Infobel – €40,000 Fine (Belgium, 2025)

€40,000Autorité de Protection des Données27 November 2025Belgium
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Infobel (the controller) is a commercial data broker who bought personal data from Z4, a telecom operator, regarding a customer (the data subject). Subsequently, the controller sold the personal data to Z3, a direct marketing company. The data subject received unsolicited direct marketing communications from Z1, a client of the direct marketing company and filed a complaint with the Belgian DPA against the controller and the other companies involved in the case. The current proceedings concern only the controller. The controller claimed that it had a right to access and use Z4’s database in particular for marketing purposes based on contractual agreements. The information referred to in the contracts amounted to the names, phone numbers, and addresses of customers who had a telephone connection with Z4 in Belgium and with 3rd party operators with which Z4 concluded agreements. The exceptions to the right to access and use of the databases were private numbers and the lists of restricted numbers which required the customer to opt-out from the database in order to be added to the restricted numbers list. The controller further specified that the data subject’s personal data (first and last name, street and house number, postal code, city and the creation date and source of the data) were added on 3 May 2006 to their database. The controller claimed that it added the personal data to the database on the basis of the consent of the data subject allegedly given by the data subject to Z4 when taking out a telephone subscription. The data subject denied having given consent for the processing of his personal data by the controller. The controller sold the data subject’s first and last name and address to a third party for a marketing campaign. The controller’s DPO stated that the database had not been used by the controller since 2023. The controller states that the data was deleted. Z4 contradicted the interpretation given by the controller to the contractual agreem

GDPR Articles Cited

Art. 6 GDPR
Art. 5(1)(a) GDPR
Art. 24(1) GDPR
Full Legal Summary

Infobel (the controller) is a commercial data broker who bought personal data from Z4, a telecom operator, regarding a customer (the data subject). Subsequently, the controller sold the personal data to Z3, a direct marketing company. The data subject received unsolicited direct marketing communications from Z1, a client of the direct marketing company and filed a complaint with the Belgian DPA against the controller and the other companies involved in the case. The current proceedings concern only the controller. The controller claimed that it had a right to access and use Z4’s database in particular for marketing purposes based on contractual agreements. The information referred to in the contracts amounted to the names, phone numbers, and addresses of customers who had a telephone connection with Z4 in Belgium and with 3rd party operators with which Z4 concluded agreements. The exceptions to the right to access and use of the databases were private numbers and the lists of restricted numbers which required the customer to opt-out from the database in order to be added to the restricted numbers list. The controller further specified that the data subject’s personal data (first and last name, street and house number, postal code, city and the creation date and source of the data) were added on 3 May 2006 to their database. The controller claimed that it added the personal data to the database on the basis of the consent of the data subject allegedly given by the data subject to Z4 when taking out a telephone subscription. The data subject denied having given consent for the processing of his personal data by the controller. The controller sold the data subject’s first and last name and address to a third party for a marketing campaign. The controller’s DPO stated that the database had not been used by the controller since 2023. The controller states that the data was deleted. Z4 contradicted the interpretation given by the controller to the contractual agreem

Violations (1)

Third-Party Cookies Without Consent
critical

Third-party tracking cookies or scripts are loaded without obtaining prior user consent.

Art. 13, 14 GDPR

Related Enforcement Actions (0)

No other enforcement actions found for Infobel in BE

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

27 November 2025

Authority

Autorité de Protection des Données

Fine Amount

€40,000

Enforcement Tracker ID

ETid-2948

GDPRhub ID

gdprhub-9671

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Infobel - Belgium (2025). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: