YAY ehf. – €27,200 Fine (Iceland, 2021)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
YAY ehf. was fined for its role in a travel voucher app that mishandled user data. The app collected more data than necessary and lacked proper security measures. This case emphasizes the importance of data minimization and security in app development.
What happened
YAY ehf.'s app collected more user data than needed and lacked proper data security measures.
Who was affected
Users of the YAY app who provided personal information for the travel voucher promotion.
What the authority found
The Icelandic DPA found YAY ehf. violated data protection rules by processing excessive data and failing to secure it properly.
Why this matters
This case serves as a reminder for app developers to implement strong data security measures and ensure data collection is limited to what's necessary. Companies should regularly audit their data practices to comply with data protection laws.
GDPR Articles Cited
The Icelandic Data Protection Authority has imposed a fine of EUR 51,000 on the Ministry of Industry and Innovation and a fine of EUR 27,200 on YAY ehf. The fine is related to a campaign by the ministry to encourage Icelanders to travel domestically in the summer of 2020. This involved a digital gift voucher that could be obtained through the app of the company YAY ehf. The DPA received a number of complaints regarding the fact that the use of the travel gift required extensive personal information and access to users' phones. As a result, the DPA launched investigations against the ministry and the company. The DPA found that the ministry had violated the principle of legality and transparency. Participating individuals were only required to agree to the General Terms of Use of the YAY app in order to participate in the voucher promotion. However, the DPA found that by doing so, the data subjects had not expressly consented to the processing of their personal data carried out as part of the promotion. The DPA also found that the information provided about the actual processing of personal data was insufficient. Moreover, neither the ministry nor YAY ehf. had implemented appropriate technical and organizational measures to ensure the security of the processing of personal data. Also, due to a configuration error on the part of YAY, more data than necessary was processed, which is why the DPA found a violation of the principle of data minimization.
Related Enforcement Actions (0)
No other enforcement actions found for YAY ehf. in IS
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
23 November 2021
Authority
Persónuvernd
Fine Amount
€27,200
Enforcement Tracker ID
ETid-917
About this data
Cite as: Cookie Fines. YAY ehf. - Iceland (2021). Retrieved from cookiefines.eu
Last updated: