Etterforsker1 Gruppen AS – €4,350 Fine (Norway, 2022)

€4,350Datatilsynet (Norway)1 February 2022Norway
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Etterforsker1 Gruppen AS was fined EUR 4,350 for conducting a credit check without a legal reason. The company failed to follow GDPR rules about having a valid basis for processing personal data. Businesses should ensure they have a clear legal basis before accessing personal data.

What happened

Etterforsker1 Gruppen AS conducted a credit check on an individual without a valid legal basis.

Who was affected

An individual who was subjected to a credit check by Etterforsker1 Gruppen AS.

What the authority found

The Norwegian DPA found that the company lacked a valid legal basis for the credit check, breaching GDPR's accountability principle.

Why this matters

This ruling highlights the importance of having a legal basis for data processing. Companies should review their data handling practices to ensure compliance with GDPR requirements.

GDPR Articles Cited

Art. 24 GDPR
Art. 5(2) GDPR
Art. 6(1) GDPR
Art. 6(1)(f) GDPR
Art. 24(1) GDPR
Art. 24(2) GDPR
Full Legal Summary
Detailed

The Norwegian DPA (Datatilsynet) received a complaint from a data subject who had been credit rated by a private investigation company, whom had informed in their privacy notice that they should be viewed as the controller as per the GDPR, for any such processing of the personal data of third parties. The controller had been hired by the data subject's former partner. She claimed to have a financial claim against the data subject. He disputed this and also claimed he did not have any funds to pay for such a claim, regardless. Consequently, the controller conducted a credit rating of the data subject, to validate his claims. Following the data subject's complaint, the DPA launched an investigation. The DPA found that the controller lacked a legal basis as per Article 6(1) GDPR, and informs in their decision that the relevant legal basis as per the GDPR, is Article 6(1)(f). The DPA found that the controller had also breached Article 5(2) GDPR, cf. Article 24. For this, the DPA intends to fine the controller NOK 50,000 (€5,000), for conducting a credit rating without a legal basis under Article 6(1) GDPR and for not adhering to the accountability principle as per Article 5(2) GDPR, cf. Article 24. The DPA also requires that the company implement internal controls of their credit rating process. The controller has four weeks to fulfill the penalties, unless they appeal. The controller has three weeks to appeal the decision, otherwise it will take full effect.

Details

Fine Date

1 February 2022

Authority

Datatilsynet (Norway)

Fine Amount

€4,350

50,000 NOK

GDPRhub ID

gdprhub-4617

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Etterforsker1 Gruppen AS - Norway (2022). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: