Home / Business and Politics / AZOP: B2 Kapital fined 2.26 million euros for violation of GDPR regulation

AZOP: B2 Kapital fined 2.26 million euros for violation of GDPR regulation

The Agency for Personal Data Protection (AZOP) has fined the debt collection agency B2 Kapital d.o.o. 2.265 million euros as the data controller for established violations of the General Data Protection Regulation (GDPR), the agency reported on Thursday.

– In this specific case, it concerns violations of several provisions of the General Data Protection Regulation-GDPR by one of the leading companies in the field of debt collection, which should not have allowed itself to process personal data of a large number of respondents in a non-transparent and insecure manner -, AZOP stated.

This administrative monetary fine was imposed on B2 Kapital because the data controller did not clearly and accurately inform its respondents about the processing of their personal data through the notice on personal data processing (privacy policy), regarding the legal basis for the return of overpaid funds, which is contrary to the provision of Article of the general GDPR regulation.

This also led to non-transparent processing of personal data of respondents or incorrect information regarding the legal basis for processing from the article of that regulation, of which there were (at least) 132,652 at the time of the inspection, and the privacy policy remained unchanged, and the violation has not yet been remedied and has lasted from May 25, 2018, to the present day, AZOP stated.

– It is also contrary to the regulation that the data controller did not conclude a contract for the processing of personal data with the processor for the service of monitoring simple consumer bankruptcy – AZOP added, explaining that this endangered the security of personal data of 83,896 respondents (OIB), since concluding a contract with the processor is one of the security levers that ensures that the rules for processing personal data are clearly agreed upon.

It was also established that the mentioned violation lasted from the acceptance of the offer for providing the service of monitoring simple consumer bankruptcy, i.e., from February 14, 2019, to February 26, 2021, when the business cooperation was terminated.

AZOP also states that this data controller did not take appropriate technical and organizational measures to protect personal data processing, which is also contrary to the regulation, and thus there was a violation of the security of personal data of all respondents, at least 132,652 at the time of the inspection.

These are data such as names and surnames, dates of birth, OIB, but also others that are recorded in the storage systems of the debt collection agency, which are of a financial nature and thus quite sensitive.

Failure to take technical protection measures

In the inspection process, AZOP also determined that the violation of the regulation has lasted at least since 2019 and has not yet been remedied, all due to the failure to take appropriate protection measures.

In AZOP, they received an anonymous complaint in December 2022, stating that there had been unauthorized processing of a large number of personal data of physical persons-debtors by the debt collection agency, and a USB stick was attached containing personal data in the structure of name and surname, date of birth, and OIB for a total of 77,317 physical persons, who had outstanding debts to credit institutions, which were purchased by the debt collection agency based on a contract of assignment.

At that time, AZOP, based on official duty, initiated an inspection in which the mentioned violations of the regulation were established due to negligent conduct by the data controller (debt collection agency).

– The data controller bears the highest degree of responsibility for failing to take technical protection measures, as it was precisely due to deficiencies in such a security system that there was insecure processing of a large number of personal data. AZOP lost complete control over the movement of personal data of their respondents and could not explain the causes of unauthorized exfiltration (extraction) of personal data – AZOP stated.

There were, they say from AZOP, also aggravating circumstances in the conducted administrative procedure due to deficiencies in cooperation, as in several letters sent to that data controller, responses were received just before the last days of the set deadline, and letters were sent for the purpose of extending the deadline and clarifying the requested circumstances. This somewhat affected the prolongation of the procedure, as well as the fact that the data controller did not provide certain documentation (list of system records) despite repeated requests from AZOP.

Also, B2 Kapital has not informed AZOP to this day that it has taken additional protection measures that would prevent future risks from established violations, nor has it adjusted the privacy policy available on their websites.

– We emphasize that in this specific case, it concerns possible individual criminal liability, i.e., the commission of a criminal offense, which is under the jurisdiction of the Ministry of the Interior, which is conducting a criminal investigation within its jurisdiction -, AZOP concluded.

Tagged: