Ireland Ireland

Permanent TSB plc

277,500 €

GDPR enforcement action by Data Protection Authority of Ireland on 2026-04-30.

Rank · Sector
#56
of 326 in Finance, Insurance and Consulting
Rank · Ireland
#20
of 38
Rank · All fines
#317
of 3,070

Case details

Authority
Data Protection Authority of Ireland
Date
2026-04-30
Controller / Processor
Permanent TSB plc
Sector
Finance, Insurance and Consulting
Quoted Articles
Art. 5 (1) f) GDPR, Art. 32 (1) GDPR, Art. 33 (1) GDPR
Type of violation
Insufficient technical and organisational measures to ensure information security

Summary

The Irish DPA has imposed a fine of EUR 277,500 on Permanent TSB plc. The controller offers call-based banking services via Open24. In three instances the controller breached the personal data of data subjects. In the first instance an attacker called the controller after collecting the data subject's phone number via a smishing attack and changed the number linked to the account. Furthermore the controller disclosed the data subject's email address to the attacker. In another instance a customer contacted Permanent TSB to inquire about fraudulent transactions on their account. Permanent TSB investigated and found that a malicious actor had extracted account information in three consecutive calls, which allowed them to make a number of fraudulent transactions totalling EUR 35,000. In the third incident a third party was able to change the phone number linked to a data subject's subsequent bank account held with the controller through a number of malicious calls. This allowed them to make fraudulent transactions totalling EUR 10,000. All three breaches occurred because the controller's agents did not follow security protocols and disclosed personal data to third parties. The controller failed to implement adequate measures to ensure the security and integrity of personal data.

Open original source Links to the regulator's original publication or another source.

Related fines