Bankia S.A.
€50,000
Non-compliance with general data processing principles
決定日
2020年8月28日
権威
Spanish Data Protection Authority (aepd)
ES
セクター
Finance, Insurance and Consulting
国名
ES
法律
GDPRステータス
FINAL説明
The bank kept personal data of a data subject for several years, even after the data subject was no longer a customer. The data was also accessible to bank employees during this time. This constituted a violation of the principle of purpose limitation.
法的引用
Art. 5 (1)
問題と違反
Non-compliance with general data processing principles