publishable_de_north_rhine_west2018-12_lawfulnessoftreatment_summarypublic.pdf

Summary Final Decision Art 60
Complaint

No violation

Background information
Date of final decision: 21 December 2018
LSA: DE – North Rhine-Westphalia
CSAs: DE – Rhineland-Palatinate, DE – Mecklenburg-Western Pomerania, DE – Bavaria (priv), DE – Lower Saxony, DE – Saarland, ES
Legal Reference: Lawfulness of the processing (Article 6)

Decision: No violation
Key words: Direct Marketing, Legitimate interest, publicly available data

Summary of the Decision

Origin of the case
Complainant states they received postal advertisement and tried to exercise their right of access and right to erasure. The contacted branch stated that the letter was not sent to the correct recipient, as they do not manage personal data. The correct establishment is in Germany. The complainant contacted their local SA as they deem that the controller is wrongfully processing their personal data, which is stored in a publicly accessible register.

Findings
According to recital 47 and Art 6.1.f GDPR legitimate interest of the controller or of a third party may be used as legal basis, also when the processing is carried out for marketing purposes. LSA argues the data subject did not present any prevailing fundamental rights and freedoms and neither are prevailing rights and freedoms apparent, as the data is already publicly accessible. As such, the aforementioned legal basis “can be considered as an allowing legal basis.”

The original request of access and to erasure were filed before the 25 May 2018. Articles 13 and 14 GDPR were thus not yet applicable. However, under the GDPR the data subjects are to be informed from which source the personal data originate. The enterprise should be informed about this for future advertising mails”.

Decision
The LSA deems this not be an infringement. The processing of publically available personal data for
direct marketing purposes may constitute lawful processing according to Art 6.1.f GDPR.


This text has been converted automatically from the PDF available via
https://edpb.europa.eu/our-work-tools/consistency-findings/register-for-article-60-final-decisions_en
using Apache Tika to allow for a better search. This might result in some characters being mangled.
Please see the original file for the official wording at
https://edpb.europa.eu/sites/edpb/files/article-60-final-decisions/summary/publishable_de_north_rhine_west2018-12_lawfulnessoftreatment_summarypublic.pdf

Please see also EDPB Copyright page

publishable_cz_2019-10_lawfulness_of_processing_summarypublic.pdf

Summary Final Decision Art 60
Complaint

Compliance order

Background information
Date of final decision: 7 October 2019
LSA: CZ
CSAs: AT, DE-All, HR, SI, SK
Legal Reference: Lawfulness of the processing (Article 6)

Decision: Order to the controller, Infringement of the GDPR
Key words: Lawfulness of processing, Legitimate interest, Data subject rights

Summary of the Decision

Origin of the case
The data subjects filed a complaint with one of the CSAs alleging that the controller published his personal data on its social media page without a legal basis.

Findings
The controller published on its social media page information concerning the complainant and other data subjects, referring to debts which the controller was in charge of collecting. The abbreviated first name and the entire surname of the data subjects, as well as the status of debtor and the amount owed by them were specified. Through a balancing test between the data subjects’ interests and basic rights with the controller’s interests, it was concluded that the controller did not rely on any lawful basis pursuant to Art. 6 GDPR. More specifically, the data subject had not expressed his/her consent; moreover, in the balancing between the legitimate interest pursued by the controller and the interests and rights of the data subject, the latter prevailed, given the significant risk of adverse impact arising
from the publication of negative information about the data subjects’ financial situation.

Decision
The LSA ordered the controller to cease processing the complainant’s personal data and to remove the published personal data within ten business days of the decision. The LSA also ordered the controller to submit a report to LSA on the implementation of the order within five business days of its completion.


This text has been converted automatically from the PDF available via
https://edpb.europa.eu/our-work-tools/consistency-findings/register-for-article-60-final-decisions_en
using Apache Tika to allow for a better search. This might result in some characters being mangled.
Please see the original file for the official wording at
https://edpb.europa.eu/sites/edpb/files/article-60-final-decisions/summary/publishable_cz_2019-10_lawfulness_of_processing_summarypublic.pdf

Please see also EDPB Copyright page