Details:

Summary The Icelandic DPA has fined Hörpu tónlistar- og ráðstefnuhúss ohf. EUR 7,000.

The DPA had received a complaint regarding the concert hall’s collection of ID number and date of birth information as part of an electronic ticket purchase.

The incident occurred prior to the start of the Covid-19 pandemic, when the registration of personal data for contact tracking in the context of event visits was not yet required.
The DPA concluded that it would not have been necessary to collect the data for issuing a ticket, as it would have been possible to conclude a purchase contract even without this collection. For this reason, the DPA found that the concert hall had violated the principle of data minimization.

Link: link
Related articles:  Art. 5 (1) c) GDPR, Art. 6 GDPR
Type: Non-compliance with general data processing principles
Fine: EUR 7,000
Sector Industry and Commerce

 

All data is based on The CMS’s Law GDPR Enforcement Tracker Source: https://www.enforcementtracker.com/

Tags: case law