Bankia S.A.
€50,000
Non-compliance with general data processing principles
Dato for beslutning
28. august 2020
Myndighet
Spanish Data Protection Authority (aepd)
ES
Sektor
Finance, Insurance and Consulting
Land
ES
Lov og rett
GDPRStatus
FINALBeskrivelse
The bank kept personal data of a data subject for several years, even after the data subject was no longer a customer. The data was also accessible to bank employees during this time. This constituted a violation of the principle of purpose limitation.
Juridiske henvisninger
Art. 5 (1)
Problemer og overtredelser
Non-compliance with general data processing principles