MD Reader Open in MD Reader

Art. 15 GDPR response — Friedrich Baur (DE) — review v4

Reviews draft v1.2 (28.07.2026) against Mirco Lehr's letter of 30 June 2026, the 24 March email as sent (Appendix 1), the Pierson Ferdinand thread, the signup form, the published Terms of Service and Privacy Policy. Due 30 July 2026.


1. The request is far narrower than the draft treats it, and that changes everything

Lehr asks three questions and nothing else:

  1. Source — the URL of the registration page, or the name and serviceable address of the data supplier / partner company
  2. Legal basis — on which basis do you rely for sending the email
  3. Evidence"If you rely on consent", the DOI log data

He then characterises his own request, twice, as narrow: "the narrowly limited information requested here" and "narrowly limited protocol or consent evidence."

He has not asked for a full Art. 15 disclosure. No categories of data, no recipients, no retention period, no international transfers, no automated decision-making, no Art. 15(3) copy.

Draft v1.2 volunteers all of it. That direction came from Maryam's review, which reads the invocation of Art. 15 as triggering the full Art. 15(1) information set — a defensible conservative position, and the one most controllers default to. But look at what the last three rounds of analysis actually found:

Problem found Lives in a disclosure that was…
The DPF certification gap (§4.2) Not asked for
The DoubleClick / ad-tech recipients denial (§4.1) Not asked for
"60 months" vs. a policy not yet live Not asked for
Purposes/categories mismatch Not asked for
Name and DOB missing from categories Not asked for

Every serious problem in this response sits in material nobody requested. The three questions actually asked are answerable cleanly, truthfully and in about half a page.

Recommendation: answer the three questions, and offer the rest. A closing line stating that a full Art. 15(1)/(3) export is available on request preserves the compliance posture — you are not refusing anything, you are responding to the request as the data subject framed it, and Recital 63 supports a controller answering a request the data subject has himself specified. If he later says the response was incomplete, the answer is "you asked three questions; we answered them and offered the rest."

This diverges from Maryam's advice and she should decide it. She is retained and this is a judgment call about risk appetite, not a matter of clear law. But she formed her view without the DPF-gap dates or the ad-tech exposure in front of her, and both cut hard toward the narrow answer. Put it to her as an explicit choice today.


2. What this reverses from my earlier drafts

Being explicit, since the advice has moved:

The draft's structure is kept — only the basis under it changes. v1.2 answers Q3 as a consequence of Q2: assert Art. 13 ePrivacy as the basis for the sending, so the consent question never arises and the DOI logs are moot. That architecture is sound and the revised letter preserves it — section 3 still refers back to section 2 rather than answering independently. What cannot be preserved is the basis it rests on. Art. 13(2) requires contact details obtained "in the context of the sale of a product or a service" from "its customers", so a free registration by a free user fails at EU level, not merely in the German transposition — and in Germany the operative rule is §7(3) UWG in any event, so citing the Directive invites a reply framed in §7 terms. Worse, v1.2 supports the claim by stating the email "contained a clear, free-of-charge unsubscribe option"; the actual footer reads only "Update preferences … or unsubscribe", with nothing about cost, and Lehr attached that email to his own letter as Appendix 1. A written basis that he can break with a document already in his hands costs more than the gap it fills.

What does not change: drop the Art. 95 lex specialis argument — it is a duplicate-administrative-burden provision scoped to processing in connection with providing a publicly available electronic communications service, which this is not (verified at §3.1) — and state Art. 6(1)(f), which your own Privacy Policy §3 already names for marketing. Do not assert the §7(3) UWG soft opt-in — see §3.


