VDAI (Lithuania) - 3R-1005
| VDAI - 3R-1005 | |
|---|---|
| [[File:|center|250px]] | |
| Authority: | VDAI (Lithuania) |
| Jurisdiction: | Lithuania |
| Relevant Law: | Article 6(1)(b) GDPR |
| Type: | Complaint |
| Outcome: | Upheld |
| Started: | 03.05.2021 |
| Decided: | 01.08.2025 |
| Published: | |
| Fine: | n/a |
| Parties: | Vinted UAB |
| National Case Number/Name: | 3R-1005 |
| European Case Law Identifier: | n/a |
| Appeal: | Unknown |
| Original Language(s): | Lithuanian |
| Original Source: | VDAI (in LT) |
| Initial Contributor: | cci |
The DPA held that Vinted unlawfully collected a user's phone number for the purpose of account verification.
English Summary
Facts
The case relates to a complaint over Vinted’s use of a user’s phone number for verification purposes.
A user (the data subject) created an account with Vinted (the controller), an e-commerce platform for buying and selling second-hand items. During account creation, the data subject was not required to provide a phone number. However, the controller later required the data subject to provide their phone number. The stated purpose for the collection was combating fraud and ensuring the safety of the Vinted platform and its users. The data subject considered the controller’s request unjustified but provided their phone number anyway because they were otherwise unable to access their account.
The data subject later filed a complaint with a German DPA[1], challenging the lawfulness of the collection of their phone number. The German DPA, in turn, held that the Lithuanian DPA was the lead supervisory authority for the case and forwarded the complaint.
In its defense, the controller pointed out that the Vinted Terms of Service explicitly listed the collection of the user’s phone number as one of several methods of account verification, for the purpose of ensuring account security and combating fraud. On these grounds, the controller claimed that the collection of the phone number for account verification was lawful under the legal grounds of the performance of a contract (Article 6(1)(b)). Furthermore, the controller argued that ensuring the security of users' accounts, constituted an integral part of its contract with end users. Finally, the controller claimed that the collection of personal data for the purpose of account verification, fit the expectation of end users.
Holding
The DPA held that verifying users' accounts and ensuring the security of the platform was not an essential aspect of the contract between the controller and the data subject. For this reason, the DPA held that the processing of the data was not based on the legal basis of Article 6(1)(b) GDPR. In this regard, the DPA referred to EDPB guidance on Article 6(1)(b) GDPR[2] and emphasized that the necessity criterion of the provision must be interpreted narrowly.
The DPA also noted that the controller’s Terms of Service listed the collection of phone numbers as one of several possible means of verifying a user’s identity. In the DPA’s view, this was enough to conclude that the processing of personal data did not meet the criterion of necessity under Article 6(1)(b) GDPR.
Finally, the DPA pointed out that the controller did not require the data subject’s phone number at sign up, Therefore, the controller could not match it with a known number in order to verify the account. Therefore, the DPA held that the data subject's phone number was not needed to secure the account, to begin with[3].
On these grounds, the DPA held that the controller unlawfully collected the data subject’s numbers. The DPA ordered the controller to stop collecting phone numbers for verification purposes on the basis of Article 6(1)(b) GDPR, and to delete the data subject’s number.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Lithuanian original. Please refer to the Lithuanian original for more details.
Extract from an electronic document STATE DATA PROTECTION INSPECTORATE DECISION 1 August 2025 No 3R-1005 (2.13-1.E) Vilnius On 3 May 2021, the State Data Protection Inspectorate (hereinafter referred to as 'the Inspectorate') received a complaint from the applicant [DATA NOT DISCLOSED] (hereinafter referred to as 'the Applicant') dated 19 February 2021 regarding the actions of the company Vinted, UAB (hereinafter referred to as 'the Complained Party'), which was transmitted by the German supervisory authority through the Internal Market Information System (IMI) (Inspectorate Reg. No 1R-3125 (2.13.Mr) ('the Complaint'). In her complaint, the Applicant stated that one day she was suddenly unable to log in to her account on the Complainant's platform, as she had to provide her mobile phone number to verify her account. The applicant also indicated that she was unable to log in to her account in order to edit or delete it. According to the applicant, she was not properly informed about the management of her telephone number. According to the Applicant, she was told that she could not use the Complainant's platform without providing her mobile number. The Inspectorate, being competent to act as lead supervisory authority and to take a final decision on the Complainant's Complaint (Articles 56, 60(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC ("General Data Protection Regulation") ("GDPR"), has decided as follows: The Inspectorate received a reply from the Complainant on 25 June 2021 (Inspectorate reg. No. 1R 4502(2.13.)) (hereinafter referred to as the "Response"), in which the Complained Person stated that the Complainant had been asked to provide her mobile phone number for the purpose of the mandatory verification of the phone number for the purpose of fraud protection, security of the company's platform and its members. The telephone number is requested for security purposes when a suspicious connection is observed, for example when a user connects from another country. The Complainant explained that when the Applicant attempted to log in, she was shown a standard confirmation window for the telephone number. The person complained against indicated that the legal basis for such processing of personal data was the performance of the contract with the Applicant (point 1.5 of the General Rules of the Vinted Platform ('the Rules')) on the basis of the condition of lawful processing of personal data laid down in Article 6(1)(b) of GDPR. In its reply to the Inspectorate on 28 July 2023 (Inspectorate reg. No 1R-5341 (2.13.Mr)) (hereinafter referred to as the "2023-07-28 response"), the Complained Party noted that the Rules constitute a legally binding agreement between the user and the company on the conditions of access to and use of the Complained Party's platform. The security of the Complainant's platform and the related application of security procedures and restrictions on the use of the platform are an integral part of the contract and an essential element of the contract. The validation of the telephone number is one of the procedures for ensuring the security of the account. Both the right of the Complainant to apply such a procedure in relation to the user and the restrictions to which the consumer faces until the telephone number is confirmed, arises directly from the Terms and Conditions as a contract. According to the Complainant, as the operator of an e-commerce platform, it has a reasonable expectation to implement measures to ensure the security of the platform and to prevent unlawful acts. Users of the platform have a reasonable expectation that the Complained Party will make reasonable efforts to ensure that the platform and the user accounts created on it are protected against malicious acts of third parties. It can also be appreciated that an ordinary user who creates an account on an e-commerce platform can expect that certain proportionate security measures may be applied to ensure their security and that of other users of the platform. Therefore, according to the Complainant, the processing of data which asks the user to provide a telephone number for the purpose of confirmation of suspicious activity on the account does not fall outside the scope of the Rules as a contract and is necessary for the performance of that contract. In its reply of 28.07.2023, the Complained Party also pointed out that the mandatory confirmation of the telephone number can only be waived in exceptional cases where a person makes a request to explain the specific circumstances of his/her situation. According to the Complainant, the principle of freedom of contract allows for the possibility to derogate from the existing contractual conditions by agreement between the parties, but such derogation does not in itself negate the necessity of the management of the telephone number in the circumstances set out in the contract (the rules) (in the event of the discovery of suspicious activity). The person complained against replied on 2 February 2023 (Inspectorate reg. No 914(2.13.Mr)) explained that at the time of the collection of the Applicant's telephone number, the version of the privacy policy of the Vinted.de platform in force at the time of the collection of the Applicant's telephone number was version 2020-11-26 of the privacy policy of the Vinted.de platform, which provided the Applicant with the information required to be provided pursuant to Article 13 of GDPR. On the lawfulness of the collection of the Applicant's telephone number The complaint established