Tietosuojavaltuutetun toimisto (Finland) · 30 May 2023
Kesko Oyj
About: Accountability, Data principles, Special categories, Transparency
FineNo fineViolation found
- Regulator
- Tietosuojavaltuutetun toimisto (Finland)
- Decided
- 30 May 2023
- Country
- Finland
- Sector
- Not given
- Regulator’s reference
- 3831/161/21
- Fino case number
- 2023/FI/013
What happened
The Finnish DPA found a retail chain to have breached Article 5(1)(e) GDPR, Article 25(1) GDPR and Article 25(2) GDPR for its lengthy storage of purchase behaviour data in connection with its loyalty program.
Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1)(e)Read →
- Art. 9Processing of special categories of personal dataRead →
- Art. 13Information to be provided where personal data are collected from the data subject13(2)(a)Read →
- Art. 25Data protection by design and by default25(1) · 25(2)Read →
- Art. 58Powers58(2)(b) · 58(2)(d)Read →
- Art. 83General conditions for imposing administrative finesRead →
- Accountability
- Data principles
- Special categories
- Transparency
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2023/FI/013.