Company – €50,000 Fine (Germany, 2022)

€50,000Bundesbeauftragter für den Datenschutz1 January 2022Germany
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

A company in Germany was fined €50,000 for sending out a social plan with personal details of employees to all staff without permission. This is important because it shows that companies must protect sensitive employee information.

What happened

The company sent an unredacted social plan containing personal details to all employees without a legal basis.

Who was affected

Employees whose personal data, including sensitive information like disability status, was disclosed to all staff.

What the authority found

The DPA ruled that the company unlawfully disclosed personal data without a valid legal basis, violating GDPR's requirements for data protection.

Why this matters

This case underscores the need for companies to handle sensitive employee data carefully and ensure they have a legal basis for any disclosures. It serves as a warning to protect employee privacy, especially when dealing with sensitive information.

GDPR Articles Cited

Art. 6(1) GDPR
Full Legal Summary
Detailed

The DPA of Bremen has imposed a five-digit fine on a company. The company had sent an unredacted social plan to all affected employees in the context of dismissals due to operational reasons, resulting in the disclosure of personal data contained therein, such as date of birth, age, marital status, number of dependent children, function in the company, severe disability, etc., to all employees. The DPA found that such extensive disclosure of personal data was unlawful due to the lack of a legal basis. The DPA considered the fact that special categories of personal data, such as information on a severe disability, had also been disclosed to be an aggravating factor.

Related Enforcement Actions (20)

Other enforcement actions involving Company in DE

Current
Jan 2022

Fine

€50K

Details

Fine Date

1 January 2022

Authority

Bundesbeauftragter für den Datenschutz

Fine Amount

€50,000

Enforcement Tracker ID

ETid-1724

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Company - Germany (2022). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: