Commissioner (Cyprus) - Housing Finance Corporation

From GDPRhub
Commissioner - Housing Finance Corporation
Authority: Commissioner (Cyprus)
Jurisdiction: Cyprus
Relevant Law: Article 5(1)(d) GDPR
Article 5(1)(e) GDPR
Article 24(1) GDPR
Type: Complaint
Outcome: Upheld
Started:
Decided: 10.03.2025
Published:
Fine: 10.000 EUR
Parties: Housing Finance Corporation
National Case Number/Name: Housing Finance Corporation
European Case Law Identifier: n/a
Appeal: Unknown
Original Language(s): Greek
Original Source: Commissioner for Personal Data Protection (in EL)
Initial Contributor: Le

The DPA fined a bank €10,000 for storing inaccurate data of the data subject beyond the statutory retention period. As well as for failing to implement meaningful and effective measures to ensure compliance with the GDPR.

English Summary

Facts

The controller is ‘Housing Finance Corporation’ (Οργανισμός Χρηματοδοτήσεως Στέγης), a bank specialised in the provision of long-term loans relating to housing, education, and health.


In 2023, the data subject filed an application to the controller for a loan (third loan). The data subject was informed by letter that his application had been rejected due to a non-performing loan he had received several years ago (first loan). The letter also mentioned that, according to the controller’s system, a previous loan application dated in 2020 that had been rejected for the same reason (second loan).

The data subject filed a complaint before the DPA (Commissioner for Personal Data Protection). He stated that he had settled the alleged non-performing loan in 2020, as demonstrated from the database of the credit information agency ‘Artemis’. This loan should not have been included in the data maintained by the controller. He also claimed that the data about the second loan application shouldn’t have been retained for more that 6 months, as described in the controller’s privacy policy.


The controller informed the DPA that, with regard to the electronic registration of applications and the process of deleting information and electronic attachments, there was no automated setting in the system and, in such cases, any action had to be performed by an official who had access to the application system for each document/item individually. It maintained that the serious shortage of human resources made this task more difficult. It also claimed that this created a time-consuming process that was prone to human error.


Regarding the retention of the data about the rejection of the second loan application, the controller claimed that it did not keep the data, instead, the members of its credits committee remembered this information and took it into consideration for the rejection of the third loan application. Finally, it claimed that a reference to the rejection of the second loan application was included in the rejection letter of the third loan application by mistake.

Holding

The DPA found that the controller breached Article 5(1)(d) GDPR, Article 5(1)(e) GDPR and Article 24(1) GDPR.


First, the DPA held that the controller failed to implement meaningful and effective technical and organisational measures to ensure compliance with the GDPR, according to Article 24 GDPR. Instead, its approach was limited to written policies without practical implementation. The inability of the controller to delete data on the grounds of technical or organisational difficulties does not relieve it of its compliance obligations.

Second, the DPA found that the rejection letter of the third loan application included a detailed analysis of the reasons for rejection of the second loan application. This analysis demonstrated that the rejection was based on information that remained available and accessible on the controller’s application system beyond the statutory six-month retention period. Also, even though data regarding the non-performing loan had been lawfully deleted from the Artemis data base, as the loan had been paid off in full, it still remained available in the controller's database. The DPA found that the controller should have deleted the data because it was inaccurate. Therefore, the DPA ruled that the controller violated the principles of accuracy (Article 5(1)(d) GDPR) and storage limitation (Article 5(1)(e) GDPR).

The DPA imposed an administrative fine in the amount of €10,000 to the controller. In addition, it ordered the immediate deletion of all data of the data subject stored beyond the statutory retention period and the implementation of appropriate and effective technical and organisational measures within 6 months of receipt of the decision.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Greek original. Please refer to the Greek original for more details.

No. Fax.: XXXXXXXXXXXXXXXXXX Tel. No.: 22 818456 Fax. No.: 22 304565 March 10, 2025 Housing Finance Organization Attention: Ms. XXXXXX Data Protection Officer dpo@hfc.com.cy DECISION Regarding the retention of data beyond the legal retention period of the complainant XXXXXX by the Housing Finance Organization Based on the duties and powers conferred on me by Article 57(1)(f) of Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter, “the GDPR”), I examined a complaint submitted to my Office, on 24/10/24, on behalf of Mr. XXXXXX (hereinafter, “the Complainant”), against the Housing Finance Organization (hereinafter, “the Respondent of the complaint”), regarding the retention of his data beyond the legal retention period in violation of the provisions of the Regulation. Based on the investigation, I found a violation of the Regulation by the Respondent and, therefore, I issue this Decision. 2. Facts of the Case 2.1 Allegations of the Complainant 2.1.1. On 17/XX/23, the Complainant together with his partner XXXXX, registered an application for a housing loan. 1 2.1.2. After months of waiting and continuous updates of their information, the Complainant was informed by telephone by Messrs. XXXXX and XXXXX that their application was rejected due to the Complainant's credit behavior in relation to the repayment of a loan he had with another ACI, which was non-performing. 2.1.3. During his telephone conversation with Mr. XXXXX, the Complainant was informed that in the system of the Respondent, the complaint appeared his previous application for a loan, dated 17/XX/2020, which had also been rejected for the same reason as his application in 2023. During the conversation, the Complainant requested a copy of the said application, a request that was not granted. At a later stage, the Complainant received a response that the application could not be located in the file, with only the letter of rejection of the application available. 2.1.4. The above was also communicated through a written letter, dated 08/XX/2024, which was addressed to both him and his partner, XXXXX, a copy of which we have in our possession. 2.1.5. According to the information provided to our Office, the Complainant himself proceeded with the full repayment of the non-performing loan he held with another ACI in early February 2020. This repayment is confirmed by the data maintained in the “Artemis” electronic system. Therefore, the said loan should not have been included in the data maintained by the Respondent of the complaint, nor should it have been taken into account during the assessment of the loan application of 17/XX/2023. 2.1.6. The Complainant argues that the previous loan application should not have been maintained in the files of the Respondent of the complaint for a period longer than six (6) months from the date of its rejection. It claims that its retention beyond this period constitutes a violation of the data retention policy established by the Respondent of the complaint for prospective customers, as described on page 3 of the Privacy Statement, which is posted on the official website of the Respondent. 2.2. Allegations of the Respondent of the complaint 2.2.1. On December 12, 2024, I sent a letter, via email, to the Respondent of the complaint, asking him to state his allegations, on those of the Complainant and to inform my Office, regarding the following: 2.2.2. The reason why the data in question (the initial loan application and the information regarding the non-performing loan that the Complainant held with another ACI) were retained beyond their legal retention period, with the result that these data were taken into account when evaluating the second loan application and constituted the reasons for its rejection, and 2.2.3. Information on the internal procedures of the Respondent of the complaint governing the updating of the data retained for prospective and existing 2 customers, which are drawn from the electronic system "Artemis", as well as the procedures applied for the secure deletion of personal data of prospective and existing customers after the expiry of their legal retention period. 2.3. In a reply letter dated 9 January 2025, the Respondent of the complaint stated the following: 2.3.1. The hard copy of the documents submitted by the Complainant in the context of the first loan application of 2020 were not available and had already been destroyed in accordance with the procedures and security controls implemented by the Respondent. 2.3.2. Regarding the electronic registration of applications and the process of deleting information and attachments in electronic form, the Respondent notes that there is no automated regulation in the system and in these cases, any action should be performed by an officer who has access to the application system for each record/element individually. Therefore, the Respondent notes the complaint, it is a time-consuming process and prone to the risk of human error since it cannot be done automatically. The serious lack of human resources, the Respondent states, makes this task more difficult. Finally, he notes that the automation of the said procedure is something that he hopes will be resolved with the technological upgrade of the systems of the Respondent the Complaint. He also adds that the right to access and process the said system also includes the members of the Credit Committee of the Respondent the Complaint (department responsible for the evaluation of applications and grants) who record comments related to their decisions (approval/rejection) on each application separately. 2.3.3. As regards the telephone communications that the Complainant had with the Respondent the Complaint, these are not recorded. According to information from the staff involved in the Complainant the Complaint, the Complainant has never had contact with the General Manager of the Respondent the Complaint Mr. XXXXXX, but repeated telephone calls were made (both by the Complainant and by his relative) to members of staff, trying to influence the decision through their personal relationships, something that also happened during the first loan application of 2020, which allowed two members of the Credit Committee to accurately remember the reasons for rejection and the history of the initial 2020 application and therefore recorded it in the system during the 2023 loan application. The Respondent notes that by mistake the said comments were included in the rejection letter dated 8/XX/2024 that the Complainant provided to my Office. 2.3.4. Finally, the Respondent notes that although the data on the non-performing loan had been deleted from the “Artemis” electronic system, the information and knowledge of the members of the Credit Committee regarding the previous rejection 3 contributed to the final evaluation of the new loan application and did not constitute the only reason/factor that substantiated the rejection decision. 2.3.5. In addition to what he mentioned above, the Respondent submitted to my Office for review the following documents: (a) the Respondent’s Data Retention Policy and (b) an excerpt from the Respondent’s Anti-Money Laundering and Anti-Terrorism Financing Manual which contains a reference to the process for updating existing customer data. 2.4. Prima facie Decision 2.4.1 In the light of all the elements, as presented before me and based on the powers conferred on me by Articles 58 and 83 of the GDPR, on 22 January 2025, I concluded that there is a prima facie infringement of Articles 5(1)(d), (e) and 24(1) of the Regulation by the Respondent to the complaint. The Prima facie Decision was notified to the Respondent to the complaint, on the aforementioned date. 2.4.2 In the context of the right to be heard, provided for by Article 43 of the General Principles of Administrative Law Law of 1999, Law 158(I)/1999, as amended, I invited the Respondent to the complaint within 4 weeks from the receipt of the said Decision, to inform me, for what reasons it believes that no corrective measure or administrative sanction and/or any mitigating factors should be imposed, before I proceed to issue a Decision, pursuant to Article 58(2) of the GDPR. 2.4.3 Furthermore, I requested that I be informed of the turnover of the Respondent to the complaint, for the previous financial year, as well as the number of its employees. 2.4.4. On 19 February 2025, I received the Respondent's submissions on the prima facie Decision. 2.4.5. In its reply letter, the Respondent reiterated its commitment to ongoing compliance with the principles governing the processing of personal data. In this context, it stated that it has developed and implemented relevant policies and procedures, as well as technical and organizational security measures, in order to ensure its compliance with these principles. 2.4.6. Following careful consideration of the issues raised by my Office in the initial Decision of 22 January, the Respondent has decided to take the following corrective measures: (a) The Respondent is in negotiations with a software provider for recording data and documents in relation to applications for the provision of facilities to make the required improvements, which include, among others: 4 I. The automation of deletions of all submitted and/or submitted data and documents in relation to applications for the provision of credit facilities that were rejected and 6 months have passed or where the interested parties have withdrawn their interest.  II. The anonymization of documents and data concerning and/or related to rejected applications for credit facilities - rejection letters. In this regard, the Respondent of the complaint states that the software supply company has received the specifications of the requirements, however, the completion of these changes is subject to the approval of the 2025-2027 GFSF budget by the House of Representatives. (b) review of existing accesses with possible minimization of the competent officers, and (c) review of the Personal Data Retention Policy and the implementation of controls and improvements to ensure compliance with the requirements of the Regulation. 2.4.7. The Respondent informed my Office that its audited turnover for the year preceding the complaint, namely 2023, amounted to XXXXX and that the number of its employees for the year 2024 amounted to XX. 2.4.8. Finally, the Respondent requested that when making my final decision I take into account the adoption and/or implementation of the above-mentioned corrective measures, the fact that the Respondent, as a public law organization, depends on institutional and administrative procedures that affect the implementation of technological improvements as well as the fact that any imposition of administrative sanctions may negatively affect the budget and, by extension, the operation of the Respondent. 3. Legal Aspect 3.1 The following are the Articles and the Reasons of the GDPR which will constitute the legal basis for the Decision in question. Article 57 of the GDPR: “1. Without prejudice to the other tasks set out in this Regulation, each supervisory authority shall, on its territory, (a) monitor and enforce the application of this Regulation, […] (f) handle complaints lodged by the data subject […]”. Article 4 of the GDPR: “1) ‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, psychological, economic, cultural or social identity of that natural person; 2) ‘processing’ means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination with other data subjects; combination, restriction, erasure or destruction, […] 7) ‘controller’ means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; […]”. Article 5 of the GDPR “1. The personal data: (d) are accurate and, where