Lithuanian Data Protection Inspectorate Levies Fine For GDPR Data Management Violations

Fox Rothschild LLP
Contact

Fox Rothschild LLP

The Lithuanian data protection inspectorate issued a 61,500 EUR fine against a payment services provider for violations of the data minimization, adequate security measures and data breach reporting requirements of GDPR.

Key takeaways:

  • Data minimization:
    • Collect only the information you need. If you only need name, identification code, bank account number, currency, balance, purpose of payment/payment code,  then collect just that.
    • It is not necessary to also collect: date of unreported electronic invoicing, names and amounts of senders; part of message text for unread messages; purpose, nature and amounts of available loans; pension fund names, units and value; types of credit; outstanding balances; numbers of issued payment cards and amounts in them.
    • Do not retain data for longer than necessary. Here, the inspectorate held that holding data for 216 days was too long (especially when the retention term was supposed to be 10 minutes).
  • Data Breach:
    • Two (2) days of unauthorized access to personal data available on the Internet is considered as a personal data breach that must be reported.

Read more about the fine.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Fox Rothschild LLP

Written by:

Fox Rothschild LLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Fox Rothschild LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide