Bankia S.A.
€50,000
Non-compliance with general data processing principles
تاريخ القرار
28 أغسطس 2020
الهيئة
Spanish Data Protection Authority (aepd)
ES
القطاع
Finance, Insurance and Consulting
البلد
ES
القانون
GDPRالحالة
FINALالوصف
The bank kept personal data of a data subject for several years, even after the data subject was no longer a customer. The data was also accessible to bank employees during this time. This constituted a violation of the principle of purpose limitation.
الاستشهادات القانونية
Art. 5 (1)
القضايا والانتهاكات
Non-compliance with general data processing principles