Fino

Persónuvernd (Iceland) · 23 November 2021

Ministry of Industries and Innovation

About: Accountability, Consent, Data principles, Data security, Processor obligations, Transparency, Unlawful processing

FineISK11,500,000≈ €77,900Violation found
Regulator
Persónuvernd (Iceland)
Decided
23 November 2021
Country
Iceland
Sector
Not given
Regulator’s reference
2020092288
Fino case number
2021/IS/031
Export as PDF

What happened

The Icelandic DPA found that the Ministry of Industries and Innovation and the company YAY contravened the GDPR by collecting personal data without a legal basis and processing it without consent, violated the principle of data minimisation, and failed to comply with its information obligations by processing the personal data of the users of a gift card application, and imposed administrative fines of approximately €50,800 (7,500,000 ISK) and €27,100 (4,000,000 ISK) respectively.

Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Accountability
  • Consent
  • Data principles
  • Data security
  • Processor obligations
  • Transparency
  • Unlawful processing

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2021/IS/031.