S-Pankki Oyj
€1,800,000
Insufficient technical and organisational measures to ensure information security
Decision Date
September 8, 2025
Authority
Deputy Data Protection Ombudsman
FI
Sector
Finance, Insurance and Consulting
Country
FI
Law
GDPRStatus
FINALDescription
The Finish DPA has imposed a fine of EUR 1,800,000 on S-Pankki Oyj. Due to a software error, customers of the controller were able to log in to the bank accounts of other customers, resulting in financial losses.
Legal Citations
Art. 5 (1)Art. 25 (1)Art. 32 (1)
Issues & Violations
Insufficient technical and organisational measures to ensure information security