Bank

€500($540 USD)final

Date Issued

2018-05-12

Regulation

Authority

Bulgarian Commission for Personal Data Protection (KZLD)

Country

Bulgaria

Violation Type

Non-compliance with lawful basis for data processing

Currency

EUR

Violation Summary

The bank was fined 500 EUR for calling a client about the unresolved bills of his neighbor. The client then invoked his right to be forgotten, which the bank ignored at first. Another motion was started, and the client complained to the KZLD. Apparently, the bank hadn’t requested consent from the subject when processing his data.

Articles Violated

Art. 5 (1) b) GDPRArt. 6 GDPR

Other Fines for Bank

DateRegulationAmount (USD)Type
2022-10-05GDPR$78,300Failure to comply with data processing principles
2022-01-01GDPR--Failure to implement sufficient measures to ensure information security
2021-12-16GDPR$81,000Insufficient involvement of data protection officer
2021-10-26GDPR$410Non-compliance with lawful basis for data processing
2020-08-05GDPR$108Non-compliance with lawful basis for data processing
2020-03-26GDPR$3,121Non-compliance with lawful basis for data processing
2020-01-01GDPR--The bank made it mandatory for customers to provide a copy of their IDs when opening an account. This was unlawful.
2019-01-17GDPR$540Non-compliance with lawful basis for data processing
2019-01-17GDPR$540Non-compliance with lawful basis for data processing
2018-05-12GDPR$540Non-compliance with lawful basis for data processing