Bankia S.A.
€50,000
Non-compliance with general data processing principles
Sprendimo priėmimo data
2020 m. rugpjūčio 28 d.
Institucija
Spanish Data Protection Authority (aepd)
ES
Sektorius
Finance, Insurance and Consulting
Šalis
ES
Teisė
GDPRStatusas
FINALAprašymas
The bank kept personal data of a data subject for several years, even after the data subject was no longer a customer. The data was also accessible to bank employees during this time. This constituted a violation of the principle of purpose limitation.
Teisinės citatos
Art. 5 (1)
Problemos ir pažeidimai
Non-compliance with general data processing principles