Imposition of a fine on a bank in Greece for an incident of personal data breach

The Greek Data Protection Supervisory Authority imposed on a Bank, as Data Controller, an administrative fine of EUR 100,000 for violating the principles of accuracy, integrity, and confidentiality of data, and the principles of data protection by design and by default, in conjunction with Articles 32, 33, and 34 of the GDPR, as well as an administrative fine of EUR 20,000 for violating the complainants' right of access.

Complaints were submitted to the Supervisory Authority of Greece against the National Bank of Greece for the incorrect linking of a complainant's bank account with the mobile phone number of another complainant in the “i-bank Pay application”, which resulted in money transfers, via “IRIS online payments service”, which were made to the first complainant's account instead of the second's.

 In the context of the administrative audit conducted by the Authority, the Bank eventually identified that the issue was due to incorrect configuration during the 2020 upgrade of the mobile banking application, which had affected another 24 of its customers. Additionally, the Bank submitted a data breach notification to the Authority and took further corrective measures.

You  might also like: An overview of the regulatory framework on Gambling Services in the European Union / Article by Efi Thoma, Lawyer in Cyprus

(source:edpb.europa.eu/photo:freepik.com)


Comments

Popular posts from this blog

Annual Report on the execution of the European Court's judgments and decisions

Ombudsman inquiry on Commission President’s text messages is a wake-up call for EU

Prison overcrowding remains a problem in Europe: Council of Europe’s annual penal statistics for 2023

Fully-funded PhD position in AI, Law and Public Power

Cancellation of a flight: The refund of the airline ticket price must include the commission collected by an intermediary at the time of purchase (CJEU)

The Concept of "Habitual Residence" as a Jurisdictional Basis in International Parental Responsibility Disputes: The Cypriot Approach

The struggle for truth against time and limitation period in the light of two paternity court cases