PIRAEUS BANK S.A.

€20,000

Insufficient fulfilment of information obligations

Date de décision

3 octobre 2022

Autorité

Hellenic Data Protection Authority (HDPA)

GR

Secteur

Finance, Insurance and Consulting

Pays

GR

Droit

GDPR

Statut

FINAL

Description

The Hellenic DPA has imposed a fine of EUR 20,000 on PIRAEUS BANK S.A.. In the context of the use of certain debit/credit cards, information of the last 10 transactions were stored on the chip of the card without the customers' explicit consent. This information could be read out later. The DPA found that the bank had failed to inform affected customers about this storage of transaction information and therefore violated Art. 13 GDPR.

Citations légales

Art. 13

Questions et violations

Insufficient fulfilment of information obligations

Restez informé sur l'application de la législation en matière de protection de la vie privée

Nous respectons votre vie privée. Un courriel par mois, pas de spam, désabonnement à tout moment.