The Handelsblatt conducted a survey among German data protection supervisory authorities regarding fines imposed under the GDPR. With the exception of Mecklenburg-Western Pomerania, all authorities provided data. As of mid-September, a total of 225 fines had been imposed, 185 of which were issued in 2019.
According to Handelsblatt, most of the fines (2019: 64, 2018: 33) were issued in North Rhine-Westphalia. In the LDI NRW 2019 Activity Report , however, 36 notices of fines totaling 15,600 euros are listed for the year 2018. Berlin ranks second in the fine ranking with 44 fines in 2019. Lower Saxony follows with 19 administrative offense proceedings resulting in fines.
The highest fine, amounting to 14.5 million euros, was imposed by Berlin’s Commissioner for Data Protection and Freedom of Information (BlnBDI), Maja Smoltczyk, against the Deutsche Wohnen SE. The second-highest fine, amounting to 9.55 million euros, was imposed by the Federal Commissioner for Data Protection and Freedom of Information (BfDI) against the 1&1 Telecom GmbH. Both companies have filed appeals against the fine notices. Third place in the ranking of the highest finesin Germany goes to the State Data Protection Commissioner of Lower Saxony (Barbara Thiel), who issued a fine of 294,000 euros against an unknown organization. The unidentified organization is accused of retaining personnel files for an unnecessarily long period of time (violation the principle of data minimization, Art. 5(1)(e) GDPR) and collecting health data during personnel selection processes (violation of the principle of storage limitation, Art. 5(1)(e) GDPR and the prohibition on processing special categories of personal data, Art. 9(1) GDPR).
In our fines database currently contains 19 entries regarding fines imposed by German regulatory authorities. Of these, six fines were imposed by the Federal Network Agency, which is responsible, among other things, for telecommunications companies and, under thepenalty limits of the Telecommunications Act—a maximum of 500,000 euros—rather than the penalty limits of the GDPR. This leaves 13 fines that were imposed based on the GDPR. No further details are available regarding the remaining 212 fine proceedings by the German data protection supervisory authorities. Although there is no obligation to publicize fine proceedings, this practice nevertheless raises doubts as to whether it can achieve the necessary deterrent effect, particularly against companies. Barbara Thiel, State Data Protection Commissioner in Lower Saxony, states in a ZD interview that, in her view, a sanction pursuant to Art. 83(1) of the GDPR would be effective and dissuasive if, on the one hand, it were suitable as a general preventive measure to deter the general public from committing violationsand to strengthen the public’s trust in the rule of law, while also serving as a specific deterrent to prevent the offender from committing further violations. No information on this topic has been found on the website of the State Data Protection Commissioner to date. Other government websites also contain no information or only aggregated data that is not suitable for inclusion in our database.
The supervisory authorities in Hamburg, Lower Saxony, North Rhine-Westphalia, Saarland, Saxony, and Thuringia have provided information on ongoing proceedings, some of which are still being handled under the old law prior to the GDPR’s applicability. As of mid-December 2019, 223 cases are under investigation. Overall, the authorities complain that they lack sufficient staff to process the cases. Heinz Müller, the data protection commissioner for the state of Mecklenburg-Western Pomerania, resigned from the SPD in December because he felt his agency had received too little support from the red-black coalition.