PogoWasRight.org

Menu
  • About
  • Privacy
Menu

Lidl fined for data protection violations

Posted on August 31, 2009July 3, 2025 by Dissent

The Privacy and Information Security Law Blog reports that earlier this month,

the state DPA in North Rhine-Westphalia fined a subsidiary of the discount supermarket chain Lidl € 36,000 (approximately $51,000) for illegally keeping records of employee health data.

To compound the employee privacy breach with a security breach, it seems that the case was triggered by a report in the German news magazine Der Spiegel after someone found papers and forms containing Lidl employees’ health data in a trash bin at a car wash.

Subsequent investigations revealed that at least four Lidl branches in North Rhine-Westphalia were using a form to record data about employees’ medical conditions, partly without their knowledge. This activity was found to violate data protection law in many cases.

No related posts.

Category: BreachesBusinessNon-U.S.SurveillanceWorkplace

Post navigation

← Gmail may hand over IP addresses of journalists
3rd International conference on IPRs, Personal Data Protection and National Security →

Now more than ever

Search

Contact Me

Email: info@pogowasright.org

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

Categories

Recent Posts

  • Attorney General James Takes Action to Protect Sensitive Personal Information of Tens of Millions of People
  • Searches of Your Private Data in the Cloud Amount to Illicit State Action
  • How a Tax Subpoena in Ohio Tests European Privacy Law
  • Cambodia moves to enact comprehensive data privacy law
  • White House ordered to restore Medicaid funding to Planned Parenthood clinics
  • California Attorney General Announces $1.55M CCPA Settlement with Healthline.com
  • Canada’s Bill C-2 Opens the Floodgates to U.S. Surveillance

RSS Recent Posts on DataBreaches.net

  • Oops! Catasauqua employees’ Social Security numbers, other data accidentally sent to government watchdog group
  • EU-wide Breach Notification Template on the Horizon
  • Sex toy maker Lovense caught leaking users’ email addresses and exposing accounts to takeovers
  • Hackers wipe out Rs 384 crore from Bengaluru cryptocurrency firm Neblio Technologies; firm says inside job
  • Intelligence cyberattack on Crimea. Documents confirming abduction of children from Ukraine found
©2025 PogoWasRight.org. All rights reserved.
Menu
  • About
  • Privacy