May 23, 2025, and the action filed on June 16, 2025.

Where: Berlin, Germany, under German administrative procedure and EU data protection law, with reasoning drawn from Court of Justice case law binding across the European Economic Area.

Why: The court found the credit check was not objectively indispensable for concluding the contract, evidenced by the company's own earlier practice of running it after the site visit, and found the processing could not be attributed to a request by the data subject because the privacy notice told him the check would happen later. Because the company had not disclosed the legitimate interests it pursued, Article 6(1)(f) was unavailable, and the balancing test would have failed on reasonable expectations regardless.