Hellenic Data Protection Authority (HDPA) · 12 June 2023
Piraeus Bank
Non-compliance with general data processing principles
Fine€210,000Fine issued
- Regulator
- Hellenic Data Protection Authority (HDPA)
- Decided
- 12 June 2023
- Country
- Greece
- Sector
- Finance, Insurance and Consulting
- Regulator’s reference
- Not recorded
- Fino case number
- 2023/GR/007
What happened
The Hellenic DPA fined a bank €210,000 for mistakenly including its customers's personal data in a list of debtors and for not properly responding to an access request. The DPA also concluded that the controller did not implement sufficient organizational and technical measures according to Article 25 GDPR.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1)(a)Read →
- Art. 6Lawfulness of processingRead →
- Art. 15Right of access by the data subject15(1)Read →
- Art. 25Data protection by design and by default25(1)Read →
- Accountability
- Data principles
- Data subject rights
- Unlawful processing
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2023/GR/007.