logo

Dutch SA Sanctions Credit Card Company for Failure to Perform Data Protection Impact Assessment

ID: 9881e4a5-68fe-5a89-9306-3a60c2b579a1

STIX ID: report--9881e4a5-68fe-5a89-9306-3a60c2b579a1

Feed Name: DataBreaches.Net

Date Published: 2024-01-23

Date Updated: 2026-05-13

Author: Dissent

...
...

In December 2023 the Dutch Supervisory Authority fined a credit card company €150,000 for failing to perform a GDPR-required Data Protection Impact Assessment for its identification and verification process, which involved large-scale processing (1.5 million customers) and sensitive personal data (names, DOB, place of birth, government ID numbers, photos, contact details). The SA determined the DPIA was required under EDPB guidance because the processing met multiple criteria for high-risk processing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.