Ruling
Deutsche Wohnen: a fine on a legal person needs no identified natural person, but does require fault
- Date
- Status
- final
- Body
- Hof van Justitie van de EU (Grote kamer), Deutsche Wohnen SE tegen Staatsanwaltschaft Berlin
- Reference
- C-807/21, ECLI:EU:C:2023:950
What it is about
Question: may a Member State allow a GDPR fine on a company only where the infringement has first been attributed to a specific manager or employee, and is a fine possible without intent or negligence? Ruling: national rules making a fine on a legal person conditional on attribution to an identified natural person are contrary to Article 58(2)(i) and Article 83 GDPR. A fine may however be imposed only where it is established that the controller committed the infringement intentionally or negligently. That is the case where the controller could not be unaware of the infringing nature of its conduct, whether or not it was aware that it was infringing the GDPR. For the maximum fine the total worldwide annual turnover of the undertaking in the competition law sense (Articles 101 and 102 TFEU) counts.
What this means in practice
Your organisation can be fined directly as a legal person; the defence that no employee is personally responsible does not work. The authority must however establish intent or negligence, but ignorance of the GDPR is no defence where you could not have been unaware that your conduct was infringing. A well documented compliance programme and demonstrable diligence strengthen your position. For corporate groups the maximum fine is set by reference to the turnover of the whole economic unit, not just that of the subsidiary that made the error.
The GDPR articles concerned
Source: EUR-Lex, arrest C-807/21checked on 15 September 2026
Summary and practical reading by Praxikon. Not legal advice; the source prevails.
Connections
What connects to this development
Themes where this returns
The counterpart in the other law
- Article 3 AI Act: Definitions
- Article 5 AI Act: Prohibited AI practices
- Article 6 AI Act: Classification rules for high-risk AI systems
- Article 16 AI Act: Obligations of providers of high-risk AI systems
- Article 25 AI Act: Responsibilities along the AI value chain
- Article 26 AI Act: Obligations of deployers of high-risk AI systems
- Article 50 AI Act: Transparency obligations for providers and deployers of certain AI systems
- Article 70 AI Act: Designation of national competent authorities and single points of contact
- Article 74 AI Act: Market surveillance and control of AI systems in the Union market
- Article 99 AI Act: Penalties
Case law8 of 14
- Land Hessen: the supervisory authority need not always fine where the organisation already remedied the breach
2024-09-26 · final, Hof van Justitie van de EU (Eerste kamer), TR tegen Land Hessen
- Reddit's summary proceedings against the DPA over a penalty order and legal privilege dismissed
2026-03-04 · status not established, Rechtbank Den Haag, voorzieningenrechter
- Council of State: DPA could fine DPG Media for routinely demanding ID copies, fine halved to 262,500 euros
2025-09-24 · final, Raad van State, Afdeling bestuursrechtspraak
- IAB Europe: the TC String is personal data and the industry body is a joint controller
2024-03-07 · final, Hof van Justitie van de EU (Vierde kamer), IAB Europe tegen Gegevensbeschermingsautoriteit (België)
- Council of State: 600,000 euro fine for wifi tracking in Enschede stays annulled
2026-07-29 · final, Raad van State, Afdeling bestuursrechtspraak
- EDPS v SRB: pseudonymised data are not always personal data for everyone, but the information duty applies from collection
2025-09-04 · final, Hof van Justitie van de EU (Eerste kamer), Europese Toezichthouder voor gegevensbescherming (EDPS) tegen Gemeenschappelijke Afwikkelingsraad (SRB)
- Gelderland District Court: bankruptcy trustee is controller, DPA fine for unsecured hard drive cut to 58,125 euros
2025-08-07 · status not established, Rechtbank Gelderland
- Council of State upholds 6,000 euro DPA fine for recruitment firm
2024-05-29 · final, Raad van State, Afdeling bestuursrechtspraak
Guidelines8 of 9
- Consultation on the Dutch DPA's enforcement policy (April 2026)
2026-04-13 · under consultation, Autoriteit Persoonsgegevens
- Guidelines 02/2026 on Anonymisation
2026-07-07 · under consultation, European Data Protection Board (EDPB)
- Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models
2024-12-17 · final, European Data Protection Board (EDPB)
- Guidelines 07/2020 on the concepts of controller and processor in the GDPR
2021-07-07 · final, European Data Protection Board (EDPB)
- Guidelines 05/2020 on consent under Regulation 2016/679
2020-05-04 · final, European Data Protection Board (EDPB)
- Dutch DPA (AP) publishes position paper on the Digital Omnibus and the AI Omnibus
2026-01-13 · final, Autoriteit Persoonsgegevens
- Guidelines 01/2025 on Pseudonymisation
2025-01-16 · adopted, European Data Protection Board (EDPB)
- Guidelines on Automated individual decision-making and Profiling for the purposes of Regulation 2016/679
2018-05-25 · final, Article 29 Working Party, bekrachtigd door de European Data Protection Board (EDPB)
Enforcement and fines
- Coolblue fined 40,000 euros on objection for cookies without consent
2024-12-23 · status not established, Autoriteit Persoonsgegevens
- DPA cuts Kruidvat fine to 50,000 euros on objection
2025-05-27 · status not established, Autoriteit Persoonsgegevens
- Ten municipalities fined a total of 250,000 euros for unlawful files on Muslim residents
2026-02-03 · final, Autoriteit Persoonsgegevens
- Formal warning to the Dutch Minister of Education, Culture and Science not to put the CABR war archive online and searchable
2024-11-26 · final, Autoriteit Persoonsgegevens
Legislation in motion6 of 9
- Amendment to the Dutch GDPR Implementation Act: DPA must publish GDPR sanctions from 1 September 2026
2026-09-01 · in force, Wetgever (Tweede Kamer) en Autoriteit Persoonsgegevens
- Proposal: relative definition of personal data (Article 4(1) GDPR)
2025-11-19 · proposal, Europese Commissie
- European Parliament: joint ITRE-LIBE draft report, amendments tabled, no committee vote yet
2026-06-22 · under negotiation, Europees Parlement, commissies ITRE en LIBE (gezamenlijke commissie)
- Proposal: implementing acts on when pseudonymised data ceases to be personal data (new Article 41a GDPR)
2025-11-19 · proposal, Europese Commissie
- Council: Irish Presidency continues with a revised compromise, Antici Group 11 September 2026
2026-09-11 · under negotiation, Raad van de Europese Unie, Iers voorzitterschap
- Proposal: cookie rules move from ePrivacy to the GDPR, with new exceptions and a six-month rule (new Article 88a GDPR and Article 5(3) ePrivacy)
2025-11-19 · under negotiation, Europese Commissie