[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fKpnuaLLIL6dj079jS2M0il8JBYoXeU0I2IqEe2oPBME":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":42},"e05bbfac-19bd-4524-8cb0-291a2d323cd4","data-broker-fined-for-unlawful-resale-of-personal-data-without-consent","55e10a4f-81f5-476c-93a2-5fa331013f81","Data Broker Fined for Unlawful Resale of Personal Data Without Consent","Infobel S.A. unlawfully obtained personal data from a telecom operator and resold it for direct marketing purposes without securing valid consent from the individuals involved, violating GDPR's lawful basis requirements. This case highlights the risk that data brokers face when they fail to establish a clear, documented legal basis for each stage of data processing and sharing. The reduced fine, while smaller than the original, still represents regulatory and reputational exposure that could have been avoided with proper data governance. It also underscores that courts and regulators are scrutinizing the entire data supply chain, not just the original data collector.","**Immediate actions:**\n- Audit all personal data sources to confirm a valid legal basis (consent, legitimate interest, etc.) is documented before any processing or resale occurs.\n- Halt any data sharing or resale arrangements with third parties until lawful basis and data-sharing agreements are verified and compliant.\n\n**Long-term improvements:**\n- Implement a Data Processing Register (Article 30 record) that maps every data flow, its origin, legal basis, and recipient to maintain ongoing GDPR compliance.\n- Establish contractual due diligence procedures for all data supplier relationships, requiring proof of lawful collection before acquiring any dataset.\n- Embed privacy-by-design principles into product and business development so that consent and legal basis are validated at the point of data acquisition, not retroactively.\n\n**Detection & Monitoring measures:**\n- Schedule periodic internal audits and third-party assessments to detect unlawful or undocumented data processing activities before regulators do.\n- Deploy automated data governance tooling to flag datasets lacking a verified legal basis or expiring consent records.",[12,13,14,15,16,17,18,19,20,21],"GDPR Article 5(1)(a) – Lawfulness, fairness, and transparency","GDPR Article 6 – Lawful basis for processing","GDPR Article 13\u002F14 – Transparency obligations to data subjects","GDPR Article 30 – Records of processing activities","GDPR Article 44-49 – Restrictions on international transfers","NIST Privacy Framework PR.DS-P1 – Data processing policies","NIST SP 800-53 PT-2 – Authority to process personally identifiable information","CIS Control 3 – Data Protection","ISO\u002FIEC 27701 – Privacy Information Management System (PIMS)","ITIL Service Value Chain – Governance and compliance management","published","2026-10-08T10:21:10.168929+00:00","2026-10-08T10:21:09.857+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=C._A._-_2025\u002FAR\u002F2079&diff=53336&oldid=51965","c-a-2025-ar-2079-ff8c24","C. A. - 2025\u002FAR\u002F2079",[30,36],{"id":31,"name":32,"slug":33,"description":34,"color":35},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]