Bankia S.A.
€50,000
Non-compliance with general data processing principles
Datum der Entscheidung
28. August 2020
Behörde
Spanish Data Protection Authority (aepd)
ES
Sektor
Finance, Insurance and Consulting
Land
ES
Recht
GDPRStatus
FINALBeschreibung
The bank kept personal data of a data subject for several years, even after the data subject was no longer a customer. The data was also accessible to bank employees during this time. This constituted a violation of the principle of purpose limitation.
Juristische Zitate
Art. 5 (1)
Probleme und Verstöße
Non-compliance with general data processing principles