Unnamed financial institution

€3,200

Insufficient fulfilment of data subjects rights

Lēmuma datums

2019. gada 4. marts

Iestāde

Hungarian National Authority for Data Protection and the Freedom of Information (NAIH)

HU

Nozare

Finance, Insurance and Consulting

Valsts

HU

Likums

GDPR

Statuss

FINAL

Apraksts

The fine was imposed in relation to a data subject's request for data correction and erasure. NAIH levied a fine against an unnamed financial institution for unlawfully rejecting a customer’s request to have his phone number erased after arguing that it was in the company's legitimate interest to process this data in order to enforce a debt claim against the customer. In its decision, the NAIH emphasised that the customer’s phone number is not necessary for the purpose of debt collection because the creditor can also communicate with the debtor by post. Consequently, keeping the phone number of the debtor was against the principles of data minimisation and purpose limitation. As per the law, the assessed fine was based on 0.025% of the company's annual net revenue.

Juridiskās atsauces

Art. 5 (1)Art. 5 (1)Art. 13 (3)Art. 17 (1)Art. 6 (4)

Jautājumi un pārkāpumi

Insufficient fulfilment of data subjects rights

Atjauniniet informāciju par konfidencialitātes ieviešanu

Mēs respektējam jūsu konfidencialitāti. Viens e-pasts mēnesī, bez surogātpasta, jebkurā laikā varat atteikties no abonēšanas.