GDPR Fines: Real Cases from Germany and What Companies Can Learn from Them

A GDPR fine can hit you under two ceilings set out in Art. 83 GDPR: up to 10 million euros or 2 percent of worldwide annual revenue for inadequate data security, up to 20 million euros or 4 percent for violations of core principles such as lawfulness or special categories of data. Whichever figure is higher applies.
From the Provimedia editorial team, as of: July 2026, this article is general information, not legal advice.
The record: 45 million euros against Vodafone in 2025. Four real cases show you which process gaps cost companies millions, and why courts later cut two of the fines by more than 90 percent.
How high can GDPR fines be?
Art. 83 (4) GDPR covers obligation violations by controllers and processors, such as inadequate measures under Art. 32 or missing data processing agreements under Art. 28: up to 10 million euros or 2 percent of worldwide annual revenue. Art. 83 (5) GDPR covers more serious violations of processing principles (Art. 5, 6, 9), data subject rights, or international data transfers: up to 20 million euros or 4 percent. For groups with several billion euros in annual revenue, the revenue percentage is practically always the decisive figure, not the fixed maximum amount.
What real cases have there been in Germany?
The following four cases are documented through press releases from the responsible supervisory authorities or court rulings.
| Company | Year | Amount | Authority | Core violation |
|---|---|---|---|---|
| H&M Hennes & Mauritz | 2020 | 35.3 million euros | HmbBfDI (Hamburg) | Systematic collection of employees' private data |
| Deutsche Wohnen SE | 2019 | 14.5 million euros (reduced by a court to 900,000 euros in 2026, not yet final) | BlnBDI (Berlin) | Archive system with no way to delete tenant data |
| 1&1 Telecom GmbH | 2019 | 9.55 million euros (reduced by a court to 900,000 euros in 2020, final) | BfDI | Inadequate authentication on the customer hotline |
| Vodafone GmbH | 2025 | 45 million euros (2 individual fines: 15 plus 30 million euros) | BfDI | Deficiencies in sales partner oversight and authentication |
H&M: employees' private data in the service center
At the Nuremberg service center, managers had since 2014 been collecting notes from "Welcome Back Talks" held after employees' vacations or illnesses, recording details about family problems, symptoms of illness, and religious beliefs, and storing them on a network drive. In October 2019, a configuration error made this data visible company wide. The HmbBfDI imposed a fine of 35,258,707.95 euros on October 1, 2020, which became final because H&M did not appeal.
Lesson for your company: Without clear rules on which conversation content may be documented, and without training managers on permissible personnel conversations, a collection of sensitive data builds up for which there is simply no legal basis.
Deutsche Wohnen: archive system with no deletion function
During inspections in 2017 and 2019, the BlnBDI found that Deutsche Wohnen used an archive system from which tenant data no longer needed could not be technically removed. On November 5, 2019, the authority imposed a fine of around 14.5 million euros. Deutsche Wohnen challenged this in court; the ECJ ruled on December 5, 2023 (C-807/21) that companies can be held directly liable even without attribution to a member of management, but required intentional or negligent conduct for this. The Berlin Regional Court subsequently reduced the fine on June 9, 2026 to 900,000 euros, partly because the company had cooperated and worked on a technical solution. The ruling is not yet final.
Lesson for your company: It lies less in training than in process: documented deletion routines and retention periods for personal data are not a nice to have but a core obligation under Art. 5 (1)(e) GDPR.
1&1 Telecom: weak authentication on the hotline
The trigger was a 2018 case in which a caller was able to obtain her ex partner's new phone number through the 1&1 hotline using only his name and date of birth. In December 2019, the BfDI imposed a fine of 9.55 million euros for inadequate technical and organizational measures in the customer hotline's authentication process (Art. 32 GDPR). The Bonn Regional Court confirmed the violation in principle on November 11, 2020, but found no mass disclosure of data and reduced the fine to 900,000 euros. It based this reduction on the fact that it did not accept the authority's calculation method, which was oriented to group wide revenue. The ruling is final.
Lesson for your company: A trained hotline team that knows to apply additional verification steps for sensitive requests would have practically closed the security gap.
Vodafone: sales partners and eSIM access
In June 2025, the BfDI imposed two fines on Vodafone GmbH totaling 45 million euros, the authority's highest amount to date. 15 million euros related to inadequately monitored sales partners, through whom fraudulent contracts were concluded to customers' detriment. 30 million euros concerned security gaps in the interplay between the online portal "MeinVodafone" and the hotline, through which attackers were able to gain access to eSIM profiles.
Lesson for your company: Both violations concern oversight and security processes; regular audits of service providers under Art. 28 GDPR and multi step authentication procedures would have been the obvious technical answers.
How do authorities calculate the amount?
Two of these criteria you can influence directly: cooperation with the authority and documented measures. Art. 83 (2) GDPR names the criteria supervisory authorities must consider when setting the amount:
- Nature, gravity, and duration of the violation
- Intent or negligence
- Measures taken to mitigate the damage
- Degree of responsibility, taking into account the technical and organizational measures implemented
- Previous relevant violations
- Degree of cooperation with the authority
- Categories of data affected
- Manner in which the violation became known
These exact criteria explain why courts later lowered the fines in the 1&1 and Deutsche Wohnen cases: they assessed cooperation, measures taken, and actual severity differently than the authority did in its decision.
What actually protects companies?
Documented technical and organizational measures, deletion concepts, and employee training are part of the accountability obligation under Art. 5 (2) and Art. 24 GDPR, more on this in our article on accountability under the GDPR. Under Art. 83 (2)(d) GDPR, they expressly count as a mitigating factor when calculating a fine. Honestly speaking, training is therefore one building block in risk management, not a free pass: none of the four cases would have been prevented by training alone.
All four cases show, however, that missing or unpracticed processes, deletion routines, access controls, authentication standards, clear conversation guidelines, were the actual trigger. A company that can demonstrate that employees know the core principles of the GDPR and that processes are regularly reviewed generally fares better when a fine is calculated than a company with no documentation at all.
Frequently asked questions (FAQ)
Who imposes GDPR fines in Germany?
The data protection supervisory authorities of the federal states where the company is based are responsible, such as the HmbBfDI in Hamburg or the BlnBDI in Berlin. For telecommunications and postal service providers as well as federal authorities, the Federal Commissioner for Data Protection and Freedom of Information (BfDI) is responsible.
Can courts reduce GDPR fines again?
Yes. Companies can challenge fine notices before the ordinary courts. In two of the cases presented here, the originally imposed amount was later reduced by more than 90 percent.
Does the 10/20 million ceiling also apply to small companies?
The maximum amounts under Art. 83 (4) and (5) GDPR apply regardless of company size. For small companies, the fixed maximum amount is usually the practically relevant limit, while for large groups with high annual revenue it is almost always the revenue percentage.
What does a small company realistically risk?
The cases presented here all involve groups with high annual revenue. Under Art. 83 (1) GDPR, fines must be effective, proportionate, and dissuasive; for low revenue, a proportionate fine is therefore considerably lower than for a company worth billions. A reliable average figure for small and medium sized businesses cannot be derived from these four cases, since all the decisions are directed at large companies.
For companies that want to embed the GDPR's core principles not just on paper but in everyday work, Provimedia's GDPR foundations training offers a practical introduction with a certificate of participation as proof that the training was carried out.
Sources
- HmbBfDI, press release "35.3 million euro fine against H&M," October 1, 2020: datenschutz-hamburg.de
- BlnBDI, press release on the fine against Deutsche Wohnen, November 5, 2019: datenschutz-berlin.de
- ECJ, ruling of December 5, 2023, case C-807/21 (Deutsche Wohnen), referenced in the BlnBDI press release: datenschutz-berlin.de
- Berlin Regional Court I, ruling of June 9, 2026, case no. 526 OWiG LG 1/20, reported by Legal Tribune Online: lto.de
- BfDI, press release "BfDI imposes fine against 1&1," December 9, 2019: bfdi.bund.de
- BfDI, press release on the Bonn Regional Court ruling in the proceedings against 1&1, 2020: bfdi.bund.de
- BfDI, press release "BfDI imposes fines against Vodafone," June 2025: bfdi.bund.de
Share this article
Stay up to date
Get the latest articles, insights and industry updates straight to your inbox.
Decide for yourself what Google shows you
Google lets you choose which sources appear more prominently in your search results: in Top Stories and in AI answers. Two clicks, and you see the sites you trust.
Add provimedia.de to my preferred sourcesRelated articles
More articles you might find interesting.
Phishing and Social Engineering: How Your Employees Can Spot an Attack
Phishing, spear phishing, CEO fraud, and smishing target people, not systems. The warning signs a phishing employee training should teach, and why a successful attack quickly turns into a reportable data breach.
Information Security Training vs. GDPR Training: What Companies Actually Need
Information security protects systems and information, data protection protects people and their data. The difference, the overlap under Art. 32 GDPR, and what the new NIS2 training duty means for management boards.
Reporting a Data Breach: The 72-Hour Deadline Under Art. 33 GDPR
A data breach must be reported to the competent supervisory authority without undue delay, where feasible within 72 hours of becoming aware of it. What Art. 33 and Art. 34 GDPR specifically require, and why the deadline only starts once employees actually recognize the breach.
Bereit für den dokumentierten Schulungsnachweis?
Die DSGVO-Grundlagenschulung für Ihr Team – online, in rund 90 Minuten, mit datiertem Teilnahmezertifikat je Person.