Banco Bilbao Vizcaya Argentaria, S.A.
GDPR enforcement action by Spanish Data Protection Authority (aepd) on 2020-12-21.
Case details
- Authority
- Spanish Data Protection Authority (aepd)
- Date
- 2020-12-21
- Controller / Processor
- Banco Bilbao Vizcaya Argentaria, S.A.
- Sector
- Finance, Insurance and Consulting
- Quoted Articles
- Art. 5 (1) d) GDPR
- Type of violation
- Non-compliance with general data processing principles
Summary
The Spanish DPA (AEPD) fined the financial and credit institution Banco Bilbao Vizcaya Argentaria, S.A. (BBVA) with a fine in the amount of EUR 36,000. The BBVA asked the data subject to settle debts with the BBVA, although the data subject did not have any debts with the bank. As a result, BBVA had transmitted the personal data of the data subject to the debt collection company Multigestión Iberia, S.L., which, over a period of several months, contacted the data subject by telephone and e-mail on behalf of BBVA and requested the payment. The data subject then demanded the erasure of his/her data from BBVA. However, the controller refused to do so.