Home

Some companies that have chosen us

Privacy Officer and Privacy Consultant
CDP Scheme according to ISO/IEC 17024:2012
European Privacy Auditor
ISDP©10003 Certification Scheme according to ISO/IEC 17065:2012
Auditor
According to standard UNI 11697:2017
Lead Auditor ISO/IEC 27001:2022
According to standard ISO/IEC 17024:2012
Data Protection Officer
According to standard ISO/IEC 17024:2012
Anti-Bribery Lead Auditor Expert
According to standard ISO/IEC 17024:2012
ICT Security Manager
According to standard UNI 11506:2017
IT Service Management (ITSM)
According to the ITIL Foundation
Ethical Hacker (CEH)
According to the EC-Council
Network Defender (CND)
According to the EC-Council
Computer Hacking Forensics Investigator (CHFI)
According to the EC-Council
Penetration Testing Professional (CPENT)
According to the EC-Council

Professional qualifications

Stay up-to-date with world news!

Select your topics of interest:

News

Home / News
/
FINNISH SUPERVISORY AUTHORITY: personal data shall not be recollected from clients without their acknowledge

FINNISH SUPERVISORY AUTHORITY: personal data shall not be recollected from clients without their acknowledge

The Personal Data Protection Authority has warned a Fan Company that the recollection of personal data by the client’s control but without informing data subject does not fulfil the personal data protection legislation. The recollection and the usage would also ask a legal basis for the processing.

On the website of the data controller has been noticed a form that, in addition to information about the type of houses and the fan system, was reserving also a space for the information on, for example, the developments of the relationships, the financial situation and the life of the client.

According to information provided by the data controller, the form published on the website of the company was underdevelopment and questions were random fill questions used by the developer of the form in order to help in projecting the form. The form was unvisible for few days. According to the data controller, the form has not been used at any time, for example during visits of clients, in order to recollect personal data.

The recollection of personal data shall be communicated to the data subject in a transparent way

The Authority warns that the personal data processing recollected by clients by the observation would be in breaching of the personal data processing if data subjects are not informed of the recollection and does not exist a legal processing basis.

If the responsible of the processing shall recollect information on clients by observing and not informing them in advance, this would breach the transparency principle of the General Data Protection Regulation. The personal data processing shall be clear and transparent, and the control shall inform the data subject in a comprehensible way on how his/her personal data are recollected and used.

The recollection of personal data by the controlling shall be explained in order that the personal data processing is not a surprise for the data subject. The data subject shall be able to avoid being submitted to the control and to exercise his/her personal data protection rights.

The decision is not final.

TSV Päätös 5417.163.20

SOURCE: AUTORITA’ PER LA PROTEZIONE DEI DATI DELLA FINLANDIA

Recommended to you

Advanced Research