GDPR - Scam via fraudulent fax

- Since the GDPR, there has been an increase in fraudulent faxes from the "Datenschutzauskunft-Zentrale".
- These faxes request data updates and paid orders.
- Scammers are exploiting uncertainty surrounding the GDPR and the fear of fines.
- Dubious warning letters and fake data protection consultants are on the rise.
- If you receive a warning letter, consult a lawyer or a certified data protection consultant.
Since the GDPR came into effect, there has been widespread uncertainty regarding data protection. Some people are exploiting this to run scams and commit fraud based on the GDPR. However, with a little background knowledge, it is not difficult to spot fraudulent data protection schemes. Whether it is a fax, an email, or a "fake" data protection officer – we will show you what to look out for.
Warning regarding the "Datenschutzauskunft-Zentrale"
Since the beginning of October, a fax from a so-called "Datenschutzauskunft-Zentrale" (Data Protection Information Center) has been circulating. The sender wants to pressure you into fulfilling your "data protection obligation to comply with the requirements set out by data protection laws." To do this, you are asked to complete your details and send the document back to the provided fax number.
The fax looks like this:
Fraudulent fax from the "Datenschutzauskunft-Zentrale"
You should under no circumstances respond to this fax. This is not an official document from an authority, but rather a subscription trap and therefore an attempt to scam you using the GDPR. By signing this document, you are confirming a paid order for a "Basic Data Protection Service Package." The confusing fine print in the so-called "Service Overview" reveals what this is really about: the senders demand an annual payment of 498 euros plus VAT with a minimum contract term of three years. In reality, you receive no services relevant to data protection. This fax is a pure GDPR scam.
GDPR – Scams and fraud based on the new, complex legal situation
Since the General Data Protection Regulation (GDPR) came into effect in May 2018, misinformation regarding the new legal situation has circulated frequently due to the abstract nature of the regulations. Aside from the GDPR scam in the form of the fax described above, there were also fears of a "wave of warning letters" that would hit many companies. Many fraudsters are now exploiting these very uncertainties and, above all, the fear of fines. As a result, there have been more frequent cases of fraud aimed at obtaining personal data such as bank account information.
Another problem is that the position of data protection officer is unfortunately not currently a protected professional title. Theoretically, anyone can claim to be a data protection officer, which paves the way for GDPR fraud. Furthermore, shortly after the GDPR came into effect, some companies received isolated warning letters from dubious law firms. These letters demanded payment of a sum of money, claiming that the company had violated certain data protection laws.
Although the feared "wave of warning letters" did not materialize, there are always new tricks for committing GDPR fraud. It is therefore always advisable not to sign warning letters blindly and not to disclose personal data immediately. Instead, you should carefully question whether it is a GDPR scam or a legitimate inquiry. Furthermore, you should not blindly trust advice found on the internet.
Dubious warning letters – don't fall for a GDPR scam
A dubious data protection warning letter usually arrives unexpectedly and often demands payment for an alleged "violation of the GDPR." The supposed legal violation is justified by the claim that the recipient "never consented to the use of personal data." Furthermore, the letters include bank details to which compensation should be transferred. With this GDPR scam, the fraudsters are trying to get their hands on your money quickly.
Compared to large corporations, small and medium-sized businesses have so far been the primary targets for warning letters from dubious law firms or alleged authorities. Due to isolated attempts at fraudulent warnings, the Ministry of Justice is currently drafting legislation against the abuse of warning letters. It was already agreed in the coalition agreement to curb this type of GDPR fraud.
Avoiding dubious data protection consultants and GDPR fraud
A certified and therefore reputable data protection expert works closely with data protection supervisory authorities and can provide proof of this. They also hold certification—for example, from TÜV or DEKRA—confirming that they are a certified and fully trained data protection officer.
If you suspect a data protection provider is disreputable, it is worth asking for proof of their qualifications. You should also ask for the specific legal basis in the GDPR that they are citing. Furthermore, if advice is phrased in an overly complicated way, you should question the credibility of the data protection officer.
If you are uncertain or suspect a GDPR scam, it is always advisable to seek the opinion of a demonstrably certified data protection consultant.
What should you do if you have received a warning letter or a payment demand?
With any warning letter, it is advisable to seek the advice of a lawyer specializing in data protection. Alternatively, you can of course contact your internal or external data protection officer at any time, if you have one. If you have already signed and returned the GDPR scam fax or warning letter described above, the Thuringian State Commissioner for Data Protection and Freedom of Information (TLfDI) recommends revoking the statement immediately and under no circumstances paying the amount. In addition, you should contact a certified data protection officer or the police.
If you have any further questions about GDPR scams, we are always happy to help.
Do you have further questions on this topic? Our experts will be happy to advise you free of charge.













