The German Federal Data Protection Commission (BfDI) has imposed a large fine on mobile phone service provider 1&1 Telecommunications for violating the GDPR.
The fine, which reached €9.55 million ($10.65 million), is one of the largest fines ever imposed on a company under GDPR. The German commission found that the telecoms company had failed to implement Article 32 of the European law, which requires companies to take appropriate technical and organisational measures to protect personal data.
BfDI discovered that anyone calling 1&1's call centers could learn personal details of the company's customers by simply giving a name and date of birth . This means that the company is not properly protecting customers ' personal data .
Federal Commissioner Ulrich Kelber considered that this fine constitutes “clear message” that GDPR will be effectively enforced in the country.
“The European General Data Protection Regulation gives us the opportunity to severely punish inadequate security of personal data,” he said.
1&1 Telecommunications is one of Germany's largest DSL and mobile providers. It is a subsidiary of 1&1 Drillisch, which has more than 14 million customers.
However, the German Data Protection Commission ultimately praised 1&1 for its transparency and cooperation . Since the recommendations on security issues were made, the company has introduced an additional step to verify the identity of callers before providing information . However, the BfDI said that “despite these measures, the imposition of a fine was necessary.”
On the same day that the BfDI issued a fine to 1&1, it also announced another fine to internet Rapidata (€10,000 $11,110.) And in this case, the company had not fully complied with the GDPR.
Earlier this year, a Capgemini survey showed that fewer than one in three organizations in Europe are fully compliant with the GDPR. The main obstacle to secure data protection is the use of legacy technologies and IT systems

