ING Bank N.V. Amsterdam
€80K($86K USD)final
Date Issued
2019-11-29
Regulation
Authority
Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP)
Country
Romania
Violation Type
Failure to comply with data processing principles
Currency
EUR
Violation Summary
The Romanian branch of ING Bank N.V. Amsterdam was fined with €80,000 due to not respecting data protection principles (privacy by design și privacy by default) by not implementing adequate technical measures to ensure the protection of personal data. As a consequence of this, a total of 225,525 had their transactions doubled on debit card payments during the period of 8-10 October 2018.This is one of the bigger fines in Romania, but it’s interesting to note that for similar offenses in other countries fines of over several millions of Euros are usually awarded. This denotes again the fact that different countries have different approaches to GDPR enforcement.
Articles Violated
Art. 25 GDPR