{"id":791,"date":"2022-05-24T10:52:42","date_gmt":"2022-05-24T07:52:42","guid":{"rendered":"https:\/\/lawlorkiernan.ie\/?p=791"},"modified":"2025-02-14T10:07:08","modified_gmt":"2025-02-14T07:07:08","slug":"bank-ireland-fined-data-protection-commissioner-civil-cases-may-follow","status":"publish","type":"post","link":"https:\/\/lawlorkiernan.ie\/en\/bank-ireland-fined-data-protection-commissioner-civil-cases-may-follow\/","title":{"rendered":"Bank of Ireland Fined by the Data Protection Commissioner \u2013 Civil Cases may follow"},"content":{"rendered":"
Overview<\/strong><\/p>\n Bank of Ireland Group PLC (the Bank) has been fined \u20ac463,000.00 by the Data Protection Commissioner (DPC) after an investigation concluded that the personal date of approximately 47,000 customers had been breached, the DPC said.<\/p>\n The investigation related to 22 personal data breach notifications that the Bank reported to the DPC between the 9th<\/sup> November 2018 and 27 June 2019. The data breach incidents relate to unauthorised and inaccurate disclosures of customers personal data to the Central Credit Register (CCR) \u2013 the Central Banks centralised finance database that collects and stores personal credit information on loans of \u20ac500.00 or more. The CCR processes financial data provided by the bank and prepare credit reports to both borrowers and lenders to assist Banks in deciding whether to approve an application for a loan.<\/p>\n The DPC decision highlighted a number of incidents where the bank had submitted incorrect information to the CCR which indicated that certain customers were in financial distress.<\/p>\n The 14th March 2022 decision found that the Bank\u2019s reporting of inaccurate information to CCR had breached a number provisions of the General Data Protection Regulation (GDPR). The decision found infringements of the following provisions:<\/p>\n <\/p>\n <\/p>\n Impact of the Decision<\/strong><\/p>\n As highlighted above, the Bank have been fixed with a fine of \u20ac463,000.00 by the DPC. The DPC decision concluded by saying that they were satisfied that the fines imposed are effective, proportionate and dissuasive, taking into account all of the circumstances of the inquiry.<\/p>\n Despite the fine, it is probable that some of the customers impacted by the data breach may bring civil actions for damages against the Bank for the GDPR breaches.<\/p>\n <\/p>\n Can I Bring a Case?<\/strong><\/p>\n If you have recently received correspondence from the Bank advising you of a breach of your personal data or if you have received confirmation from the Bank advising you of an incorrect credit rating report, you may have been impacted by this Breach.<\/p>\n Lawlor Kiernan LLP have extensive experience in Data Breach litigation and we have successfully prosecuted and obtained Damages for clients arising out of data breaches by various Financial Institutions including Bank of Ireland.<\/p>\n In 2017, our firm obtained a settlement in the sum of \u20ac110,000.00 on behalf of a client. In that case, Bank of Ireland wrongfully and unlawfully processed the Plaintiff\u2019s personal information without his consent and disclosed his personal data to a third party.<\/p>\n\n