Unnamed financial institution

€3,200

Insufficient fulfilment of data subjects rights

Ngày ra quyết định

4 tháng 3, 2019

Thẩm quyền

Hungarian National Authority for Data Protection and the Freedom of Information (NAIH)

HU

Ngành

Finance, Insurance and Consulting

Quốc gia

HU

Luật

GDPR

Trạng thái

FINAL

Mô tả

The fine was imposed in relation to a data subject's request for data correction and erasure. NAIH levied a fine against an unnamed financial institution for unlawfully rejecting a customer’s request to have his phone number erased after arguing that it was in the company's legitimate interest to process this data in order to enforce a debt claim against the customer. In its decision, the NAIH emphasised that the customer’s phone number is not necessary for the purpose of debt collection because the creditor can also communicate with the debtor by post. Consequently, keeping the phone number of the debtor was against the principles of data minimisation and purpose limitation. As per the law, the assessed fine was based on 0.025% of the company's annual net revenue.

Trích dẫn pháp lý

Art. 5 (1)Art. 5 (1)Art. 13 (3)Art. 17 (1)Art. 6 (4)

Vấn đề & Vi phạm

Insufficient fulfilment of data subjects rights

Cập nhật thông tin về việc thực thi quy định bảo vệ dữ liệu cá nhân

Chúng tôi tôn trọng quyền riêng tư của bạn. Chỉ một email mỗi tháng, không spam, có thể hủy đăng ký bất cứ lúc nào.