Data protection: what the proceedings against Deutsche Wohnen mean for your data archives

A €14.5 million fine, seven years of proceedings and a CJEU judgment. The Deutsche Wohnen SE case ended with a €900,000 penalty. It is far more than a data protection precedent. The case offers practical lessons for any company that archives personal data without a genuinely workable deletion policy.

What the case is about

Deutsche Wohnen SE, a listed real estate company based in Berlin, with around 163,000 housing units, stored the personal data of former tenants in an archive system that technically did not allow certain data to be deleted selectively. Salary certificates, bank statements, copies of identity documents, and tax and social security data therefore remained in the system, even though the original purpose for retaining them had often ceased to exist. During inspections carried out in June 2017 and March 2019, the Berlin authority responsible for data protection and freedom of information (BlnBDI) found that the shortcomings had essentially continued.

In October 2019, it imposed an administrative fine of around €14.5 million for alleged infringements of Art. 5(1)(a), (c) and (e), as well as Art. 25(1) GDPR. Art. 5(1)(a) protects lawfulness, fairness and transparency; Art. 5(1)(c) establishes the principle of data minimisation, meaning the duty to retain only the data that are necessary; and Art. 5(1)(e) requires retention to be limited to the period necessary. Art. 25(1), for its part, requires companies to build data protection into the design of their systems and to provide for data-protection-friendly default settings in their systems and processes.

In addition to the main allegation concerning the absence of a deletion policy, 15 specific individual cases involving former tenants concerned the continued processing of their data without any legal basis under Art. 6(1) GDPR. This provision determines the circumstances in which processing is lawful. The data had therefore not merely been retained for too long, but had been retained without any lawful basis. The authority imposed separate administrative fines of between €6,000 and €17,000 in each case.

Seven years of proceedings

Deutsche Wohnen challenged the decision imposing the fine. In February 2021, the Berlin Regional Court initially discontinued the proceedings because the chamber doubted whether, under German law, a fine could be imposed directly on a company without identifying a specific individual holding a management position. Following an appeal by the public prosecutor’s office, the Berlin Court of Appeal referred the question to the Court of Justice of the European Union (CJEU). In December 2023, the CJEU held, in Case C-807/21, that Art. 83 GDPR permits the direct liability of a company. Art. 83 sets out the conditions for and the amount of GDPR fines; under that decision, a fine may be imposed directly on a company without establishing the fault of a particular individual holding a management position. The Berlin Court of Appeal set aside the decision to discontinue the proceedings and referred the case back to the Berlin Regional Court. In a different composition, the court subsequently held several days of hearings devoted to the examination of the evidence.

A substantial correction of the authority’s decision

On 9 June 2026, the Berlin Regional Court (ref. 526 OWi LG 1/20) reduced the administrative fine to €900,000, representing a reduction of around 94 per cent. The judgment is not yet final and may be challenged by an appeal on points of law.

The court justified this substantial reduction, among other things, by noting that Deutsche Wohnen had already engaged external auditors, consultants and IT specialists to adapt its IT systems to the new rules. The infringements occurred during the GDPR implementation phase. In addition, the Berlin authority responsible for data protection had itself encountered difficulties adapting to the new legal framework and documenting the existing situation in a manner capable of standing up in court.

This case illustrates the value of a strong defence against fines imposed under the GDPR. Courts are not bound by the assessment of supervisory authorities. They examine the statutory elements, the relevant period, fault and the amount of the fine independently.

What this means for your company

For each data category, such as data subjects, customers, applicants, former employees or former contractual partners, the purpose that still justifies retaining the data after the end of the business relationship should be documented, together with the period for which that purpose remains relevant. This may include statutory tax retention obligations, defending against claims during the limitation period, or statutory obligations such as anti-money-laundering requirements. The same data may simultaneously serve several purposes with different retention periods. In these circumstances, a blanket rule to “delete after X years” is too simplistic.

The systems used must be capable of implementing these periods through deletion or, where permitted, anonymisation. Mere access restrictions do not replace the erasure required under Art. 17 GDPR. They can nevertheless reduce the risk during a documented system transition and helped Deutsche Wohnen when the fine was assessed.

Professionals who regularly work with corporate IT systems know this well: a perfectly GDPR-compliant system is something of a rare beast. The key is therefore to make the best possible use of the available functionality and, where technology is not enough, to put organisational procedures in place to document the gaps and close them effectively.