Google search page with the words "right to be forgotten" on the smartphone screen.
© Ascannio/Shutterstock.com
No AI-generated content: this article is written and researched by humans
Table of contents

Incogni has filed a complaint with the Dutch Data Protection Authority (DPA) against GfK Group, accusing the German market research company of failing to comply with data deletion requests from its clients.

In a press release on Tuesday, Incogni said GfK Group has “consistently ignored” data deletion requests from its clients, effectively violating their right to erasure under the GDPR (General Data Protection Regulation). According to Incogni, its Dutch customers have submitted nearly 500 data deletion requests to the GfK Group.

“The group has been making it unnecessarily difficult for Incogni’s clients to have their personal data deleted,” Darius Belejevas, head of Incogni, said.

Incogni is a data removal service created by popular VPN provider Surfshark.

The ‘Right to be Forgotten’

Article 17 of the GDPR gives individuals the right to request the erasure of their data from the databases of companies “without undue delay” under certain conditions. For example, individuals can request the erasure of their data if they withdraw consent or believe their data was processed unlawfully.

Incogni has filed an enforcement request with the Dutch Data Protection Authority, urging the agency to intervene and ensure that GfK Group complies with the GDPR. GfK is the largest market research company in Germany, so the outcome of this complaint is likely to have far-reaching consequences and will be closely monitored by other data brokers in the EU.

A GDPR violation can result in millions in penalties for the offending party. According to law firm DLA Piper, 2021 was a record year for GDPR fines, with a sevenfold increase from 2020, tallying up an estimated €1.1 billion (about $1.2 billion) in fines. A large portion of those fines — €746 million (about $824 million) — was imposed on Amazon by Luxembourg’s data protection watchdog.

“The potential impact of the requested action by the DPA is far-reaching, as companies that manage substantial amounts of user data, particularly data brokers, often place unwarranted and illegal obstacles before individuals seeking to delete information,” Incogni said in its press release.

According to Incogni, sometimes companies request “highly sensitive data” to process data deletion requests.

“Some data protection laws state that information required to process data removal needs to be proportional to the request,” Belejevas said in an email to VPNOverview. “[However,] GfK demands an excessive and disproportionate amount of data from individuals who wish to delete it. It’s even more concerning that they disregard individuals’ rights despite their obligations.”

Rampant Data Collection

Companies collect vast amounts of data when users visit websites and use online products and services — often without users’ knowledge or consent. “Data brokers continue to employ increasingly sophisticated data collection methods, resulting in higher availability of users’ data,” Belejevas explained.

A research paper published in May 2022 revealed that websites track users’ keystrokes and log data even when users don’t submit any data. The researchers said consent boxes are ineffective at preventing this invasive tracking.

According to Incogni, this complaint is “the first step in a broader mission to establish a more equitable and privacy-focused digital landscape.”

It’s almost impossible to stop companies from tracking you online or collecting your data when you visit their websites or use their apps. However, you can mask your location by using a VPN.

Check out our article on big data and privacy to learn about other ways to take control of your privacy.

Leave a comment