Imposition of a fine on a bank in Greece for an incident of personal data breach

The Greek Data Protection Supervisory Authority imposed on a Bank, as Data Controller, an administrative fine of EUR 100,000 for violating the principles of accuracy, integrity, and confidentiality of data, and the principles of data protection by design and by default, in conjunction with Articles 32, 33, and 34 of the GDPR, as well as an administrative fine of EUR 20,000 for violating the complainants' right of access.

Complaints were submitted to the Supervisory Authority of Greece against the National Bank of Greece for the incorrect linking of a complainant's bank account with the mobile phone number of another complainant in the “i-bank Pay application”, which resulted in money transfers, via “IRIS online payments service”, which were made to the first complainant's account instead of the second's.

 In the context of the administrative audit conducted by the Authority, the Bank eventually identified that the issue was due to incorrect configuration during the 2020 upgrade of the mobile banking application, which had affected another 24 of its customers. Additionally, the Bank submitted a data breach notification to the Authority and took further corrective measures.

You  might also like: An overview of the regulatory framework on Gambling Services in the European Union / Article by Efi Thoma, Lawyer in Cyprus

(source:edpb.europa.eu/photo:freepik.com)


Comments

Popular posts from this blog

Ombudsman inquiry on Commission President’s text messages is a wake-up call for EU

New President of the European Court of Human Rights

An overview of the regulatory framework on Gambling Services in the European Union

Lawyer vs. Lawyer: Confronting Unethical Conduct Within the Profession