necessary, kept up to date; all reasonable steps must be taken to ensure that personal data which are inaccurate, having regard to the purposes of the processing, are erased or rectified without delay (‘accuracy’); (e) are kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods, […] and provided that the appropriate technical and organisational measures required by this Regulation to safeguard the rights and freedoms of the data subject are implemented (‘storage limitation’); 2. The controller shall be responsible for and shall be able to demonstrate compliance with paragraph 1 (‘accountability’). Recital 78 of the GDPR: “ […] In order to ensure that personal data are not kept longer than necessary, the controller should set time limits for their erasure or for their periodic review. Every reasonable step should be taken to ensure that inaccurate personal data are rectified or erased. […]”. Article 6 of the GDPR: 6 “1. Processing is lawful only if and to the extent that at least one of the following conditions applies: b) processing is necessary for the performance of a contract to which the data subject is a party or in order to take steps at the data subject's request prior to entering into a contract, c) processing is necessary for compliance with a legal obligation to which the controller is subject, d) processing is necessary to protect the vital interests of the data subject or of another natural person, e) processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, unless such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require the protection of personal data, in particular where the data subject is a child. Article 24 of the GDPR: "1. Taking into account the nature, scope, context and purposes of the processing and the risks of varying likelihood of severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organisational measures to ensure and be able to demonstrate that the processing is carried out in accordance with this Regulation. Those measures shall be reviewed where necessary […]”. Recital 74 of the GDPR: “ […]. In particular, the controller should be required to implement appropriate and effective measures and be able to demonstrate the compliance of processing activities with this Regulation, including the effectiveness of the measures. Those measures should take into account the nature, scope, context, purposes of the processing and the risk to the rights and freedoms of natural persons”. Article 58(2) GDPR: “Each supervisory authority shall have the following corrective powers: 7 (d) to order the controller or the processor to bring the processing operations into compliance with this Regulation, where necessary, in a specific manner and within a specified time limit […]”. (g) to order the rectification or erasure of personal data […] (i) to impose an administrative fine pursuant to Article 83, in addition to or instead of the measures referred to in this paragraph, depending on the circumstances of each individual case […]”. Article 83 GDPR: “1. Each supervisory authority shall ensure that the imposition of administrative fines in accordance with this Article for infringements of this Regulation referred to in paragraphs 4, 5 and 6 is, in each individual case, effective, proportionate and dissuasive. 2. Administrative fines, depending on the circumstances of each individual case, shall be imposed in addition to or instead of the measures referred to in points (a) to (h) of Article 58(2) and point (j) of Article 58(2). When deciding on the imposition of an administrative fine, as well as on the amount of the administrative fine in each individual case, due account shall be taken of the following: (a) the nature, gravity and duration of the infringement, taking into account the nature, scope or purpose of the processing concerned, as well as the number of data subjects affected by the infringement and the degree of damage suffered by them; (b) the intent or negligence which caused the infringement; (c) any action taken by the controller or processor to mitigate the damage suffered by data subjects; (d) the degree of responsibility of the controller or processor, taking into account the technical and organisational measures implemented pursuant to Articles 25 and 32; (e) any relevant previous infringements by the controller or processor; (f) the degree of cooperation with the supervisory authority. to remedy the breach and limit its likely adverse effects, g) the categories of personal data affected by the breach, h) the manner in which the supervisory authority was informed of the breach, in particular whether and to what extent the controller or processor notified the breach, i) where measures referred to in Article 58(2) have previously been ordered against the controller or processor concerned in relation to the same subject matter, compliance with those measures, j) adherence to approved codes of conduct in accordance with Article 40 or approved certification mechanisms in accordance with Article 42 and 8, k) any other aggravating or mitigating factors arising from the circumstances of the specific case, such as the financial benefits gained or losses avoided, directly or indirectly, as a result of the breach. 3. Where the controller or processor, for the same or related processing operations, infringes several provisions of this Regulation, the total amount of the administrative fine shall not exceed the amount specified for the most serious infringement.  4. Infringements of the following provisions shall, in accordance with paragraph 2, be subject to administrative fines of up to EUR 10 000 000 or, in the case of undertakings, up to 2 % of the total worldwide annual turnover of the preceding business year, whichever is higher: (a) the obligations of the controller and the processor pursuant to Articles 8, 11, 25 to 39 and 42 and 43; (b) the obligations of the certification body pursuant to Articles 42 and 43; (c) the obligations of the monitoring body pursuant to Article 41(4). 5. Infringements of the following provisions shall, in accordance with paragraph 2, be subject to administrative fines of up to EUR 20 000 000 or, in the case of undertakings, up to 4 % of the total worldwide annual turnover of the preceding business year, whichever is higher: (a) the basic principles for the processing, including the conditions applicable to the consent, in accordance with Articles 5, 6, 7 and 9, (b) the rights of data subjects in accordance with Articles 12 to 22, (c) the transfer of personal data to a recipient in a third country or to an international organisation in accordance with Articles 44 to 49, (d) any obligations under Member State law established pursuant to Chapter IX, (e) failure to comply with an order or with a temporary or definitive restriction of processing or with a suspension of data flows imposed by the supervisory authority pursuant to Article 58(2) or failure to provide access in breach of Article 58(1). […]” Recital 148 of the GDPR: “(148) In order to strengthen the enforcement of the rules of this Regulation, penalties, including administrative fines, should be provided for for any infringement of this Regulation, in addition to or instead of of the appropriate measures imposed by the supervisory authority in accordance with this Regulation. In the case of a minor infringement or where the fine that may be imposed would constitute a disproportionate burden on a natural person, a reprimand could be imposed instead of a fine. However, due account should be taken of the nature, gravity and duration of the infringement, the intentional nature of the infringement, the actions taken to mitigate the damage, the degree of liability or any other relevant previous infringements, the manner in which the supervisory authority became aware of the infringement, compliance with the measures against the controller or processor, adherence to a code of conduct and any other aggravating or mitigating factors. The imposition of sanctions, including administrative fines, should be subject to appropriate procedural guarantees in accordance with the general principles of Union law and the Charter, including effective judicial protection and due process. "Relevant are also the Instructions of my Office to all Licensed Credit Institutions operating in the Republic for determining the retention period of customer/associated persons/guarantors data (No. 1/2017) and Supplementary Instructions (No. 2/20217), dated 8/08/2017 and specifically Part D - INSTRUCTIONS REGULATIONS, paragraph 2, which states that: "Special regulation regarding prospective customers: The retention period of the data of par. 3. of part C. of the Guidelines is set at 6 months from the notification of the rejection of their request or from the withdrawal of their request. 4. Rationale: 4.1. From the study of the documents attached by the Respondent to the complaint and specifically the Data Retention Policy (hereinafter the “Policy”), the following are noted: (a) The Policy was put into effect from 01/02/2023. (b) According to paragraph 2.2. of the Policy, its purpose is to determine the required conditions regarding the duration of data retention as well as their destruction (deletion/anonymization) after the purpose of the processing has been fulfilled and provided that there is no legal obligation to maintain them. (c) According to paragraph 2.3. of the Policy - Roles and Responsibilities, the Technology and Process Development Department ("TPD") must be aware of the Respondent's obligations regarding data retention and deletion arising from the applicable legislative framework, to ensure that the Respondent maintains an effective data retention and deletion system, and is also responsible for the Respondent's compliance with all provisions of the Policy. At the same time, the Data Protection Officer of the Respondent reviews the Policy and submits to the Regulatory Compliance Unit suggestions for its improvement, while informing the Management in case of weaknesses identified during the implementation of the Policy. (d) In accordance with paragraph 3.3. of the Policy - Determination of Retention Periods, the data collected from the Respondent of the Complaint are retained only for specific periods of time and are subsequently anonymized and destroyed if the purpose of the processing is fulfilled and if there is no legal obligation to retain them. Exceptions to the retention periods, listed in the relevant Table of Annex A of the Policy, apply in the following cases: 10 I. There is a legal obligation to change the retention period of the specific data category. II. There is a legitimate interest of the Respondent of the Complaint to raise, prove or defend legal claims related to the products and services it offers, III. The extension of the data retention period is required for accounting, tax or audit purposes. IV. The retention of the data is required to protect a legitimate interest of an employee of the Respondent of the Complaint. V. The retention of data is required to protect the legitimate interest of the Respondent to whom the complaint is made. (e) According to paragraph 4.1. of the Policy - Categories of Data to be deleted/destructed, the procedures for deleting/destructing data concern the following types of data: I. […] Data in structured electronic format (database). (f) According to paragraph 4.2. of the Policy - Deletion/Destruction of data in the OGFS, data that is received/created and used in the context of performing daily tasks is destroyed if the tasks have been completed and their retention is no longer required. The specific data may, among others, include copies of agreements, draft notes/reports and other information material, both in printed and electronic form. It is understood that internal correspondence and notes should be retained for the same period as the documents to which they refer. (g) In accordance with paragraph 5. of the Policy – Compliance with the Data Retention Policy, Risks of Non-Compliance, any violation of the Policy entails an increased risk of compliance which may, among others, include: I. Imposition of sanctions against the Respondent of the complaint. II. Imposition of a fine on the Respondent of the complaint. III. Damage to the reputation of the Respondent of the complaint. IV. Legal proceedings against the Respondent of the complaint. (h) In accordance with Annex A of the Policy – Data Retention Periods, point 5 for Prospective Clients (those who are in the process of becoming clients of the HFSF and there is no business relationship yet, the retention period is set at 6 months from the date of rejection or withdrawal of interest, or 6 months from the date of initial interest if no comments were received from the client. 4.2. With regard to the position of the Respondent of the complaint, and in particular the difficulty in deleting data from the electronic loan application registration system, due to the non-automated operation of the system and the lack of human resources (paragraph 2.3.2 above), it is noted that, in accordance with the provisions of article 24 of the Regulation, it is the obligation of the Respondent of the complaint to implement appropriate technical and organizational measures to ensure compliance with the requirements of the Regulation. This compliance does not depend on technical limitations or lack of resources, as the Regulation requires the provision of appropriate measures from the beginning of the design of processing procedures (privacy by design) and data protection by default 11 (privacy by default). The inability of the Respondent to the complaint to delete data citing technical or organizational difficulties does not relieve its obligation to comply with the Regulation, given that these responsibilities are fundamental and aim at the effective protection of the rights of natural persons. 4.3. In relation to the position of the Respondent to the Complaint, as formulated in paragraph 2.3.3 above, and specifically the statement that “two members of the Credit Committee accurately remembered the reasons for rejection and the history of the initial 2020 application, and therefore recorded it in the system during the 2023 loan application”, it is noted that the content of the letter, which was sent to the Complainant and his partner on 08/XX/2024, includes a detailed analysis of the reasons for rejection of the 2020 loan application. This analysis demonstrates that the rejection was not based only on the rote knowledge of the members of the Credit Committee, but also on information concerning the Complainant, which remained available and accessible in the Complainant’s application system, beyond the legal retention period of six months. 4.3.4. The above understanding is further reinforced by the statement of the Data Protection Officer, Ms. XXXXXX, as referred to in paragraph 4 of her response letter, dated 9 January 2025, where it is noted that the specific comments (i.e. the comments recorded by the Committee members in the system and linked to their decisions (approval/rejection) on each application separately), were included by mistake in the rejection letter, dated 8/XX/2024.
4.3.5. With regard to the statement of the Data Protection Officer, Ms. XXXXX, as recorded in paragraph 5 of her reply letter dated 9 January 2025, and in particular the observation that, although the data relating to the non-performing loan had been deleted from the “Artemis” electronic system, the knowledge and information held by the members of the Credit Committee regarding the previous loan rejection contributed to the final assessment, without however constituting the sole reason for rejection, I note that my Office does not examine the correctness or otherwise of the decision to reject the Complainant’s loan application. I focus, however, on the fact that
the Complainant’s personal data, which had been lawfully deleted from
the “Artemis” system, appear to have remained available in the Complainant’s database, in violation of the provisions of Article 5(1)(d) and (e) of the Regulation.
4.3.6. Taking into account everything that has been analyzed in the Reasons of the prima facie Decision,
I have reached the general conclusion that the Complainant’s compliance with the
obligations arising from Articles 5(1)(d), (e) and 24(1) of the Regulation remains
at a theoretical level, limited to written policies, without being accompanied by
substantial and effective practical implementation.
4.3.7. Regarding the corrective measures that the Respondent has decided to take, as set out in its response letter dated 19 February 2025, I note the following:
12
I. Regarding the first measure and the decision of the Respondent to proceed with negotiations with a software supplier, with the aim of automating the deletion of the submitted and submitted data relating to applications for credit facilities—which were either rejected and six months have passed or were withdrawn by the interested parties—I note that,
although the said measure is positive as a step in the right direction,
it is considered insufficient and ineffective for the following reasons. Firstly,
the proposed measure is not accompanied by a clear and binding implementation timetable, which creates uncertainty as to its effective
implementation. Secondly, the lack of immediate and substantial amendments to the existing process for managing the data in question leaves room for continued non-compliance. Furthermore, the dependence of the implementation of these measures on administrative approvals and budgetary procedures cannot be considered a reason for delays, as the obligations arising from the Regulation have been in force since 2018. Consequently, any further postponement of full compliance is considered unjustified. The immediate adoption of substantial and binding measures is absolutely necessary to ensure the compliance of the Respondent with its obligations under the Regulation. II. With regard to the second proposed measure, which concerns the review of existing accesses and a possible reduction of the competent officers, reservations are expressed as to its effectiveness in relation to the violation of Article 5(1)(d) of the Regulation. From the examination of the information brought to my attention, no unauthorized or excessive accesses to personal data were found. On the contrary, inaccurate data were identified, which remained available and accessible beyond the legal retention period in the systems of the Respondent of the complaint. Therefore, the specific measure does not ensure the accuracy and updating of the data, which is a basic requirement of Article 5(1)(d) of the Regulation. Consequently, it does not respond to the essential compliance needs that have been identified. III. Regarding the third and final measure, which concerns the revision of the Respondent's Personal Data Retention Policy, it is noted that it constitutes a reasonable and necessary step, given the discrepancies that have been identified. However, this revision cannot be limited to a simple revision of documents and procedures, but must be accompanied by a clear, binding and enforceable implementation plan. According to Article 24(1) of the GDPR, the Respondent is responsible for implementing appropriate technical and organizational measures in order to ensure and demonstrate that the processing of personal data complies with the Regulation. Such compliance cannot remain at a theoretical level or be limited to the formulation of policies that are not implemented in practice. Therefore, the revision of the Personal Data Retention Policy should be directly linked to the effective and effective implementation of new measures.
13
5. Conclusion
5.1. In the light of the evidence before me and based on the powers conferred on me by Articles 58 and 83 of the GDPR, I find that there has been a violation of the provisions of Articles 5(1)(d), (e) and 24(1) of the GDPR.
5.2. Taking into account, among others:
a. The failure of the Respondent to demonstrate that the rejection of the Complainant’s application was not based solely on the memory of the members of the Credit Committee, but on legally available information. On the contrary, it appears that the Complainant's personal data remained available and accessible in the Complainant's application system beyond the statutory retention period of six months, in violation of the provisions of the Regulation. b. The lack of implementation of effective and efficient technical and organizational measures to ensure compliance, with the Complainant's approach being limited to written policies without practical implementation. Invoking lack of resources and understaffing as a justification for non-compliance cannot be considered a reason, as the Regulation requires the controller to adopt appropriate measures, regardless of internal, administrative or financial constraints. 5.3. Having heard the Respondent and with regard to the mitigating factors and the reasons why he believes that he should not be imposed on any corrective measure or administrative sanction, as provided for in the provisions of Article 58(2) of the GDPR, I have assessed the following: Mitigating / Mitigating factors: a. The cooperation of the Respondent with my Office. b. The nature of the complaint. c. The categories of data affected by the breaches. d. The existence of a documented personal data retention policy. Aggravating factors: a. The failure of the Respondent to implement appropriate technical and organizational measures to ensure the practical compliance with the personal data retention policy, which resulted in the retention of the Complainant’s data beyond the legal period. b. The failure of the Respondent to demonstrate its compliance with the provisions of the Regulation and to refute the findings indicating violations.
c. The adoption of corrective measures without a clear and binding implementation plan, with the justification that full compliance with the obligations of the Regulation depends on the
14 availability of financial resources, despite the fact that the requirements of the Regulation
have been in force since 2018 and constitute a fundamental obligation of the Respondent to the complaint.
5.4. Taking into account the circumstances surrounding the present case and
exercising the powers granted to me under the provisions of Articles 58(2)(i)
and 58(2)(g) of the GDPR, I consider it entirely reasonable, proportionate and justified to
impose the administrative sanctions of the fine and the order.
5.5. I DECIDE as follows:
I impose on the Respondent the complaint,
An administrative fine of €10,000 (Ten Thousand Euros).
Order for the immediate deletion, within 10 days of receipt of this
Decision, of all data of the Complainant that are still available
and accessible in the electronic credit facilities management system, beyond the
legal retention period.
Order for the implementation, within 6 months from the receipt of this Decision, of appropriate and effective corrective technical and organizational measures, with the aim of restoring the identified violations and ensuring full compliance of the procedures with the requirements of the Regulation. Upon completion of the measures, my Office is required to be informed of the violation by him of Articles 5 (1) (d), (e) and 24 (1) of the Regulation.
Irini Loizidou Nikolaidou
Personal Data Protection Commissioner