that the Complained Person offers a platform (website and app) on which individuals can buy and sell clothes and other goods, i.e. individuals are given the opportunity to be a buyer and/or seller of goods on the company's platform. Once a person becomes a member of the platform operated by the Complained Party, i.e. by registering, a contractual relationship is established between the Complained Party and the registered person. In the present case, the Applicant had an account on the Complainant's platform and, consequently, a contractual relationship was established between the Complainant and the Applicant with regard to the exercise of the respective obligations, rights and duties. According to the Complainant, the latter collected the Applicant's telephone number for the purpose of carrying out the mandatory verification of the telephone number for the purpose of fraud protection and to ensure the security of the company's platform and its members. Such processing, according to the Complainant, was carried out pursuant to Article 6(1)(b) of the GDPR. In its reply to the Inspectorate dated 17 February 2022 (Inspectorate reg. No 1R-968 (2.13.Mr)) also noted (on page 9) that the rules form part of the contract concluded between the company and the users. According to the company, each registered user of the Vinted platform is required to acknowledge that he/she has read the rules at the time of registration. In its reply of 28.07.2023, the Complained Party further noted that the security of the platform it operates and the related application of security procedures and restrictions on the use of the platform are an integral part of the contract and an essential element of the contract. Therefore, the processing of data, whereby the user is asked to provide a telephone number for the purpose of confirmation of suspicious activity on the account, does not fall outside the scope of the Rules as a contract and is necessary for the performance of that contract. Pursuant to the GDPR, personal data may only be processed in accordance with the principles relating to the processing of personal data as set out in Article 5 of the GDPR and where such processing can be based on at least one of the conditions for the lawful processing of personal data set out in Articles 6 and/or 9 of the GDPR, depending on the category of personal data processed. Pursuant to Article 6(1)(b) of the GDPR 2 paragraph 1(2) of the GDPR, processing is lawful if (and to the extent that) the processing is necessary for the performance of a contract to which the data subject is a party or for the purpose of taking action at the request of the data subject prior to entering into a contract. The European Data Protection Board's ("EDPB") Guideline 2/2019 on the processing of personal data pursuant to Article 6(1)(b) of the GDPR in the context of the provision of online services to data subjects ("the Guideline") states that the necessity of processing is a prerequisite for the choice of the two options of Article 6(1)(b). The notion of what is 'necessary for the performance of the contract' is not simply an assessment of what is permitted by or included in the terms of the contract. The notion of necessity has an independent meaning in European Union law and must reflect the objectives of data protection law. The assessment of what is 'necessary' involves a general fact-based assessment of the processing in relation to the purpose pursued and whether it is less intrusive on privacy compared to other options that may pursue the same purpose. If there are realistic possibilities that are less restrictive of privacy, the processing is not 'necessary'. Article 6(1)(b) of the GDPR will not apply to processing which is useful but not necessary, from an objective point of view, for the provision of the service referred to in the contract, or for the purpose of taking appropriate steps at the request of the data subject prior to the conclusion of the contract, even if such processing is necessary for other business purposes of the controller (p. 23, 25 of the Guidelines). The Guidelines emphasise that the provision "processing is necessary for the performance of a contract entered into by the data subject": must be understood narrowly and does not apply in cases where the processing of the data subject's data is not really necessary for the performance of the contract, but the controller does it unilaterally anyway. The mere fact that the processing of some data is provided for in the contract does not always imply that the processing is necessary for the performance of the contract either. The assessment of the necessity of the processing is clearly linked to compliance with the purpose limitation principle. It is important to identify precisely the rationale for the conclusion of the contract, i.e. its essence and its main purpose, as this will be the basis for verifying whether the processing is necessary for the performance of the contract (paragraphs 28, 29 of the Guidelines). Accordingly, in order to assess whether the processing of the Applicant's personal data (telephone number) was lawful pursuant to Article 6(1)(b) of the GDPR, it is necessary to establish whether such processing was objectively necessary for the performance of the contract with the Applicant. As mentioned above, the Complained Person offers a platform (website and app) on which individuals can buy and sell clothes and other goods, i.e. individuals are given the opportunity to be a buyer and/or seller of goods on the company's platform. In its reply to the Inspectorate of 28 July 2023, the Complained Person indicated that, as an operator of an e-commerce platform, it has a reasonable expectation that it will implement measures to ensure the security of the platform and to prevent unlawful activities. According to the Complained Person, users of the platform have an expectation that the Complained Person will make reasonable efforts to ensure that the platform and the user accounts created on it are protected against malicious acts by third parties. The Complained Party bases this position on the provisions of the Rules 1.5, which states that "for security reasons, VINTED may ask the USER to confirm his/her ACCOUNT. This may be done, for example, by confirming the USER's Facebook or Google account, the USER's telephone number, the USER's credit or debit card, PIN-based or other methods that VINTED may use at its discretion." Having assessed the material collected during the examination of the Complaint, the EDVA's methodological material as well as the explanations provided by the Complainant, the Inspectorate concludes that the processing of the Applicant's telephone number could not be based on Article 6(1)(b) of GDPR. This conclusion is based on the following considerations. First, in the Inspectorate's view, the Complained Party has not demonstrated the objective necessity required by the spirit and purpose of the regulation laid down in Article 6(1)(b) of the GDPR 3 objectives. The Complained Person justifies the necessity of such processing by stating that 'an ordinary user who creates an account on an e-commerce platform can expect that certain proportionate security measures may be applied to their security and that of other users of the platform. Therefore, the processing of data whereby the user is asked to provide a telephone number for confirmation purposes in the event of suspicious activity on the account does not go beyond the Terms and Conditions as a contract and is necessary for the performance of that contract." However, the Inspectorate considers the arguments of the Complainant to be declarative and unsubstantiated by any objective arguments and data. As already mentioned, the assessment of what is 'necessary' involves an overall factual assessment of the processing in the light of the purpose pursued and whether it is less restrictive of privacy compared to other options that may pursue the same purpose1. 1.Paragraph 5 states that "In order to register, the USER must provide his/her username (pseudonym), email address and password (either directly or through a Facebook or Google account), so that the WEBSITE can identify the USER each time the WEBSITE is accessed." As can be seen from the Rules, the provision of a telephone number is only one of the ways in which a person's account can be authenticated and, consequently, the security claimed by the Complainant can be ensured2) .(2Given that individuals (including the Applicant) are required to provide their email address and phone number in all cases in order to register on the Complainant's platform, the Applicant must provide his/her email address and phone number in order to be able to register. The Inspectorate concludes that the provision of a telephone number is not objectively necessary for the fulfilment of the contract between the parties (the Rules). The fact that such processing is not objectively necessary is further confirmed by the explanations provided by the Complainant during the examination of the Complaint. For example, in its reply of 28.07.2023, the Complained Party has stated that "the verification of the telephone number can only be waived in exceptional cases, when a person contacts Vinted to explain the specific circumstances of his/her situation". In the Guidelines, the EDPS has indicated that the controller should be able to demonstrate how the main object of a specific contract with a data subject cannot actually be fulfilled if the specific processing of the personal data in question is not carried out.3Thus, the circumstance that the data subject has the possibility to contact the controller (the Complained Person) and to ask for an exemption from the telephone number verification procedure further confirms that the contract with the data subject could be fulfilled without such processing. These conclusions of the Inspectorate are also supported by the principle of data minimisation enshrined in Article 5(1)(c) of the GDPR, which requires that personal data are adequate, relevant and only necessary for the purposes for which they are processed. The importance of this principle in the context of online/digital service contracts is also highlighted by the EDPS4. In the present case, having established that the security purposes of the platform, as set out in the Terms and Conditions of the Complained Person, could have been achieved by other means which did not require the collection of additional personal data (telephone number) of the Applicant(5) ,the Inspectorate has no reason to consider such processing as objectively necessary for the purposes of Article 6 of the GDPR 1Point 25 of the Guidelines. 2Paragraph 1.5 ofthe Guidelines also provides that a person's account may be verified using Facebook, Google accounts, as well as other methods that the Complainant may use at his/her discretion. 3Paragraph 30 of the Guidelines. 