Hungary Hungary

Unknown

97,150 €

GDPR enforcement action by Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) on 2020-12-16.

Rank · Sector
#91
of 322 in Finance, Insurance and Consulting
Rank · Hungary
#6
of 73
Rank · All fines
#490
of 3,042

Case details

Authority
Hungarian National Authority for Data Protection and the Freedom of Information (NAIH)
Date
2020-12-16
Controller / Processor
Unknown
Sector
Finance, Insurance and Consulting
Quoted Articles
Art. 5 (1) c) GDPR, Art. 6 (1) GDPR, Art. 9 (1) GDPR, Art. 12 GDPR
Type of violation
Insufficient legal basis for data processing

Summary

The Hungarian DPA (NAIH) imposed a fine of EUR 97,150 against a credit institute. Two parents contacted the Hungarian DPA regarding the processing of personal data by their credit institute related to a "childbirth incentive loan". The couple requested a suspension of repayment, for which they had to prove that the fetus is at least 12 weeks old. To certify this fact, the controller copied their entire pregnancy booklet. The NAIH found that the controller violated the principle of data minimization by copying the entire pregnancy booklet, which contained excessive amounts of health data, even though this was not necessary regarding the purpose of the processing. For this reason, the NAIH ultimately concluded that the controller had no legal basis for such extensive data processing

Open original source Links to the regulator's original publication or another source.

Related fines