The supervisory activities of European data protection authorities repeatedly set new records in 2022. For example, the total amount of fines imposednot only exceeded 1 billion EUR, but also surpassed that mark by 1.64 billion EUR —an increase of nearly 50 percent. The highest fine was imposed on the Facebook parent company Meta. Due to various violations of the GDPR in the area of personalized advertising, the Irish Data Protection Commission (DPC) imposed a fine on Facebook and Instagram fines totaling 210 and 180 million euros.
But the German data protection authoritieswere active in 2022. As in previous years, the GDPR Portal asked them which fines they imposed, how many processing bans or restrictions on processing had been issued, and how many data breach reports had been registered. With the exception of the Mecklenburg-Western Pomerania authority, all authorities provided us with information (see below for a detailed overview).
Over the course of the past year, German data protection authorities imposed 453 fines totaling 5.8 million EUR(since not all authorities disclosed the amounts of the fines, this figure should be considered a lower limit). With 113 fines imposed, Hesse led the way in 2022. North Rhine-Westphalia followed (85), while Lower Saxony took third place (44).
Compared to the figures from 2021, it is striking that the number of German fines rose slightly again, while the total amount of those fines has (once again) increased significantly. Although the total amount of thefrom 2022 does not reach the record of over48 million EUR set in 2020, it represents a significant increase compared to the 2.11 million EUR from 2021, it nonetheless represents a 175 percent increase. Two decisions this year exceeded the one-million mark, with spectacular fines similar to those imposed in 2020 against H&M (33.5 million EUR) and notebooksbilliger.de (10.4 million EUR), however, were not imposed.
The highest fine from 2022—EUR 1.9 million—was imposed by the regulatory authority in Bremen. The sanction was directed against the housing association BREBAU GmbH for violations of Article 5(1) of the GDPR, Art. 6(1) of the GDPR, Art. 9(1) of the GDPR, Art. 12(1) of the GDPR and Art. 15 of the GDPR. BREBAU had processed data from more than 9,500 prospective tenants without a legal basis for doing so. For example, information regarding hairstyles, body odor, and personal appearance was recorded. In more than half of the c&cases, special categories of personal data within the meaning of Art. 9(1) GDPR were processed. In particular, information regarding skin color, ethnic origin, religious affiliation, sexual orientation, and health status was processed unlawfully.
Second place in the 2022 ranking went to the 1.1 million EUR fine imposed by the State Commissioner for Data Protection (LfD) of Lower Saxony against Volkswagen for violations of Art. 13 of the GDPR, Art. 28 of the GDPR, Art. 30 GDPR and Art. 35 GDPR. The fine was related to the testing of a driver assistance system designed to prevent traffic accidents by a service provider commissioned by Volkswagen. The Lower Saxony State Office for Data Protection (LfD) had launched an investigation into the automaker after one of the vehicles used for the test drives was stopped during a traffic check by the öAustrian police in 2019. The vehicle in question had not been fitted with any signs indicating the presence of the driver assistance system’s cameras or the data processing associated with their use. Furthermore, Volkswagen had not regulated the activities of the service provider commissioned to conduct the test drives in a data processing agreement, nor had it properlyin the record of processing activities. A data protection impact assessment had also not been conducted.
However, in 2022, most fines were again in the four-digit or, at most, five-digit range. As in the previous year, among thefrequently penalized violations were the unlawful processing of data ( Art. 5 and 6 of the GDPR), such as through unauthorized video recordings, database queries, or transfers to third parties, as well as violations of the obligations to provide access and information ( Art. 12 through 15 of the GDPR), as well as inadequate technical and organizational security measures (Art. 32 of the GDPR). Once again, it is striking that, as in 2020 and 2021, police officers were sanctioned in several cases due to unauthorized queries of the police database.
Our inquiries also reveal that in 2022, the German supervisory authorities issued restrictions or prohibitions on data processing in three cases pursuant to Art. 58(2)(f) of the GDPR. In Berlin, the Commissioner for Data Protection and Freedom of Information issued an order against a real estate company that had improperly made tenant data available in an online storage system, thereby violating Article 6(1), first sentence, of the GDPR. Unfortunately, the other authorities did not specify the restrictions in greater detail in their reports.
It is also interesting to compare the actions of the German authorities with the fine practices of other major EU member states. As examples, we have examined France, Spain, and Italy.
Last year, we reported on the increase in activity by the Spanish data protection authority AEPD, and this trend continues this year as well. A total of 290 fines were issued, representing an increase of nearly 20 percent compared to the 242 fines imposed in 2021. While the amounts of most fineswere also in the low four- or five-digit range, there were once again some exceptions. For example, the AEPD imposed a fine on the tech giant Google LLC (10 million EUR), the telecommunications company VODAFONE ESPAÑA (3.94 million EUR), the ABANCA Corporación Bancaria, S.A. (3.0 million EUR), in two cases against CAIXABANK PAYMENTS & CONSUMER EFC (3.0 million EUR), and the CAIXABANK S.A. (EUR 2.52 million) and AMAZON ROAD TRANSPORT SPAIN, S.L. (EUR 2.0 million) have been hit with a series of fines totaling millions. In summary, it can be stated that the Spanish AEPD significantly surpassed the German authorities both in the amount of the fines imposed and in the total number of sanctions.
The Italian data protection authority also saw a significant increase in the number of sanctions compared to the previous year. While 82 fines were imposed in 2021, there were 137 cases in 2022. Among these were once again several cases involving fines in the multimillion range. For example, the authority imposed fines on Clearview AI (20.0 million EUR), Uber B.V. (2.12 million EUR) and Uber Technologies Inc. (2.12 million EUR), Alpha Exploration (2.0 million EUR), Douglas Italia SpA (1.4 million EUR) and Areti SpA (1.0 million EUR). Once again, various municipalities in the country were also sanctioned in connection with violations during the COVID-19 pandemic.
A clear trend can also be observed in France. Although the French data protection authority CNIL imposed only 14 fines in 2022, these were set at comparatively high levels. Recipients of the fines included, for example, Microsoft Ireland Operations Limited (60.0 million EUR), Clearview AI (20.0 million EUR), Dedalus Biologie (1.5 million EUR), and TOTALENERGIES ÉLECTRICITÉ ET GAZ FRANCE (1.0 million EUR). But there were also interesting decisions below the million-mark threshold, such as the fineimposed on Discord Inc. (800,000 EUR)
In a direct comparison with other major EU countries, German regulatory authorities lag somewhat behind and follow the trend from the previous year, withfigures compared to the rest of Europe. Spectacular fines against large corporations remain rather rare.
In 2022, with 21,170 thousand reports, there were once again fewer data breaches reported to German supervisory authorities under Art. 33 of the GDPR were reported to German supervisory authorities than in the record year of 2020 (26 thousand reports), but more than in 2021 (13,890 reports). Since not all supervisory authorities had provided statistics on reported data breaches at the time of this article’s publication, this figure should also be considered a lower bound. As was the case in 2021, most breaches were recorded in Baden-Württemberg (2,747), followed by Hesse (1,754) and Lower Saxony (1,149). A large proportion of the data breaches were related to hacker attacks, data loss, the mistaken transmission of documents, or technical failures.
Although the Federal Commissioner for Data Protection and Freedom of Information (BfDI) once again did not impose any fines in 2022, he noted in his 31st Annual Report that there was a slight increase in reported data breaches. While there were 10,106 in 2021, this number rose to 10,614 in 2022. However, it should be noted that, following the many complaints at the start of the GDPR, interest and the need for consultation have declined somewhat.
Right at the start of the year, the fine imposed on Meta Platforms Ireland Ltd. (390 million EUR) provided a preview of what to expect in 2023. It is likely that this decision will set a precedent for further action against online services that finance themselves through behavior-based advertising. As a landmark decision on one of the most important issues in European data protection, it could significantly influence future developments.
The Clearview AI case is also not expected to be concluded just yet. After legal action was already taken against the U.S. company in France, Italy, Greece and United Kingdom Finesin the millions have been imposed, further fines from other European authorities are to be expected. The Art. 55 and 56 of the GDPR stipulate that, in the event that a controller basedthe EU or the EEA but has no principal establishment or any establishment at all in the Union, the one-stop-shop procedure under Article 60 of the GDPR does not apply, and consequently the national supervisory authoritiesare responsible for monitoring compliance with the GDPR within their own territory. Fines are already being imposed in both Germany and Austria—and further fines are to be expected.
The European Court of Justice’s ruling against Deutsche Wohnen is also still pending. In 2019, Berlin’s Commissioner for Data Protection and Freedom of Information imposed a fine of 15.4 million euros on the company after it had stored an excessive amount of tenant data. Deutsche Wohnen filed an appeal against this decision, which subsequently led to the fine being overturned. The reason for this was that data protection violationsare currently classified as administrative offenses in Germany and can therefore only be committed by natural persons—in the case of Deutsche Wohnen, however, the decision did not provide evidence of fault on the part of a specific corporate body. According to this legal interpretation, fines against large companies would be virtually impossible in practice, since it is nearly impossible to prove personal culpability—for example, on the part of corporate management—in such cases. Accordingly, the ECJ decision is expected to hold that finescan be imposed on legal entities even without conclusive proof of fault on the part of specific natural persons, thereby resolving the current discrepancy between German and EU law.
| Supervisory Authority | Fines | Total in € | Data Breaches |
|---|---|---|---|
| Baden-Württemberg | 19 | 145,950 | 2,747 |
| Bavaria (non-public sector) | n/a | n/a | n/a |
| Bavaria (public sector) | 0 | 0 | n/a |
| Berlin | 35 | 716,575 | 1,068 |
| BfDI | 0 | 0 | 10,614 |
| Brandenburg | 13 | 123,000 | 451 |
| Bremen | 21 | 2,075,820 | 162 |
| Hamburg | 15 | 60,473 | 859 |
| Hesse | 113 | 44,350 | 1,754 |
| Mecklenburg-Western Pomerania | n/a | n/a | n/a |
| Lower Saxony | 51 | 2,200,000 | 1,149 |
| North Rhine-Westphalia | 85 | 80,350 | n/a |
| Rhineland-Palatinate | 4 | n/a | n/a |
| Saarland | 11 | 135,550 | 543 |
| Saxony | 16 | 11,600 | 790 |
| Saxony-Anhalt | 13 | 182,035 | 287 |
| Schleswig-Holstein | 2 | 100 | 485 |
| Thuringia | 55 | 31,165 | 261 |
| Total | 453 | 5,806,968 | 21,170 |
This article was updated on March 23, 2023, and April 24, 2023, to include additional information provided by the regulatory authorities in Berlin and Hesse.