The Romanian authority sanctions Banca Transilvania for failures in the security of personal data
Facts and context
The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) issued a sanction decision against the bank Banca Transilvania S.A., imposing a fine of 26,172 lei (approximately €5,000) for breaches of its data security obligation.
The investigation was initiated following a complaint from an individual contesting the processing of their banking data without their consent.
Grounds for the decision
- Obligation to ensure the security of processing (Article 32 of the GDPR): The authority found that a bank employee accessed the complainant's account statements without authorization, outside of their duties and at the request of a third party. This access concerned data such as name, first name, bank account number, account type, client code, transaction data, and account balances. The authority considered that the controller had not implemented appropriate technical and organizational measures to ensure a level of security appropriate to the risk, notably to ensure that employees acting under its authority only process data on its instructions. This deficiency allowed unlawful access to the data of the data subject for personal purposes.
Decision of the authority
Consequently, the authority imposed a fine of 26,172 lei (approximately €5,000) on Banca Transilvania S.A.
Furthermore, the authority ordered the operator to bring its processing operations into compliance with the GDPR. This corrective measure requires the implementation of adequate technical and organizational measures to prevent any illegal access to personal data by employees for personal purposes.
Lessons learned
This decision reminds that:
- The responsibility for securing data lies with the controller, including regarding unlawful access committed by its own employees.
- Technical and organizational measures must be specifically designed to ensure that employees only access personal data strictly within their duties and on the controller's instructions.
- Managing authorizations and controlling access to client data are essential components of the security obligation, particularly in the banking sector.
- Unauthorized access, even by an internal staff member acting for personal purposes, constitutes a data security breach attributable to the organization if preventive measures were insufficient.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire