HmbBfDI (Hamburg) - Fine against a financial company

From GDPRhub
HmbBfDI - Fine against a financial company
Authority: HmbBfDI (Hamburg)
Jurisdiction: Germany
Relevant Law: Article 22 GDPR
Type: Other
Outcome: n/a
Started:
Decided:
Published: 30.09.2025
Fine: 492,000 EUR
Parties: n/a
National Case Number/Name: Fine against a financial company
European Case Law Identifier: n/a
Appeal: Unknown
Original Language(s): German
Original Source: HmbBfDI (in DE)
Initial Contributor: ap

The DPA fined a company providing financial services €492,000 for non-transparently rejecting credit card applications of data subjects based on automated decision-making; thereby the company failed to fulfill its information obligations and to provide access to the logic involved.

English Summary

Facts

The DPA’s investigated a company providing financial services (the controller). It is unclear if the investigation originated from a data subject’s complaint or an ex officio investigation. The DPA found that the controller rejected data subjects’ requests for credit cards based on automated decision-making. This was done despite the data subjects’ good creditworthiness.

Holding

The DPA found that the controller had rejected data subjects' credit card applications in a non-transparent way. In addition, the DPA noted that the controller had provided incomplete information to data subjects who requested an explanation, in violation of its information obligations.

The DPA fined the controller €492,000 euros.

Comment

This summary is based on a press release by the DPA and will be updated when further details are known.

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the German original. Please refer to the German original for more details.

A financial company pays almost 500,000 euros due to non-transparent automated decisions. The Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI) has imposed a fine of 492,000 euros on a financial company for violations of the rights of affected customers in individual cases of automated decisions. Despite good creditworthiness, the credit card applications of several customers were rejected due to automated decisions - these are decisions made by machines on the basis of algorithms and without human intervention. When the affected customers subsequently demanded reasons for the rejected applications, the company did not adequately fulfill its statutory information and disclosure obligations. Background: Automated decisions made by machines on the basis of algorithms and without human intervention are associated with particular risks to the rights and freedoms of the data subjects. The use of such procedures is therefore only permitted under strict conditions under the provisions of the General Data Protection Regulation (GDPR). In addition to these stricter legal requirements, controllers have additional information obligations, while data subjects are entitled to more extensive rights of access. If, for example, data subjects submit a request for information to the controller, the controller is obligated to provide the requestor with meaningful information about the logic involved in the automated decision. In both the administrative and fine proceedings, the affected company made considerable efforts to improve its process for fulfilling the rights of data subjects in automated decision-making and cooperated extensively with the HmbBfDI. This circumstance was taken into account as a significant mitigating factor in the assessment of the fine. The company has accepted the fine notice. Interim report as of the end of September 2025: Including the above-mentioned fine, the HmbBfDI has so far imposed fines totaling approximately €775,000 for violations of the GDPR in 2025. A total of 15 administrative offense proceedings were legally concluded by September 2025. The focus of the penalties was on unlawful advertising measures and individual violations by employees. In three cases, companies had sent customers advertising by email without the recipients' consent. Fines in the low five-figure range were imposed on these companies. A total of six fines were imposed on employees of the police and other Hamburg authorities for conducting queries on private individuals in official databases without official authorization. A hospital employee had to pay a fine for viewing a colleague's patient file despite not being involved in the treatment. In addition, the Hamburg Federal Office for Data Protection (HmbBfDI) imposed a fine of €195,000 on a trading company. The company had commissioned service providers to send mailings. In several cases and over an extended period, the company failed to fulfill the data subjects' rights asserted by the recipients after receiving the advertising mail in a timely manner. Thomas Fuchs, Hamburg's Commissioner for Data Protection and Freedom of Information, stated: "If companies systematically fail to respond, or respond inadequately, to requests for information, a significant sanction is warranted. This applies particularly to structures that are opaque to those affected, such as address trading or complex decision-making algorithms—and increasingly also to the use of artificial intelligence. If software makes decisions over people, the processing agency must be able to explain the underlying reasons clearly."