Bankia S.A.
50,000 €
GDPR enforcement action by Spanish Data Protection Authority (aepd) on 2020-08-28.
Rank · Sector
#126
of 322 in Finance, Insurance and Consulting
Rank · Spain
#217
of 1,075
Rank · All fines
#701
of 3,050
Case details
- Authority
- Spanish Data Protection Authority (aepd)
- Date
- 2020-08-28
- Controller / Processor
- Bankia S.A.
- Sector
- Finance, Insurance and Consulting
- Quoted Articles
- Art. 5 (1) b) GDPR
- Type of violation
- Non-compliance with general data processing principles
Summary
The bank kept personal data of a data subject for several years, even after the data subject was no longer a customer. The data was also accessible to bank employees during this time. This constituted a violation of the principle of purpose limitation.
Open original source
Links to the regulator's original publication or another source.
Related fines
Spain
2025-04-07
14,400,000 €
ETid-3192
AMADEUS IT GROUP, S.A.
Transportation and Energy
Spain
2025-11-06
10,043,002 €
ETid-2962
Aena, S.M.E., S.A.
Transportation and Energy
Spain
2022-05-18
10,000,000 €
ETid-1176
Google LLC
Media, Telecoms and Broadcasting
Spain
2021-03-11
8,150,000 €
ETid-594
Vodafone España, S.A.U.
Media, Telecoms and Broadcasting
Spain
2023-12-27
6,500,000 €
ETid-2532
THE PHONE HOUSE SPAIN, S.L.
Media, Telecoms and Broadcasting
Spain
2023-10-25
6,100,000 €
ETid-2220
ENDESA ENERGÍA, S.A.U.
Transportation and Energy