
Summary The Spanish DPA has imposed a fine on Banco Bilbao Vizcaya Argentaria, S.A.. An individual had filed a complaint with the DPA due to requesting information on one of their accounts and then receiving contract information from a third party. The DPA found that the unauthorized disclosure of third-party data was due to inadequate technical and organizational measures at the bank. The original fine of EUR 80,000 was reduced to EUR 48,000 due to voluntary payment and admission of responsibility.
Link: link
Related articles:  Art. 5 (1) f) GDPR, Art. 32 GDPR
Type: Non-compliance with general data processing principles
Fine: EUR 48,000
Sector Finance, Insurance and Consulting


All data is based on The CMS’s Law GDPR Enforcement Tracker Source:

Tags: case law