Freedom Finance Europe Ltd – Complaint Upheld (Cyprus, 2023)

Complaint Upheld
DPA Commissioner7 September 2023Cyprus
final
Complaint Upheld

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Freedom Finance Europe Ltd faced a complaint for not responding to a customer's request to delete her personal data. This case is important because it highlights the need for companies to have proper systems in place to handle data requests from users.

What happened

A customer requested the deletion of her data but did not receive a response from Freedom Finance.

Who was affected

The customer who requested her personal data to be deleted.

What the authority found

The Cypriot DPA found that Freedom Finance failed to inform the customer about her deletion request in a timely manner.

Why this matters

This ruling underscores the importance of having clear procedures for handling user data requests. Companies should ensure they have the right systems to respond promptly to such requests to avoid complaints.

GDPR Articles Cited

AI-verified

Art. 17(GDPR)
Art. 12(3) GDPR
Art. 24(1) GDPR
Art. 58(2) GDPR
View original scraped data
Art. 12(3) GDPR
Art. 17(GDPR)
Art. 24(1) GDPR
Art. 58(2) GDPR

Original data from scraper before AI verification against source document.

Source verified 20 March 2026
articles corrected
Full Legal Summary
Detailed

A data subject made a request for the deletion of her data with Freedom Finance Germany TT GmbH, a subsidiary of Freedom Finance Europe Ltd (the controller). Since the data subject never got a reply, she requested again the erasure of her data. Having not received a reply again; the data subject filed a complaint with the German DPA against the controller regarding the non-fulfilment of her right to erasure. However, given that the controller has its main establishment in Cyprus, under Article 60 GDPR, the complaint was transmitted to the Cypriot DPA as the lead supervisory authority in line with Article 56 GDPR. The Cypriot DPA requested the controller its views on the matter and proof that the complainant's personal data had been deleted, which the controller confirmed to have done after it was notified of the complaint. Additionally, the controller explained that it was not aware of the data subject’s erasure request since the data subject contacted the email used for initial customer communication and not the appropriate email address of the DPO. The DPA held that the controller should have informed the data subject, under Article 12(3) GDPR, in a clear and concise manner and without undue delay that her erasure request was satisfied. Moreover, considering that at the time of the data subject's first erasure request, the GDPR had been enforced for more than two years, the controller should have had in place appropriate measures to comply with data subject rights set out in Articles 15 to 22 of the GDPR. Pursuant to Article 24(1) GDPR, the controller should have implemented appropriate technical and organisational measures to ensure that all emails received relating to data subject rights would be acknowledged without further delay. On the basis of the infringements found and considering that the controller satisfied the erasure request after being notified of the complaint, the DPA issued a reprimand to the controller under Article 58(2)(b) GDPR.

Outcome

Complaint Upheld

A data subject complaint that was upheld by the DPA.

Related Enforcement Actions (1)

Other enforcement actions involving Freedom Finance Europe Ltd in CY

Details

Decision Date

7 September 2023

Authority

DPA Commissioner

GDPRhub ID

gdprhub-7551

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Freedom Finance Europe Ltd - Cyprus (2023). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: