Merchant

€10,000

Non-compliance with general data processing principles

Data della decisione

17 settembre 2019

Autorità

Belgian Data Protection Authority (APD)

BE

Settore

Industry and Commerce

Paese

BE

Legge

GDPR

Stato

FINAL

Descrizione

The Belgian data protection authority has imposed a fine of 10,000 euros on a merchant who wanted to use an electronic identity card (eID) to create a customer card. The DPA's investigation revealed that the merchant required access to personal data located on the eID, including the photo and barcode which is linked to the data subject's identification number. In the meantime, the decision of the data protection authority has been annulled by a court: link

Citazioni legali

Art. 5 (1)

Problemi e violazioni

Non-compliance with general data processing principles

Rimanete aggiornati sull'applicazione della privacy

Rispettiamo la vostra privacy. Un'email al mese, niente spam, cancellazione in qualsiasi momento.