Banco Bilbao Vizcaya Argentaria, S.A.

€5,000,000

Insufficient fulfilment of information obligations

決定日期

2020年12月11日

權限

Spanish Data Protection Authority (aepd)

ES

部門

Finance, Insurance and Consulting

國家

ES

法律

GDPR

狀態

FINAL

說明

The Spanish DPA (AEPD) fined Banco Bilbao Vizcaya Argentaria, S.A. EUR 5,000,000 for violating Art. 6 GDPR (EUR 3,000,000) and Art. 13 GDPR (EUR 2,000,000). The bank had not implemented a specific mechanism to obtain the consent of the customers to process their data. Furthermore, it did not use precise terminology in its privacy policy, nor did it provide adequate information about the type of personal data that might be processed. In particular the AEPD notes that the purpose and legal basis for data processing are not sufficiently identifiable in the privacy statement.

法律引文

Art. 6Art. 13

問題與違規

Insufficient fulfilment of information obligations

保持最新的隱私權執法資訊

我們尊重您的隱私。每月一封電子郵件,無垃圾郵件,可隨時取消訂閱。