Telecoms provider (1&1 Telecom GmbH) – €900,000 Fine (Germany, 2020)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
1&1 Telecom GmbH was fined €900,000 for not adequately protecting customer data. Their customer service allowed access to personal data using just a name and birthdate, which was deemed insufficient security. This case emphasizes the need for strong data protection measures in customer service operations.
What happened
1&1 Telecom GmbH's customer service allowed access to personal data with only a name and birthdate.
Who was affected
Customers of 1&1 Telecom GmbH were affected because their personal data could be accessed too easily.
What the authority found
The German data protection authority found that 1&1 Telecom GmbH violated GDPR by failing to implement adequate security measures for customer data.
Why this matters
This case highlights the importance of robust security measures to protect personal data, especially in customer service. It serves as a warning for companies to regularly review and update their data protection practices.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
Original Fine Summary: The Controller is a company offering telecommunication services. A caller could obtain extensive information on personal customer data from the company's customer service department simply by entering a customer's name and date of birth. In this authentication procedure, the BfDI aws a violation of Article 32 GDPR, according to which a company is obliged to take appropriate technical and organisational measures to systematically protect the processing of personal data. Due to the company's cooperation with the data protection authority, the fine imposed was at the lower end of the scale. -- Update: On November 11th, 2020, after an appeal against the fine, the Bonn District Court decided that although the fine is justified in principle, it is unreasonably high. The chamber has therefore reduced the fine from originally EUR 9,55 million to EUR 900,000. One of the reasons for the reduction was that the company's procedure for authenticating customers used for its telephone hotline (requesting only the name and date of birth of the caller) had remained unobjected for a long time and therefore the company lacked a concrete awareness of the problem which leads to the fact that the concrete culpability in this case had to be classified as rather low. Furthermore, according to the court, the violation was also rather minor, as it could not lead to a massive data leakage.
Related Enforcement Actions (0)
No other enforcement actions found for Telecoms provider (1&1 Telecom GmbH) in DE
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
11 November 2020
Authority
Bundesbeauftragter für den Datenschutz
Fine Amount
€900,000
Enforcement Tracker ID
ETid-128
About this data
Cite as: Cookie Fines. Telecoms provider (1&1 Telecom GmbH) - Germany (2020). Retrieved from cookiefines.eu
Last updated: