TELECOMMUNICATION SERVICE PROVIDERS ARE UNDER THE MICROSCOPE

23 December 2019

The telecommunication service provider 1&1 Telecom GmbH was fined 9.550.000 EUR by the Federal Commissioner for the Data Protection and Freedom of Information (BfDI) on the ground of that  technical and organisational measures which are set to avoid third person or unauthorised person from being able to have customer information by way of customer hotline service, was not adequate. The BfDI also fined Rapidata GmbH 10.000 EUR in another case.

Regarding this issue, it was stated by the Federal Commissioner Ulrich Kelber that Protection of Fundamental rights include data protection, and the BfDI has decisively power given by the European General Data Protection Regulation (GDPR) to penalise inadequate safeguarding of personal data so that meaning of these fines is a clue of enforcing the protection of fundamental rights.

In the case of 1&1Telecom GmbH, the BfDI found that comprehensive personal data could be taken by who calls the company’s customer service and provide customer’s name and date of birth. Therefore, under the BfDI consideration, the company is failed to comply with the article 32 of the GDPR requiring the company to provide sufficient safeguarding for protection of personal data.

Upon the penalisation, 1&1 Telecom has taken steps to improve the system of protection of personal data by strengthening the authentication procedure and consulting the BfDI. As a result of this developments, 1&1 Telecom will introduce radically impowered new authentication procedure.  

Beside those measure, still the BfDI necessarily fined the 1&1 Telecom. In the case, not only small number of customers was subject to the breach, the all customer was at the risk of possibility of transfer of their personal data. Nevertheless 1&1 Telecom was imposed fine in the lower range of possible fines through their cooperation in good faith.

Nowadays, other telecommunication service providers are put under the microscope by the BfDI.

In another case against Rapidata GmbH, the company infringed article 37 of the GDPR which requires an appointment of internal data protection officer. The reason of the amount of the fine which is only 10.000 EUR is the categorisation of the company as micro- enterprises.

For further information, click here.

Should you have any queries and/or remarks, please do not hesitate to contact us. 

Kind regards,

Zumbul Attorneys-at-Law

info@zumbul.av.tr