4Paragraph 16 of the Guidelines states that both the purpose limitation principle and the data minimisation principle are particularly relevant in the case of contracts for online services, which are generally not negotiated on an individual basis. Technological advances allow controllers to easily collect and process more personal data than ever before. This creates a significant risk that controllers may seek to include general processing clauses in contracts in order to collect and use as much data as possible without properly specifying the purposes for which they are doing so and without considering the possibility of complying with data minimisation obligations. 5The account may have been validated using other personal data (such as email) already held by the Complainant. 4 In the context of paragraph 1(b). The right of the Complainant to require the Applicant to provide her telephone number "for security reasons", as set out in the Rules, cannot in itself justify the proper application of Article 6(1)(b) of the GDPR either.6 Secondly, when assessing whether Article 6(1)(b) GDPR is the appropriate legal basis for processing in the context of a contractual online service, the specific aim, purpose or objective of the service should be taken into account.7In the Inspectorate's view, the main purpose of the contract as the operator of the e-commerce platform is to enable individuals to act on the platform as buyers/sellers. While the Inspectorate agrees that an important part of the proper functioning of such a platform is the security of the platform and of the accounts on it, the guarantee of this security cannot be based on the performance of a contract with a data subject. This conclusion of the Inspectorate is directly supported by the Guidelines, which, in relation to the specific cases of application of Article 6(1)(b) of the GDPR, under the heading of 'Processing for fraud prevention purposes'8, state that such processing is likely to go beyond what is objectively necessary for the performance of the contract with the data subject.9 This is also the practice of the EDPS, which, in its binding decision No 5/2022 of 05.12.202210, examined, inter alia, whether WhatsApp IE could rely on Article 6(1)(b) of the GDPR when processing data subjects' data for "security" purposes. The EDPS pointed out that the Irish supervisory authority had not found that "WhatsApp IE had infringed Article 6(1)(b) of the GDPR, that provision is in principle rendered meaningless and, in theory, any collection and re-use of personal data in connection with the performance of a contract with the data subject becomes lawful. Accordingly, the EDPS concluded and agreed with the arguments of the supervisory authorities concerned that the processing was not objectively necessary11for the purposes of the security functions and was not an essential or fundamental part of such a contract12. Although the person complained against additionally emphasises in the Response that this measure (confirmation of the telephone number) is intended, inter alia, to implement "the requirements of Article 31 of the GDPR [GDPR] and to ensure the security of personal data", the aim of ensuring compliance with the requirements of the GDPR cannot, in the context of the Applicant's Complaint, be a justification for the proper application of Article 6(1)(b) of the GDPR. Finally, the Inspectorate notes that, on the one hand, as can be seen from point 1.5 of the Rules, when registering on the Complainant's platform, the data subject (including the Applicant) is required to provide a username/pseudonym, an e-mail address and a password, and the telephone number 6This is also the position of the EDPS. Paragraph 27 of the Guidelines states that the mere reference or mention of processing in a contract is not sufficient for Article 6(1)(b) to apply to that processing. To be 'necessary for the performance of the contract', more than the terms of the contract is certainly required. 7Point 30 of the Guidelines. 8Given that the validation of the Applicant's account using her telephone number was triggered by the discovery of a "suspicious login" (page 1 of the Complainant's Response), the purpose of such processing was, inter alia, to prevent possible fraudulent access to the Applicant's account. 9Paragraph 50 of the Guidelines. 10Online link to the EAGGF Decision (in English): https://www.edpb.europa.eu/our-work-tools/our-documents/binding-decision board-art-65/binding-decision-52022-dispute-submitted_en 11Paragraphs 121, 122 of the Decision. 12In paragraph 118 of the Decision, the EDPS c o n c l u d e d that the main purpose for which a user uses WhatsApp services is to communicate with other users. (13) Inpoint 50 of the Guidelines, the EDPS has clarified that the processing of personal data strictly necessary for the purposes of fraud prevention may be a legitimate interest of the controller and thus may be considered lawful if the controller fulfils the specific requirements of Article 6(1)(f) (legitimate interests). In addition, Article 6(1)(c) (legal obligation) may also be a ground for lawfulness for such processing. Accordingly, if the Complained Party partially relies on the processing for the purpose of enforcing Article 31 of the GDPR, it should be able to demonstrate compliance with Article 6(1)(c) of the GDPR (the processing is necessary for the fulfilment of a legal obligation imposed on the data controller). 5 The provision of the data is not a prerequisite for access to the services provided by the Complainant. On the other hand, in its reply, the Complained Party indicates that the verification of the telephone number is carried out for the purpose of protection against fraud and to ensure the security of the platform and its members and that, in the case of the Applicant, the verification procedure was initiated following the discovery of a suspicious login. Accordingly, the Inspectorate considers that in the absence of objective data from the Complainant as to whether the telephone number entered during the validation of the telephone number belongs to the user of an account on the platform(14) ,the processing of the telephone number for the purpose of ensuring the security of such an account is essentially pointless. In conclusion, the processing of the applicant's personal data (telephone number) could not, in the context of the circumstances of the Complaint, be based on the legitimate processing condition of Article 6(1)(b) of the GDPR, since such processing was not objectively necessary for the performance of the contract with the applicant. The Complained Person did not rely on the other grounds set out in Article 6(1) of the GDPR for the processing of the Applicant's personal data (telephone number), and the Inspectorate therefore does not elaborate on them (Article 5(2) of GDPR). Accordingly, the Complaint is considered justified. Concerning the imposition of sanctions against the Complainant Article 31(2) of the GDPR states that where the complaint or part thereof is found to be justified, the Inspectorate shall issue instructions, recommendations and/or apply other measures as provided for in the legislation on the protection of personal data and/or privacy to the controller and/or processor. Pursuant to Article 12(2)(5) of the GDPR, the Inspectorate has the right to provide recommendations and instructions to data controllers, data processors and other legal or natural persons with regard to the processing of personal data and/or privacy protection. į Paragraph 129 of the GDPR Preamble provides that any measure taken by a supervisory authority must be appropriate, necessary and proportionate to ensure compliance with this Regulation, taking into account each should be noted, see specific ADTAA case by case circumstances of each individual case. It provides for the Inspectorate's discretion to select remedial measures if a complaint is found to be justified, but it is important that any measure taken by the Inspectorate is appropriate, necessary and proportionate in relation to the infringement. Article 58(2)(d) of the GDPR provides that each supervisory authority shall have the power to order the controller or processor to bring processing operations into conformity with the provisions of this Regulation, where appropriate, in a prescribed manner and within a prescribed time limit. period. In the present case, if it is established that the Complained Person unjustifiably processed the Applicant's personal data (telephone number) on the basis of Article 6(1)(b) of the GDPR, it is concluded that the processing of those data is unlawful, and that, accordingly, the Complained Person is under an obligation to delete those data. Furthermore, given that it is likely that the Complained Person processes (and intends to process) other data subjects' data (telephone numbers) in similar circumstances, and in order to ensure that the Complained Person's processing continues to comply with the GDPR, the Complained Person is hereby instructed to ensure that the data subjects' data (telephone numbers) are 14As the Complainant did not provide her telephone number during the registration process on the platform, a corresponding check whether the telephone number entered during the validation procedure corresponds to the one belonging to the Complainant is objectively impossible. 6 would not be processed for the purpose of protection against fraud and for the security of the platform and its members under GDPR 6 Article 1(1)(b). On the basis of the above, Article 31(1)(1), (2)(1), Article 58(2)(d), Article 60(7) of the Law of the Republic of Lithuania on Legal Protection of Personal Data, the Inspectorate shall has adopted the following provisions: 1. declare the Complaint of the Applicant to be well-founded. 2. Provide instructions to the Appellant within 1 (one) month of receipt of this Decision days: 2.1. delete the details of the Applicant's telephone number; 2.2. Ensure that the telephone numbers of data subjects are not processed for protection against for the purpose of ensuring the security of the platform and its members for the purposes of Article 6(1)(b) GDPR on the basis of Article 2(1) of the GDPR. 3. Inform the Complained Party and the Applicant of the decision taken. This decision may be appealed to the Administrative Court of the Regions (address: Žygimantų g. 2, Vilnius) in accordance with the procedure laid down by the Law on Administrative Procedure of the Republic of Lithuania within one month from the day of its service. Director Dijana Šinkūnienė 7
- ↑ The decision does not clarify whether the complaint was forwarded by a State DPA or by the Federal DPA of Germany.
- ↑ EDPB, 'Guidelines 2/2019 on the processing of personal data under Article 6(1)(b) GDPR in the context of the provision of online services to data subjects', 8 October 2019 (Version 2.0), available here.
- ↑ N.B.: this entails that the processing effectively failed two distinct necessity tests. First, the DPA held that securing user's accounts and preventing fraud were not strictly necessary to the performance of the contract. Second, the DPA held that the phone number was not necessary for the stated purpose of user verification to begin with.



