Greece Greece

PIRAEUS BANK S.A.

20,000 €

GDPR enforcement action by Hellenic Data Protection Authority (HDPA) on 2022-10-03.

Rank · Sector
#164
of 322 in Finance, Insurance and Consulting
Rank · Greece
#39
of 93
Rank · All fines
#1,066
of 3,050

Case details

Authority
Hellenic Data Protection Authority (HDPA)
Date
2022-10-03
Controller / Processor
PIRAEUS BANK S.A.
Sector
Finance, Insurance and Consulting
Quoted Articles
Art. 13 GDPR
Type of violation
Insufficient fulfilment of information obligations

Summary

The Hellenic DPA has imposed a fine of EUR 20,000 on PIRAEUS BANK S.A.. In the context of the use of certain debit/credit cards, information of the last 10 transactions were stored on the chip of the card without the customers' explicit consent. This information could be read out later. The DPA found that the bank had failed to inform affected customers about this storage of transaction information and therefore violated Art. 13 GDPR.

Open original source Links to the regulator's original publication or another source.

Related fines