Permanent TSB plc
GDPR enforcement action by Data Protection Authority of Ireland on 2026-04-30.
Case details
- Authority
- Data Protection Authority of Ireland
- Date
- 2026-04-30
- Controller / Processor
- Permanent TSB plc
- Sector
- Finance, Insurance and Consulting
- Quoted Articles
- Art. 5 (1) f) GDPR, Art. 32 (1) GDPR, Art. 33 (1) GDPR
- Type of violation
- Insufficient technical and organisational measures to ensure information security
Summary
The Irish DPA has imposed a fine of EUR 277,500 on Permanent TSB plc. The controller offers call-based banking services via Open24. In three instances the controller breached the personal data of data subjects. In the first instance an attacker called the controller after collecting the data subject's phone number via a smishing attack and changed the number linked to the account. Furthermore the controller disclosed the data subject's email address to the attacker. In another instance a customer contacted Permanent TSB to inquire about fraudulent transactions on their account. Permanent TSB investigated and found that a malicious actor had extracted account information in three consecutive calls, which allowed them to make a number of fraudulent transactions totalling EUR 35,000. In the third incident a third party was able to change the phone number linked to a data subject's subsequent bank account held with the controller through a number of malicious calls. This allowed them to make fraudulent transactions totalling EUR 10,000. All three breaches occurred because the controller's agents did not follow security protocols and disclosed personal data to third parties. The controller failed to implement adequate measures to ensure the security and integrity of personal data.