PrivacyCache
DEData MinimizationOtherDecision: 2019-10-30

Deutsche Wohnen SE

€14.5M

Issued by Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI) on 2019-10-30

What happened

Berlin's data protection authority fined Deutsche Wohnen, one of Germany's largest residential real estate companies, €14.5 million for storing tenants' personal data indefinitely without any legal basis for continued retention. The company's archiving system did not allow for the deletion of data that was no longer needed. Personal data including salary statements, self-disclosure forms, employment contracts, tax and social security data, and bank statements of tenants were retained for years beyond their lawful retention period. Despite being warned by the DPA in 2017, Deutsche Wohnen failed to implement a data deletion concept. This case became a landmark for the principle that companies can be directly fined under GDPR.

Articles violated

Art. 5(1)(c) GDPRArt. 5(1)(e) GDPRArt. 25(1) GDPR

Lessons learned

Companies must implement data retention policies with automated deletion mechanisms. Storing personal data indefinitely 'just in case' violates the storage limitation principle. When a DPA issues a warning, organizations must act promptly to remediate. Real estate companies handling sensitive financial data of tenants must establish clear retention schedules and ensure their IT systems support data deletion. This case confirmed direct corporate liability under GDPR after the CJEU's 2023 ruling.

Source

View original decision

Disclaimer: This summary is for informational purposes only and does not constitute legal advice. Refer to the original decision for complete details.

Get enforcement alerts for Other

We track GDPR fines across Europe. Enter your email to get notified about new enforcement actions.

Related enforcement actions