Iberdrola Clientes

€24,000

Non-compliance with general data processing principles

Date de décision

2 juillet 2020

Autorité

Spanish Data Protection Authority (aepd)

ES

Secteur

Transportation and Energy

Pays

ES

Droit

GDPR

Statut

FINAL

Description

A third person had received an electricity bill with personal details such as name, address and bank account of another customer. The reason for this was that Iberdola Clientes was not able to guarantee adequate security measures in the processing of the personal data of the data subject, in violation of the principles of data integrity and confidentiality. The fine of €40,000 has been reduced to €24,000 due to voluntary payment.

Citations légales

Art. 5

Questions et violations

Non-compliance with general data processing principles

Restez informé sur l'application de la législation en matière de protection de la vie privée

Nous respectons votre vie privée. Un courriel par mois, pas de spam, désabonnement à tout moment.