Persónuvernd (Iceland) · 14 December 2022
Íslandsbanki (Bank of Iceland)
About: Data principles, Data security, Unlawful processing
- Regulator
- Persónuvernd (Iceland)
- Decided
- 14 December 2022
- Country
- Iceland
- Sector
- Not given
- Regulator’s reference
- 2022020333
- Fino case number
- 2022/IS/022
What happened
According to the Icelandic DPA, in case of legal obligation to carry out a certain processing operation, controllers must assess the law requirements diligently before taking any action. In this case, a bank should have verified the accuracy of information available in some official registration books before disclosing the data subject's data to third parties.
Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1) · 5(2)Read →
- Art. 6Lawfulness of processingRead →
- Art. 32Security of processing32(1)Read →
- Data principles
- Data security
- Unlawful processing
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2022/IS/022.