Homepage » Blog » News

News from the areas of compliance, data protection and information security

We inform you about the latest news, reports and incidents relating to compliance, data protection and information security. You will find white papers and videos on many of our topics directly in the news articles.

Robin Data stands for highest
quality and safety standards
and is TÜV certified.

News from the areas of compliance, data protection and information security

NIS2: EU directive for more cyber security

What does the NIS-2 Directive mean for organisations in Germany? Implementation obligations, sanctions, tips for implementation.

EU Data Act: Obligations for organisations

Applicable since 12 September 2025, you will receive an overview of the content, effects and areas of application of the EU Data Protection Act.
artificial intelligence

AI REGULATION: Regulation of artificial intelligence

Find out all about the EU and German AI regulation: current status, legal requirements and effects.

The EU-U.S. Data Privacy Framework

On 10 July 2023, the EU-U.S. Data Privacy Framework entered into force. All background information on the adequacy decision.

HinSchG: Protection of whistleblowers

The Whistleblower Protection Act: regulations and obligations for companies, requirements for whistleblowers, white paper including checklist!

Smart Home Privacy Concerns

Smart Home applications: Find out why the benefits in everyday life often involve data protection risks and how you can protect yourself.

The Supply Chain Act (LkSG)

The Supply Chain Act (LkSG) came into force on 01.01.2023. Learn about the current regulations and obligations for companies in the article.

What is the TTDSG or TDDDG?

The TTDSG became the Telecommunications Digital Services Data Protection Act (TDDDG) on 13 May 2024 as a result of the harmonisation with the EU Directive.

The new EU standard contract clauses

On 07 June 2021, the European Commission published the new version of the EU Standard Contractual Clauses for the international transfer of personal data.
Picture of Thomas Ulrich on Pixabay

Federal Council increased duty to appoint data protection officer to 20 persons

On 20 September, the Federal Council decided that a company data protection officer only needs to be appointed if the number of employees exceeds 20.
Data protection DSGVO

11 months of GDPR: What are the main findings?

In May 2018, the basic data protection regulation (DSGVO) came into force. The legal requirements of the DSGVO posed a challenge for many companies. This article summarizes the most important findings of the last 11 months with the DSGVO.

Read posts from the category Fines

Examples of GDPR fines: what happens in data protection

GDPR infringements are punished with heavy fines. Find out which data protection infringements are suspected and secure yourself.

Data protection fine imposed on the Municipality of Oslo Education Authority

120.000 € because the security of the app "Skolemelding" for communication between school staff, parents and pupils was not guaranteed.

Data protection fine Swedish company

35,000 euros fine for violation of three Swedish laws at once. Information about creditworthiness published.

Highest data protection fine to date hits Delivery Hero

In August, the Berlin data protection commissioner had already imposed the highest German fine to date, amounting to 195,407 euros.

Data protection fine for the City of Oslo

EUR 50 000 fine for a serious infringement by the City of Oslo. Over a period of 11 years, patient data was incorrectly processed.

BfDI imposes fine on Rapidata GmbH

No appointment of a data protection officer despite repeated requests. Expensive even for small companies.

BfDI imposes fine on telecommunications service provider

1&1 Telecom GmbH has to pay a fine of EUR 9,550,000 for insufficient technical and organisational measures.

Data protection fine for hospital in Rhineland-Palatinate

In addition to various data protection violations, one patient was confused when he was admitted to the hospital.

Fines imposed on public bodies in Belgium

Data used without permission for election campaigns. You can read about why the Belgian supervisory authority punishes public bodies particularly severely in the article.

Data protection fine la Tribuna de Pamplona Spain

The portal La Tribuna de Cartagena published information about a person who was the victim of a crime in 2018 without their consent.

Data protection fine due to revocation of consent

To what extent did the company that was punished violate the DSGVO? What must be taken into account when revoking consent?

Million Euro fine against Deutsche Wohnen

On 05.11.2019, the Berlin data protection authority imposed a fine in an unprecedented amount. Deutsche Wohnen is to pay 14.5 million euros.

Current data breaches in the areas of compliance, data protection and information security.

Examples of data breaches: what happens in data protection

According to Art. 33 GDPR, data breaches must be reported to the supervisory authority. Examples of data breaches in data protection.

Data breach at Klarna: Third party data visible

Entering a postcode and e-mail was sufficient to view third party data. The autofill function is to blame.

Data breach Microsoft customer records leaked

In December 2019, 250 million support requests to Microsoft were available online for two days. Security researchers reported the data breach to Microsoft.

British government published private addresses of stars

The British government publishes the addresses of around 1000 celebrities, politicians and private individuals who receive the traditional New Year's honours.

Data breach at Phoenix: sensitive data sent by pharmacies

An employee unintentionally sent delivery and turnover data of 211 pharmacies by fax. Data protection officers were involved.

Data failure in the district office Coburg

Allegedly deleted data on a hard drive came into circulation: Some 12,000 documents, e-mails and passwords were released.

Data breach employees fashion house H&M

The Swedish fashion house H&M is accused of having sounded out its employees. This also involved sensitive health data.

Data breakdown frequent flyer programme Miles & More

Lufthansa's frequent flyer programme confirms data breakdown. Thousands of users had access to foreign profiles.

Data breach patient data sent to wrong recipient

Nationwide NDR survey revealed that patient data is sent to the wrong recipients. Now data protection is threatened with a fine.

Data breach in medical practice: patient data online

Patient data of a medical practice publicly accessible for several months. The reason was a weakness of the router used.

Data breach at UniCredit

The Italian bank UniCredit is the victim of a hacker attack. Around three million names, e-mail addresses and telephone numbers were captured.

Data breach at Adobe

Due to a security vulnerability, 7.5 million data of users of the Creative Cloud were publicly accessible. Read what you should be aware of now.

Data breach at Mercedes Benz

Several customers of the application Mercedes-Me got temporarily the data of other users displayed. Only customers from the USA were affected.

30.000 Euro fine for defective cookie banner

Shortly after the ruling of the European Court of Justice, the Spanish regulatory authority imposed the first fine on the airline Vueling.

Data breach and fine for Greek company

The Greek data protection authority has imposed a fine of EUR 200 000 on the telecommunications operator OTE.
© Copyright - Robin Data GmbH
en_GB