Company – €13,000 Fine (Germany, 2020)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
A company was fined EUR 13,000 for sharing customer data between legally separate companies without a proper agreement. This matters because it shows that companies must have clear agreements when sharing data to comply with GDPR. The case highlights the need for transparency and proper data-sharing protocols.
What happened
The company shared customer data with another company without a proper agreement, leading to a fine.
Who was affected
Customers who had their data shared between companies without proper consent or agreement.
What the authority found
The privacy authority fined the company for not having a joint responsibility agreement, violating GDPR's requirements for shared data management.
Why this matters
This case highlights the necessity for companies to establish clear agreements when sharing customer data. It serves as a warning that informal data-sharing practices can lead to significant fines under GDPR.
GDPR Articles Cited
The DPA from Hamburg as imposed a fine of EUR 13,000 on a company. An individual had booked and attended a course with a company, but had not paid the course fees incurred. Some time later, he registered for a course at another company of the same parent company and was rejected there. As a reason, he was told that he still had arrears with the company whose courses he had already attended. Following a complaint filed by the individual against the company, the DPA launched an investigation. It found that those companies shared a common database. It pointed out that the maintenance of a common customer database by several, legally independent companies, leads to joint responsibility according to Art. 26 GDPR. According to Art. 26 (2) GDPR, this requires an agreement that reflects the respective actual functions and relationships of the jointly responsible parties towards data subjects. However, such an agreement did not exist.
Related Enforcement Actions (20)
Other enforcement actions involving Company in DE
Fine
€13K
Details
Fine Date
1 January 2020
Authority
Bundesbeauftragter für den Datenschutz
Fine Amount
€13,000
Enforcement Tracker ID
ETid-1046
About this data
Cite as: Cookie Fines. Company - Germany (2020). Retrieved from cookiefines.eu
Last updated: