GDPR Fines

A public record of GDPR enforcement across Europe — compiled by INPLP members

Merchant

Country
Belgium
Fine
10,000 EUR
Date
2019-09-17
Sector
Business Sector
Articles
Art. 5 (1) c) GDPRArt. 6 GDPRArt. 12 and 13 GDPR

Violation of proportionalitypprinciple, no legal basis, and violation of transparency obligations

The Litigation Chamber of the Belgian Data Protection Authority imposed a fine of 10,000 euros on a merchant who used the national Belgian electronic identity card (eID) to create customer loyalty cards. The chamber ruled that the data on the card was used unlawfully. Moreover, it noted that the eID card was the only way for customers to obtain a loyalty card, so that no free and valid consent was given. Customers were not also informed in detail about the conditions of data processing. Authority: Belgian Data Protection Authority (GBA-APD)