Art. 15 GDPR response — Friedrich Baur (DE) — review v2
1. Where this stands — due tomorrow, 30 July
Maryam's review is scoped to "does this satisfy Art. 15." On that scope, v1.2 is close. Three things are still open on her list, one has been resolved, and there are two exposures outside her scope that nobody in the thread has looked at.
Open, blocking:
| # | Item | Owner | Status |
|---|---|---|---|
| 1 | Categories of personal data — India team confirming | Kunal / eng | Open |
| 2 | Recipients specific to this data subject | Kunal / eng | Open |
| 3 | Retention wording — policy not yet live | See §3 | Needs rewrite |
| 4 | EU Rep/DPO sign-off — Maryam expressly conditioned her approval on this | DPO | Not done |
Resolved: the Art. 46 bracket. Maryam confirms DPF status is Active, renewed 1 July 2026, valid to 1 July 2027. But see §2 — the resolution is not as clean as the thread assumes.
Not yet looked at by anyone: the DPF coverage gap (§2) and German UWG exposure (§5).
2. New finding: the DPF certification lapsed across the exact period being complained about
Maryam's note: "At the time your DPF certification had expired back in 2024. I just checked again and it appears that you are now in 'Active' status (renewed on July 1, 2026)."
Line up the dates:
| DPF certification expired | 2024 |
| Baur registers | 28 February 2026 |
| Marketing email sent | 24 March 2026 |
| Baur's lawyer writes | 30 June 2026 |
| DPF renewed | 1 July 2026 |
Every act this complaint concerns happened while the certification was lapsed. Renewal landed the day after their letter.
So a sentence like "transfers are carried out subject to appropriate safeguards under Art. 46 GDPR" is true as of today and not true of the processing they are asking about. The DPF participant list at dataprivacyframework.gov is public and shows status history — opposing counsel can check it in a minute, and a US company's DSAR response that implies continuous coverage over a period when there was none is exactly the kind of thing that turns a narrow request into a supervisory-authority complaint.
Two things to get right:
(a) Phrase it in the present tense and don't backdate. Art. 15(2) asks about the safeguards relating to the transfer; state current participation as a fact without asserting it covered February–June 2026. Don't volunteer the renewal date.
(b) Have an answer ready for the gap, because it is a good one. Under EDPB Guidelines 05/2021 (interplay of Art. 3 and Chapter V), a transfer requires an exporter that discloses data to a separate importer. Personal data collected directly from a data subject in the EEA by a non-EEA controller is not a restricted transfer at all — there is no exporter. Lumos collected Baur's data directly via the DE signup form. Chapter V therefore bites only on the onward flows from Lumos to its processors (ESP, hosting), and those are covered by the SCCs in the vendor DPAs, not by Lumos's own DPF certification.
That last point is worth spelling out, because there is a mismatch the thread glosses over: DPF certification protects Lumos as a data importer, i.e. when an EEA entity sends data to it. Here Lumos is the controller collecting directly and then exporting onward to its own vendors. Its DPF certification does comparatively little work on these facts. What actually covers the vendor flows is whether those vendors are themselves DPF-certified or under SCCs.
Action: confirm the ESP and hosting DPAs contain current SCCs (Implementing Decision (EU) 2021/914) or that those vendors are DPF-certified. That, not Lumos's own certification, is the real answer if they push. Worth raising with Maryam today — she's right that the active DPF is sufficient for the letter, but the gap period is a separate risk she flagged the underlying issue on back in June and may not have connected to these dates.
3. Retention — Maryam is right, and "60 months" should come out
Kunal put 60 months in v1.2 while noting the deletion policy (2 years for under-18, 5 years otherwise) is "in midst of rolling out" — 4–6 weeks away. Maryam: "If the time gap is material, I would not represent that that is your current policy." Agreed, and it is material: a written Art. 15 response is a formal representation to a lawyer building a file. Stating a retention period that no system currently enforces is a misstatement that is trivially disprovable later.
Art. 15(1)(d) permits "the criteria used to determine that period" as an alternative to a fixed period. Use that. Suggested:
Personal data is retained for no longer than is necessary for the purposes for which it is processed. The criteria determining the retention period are the duration of the Data Subject's account, the purposes set out above, and any applicable legal retention obligations. Lumos Labs is currently implementing a scheduled deletion and de-identification programme under which account data will be deleted or de-identified five years after the account becomes inactive; the Data Subject's data will fall within that programme.
This is accurate, satisfies Art. 15(1)(d), matches the published privacy policy rather than contradicting it, and mentions the improvement without claiming it is already live.
Separately — the suppression record is an exception and must be called out. Baur's email address has to be kept indefinitely on the suppression list precisely so the objection keeps being honoured. If the letter says "deleted after five years" without carving that out, it contradicts itself. Add it.
4. Two fixes to counsel's own redlines
(a) "may include" won't hold. Maryam's recipients redline reads "categories of recipients may include service providers…" — and her own follow-up asks Kunal to confirm the categories are specific to this data subject, so she's alive to the problem. Art. 15 requires what actually happened to this person, not a hypothetical. Conditional phrasing in a DSAR response is a well-known complaint trigger.
Stronger still: CJEU C-154/21, RW v Österreichische Post (12 Jan 2023) — on request, the controller must disclose the identity of actual recipients, not merely categories, unless identification is impossible or the request is manifestly unfounded. Once the India team confirms, name the ESP and the hosting provider. It costs nothing and removes the cleanest follow-up they have.
(b) Kunal's automated decision-making read is correct — keep it narrow. "No decisions are made about the user… it's pure information for the user" is the right analysis for Art. 22(1): no legal or similarly significant effect. Note that the Game Strength Profile / LPI almost certainly is profiling within Art. 4(4) — but Art. 15(1)(h) only requires disclosure of automated decision-making referred to in Art. 22(1) and (4), so the tight denial in v1.2 is right. Do not broaden it to "we do not profile," which would be inaccurate and is not required.
5. The bigger exposure nobody has looked at: German law
Maryam is US counsel reviewing Art. 15 compliance. Nothing in the thread examines whether the 24 March email was lawful to send under German law, and that is what this dispute is actually about.
Read the request for what it is. They asked for: registration opt-in timestamp, confirmation email dispatch, DOI confirmation click, IP addresses, user agent string. That is not a curious user wanting their data — it is the standard German template for establishing that no documented double opt-in exists, because BGH case law requires documented double opt-in to prove consent for email marketing. These requests are routinely the evidence-gathering step before a §7 UWG / §823 BGB Unterlassung demand and an Art. 82 GDPR damages claim. Expect a follow-up letter; the Art. 15 answer is the easy half.
The soft opt-in defence has a problem. In Germany, ePrivacy Art. 13(2) is transposed as §7(3) UWG, requiring all four of:
- the address was obtained "im Zusammenhang mit dem Verkauf einer Ware oder Dienstleistung" — in connection with a sale;
- advertising is for the trader's own similar goods or services;
- the customer has not objected;
- the customer was clearly informed at the point of collection and in every message of the free right to object.
Baur registered a free account. Condition (1) is the weak link — German courts read "Verkauf" narrowly, and the existence of a paid tier does not make a free signup a sale. Condition (4) requires the notice on the signup form, not just the email footer, and nobody has confirmed what the DE form showed on 28 February 2026.
Also fix the Art. 95 argument. v1.2 says Art. 13 ePrivacy is lex specialis "pursuant to Article 95 GDPR" and therefore declines to state an Art. 6(1) basis. Art. 95 only disapplies additional GDPR obligations for providers of publicly available electronic communications services in public communication networks. Lumosity is a cognitive-training app; Art. 95 is not engaged. And per EDPB Opinion 5/2019, ePrivacy governs the sending while the underlying processing still needs an Art. 6 basis. Refusing to name one reads as evasion to a German regulator.
Recommendation: state Art. 6(1)(f) with a short balancing paragraph (Recital 47 expressly names direct marketing as a legitimate interest), and do not litigate §7(3) UWG in a DSAR response. Answer what Art. 15 requires, record the suppression, and say the UWG questions are outside the scope of an Art. 15 request without conceding anything. Asserting a soft opt-in whose first condition probably fails is worse than staying silent on it — it hands them a written position to attack.
Two variants are in §7 below: Variant A if the signup form evidence supports all four §7(3) conditions, Variant B (recommended on current information) if it doesn't or can't be confirmed today.
Before choosing: confirm whether a marketing consent checkbox existed at DE signup. If a consent record exists, the whole framing changes and is much stronger — and part of what they asked for actually exists. An incorrect "no consent" denial would be far worse than any drafting problem here.
Suggest engaging German counsel now, separately from Maryam, on the UWG/Art. 82 track. That does not need to delay tomorrow's Art. 15 response.
6. Smaller points
- Respond in English. Their request came in English (subject line, ref CY-56419-MM), so English is right. Disregard any suggestion to translate.
- Give them the registration IP and user agent. v1.2 lists IP and device data as processed, then calls the requested IP/user agent "not applicable" because no DOI process existed. Both halves are true, but together they read as withholding. The registration-event IP and UA exist and are his personal data. Handing them over is free and removes the strongest "incomplete response" argument.
- Align purposes with categories. Five categories are listed; the stated purposes cover only account provisioning and communications. Nothing addresses game-performance data, LPI, device data or cookies. Fix the mismatch.
- Name the controller, DPO and Art. 27 EU representative in the letter, with a signature block. Maryam's sign-off is conditioned on EU Rep/DPO review — that step is still outstanding and should not be skipped to make the deadline.
- Provide the Art. 15(3) copy, don't offer it conditionally. Offering "should the Data Subject wish" invites a second letter.
- Extension is not viable. Art. 12(3) requires notifying an extension within the first month with reasons; given the narrow scope Maryam rightly calls it a last resort. Send on time.
- Cookie/§25 TDDDG is a likely next target once they see cookie data listed. Nothing to change in this letter; worth queuing behind the privacy-policy work already in flight with Maryam.
7. Revised letter
Changes from v1.2: Art. 95 argument removed and Art. 6(1)(f) substituted; DPF stated in present tense; retention converted to criteria + suppression carve-out; registration IP/UA disclosed; purposes aligned; controller/DPO/EU Rep identified; Art. 15(3) copy provided rather than offered. Remaining unknowns marked [[LIKE THIS]] — none should ship unresolved.
Lumos Labs, Inc.
[[ADDRESS]]
[[LAW FIRM]]
[[ADDRESS]]
Your ref: CY-56419-MM · Our ref: [[REF]]
[[DATE]] July 2026
Re: Request for information pursuant to Article 15 GDPR — Mr Friedrich Baur
Dear Sirs,
We refer to your letter of 30 June 2026, submitted on behalf of your client Mr Friedrich Baur ("the Data Subject") pursuant to Article 15 of Regulation (EU) 2016/679 ("GDPR"), and respond to the three points raised, followed by the further information required under Article 15(1) and (2).
The controller is Lumos Labs, Inc., [[ADDRESS]]. Our Data Protection Officer may be contacted at [[EMAIL]]. Our representative in the Union pursuant to Article 27 GDPR is [[NAME AND ADDRESS]].
1. Source of the data
The personal data in question (email address and associated registration details) were provided directly by the Data Subject when he created a free Lumosity account via the registration form at https://app.lumosity.com/de/signup on 28 February 2026. The data were not obtained from any third-party data supplier, list broker, partner company or other external source.
2. Legal basis for the email of 24 March 2026
[Insert Variant A or Variant B — see below.]
Irrespective of the above, upon receipt of the Data Subject's objection we suppressed his email address from all further marketing communications with effect from 2 July 2026. He will receive no further marketing communications from us. Our records show that the email of 24 March 2026 was the only marketing communication ever sent to this address.
3. Records relating to consent
Your letter requests records of a double opt-in verification process (opt-in timestamp, dispatch of a confirmation email, confirmation click, and associated IP addresses and user agent strings). We confirm that no double opt-in verification process was applied to this address, and accordingly no records of such a process exist. We do not wish to leave that answer at a bare negative, and so set out below the records we do hold in relation to the registration and the communication, including the IP address and user agent string captured at registration.
4. Information under Article 15(1) and (2) GDPR
| Date and time of registration | 28 February 2026, 18:15:08 UTC |
| Email address provided | friedrich.baur@gfbaur.de |
| IP address at registration | [[IP]] |
| User agent at registration | [[UA]] |
| Marketing email sent | 24 March 2026 |
| Suppressed from marketing | 2 July 2026 |
Categories of personal data processed — [[CONFIRM WITH ENG]] account and registration data (email address, account creation date); usage and game-performance data (games played, scores, and derived metrics including the Lumosity Performance Index); device and technical data (IP address, device identifiers, log data); cookie and similar tracking data; marketing and communications data (delivery, engagement and suppression records).
Purposes of processing — provision and administration of the Lumosity service; delivery and personalisation of training content; measurement of training performance, including derivation of the Lumosity Performance Index; security, fraud prevention and abuse detection; analytics and product improvement; service and transactional communications; direct marketing, including the communication referred to in your letter; and compliance with legal obligations.
Recipients — the Data Subject's personal data has not been disclosed to any third party for that party's own marketing purposes. Personal data is processed on our behalf, under contract and subject to confidentiality and data protection obligations, by: [[ESP NAME]] (email delivery) and [[HOSTING PROVIDER]] (hosting and infrastructure) [[ANY OTHERS]]. Disclosure may additionally be made to competent authorities where required by law.
