DPC (Ireland) · 16 December 2020
Groupon International Limited
About: Data principles, Data subject rights, Transparency, Unlawful processing
- Regulator
- DPC (Ireland)
- Decided
- 16 December 2020
- Country
- Ireland
- Sector
- Not given
- Regulator’s reference
- C-XX-X-XX Groupon International Limited - December 2020
- Fino case number
- 2020/IE/010
What happened
The Irish DPA found that Groupon infringed the principle of data minimisation (Article 5(1)(c) GDPR) by requiring the complainant to verify their identity by submitting a copy of a national ID document when a less data-driven solution to the question of identity verification was available. The DPC also found that Groupon infringed Articles 12(2),17(1)(a) and 6(1) GDPR.
Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1)(c)Read →
- Art. 6Lawfulness of processing6(1)Read →
- Art. 12Transparent information, communication and modalities for the exercise of the rights of the data subject12(2) · 12(6)Read →
- Art. 17Right to erasure (‘right to be forgotten’)17(1)Read →
- Art. 60Cooperation between the lead supervisory authority and the other supervisory authorities concerned60(2) · 60(3) · 60(4)Read →
- Data principles
- Data subject rights
- Transparency
- Unlawful processing
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2020/IE/010.