FineME
Run assessment
Back to Cases
technologyfinance · 2022

mBank S.A.

UODO examined mBank's customer-data retention and internal access governance, identifying minimization and security shortcomings under GDPR Articles 5 and 32.

Fine Imposed€410,000.0
Authority

Urząd Ochrony Danych Osobowych

Styleaggressive
Avg. investigation15 mo
View authority profile
Regulation

Key Takeaways
  • Banks need periodic access recertification and retention cleanup for legacy customer data.