Company – €13,000 Fine (Germany, 2020)

€13,000Bundesbeauftragter für den Datenschutz1 January 2020Germany
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

A company was fined EUR 13,000 for sharing customer data between legally separate companies without a proper agreement. This matters because it shows that companies must have clear agreements when sharing data to comply with GDPR. The case highlights the need for transparency and proper data-sharing protocols.

What happened

The company shared customer data with another company without a proper agreement, leading to a fine.

Who was affected

Customers who had their data shared between companies without proper consent or agreement.

What the authority found

The privacy authority fined the company for not having a joint responsibility agreement, violating GDPR's requirements for shared data management.

Why this matters

This case highlights the necessity for companies to establish clear agreements when sharing customer data. It serves as a warning that informal data-sharing practices can lead to significant fines under GDPR.

GDPR Articles Cited

Full Legal Summary
Detailed

The DPA from Hamburg as imposed a fine of EUR 13,000 on a company. An individual had booked and attended a course with a company, but had not paid the course fees incurred. Some time later, he registered for a course at another company of the same parent company and was rejected there. As a reason, he was told that he still had arrears with the company whose courses he had already attended. Following a complaint filed by the individual against the company, the DPA launched an investigation. It found that those companies shared a common database. It pointed out that the maintenance of a common customer database by several, legally independent companies, leads to joint responsibility according to Art. 26 GDPR. According to Art. 26 (2) GDPR, this requires an agreement that reflects the respective actual functions and relationships of the jointly responsible parties towards data subjects. However, such an agreement did not exist.

Related Enforcement Actions (20)

Other enforcement actions involving Company in DE

Current
Jan 2020

Fine

€13K

Details

Fine Date

1 January 2020

Authority

Bundesbeauftragter für den Datenschutz

Fine Amount

€13,000

Enforcement Tracker ID

ETid-1046

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Company - Germany (2020). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: