German telecoms firm slapped with €10m GDPR fine
People could access sensitive customer data in some cases by only providing a name and date of birth


The German data regulator has fined the telecoms giant 1&1 almost €10 million for not taking sufficient measures to prevent unauthorised access to customer data.
The company has been punished because it failed to take measures to adequately protect the data of its customers, meaning extensive customer information could be accessed by just providing the name and date of birth.
The lack of protections for customer data constituted a violation of Article 32 of the General Data Protection Regulation (GDPR), according to the Federal Commissioner for Data Protection and Freedom of Information (BfDI).
The Federal Commissioner Ulrich Kelber explained the €9,550,000 fine was a clear sign the data regulator would enforce the protection of fundamental rights under GDPR, and that due consideration was taken in the decision.
Despite the severity of the fine, BfDI also noted that 1&1 was transparent and cooperative during the investigation.
To rectify its processes, the telecoms giant first introduced new authentication steps, before unveiling plans to roll out an authentication procedure with significantly stronger barriers to accessing data.
The BfDI said the fine could have been much higher had 1&1 representatives not been as cooperative as they were during the investigation. The infringement, moreover, was limited to just a handful of customers, despite all customers being at risk.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
RELATED RESOURCE
Understanding the must-haves of modern data protection
Go beyond traditional backup and recovery
The data regulator added it would be investigating the customer authentication procedures of rival telecoms companies as a result of its findings.
The agency has been active in recent months, having previously issued a €14.5 million fine against a housing giant for hanging onto the personal and financial data of former and current tenants longer than necessary.
The fines have been adding up since GDPR came into effect in May 2018, but are blown out of the water when compared with the multi-million-pound penalties issued against the likes of BA and Marriot.

Keumars Afifi-Sabet is a writer and editor that specialises in public sector, cyber security, and cloud computing. He first joined ITPro as a staff writer in April 2018 and eventually became its Features Editor. Although a regular contributor to other tech sites in the past, these days you will find Keumars on LiveScience, where he runs its Technology section.
-
Why veterans can excel in data centers – and could help the IT sector address its skill shortages
In-depth Ex-military workers can bring software and hardware to civilian roles
By John Loeppky
-
LaunchDarkly to "double down" on observability with Highlight acquisition
News Highlight's observability tools will be integrated into LaunchDarkly's Guarded Releases software deployment service
By Daniel Todd
-
Data sovereignty a growing priority for UK enterprises
News Many firms view data sovereignty as simply a compliance issue
By Emma Woollacott
-
Elevating compliance standards for MSPs in 2025
Industry Insights The security landscape is set to change significantly in the years to come with new regulations coming into effect next year, here's how the channel needs to adapt
By Ross Brewer
-
How ready is your company for NIS2?
Supported Content The EU’s latest cybersecurity legislation raises the stakes for enterprises and IT leaders - and ensuring compliance can be a daunting task
By Ross Kelly
-
Top data security trends
Whitepaper Must-have tools for your data security toolkit
By ITPro
-
Conquering technology risk in banking
Whitepaper Five ways leaders can transform technology risk into advantage
By ITPro
-
Advancing your risk management maturity
Whitepaper A roadmap to effective governance and increase resilience
By ITPro
-
When banking works, the world works
Whitepaper Five ways automated processes can drive revenue and growth across your bank
By ITPro
-
Automating digital resiliency in banking
Whitepaper Prioritize investment in solutions that mitigate a lack of digital resiliency when disruptions strike
By ITPro