Retention — personal data is retained for no longer than is necessary for the purposes for which it is processed. The criteria determining the retention period are the duration of the Data Subject's account, the purposes set out above, and any applicable legal retention obligations. Lumos Labs is currently implementing a scheduled deletion and de-identification programme under which account data will be deleted or de-identified five years after the account becomes inactive; the Data Subject's data will fall within that programme. By way of exception, the Data Subject's email address is retained on our marketing suppression list for as long as necessary to ensure that his objection continues to be given effect; that retention is necessary under Articles 6(1)(c) and 6(1)(f) GDPR and cannot be shortened without risking further unwanted contact.
Automated decision-making — Lumos Labs does not carry out automated decision-making, including profiling, which produces legal effects concerning the Data Subject or similarly significantly affects him within the meaning of Article 22(1) GDPR.
International transfers — Lumos Labs, Inc. is established in the United States and personal data is processed there. Lumos Labs, Inc. participates in and is certified under the EU-U.S. Data Privacy Framework. Where personal data is disclosed to service providers acting on our behalf, appropriate safeguards under Chapter V GDPR are in place, including the Standard Contractual Clauses approved by the European Commission by Implementing Decision (EU) 2021/914 where applicable. Copies of the relevant safeguards are available on request.
Rights — the Data Subject has the right to request access to, rectification of and erasure of his personal data, to request restriction of processing, to object to processing carried out on the basis of legitimate interests (including, at any time and without giving reasons, to processing for direct marketing purposes), and to data portability. He also has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his habitual residence or place of work.
5. Copy of the personal data
A copy of the personal data undergoing processing, pursuant to Article 15(3) GDPR, is [[enclosed / provided via the secure link below]] in a structured, commonly used electronic format.
We trust this fully answers the points raised. Please let us know if anything requires clarification.
Yours faithfully,
[[NAME]]
[[TITLE]], Lumos Labs, Inc.
Sent without prejudice to Lumos Labs, Inc.'s position on any matter not expressly addressed herein.
Variant A — only if the DE signup form of 28 Feb 2026 evidences all four §7(3) UWG conditions
The email of 24 March 2026 was a direct marketing communication sent to a registered user of our own service, promoting our own similar (paid tier) offering.
The legal basis for the processing is Article 6(1)(f) GDPR. Our legitimate interest is the promotion of our own similar services to our own registered users, which Recital 47 GDPR expressly recognises as a legitimate interest. In carrying out the balancing exercise we took into account that the data used was first-party data provided to us directly by the Data Subject, that the communication concerned the very service for which he had registered less than four weeks earlier, that his data was not disclosed to any third party, and that a free and immediate means of objection was provided in the message.
As to the sending of the communication, §7(3) UWG permits direct advertising by electronic mail where the address was obtained in connection with the sale of goods or services, the advertising relates to the trader's own similar goods or services, the customer has not objected, and the customer was informed at the point of collection and in each message of the right to object at no cost beyond basic transmission rates. Each condition was satisfied: [[STATE HOW THE ADDRESS WAS OBTAINED IN CONNECTION WITH THE SALE OF SERVICES]]; the communication concerned our own paid tier of the same service; no objection had been received before 24 March 2026; and the objection notice was displayed on the registration form of 28 February 2026 and repeated in the email itself.
Variant B — recommended on current information
The email of 24 March 2026 was a direct marketing communication sent to a registered user of our own service, promoting our own similar (paid tier) offering. It was not sent on the basis of consent, and we do not assert that consent was obtained.
The legal basis for the processing of personal data for this purpose is Article 6(1)(f) GDPR. Our legitimate interest is the promotion of our own similar services to our own registered users, which Recital 47 GDPR expressly recognises as a legitimate interest. In carrying out the balancing exercise we took into account that the data used was first-party data provided to us directly by the Data Subject, that the communication concerned the very service for which he had registered less than four weeks earlier, that his data was not disclosed to any third party, and that a free and immediate means of objection was provided in the message.
The Data Subject exercised his right to object, and we gave effect to that objection immediately.
We note that your letter also raises questions arising under the Gesetz gegen den unlauteren Wettbewerb. Those questions fall outside the scope of a request under Article 15 GDPR and we do not address them here; nothing in this letter should be taken as an admission in relation to them. We are willing to correspond separately on that subject should your client wish.
8. If only three things change before dispatch
- Take "60 months" out and use the criteria-based wording — the policy isn't live, and Maryam has already flagged representing it as current.
- Present-tense the DPF sentence and get the vendor SCC position confirmed. The certification was lapsed across the exact February–March 2026 window they are asking about, the participant list is public, and nobody in the thread has connected those dates.
- Get the EU Rep/DPO sign-off Maryam conditioned her approval on, and drop the Art. 95 / lex specialis argument in favour of Art. 6(1)(f).