Skip to content
Enforcement · Icelandic data protection authority ('Persónuvernd') EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

YAY ehf.: Non-compliance with general data processing principles

The Icelandic Data Protection Authority has imposed a fine of EUR 51,000 on the Ministry of Industry and Innovation and a fine of EUR 27,200 on YAY ehf.

Full text 2 findings

Paragraphs carrying a topic or an applied provision show those connections inline
§

The Icelandic Data Protection Authority has imposed a fine of EUR 51,000 on the Ministry of Industry and Innovation and a fine of EUR 27,200 on YAY ehf. The fine is related to a campaign by the ministry to encourage Icelanders to travel domestically in the summer of 2020. This involved a digital gift voucher that could be obtained through the app of the company YAY ehf. The DPA received a number of complaints regarding the fact that the use of the travel gift required extensive personal information and access to users' phones. As a result, the DPA launched investigations against the ministry and the company. The DPA found that the ministry had violated the principle of legality and transparency. Participating individuals were only required to agree to the General Terms of Use of the YAY app in order to participate in the voucher promotion. However, the DPA found that by doing so, the data subjects had not expressly consented to the processing of their personal data carried out as part of the promotion.

§

The DPA also found that the information provided about the actual processing of personal data was insufficient. Moreover, neither the ministry nor YAY ehf. had implemented appropriate technical and organizational measures to ensure the security of the processing of personal data. Also, due to a configuration error on the part of YAY, more data than necessary was processed, which is why the DPA found a violation of the principle of data minimization. GDPR Articles: Art. 5 GDPR, Art. 6 GDPR, Art. 28 GDPR, Art. 32 GDPR Industry: Industry and Commerce

How it connects

2 of 2 paragraphs apply legislation or carry a topic — see them in the full text ↓
15625/2026 Cass.Civ. - 15625/2026 Istituto nazionale della previdenza sociale (INPS, the controller) is the Italian National Institute for Social Security. In 2021, the DPA fined the controller €300,000 for its… Supreme Court May 21, 2026 Privacy by Design & Default Privacy by Design DPIA
C-175/20 SIA 'SS' v Valsts ieņēmumu dienests In Case C-175/20, the Court of Justice of the EU interpreted GDPR Articles 5 and 6 in response to a preliminary ruling from the Latvian Regional Administrative Court concerning a… CJEU ·Fifth Chamber Feb 24, 2022 Retention Period Personal Data Legitimate Interest
C-252/21 Meta Platforms v noyb C-252/21 (Meta Platforms (noyb)) CJEU Jan 12, 2023 Supervisory Authorities IP Address Supervision
C-634/21 OQ v Land Hessen In Case C-634/21, the CJEU addressed a preliminary ruling from the Verwaltungsgericht Wiesbaden concerning OQ's challenge against Land Hessen's refusal to order SCHUFA Holding AG… CJEU ·First Chamber Dec 7, 2023 Profiling Automated Decision-Making Marketing
C-740/22 Endemol Shine Finland Oy In Case C-740/22, the Court of Justice of the European Union (Sixth Chamber) ruled on a preliminary reference from the Itä-Suomen hovioikeus (Court of Appeal, Eastern Finland)… CJEU ·Sixth Chamber Mar 7, 2024 Criminal Data Personal Data Types of Special Categories of Personal Data
C-422/24 Case C-422/24 - AB Storstockholms Lokaltrafik. A new page has been created with the following information: "" CJEU Jan 7, 2026 Personal Data Fairness & Transparency Controllers