Bankia S.A.
€50,000
Non-compliance with general data processing principles
决定日期
2020年8月28日
权力
Spanish Data Protection Authority (aepd)
ES
部门
Finance, Insurance and Consulting
国家
ES
法律
GDPR现状
FINAL说明
The bank kept personal data of a data subject for several years, even after the data subject was no longer a customer. The data was also accessible to bank employees during this time. This constituted a violation of the principle of purpose limitation.
法律引文
Art. 5 (1)
问题与违规
Non-compliance with general data processing principles