The archiving risk - €14.5m fine in Germany

Big fine by the Berlin data protection supervisory authority against a property company for keeping tenants' personal data in an archive system that didn't allow deletion of specific personal data that was no longer necessary for the original purpose of deciding whether to take them on as a tenant.

Data retention is clearly now a much bigger risk under GDPR. This fine will no doubt spur the takeup of archiving systems allowing selective deletion/anonymisation, perhaps on an automated scheduled basis. But legacy systems, aaaargh! (Note also that this issue has come up before in France, where the CNIL is similarly hot under the collar about archiving, including segregation even of personal data that needs to be retained e.g. the SERGIC fine.)

Details

In 2017 the SA had previously conducted an onsite audit and strongly recommended changing the archive system but, in a March 2019 followup audit, Deutsche Wohnen SE couldn't demonstrate a cleanse of their data archives, or any legitimate reason for the ongoing storage of the tenants' personal data. Even though it had taken some measures to remediate the lack of compliance, it couldn't justify its continued storage.

The Berlin SA therefore imposed a fine based on the company's global turnover of >€1b in 2018. Factors:

  • the archive structure was intentionally created
  • the company illegitimately processed the data over a long period of time
  • it had taken initial measures for remedying the compliance failures
  • good cooperation with the DPA
  • no evidence of abusive access to the illegitimately stored data

So the fine imposed was in the median range, rather than the maximum possible. 

Huge thanks to my colleague, Fieldfisher partner Katherina Weimer, for her very helpful summary.

Oriol Cruz

Privacy & Data Protection Legal Counsel en Grifols

5 年

Great contribution!! Do you know by chance any document for guidance from any Data Protection Authority about the archiving or retention of employees or other data subject images (pictures, not videosurveillance)?

Really something to be concerned about for any company with legacy systems! The DPAs are ramping up the fines!

回复

A good call to the many companies storing far longer than necessary, time to clean up. A special thought to the organisation proudly stating in their privacy notice ‘we will keep your special category personal data for 100 years’.

回复

要查看或添加评论,请登录

Dr W Kuan Hon的更多文章

  • Action after the GDPR 2-yr report? (what's NOT in the report but tucked away)

    Action after the GDPR 2-yr report? (what's NOT in the report but tucked away)

    Most of the below isn't in the Commission's Communication or EDPB work programme, but from the Commission's Staff…

  • Processor - not processor? Covid-19 testing privacy notice

    Processor - not processor? Covid-19 testing privacy notice

    It's not easy determining if an organisation is acting as a controller, processor (or indeed neither) for a particular…

  • Loo roll song - Beatles parody!

    Loo roll song - Beatles parody!

    Parody of "With A Little Help From My Friends" - with apologies to the Beatles and Ringo! https://www.youtube.

  • Don't walk so close to me!

    Don't walk so close to me!

    Here's something for fans of The Police and Sting to sing at home in the shower - but not in public, for obvious…

    5 条评论
  • Data localisation - now webinar / video

    Data localisation - now webinar / video

    Just to confirm that the session next Monday evening 23 Mar on my data localisation book is still going ahead, but only…

  • COVID-19: missing UK info

    COVID-19: missing UK info

    The main UK government COVID-19 webpage omits important info that should be there or linked to from there - not buried…

  • Encryption - humans miss the point!

    Encryption - humans miss the point!

    Encryption is a great way to secure data confidentiality, but getting people to use it properly is tough like you…

  • Data localization / transfers - BCS session 23 Mar

    Data localization / transfers - BCS session 23 Mar

    I'm presenting on the topics covered in my book Data Localization Laws and Policy - the EU data protection…

    5 条评论
  • Doctor Who - and data protection

    Doctor Who - and data protection

    Just catching up on season 12 of Doctor Who and whaddayaknow, there's this in episode 1: Hospital doctor to Graham…

    7 条评论
  • Data localization book - new review

    Data localization book - new review

    I'm really happy to have come across this recent (Nov 2019) review of my book on data localisation / international data…

社区洞察

其他会员也浏览了