Germany Germany

Hannoversche Volksbank

900,000 €

GDPR enforcement action by Data Protection Authority of Niedersachsen on 2022-07-28.

Rank · Sector
#32
of 322 in Finance, Insurance and Consulting
Rank · Germany
#14
of 116
Rank · All fines
#183
of 3,042

Case details

Authority
Data Protection Authority of Niedersachsen
Date
2022-07-28
Controller / Processor
Hannoversche Volksbank
Sector
Finance, Insurance and Consulting
Quoted Articles
Art. 6 (1) GDPR
Type of violation
Insufficient legal basis for data processing

Summary

The DPA of Lower Saxony has imposed a fine of EUR 900,000 on Hannoversche Volksbank.

The bank had analyzed data from active and former customers without their consent. For this purpose, the bank analyzed digital usage behavior and evaluated, among other things, purchases in app stores, the frequency of use of bank statement printers and the total number of transfers in online banking compared to the use of in-branch services.

In addition, the results were cross-checked with a credit agency, where they were further supplemented. The aim was to identify customers with an increased willingness to use digital media and to address them more intensively via electronic communication channels for promotional purposes. Most customers were provided with information in advance. However, the DPA found that this did not replace the required consent.

In determining the fine, it was taken into account that the bank did not make further use of the results of its evaluations. In addition, the bank cooperated with the DPA during the investigation.

Open original source Links to the regulator's original publication or another source.

Related fines