Bankia S.A.
€50,000
Non-compliance with general data processing principles
Karar Tarihi
28 Ağustos 2020
Otorite
Spanish Data Protection Authority (aepd)
ES
Sektör
Finance, Insurance and Consulting
Ülke
ES
Hukuk
GDPRDurum
FINALAçıklama
The bank kept personal data of a data subject for several years, even after the data subject was no longer a customer. The data was also accessible to bank employees during this time. This constituted a violation of the principle of purpose limitation.
Yasal Atıflar
Art. 5 (1)
Sorunlar & İhlaller
Non-compliance with general data processing principles