Data Security, Privacy, Government Regulations

Belgian authority penalizes data broker Infobel

Judge gavel

The Belgian Data Protection Authority has fined data broker Infobel 40,000 for unlawfully selling personal information for marketing purposes, emphasizing the strict requirements for valid consent under the GDPR, according to Cybernews.

The ruling stemmed from a consumer complaint after receiving unsolicited marketing from a company that had acquired his data through a chain involving Infobel and a telecom provider. Infobel claimed it had consent to resell the data, but the authority found the consent was neither specific nor unambiguous, as required by law. The GBA explicitly stated that "consent must be actively given" and cannot be inferred from pre-checked boxes or inactivity, stressing that individuals must have the freedom to consent to each distinct purpose.

In addition to the financial penalty, Infobel is ordered to notify its corporate clients of the decision and delete any data for which valid consent cannot be demonstrated. GBA Director Hielke Hijmans highlighted the particular risks posed by data brokers, whose indirect data handling often leaves individuals unaware that their information is being processed.

The fine was mitigated because the implicated database was deleted last year.

You can skip this ad in 5 seconds