Bankia S.A.
€50,000
Non-compliance with general data processing principles
Date de décision
28 août 2020
Autorité
Spanish Data Protection Authority (aepd)
ES
Secteur
Finance, Insurance and Consulting
Pays
ES
Droit
GDPRStatut
FINALDescription
The bank kept personal data of a data subject for several years, even after the data subject was no longer a customer. The data was also accessible to bank employees during this time. This constituted a violation of the principle of purpose limitation.
Citations légales
Art. 5 (1)
Questions et violations
Non-compliance with general data processing principles