Permanent TSB Group Holdings plc – €277,000 Fine (Ireland, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Ireland's Data Protection Commission fined Permanent TSB €277,000 for failing to protect customer data during social engineering attacks. This case matters because it shows the serious consequences of inadequate security measures. It highlights the need for businesses to strengthen their data protection practices to prevent fraud and protect customer information.
What happened
Permanent TSB failed to secure customer accounts from social engineering attacks, resulting in unauthorized access to personal data.
Who was affected
Customers of Permanent TSB whose accounts were compromised during the attacks.
What the authority found
The commission found that the bank did not implement adequate security measures to protect customer data, violating GDPR requirements for data security.
Why this matters
This fine serves as a warning to all businesses about the importance of robust security measures. Companies must prioritize data protection to avoid similar penalties and protect their customers.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
Entities Involved
Permanent TSB Group, the controller, is a provider of banking services in Ireland. Its Open24 Contact Centre allows customers to access their accounts and perform banking operations by telephone. On 26 and 27 May 2022, the controller submitted three personal data breach notifications to the Data Protection Commission, the DPA. The breaches concerned social engineering attacks carried out between April and May 2022. Malicious actors contacted the controller’s call centre while impersonating three customers. In each incident, call centre agents failed to follow the applicable customer identification and security procedures. The malicious actors obtained or changed account information, including the mobile telephone numbers used for authentication. They were consequently able to access customer accounts and personal data. The affected data included identity, contact and financial data. Two data subjects suffered fraudulent transactions of approximately €35,000 and €10,000 respectively. These amounts were subsequently refunded. Although three data subjects were directly affected, the weaknesses in the controller’s call centre systems exposed a potentially much larger number of customers to similar attacks. The controller had implemented policies, customer authentication procedures, fraud monitoring systems and staff training. However, employees could manually amend important account information without mandatory technical validation. The controller also lacked an effective procedure for recording repeated failed authentication attempts, alerting staff to suspicious calls or escalating attempts to change account details. The DPA initiated an own-volition inquiry on 24 August 2022. It examined whether the controller had implemented appropriate technical and organisational measures and whether it had notified the breaches without undue delay. The DPA held that the controller infringed Articles 5(1)(f) and 32(1) GDPR. The processing carried out through the Open24 Contact
Related Enforcement Actions (0)
No other enforcement actions found for Permanent TSB Group Holdings plc in IE
This is the only recorded action for this entity in this jurisdiction.
Details
About this data
Cite as: Cookie Fines. Permanent TSB Group Holdings plc - Ireland (2026). Retrieved from cookiefines.eu
Last updated: