Skip to content
Enforcement · Data Protection Authority of Brandenburg EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Restaurant operator: Insufficient legal basis for data processing

The DPA of Brandenburg has imposed a five-figure fine on a restaurant operator.

Restaurant operator
GERMANY
Art. 5 GDPR Art. 6 GDPR

Full text

The DPA of Brandenburg has imposed a five-figure fine on a restaurant operator. During the Corona pandemic, the operator had required restaurant visitors to fill out forms with their name, address, telephone number and e-mail address for the purpose of contact tracing as required by law. However, there was no legal requirement to collect the e-mail address. Visitors were further required to check a box stating that they agreed to be contacted by the restaurant. However, the restaurant subsequently used the email addresses to send a promotional newsletter. During its investigation, the DPA found that the processing of the email address for advertising purposes was unlawful due to the fact that the requirements for giving effective consent were not met. After all, it was not clear to the data subjects that the restaurant intended to use the e-mail address for advertising purposes. The restaurant operator also failed to inform the data subjects of their right to withdrawal.

Industry: Accomodation and Hospitality

How it connects

C-252/21 Meta Platforms v noyb C-252/21 (Meta Platforms (noyb)) CJEU Jan 12, 2023 Supervisory Authorities IP Address Supervision
HvJ EU 9 januari 2025, C‑394/23 (Mousse) Artikelen: 5(1)(c), 6(1), en 21 AVG Onderwerp : Beginsel van minimale gegevensverwerking Gek genoeg verwijst het HvJ EU zelf niet naar HvJ EU 1 augustus 2022, C‑184/20… HvJ EU 9 januari 2025, C‑394/23 (Mousse). ·CJEU Jan 9, 2025 IP Address Retention Period Identification
Guidelines 05/2020 consent under Regulation 2016/679 Guidelines on consent Guidelines ·EDPB May 4, 2020 Consent Data Portability Personal Data
C-154/21 RW v Österreichische Post AG The Court of Justice of the European Union (First Chamber), in response to a preliminary reference from the Oberster Gerichtshof (Austrian Supreme Court), interpreted Article… CJEU ·First Chamber Jan 12, 2023 Right of Access Personal Data Recipient
C-654/23 Inteligo Media SA v Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) Het Hof van Justitie van de EU (Eerste Kamer) beantwoordt een prejudiciële vraag over de uitleg van artikel 13 van Richtlijn 2002/58/EC (ePrivacy) en de verhouding tot de GDPR,… CJEU Mar 27, 2025 Telecommunications Personal Data Marketing
C-129/21 Proximus NV v Gegevensbeschermingsautoriteit In a preliminary ruling requested by the Brussels Court of Appeal, the Court of Justice of the European Union addressed the interpretation of Article 12 of Directive 2002/58/EC… CJEU ·Fourth Chamber Oct 27, 2022 Telecommunications Right to be Forgotten Personal Data