Telecoms provider (1&1 Telecom GmbH) – €900,000 Fine (Germany, 2020)

€900,000Bundesbeauftragter für den Datenschutz11 November 2020Germany
reduced
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

1&1 Telecom GmbH was fined €900,000 for not adequately protecting customer data. Their customer service allowed access to personal data using just a name and birthdate, which was deemed insufficient security. This case emphasizes the need for strong data protection measures in customer service operations.

What happened

1&1 Telecom GmbH's customer service allowed access to personal data with only a name and birthdate.

Who was affected

Customers of 1&1 Telecom GmbH were affected because their personal data could be accessed too easily.

What the authority found

The German data protection authority found that 1&1 Telecom GmbH violated GDPR by failing to implement adequate security measures for customer data.

Why this matters

This case highlights the importance of robust security measures to protect personal data, especially in customer service. It serves as a warning for companies to regularly review and update their data protection practices.

GDPR Articles Cited

AI-verified

Art. 32 GDPR
View original scraped data
Art. 32 GDPR

Original data from scraper before AI verification against source document.

Source verified 5 March 2026
amount discrepancy
date discrepancy
Full Legal Summary
Detailed

Original Fine Summary: The Controller is a company offering telecommunication services. A caller could obtain extensive information on personal customer data from the company's customer service department simply by entering a customer's name and date of birth. In this authentication procedure, the BfDI aws a violation of Article 32 GDPR, according to which a company is obliged to take appropriate technical and organisational measures to systematically protect the processing of personal data. Due to the company's cooperation with the data protection authority, the fine imposed was at the lower end of the scale. -- Update: On November 11th, 2020, after an appeal against the fine, the Bonn District Court decided that although the fine is justified in principle, it is unreasonably high. The chamber has therefore reduced the fine from originally EUR 9,55 million to EUR 900,000. One of the reasons for the reduction was that the company's procedure for authenticating customers used for its telephone hotline (requesting only the name and date of birth of the caller) had remained unobjected for a long time and therefore the company lacked a concrete awareness of the problem which leads to the fact that the concrete culpability in this case had to be classified as rather low. Furthermore, according to the court, the violation was also rather minor, as it could not lead to a massive data leakage.

Related Enforcement Actions (0)

No other enforcement actions found for Telecoms provider (1&1 Telecom GmbH) in DE

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

11 November 2020

Authority

Bundesbeauftragter für den Datenschutz

Fine Amount

€900,000

Enforcement Tracker ID

ETid-128

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Telecoms provider (1&1 Telecom GmbH) - Germany (2020). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: