Berlin, 28. April 2020
Berlin Commissioner for
Data Protection and
521.11540 / 631.144.1 Freedom of Information
A56ID 105454 Friedrichstr. 219
10969 Berlin
CR 112682 Visitors’ entrance:
Puttkamer Str. 16-18
DD 114100
The building is fully accessible to
disabled members of the public.
FD 123064
Contact us
Phone: +49 (0)30 13889-0
Final Decision Fax: +49 (0)30 215 50 50
Use our encrypted contact form
for registering data protection
complaints:
Reprimand www.datenschutz-berlin.de/be-
schwerde.html
To:
For all other enquiries, please
N26 Bank GmbH send an e-mail to:
Klosterstr. 62 [email protected]
10179 Berlin Fingerprint of our
PGP-Key:
Dear D3C9 AEEA B403 7F96 7EF6
C77F B607 1D0F B27C 29A7
Dear
We hereby reprimand your company for an infringement of the Gen- Office hours
eral Data Protection Regulation (GDPR) when processing personal Daily from 10 am to 3 pm,
Thursdays from 10 am to 6 pm
data in your area of responsibility. (or by appointment)
Justification: How to find us
The underground line U6 to
Our decision is based on the following considerations: Kochstraße / Bus number M29
and 248
I.
We have established the following facts: Visit our Website
https://privacy.de
On 1 June 2019, the complainant exercised his right to information under
Article 15 GDPR. You only fulfilled the right to information after we wrote to
you on 17 July 2019. The reason for the delay was the mistake of an indi-
vidual employee. There has been a breach of Art. 12 (3) (1) GDPR (one-
month period).
You have also transferred data about the complainant through the Face-
book Custom Audiences program. This was done without consent and with-
out a justifiable legal provision (see memorandum by dated 19
September 2019).
II.
The reprimand is based on Art. 58 (2) (b) GDPR. There has been a viola-
tion of the GDPR in your area of responsibility.
-2-
Taking into account the specific circumstances of the facts of the case un-
der investigation, we consider a reprimand to be appropriate following the
conclusion of our investigation. With regard to the violation of Art. 12
GDPR, we have taken into account that this was the fault of an individual
employee and that you further trained this employee. Regarding the trans-
fer of data to Facebook, we refrained from initiating administrative offence
proceedings only because you changed the procedure following our criti-
cism.
In the safe expectation that you will comply with data protection regulations
in the future, we consider the matter closed.
With kind regards,