Hellenic Data Protection Authority (HDPA) · 2 February 2023
Piraeus Bank
Non-compliance with general data processing principles
Fine€30,000Fine issued
- Regulator
- Hellenic Data Protection Authority (HDPA)
- Decided
- 2 February 2023
- Country
- Greece
- Sector
- Finance, Insurance and Consulting
- Regulator’s reference
- Not recorded
- Fino case number
- 2023/GR/009
What happened
The Greek DPA fined a bank €30,000 for transferring financial data of the data subject to an unauthorized third party, in violation of Articles 5(1)(a) and (f), and for failing to notify the breach in line with Articles 33 and 34 GDPR.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 33Notification of a personal data breach to the supervisory authorityRead →
- Art. 34Communication of a personal data breach to the data subjectRead →
- Data breach
- Data principles
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2023/GR/009.