Skip to content
Enforcement · Icelandic data protection authority ('Persónuvernd') EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Creditinfo Lánstraust hf.: Insufficient legal basis for data processing

The Icelandic DPA has imposed a fine of EUR 257,000 on Creditinfo Lánstraust hf..

€257,000 Fine
Creditinfo Lánstraust hf.
ICELAND
Art. 5 GDPR Art. 6 GDPR Art. 8 GDPR Art. 9 GDPR

Full text

The Icelandic DPA has imposed a fine of EUR 257,000 on Creditinfo Lánstraust hf.. The controller had registered information on loan defaults even though the required registration conditions for this have not been in place. For instance, unpaid small loans were registered although they were below the required minimum amount. In assessing the fine, the fact that a large number of people were affected by the incident and that the controller was pursuing profits were considered aggravating factors.

Industry: Finance, Insurance and Consulting

How it connects

Guidelines 8/2022 identifying a controller or processor's lead supervisory authority Guidelines for identifying a controller or processor’s lead supervisory authority Guidelines ·EDPB Apr 17, 2023 Supervision Controllers Supervisory Authorities
1 As 183/2023-62 Health insurer must disclose aggregated patient treatment data under Free Access to OAKS Consulting s.r.o. (the company) provided consulting services concerning market access conditions for medicinal products and medical devices. Pursuant to the Czech Act on Free… Supreme Administrative Court Aug 4, 2026 Pseudonymization Anonymization Personal Data
SAN 3154/2026 National court annuls DPA sanction against KFC Spain over website privacy information In May 2021, a data subject lodged a complaint with the DPA against KFC Restaurants Spain, S.L.U., the controller, concerning the processing of personal data through its website.… Jul 16, 2026 Supervisory Authorities Personal Data Controllers
Guidelines 1/2020 processing personal data in the context of connected vehicles and mobility related applications Guidelines on processing of personal data through video devices Guidelines ·EDPB Jan 28, 2020 Personal Data Privacy by Design & Default Processing