
Summary The DPA from Hamburg has imposed a fine of EUR 900,000 on Vattenfall Europe Sales GmbH. The fine is related to data matching, which the controller had carried out in the period from August 2018 to December 2019 in the course of contract inquiries for special contracts. The special contracts served to attract new customers and were accompanied by bonus payments for the customers. The controller compared personal data of prospective customers who had submitted an inquiry for a special contract with contracts concluded by existing customers. If this revealed that an applicant had already signed a contract with the controller, then switched to another supplier and now wanted to sign a contract again, the controller could reject the application for the special contract if necessary. This was intended to prevent ‘bonus shopping’, which is not lucrative for the companies. However, the controller had not properly informed the customers that such comparisons would be made. The DPA considered this to be a violation of the company’s transparency and information obligations. Around 500,000 people were affected.
Link: link
Related articles:  Art. 12 GDPR, Art. 13 GDPR
Type: Insufficient data processing agreement
Fine: EUR 900,000
Sector Transportation and Energy


All data is based on The CMS’s Law GDPR Enforcement Tracker Source:

Tags: case law