Deutsche Bahn Accepts € 1.1 Million Fine Imposed for Violation of Data Protection Law
Time 2 Minute Read

On Friday, October 23, 2009, the German Railways Operator Deutsche Bahn AG announced that they would pay a fine of over €1.1 million that was imposed on October 16, 2009 by the Berlin data protection authority.  This fine is the highest ever imposed by a German data protection authority.  The imposition of this fine follows a major data protection scandal that reportedly broke out within the company.  From 2002 to 2005, Deutsche Bahn had screened a large quantity of employee data and compared it to supplier data in an effort to combat corruption, but without specific suspicions related to individual employees.  In addition, the regulator considered activities by the company's security department from 2006 to 2007, which included monitoring the email communications of all employees who used external email accounts at work.  The purpose of this monitoring was to identify communication with journalists and employees of members of the federal parliament to detect which employees may have disclosed company information.  At the time it broke, the scandal cost the CEO and several top managers their jobs.  Thereafter, a major restructuring was undertaken within the company.  In addition to the changes in top management, a separate position was created at the CEO level for compliance, data protection and legal affairs.  Furthermore, it was agreed with the works council, that the company will develop new guidelines for HR data protection by the end of November.

You May Also Be Interested In

Time 2 Minute Read

On February 23, 2026, a Joint Statement on AI-Generated Imagery was published by 61 data protection authorities. The Joint Statement addresses concerns regarding AI systems capable of generating realistic images and videos depicting identifiable individuals without their knowledge or consent.

Time 4 Minute Read

On January 27, 2026, the Centre for Information Policy Leadership hosted a fireside chat with California Privacy Protection Agency General Counsel Phil Laird in honor of Data Privacy Day.

Time 2 Minute Read

On January 8, 2026, the California Privacy Protection Agency announced enforcement activity against Rickenbacher Data LLC d/b/a Datamasters and S&P Global Inc. for failing to register as data brokers in California.

Time 2 Minute Read

On December 17, 2025, the California Privacy Protection Agency announced the release of its Enforcement Advisory No. 2025-01, reminding data brokers of their obligations under California’s Delete Act.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page