Infobel – Court Ruling (Belgium, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Belgian authorities found that Infobel, a data broker, processed and sold personal data for marketing without proper consent. This case is significant because it shows that companies must have clear permission to use personal data, especially for selling it. It serves as a reminder for businesses to ensure they have valid legal bases for their data practices.
What happened
Infobel processed and resold personal data obtained from a telecom operator without demonstrating valid consent.
Who was affected
Individuals whose personal data was used and resold by Infobel for marketing purposes.
What the authority found
The authority ruled that Infobel did not obtain valid consent for processing personal data, violating GDPR requirements.
Why this matters
This case highlights the importance of obtaining explicit consent for data processing activities. Companies should review their consent practices to avoid similar issues.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
The Belgian DPA had imposed a €40,000 fine on INFOBEL S.A., a commercial data broker (the controller), for processing and reselling personal data for direct marketing purposes without demonstrating a valid legal basis. The data at issue had been obtained from a telecom operator with which the data subject had took a telephone subscription in the past and were subsequently used and resold by the controller for direct marketing purposes. The DPA found that the controller had not demonstrated that the data subject had given freely given, specific, informed and unambiguous consent to the processing of his data for their resale for direct marketing purposes. Specifically, it held that the consent was not freely given, since the resale of personal data was not directly and objectively linked to the performance of the contract that concerned the provision of telephone services. The DPA also found that no separate opt-in had been offered for the specific purpose of reselling the data for direct marketing purposes, that the data subject had not been adequately informed as the controller’s identity was not mentioned anywhere in telecom operator’s general terms and conditions and that the consent was based on an opt-out rather than a clear affirmative act. The DPA had accordingly determined that the controller infringed article 5(1)(a) GDPR in conjunction with Article 6 GDPR and Article 24 GDPR. It had also ordered the controller to delete the personal data processed without a valid legal basis and to inform the recipients of those data of the decision and of the lack of a legal basis for the processing. The controller appealed the decision and challenged the fine before the Brussels Court of Appeal. It argued, inter alia, that the erasure order and the related obligation to inform recipients had become devoid of purpose because the relevant database had already been deleted in 2023. The DPA maintained that the erasure order was still justified because it had not been able to
Outcome
Court Ruling
A ruling by a national court on a data-protection matter.
Related Cases (1)
Other cases involving Infobel in BE
Details
About this data
Cite as: Cookie Fines. Infobel - Belgium (2026). Retrieved from cookiefines.eu
Last updated: