Fino

Spanish Data Protection Authority (AEPD) · 25 August 2021

Banco Bilbao Vizcaya Argentaria, S.A.

Insufficient technical and organisational measures to ensure information security

Fine€120,000Fine issued
Regulator
Spanish Data Protection Authority (AEPD)
Decided
25 August 2021
Country
Spain
Sector
Finance, Insurance and Consulting
Regulator’s reference
Not recorded
Fino case number
2021/ES/074
Export as PDF

What happened

The Spanish DPA fined the Banco Bilbao €120,000 for allowing anyone who could provide the ID number of card holders to obtain detailed information on their latest credit card transactions. It concluded that such a procedure violates the confidentiality of personal data due to insufficient technical and organizational safeguards.

Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Data security

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2021/ES/074.