Persónuvernd (Iceland) · 4 September 2020
Íslandsbanki
About: Accountability, Data principles, Data security
FineNo fineViolation found
- Regulator
- Persónuvernd (Iceland)
- Decided
- 4 September 2020
- Country
- Iceland
- Sector
- Not given
- Regulator’s reference
- 2020010649
- Fino case number
- 2020/IS/019
What happened
The Icelandic DPA (Personuvernd) established that by granting access to the complainant's online banking account to an unauthorised person, Íslandsbanki (bank) was processing personal data in violation of Articles 8(1)(6), 23, 24, and 27 Act 90/2018 (Articles 5(1)(f), 24, 25 and 32 GDPR).
Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1)(f)Read →
- Art. 24Responsibility of the controllerRead →
- Art. 25Data protection by design and by default25(2)Read →
- Art. 32Security of processingRead →
- Accountability
- Data principles
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2020/IS/019.