The ex officio inspection of the Personal Data Protection Authority at the company RANNER turned up a few fish, following complaints from citizens about sending emails with the aim of promoting products and services.
The investigation showed that the company was in possession of files that it had illegally collected and was in possession of, while as stated in the Authority's decision, company representatives not only obstructed the inspection but also "turned off" the power switch to stop it!!
The results of the…search of the company’s files showed that RANNER possessed files that it should not have, such as data that can only be managed by the General Secretariat of Information Systems and that concern 5,000,000 taxpayers and what they declare on the E1 form (income tax). In addition, they possessed files for 110,000 births in three maternity hospitals, data of 200,000 people who hold credit cards, 4,300,000 names of OTE subscribers, their telephone numbers and data of their income, etc.
What was the purpose of the company?
It sold the files, without the consent of the subjects, in order to respond to requests for information from its clients for a fee. These requests generally concerned
the creation of files with personal data, based on specific criteria, such as profession, income, region or any other information that was available to the RANNER company. Although the requests often concerned business data, no distinction was made between natural or legal persons.
Following the complaints and the Authority's findings, a fine of 100,000 euros was imposed on the company, while a copy of the findings was forwarded to the prosecutor for the purpose of seeking criminal liability.
Source: iefimerida.gr
