- BANCO FALABELLA was fined 496 million pesos and must comply with orders regarding the processing of personal data.
- The company RAPPI was fined 298 million pesos and must adopt measures to respect individuals' rights regarding the processing of their information.
Bogotá D.C., May 22, 2019. The Superintendence of Industry and Commerce, as the national authority for the protection of personal data, imposed a fine of $496,899,600 on BANCO FALABELLA S.A. and ordered it to adopt measures to respect individuals' rights regarding the processing of their information, such as the right to delete their data and the due and timely attention to their requests.
The aforementioned decision, contained in Resolution 9766 of 2019, was made in response to a citizen's complaint who reported that he submitted eight (8) requests to BANCO FALABELLA to have his telephone number removed from its database and to stop sending him messages for commercial prospecting purposes, a request that was ignored by that company.
The SIC concluded that BANCO FALABELLA:
- Did not respect the individual's right to delete their data when used by the bank for advertising purposes.
- Did not respond to the citizen's request properly and timely, as it took one (1) year and five (5) months to do so, when the maximum period is 15 days.
Given the above, in addition to the fine, the SIC ordered BANCO FALABELLA to adopt effective, appropriate, and verifiable measures within a period of two (2) months to:
- Permanently and timely delete the personal data of data subjects who request it when that information is used by BANCO FALABELLA for commercial or marketing purposes.
- Respond timely and substantively to queries or complaints submitted by individuals, eliminating any unnecessary barriers to guarantee the rights of data subjects.
- Make available to the data subject free and easily accessible mechanisms to submit a request for data deletion or revocation of the granted authorization. These must be implemented through the same means or channels through which BANCO FALABELLA contacts or communicates with data subjects.
- Additionally, the banking entity must not only implement a permanent monitoring mechanism regarding the effectiveness of the measures adopted to comply with the above orders, but also conduct an external audit focused on verifying the application of effective and appropriate measures to comply with everything ordered.
THE RAPPI CASE
Through Resolution 9800 of 2019, the Superintendence of Industry and Commerce imposed a fine of $298,121,760 on RAPPI S.A.S. and ordered it to adopt measures to protect individuals' rights regarding the processing of their information, such as the right to delete their data and the requirement that prior authorization exists for its processing.
The aforementioned decision was made in response to a citizen's complaint stating that he asked RAPPI to stop using his information and not to send him emails or data messages for commercial or marketing purposes, but the company did not properly address the requests.
The SIC concluded that RAPPI:
- Did not respect the individual's right to delete their data when used by RAPPI for advertising purposes.
- Did not demonstrate the existence of authorization to collect and use the data.
- Did not prove that it informed the individual as required by Article 12 of Law 1581 of 2012.
- Did not respond to the citizen's request properly and timely, as it took 4 months and 25 days to do so, when the maximum period is 15 days.
- Did not prove that it has an appropriate mechanism to establish the identity of individuals visiting RAPPI's platforms.
In light of the above, in addition to the fine, the SIC ordered RAPPI to adopt effective, appropriate, and verifiable measures within a period of three (3) months to:
- Refrain from sending text messages, emails, making phone calls, or communicating by any means with data subjects for whom it does not have full proof of prior, express, and informed authorization for such purpose.
- Establish the full identity of visitors to its website or users of its platforms whose data is collected, used, or processed by RAPPI S.A.S.
- Permanently and timely delete the personal data of data subjects who request it when that information is used by RAPPI S.A.S. for commercial or marketing purposes.
- Keep proof of the prior, express, and informed authorization granted by each data subject.
- Make available to the data subject free and easily accessible mechanisms to submit a request for data deletion or revocation of the granted authorization. These must be implemented through the same means or channels through which RAPPI S.A.S. contacts or communicates with data subjects.
- Additionally, RAPPI S.A.S. must not only implement a permanent monitoring mechanism regarding the effectiveness of the measures adopted to comply with the above orders, but also conduct an external audit focused on verifying the application of effective and appropriate measures to comply with everything ordered by this entity.
#Repost via http://www.sic.gov.co/Rappi-y-Banco-Falabella-sancionados-por-incumplir-Ley-de-Proteccion-de-Datos

