Bankia S.A.
€50,000
Non-compliance with general data processing principles
Data decyzji
28 sierpnia 2020
Władza
Spanish Data Protection Authority (aepd)
ES
Sektor
Finance, Insurance and Consulting
Kraj
ES
Prawo
GDPRStatus
FINALOpis
The bank kept personal data of a data subject for several years, even after the data subject was no longer a customer. The data was also accessible to bank employees during this time. This constituted a violation of the principle of purpose limitation.
Cytaty prawne
Art. 5 (1)
Problemy i naruszenia
Non-compliance with general data processing principles