Published on 31 July 2026
A €900,000 fine for an archive system that couldn't delete data. What at first sounds like a technical detail is in fact one of the most important data-protection precedents of recent years. On 9 June 2026, the Regional Court of Berlin I (Landgericht Berlin I) fined Deutsche Wohnen SE because the real-estate company had stored personal data of tenants in a system from which it could no longer be deleted for technical reasons. Salary statements, bank statements, copies of ID cards, tax and health-insurance data – all of it remained there permanently, even long after the original purpose had ceased to exist.
For small and medium-sized enterprises, this ruling is a wake-up call. Because the core message concerns not only real-estate conglomerates, but every company that stores customer data, applicant data or employee data in systems that do not allow for targeted deletion. In this article, we explain exactly what happened, why the court assumed an intentional violation – and how you can check whether your own company is affected.
On 9 June 2026, the 26th Grand Criminal Chamber of the Regional Court of Berlin I (case no.: 526 OWi LG 1/20) imposed a fine of €900,000 on Deutsche Wohnen SE. The court considered it proven that, in the period from 25 May 2018 to 5 March 2019, the company had intentionally violated central principles of the General Data Protection Regulation (GDPR):
Important: The ruling is not yet final. Deutsche Wohnen can lodge an appeal on points of law. Nevertheless, the decision already carries considerable significance – because it provisionally ends a seven-year legal dispute that went via the European Court of Justice (ECJ) and the Higher Regional Court of Berlin (Kammergericht Berlin).
The core of the violation is not a hacker attack and not a classic software vulnerability. There is therefore also no CVE number (the standardised identifier for security vulnerabilities). The violation is based on a structural deficit: the electronic archive system in use simply had no technical means of deleting individual data records in a targeted manner.
Once documents had been entered, they could no longer be removed – not even when the original purpose of collection, for example a credit check prior to concluding a contract, had long since ceased to apply. Highly sensitive categories of data were affected:
This data remained permanently in the system even after tenancies had ended, and it remained retrievable. The former Berlin data protection commissioner Maja Smoltczyk coined the term “data graveyard” for this in 2019:
“Data graveyards, such as the one we found at Deutsche Wohnen SE, are unfortunately something we encounter frequently in supervisory practice. The explosive nature of such shortcomings is unfortunately only brought clearly home to us once, for instance through cyberattacks, abusive access to the mass-hoarded data has occurred. But even without such serious consequences, we are dealing here with a blatant violation of the principles of data protection.” – Maja Smoltczyk, BlnBDI (2019)
The system had been introduced before the GDPR came into force and did not comply with the new requirements for Privacy by Design (Art. 25 GDPR) – the principle that systems must be designed from the outset so that deletion deadlines are technically enforceable. Decisive for the court: Deutsche Wohnen had been aware of the shortcoming since 2017, after the Berlin data protection authority (BlnBDI) had pointed it out during an on-site inspection. Because the company did not switch over in time despite this knowledge, the court classified the violation as intentional.
The history of this case is remarkable:
Why was the fine reduced so significantly? The court took into account as a mitigating factor that Deutsche Wohnen had brought in external auditors, consultants and IT specialists to overhaul the systems. In addition, the violations fell within the introductory phase of the GDPR, and the authority itself had difficulty documenting the actual state of affairs in a way that would hold up in court.
But – and this is the crucial warning for all companies – this mitigating factor will scarcely apply in future. Attorney Lukas Hufeld puts it in a nutshell:
“For violations that occur today – more than seven years after the GDPR came into force – courts and authorities will have little reason to show similar leniency by pointing to an introductory phase. The core message of the case is clear: storing personal data without the technical ability to delete it constitutes a GDPR violation – and fines can follow.” (paraphrased translation) – Lukas Hufeld, HUFELD PartGmbB
One detail of the proceedings has far-reaching consequences for all companies in the EU. On 5 December 2023 (case C-807/21, Grand Chamber), the ECJ ruled:
The current Berlin data protection commissioner Meike Kamp welcomed this as creating legal certainty. For SMEs, this means in plain terms: you cannot rely on a fine only being issued if an individual employee is identified as the culprit. The company as a whole is liable.
In short: every company that processes personal data. The principles confirmed in the ruling apply regardless of size and sector. You are potentially affected if you:
The particular risk: this violation requires no external attacker. The data protection authority can take action through on-site inspections or on the basis of complaints from affected individuals. If a technical deletion function is lacking, a structural violation already exists – regardless of whether the data was ever misused.
Lawyer Daniela Dannapel-Groneberg concisely sums up the lesson of the case:
“Deletion concepts must be technically implemented. An archive system that does not permit the deletion of personal data establishes a structural violation of the principles of data minimisation and storage limitation – regardless of whether the data was actually misused.” – Daniela Dannapel-Groneberg, datenschutz süd GmbH
For violations of Art. 5 GDPR, Art. 83(5) GDPR provides for fines of up to €20 million or 4% of worldwide annual turnover. For Deutsche Wohnen, the theoretical ceiling was around €28 million. But fines in the five- to six-figure range can also be imposed on SMEs – and without turnover in the millions they can quickly become a threat to the company's very existence.
On top of this: affected individuals can claim damages under Art. 82 GDPR. And retaining data without a deletion function is a clear indicator of inadequate technical and organisational measures (TOMs) under Art. 32 GDPR.
To put this in perspective, a few figures: In Germany, a total of 249 GDPR fines with a combined value of around €46.9 million were imposed in 2025. Across the EU, the GDPR Enforcement Tracker Report 2026 recorded around 2,685 fines with a total sum of about €6.11 billion. And the Deutsche Wohnen case is no isolated incident: in November 2024, the Hamburg data protection authority likewise imposed €900,000 on a debt-collection company that had retained debtor data for up to five years beyond the statutory deletion deadlines.
The Deutsche Wohnen ruling marks a clear turning point: an archive system without a deletion function is not a minor offence, but an intentional GDPR violation with fine potential. The reduced sum of €900,000 should not deceive anyone – the mitigation was essentially based on the GDPR's “introductory phase”. This argument is definitively exhausted more than seven years after the regulation came into force.
For small and medium-sized enterprises, this means: check now whether your systems can actually delete personal data – and whether your deletion concept exists not only on paper but is technically practised. Whoever clarifies this point today saves themselves fine proceedings tomorrow. As Christopher Schewior of Dr. Datenschutz warns: anyone using systems that do not allow for data-protection-compliant deletion is creating precisely those “data graveyards” that supervisory authorities set their sights on.