Data protection officer – €500 Fine (Germany, 2022)

€500Bundesbeauftragter für den Datenschutz1 January 2022Germany
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

A data protection officer in Germany was fined for sharing a photo of an injured person in a company WhatsApp group without their consent. This matters because it highlights the importance of having a valid reason to share personal information, even within a company. The fine shows that privacy rules apply to internal communications too.

What happened

A company data protection officer shared a photo of an injured person in a WhatsApp group without consent.

Who was affected

The person in the photo, who was injured and did not agree to have their image shared.

What the authority found

The authority found the sharing of the photo unlawful due to the lack of a valid reason under GDPR.

Why this matters

This case reminds businesses that sharing personal information internally still requires a valid legal basis. It underscores the need for companies to ensure all staff understand privacy rules, even in casual communication settings.

GDPR Articles Cited

Art. 6 GDPR
Full Legal Summary
Detailed

The DPA of Thüringen has imposed a three-digit fine on the data protection officer of a company. The controller had posted a photo in a WhatsApp group of the company which showed the data subject bleeding heavily after a physical attack. The data subject had not consented to the publication in the WhatsApp group, which is why the DPA concluded that the publication was unlawful due to the lack of a valid legal basis.

Related Enforcement Actions (0)

No other enforcement actions found for Data protection officer in DE

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

1 January 2022

Authority

Bundesbeauftragter für den Datenschutz

Fine Amount

€500

Enforcement Tracker ID

ETid-1974

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Data protection officer - Germany (2022). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: