Merchant
- Country
- Belgium
- Fine
- 10,000 EUR
- Date
- 2019-09-17
- Sector
- Business Sector
- Articles
- Art. 5 (1) c) GDPRArt. 6 GDPRArt. 12 and 13 GDPR
Violation of proportionalitypprinciple, no legal basis, and violation of transparency obligations
The Litigation Chamber of the Belgian Data Protection Authority imposed a fine of 10,000 euros on a merchant who used the national Belgian electronic identity card (eID) to create customer loyalty cards. The chamber ruled that the data on the card was used unlawfully. Moreover, it noted that the eID card was the only way for customers to obtain a loyalty card, so that no free and valid consent was given. Customers were not also informed in detail about the conditions of data processing. Authority: Belgian Data Protection Authority (GBA-APD)
