Bankia S.A.
€50,000
Non-compliance with general data processing principles
Határozat dátuma
2020. augusztus 28.
Hatóság
Spanish Data Protection Authority (aepd)
ES
Szektor
Finance, Insurance and Consulting
Ország
ES
Törvény
GDPRÁllapot
FINALLeírás
The bank kept personal data of a data subject for several years, even after the data subject was no longer a customer. The data was also accessible to bank employees during this time. This constituted a violation of the principle of purpose limitation.
Jogi hivatkozások
Art. 5 (1)
Kérdések és jogsértések
Non-compliance with general data processing principles