Spain Spain

Bankia S.A.

50,000 €

GDPR enforcement action by Spanish Data Protection Authority (aepd) on 2020-08-28.

Rank · Sector
#126
of 322 in Finance, Insurance and Consulting
Rank · Spain
#217
of 1,075
Rank · All fines
#701
of 3,050

Case details

Authority
Spanish Data Protection Authority (aepd)
Date
2020-08-28
Controller / Processor
Bankia S.A.
Sector
Finance, Insurance and Consulting
Quoted Articles
Art. 5 (1) b) GDPR
Type of violation
Non-compliance with general data processing principles

Summary

The bank kept personal data of a data subject for several years, even after the data subject was no longer a customer. The data was also accessible to bank employees during this time. This constituted a violation of the principle of purpose limitation.

Open original source Links to the regulator's original publication or another source.

Related fines