Search
Contact
15.04.2021 | KPMG Law Insights

Data protection – fine of 475,000 euros for late notification of a data protection incident

Fine of 475,000 euros for late notification of a data protection incident

The Dutch data protection authority (Autoriteit Persoonsgegevens – AP) has imposed a fine of 475,000 euros on the accommodation and travel agency platform booking.com for failing to report a data protection incident in good time.

Already in 2019, hackers had managed to access the data of 4109 customers of booking.com(https://edpb.europa.eu/news/national-news/2021/dutch-dpa-fines-bookingcom-delay-reporting-data-breach_en). The data included names, addresses, telephone numbers and details of hotel bookings, as well as credit card information for 283 data subjects, including security numbers in 97 cases. The hackers gained access to the data through employee accounts at several hotels in the United Arab Emirates, presumably through “socialengineering” techniques or phishing. In addition, the hackers attempted to gain access to additional credit card data by contacting guests of the hotels via email or phone. This posed a high security risk even for those booking.com customers whose credit card data was not affected.

booking.com did not consider itself responsible for the data protection incident, as the data had not been accessed via its own IT infrastructure. The AP, on the other hand, saw evidence of shared responsibility on the part of the operator. However, the fine was issued regardless of this issue solely based on the fact that booking.com had reported the data protection incident to the affected customers only after 22 days and to the supervisory authority only after 25 days. A data breach of this magnitude should have been reported to the data protection authority pursuant to Art.33 Para.1 GDPR must be reported to booking.com at the latest within 72 hours of becoming aware of it.

The fine can still be appealed. However, booking.com has already had it stated that it will accept the fine. The booking.com database had not been compromised at any point, but the company said it was working to improve its internal processes.

What is remarkable about this fine decision is that the actual incident was not sanctioned. Rather, only the late reporting was penalized. This proves that the supervisory authorities do not only examine and sanction measures to prevent data protection incidents. Delayed reporting of incidents to the supervisory authorities and/or the data subjects also constitutes a violation in its own right and one that is subject to sanctions.

Responsible parties are therefore well advised to review their internal processes for reporting data protection incidents and ensure that any required notification can be made in a timely manner. In particular, it must be taken into account that the 72-hour period is a maximum period and – at least according to the German supervisory authorities – also runs on weekends or public holidays. Against the background of the fact-finding usually required in the company, appropriate organizational precautions must be taken for this purpose.

Explore #more

19.08.2026 | In the media

KPMG Law Interview in HAUFE: Even If AI Makes a Mistake, the Board of Directors Is Still Liable

AI analyzes, makes recommendations, and helps make decisions. But who bears the consequences if it makes a mistake? KPMG Law experts Vincent Manthey and Sabrina

19.08.2026 | In the media

KPMG Law Article in Bloomberg Tax: Germany’s Tax Crime Action Plan Pushes the Boundaries of the Constitution

The new 26-point action plan against tax and financial crime, issued by Germany’s finance and justice ministries, signals a shift toward tougher sanctions, closer interagency…

13.08.2026 | KPMG Law Insights

Federal Ministry of Finance Presents Draft Bill on Mandatory Use of Electronic Cash Registers and Combating Tax Evasion

In July 2026, the Federal Ministry of Finance (BMF) and the Federal Ministry of Justice (BMJV) presented an action plan to combat tax and financial

11.08.2026 | In the media

Guest article in *Versicherungsmonitor* on the topic of cyber claims regulation

Cyberattacks—particularly ransomware campaigns—pose challenges for insurers when it comes to claims settlement. When entire IT infrastructures at insured companies come to a standstill and the…

11.08.2026 | KPMG Law Insights

Transparency Requirements Under Article 50 of the AI Act: Companies Should Address These Questions Now

The transparency requirements of the EU AI Act have been in effect since August 2, 2026. These obligations apply to chatbots, AI assistants, avatars, synthetic…

10.08.2026 | In the media

Op-Ed on the Procurement Acceleration Act and Sustainable Public Procurement

On April 23, 2026, the Bundestag passed the Act on Accelerating the Award of Public Contracts. After the Act was published in the Federal Law…

05.08.2026 | Deal Notifications

KPMG Law and KPMG Advise NMP Germany on the Acquisition of Klöckner Desma Elastomertechnik GmbH

KPMG Law Rechtsanwaltsgesellschaft mbH (KPMG Law) and KPMG AG Wirtschaftsprüfungsgesellschaft (KPMG) advised NMP Germany GmbH on the legal, tax, and financial aspects of the transaction…

04.08.2026 | In the media

Portrait of Mathias Oberndörfer in the *Börsen-Zeitung*

Mathias Oberndörfer has been with KPMG for more than 20 years—reason enough for an in-depth profile in the *Börsen-Zeitung*. The Börsen-Zeitung traces his career path…

03.08.2026 | Unkategorisiert

KPMG Law und KPMG beraten NMP Germany beim Erwerb der Klöckner Desma Elastomertechnik GmbH

Die KPMG Law Rechtsanwaltsgesellschaft mbH (KPMG Law) und die KPMG AG Wirtschaftsprüfungsgesellschaft (KPMG) haben die NMP Germany GmbH beim Erwerb der Klöckner Desma Elastomertechnik Gruppe…

03.08.2026 | In the media

Statement by KPMG Law experts on the EU Packaging Regulation in the business magazine *impulse*

Starting January 1, 2030, packaging must consist of at least 70 percent recyclable materials. Starting August 1, 2030, so-called “deceptive packaging” will also be banned.…

Contact

Sebastian Hoegl, LL.M. (Wellington)

Senior Manager
Lawyer
Specialist lawyer for IT law
LL.M. (Wellington)

Heinrich-von-Stephan-Straße 23
79100 Freiburg im Breisgau

Tel.: +49 761 769999-20
shoegl@kpmg-law.com

© 2026 KPMG Law Rechtsanwaltsgesellschaft mbH, associated with KPMG AG Wirtschaftsprüfungsgesellschaft, a public limited company under German law and a member of the global KPMG organisation of independent member firms affiliated with KPMG International Limited, a Private English Company Limited by Guarantee. All rights reserved. For more details on the structure of KPMG’s global organisation, please visit https://home.kpmg/governance.

KPMG International does not provide services to clients. No member firm is authorised to bind or contract KPMG International or any other member firm to any third party, just as KPMG International is not authorised to bind or contract any other member firm.

Scroll