Fino

Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) · 10 February 2021

ING Bank N.V. Amsterdam - Bucharest office

Insufficient technical and organisational measures to ensure information security

Fine€1,000Fine issued
Regulator
Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP)
Decided
10 February 2021
Country
Romania
Sector
Finance, Insurance and Consulting
Regulator’s reference
Not recorded
Fino case number
2021/RO/022
Export as PDF

What happened

The Romanian DPA (ANSPDCP) conducted an investigation into ING Bank N.V. Amsterdam – Bucharest Branch, following a personal data breach notification, and found that the controller sent files containing outdated information to a contractual partner, through a mandated company.

Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Data security

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2021/RO/022.