Banco Bilbao Vizcaya Argentaria, S.A.

€800,000

Insufficient technical and organisational measures to ensure information security

决定日期

2023年10月20日

权力

Spanish Data Protection Authority (aepd)

ES

部门

Finance, Insurance and Consulting

国家

ES

法律

GDPR

现状

FINAL

说明

The Spanish DPA has fined BANCO BILBAO VIZCAYA ARGENTARIA, S.A. EUR 800,000. A customer had lost her handbag, which also contained her bank card. The individual therefore requested the controller to block all banking products. However, the controller failed to comply, which is why it was then possible for third parties to access the individual's bank products and transfer money under false identities. During its investigation, the DPA found that the controller had failed to implement appropriate technical and organizational measures to prevent such a case and protect personal data.

法律引文

Art. 25Art. 32

问题与违规

Insufficient technical and organisational measures to ensure information security

随时了解隐私执法的最新情况

我们尊重您的隐私。每月一封电子邮件,无垃圾邮件,随时退订。