Equifax Iberica S.L.

€50,000

Insufficient legal basis for data processing

Decision Date

March 10, 2021

Authority

Spanish Data Protection Authority (aepd)

ES

Sector

Finance, Insurance and Consulting

Country

ES

Law

GDPR

Status

FINAL

Description

The Spanish DPA (AEPD) fined Equifax Iberica S.L. EUR 50,000 for a violation of Art. 6 (1) f) GDPR. The controller had added the data subject to a debtor register without informing her beforehand. The data subject had outstanding payments of rent with her landlord, who had previously sent her corresponding requests for payment. The controller itself had also sent notices to the data subject requesting her to pay the debts. These, however, did not contain any information that the data subject would be entered in the debtors' register in the event of non-payment. Also, the rental contract of the data subject did not contain any provisions in this regard, which led the DPA to conclude that the controller did not have a legitimate interest within the terms of the GDPR and thus had processed the personal data of the data subject without a legal basis.

Legal Citations

Art. 6 (1)

Issues & Violations

Insufficient legal basis for data processing

Stay Updated on Privacy Enforcement

We respect your privacy. One email per month, no spam, unsubscribe anytime.