PrivacyDesigner’s Post

View organization page for PrivacyDesigner, graphic

5,297 followers

Swedish DPA IMY fines Avanza Bank AB 15 million SEK (around 1.3m€) for using Meta Pixel on its website without implementing proper technical and organizational measures, leading to unauthorized transfer of personal data, including personal IDs and financial information, to Meta (Facebook). IMY received a breach notification from Avanza Bank AB in 2021. The notification showed that personal data of 500k – 1 million data subjects was erroneously transferred to Facebook (now Meta). Among the data transferred were social security numbers, loan amounts and account number. From the investigation of the case IMY found that personal data of bank's customers and website visitors were transferred to Meta. The personal data transferred has included, among other things social security numbers and extensive financial information. The information, including detailed information about customers' finances, has in several cases been transmitted in plain text. IMY notes that the data subjects have legitimate expectations of a high degree of confidentiality and a robust protection against unauthorized access. The data transferred has been covered by statutory duty of confidentiality. The processing of personal data has taken place within the framework of the bank's core business, which entails even higher requirements for the level of protection. Link in the comments!

To view or add a comment, sign in

Explore topics