PogoWasRight.org

Menu
  • About
  • Privacy
Menu

Danish SA: fine proposed for Danske Bank

Posted on April 12, 2022June 24, 2025 by Dissent

Seen at the European Data Protection Board:

Background information

Date of final decision: 4 April 2022
Cross-border case or national case: National
Controller: Danske Bank
Legal Reference: Article 5 (2)
Decision: Infringement of the GDPR
Key words: Deletion

Summary of the Decision

Origin of the case

The Danish Data Supervisory Authority (SA) has reported Danske Bank to the Danish police and proposed a fine of DKK 10 million (app.1.3 million EUR). This concludes a case that the SA opened in November 2020 after the bank itself had stated that they had identified a problem with the deletion of personal data in which there was not necessarily a commercial justification for continuing to process.

During the Danish SA’s investigation, it has become clear that the bank in more than 400 systems has not been able to document whether rules have been laid down for deletion and storage of personal data, or whether manual deletion of personal data has been carried out. These systems process personal data of millions of people.

Key Findings

During the Danish SA’s investigation, it has become clear that the bank in more than 400 systems has not been able to document whether rules have been laid down for deletion and storage of personal data, or whether manual deletion of personal data has been carried out. These systems process personal data of millions of people. The Danish Supervisory Authority has reported Danske Bank to the police and proposed a fine of DKK 10 million (app.1.3 million EUR) for the infringement of Article 5 (2) of the GDPR.

Decision

The Danish Supervisory Authority has reported Danske Bank to the police and proposed a fine of DKK 10 million (1.3 million EUR) for the infringement of Article 5 (2) of the GDPR.

For further information: https://www.datatilsynet.dk/presse-og-nyheder/nyhedsarkiv/2022/apr/danske-bank-indstilles-til-boede (DA)


The news published here does not constitute official EDPB communication, nor an EDPB endorsement. This news item was originally published by the national supervisory authority and was published here at the request of the SA for information purposes. Any questions regarding this news item should be directed to the supervisory authority concerned.

No related posts.

Category: BreachesNon-U.S.

Post navigation

← You’re muted… or are you? Videoconferencing apps may listen even when mic is off
Would-be tribal leader who wouldn’t sign confidentiality agreement loses case →

Search

Contact Me

Email: info[at]pogowasright.org
Security Issue: security[at]pogowasright.org
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: Dissent.73
DMCA Concern: dmca[at]pogowasright.org

Research Report of Note

A report by EPIC.org:

State Attorneys General & Privacy: Enforcement Trends, 2020-2024

Categories

Recent Posts

  • FTC Denies Petition from SpyFone App CEO to Vacate 2021 Order
  • Privacy concerns raised as Grok AI found to be a stalker’s best friend
  • PRIVACY—S.D. Cal.: Employee did not waive privacy right in personal email data on company provided laptop, (Dec 5, 2025)
  • EU justice chief draws red line on privacy reforms
  • Kaiser Permanente to Pay Up to $47.5M in Web Tracker Lawsuit
  • How Palantir shifted course to play key role in ICE deportations
  • U.S. Judge Blocks Trump From Cutting Medicaid Funding For Planned Parenthood In 22 States

RSS Recent Posts at DataBreaches.net

  • Defense Bill Would Require New Cyber Requirements for Some DoD Telecom Contracts
  • Tell the truth, or someone will tell it for you — Trumbull County, Ohio edition (1)
  • US Posts $10 Million Bounty for Iranian Hackers
  • South Korea police raid e-commerce giant Coupang over data leak; govt schedules hearing
  • FinCEN Report: Reported Ransomware Incidents and Payments Reached All-Time High in 2023
©2025 PogoWasRight.org. All rights reserved.