Bankia S.A.
€50,000
Non-compliance with general data processing principles
Ημερομηνία απόφασης
28 Αυγούστου 2020
Αρχή
Spanish Data Protection Authority (aepd)
ES
Τομέας
Finance, Insurance and Consulting
Χώρα
ES
Νόμος
GDPRΚατάσταση
FINALΠεριγραφή
The bank kept personal data of a data subject for several years, even after the data subject was no longer a customer. The data was also accessible to bank employees during this time. This constituted a violation of the principle of purpose limitation.
Νομικές παραπομπές
Art. 5 (1)
Θέματα & Παραβάσεις
Non-compliance with general data processing principles