Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupport
Contact Us
Search
Close

Data Protection Authority Imposes First GDPR Non-Compliance Fine in Germany

By Dr. Ulrich Worm, Björn Vollmuth, Ana Hadnes Bruder & Benjamin Beck on November 29, 2018
Email this postTweet this postLike this postShare this post on LinkedIn

On 21 November 2018, the data protection authority of Baden-Württemberg, Germany (the “authority”) imposed a fine of EUR 20,000 against a German social media provider (the “company”) for failing to encrypt user passwords. The authority’s decision marks the first time that a fine was imposed on a company for violating the European General Data Protection Regulation (GDPR) in Germany (here: Art. 32(1)(a)).

Email addresses and passwords of about 330,000 users of the company’s social media website were hacked and published on the Internet. The company notified the authority of the personal data breach and provided extensive information concerning its data processing activities. The company also informed its users of the breach in accordance with the applicable GDPR provisions.

From the information provided by the company, the authority learned that user passwords were stored unencrypted. Pursuant to Art. 32 of the GDPR, companies shall implement appropriate technical and organizational measures to secure personal data so that the rights and freedoms of the concerned natural persons are protected. To determine the appropriate measures, companies must take into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing the personal data. Based on those considerations—and the fact that encryption of personal data is listed as an appropriate measure in Art. 32(1)(a) of the GDPR—the authority determined that the company should have encrypted user passwords, rather than processing them in plain text, to grant a level of protection appropriate to the risks. Consequently, the authority concluded that the company had violated Art 32(1)(a) of the GDPR and applied a fine pursuant to Art. 83(4).

The fine could have been as high as EUR 10 million or 2 percent of the company’s worldwide turnover of the previous year, whichever is higher. However, when determining the amount of the fine, the authority considered the efforts taken by the company to implement the measures ordered and suggested by the authority and the company’s willingness to cooperate, in a very positive collaboration, with the authority.

 

This article was originally published on AllAboutIP – Mayer Brown’s  blog on relevant developments in the fields of intellectual property and unfair competition law. For intellectual property-themed videos, Mayer Brown has launched a dedicated YouTube channel. 

Photo of Dr. Ulrich Worm Dr. Ulrich Worm

Ulrich Worm is a partner in the Frankfurt office of Mayer Brown and heads the German Intellectual Property practice. His practice focuses on technology related advice.

Ulrich advises clients in IP related matters, including patent, trade secrets, design right, trademark and copyright matters…

Ulrich Worm is a partner in the Frankfurt office of Mayer Brown and heads the German Intellectual Property practice. His practice focuses on technology related advice.

Ulrich advises clients in IP related matters, including patent, trade secrets, design right, trademark and copyright matters as well as on licensing, co-operation and other technology transfer agreements. He represents clients in patent infringement and nullity proceedings and in trade secrets litigation cases before courts in Germany. In addition to litigating IP cases before German courts, he coordinates pan-European and cross-Atlantic litigation cases. Further to his IP litigation practice, Ulrich advises on patent related matters such as patent license and other technology transfer agreements and is experienced in fighting counterfeiting of patent, design right and trademark protected products.

His practice further covers IT-related matters, including advising on cloud services, software licensing agreements, SaaS agreements, software development projects, e-commerce, and related data protection and privacy questions.

Read Ulrich’s full bio.

Read more about Dr. Ulrich WormEmail
Show more Show less
Photo of Ana Hadnes Bruder Ana Hadnes Bruder

Ana Hadnes Bruder is a partner in Mayer Brown’s Frankfurt office and an active member of the global Cybersecurity & Data Privacy practice. She is also a member of the firm’s Intellectual Property practice. Ana advises clients on data privacy and cybersecurity matters…

Ana Hadnes Bruder is a partner in Mayer Brown’s Frankfurt office and an active member of the global Cybersecurity & Data Privacy practice. She is also a member of the firm’s Intellectual Property practice. Ana advises clients on data privacy and cybersecurity matters, including preparing for and reacting to cyber-attacks, assessing and making required data breach notifications, analyzing data protection implications of new products and tools and providing strategic advice with a focus on cross-border data processing. Ana further advises on Technology Transactions including cloud services, data and software licensing agreements, SaaS agreements, software development projects, e-commerce, and related Cybersecurity & Data Privacy questions.

Ana is a registered lawyer in Germany and Brazil and has ten years of international experience as legal counsel in Brazil, France and Germany. Ana started her career at Mayer Brown in the Dispute Resolution practice where she represented clients in litigation and arbitration proceedings involving complex commercial, intellectual property and liability matters.

Before joining Mayer Brown, Ana gained experience representing foreign clients in judicial proceedings in Brazil and also worked as in-house counsel for a leading French company in Paris.

Read full bio

Read more about Ana Hadnes BruderEmail
Show more Show less
Photo of Benjamin Beck Benjamin Beck

Benjamin Beck is an associate in Mayer Brown’s Düsseldorf office and a member of the Intellectual Property practice.

Publications

Post GDPR Enforcement in Germany — A Sneak Peek, in: Privacy & Data Protection Journal (PDP), 2019, No. 5, p. 16-17, with Dr. Ulrich…

Benjamin Beck is an associate in Mayer Brown’s Düsseldorf office and a member of the Intellectual Property practice.

Publications

Post GDPR Enforcement in Germany — A Sneak Peek, in: Privacy & Data Protection Journal (PDP), 2019, No. 5, p. 16-17, with Dr. Ulrich Worm

Annotation to Higher Regional Court of Berlin (Kammergericht Berlin), Germany, Judgment of 25 September 2018 — (4) 161 Ss 28/18 (35/18), in: Europäische Zeitschrift für Wirtschaftsrecht (EuZW), 2019, No. 1, p. 42-46, with Dr. Dominik König

Die Wirksamkeit von sog. „Nicht-Einsatz-Klauseln“ für den Wettbewerb der Fußball-Bundesliga, in: Zeitschrift für Sport und Recht (SpuRt), 2019, No. 1, p. 2-6, with Patrick Schulz

Bitcoin and Money, in: Leslie Thompson, Jean-Toussaint Pindi, Stephanie Amar-Flood (ed.), Anglais appliqué: Economie, Gestion, Droit, AES, 4th ed. 2018, p. 44-45

GDPR Implications for Blockchain and Distributed Ledger Technologies, in: SA Financial Regulation Journal, 19.06.2018, with Dr. Ulrich Worm

Yoga and Copyright, in: WIPO Magazine, 2017, No. 3, p. 44-45, with Konstantin von Werder

Annotation to Administrative Court of Frankfurt am Main (Verwaltungsgericht Frankfurt), Germany, Judgment of 31 October 2016 — 1 K 2903/15.F, in: Kommunikation & Recht (K&R), 2017, No. 2, p. 142-144, with Dr. Dominik König

IP scenarios in a Brexit world, in: World Intellectual Property Review (WIPR), 18.07.2016, with Dr. Ulrich Worm

Судебная практика в Германии / Court practice in Germany, in: Интеллектуальная собственность Казахстана (Intellectual property of Kazakhstan), 2016, No. 1, p. 13-16, with Ana Elisa Bruder and Konstantin von Werder

Oktoberfest for the UPC?, in: World Intellectual Property Review (WIPR), 24.03.2016, with Dr. Ulrich Worm

Die immaterialgüterrechtliche Schutzfähigkeit von „Affen-Selfies“, in: Zeitschrift für Urheber- und Medienrecht (ZUM), Vol. 60 (2016), No. 1, p. 34-38, with Dominik König

Bitcoins als Gegenstand von sekundären Leistungspflichten. Erfassung dem Grunde und der Höhe nach, in: Archiv für die civilistische Praxis (AcP), Vol. 215 (2015), No. 5, p. 655-682, with Dominik König

Annotation to CJEU, Judgment of 22 October 2015 — C‑264/14 — David Hedqvist, in: Umsatzsteuer-Rundschau (UR), 2015, No. 22, p. 864-871, with Dominik König

Court considers likelihood of confusion between word marks using same letters in different order, in: World Trademark Review Daily, 25.09.2015, with Konstantin von Werder

Do Bitcoins Fulfil the Classic Economic Functions of Money? An Analysis and its Legal Implications, published online on lichter-filmfest.de on 09.03.2015

Bitcoins als Geld im Rechtssinne, in: Neue Juristische Wochenschrift (NJW), Vol. 68 (2015), No. 9, p. 580-586

Bitcoin: Der Versuch einer vertragstypologischen Einordnung von kryptographischem Geld, in: JuristenZeitung (JZ), Vol. 70 (2015), No. 3, p. 130-138, with Dominik König

Klinische und rechtliche Aspekte einer Abstinenzkontrolle unter besonderer Berücksichtigung kontinuierlicher transdermaler Alkoholmessung, in: Blutalkohol – Alcohol, Drugs and Behavior (BA), Vol. 50 (2013), No. 4, p. 153-167

Elektronische Fußfessel – Fluch oder Segen der Kriminalpolitik?, in: Schriftenreihe der Stiftung der Hessischen Rechtsanwaltschaft, Vol. 2 (2011), p. 65-94

Read more about Benjamin BeckEmail
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    All About IP
  • Organization:
    Mayer Brown

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
  • About LexBlog
  • The Field We Built
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo