PIRAEUS BANK S.A.
€20,000
Insufficient fulfilment of information obligations
Date de décision
3 octobre 2022
Autorité
Hellenic Data Protection Authority (HDPA)
GR
Secteur
Finance, Insurance and Consulting
Pays
GR
Droit
GDPRStatut
FINALDescription
The Hellenic DPA has imposed a fine of EUR 20,000 on PIRAEUS BANK S.A.. In the context of the use of certain debit/credit cards, information of the last 10 transactions were stored on the chip of the card without the customers' explicit consent. This information could be read out later. The DPA found that the bank had failed to inform affected customers about this storage of transaction information and therefore violated Art. 13 GDPR.
Citations légales
Art. 13
Questions et violations
Insufficient fulfilment of information obligations