Fino

Persónuvernd (Iceland) · 4 October 2021

Creditinfo

About: Data principles, Unlawful processing

FineNo fineViolation found
Regulator
Persónuvernd (Iceland)
Decided
4 October 2021
Country
Iceland
Sector
Not given
Regulator’s reference
no. 2020020909
Fino case number
2021/IS/027
Export as PDF

What happened

The Icelandic DPA ruled that a credit scoring company had violated the GDPR by assigning a credit score to an individual on the basis of information that was more than 4 years old. The Icelandic DPA therefore ordered the controller to delete the personal data in question.

Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Data principles
  • Unlawful processing

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2021/IS/027.