The German payment service giropay stores item‑by‑item purchase information from online shops, including health‑related and sexual‑preference data. noyb lodged a complaint with the Hessian State Commissioner for Data Protection, alleging violations of GDPR principles such as consent and data minimisation. The complaint asserts that giropay’s practice is not required for payment processing and lacks a lawful basis.
Why it matters: The case highlights potential GDPR breaches by a payment provider that retains sensitive purchase details without explicit user consent.
Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.