Aktia Pankki Oyj
865,000 €
GDPR enforcement action by Deputy Data Protection Ombudsman on 2025-10-23.
Rank · Sector
#34
of 322 in Finance, Insurance and Consulting
Rank · Finland
#5
of 27
Rank · All fines
#191
of 3,050
Case details
- Authority
- Deputy Data Protection Ombudsman
- Date
- 2025-10-23
- Controller / Processor
- Aktia Pankki Oyj
- Sector
- Finance, Insurance and Consulting
- Quoted Articles
- Art. 5 (1) f) GDPR, Art. 25 (1) GDPR, Art. 32 (1), (2) GDPR
- Type of violation
- Insufficient technical and organisational measures to ensure information security
Summary
The Finish DPA has imposed a fine of EUR 865,000 on Aktia Pankki Oyj. The controller changed its strong authentication process in such a way that it no longer guaranteed adequate data security, resulting in a data breach.
Open original source
Links to the regulator's original publication or another source.
Related fines
Finland
2024-11-13
2,400,000 €
ETid-2544
Posti Jakelu Oy
Transportation and Energy
Finland
2025-09-08
1,800,000 €
ETid-2873
S-Pankki Oyj
Finance, Insurance and Consulting
Finland
2025-05-27
1,100,000 €
ETid-2647
Yliopiston Apteekin
Health Care
Finland
2024-12-17
950,000 €
ETid-2506
Sambla Group Oy
Finance, Insurance and Consulting
Finland
2024-03-06
856,000 €
ETid-2243
Verkkokauppa.com
Industry and Commerce
Finland
2022-12-13
750,000 €
ETid-1565
Alektum Oy
Finance, Insurance and Consulting