Raiffeisen Bank S.A – €19,893 Fine (Romania, 2024)

€19,893Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal20 October 2024Romania
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Raiffeisen Bank S.A. was fined EUR 19,893 for serious data breaches involving unauthorized access to customer information by employees. This case illustrates the importance of having strong internal controls to prevent misuse of personal data.

What happened

The Romanian DPA fined Raiffeisen Bank for multiple breaches of personal data security by its employees.

Who was affected

Customers of Raiffeisen Bank whose personal data was accessed and misused by employees.

What the authority found

The DPA ruled that the bank failed to implement sufficient security measures to prevent unauthorized access to personal data, violating GDPR.

Why this matters

This case underscores the need for companies to enforce strict data access policies and training for employees. Businesses must ensure that personal data is protected from internal threats as well as external ones.

GDPR Articles Cited

AI-verified

Art. 32(1)(b) GDPR
Art. 32(1)(d) GDPR
Art. 32(4) GDPR
View original scraped data
Art. 32(1)(b) GDPR
Art. 32(1)(d) GDPR
Art. 32(4) GDPR

Original data from scraper before AI verification against source document.

Source verified 13 March 2026
articles corrected
amount discrepancy
Full Legal Summary
Detailed

Raiffeisen Bank S.A., the controller, communicated to the Romanian DPA multiple personal data breaches. A customer, the data subject, complained about a loan taken in its name, which started an internal investigation. Such investigation revealed that an employee of the controller unlawfully used the data subject’s personal data collected in the context of a prior application which was however withdrawn by the data subject. Moreover, the controller’s employee withdrew cash, conducted bank transfers on behalf of several data subjects, changed contact details, operated Smart banking operations without data subjects’ consent, and, during this process, affected multiple categories of personal data. In this context, the controller also admitted that two employees sent confidential information about a data subject’s transaction on Facebook, Messenger and WhatsApp to a former employee, who subsequently shared it to the data subject’s relatives. The DPA considered that the controller did not implement sufficient measures to ensure that any employee having access to personal data does not process them except at the controller’s request. In fact, it was the lack of measures that led to the unauthorized access and unauthorized disclosure of personal data transmitted, stored or processed. Therefore, the DPA found a violation of Article 32(1)(2) and Article 32(4) GDPR and, as such breaches happened between 2015 to beginning of 2023 deemed it appropriate to fine the controller RON 99,466 (€20,000).

Details

Fine Date

20 October 2024

Authority

Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal

Fine Amount

€19,893

99,466 RON

GDPRhub ID

gdprhub-8619

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Raiffeisen Bank S.A - Romania (2024). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: