Merchant

€10,000

Non-compliance with general data processing principles

決定日期

2019年9月17日

權限

Belgian Data Protection Authority (APD)

BE

部門

Industry and Commerce

國家

BE

法律

GDPR

狀態

FINAL

說明

The Belgian data protection authority has imposed a fine of 10,000 euros on a merchant who wanted to use an electronic identity card (eID) to create a customer card. The DPA's investigation revealed that the merchant required access to personal data located on the eID, including the photo and barcode which is linked to the data subject's identification number. In the meantime, the decision of the data protection authority has been annulled by a court: link

法律引文

Art. 5 (1)

問題與違規

Non-compliance with general data processing principles

保持最新的隱私權執法資訊

我們尊重您的隱私。每月一封電子郵件,無垃圾郵件,可隨時取消訂閱。