Raiffeisen Bank S.A – €19,893 Fine (Romania, 2024)

€19,893Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal20 October 2024Romania
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Raiffeisen Bank S.A., the controller, communicated to the Romanian DPA multiple personal data breaches. A customer, the data subject, complained about a loan taken in its name, which started an internal investigation. Such investigation revealed that an employee of the controller unlawfully used the data subject’s personal data collected in the context of a prior application which was however withdrawn by the data subject. Moreover, the controller’s employee withdrew cash, conducted bank transfers on behalf of several data subjects, changed contact details, operated Smart banking operations without data subjects’ consent, and, during this process, affected multiple categories of personal data. In this context, the controller also admitted that two employees sent confidential information about a data subject’s transaction on Facebook, Messenger and WhatsApp to a former employee, who subsequently shared it to the data subject’s relatives. The DPA considered that the controller did not implement sufficient measures to ensure that any employee having access to personal data does not process them except at the controller’s request. In fact, it was the lack of measures that led to the unauthorized access and unauthorized disclosure of personal data transmitted, stored or processed. Therefore, the DPA found a violation of Article 32(1)(2) and Article 32(4) GDPR and, as such breaches happened between 2015 to beginning of 2023 deemed it appropriate to fine the controller RON 99,466 (€20,000).

GDPR Articles Cited

Art. 32(1)(b) GDPR
Art. 32(1)(d) GDPR
Art. 32(4) GDPR
Full Legal Summary

Raiffeisen Bank S.A., the controller, communicated to the Romanian DPA multiple personal data breaches. A customer, the data subject, complained about a loan taken in its name, which started an internal investigation. Such investigation revealed that an employee of the controller unlawfully used the data subject’s personal data collected in the context of a prior application which was however withdrawn by the data subject. Moreover, the controller’s employee withdrew cash, conducted bank transfers on behalf of several data subjects, changed contact details, operated Smart banking operations without data subjects’ consent, and, during this process, affected multiple categories of personal data. In this context, the controller also admitted that two employees sent confidential information about a data subject’s transaction on Facebook, Messenger and WhatsApp to a former employee, who subsequently shared it to the data subject’s relatives. The DPA considered that the controller did not implement sufficient measures to ensure that any employee having access to personal data does not process them except at the controller’s request. In fact, it was the lack of measures that led to the unauthorized access and unauthorized disclosure of personal data transmitted, stored or processed. Therefore, the DPA found a violation of Article 32(1)(2) and Article 32(4) GDPR and, as such breaches happened between 2015 to beginning of 2023 deemed it appropriate to fine the controller RON 99,466 (€20,000).

Details

Fine Date

20 October 2024

Authority

Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal

Fine Amount

€19,893

99,466 RON

GDPRhub ID

gdprhub-8619

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Raiffeisen Bank S.A - Romania (2024). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: