Foodinho Srl

€5,000,000

Non-compliance with general data processing principles

Lēmuma datums

2024. gada 13. novembris

Iestāde

Italian Data Protection Authority (Garante)

IT

Nozare

Employment

Valsts

IT

Likums

GDPR

Statuss

FINAL

Apraksts

The Italian DPA has fined the food delivery service Foodinho Srl EUR 5 million for unlawfully processing the data of approximately 35,000 drivers and for several violations of the GDPR. The DPA's investigation revealed that the company collected drivers' location data without their knowledge or consent—not only during working hours but also when the app was running in the background or inactive. Additionally, the DPA found that the company shared driver data with third parties without a valid legal basis. The investigation also uncovered that automated data processing was used for functions such as the evaluation system and task allocation during shifts, but the company had failed to implement necessary GDPR measures, such as allowing human intervention or enabling drivers to contest decisions made through the automated systems. Furthermore, biometric data, including facial recognition, was used without a valid legal basis. The investigation also revealed that drivers whose accounts were blocked received only standardized messages, with no information provided about their rights to appeal.

Juridiskās atsauces

Art. 5 (1)Art. 6Art. 9 (2)Art. 12Art. 13Art. 22 (3)Art. 25Art. 28Art. 32Art. 35Art. 88Art. 2Art. 114Art. 47

Jautājumi un pārkāpumi

Non-compliance with general data processing principles

Atjauniniet informāciju par konfidencialitātes ieviešanu

Mēs respektējam jūsu konfidencialitāti. Viens e-pasts mēnesī, bez surogātpasta, jebkurā laikā varat atteikties no abonēšanas.