900,000 Euro GDPR Fine: Berlin Court Convicts Deutsche Wohnen

Short & clear answers
Frequently asked questions about this incident
Does this ruling affect me as a small business?
Potentially yes, because the confirmed GDPR principles apply regardless of company size or industry. You are affected if you store personal data in systems that do not allow targeted deletion of individual records – such as CRM systems, applicant databases, email archives or cloud storage. This type of violation requires no cyberattack; the mere inability to delete is enough.
What exactly do I need to do now to avoid a fine?
First, create a complete inventory of all IT systems and databases in which you store personal data. For each system, check whether individual records can be deleted in a targeted way, and define retention periods. Systems that offer no deletion function must be adapted or replaced accordingly.
Why was the violation deemed intentional and the fine reduced from 14.5 million to 900,000 euros?
The court ruled the violation intentional because Deutsche Wohnen had known about the missing deletion mechanism since a regulatory inspection in 2017 yet failed to fix it in time. Mitigating factors included the company engaging external auditors, consultants and IT specialists, and the violations occurring during the early GDPR rollout phase. Lawyers warn this mitigating factor will barely apply in future cases.
Can my company be held directly liable, or only an individual managing director?
The CJEU ruled on 5 December 2023 (Case C-807/21) that GDPR fines can be imposed directly on a company without identifying a specific natural person in management as the perpetrator. However, fault in the form of intent or negligence is required. The CJEU rejected strict liability without fault.
How can a data protection authority even discover such a violation?
The authority can act through on-site inspections or based on complaints from affected individuals – in the Deutsche Wohnen case, two on-site inspections took place in 2017 and 2019. A violation already exists when a technical deletion function is missing, regardless of whether the data was ever misused. So no external attacker and no data breach need to occur.
More security news
You might also be interested in
Critical Elementor Pro Flaw: Attackers Can Fully Take Over WordPress Sites
A file upload bug in Elementor Pro up to 4.2.1 allows RCE without login. Version 4.2.2 fixes the flaw – update now!
Pods Plugin: Critical Flaw Enables Admin Takeover, No Login
A critical flaw in the WordPress plugin Pods lets attackers overwrite admin passwords without login. Over 100,000 sites are affected.
miniOrange SAML SSO: Critical Bypass Turns Attackers Into Admins
Two critical auth bypasses in the miniOrange SAML SSO plugin allow forged SAML assertions—up to full WordPress admin access.