NBQ Technology, S.A.U.
Insufficient legal basis for data processing
Datum odločitve
12. marec 2021
Organ
Spanish Data Protection Authority (aepd)
ES
Sektor
Finance, Insurance and Consulting
Država
ES
Zakon
GDPRStatus
FINALOpis
The Spanish DPA (AEPD) has fined NBQ Technology, S.A.U. EUR 20,000. An identity thief had obtained the data of a third party without authorization and applied for a microcredit from the controller under pretence of the data subject's identity. The controller then approved the loan. Since the data processed in the course of granting the loan did not belong to the loan recipient, but to the data subject, the AEPD determined that the controller did not have a legal basis for processing the data. The processing was therefore unlawful, and a breach of Art. 6 (1) GDPR was affirmed. The original fine of EUR 20,000 was reduced to EUR 12,000 due to immediate payment and admission of responsibility.