3. Do not assert the soft opt-in

Question 2 asks the basis "for sending the email" — that is the ePrivacy/UWG question, and it is the trap. Against §7(3) UWG, all four conditions cumulative:

Condition Status
1 Address obtained "im Zusammenhang mit dem Verkauf" — in connection with a sale Fails. Free registration; a paid tier elsewhere doesn't make this signup a sale.
2 Advertising for own similar goods or services Satisfied
3 Customer has not objected Satisfied at the time
4 Informed klar und deutlich at the point of collection and in each message of the right to object at no cost beyond base transmission rates Fails on both limbs. The DE form is confirmed identical to the English one, translated — no objection notice, only "you agree to our Terms of Service, Privacy Policy…", and the ToS contain no marketing provisions at all. The email footer offers "Update preferences … or unsubscribe" but says nothing about the objection being free of charge, which Nr. 4 requires.

Two of four fail. Answer with the GDPR basis (Art. 6(1)(f)), state plainly that consent is not relied on, and do not argue German unfair-competition law in a DSAR reply.

What the email settles. It is unambiguously Werbung — "25% off on Lumosity Premium" in the preheader, an "UPGRADE OFFER" block, "Premium vs Free", "Get Premium". There is no arguing it was a transactional or service message, so don't try. Two things do help: it advertises Lumosity Premium to a registered free user, which squarely satisfies condition 2 (own similar service); and the sender is identifiable (newsletter@notifications.lumosity.com, with the company name and address in the footer), so §7(2) Nr. 4 UWG sender-concealment and §5 DDG provider identification are not in play.

One thing that helps: there is no marketing consent checkbox on the form, so "no consent was obtained" is accurate. No risk of a false denial.

And the ADM answer is safer than assumed. The email markets the Game Strength Profile and Personalized Insights as Premium features — the comparison table shows Personalized Insights as "None" on Free. Baur held a free account, so these features were most likely never applied to him at all. The LPI ranking is still profiling under Art. 4(4), but it remains well outside Art. 22(1). Kunal's read holds, with room to spare.

3.1 Article 95 — checked against the source, and it does not apply

Verified against the text of Art. 95 and EDPB Opinion 5/2019 (12 March 2019), which is the authority directly on this interplay. Three findings, in order of what they settle.

Art. 13 ePrivacy does apply to Lumos — but that has nothing to do with Art. 95. The Opinion's §3.2.2 is headed "The extended material scope of articles 5(3) and 13 ePrivacy Directive", and para 28 states that those articles *"apply to providers of electronic communication services as well as website operators (e.g. for cookies) or other businesses (e.g. for direct marketing)"*, giving as its worked example: "Unsolicited electronic mail sent by a website operator for the purposes of direct marketing also fall within the extended material scope of article 13 ePrivacy Directive." That is Lumos exactly. So the draft is right that Art. 13 is engaged. It reached that conclusion through the wrong provision.

Art. 95 is confined to ECS providers, and its function is narrower than the draft assumes. Para 44: "The aim of article 95 GDPR is therefore to avoid the imposition of unnecessary administrative burdens upon controllers who would otherwise be subject to similar but not quite identical administrative burdens." The Opinion's only worked example is double breach notification — an ECS provider that has notified under national ePrivacy law need not notify the same breach again under Art. 33 GDPR. Art. 95 is a duplicate-paperwork provision. It is not a switch that turns off Chapter II.

Even where ePrivacy does govern, an Art. 6 basis is still required. Para 41, on cookies, is the closest structural analogue: the placing or reading of cookies must comply with the national transposition of Art. 5(3), and "Subsequent processing of personal data including personal data obtained by cookies must also have a legal basis under article 6 of the GDPR in order to be lawful." Same two-step here: Art. 13 / §7 UWG governs whether the message could be sent; Art. 6 governs the processing. The draft's conclusion — that Art. 13 displaces the need to state an Art. 6 basis — does not follow even on its own premises.

Is there any route to applicability? One, and it fails. Since the EECC (Directive (EU) 2018/1972, applicable from 21 December 2020, and referenced in the Opinion's own footnote 14), "electronic communications service" was broadened to include number-independent interpersonal communications services — OTT messaging. If Lumosity operated user-to-user messaging, that component might arguably qualify. But Art. 95 covers processing "in connection with the provision of" such a service, and a Premium upsell campaign is not that; and para 44 shows the relief on offer is duplicate-notification relief, not dispensation from a legal basis. There is no reading on which this helps.

What the draft was reaching for that is legitimate. A lex specialis relationship genuinely exists — paras 35, 38 and 45 confirm it — but it flows from Art. 1(2) of the ePrivacy Directive ("particularise and complement"), not from Art. 95, and para 38 is explicit that it operates only where ePrivacy specifically governs, with the GDPR applying to everything else. Citing Art. 95 to a German lawyer would read as argument-construction and invites a correction on the record.

One caution, so the letter isn't mistaken for a cure. Stating Art. 6(1)(f) is correct and conventional, but it does not repair the §7(3) UWG problem above. Para 39 shows the pattern — where ePrivacy restricts a processing operation, the range of available Art. 6 grounds narrows with it. If the send itself was unlawful under §7 UWG, a German authority is likely to find the legitimate-interests balancing fails too, since there is no legitimate interest in conduct that sector law prohibits. The letter answers the question asked accurately. It does not fix the underlying exposure, and nothing that can be written tomorrow will.

Sources: Art. 95 GDPR · EDPB Opinion 5/2019


4. The two exposures that stay out of the letter but need owners

4.1 The ad-tech recipients denial

Draft v1.2 says data "has not been disclosed to third parties for marketing purposes." Privacy Policy §6 names DoubleClick "and others" for ad serving, plus Google Analytics, Rollbar and New Relic. If tags fired on Baur's sessions, that denial is false. Under the narrow answer this sentence simply doesn't appear — which is the cleanest fix available. But eng should still establish the position, because it will surface if he escalates, and it bears on §25 TDDDG cookie consent generally.

4.2 The DPF certification gap

Privacy Policy §11 states "Lumos Labs complies with the EU-U.S. Data Privacy Framework." Maryam confirms certification expired in 2024 and was renewed 1 July 2026.

DPF certification expired 2024
Baur registers 28 February 2026
Marketing email sent 24 March 2026
Lehr's letter 30 June 2026
DPF renewed 1 July 2026

For ~2 years the public notice claimed participation in a framework the company wasn't certified under, covering every act in this complaint; renewal landed the day after the letter. Two exposures: the misstatement in the notice in force on 24 March (Wayback plus the public list at dataprivacyframework.gov proves it in minutes — confirm what §11 actually said then), and, more probably, FTC deception, which is enforced independently of anything Baur does. Neither belongs in this letter. Both belong on Maryam's desk as separate workstreams.

4.3 Email tracking and §25 TDDDG

The email carries an "Update preferences for friedrich.baur@gfbaur.de" link and multiple campaign links, and draft v1.2 lists "email delivery and unsubscribe records" — engagement tracking — among the data processed. If the message contained an open-tracking pixel or click tracking, that is storage of or access to information on terminal equipment under §25 TDDDG, which requires prior consent in Germany and has no legitimate-interests route. It is a distinct violation from the §7 UWG point and survives independently of it.

This is confirmed by the same authority relied on at §3.1: EDPB Opinion 5/2019 para 28 puts Art. 5(3) alongside Art. 13 in the "extended material scope", applying to "website operators (e.g. for cookies) or other businesses" — so §25 TDDDG binds Lumos here just as §7 UWG does. And para 41 adds a second limb often missed: where data is obtained through such access, the "subsequent processing of personal data … must also have a legal basis under article 6 of the GDPR in order to be lawful." So email engagement data needs both consent for the access and an Art. 6 basis for what is then done with it.

Nobody has looked at this. Confirm with the ESP what tracking was enabled on the 24 March campaign for DE recipients. It stays out of the letter — not asked — but it is squarely within what a UWG/Art. 82 follow-up would reach, and it connects to the wider cookie-consent question in §4.1.

DE cookie consent runs through Usercentrics, a German CMP that supports proper prior blocking — a good sign for the website side, and it materially reduces the §4.1 concern about ad and analytics tags. Two caveats remain. First, the platform is not the test, the configuration is: what matters is whether Google Analytics and any advertising tags are actually gated behind affirmative consent rather than merely listed. Second, a website CMP does nothing for email open-tracking consent — a pixel in a marketing email needs consent obtained for that purpose, and no web banner reaches it. §4.3 therefore stands independently of how well Usercentrics is configured.

4.4 Research use of user data

The email's lead item reports "A study of Lumosity users found that people living in densely populated cities scored higher on fluid intelligence…". Scientific research on user game data is a processing purpose that appears nowhere in draft v1.2's purposes list. Irrelevant under the narrow answer, but if Maryam chooses full Art. 15(1) disclosure it has to be stated, with its own legal basis. Worth confirming separately what basis research use runs on and whether the privacy notice covers it.

4.5 Scale — this is a campaign issue, not a Baur issue

Confirmed: a large number of German users received the 24 March campaign. That reframes the matter.

The defect is not specific to Baur. If the DE list was mailed on the same footing — no consent, no §7(3) Nr. 4 objection notice at signup, no free-of-charge notice in the footer, tracking presumptively enabled — then every one of those sends carries the same defect, and the analysis in §3 applies to all of them. Consequences worth weighing today:

Two decisions for today, separate from the letter:

  1. Whether to pause DE marketing sends pending a fixed signup notice and footer. Every further send on the current footing compounds the exposure. This is a business call, but it should be made deliberately rather than by default.
  2. Fix forward on the signup form — add a clear, free-of-charge objection notice at the point of collection, and the same in every marketing footer. That is cheap, it is the actual §7(3) Nr. 4 requirement, and it stops the clock on new exposure. Doing it now is not an admission about past sends.

And it makes the narrow answer in §1 more clearly right, not less. Whatever is conceded in writing to Lehr becomes the template used against the whole campaign. A short, accurate answer to three questions puts far less on the record than a full voluntary Art. 15 disclosure would.


5. Handling points from the letter itself

Do not ask for ID. Lehr pre-empts it, citing Art. 5(1)(c) and Art. 12(6), and warns that refusal "may be taken to your disadvantage in potential court proceedings." He encloses a power of attorney (Appendix 2). Art. 12(6) permits further identification only on reasonable doubts; possession of the email plus a PoA leaves none. Requesting ID would manufacture the refusal narrative he is setting up. But confirm the PoA was actually attached and covers this — responding to an unauthorised third party is itself a breach.

"Potential court proceedings" is stated, but no claim is yet made. There is no Unterlassungserklärung demand, no Art. 82 damages claim, no deadline of his own. This is evidence-gathering — the DOI-log request is the standard German template for establishing that no documented double opt-in exists, which BGH case law requires to prove consent for email marketing. Expect a follow-up. Engage German counsel now on the UWG/Art. 82 track; it need not delay tomorrow.

Reply by email as invited, but consider sending the substance as an attached PDF on letterhead rather than in the body.

Deadline: their letter is 30 June, so Art. 12(3) expires 30 July 2026. An extension must be notified within the first month with reasons — that window closes with the deadline, and Maryam rightly calls it a last resort.

Check the address before it goes on letterhead. The email footer reads "16 Maiden Lane, Suite 6"; the Terms of Service say "16 Maiden Lane, Floor 6". One of them is wrong. Confirm which before stating the controller's address in a formal response.


6. Revised letter — narrow form

Answers the three questions asked, offers everything else. Unresolved items marked [[LIKE THIS]].

Drafting guard for whoever redlines this. Question 2 asks the basis "for sending the email", but paragraph 2 of the letter deliberately says "the legal basis for the processing of personal data for this purpose." Do not "correct" that to match Lehr's wording. Sending and processing are legally distinct — ePrivacy Art. 13 and §7 UWG govern whether the message could be sent, Art. 6 governs the processing (§3.1) — and writing "the legal basis for sending the email is Art. 6(1)(f)" would assert something that is not true and concede the UWG framing in the same breath.


Lumos Labs, Inc.
16 Maiden Lane, Floor 6, San Francisco, CA 94108, USA

Mirco Lehr
[[FIRM AND ADDRESS]]

Your ref: CY-56419-MM · Our ref: [[REF]]
[[DATE]] July 2026

Re: Request for information pursuant to Article 15 GDPR — Friedrich Baur

Dear Mr Lehr,

We refer to your letter of 30 June 2026 concerning your client Friedrich Baur ("the Data Subject") and respond below to the three questions raised.

The controller is Lumos Labs, Inc., 16 Maiden Lane, Floor 6, San Francisco, CA 94108, USA. Our Data Protection Officer may be contacted at dpo@lumoslabs.com. Our representative in the Union pursuant to Article 27 GDPR is Charles Guillemet, 3 Rue Villaret de Joyeuse, 75017 Paris, France.

We accept the authority evidenced by the power of attorney enclosed with your letter and do not require further proof of identity.

1. Source of the data

The email address was entered by the Data Subject on the registration form at https://app.lumosity.com/de/signup when creating a free Lumosity account on 28 February 2026 at 18:15:08 UTC. Registration was completed directly by email; no third-party sign-in provider was used.

The email address was not obtained from any data supplier, list broker, partner company or other third-party source.

2. Legal basis

The email of 24 March 2026 was a direct marketing communication sent to a registered user of our own service, concerning our own similar (paid tier) offering.

The legal basis for the processing of personal data for this purpose is Article 6(1)(f) GDPR. Our legitimate interest is the promotion of our own similar services to our own registered users, which Recital 47 GDPR expressly recognises as a legitimate interest. In carrying out the balancing exercise we took into account that the data used was first-party data provided to us directly by the Data Subject, that the communication concerned the very service for which the Data Subject had registered less than four weeks earlier, and that a free and immediate means of objection was provided in the message itself. This is consistent with our published Privacy Policy, which identifies legitimate interests as the basis on which marketing is carried out.

Upon receipt of the Data Subject's objection we suppressed the email address from all further marketing communications with effect from 2 July 2026. No further marketing communications will be sent. Our records show that the email of 24 March 2026 was the only marketing communication ever sent to this address.

3. Evidence (double opt-in)

No double opt-in verification process was applied to this address: no confirmation email was dispatched, no confirmation click occurred, and accordingly no records of the kind listed in your third question exist. As set out under 2 above, the basis relied upon is not consent.

So that this answer is not left at a bare negative: we do hold a registration record for the event of 28 February 2026, comprising the date and time, the IP address and the user agent string. We are glad to provide that record, and a full copy of the personal data undergoing processing together with the further information under Article 15(1) GDPR, should the Data Subject wish to receive it. Please let us know and we will provide it in a commonly used electronic format.

For completeness, the Data Subject has the right to request rectification or erasure of personal data or restriction of its processing, to object to processing carried out on the basis of legitimate interests, and to lodge a complaint with a supervisory authority.

We trust this answers your questions. Please contact us if anything requires clarification.

Yours sincerely,

[[NAME]]
[[TITLE]], Lumos Labs, Inc.

Sent without prejudice to Lumos Labs, Inc.'s position on any matter not expressly addressed herein.


7. Before dispatch

Not needed for this letter: registration IP, user agent, name, date of birth. Under the narrow answer these are offered, not disclosed (§2).

Separate workstreams, after dispatch: ad-tech disclosure position (§4.1); Wayback check on Privacy Policy §11 and the FTC exposure (§4.2); §25 TDDDG email tracking on the 24 March campaign (§4.3); legal basis for research use of game data (§4.4); German counsel on UWG/Art. 82 (§5); privacy-policy remediation — "implied consent" in §3, the registration-fields mismatch (form requires name and date of birth; policy calls them optional), and the missing §7(3) objection notice on the signup form.

The bigger picture is in §4.5. A large number of German users received the same campaign, so Baur is a sample rather than an incident. The letter goes out tomorrow either way, but the two decisions that actually matter — whether to pause DE sends, and fixing the signup and footer notices — sit outside it and should not wait on it.