Hellenic Bank

€25,000

Insufficient technical and organisational measures to ensure information security

Sprendimo priėmimo data

2021 m. kovo 3 d.

Institucija

Cypriot Data Protection Commissioner

CY

Sektorius

Finance, Insurance and Consulting

Šalis

CY

Teisė

GDPR

Statusas

FINAL

Aprašymas

The Cypriot DPA imposed a fine of EUR 25,000 on Hellenic Bank. The bank had closed one of its branches in the city of Nicosia in 2015. When moving out of the space, a safe containing old documents of still existing customers, installed in one of the walls, had been forgotten. As the building was vacant in the following years, the controller only learned about this incident when the property was rented out again for the first time in 2019. The new tenant had found the safe and informed the controller. Bank staff had then retrieved the documents and reported the data breach to the Cypriot DPA. The DPA ultimately concluded that the controller had violated Art. 5 (1) e), f) GDPR, Art. 32 (1) b), c) GDPR, and Art. 33 (1) GDPR.

Teisinės citatos

Art. 5 (1)Art. 32 (1)Art. 33 (1)

Problemos ir pažeidimai

Insufficient technical and organisational measures to ensure information security

Gaukite naujausią informaciją apie privatumo vykdymo užtikrinimą

Gerbiame jūsų privatumą. Vienas el. laiškas per mėnesį, jokių šlamšto, atsisakykite prenumeratos bet kada.