The Agency for Personal Data Protection (AZOP) has fined the debt collection agency B2 Kapital d.o.o. 2.265 million euros as the data controller for established violations of the General Data Protection Regulation (GDPR), the agency reported on Thursday.
– In this specific case, it concerns violations of several provisions of the General Data Protection Regulation-GDPR by one of the leading companies in the field of debt collection, which should not have allowed itself to process personal data of a large number of respondents in a non-transparent and insecure manner -, AZOP stated.
This administrative monetary fine was imposed on B2 Kapital because the data controller did not clearly and accurately inform its respondents about the processing of their personal data through the notice on personal data processing (privacy policy), regarding the legal basis for the return of overpaid funds, which is contrary to the provision of Article of the general GDPR regulation.
This also led to non-transparent processing of personal data of respondents or incorrect information regarding the legal basis for processing from the article of that regulation, of which there were (at least) 132,652 at the time of the inspection, and the privacy policy remained unchanged, and the violation has not yet been remedied and has lasted from May 25, 2018, to the present day, AZOP stated.
– It is also contrary to the regulation that the data controller did not conclude a contract for the processing of personal data with the processor for the service of monitoring simple consumer bankruptcy – AZOP added, explaining that this endangered the security of personal data of 83,896 respondents (OIB), since concluding a contract with the processor is one of the security levers that ensures that the rules for processing personal data are clearly agreed upon.
It was also established that the mentioned violation lasted from the acceptance of the offer for providing the service of monitoring simple consumer bankruptcy, i.e., from February 14, 2019, to February 26, 2021, when the business cooperation was terminated.
AZOP also states that this data controller did not take appropriate technical and organizational measures to protect personal data processing, which is also contrary to the regulation, and thus there was a violation of the security of personal data of all respondents, at least 132,652 at the time of the inspection.
These are data such as names and surnames, dates of birth, OIB, but also others that are recorded in the storage systems of the debt collection agency, which are of a financial nature and thus quite sensitive.
