ING Bank โ Court Ruling (Italy, 2023)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
The Court of Cassation in Italy ruled that ING Bank should have responded to a customer's request to access their personal data, even if it didn't have any. This case is significant because it clarifies that companies must acknowledge data requests and can't ignore them.
What happened
The Court ruled that ING Bank should have responded to a customer's data access request.
Who was affected
A customer who requested access to their personal data from ING Bank.
What the authority found
The Court of Cassation held that ING Bank should have acknowledged the data access request, even if the response was negative.
Why this matters
This ruling emphasizes that companies must respond to data access requests, highlighting the importance of transparency and accountability in data processing. It sets a precedent for how businesses should handle similar requests under GDPR.
GDPR Articles Cited
The Court of Milan rejected a claim brought by the data subject against the controller, ING Bank, relating to the non-compliance with an access request made on the basis of Article 15 GDPR. The Court accepted the arguments of the controller, who denied having processed the data subject's data, and stated that they failed to prove that the bank was the controller in relation to the processing of their data. On this basis, it rejected the claim. The data subject challenged the decision with appeal to cassation, arguing that there was a wrong application of Articles 12 and 15 GDPR. The DPA highlighted that Article 12 GDPR burdens the controller with the obligation to provide data subjects with information regarding the existence of personal data as a result of the access request presented by them. Therefore, contrary to what was decided by the first instance, Ing Bank should have provided a complete reply to the access request within one month or at least should have asked for a deadline extension. The DPA stressed the incontrovertible fact that Ing Bank had not met the request for access to the documents, making it impossible for the data subject to know whether it possessed their personal data and to verify the legitimacy of the data collection. According to the Court of Cassation, the controller should have responded to the request, even if the response was a negative one. Contrary to what was held by the first instance Court, it held that the burden of showing whether or not it is processing personal data is on the controller and not on the data subject making the request. Similarly, it emphasized that, pursuant to Article 12(5) GDPR, the controller has the burden of demonstrating the manifestly unfounded or excessive nature of the request. In any case, the Court of Cassation stated, from the literal wording of the last-mentioned provision it clearly emerges that the controller must always acknowledge the request, even in negative terms, as it cannot hide beh
Outcome
Court Ruling
A ruling by a national court on a data-protection matter.
Related Cases (0)
No other cases found for ING Bank in IT
This is the only recorded case for this entity in this jurisdiction.
Details
About this data
Cite as: Cookie Fines. ING Bank - Italy (2023). Retrieved from cookiefines.eu
Last updated: