Persónuvernd (Iceland) · 27 October 2020
Not named in the source
About: Data principles, Unlawful processing
FineNo fineViolation found
- Regulator
- Persónuvernd (Iceland)
- Decided
- 27 October 2020
- Country
- Iceland
- Sector
- Not given
- Regulator’s reference
- 2020010673
- Fino case number
- 2020/IS/024
What happened
The Icelandic DPA (Persónuvernd) held that a controller breached the GDPR by not conducting a legitimate interest assessment and by not substantiating how its interest outweighed those of the data subject in the context of direct marketing communications.
Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1)(a) · 5(1)(b) · 5(1)(c) · 5(1)(e)Read →
- Art. 6Lawfulness of processing6(1)(f)Read →
- Data principles
- Unlawful processing
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2020/IS/024.