Unknown – €20,000 Fine (Germany, 2018)

€20,000Bundesbeauftragter für den Datenschutz1 January 2018Germany
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

A company in Germany was fined €20,000 for not reporting a data breach on time and failing to inform the people affected. This matters because it shows how important it is to act quickly and transparently when personal data is compromised.

What happened

A company failed to promptly report a data breach and did not notify the affected individuals.

Who was affected

Individuals whose personal data was involved in the unreported data breach.

What the authority found

The German authority fined the company for not meeting GDPR requirements to notify authorities and individuals about a data breach in a timely manner.

Why this matters

This case highlights the critical need for companies to have effective breach notification procedures. It serves as a reminder that delays in reporting can lead to significant penalties.

GDPR Articles Cited

AI-verified

Art. 33(1) GDPR
Art. 34(1) GDPR
View original scraped data
Art. 33(1) GDPR
Art. 34(1) GDPR

Original data from scraper before AI verification against source document.

Source verified 13 March 2026
verified correct
Full Legal Summary
Detailed

Late notification of a data breach and failure to notify the data subjects.

Related Enforcement Actions (8)

Other enforcement actions involving Unknown in DE

Details

Fine Date

1 January 2018

Authority

Bundesbeauftragter für den Datenschutz

Fine Amount

€20,000

Enforcement Tracker ID

ETid-29

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Unknown - Germany (2018). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: