Avast fined €14 million for sharing user data
Avast Software, a cybersecurity company, has been fined almost €14 million (351 million kronas) by the Czech data protection authority for unauthorized processing of users’ personal data. The fine was imposed by the Office for Personal Data Protection for incidents occurring in early 2019. Avast, known for its antivirus software and browser extensions, was found to have shared approximately 100 million users’ data with Jumpshot, INC., including pseudonymized browsing history linked to unique identifiers.
During the proven period in 2019, Avast users were misled about the sharing of supposedly anonymous data for trend analysis. Despite Avast’s claims of using robust anonymization techniques, it was revealed in the investigation that the shared data from individual antivirus software installations were not properly anonymized. This raised concerns as some data recipients could potentially re-identify at least a portion of the data subjects. The purpose of data processing was not solely for statistical analysis as Avast had indicated.
The Czech data protection authority emphasized that Avast, a key player in cybersecurity offering tools for data and privacy protection, breached user trust by sharing personal data that could reveal not only identities but also interests, preferences, residences, financial situations, professions, and other private details. The decision highlighted Avast’s misleading practices and the discrepancy between its privacy claims and actual data handling. Due to the cross-border nature of data processing within the European Union, the case was handled in coordination with other EU supervisory authorities under the One Stop Shop mechanism.
This significant fine serves as a stark reminder of the importance of compliance with GDPR regulations and proper data handling practices to protect user privacy. Avast Software’s breach of trust and failure to adequately anonymize and protect users’ personal data underscores the need for companies to prioritize data privacy and transparency in their operations.
Source: Úřad pro ochranu osobních údajů