Merchant

€10,000

Non-compliance with general data processing principles

Dato for beslutning

17. september 2019

Myndighed

Belgian Data Protection Authority (APD)

BE

Sektor

Industry and Commerce

Land

BE

Lovgivning

GDPR

Status

FINAL

Beskrivelse

The Belgian data protection authority has imposed a fine of 10,000 euros on a merchant who wanted to use an electronic identity card (eID) to create a customer card. The DPA's investigation revealed that the merchant required access to personal data located on the eID, including the photo and barcode which is linked to the data subject's identification number. In the meantime, the decision of the data protection authority has been annulled by a court: link

Juridiske citater

Art. 5 (1)

Problemer og overtrædelser

Non-compliance with general data processing principles

Hold dig opdateret om håndhævelse af privatlivets fred

Vi respekterer dit privatliv. En e-mail om måneden, ingen spam, afmeld når som helst.