GDPR Fines

A public record of GDPR enforcement across Europe — compiled by INPLP members

ING Bank N.V. Amsterdam - Bucharest Subsidiary

Country
Romania
Fine
3,000 EUR
Date
30.12.20(30.12.20)
Sector
Private Sector
Articles
Article 5 (1), a) - d)Article 6 (1)

Infringement of transparency, purpose limitation, data minimisation and accuracy principles, Lack of legal basis for data processing

The sanction applied by the supervisory authority was triggered by the fact that the controller continued to process the personal data of a data subject – customer (i.e. email address, first and last name, expiration date of the identity card) after the termination of the contractual relationship with the respective customer, non-observing the principles of data processing and without legal basis to justify such data processing. In more detail, the data subject requested the closure of the current account, but due to a system error this request was not considered and the business relationship with the controller was still maintained with the "active" status. The controller sent messages on the e-mail address of the data subject regarding the updating of his/her personal data.