Compare with different regulatory event:

Description

Issued Penalty Notice to Easylife for inferring health data without consent

On 5 October 2022, the United Kingdom (UK) Information Commissioner's Office (ICO) fined the company Easylife, a catalogue retailer that sells health products, with GBP 1'350'000 for using the personal information of over 145'400 customers without consent. In particular, ICO noted that Easylife collected its customers' data and processed it to infer health data, which is classified as sensitive personal data, to target them with health-related products. The company failed to obtain explicit consent for such data processing, violating the lawfulness, fairness and transparency requirements in the General Data Protection Regulation.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Data protection regulation
Regulated Economic Activity
platform intermediary: e-commerce
Implementation Level
national
Government Branch
executive
Government Body
data protection authority

Complete timeline of this policy change

Hide details
2022-10-05
under investigation

On 5 October 2022, the United Kingdom (UK) Information Commissioner's Office (ICO) fined the compan…

2023-03-16
in force

On 16 March 2023, the UK Information Commissioner's Office (ICO) announced it had reached an agreem…