Bürgerforum Schweiz – €3,975 Fine (Switzerland, 2024)

€3,975DPA EDBPFPDTIFPDT9 April 2024Switzerland
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Bürgerforum Schweiz, a civil association (the controller) launched a campaign called “Pfarrer-Check” on its website to publicly question church personnel (the data subjects) about their personal faith. A questionnaire was used to assess the theological views of these data subjects and published information about them in an online database. Data subjects received the questionnaire from the controller or third parties. The controller provided an online database contained data on about 6,000 data subjects. The database, accessible to anyone, contained personal details such as names, organizations, functions, postal codes, and response status. Specifically, each listed data subject was assigned a status: “recorded” (publicly known but not yet contacted), “requested” (contacted but no response or consent), or “answered” (responded and explicitly consented to publication). Nevertheless, thousands of names and response statuses without prior consent were included. There was no requirement in the questionnaire or on the website that third parties asked for consent before sharing personal data of the data subjects with the controller. Likewise, data subjects that received the questionnaire were not asked whether they agree to have their data or response status. The controller’s website hosted a general privacy policy that applies to all activities, not just Pfarrer-Check. The policy distinguished between public and non-public personal data, stating that public data could be used freely, while non-public data required explicit authorization. It granted a limited right to object, applying only to data subjects whose data were not publicly visible online. If the data subjects, whose addresses were publicly available, submitted a request to the controller to be deleted from the database, this request would not be granted. Based on inquiries from the controller as well as various reports from data subjects, the EDÖB, the Swiss DPA, was made aware of the launched campaign of the

National Law Articles

Article 30 DSG
Article 31
Article 6 DSG
Full Legal Summary

Bürgerforum Schweiz, a civil association (the controller) launched a campaign called “Pfarrer-Check” on its website to publicly question church personnel (the data subjects) about their personal faith. A questionnaire was used to assess the theological views of these data subjects and published information about them in an online database. Data subjects received the questionnaire from the controller or third parties. The controller provided an online database contained data on about 6,000 data subjects. The database, accessible to anyone, contained personal details such as names, organizations, functions, postal codes, and response status. Specifically, each listed data subject was assigned a status: “recorded” (publicly known but not yet contacted), “requested” (contacted but no response or consent), or “answered” (responded and explicitly consented to publication). Nevertheless, thousands of names and response statuses without prior consent were included. There was no requirement in the questionnaire or on the website that third parties asked for consent before sharing personal data of the data subjects with the controller. Likewise, data subjects that received the questionnaire were not asked whether they agree to have their data or response status. The controller’s website hosted a general privacy policy that applies to all activities, not just Pfarrer-Check. The policy distinguished between public and non-public personal data, stating that public data could be used freely, while non-public data required explicit authorization. It granted a limited right to object, applying only to data subjects whose data were not publicly visible online. If the data subjects, whose addresses were publicly available, submitted a request to the controller to be deleted from the database, this request would not be granted. Based on inquiries from the controller as well as various reports from data subjects, the EDÖB, the Swiss DPA, was made aware of the launched campaign of the

Related Enforcement Actions (0)

No other enforcement actions found for Bürgerforum Schweiz in CH

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

9 April 2024

Authority

DPA EDBPFPDTIFPDT

Fine Amount

€3,975

3,750 CHF

GDPRhub ID

gdprhub-9600

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Bürgerforum Schweiz - Switzerland (2024). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: