返回網站

GDPR Case 30. The Romanian Supervisory Authority fines INTELIGO MEDIA SA

GDPR:§5(1)(a) (lawfulness, fairness and transparency)、§5(1)(b) (purpose limitation)、§6(1)(a) (consent as a legal basis for the processing of data)、§7 (conditions for consent)

2023年4月2日

日期:31 October 2019

國家:羅馬尼亞

關鍵字:當事人同意

GDPR:§5(1)(a) (lawfulness, fairness and transparency)、§5(1)(b) (purpose limitation)、§6(1)(a) (consent as a legal basis for the processing of data)、§7 (conditions for consent)

裁決:行政罰鍰(€ 9,000)

摘要:

(1) 羅馬尼亞監管機關對控管者 INTELIGO MEDIA SA 進行調查後,發現該公司違反 GDPR §5(1)(a) (lawfulness, fairness and transparency)、§5(1)(b) (purpose limitation)、§6(1)(a)、§7 等規定,而對其課以 € 9,000 之行政罰鍰。

(2) 當資料主體在控管者經營的 avocatnet.ro 網站上開設新帳戶時,將會出現一個未經選擇的核取方塊,同時伴隨著下列文字:「我不想收到『個人更新』,以及 avocatnet.ro 提供的每日新訊。」(I do not want to receive “Personal Update”, the information sent daily, free of charge, by email, by avocatnet.ro)

(3) 監管機關認為,根據控制者設定的這些條件,如果使用者略過這個核取方塊,他將會自動訂閱 avocatnet.ro 提供的每日新訊,因此,訂閱是在沒有取得資料主體明確同意的情況下進行。

備註:控管者是以「個人更新」,作為綁定接收每日新訊的條件,資料主體倘若需要取得個人更新的服務,勢必略過這個核取方塊,從而帶來同意接收每日新訊的結果;也因此,監管機關才會認為,在此情況下,控管者故意設定的條件,不足以認定資料主體有訂閱每日新訊的明確同意。

(4) 雖然控管者主張,其係基於履行契約之目的而處理個人資料,但是監管機關認為,透過電子郵件傳送每日新訊,與履行契約無關,因此,控管者在未取得資料主體明確同意的情況下處理個人資料,已經違反 GDPR §7 規定。

(5) 監管機關強調,根據 GDPR §7 規定,倘若控管者是基於資料主體同意而進行資料處理,必須舉證證明,本件因為控管者無法證明資料主體已經確實給予同意,因而對其課以行政罰鍰。

 

Reference

Article 7 Conditions for consent

1. Where processing is based on consent, the controller shall be able to demonstrate that the data subject has consented to processing of his or her personal data.

2. If the data subject's consent is given in the context of a written declaration which also concerns other matters, the request for consent shall be presented in a manner which is clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language. Any part of such a declaration which constitutes an infringement of this Regulation shall not be binding.

3. The data subject shall have the right to withdraw his or her consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. Prior to giving consent, the data subject shall be informed thereof. It shall be as easy to withdraw as to give consent.

4. When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract.