Back to Cases
technologyfinance · 2024
Millennium BCP
CNPD reviewed banking customer-data governance and found shortcomings in retention and internal access controls under GDPR Articles 5, 24 and 32.
Fine Imposed€180,000.0
Authority
Comissão Nacional de Proteção de Dados
Stylebalanced
Avg. investigation15 mo
Regulation
Key Takeaways
- Banking privacy controls must cover both lifecycle retention and employee access discipline.