Infobel – Court Ruling (Belgium, 2026)

Court Ruling
Autorité de Protection des Données3 June 2026Belgium
final
Court Ruling

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Belgian authorities found that Infobel, a data broker, processed and sold personal data for marketing without proper consent. This case is significant because it shows that companies must have clear permission to use personal data, especially for selling it. It serves as a reminder for businesses to ensure they have valid legal bases for their data practices.

What happened

Infobel processed and resold personal data obtained from a telecom operator without demonstrating valid consent.

Who was affected

Individuals whose personal data was used and resold by Infobel for marketing purposes.

What the authority found

The authority ruled that Infobel did not obtain valid consent for processing personal data, violating GDPR requirements.

Why this matters

This case highlights the importance of obtaining explicit consent for data processing activities. Companies should review their consent practices to avoid similar issues.

GDPR Articles Cited

AI-verified

Art. 24(GDPR)
Art. 5(1)(a) GDPR
Art. 6(1) GDPR
View original scraped data
Art. 5(1)(a) GDPR
Art. 6(1) GDPR
Art. 24(GDPR)

Original data from scraper before AI verification against source document.

Decision AuthorityBrussels Court of Appeal
Reviewed AuthorityAPD
Source verified 23 June 2026
amount discrepancy
authority corrected
Full Legal Summary
Detailed

The Belgian DPA had imposed a €40,000 fine on INFOBEL S.A., a commercial data broker (the controller), for processing and reselling personal data for direct marketing purposes without demonstrating a valid legal basis. The data at issue had been obtained from a telecom operator with which the data subject had took a telephone subscription in the past and were subsequently used and resold by the controller for direct marketing purposes. The DPA found that the controller had not demonstrated that the data subject had given freely given, specific, informed and unambiguous consent to the processing of his data for their resale for direct marketing purposes. Specifically, it held that the consent was not freely given, since the resale of personal data was not directly and objectively linked to the performance of the contract that concerned the provision of telephone services. The DPA also found that no separate opt-in had been offered for the specific purpose of reselling the data for direct marketing purposes, that the data subject had not been adequately informed as the controller’s identity was not mentioned anywhere in telecom operator’s general terms and conditions and that the consent was based on an opt-out rather than a clear affirmative act. The DPA had accordingly determined that the controller infringed article 5(1)(a) GDPR in conjunction with Article 6 GDPR and Article 24 GDPR. It had also ordered the controller to delete the personal data processed without a valid legal basis and to inform the recipients of those data of the decision and of the lack of a legal basis for the processing. The controller appealed the decision and challenged the fine before the Brussels Court of Appeal. It argued, inter alia, that the erasure order and the related obligation to inform recipients had become devoid of purpose because the relevant database had already been deleted in 2023. The DPA maintained that the erasure order was still justified because it had not been able to

Outcome

Court Ruling

A ruling by a national court on a data-protection matter.

Details

Ruling Date

3 June 2026

Authority

Autorité de Protection des Données

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Infobel - Belgium (2026). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: