Art. 15 GDPR response — Friedrich Baur (DE) — review v5
Reviews draft v1.2 (28.07.2026) against Mirco Lehr's letter of 30 June 2026, the 24 March email as sent (Appendix 1), the Pierson Ferdinand thread, the signup form, the published Terms of Service and Privacy Policy, CJEU C-654/23, and live captures of competitor signup flows. Due 30 July 2026.
Read §3.2 before §3.1. §3.1 records the Art. 95 check and concludes an Art. 6 basis is always required; §3.2 corrects that on the authority of a 2025 CJEU judgment. Where the two conflict, §3.2 governs.
1. The request is far narrower than the draft treats it, and that changes everything
Lehr asks three questions and nothing else:
- Source — the URL of the registration page, or the name and serviceable address of the data supplier / partner company
- Legal basis — on which basis do you rely for sending the email
- Evidence — "If you rely on consent", the DOI log data
He then characterises his own request, twice, as narrow: "the narrowly limited information requested here" and "narrowly limited protocol or consent evidence."
He has not asked for a full Art. 15 disclosure. No categories of data, no recipients, no retention period, no international transfers, no automated decision-making, no Art. 15(3) copy.
Draft v1.2 volunteers all of it. That direction came from Maryam's review, which reads the invocation of Art. 15 as triggering the full Art. 15(1) information set — a defensible conservative position, and the one most controllers default to. But look at what the last three rounds of analysis actually found:
| Problem found | Lives in a disclosure that was… |
|---|---|
| The DPF certification gap (§4.2) | Not asked for |
| The DoubleClick / ad-tech recipients denial (§4.1) | Not asked for |
| "60 months" vs. a policy not yet live | Not asked for |
| Purposes/categories mismatch | Not asked for |
| Name and DOB missing from categories | Not asked for |
Every serious problem in this response sits in material nobody requested. The three questions actually asked are answerable cleanly, truthfully and in about half a page.
Recommendation: answer the three questions, and offer the rest. A closing line stating that a full Art. 15(1)/(3) export is available on request preserves the compliance posture — you are not refusing anything, you are responding to the request as the data subject framed it, and Recital 63 supports a controller answering a request the data subject has himself specified. If he later says the response was incomplete, the answer is "you asked three questions; we answered them and offered the rest."
This diverges from Maryam's advice and she should decide it. She is retained and this is a judgment call about risk appetite, not a matter of clear law. But she formed her view without the DPF-gap dates or the ad-tech exposure in front of her, and both cut hard toward the narrow answer. Put it to her as an explicit choice today.
2. What this reverses from my earlier drafts
Being explicit, since the advice has moved:
- Full Art. 15(1) disclosure block — drop it. v2/v3 built out categories, purposes, recipients, retention, transfers and rights. Not requested. Removing it eliminates the DPF, DoubleClick and retention problems from this letter entirely.
- Registration IP and user agent — don't volunteer, offer. I previously said hand them over. That was premised on a broad Art. 15 request. Lehr asks for IP and user agent only within the double opt-in limb, which is expressly conditional on reliance on consent. Since you don't rely on consent, that limb doesn't arise. Say the registration record exists and you'll provide it on request — cooperative, and not a data dump.
- "Mr Baur" / "he" / "his" — remove. Nothing establishes an honorific or pronouns; your original draft said only "the Data Subject" and I introduced them. Revert.
- Art. 15(3) copy — offer, don't attach. Same reasoning.
The draft's structure is kept — only the basis under it changes. v1.2 answers Q3 as a consequence of Q2: assert Art. 13 ePrivacy as the basis for the sending, so the consent question never arises and the DOI logs are moot. That architecture is sound, the revised letter preserves it, and — as §3.1 now records — the draft's underlying instinct about Art. 13 displacing Art. 6 turns out to be correct in law after Inteligo Media. What it cannot survive is the facts. The soft opt-in requires clear notice of the intended advertising use at the point of collection, and the DE signup form carries none; v1.2 also states the email "contained a clear, free-of-charge unsubscribe option", whereas the actual footer reads only "Update preferences … or unsubscribe", with nothing about cost — and Lehr attached that email to his own letter as Appendix 1. A written basis he can break with a document already in his hands costs more than the gap it fills.
What does not change: drop the Art. 95 lex specialis argument — it is a duplicate-administrative-burden provision scoped to processing in connection with providing a publicly available electronic communications service, which this is not (verified at §3.1) — and state Art. 6(1)(f), which your own Privacy Policy §3 already names for marketing. Do not assert the §7(3) UWG soft opt-in — see §3.
3. Do not assert the soft opt-in
Question 2 asks the basis "for sending the email" — that is the ePrivacy/UWG question, and it is the trap. Against §7(3) UWG, all four conditions cumulative:
| Condition | Status | |
|---|---|---|
| 1 | Address obtained "im Zusammenhang mit dem Verkauf" — in connection with a sale | Satisfied — corrected, see §3.1. Free registration qualifies: the data is the consideration (CJEU C-654/23; OLG München 29 U 2799/17). |
| 2 | Advertising for own similar goods or services | Satisfied |
| 3 | Customer has not objected | Satisfied at the time |
| 4 | Informed klar und deutlich at the point of collection and in each message of the right to object at no cost beyond base transmission rates | Fails on both limbs. The DE form is confirmed identical to the English one, translated — no objection notice, only "you agree to our Terms of Service, Privacy Policy…", and the ToS contain no marketing provisions at all. The email footer offers "Update preferences … or unsubscribe" but says nothing about the objection being free of charge, which Nr. 4 requires. |
One of four fails — and one is enough. The conditions are cumulative, so the outcome is unchanged: the soft opt-in is not available and must not be asserted. But the reasoning has narrowed to a single point, and it is the most evidentially exposed of the four: the signup page is public, and Lehr already holds the email. There is nothing to argue about.
Do not argue German unfair-competition law in a DSAR reply. But note the Art. 6(1)(f) answer now carries a complication — see §3.2.
What the email settles. It is unambiguously Werbung — "25% off on Lumosity Premium" in the preheader, an "UPGRADE OFFER" block, "Premium vs Free", "Get Premium". There is no arguing it was a transactional or service message, so don't try. Two things do help: it advertises Lumosity Premium to a registered free user, which squarely satisfies condition 2 (own similar service); and the sender is identifiable (newsletter@notifications.lumosity.com, with the company name and address in the footer), so §7(2) Nr. 4 UWG sender-concealment and §5 DDG provider identification are not in play.
One thing that helps: there is no marketing consent checkbox on the form, so "no consent was obtained" is accurate. No risk of a false denial.
And the ADM answer is safer than assumed. The email markets the Game Strength Profile and Personalized Insights as Premium features — the comparison table shows Personalized Insights as "None" on Free. Baur held a free account, so these features were most likely never applied to him at all. The LPI ranking is still profiling under Art. 4(4), but it remains well outside Art. 22(1). Kunal's read holds, with room to spare.
3.1 Article 95 — checked against the source, and it does not apply
Verified against the text of Art. 95 and EDPB Opinion 5/2019 (12 March 2019), which is the authority directly on this interplay. Three findings, in order of what they settle.
Art. 13 ePrivacy does apply to Lumos — but that has nothing to do with Art. 95. The Opinion's §3.2.2 is headed "The extended material scope of articles 5(3) and 13 ePrivacy Directive", and para 28 states that those articles *"apply to providers of electronic communication services as well as website operators (e.g. for cookies) or other businesses (e.g. for direct marketing)"*, giving as its worked example: "Unsolicited electronic mail sent by a website operator for the purposes of direct marketing also fall within the extended material scope of article 13 ePrivacy Directive." That is Lumos exactly. So the draft is right that Art. 13 is engaged. It reached that conclusion through the wrong provision.
Art. 95 is confined to ECS providers, and its function is narrower than the draft assumes. Para 44: "The aim of article 95 GDPR is therefore to avoid the imposition of unnecessary administrative burdens upon controllers who would otherwise be subject to similar but not quite identical administrative burdens." The Opinion's only worked example is double breach notification — an ECS provider that has notified under national ePrivacy law need not notify the same breach again under Art. 33 GDPR. Art. 95 is a duplicate-paperwork provision. It is not a switch that turns off Chapter II.
Even where ePrivacy does govern, an Art. 6 basis is still required. Para 41, on cookies, is the closest structural analogue: the placing or reading of cookies must comply with the national transposition of Art. 5(3), and "Subsequent processing of personal data including personal data obtained by cookies must also have a legal basis under article 6 of the GDPR in order to be lawful." Same two-step here: Art. 13 / §7 UWG governs whether the message could be sent; Art. 6 governs the processing. The draft's conclusion — that Art. 13 displaces the need to state an Art. 6 basis — does not follow even on its own premises.
Is there any route to applicability? One, and it fails. Since the EECC (Directive (EU) 2018/1972, applicable from 21 December 2020, and referenced in the Opinion's own footnote 14), "electronic communications service" was broadened to include number-independent interpersonal communications services — OTT messaging. If Lumosity operated user-to-user messaging, that component might arguably qualify. But Art. 95 covers processing "in connection with the provision of" such a service, and a Premium upsell campaign is not that; and para 44 shows the relief on offer is duplicate-notification relief, not dispensation from a legal basis. There is no reading on which this helps.
What the draft was reaching for that is legitimate. A lex specialis relationship genuinely exists — paras 35, 38 and 45 confirm it — but it flows from Art. 1(2) of the ePrivacy Directive ("particularise and complement"), not from Art. 95, and para 38 is explicit that it operates only where ePrivacy specifically governs, with the GDPR applying to everything else. Citing Art. 95 to a German lawyer would read as argument-construction and invites a correction on the record.
3.2 Correction — Inteligo Media changes two things, and the DPO was closer to right than I credited
Benchmarking research surfaced a 2025 CJEU judgment that postdates EDPB Opinion 5/2019 and overturns part of my analysis above. CJEU C-654/23, Inteligo Media SA v ANSPDCP, 13 November 2025.
The facts are uncomfortably close to these. A Romanian platform, avocatnet.ro, offered free user accounts; users registered with an email address and received a daily newsletter whose links drove them to the platform's paid premium content. It was sent without express consent. The Romanian DPA fined the operator ~€9,000 on the basis that an Art. 6 GDPR ground was required.
Correction 1 — the "sale" condition is satisfied, not failed. I previously wrote that a free signup cannot be a Verkauf and that condition 1 failed. That was wrong. The Court held that supplying personal data as consideration for a digital service qualifies: the provision of an email address in exchange for access to a valuable digital service functions as a contractual exchange equivalent to a purchase price. German courts had already got there — OLG München, 15 February 2018, 29 U 2799/17 held that "Verkauf" in §7(3) UWG needs no monetary payment and covers any exchange contract, on facts involving free profiles on a dating platform whose free and paid tiers served the same purpose. Lumosity's free tier and Premium plainly serve the same purpose.
Correction 2 — the draft's Art. 6 instinct was right. v1.2 said it would "address the communication by reference to Article 13 rather than Article 6(1) GDPR." On the authority above that is correct: where the Art. 13(2) conditions are met, Art. 6 GDPR is not applicable, and lawfulness is established under Art. 13(2) alone without a separate consent or legitimate-interests ground. My §3.1 analysis rested on EDPB Opinion 5/2019, which a 2025 judgment supersedes on this specific point. The draft's route — Art. 95 — remains wrong for every reason set out above. Its destination was right.
What does not change. The relief is conditional on all four conditions being met, and the Court preserved them, including clear notice of the intended advertising use at the time of collection. That condition fails here, so Art. 13(2) does not establish lawfulness and does not displace Art. 6. Variant B stands.
But a new drafting tension follows, and it needs German counsel. Post-Inteligo, Art. 6 and Art. 13(2) are alternatives rather than cumulative. So stating "the legal basis is Art. 6(1)(f)" now carries an implicit signal that Art. 13(2) is unavailable — because if it were available, you would not need Art. 6. A German lawyer who has read Inteligo can draw that inference. The alternatives are worse: asserting Art. 13(2) invites him to break it with the signup page, and refusing to answer feeds the narrative he pre-built. Art. 6(1)(f) remains my recommendation, but at lower confidence than before, and this specific point should go to German counsel today rather than being settled internally.
And the letter still is not a cure. Where ePrivacy restricts an operation, the available Art. 6 grounds narrow with it (Opinion 5/2019 para 39). If the send breached §7(3) UWG, a German authority is likely to find the legitimate-interests balancing fails too, since there is no legitimate interest in conduct sector law prohibits.
Sources: Art. 95 GDPR · EDPB Opinion 5/2019 · C-654/23 analysis, GvW · C-654/23 analysis, Inxmail · OLG München 29 U 2799/17, IT-Recht Kanzlei · EU Law Live on the Art. 6 point
4. The two exposures that stay out of the letter but need owners
4.1 The ad-tech recipients denial
Draft v1.2 says data "has not been disclosed to third parties for marketing purposes." Privacy Policy §6 names DoubleClick "and others" for ad serving, plus Google Analytics, Rollbar and New Relic. If tags fired on Baur's sessions, that denial is false. Under the narrow answer this sentence simply doesn't appear — which is the cleanest fix available. But eng should still establish the position, because it will surface if he escalates, and it bears on §25 TDDDG cookie consent generally.
4.2 The DPF certification gap
Privacy Policy §11 states "Lumos Labs complies with the EU-U.S. Data Privacy Framework." Maryam confirms certification expired in 2024 and was renewed 1 July 2026.
| DPF certification expired | 2024 |
| Baur registers | 28 February 2026 |
| Marketing email sent | 24 March 2026 |
| Lehr's letter | 30 June 2026 |
| DPF renewed | 1 July 2026 |
For ~2 years the public notice claimed participation in a framework the company wasn't certified under, covering every act in this complaint; renewal landed the day after the letter. Two exposures: the misstatement in the notice in force on 24 March (Wayback plus the public list at dataprivacyframework.gov proves it in minutes — confirm what §11 actually said then), and, more probably, FTC deception, which is enforced independently of anything Baur does. Neither belongs in this letter. Both belong on Maryam's desk as separate workstreams.
4.3 Email tracking and §25 TDDDG
The email carries an "Update preferences for friedrich.baur@gfbaur.de" link and multiple campaign links, and draft v1.2 lists "email delivery and unsubscribe records" — engagement tracking — among the data processed. If the message contained an open-tracking pixel or click tracking, that is storage of or access to information on terminal equipment under §25 TDDDG, which requires prior consent in Germany and has no legitimate-interests route. It is a distinct violation from the §7 UWG point and survives independently of it.
This is confirmed by the same authority relied on at §3.1: EDPB Opinion 5/2019 para 28 puts Art. 5(3) alongside Art. 13 in the "extended material scope", applying to "website operators (e.g. for cookies) or other businesses" — so §25 TDDDG binds Lumos here just as §7 UWG does. And para 41 adds a second limb often missed: where data is obtained through such access, the "subsequent processing of personal data … must also have a legal basis under article 6 of the GDPR in order to be lawful." So email engagement data needs both consent for the access and an Art. 6 basis for what is then done with it.
Nobody has looked at this. Confirm with the ESP what tracking was enabled on the 24 March campaign for DE recipients. It stays out of the letter — not asked — but it is squarely within what a UWG/Art. 82 follow-up would reach, and it connects to the wider cookie-consent question in §4.1.
DE cookie consent runs through Usercentrics, a German CMP that supports proper prior blocking — a good sign for the website side, and it materially reduces the §4.1 concern about ad and analytics tags. Two caveats remain. First, the platform is not the test, the configuration is: what matters is whether Google Analytics and any advertising tags are actually gated behind affirmative consent rather than merely listed. Second, a website CMP does nothing for email open-tracking consent — a pixel in a marketing email needs consent obtained for that purpose, and no web banner reaches it. §4.3 therefore stands independently of how well Usercentrics is configured.
4.4 Research use of user data
The email's lead item reports "A study of Lumosity users found that people living in densely populated cities scored higher on fluid intelligence…". Scientific research on user game data is a processing purpose that appears nowhere in draft v1.2's purposes list. Irrelevant under the narrow answer, but if Maryam chooses full Art. 15(1) disclosure it has to be stated, with its own legal basis. Worth confirming separately what basis research use runs on and whether the privacy notice covers it.
4.5 Scale — this is a campaign issue, not a Baur issue
Confirmed: a large number of German users received the 24 March campaign. That reframes the matter.
The defect is not specific to Baur. If the DE list was mailed on the same footing — no consent, no §7(3) Nr. 4 objection notice at signup, no free-of-charge notice in the footer, tracking presumptively enabled — then every one of those sends carries the same defect, and the analysis in §3 applies to all of them. Consequences worth weighing today:
- UWG. Each recipient can seek Unterlassung. So can competitors, the Wettbewerbszentrale and the Verbraucherzentralen — standing is not limited to the recipient.
- Art. 82. German awards for unsolicited marketing email are typically modest per claimant, but the exposure scales with the list, and firms exist to aggregate exactly this.
- Regulatory. A German DPA looking at this would examine the campaign, not the single send.
- Other complaints may already be in the DPO inbox. Check. If Lehr's firm is running volume — the reference CY-56419-MM reads like a case-management system — more are likely.
Two decisions for today, separate from the letter:
- Whether to pause DE marketing sends pending a fixed signup notice and footer. Every further send on the current footing compounds the exposure. This is a business call, but it should be made deliberately rather than by default.
- Fix forward on the signup form — this is now the highest-ROI action available. After Inteligo (§3.2), Lumosity's freemium model does qualify for the soft opt-in; conditions 1, 2 and 3 are met. The entire exposure traces to one missing sentence at the point of collection and a missing four words in the email footer. Add a clear notice of the intended advertising use and the free right to object at signup, and repeat it with the cost wording in every marketing footer, and the whole DE programme becomes lawful under §7(3) prospectively — and per Inteligo, no Art. 6 basis is then required at all. Cheap, fast, and it stops the clock. Doing it now is not an admission about past sends.
Benchmarking note. Whether Duolingo, Babbel or anyone else does this is worth knowing but is not a defence — a competitor's non-compliance is not a safe harbour, and after Inteligo the test is clear enough not to need a proxy. See §8 for what could and could not be verified.
And it makes the narrow answer in §1 more clearly right, not less. Whatever is conceded in writing to Lehr becomes the template used against the whole campaign. A short, accurate answer to three questions puts far less on the record than a full voluntary Art. 15 disclosure would.
5. Handling points from the letter itself
Do not ask for ID. Lehr pre-empts it, citing Art. 5(1)(c) and Art. 12(6), and warns that refusal "may be taken to your disadvantage in potential court proceedings." He encloses a power of attorney (Appendix 2). Art. 12(6) permits further identification only on reasonable doubts; possession of the email plus a PoA leaves none. Requesting ID would manufacture the refusal narrative he is setting up. But confirm the PoA was actually attached and covers this — responding to an unauthorised third party is itself a breach.
"Potential court proceedings" is stated, but no claim is yet made. There is no Unterlassungserklärung demand, no Art. 82 damages claim, no deadline of his own. This is evidence-gathering — the DOI-log request is the standard German template for establishing that no documented double opt-in exists, which BGH case law requires to prove consent for email marketing. Expect a follow-up. Engage German counsel now on the UWG/Art. 82 track; it need not delay tomorrow.
Reply by email as invited, but consider sending the substance as an attached PDF on letterhead rather than in the body.
Deadline: their letter is 30 June, so Art. 12(3) expires 30 July 2026. An extension must be notified within the first month with reasons — that window closes with the deadline, and Maryam rightly calls it a last resort.
Check the address before it goes on letterhead. The email footer reads "16 Maiden Lane, Suite 6"; the Terms of Service say "16 Maiden Lane, Floor 6". One of them is wrong. Confirm which before stating the controller's address in a formal response.
6. Revised letter — narrow form
Answers the three questions asked, offers everything else. Unresolved items marked [[LIKE THIS]].
Drafting guard for whoever redlines this. Question 2 asks the basis "for sending the email", but paragraph 2 of the letter deliberately says "the legal basis for the processing of personal data for this purpose." Do not "correct" that to match Lehr's wording. Sending and processing are legally distinct — ePrivacy Art. 13 and §7 UWG govern whether the message could be sent, Art. 6 governs the processing (§3.1) — and writing "the legal basis for sending the email is Art. 6(1)(f)" would assert something that is not true and concede the UWG framing in the same breath.
Lumos Labs, Inc.
16 Maiden Lane, Floor 6, San Francisco, CA 94108, USA
Mirco Lehr
[[FIRM AND ADDRESS]]
Your ref: CY-56419-MM · Our ref: [[REF]]
[[DATE]] July 2026
Re: Request for information pursuant to Article 15 GDPR — Friedrich Baur
Dear Mr Lehr,
We refer to your letter of 30 June 2026 concerning your client Friedrich Baur ("the Data Subject") and respond below to the three questions raised.
The controller is Lumos Labs, Inc., 16 Maiden Lane, Floor 6, San Francisco, CA 94108, USA. Our Data Protection Officer may be contacted at dpo@lumoslabs.com. Our representative in the Union pursuant to Article 27 GDPR is Charles Guillemet, 3 Rue Villaret de Joyeuse, 75017 Paris, France.
We accept the authority evidenced by the power of attorney enclosed with your letter and do not require further proof of identity.
1. Source of the data
The email address was entered by the Data Subject on the registration form at https://app.lumosity.com/de/signup when creating a free Lumosity account on 28 February 2026 at 18:15:08 UTC. Registration was completed directly by email; no third-party sign-in provider was used.
The email address was not obtained from any data supplier, list broker, partner company or other third-party source.
2. Legal basis
The email of 24 March 2026 was a direct marketing communication sent to a registered user of our own service, concerning our own similar (paid tier) offering.
The legal basis for the processing of personal data for this purpose is Article 6(1)(f) GDPR. Our legitimate interest is the promotion of our own similar services to our own registered users, which Recital 47 GDPR expressly recognises as a legitimate interest. In carrying out the balancing exercise we took into account that the data used was first-party data provided to us directly by the Data Subject, that the communication concerned the very service for which the Data Subject had registered less than four weeks earlier, and that a free and immediate means of objection was provided in the message itself. This is consistent with our published Privacy Policy, which identifies legitimate interests as the basis on which marketing is carried out.
Upon receipt of the Data Subject's objection we suppressed the email address from all further marketing communications with effect from 2 July 2026. No further marketing communications will be sent. Our records show that the email of 24 March 2026 was the only marketing communication ever sent to this address.
3. Evidence (double opt-in)
No double opt-in verification process was applied to this address: no confirmation email was dispatched, no confirmation click occurred, and accordingly no records of the kind listed in your third question exist. As set out under 2 above, the basis relied upon is not consent.
So that this answer is not left at a bare negative: we do hold a registration record for the event of 28 February 2026, comprising the date and time, the IP address and the user agent string. We are glad to provide that record, and a full copy of the personal data undergoing processing together with the further information under Article 15(1) GDPR, should the Data Subject wish to receive it. Please let us know and we will provide it in a commonly used electronic format.
For completeness, the Data Subject has the right to request rectification or erasure of personal data or restriction of its processing, to object to processing carried out on the basis of legitimate interests, and to lodge a complaint with a supervisory authority.
We trust this answers your questions. Please contact us if anything requires clarification.
Yours sincerely,
[[NAME]]
[[TITLE]], Lumos Labs, Inc.
Sent without prejudice to Lumos Labs, Inc.'s position on any matter not expressly addressed herein.
7. Before dispatch
- Maryam to decide narrow vs. full Art. 15 disclosure (§1) — the one real decision left
-
Signup path— confirmed direct email registration, no SSO. Question 1 answered definitively. -
Art. 95 applicability— checked against the source; it does not apply (§3.1). - Confirm only one marketing email was ever sent to this address. The letter asserts it; the send log has to support it.
- Confirm the power of attorney was attached to Lehr's letter and covers this request
- Confirm the controller's address — "Suite 6" or "Floor 6"
- Check whether other DE complaints or DSARs have arrived (see §4.5)
- EU Rep / DPO sign-off — Maryam's approval is conditioned on it
- Every
[[bracket]]resolved
Not needed for this letter: registration IP, user agent, name, date of birth. Under the narrow answer these are offered, not disclosed (§2).
Separate workstreams, after dispatch: ad-tech disclosure position (§4.1); Wayback check on Privacy Policy §11 and the FTC exposure (§4.2); §25 TDDDG email tracking on the 24 March campaign (§4.3); legal basis for research use of game data (§4.4); German counsel on UWG/Art. 82 (§5); privacy-policy remediation — "implied consent" in §3, the registration-fields mismatch (form requires name and date of birth; policy calls them optional), and the missing §7(3) objection notice on the signup form.
The bigger picture is in §4.5. A large number of German users received the same campaign, so Baur is a sample rather than an incident. The letter goes out tomorrow either way, but the two decisions that actually matter — whether to pause DE sends, and fixing the signup and footer notices — sit outside it and should not wait on it.
8. Benchmarking — what was and was not verified
Duolingo DE — captured live, 29 July 2026 (headless Chrome, de-DE locale, Europe/Berlin; flow walked to the credential form and stopped before submission — no account was created).
The German registration flow is two steps:
- Alter (age) — required, collected before anything else
- "Erstelle dein Profil" — Name (optional), E-Mail-Adresse, Passwort, then KONTO ERSTELLEN, with Google and Facebook SSO beneath
The only legal text on the collection screen:
"Durch deine Anmeldung bei Duolingo erklärst du dich mit unseren Geschäftsbedingungen und unserer Datenschutzerklärung einverstanden."
Zero checkboxes on the form. No marketing consent. No §7(3) Nr. 4 objection notice. Structurally identical to Lumosity's: blanket assent to terms plus privacy policy, and nothing about advertising use or a free right to object at the point of collection. On condition 4, Duolingo is in the same position Lumos is.
Two contrasts that run against Lumos, though. Duolingo makes Name optional and collects age only; the Lumosity form requires Name and a full day/month/year date of birth. Against the closest mass-market comparator, Lumos collects more identifying data than it needs at registration — an Art. 5(1)(c) data-minimisation point. Note that Lehr already invoked Art. 5(1)(c) in the identity-verification section of his letter, so it is a principle he is alert to.
NeuroNation (Synaptikon GmbH, Berlin) — the closest comparator, and it takes the other route. A direct brain-training competitor domiciled in Germany. Its German marketing signup carries an explicit, unticked opt-in checkbox:
"Ich bin damit einverstanden, Marketingmitteilungen zu erhalten."
on a form collecting E-Mail Adresse and Name (Optional). That is the consent route — §7(2) Nr. 3 UWG ausdrückliche Einwilligung / Art. 6(1)(a) — which sidesteps §7(3) and its notice requirement altogether. It is also what produces exactly the double opt-in records Lehr's letter demands.
Caveat: this was captured on their web marketing form. NeuroNation's app registration is not reachable through the web funnel — the web path routes to login only, so account creation appears to be in-app. I could not verify what the in-app registration screen shows.
So the two comparators sit on opposite sides. Duolingo runs the soft-opt-in posture without the §7(3) Nr. 4 notice — the same position as Lumos. The German-domiciled competitor in Lumos's own vertical runs explicit consent instead. That is the safer design and typically what German counsel advises.
Which gives Lumos two fix-forward options, not one:
| Route A — soft opt-in (§7(3)) | Route B — consent (§7(2) Nr. 3) | |
|---|---|---|
| Change | Notice at collection + free-of-charge wording in footer | Unticked opt-in checkbox at signup + double opt-in |
| Friction | None | Reduces list growth |
| Covers existing base | Yes, prospectively | No — needs re-permissioning |
| Answers a future Lehr letter | "Conditions of §7(3) met" | Produces the DOI logs outright |
Recommendation: Route A. Post-Inteligo it is legally solid, it costs one sentence and four words, and it covers the whole existing German base going forward — which Route B does not. Route B is worth considering for new DE signups later if the risk appetite tightens.
Babbel: not reached. Registration sits behind a multi-step onboarding funnel the run did not clear.
Screenshots and scripts: scratchpad/duo_04_credentials.png, capture_signup.py, duo_flow2.py.
The important caveat. After Inteligo the legal test is clear enough that a proxy adds little, and a competitor's practice is not a defence — LG Paderborn (2 O 325/23) found a §7(3) breach where a trader had relied on privacy-policy wording plus an unsubscribe link, holding the notice insufficient because it was buried without emphasis in a 26-page document and had to appear both at collection and at each use. Whatever the market does, that is the standard.
What compliance actually looks like at the point of collection — a visible line adjacent to the email field or the submit button, not behind a link:
Wir verwenden Ihre E-Mail-Adresse, um Ihnen Informationen zu eigenen ähnlichen Produkten und Angeboten zu senden. Sie können dieser Nutzung jederzeit widersprechen, ohne dass hierfür andere als die Übermittlungskosten nach den Basistarifen entstehen.
And the same in every marketing footer, where the current "Update preferences … or unsubscribe" needs the cost wording added. Those two changes are the whole fix.