Company – €75,000 Fine (Germany, 2023)

€75,000Bundesbeauftragter für den Datenschutz1 January 2023Germany
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

A company in Germany was fined €75,000 for improperly sharing an employee's sick leave information with multiple colleagues. This case matters because it shows that companies must protect sensitive employee data and only share it when necessary.

What happened

A company shared an employee's sick leave information with a large group of colleagues, violating privacy rules.

Who was affected

The employee whose sickness-related absences were disclosed to multiple colleagues.

What the authority found

The Hamburg data protection authority ruled that the company unlawfully disclosed sensitive health information, violating GDPR's requirements for data protection.

Why this matters

This fine highlights the importance of limiting access to sensitive employee data to only those who need it. Companies should ensure their internal policies comply with privacy laws to avoid similar penalties.

GDPR Articles Cited

Art. 9 GDPR
Art. 32 GDPR
Full Legal Summary
Detailed

The DPA of Hamburg imposed a fine of EUR 75,000 on a company. An employee had lodged a complaint with the DPA due to the fact that they had to report their sickness-related absences by e-mail in an e-mail distribution list with 25 colleagues and superiors, although the internal company guideline stipulated that the sickness report only had to be submitted to the manager of the respective department. In addition, their manager had sent an email to a e-mail distribution list with several recipients listing all their sick days. During its investigation, the DPA found that such extensive disclosure was not necessary and therefore unlawful.

Related Enforcement Actions (20)

Other enforcement actions involving Company in DE

Current
Jan 2023

Fine

€75K

Details

Fine Date

1 January 2023

Authority

Bundesbeauftragter für den Datenschutz

Fine Amount

€75,000

Enforcement Tracker ID

ETid-2280

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Company - Germany (2023). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: