GDPR Enforcement Alert: Danske Bank Faces $1.5 million Fine for GDPR Violation

Robins Kaplan LLP
Contact

Robins Kaplan LLP

Danske Bank, Denmark’s largest bank, faces a fine of approximately $1.5 million from the Danish Data Protection Agency (DPA) for a failure to comply with the GDPR’s data deletion requirements. The GDPR requires all personal data to be deleted by service providers upon the end of services or the expiration of a legal agreement. Here, Danske Bank held customer data in excess of that. Interestingly, this fine stems from Danske Bank self-reporting this violation to the DPA back in 2020. Danske Bank believes that these violations arise from difficulties of deleting data in its complex interlocked IT systems.

This latest enforcement action from a DPA shows that businesses won’t necessarily receive a free pass for the GDPR’s stringent data deletion requirements when presented with technically complex problems such as ensuring data deletion across multiple IT systems. That includes even when self-reporting problems to a DPA. Keep tuned for further significant developments with DPA GDPR enforcement.

Sources:

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Robins Kaplan LLP | Attorney Advertising

Written by:

Robins Kaplan LLP
Contact
more
less

Robins Kaplan LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide