Bulgarian Commission for Personal Data Protection
- Country
- Bulgaria
- Fine
- 1,000,000 BGN
- Date
- 2019-08-28
- Sector
- DSK Bank
- Articles
- Art. 32 (1) (b) GDPR
Incompliance with the requirement to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services
In August 2019 DSK Bank was fined for a data breach. In its decision the Commission for Personal Data Protection ("CPDP") established that DSK Bank had infringed Article 32 (1) (b) of the GDPR by not being able to guarantee ongoing confidentiality and security of the systems and servers for processing personal data of individuals, which resulted in third parties having gained unauthorised access to personal data belonging to more than 33,000 customers of the bank. The data was recorded in more than 23,000 credit record files. Among the compromised personal data was data from national ID documents, income and health insurance information, as well as details concerning assessments of individuals' capacity to work.
Source: https://www.cpdp.bg/index.php?p=news_view&aid=1514
Reported by: Dimitrov, Petrov & Co. Law Firm
