# Bank of Ireland 365: Insufficient technical and organisational measures to ensure information security

- Type: Enforcement
- Source: Data Protection Authority of Ireland
- Date: 2023-02-27
- Original: https://www.enforcementtracker.com/ETid-1696
- Canonical: https://overview.legal/posts/47811
- Topics: Data Breaches, Security, Privacy by Design & Default, Insurance, Processing Agreement, Personal Data, Supervisory Authorities

## Summary

The Irish DPA has fined Bank of Ireland 365 EUR 750,000. The bank had notified the DPA of 10 data breaches linked to the bank's app. Unauthorized persons had managed to gain access to the app as well as to other individuals' accounts. The DPA determined that this data breach was facilitated due to the bank's failure to implement appropriate technical and organizational measures to protect personal data.

## Full text

The Irish DPA has fined Bank of Ireland 365 EUR 750,000. The bank had notified the DPA of 10 data breaches linked to the bank's app. Unauthorized persons had managed to gain access to the app as well as to other individuals' accounts. The DPA determined that this data breach was facilitated due to the bank's failure to implement appropriate technical and organizational measures to protect personal data.

GDPR Articles: Art. 5 (1) f) GDPR, Art. 32 (1) GDPR
Industry: Finance, Insurance and Consulting

---
Generated by overview.legal · https://overview.legal/posts/47811 · 2026-08-22
