Fino

Persónuvernd (Iceland) · 14 December 2022

Íslandsbanki (Bank of Iceland)

About: Data principles, Data security, Unlawful processing

FineNo fineViolation found
Regulator
Persónuvernd (Iceland)
Decided
14 December 2022
Country
Iceland
Sector
Not given
Regulator’s reference
2022020333
Fino case number
2022/IS/022
Export as PDF

What happened

According to the Icelandic DPA, in case of legal obligation to carry out a certain processing operation, controllers must assess the law requirements diligently before taking any action. In this case, a bank should have verified the accuracy of information available in some official registration books before disclosing the data subject's data to third parties.

Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Data principles
  • Data security
  • Unlawful processing

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2022/IS/022.