• Latest
  • Trending
Already created a processing directory?

Bonn Regional Court confirms fine for inadequate customer verification

7. November 2022
ChatGPT and lawyers: recordings of the Weblaw launch event

Private AI use in the company

24. October 2025
Lego brick still protected as a design patent

App purchases, in-app purchases and sales tax

21. October 2025
dsgvo 1

What belongs in a DPA? Data processing agreement in accordance with Art. 28 GDPR

17. October 2025
Smart contracts in the insurance industry: contract design and regulatory compliance for InsurTech start-ups

Contract for work vs. service contract in software, AI and games projects

15. October 2025

Influencer contract: performance profile, rights/buyouts, labeling and AI content

13. October 2025
AI content for subscription platforms

AI content for subscription platforms

29. September 2025
E-sports finally charitable? What the government draft of the Tax Amendment Act 2025 really brings

E-sports finally charitable? What the government draft of the Tax Amendment Act 2025 really brings

23. September 2025
Clubs, photos and minors: managing consent properly

Clubs, photos and minors: managing consent properly

22. September 2025
AI faces, voice clones and deepfakes in advertising: rules of the game under the EU AI Act and German law

AI faces, voice clones and deepfakes in advertising: rules of the game under the EU AI Act and German law

17. September 2025
Modding in EULAs and contracts – what applies legally in Germany?

Modding in EULAs and contracts – what applies legally in Germany?

8. September 2025
Arbitration agreements in EULAs and developer contracts

Arbitration agreements in EULAs and developer contracts

7. September 2025
Chain of title in game development: building a clean chain of rights

Chain of title in game development: building a clean chain of rights

6. September 2025
Fail-fast clauses in media productions – what are they actually?

Fail-fast clauses in media productions – what are they actually?

5. September 2025
Founder’s agreement vs. shareholder agreement: setting the course for startups at an early stage

Founder’s agreement vs. shareholder agreement: setting the course for startups at an early stage

12. August 2025
Cheat software without code intervention: What the BGH really decided in the Sony ./. Datel case (I ZR 157/21)

Cheat software without code intervention: What the BGH really decided in the Sony ./. Datel case (I ZR 157/21)

11. August 2025
Digital integrity as a (new) fundamental right: status in Germany and the EU in 2025

Digital integrity as a (new) fundamental right: status in Germany and the EU in 2025

10. August 2025
European Economic Interest Grouping (EEIG)

EU Digital Decade 2030: Data law, Data Act & eIDAS 2 – what needs to be implemented in 2025

8. August 2025
Upload filters between copyright and personal rights

Upload filters between copyright and personal rights

7. August 2025
On-demand transmission right in the digital space: streaming, Section 19a UrhG and licensing

On-demand transmission right in the digital space: streaming, Section 19a UrhG and licensing

6. August 2025
Q&A: Legal issues for game developers

5-day guide: Founding a game development studio

5. August 2025
  • Mehr als 3 Millionen Wörter Inhalt
  • |
  • info@itmedialaw.com
  • |
  • Tel: 03322 5078053
Kurzberatung
Rechtsanwalt Marian Härtel - ITMediaLaw

No products in the cart.

  • en English
  • de Deutsch
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
Rechtsanwalt Marian Härtel - ITMediaLaw

Bonn Regional Court confirms fine for inadequate customer verification

7. November 2022
in Data protection Law
Reading Time: 2 mins read
0 0
A A
0
privacy policy 3344455 1280

The Ninth Chamber for Administrative Fines of the Bonn Regional Court today ruled that the fine imposed by the Federal Commissioner for Data Protection and Freedom of Information on a telecommunications service provider for a violation of the General Data Protection Regulation was justified on the merits but unreasonably high. The Board therefore reduced the fine from the original €9.55 million to €900,000.

Key Facts
  • The 9th Chamber of the Regional Court of Bonn has imposed a fine on a telecommunications service provider.
  • The original fine of 9.55 million euros was reduced to 900,000 euros.
  • The reason for this was a criminal complaint of stalking by a former partner.
  • The Chamber found that the GDPR had been violated without a manager being identified.
  • Insufficient authentication in the call center allowed unlawful access to a customer's contact details.
  • The data subject was legally mistaken about the level of data protection and the illusion of security.
  • The chamber ruled that the data breach was to be classified as minor and did not cause mass data breaches.

The reason for the fine proceedings was a criminal complaint of stalking by a customer of the telecommunications service provider. His former partner had requested the new telephone number of her ex-partner via the call center of the telecommunications service provider by posing as his wife.

For legitimation, it only had to provide the customer’s name and date of birth. She had then used the new phone number to make harassing contacts.

In November 2019, the BfDI therefore imposed a fine of EUR 9.55 million on the telecommunications service provider for grossly negligent violation of Art. 32 para. 1 GDPR.

The BfDI explained that simply requesting the name and date of birth to authenticate telephone callers did not provide sufficient protection for the data in the call center.

The telecommunications service provider appealed against this decision, which is why the case was heard on five main days before the 9th Board of Administrative Appeals for Fines.

The Board ruled that the imposition of a fine on a company does not depend on a finding of a specific violation by a management person of the company. In the Board’s view, the applicable European law, unlike the German law on administrative offenses, does not impose a corresponding requirement.

In the case in point, there was a data protection violation because the telecommunications service provider had not protected the data of its customers in the course of communication via the so-called call centers by means of a sufficiently secure authentication procedure. In this way, it was possible for unauthorized callers to obtain further customer data, such as the current telephone number, only with the help of the full name and date of birth, by cleverly asking and pretending to be authorized. However, sensitive data such as itemized bills, traffic data or account details could not have been retrieved in this way.

The person concerned had been in a legal error with regard to the adequacy of the level of protection. In the absence of binding specifications for the authentication process in call centers, this legal error was understandable but avoidable.

In its decision, the Board reduced the amount of the fine to 900,000 euros. The fault of the telecommunications service provider was minor. With regard to the authentication practice practiced over many years, which had not been objected to until the fine was imposed, there had been a lack of the necessary awareness of the problem. In addition, it should be taken into account that – even in the opinion of the BfDI – this is only a minor data protection violation. This could not have led to the mass release of data to unauthorized persons.

Marian Härtel
Author: Marian Härtel

Marian Härtel ist Rechtsanwalt und Fachanwalt für IT-Recht mit einer über 25-jährigen Erfahrung als Unternehmer und Berater in den Bereichen Games, E-Sport, Blockchain, SaaS und Künstliche Intelligenz. Seine Beratungsschwerpunkte umfassen neben dem IT-Recht insbesondere das Urheberrecht, Medienrecht sowie Wettbewerbsrecht. Er betreut schwerpunktmäßig Start-ups, Agenturen und Influencer, die er in strategischen Fragen, komplexen Vertragsangelegenheiten sowie bei Investitionsprojekten begleitet. Dabei zeichnet sich seine Beratung durch einen interdisziplinären Ansatz aus, der juristische Expertise und langjährige unternehmerische Erfahrung miteinander verbindet. Ziel seiner Tätigkeit ist stets, Mandanten praxisorientierte Lösungen anzubieten und rechtlich fundierte Unterstützung bei der Umsetzung innovativer Geschäftsmodelle zu gewährleisten.

Tags: AuthenticationInformationKIPrivacyRegulation

Weitere spannende Blogposts

BGH decides on the permissibility of fees for Paypal/immediate bank transfer

Attention: Vouchers to existing customers can be advertising!
7. November 2022

The German Federal Supreme Court today ruled that companies may charge their customers a fee for payment via Sofortüberweisung or...

Read moreDetails

Pirate server for online games and criminal law?

Pirate server for online games and criminal law?
7. September 2019

Since the topic is topical in Germany, today a short execution on criminal responsibility for the operation of pirate servers....

Read moreDetails

Commercial use of Discord: A legal guide

What about liability with a Discord server?
18. October 2023

Introduction Discord has become a popular platform for gamers, communities, and most recently professional teams since its inception in 2015....

Read moreDetails

Meanwhile: more than 1000 articles on IT/IP legal issues on the blog

Meanwhile: more than 1000 articles on IT/IP legal issues on the blog
6. September 2019

In the meantime, there are more than 1000 articles on IT legal issues, in particular on competition law, copyright, trademark...

Read moreDetails

Data Protection Commission on the ECJ Privacy Shield Decision

District Court Frankfurt a.M. on the right to be forgotten
7. November 2022

In its judgment of July 16, 2020 (Case C311/18), the European Court of Justice declared the European Commission's Decision 2016/1250...

Read moreDetails

Interstate Broadcasting Treaty: Probably no gamer privilege for streamers!

Interstate Broadcasting Treaty: Probably no gamer privilege for streamers!
7. November 2022

In the wake of this report, I received the information that the privilege for gaming streamers (i.e. especially for streamers...

Read moreDetails

Federal Court of Justice and “climate neutral”

BGH considers Uber Black to be anti-competitive
10. July 2024

The Federal Court of Justice has ruled that advertising with an ambiguous environmental term (here: "climate neutral") is only permissible...

Read moreDetails

Caution for tradespeople: risk of non-payment without revocation instructions

Lego brick still protected as a design patent
31. May 2024

Last year, I already drew attention to the problem that tradespeople and service providers who act without proper revocation instructions...

Read moreDetails

Artificial Intelligence in Software and Game Development: Opportunities, Risks and Legal Challenges

Artificial Intelligence in Software and Game Development: Opportunities, Risks and Legal Challenges
12. May 2023

AI in software and game development: potential and pitfalls The use of artificial intelligence (AI) in software and game development...

Read moreDetails
ChatGPT and lawyers: recordings of the Weblaw launch event
Law on the Internet

Private AI use in the company

24. October 2025

Private accounts on ChatGPT & Co. for corporate purposes are a gateway to data protection breaches, leaks of secrets and...

Read moreDetails
Lego brick still protected as a design patent

App purchases, in-app purchases and sales tax

21. October 2025
dsgvo 1

What belongs in a DPA? Data processing agreement in accordance with Art. 28 GDPR

17. October 2025
Smart contracts in the insurance industry: contract design and regulatory compliance for InsurTech start-ups

Contract for work vs. service contract in software, AI and games projects

15. October 2025

Influencer contract: performance profile, rights/buyouts, labeling and AI content

13. October 2025

Podcastfolge

052c2ca5ca0421f0316b42073ce61791

Innovative business models – risk and opportunity at the same time

10. September 2024

In this exciting episode of our podcast, we take a deep dive into the world of innovative business models. Our...

Read moreDetails
238a909c26a0302cbd4792cbd18e4922

Global challenges for start-ups – A legal guide

10. October 2024
c9c5d7fd380061a8018074c2ca5a81bf

Startups and innovation in Germany – challenges and opportunities

26. September 2024
d00527fd01b1f807a4f80c0f202069e7

Legal basics for startup founders – how to start on the safe side!

9. November 2024
legal challenges when implementing confidential computing data protection and encryption in the cloud

Smart contracts and blockchain

15. January 2025

Video

My transparent billing

My transparent billing

10. February 2025

In this video, I talk a bit about transparent billing and how I communicate what it costs to work with...

Read moreDetails
Fascination between law and technology

Fascination between law and technology

10. February 2025
My two biggest challenges are?

My two biggest challenges are?

10. February 2025
What really makes me happy

What really makes me happy

10. February 2025
What I love about my job!

What I love about my job!

10. February 2025
  • Privacy policy
  • Imprint
  • Contact
  • About lawyer Marian Härtel
Marian Härtel, Rathenaustr. 58a, 14612 Falkensee, info@itmedialaw.com

Marian Härtel - Rechtsanwalt für IT-Recht, Medienrecht und Startups, mit einem Fokus auf innovative Geschäftsmodelle, Games, KI und Finanzierungsberatung.

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • en English
  • de Deutsch
Kostenlose Kurzberatung