Unknown – €50,000 Fine (Belgium, 2020)

€50,000Autorité de Protection des Données23 December 2020Belgium
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

A company in Belgium was fined EUR 50,000 for not providing a proper privacy policy and mishandling user data requests. The company failed to inform a user about data processing related to a parking fine, violating GDPR rules. This case stresses the need for clear privacy policies and timely responses to data requests.

What happened

A company failed to provide a proper privacy policy and mishandled a user's data request related to a parking fine.

Who was affected

Individuals who received parking fines and had their data processed by the company.

What the authority found

The authority found the company violated GDPR by not having a clear privacy policy and not fulfilling data requests properly.

Why this matters

This ruling highlights the importance of transparency in data processing and the need for companies to have clear privacy policies. It serves as a warning to businesses to comply with GDPR requirements.

GDPR Articles Cited

Art. 5(1)(c) GDPR
Art. 12(1) GDPR
Art. 14(1) GDPR
Art. 15(1) GDPR
Art. 24(1) GDPR
Full Legal Summary
Detailed

The Belgian DPA (APD) imposed a fine of EUR 50,000 on a company for several violations of the GDPR. The controller is a company that carries out parking ticket controls. The controller controller had issued the data subject a fine for illegal parking. However, the data subject states that he or she did not receive the fine ticket. Instead, the data subject only found out about it when he or she received an official reminder letter from a law firm commissioned with debt collection, which then demanded payment of the reminder fee in addition to the original fine. The data subject then contacted the company and demanded, among others, information about which of his/her personal data had been processed. After this request was not properly fulfilled in a timely manner, the data subject filed a complaint against the controller During its investigations the DPA discovered that the controller violated several GDPR provisions. Firstly the DPA found that the controller failed to provide a proper privacy policy. The privacy policy on the controller´s website did not contain any information regarding the processing of personal data nor any contact information of the company. Secondly, the controller violated the data subject's right to information by failing to comply with the data subject's request for information on data processing. Lastly the controller infringed the principle of minimasation by processing the data subject's data for the purpose of sending a payment reminder only one day after the ticket had been issued even though the data subject had the opportunity to pay the fine without such a reminder at that time.

Details

Fine Date

23 December 2020

Authority

Autorité de Protection des Données

Fine Amount

€50,000

Enforcement Tracker ID

ETid-499

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Unknown - Belgium (2020). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: