Details:

Summary The Spanish DPA has imposed a fine on CAJA DE SEGUROS REUNIDOS, COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.. A data subject filed a complaint with the DPA. The data subject had taken out an insurance policy with the controller, the beneficiary of which was his ex-life partner at the time. After the separation, the ex-life partner asked the controller to change the debit entry for the premium from the data subject’s account to her account. The controller carried out this change without the consent of the data subject. The DPA considered this to be an unlawful change to the personal data of the data subject. The original fine of EUR 40,000 was reduced to EUR 24,000 due to voluntary payment and admission of responsibility.
Link: link
Related articles:  Art. 6 (1) GDPR
Type: Insufficient legal basis for data processing
Fine: EUR 24,000
Sector Finance, Insurance and Consulting

 

All data is based on The CMS’s Law GDPR Enforcement Tracker Source: https://www.enforcementtracker.com/

Tags: case law