IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

German telecoms firm slapped with €10m GDPR fine

People could access sensitive customer data in some cases by only providing a name and date of birth

GDPR readiness

The German data regulator has fined the telecoms giant 1&1 almost €10 million for not taking sufficient measures to prevent unauthorised access to customer data.

The company has been punished because it failed to take measures to adequately protect the data of its customers, meaning extensive customer information could be accessed by just providing the name and date of birth. 

The lack of protections for customer data constituted a violation of Article 32 of the General Data Protection Regulation (GDPR), according to the Federal Commissioner for Data Protection and Freedom of Information (BfDI).

The Federal Commissioner Ulrich Kelber explained the €9,550,000 fine was a clear sign the data regulator would enforce the protection of fundamental rights under GDPR, and that due consideration was taken in the decision.

Despite the severity of the fine, BfDI also noted that 1&1 was transparent and cooperative during the investigation. 

To rectify its processes, the telecoms giant first introduced new authentication steps, before unveiling plans to roll out an authentication procedure with significantly stronger barriers to accessing data.

The BfDI said the fine could have been much higher had 1&1 representatives not been as cooperative as they were during the investigation. The infringement, moreover, was limited to just a handful of customers, despite all customers being at risk. 

Related Resource

Understanding the must-haves of modern data protection

Go beyond traditional backup and recovery

Download now

The data regulator added it would be investigating the customer authentication procedures of rival telecoms companies as a result of its findings. 

The agency has been active in recent months, having previously issued a €14.5 million fine against a housing giant for hanging onto the personal and financial data of former and current tenants longer than necessary.

The fines have been adding up since GDPR came into effect in May 2018, but are blown out of the water when compared with the multi-million-pound penalties issued against the likes of BA and Marriot.

Featured Resources

The state of Salesforce: Future of business

Three articles that look forward into the changing state of Salesforce and the future of business

Free Download

The mighty struggle to migrate SAP to the cloud may be over

A simplified and unified approach to delivering Enterprise Transformation in the cloud

Free Download

The business value of the transformative mainframe

Modernising on the mainframe

Free Download

The Total Economic Impact™ Of IBM FlashSystem

Cost savings and business benefits enabled by FlashSystem

Free Download

Most Popular

How to boot Windows 11 in Safe Mode
Microsoft Windows

How to boot Windows 11 in Safe Mode

29 Jul 2022
Samsung proposes 11 Texas semiconductor plants worth $191 billion
Hardware

Samsung proposes 11 Texas semiconductor plants worth $191 billion

21 Jul 2022
Should you take your password manager off the internet?
Sponsored

Should you take your password manager off the internet?

28 Jul 2022