AVANTCORE Rechtsanwälte
Menu

Federal Court of Justice (BGH) denies liability for interference for password-protected WLAN

Must an internet user change an individual, pre-set WLAN router password to secure the internet connection in order to avoid liability for interference, or is this not necessary? This has been frequently discussed to date. Now the Federal Court of Justice (BGH) has stated its position.

The proceedings concerned the film "The Expendables 2", which was offered for download via the internet connection of a private person. The connection holder subsequently received a cease-and-desist letter. However, the film was not made publicly accessible by the connection holder, but by an unknown third party who had gained unauthorised access to the connection holder's WLAN.

The router was secured with a 16-digit WPA2 key issued by the manufacturer. This was printed on the back of the router. The connection holder had not changed this password when setting up the router, although it would have been possible to do so.

The claimant asserts that the connection holder must therefore be liable as an interferer. Both the Local Court (AG) Hamburg and the Regional Court (LG) Hamburg had previously already dismissed the action.

The decision of the Federal Court of Justice (BGH)

The claimant's appeal was also unsuccessful. By judgment of 24.11.2016 – Az. I ZR 220/15 (Press release) the Federal Court of Justice (BGH) denied liability for interference by the connection holder.

The Federal Court of Justice (BGH) takes the view that the defendant connection holder did not breach any examination duties and therefore is not liable as an interferer for copyright infringements committed via her internet connection by an unknown third party.

The judges in Karlsruhe are of the opinion that the holder of an internet connection with WLAN functionality is obliged to examine whether the router used has the security measures customary in the market at the time of its purchase for the private sector, namely a current encryption standard and an individual, sufficiently long and secure password. Retention of a WLAN password pre-set by the manufacturer can constitute a breach of the examination duty if it is not a password used individually for each device, but rather a password used for a plurality of devices.

Here, the claimant failed to provide evidence that it was a password that had been pre-set by the manufacturer for a plurality of devices.

Conclusion

Internet users must protect their WLAN against misuse by unauthorised persons, but are not liable for every security gap. As long as the same password is not pre-set on multiple devices, there is a presumption of adequate security customary in the market.

Last updated
05 December 2016
Author
Christopher A. Wolf, MBA

This is a translation of the German original. In case of discrepancies, the German version prevails.

All news
Federal Court of Justice (BGH) denies liability | AVANTCORE