Banco Bilbao Vizcaya Argentaria S.L.
€48,000
Non-compliance with general data processing principles
Decision Date
November 11, 2022
Authority
Spanish Data Protection Authority (aepd)
ES
Sector
Finance, Insurance and Consulting
Country
ES
Law
GDPRStatus
FINALDescription
The Spanish DPA has imposed a fine on Banco Bilbao Vizcaya Argentaria, S.A.. An individual had filed a complaint with the DPA due to requesting information on one of their accounts and then receiving contract information from a third party. The DPA found that the unauthorized disclosure of third-party data was due to inadequate technical and organizational measures at the bank. The original fine of EUR 80,000 was reduced to EUR 48,000 due to voluntary payment and admission of responsibility.
Legal Citations
Art. 5 (1)Art. 32
Issues & Violations
Non-compliance with general data processing principles