Germany Germany

Company

492,000 €

GDPR enforcement action by Data Protection Authority of Hamburg (HmbBfDI) on 2025-09-30.

Rank · Sector
#44
of 322 in Finance, Insurance and Consulting
Rank · Germany
#18
of 116
Rank · All fines
#249
of 3,042

Case details

Authority
Data Protection Authority of Hamburg (HmbBfDI)
Date
2025-09-30
Controller / Processor
Company
Sector
Finance, Insurance and Consulting
Quoted Articles
Unknown
Type of violation
Non-compliance with general data processing principles

Summary

The DPA of Hamburg has imposed a fine of EUR 492,000 on a company in the finance sector. The controller used automated systems to decide whether to approve a credit application, with no human input. This system incorrectly declined applications from applicants with a good credit score. When asked for the reasons for the negative decision, the controller also failed to respond adequately to these information requests.

Open original source Links to the regulator's original publication or another source.

Related fines