Icelandic data protection authority ('Persónuvernd') · 27 June 2023
eCommerce 2020 ApS
Insufficient legal basis for data processing
- Regulator
- Icelandic data protection authority ('Persónuvernd')
- Decided
- 27 June 2023
- Country
- Iceland
- Sector
- Finance, Insurance and Consulting
- Regulator’s reference
- Not recorded
- Fino case number
- 2023/IS/008
What happened
The Icelandic DPA held that a company offering so-called "small loans" (eCommerce 2020) breached Article 5(1)(a) GDPR by sending information on non-payments to be registered at a credit scoring company where its loan terms did not include a provision on such data sharing. The company was fined ISK 7,500,000 (approx. € 51,000).
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Unlawful processing
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2023/IS/008.