ARTICLE
23 August 2019

Berlin DPA Announced High GDPR Fines

RS
Reed Smith (Worldwide)

Contributor

Reed Smith (Worldwide) logo
Reed Smith is a dynamic international law firm helping clients move their businesses forward. By delivering smart, creative legal services, we enrich clients' experiences with us and support achievement of their business goals. Our longstanding relationships and collaborative structure enable the speedy resolution of complex disputes, transactions, and regulatory matters.
Recently, the Berlin Data Protection Authority (Berlin DPA) announced that it would issue a high administrative fine for violations of the General Data Protection Regulation
UK Privacy
To print this article, all you need is to be registered or login on Mondaq.com.

Recently, the Berlin Data Protection Authority (Berlin DPA) announced that it would issue a high administrative fine for violations of the General Data Protection Regulation 2016/679 (GDPR). The announcement is available in German on the website of the City of Berlin. The fine will likely be a double-digit million amount of euros. The Berlin DPA further commented that it recently imposed two fines on one organisation in the aggregate amount of €200,000, but did not disclose any further details of the underlying GDPR violations.

The announcement of the Berlin DPA is a clear shift from the previous practice of German Data Protection Authorities of issuing much smaller fines. According to a report in the German newspaper Welt Am Sonntag published on 12 May 2019 (available here), German DPAs imposed 81 fines in the first year post-GDPR. These fines ranged from a few hundred euros to five-digit amounts, and totalled in aggregate €485,490.

Comment

The announcement of the Berlin DPA comes in the footsteps of the UK Information Commissioner's Office's announcement of its intention to issue separate fines in the amounts of €110 million and €205 million for data security violations (Article 32 GDPR), and the Italian Data Protection Authority imposing a fine of €2 million for telemarketing without consent.

Organisations should continue to close any GDPR compliance gaps and, in particular, be prepared to maintain sufficient documentation to comply with their accountability obligations under Article 5(2) GDPR.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

We operate a free-to-view policy, asking only that you register in order to read all of our content. Please login or register to view the rest of this article.

See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More