Debt collector

€1,560

Non-compliance with general data processing principles

決定日期

2019年2月20日

權限

Hungarian National Authority for Data Protection and the Freedom of Information (NAIH)

HU

部門

Finance, Insurance and Consulting

國家

HU

法律

GDPR

狀態

FINAL

說明

A data subject requested information about and erasure of the data processed, which the debt collector refused stating that it could not identify the subject. For identification purposes he requested place of birth, mother’s maiden name and further details from the data subject. After the controller succeeded to identify the data subjects he refused to comply with the deletion request, arguing he is legally obliged to retain backup copies according to the Accountancy Act and internal policies. Since he did not properly inform about these policies, the NAIH held the controller breached the principle of transparency. The fine constitutes 0.0025% of the annual profit of the controller.

法律引文

Art. 5 (1)Art. 5 (1)

問題與違規

Non-compliance with general data processing principles

保持最新的隱私權執法資訊

我們尊重您的隱私。每月一封電子郵件,無垃圾郵件,可隨時取消訂閱。