# Bankia S.A.: Non-compliance with general data processing principles

- Type: Enforcement
- Source: Spanish Data Protection Authority (aepd)
- Date: 2020-08-28
- Original: https://www.enforcementtracker.com/ETid-385
- Canonical: https://overview.legal/posts/46500
- Topics: Personal Data, Insurance, IP Address, Processing, Supervisory Authorities

## Summary

The bank kept personal data of a data subject for several years, even after the data subject was no longer a customer. The data was also accessible to bank employees during this time. This constituted a violation of the principle of purpose limitation.

## Full text

The bank kept personal data of a data subject for several years, even after the data subject was no longer a customer. The data was also accessible to bank employees during this time. This constituted a violation of the principle of purpose limitation.

GDPR Articles: Art. 5 (1) b) GDPR
Industry: Finance, Insurance and Consulting

---
Generated by overview.legal · https://overview.legal/posts/46500 · 2026-08-22
