Skip to content

Menu

LexBlog, Inc. logo
CommunitySub-MenuPublishersChannelsProductsSub-MenuBlog ProBlog PlusBlog PremierMicrositeSyndication PortalsAboutContactResourcesSubscribeSupport
Join
Search
Close

Data Protection Authority Imposes First GDPR Non-Compliance Fine in Germany

By Dr. Ulrich Worm, Björn Vollmuth, Ana Hadnes Bruder & Benjamin Beck on November 29, 2018
Email this postTweet this postLike this postShare this post on LinkedIn

On 21 November 2018, the data protection authority of Baden-Württemberg, Germany (the “authority”) imposed a fine of EUR 20,000 against a German social media provider (the “company”) for failing to encrypt user passwords. The authority’s decision marks the first time that a fine was imposed on a company for violating the European General Data Protection Regulation (GDPR) in Germany (here: Art. 32(1)(a)).

Email addresses and passwords of about 330,000 users of the company’s social media website were hacked and published on the Internet. The company notified the authority of the personal data breach and provided extensive information concerning its data processing activities. The company also informed its users of the breach in accordance with the applicable GDPR provisions.

From the information provided by the company, the authority learned that user passwords were stored unencrypted. Pursuant to Art. 32 of the GDPR, companies shall implement appropriate technical and organizational measures to secure personal data so that the rights and freedoms of the concerned natural persons are protected. To determine the appropriate measures, companies must take into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing the personal data. Based on those considerations—and the fact that encryption of personal data is listed as an appropriate measure in Art. 32(1)(a) of the GDPR—the authority determined that the company should have encrypted user passwords, rather than processing them in plain text, to grant a level of protection appropriate to the risks. Consequently, the authority concluded that the company had violated Art 32(1)(a) of the GDPR and applied a fine pursuant to Art. 83(4).

The fine could have been as high as EUR 10 million or 2 percent of the company’s worldwide turnover of the previous year, whichever is higher. However, when determining the amount of the fine, the authority considered the efforts taken by the company to implement the measures ordered and suggested by the authority and the company’s willingness to cooperate, in a very positive collaboration, with the authority.

 

This article was originally published on AllAboutIP – Mayer Brown’s  blog on relevant developments in the fields of intellectual property and unfair competition law. For intellectual property-themed videos, Mayer Brown has launched a dedicated YouTube channel. 

Photo of Dr. Ulrich Worm Dr. Ulrich Worm

Ulrich Worm is a partner in the Frankfurt office of Mayer Brown and heads the German Intellectual Property practice. His practice focuses on technology related advice.

Ulrich advises clients in IP related matters, including patent, trade secrets, design right, trademark and copyright matters…

Ulrich Worm is a partner in the Frankfurt office of Mayer Brown and heads the German Intellectual Property practice. His practice focuses on technology related advice.

Ulrich advises clients in IP related matters, including patent, trade secrets, design right, trademark and copyright matters as well as on licensing, co-operation and other technology transfer agreements. He represents clients in patent infringement and nullity proceedings and in trade secrets litigation cases before courts in Germany. In addition to litigating IP cases before German courts, he coordinates pan-European and cross-Atlantic litigation cases. Further to his IP litigation practice, Ulrich advises on patent related matters such as patent license and other technology transfer agreements and is experienced in fighting counterfeiting of patent, design right and trademark protected products.

His practice further covers IT-related matters, including advising on cloud services, software licensing agreements, SaaS agreements, software development projects, e-commerce, and related data protection and privacy questions.

Read Ulrich’s full bio.

Read more about Dr. Ulrich WormEmail
Show more Show less
Photo of Ana Hadnes Bruder Ana Hadnes Bruder

Ana Hadnes Bruder is a senior associate in the Intellectual Property practice of the Frankfurt office.

Ana is a registered lawyer in Germany and Brazil and has ten years of international experience as legal counsel. Ana advises clients in intellectual property and information…

Ana Hadnes Bruder is a senior associate in the Intellectual Property practice of the Frankfurt office.

Ana is a registered lawyer in Germany and Brazil and has ten years of international experience as legal counsel. Ana advises clients in intellectual property and information technology law, with a focus on data privacy and cybersecurity matters, including related regulatory issues. Her practice covers the acquisition and licensing of IP rights, research and development and cooperation agreements, as well as trademark and patent infringement proceedings.

Read full bio

Read more about Ana Hadnes BruderEmail
Show more Show less
Photo of Benjamin Beck Benjamin Beck

Benjamin Beck is an associate in Mayer Brown’s Düsseldorf office and a member of the Intellectual Property practice.

Publications

Post GDPR Enforcement in Germany — A Sneak Peek, in: Privacy & Data Protection Journal (PDP), 2019, No. 5, p. 16-17, with Dr. Ulrich…

Benjamin Beck is an associate in Mayer Brown’s Düsseldorf office and a member of the Intellectual Property practice.

Publications

Post GDPR Enforcement in Germany — A Sneak Peek, in: Privacy & Data Protection Journal (PDP), 2019, No. 5, p. 16-17, with Dr. Ulrich Worm

Annotation to Higher Regional Court of Berlin (Kammergericht Berlin), Germany, Judgment of 25 September 2018 — (4) 161 Ss 28/18 (35/18), in: Europäische Zeitschrift für Wirtschaftsrecht (EuZW), 2019, No. 1, p. 42-46, with Dr. Dominik König

Die Wirksamkeit von sog. „Nicht-Einsatz-Klauseln“ für den Wettbewerb der Fußball-Bundesliga, in: Zeitschrift für Sport und Recht (SpuRt), 2019, No. 1, p. 2-6, with Patrick Schulz

Bitcoin and Money, in: Leslie Thompson, Jean-Toussaint Pindi, Stephanie Amar-Flood (ed.), Anglais appliqué: Economie, Gestion, Droit, AES, 4th ed. 2018, p. 44-45

GDPR Implications for Blockchain and Distributed Ledger Technologies, in: SA Financial Regulation Journal, 19.06.2018, with Dr. Ulrich Worm

Yoga and Copyright, in: WIPO Magazine, 2017, No. 3, p. 44-45, with Konstantin von Werder

Annotation to Administrative Court of Frankfurt am Main (Verwaltungsgericht Frankfurt), Germany, Judgment of 31 October 2016 — 1 K 2903/15.F, in: Kommunikation & Recht (K&R), 2017, No. 2, p. 142-144, with Dr. Dominik König

IP scenarios in a Brexit world, in: World Intellectual Property Review (WIPR), 18.07.2016, with Dr. Ulrich Worm

Судебная практика в Германии / Court practice in Germany, in: Интеллектуальная собственность Казахстана (Intellectual property of Kazakhstan), 2016, No. 1, p. 13-16, with Ana Elisa Bruder and Konstantin von Werder

Oktoberfest for the UPC?, in: World Intellectual Property Review (WIPR), 24.03.2016, with Dr. Ulrich Worm

Die immaterialgüterrechtliche Schutzfähigkeit von „Affen-Selfies“, in: Zeitschrift für Urheber- und Medienrecht (ZUM), Vol. 60 (2016), No. 1, p. 34-38, with Dominik König

Bitcoins als Gegenstand von sekundären Leistungspflichten. Erfassung dem Grunde und der Höhe nach, in: Archiv für die civilistische Praxis (AcP), Vol. 215 (2015), No. 5, p. 655-682, with Dominik König

Annotation to CJEU, Judgment of 22 October 2015 — C‑264/14 — David Hedqvist, in: Umsatzsteuer-Rundschau (UR), 2015, No. 22, p. 864-871, with Dominik König

Court considers likelihood of confusion between word marks using same letters in different order, in: World Trademark Review Daily, 25.09.2015, with Konstantin von Werder

Do Bitcoins Fulfil the Classic Economic Functions of Money? An Analysis and its Legal Implications, published online on lichter-filmfest.de on 09.03.2015

Bitcoins als Geld im Rechtssinne, in: Neue Juristische Wochenschrift (NJW), Vol. 68 (2015), No. 9, p. 580-586

Bitcoin: Der Versuch einer vertragstypologischen Einordnung von kryptographischem Geld, in: JuristenZeitung (JZ), Vol. 70 (2015), No. 3, p. 130-138, with Dominik König

Klinische und rechtliche Aspekte einer Abstinenzkontrolle unter besonderer Berücksichtigung kontinuierlicher transdermaler Alkoholmessung, in: Blutalkohol – Alcohol, Drugs and Behavior (BA), Vol. 50 (2013), No. 4, p. 153-167

Elektronische Fußfessel – Fluch oder Segen der Kriminalpolitik?, in: Schriftenreihe der Stiftung der Hessischen Rechtsanwaltschaft, Vol. 2 (2011), p. 65-94

Read more about Benjamin BeckEmail
Show more Show less
  • Posted in:
    Intellectual Property
  • Blog:
    All About IP
  • Organization:
    Mayer Brown
  • Article: View Original Source

LexBlog, Inc. logo
Facebook LinkedIn Twitter RSS
Real Lawyers
99 Park Row
  • About LexBlog
  • Careers
  • Press
  • Contact LexBlog
  • Privacy Policy
  • Editorial Policy
  • Disclaimer
  • Terms of Service
  • RSS Terms of Service
  • Products
  • Blog Pro
  • Blog Plus
  • Blog Premier
  • Microsite
  • Syndication Portals
  • LexBlog Community
  • 1-800-913-0988
  • Submit a Request
  • Support Center
  • System Status
  • Resource Center

New to the Network

  • LEX Reception Blog
  • Civil Justice Blog
  • Boston ERISA & Insurance Litigation Blog
  • Stridon News and Insights
  • Taft Class Action & Consumer Insights
Copyright © 2022, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo