Bankia S.A.

€50,000

Non-compliance with general data processing principles

決定日期

2020年8月28日

權限

Spanish Data Protection Authority (aepd)

ES

部門

Finance, Insurance and Consulting

國家

ES

法律

GDPR

狀態

FINAL

說明

The bank kept personal data of a data subject for several years, even after the data subject was no longer a customer. The data was also accessible to bank employees during this time. This constituted a violation of the principle of purpose limitation.

法律引文

Art. 5 (1)

問題與違規

Non-compliance with general data processing principles

保持最新的隱私權執法資訊

我們尊重您的隱私。每月一封電子郵件,無垃圾郵件,可隨時取消訂閱。