Your cookie preferences

EDPB guidance · Art. 7 GDPR

We use technical cookies essential for the platform to work (login, security, sessions). We would also like to use analytics cookies to understand how to improve it.

You can accept all, reject all, or choose which categories to switch on.Your consent is valid for 6 months and you can withdraw it at any time from the footer.

You will find everything in our privacy notice.

All news
Enforcement May 8, 2026 6 min

Ireland: EUR 277,500 for Permanent TSB over a contact centre that could be fooled, and for reporting late

The Data Protection Commission splits the two amounts: EUR 250,000 for security measures, EUR 27,500 for the delay in notification. The 72-hour deadline carries its own price, separate from the breach that caused it

TL;DR for the DPO

Two separate fines for the same episode: EUR 250,000 for inadequate security measures and EUR 27,500 for late notification. The second figure is the one that deserves attention: late notification is a standalone infringement, payable even when the controller has already paid for the flaw that caused it.

How the attack worked

There was no intrusion into any system. The attackers already held certain customer information - the kind of data that circulates after someone else's breach, or that can be assembled from social media - and used it to pass the contact centre's telephone identity checks. Once authenticated as the customer, they gained access to accounts and amended the personal and contact details attached to them. Some customers lost money.

Where the weakness lies

Identity verification based on information the data subject knows - date of birth, address, last digits of an ID, the amount of the last transaction - is not an authentication factor: it is a knowledge factor reproducible by anyone holding the same data. If a client's contact centre can change the email address or phone number attached to an account on that basis alone, the flaw is not in the software: it is in the procedure.

The two heads of sanction

  • EUR 250,000 for the failings related to account security: technical and organisational measures not appropriate to the risk (Art. 32 GDPR). Telephone account takeover has been a known risk in banking for years.
  • EUR 27,500 for the delay in notifying the breaches to the authority (Art. 33 GDPR). The first breaches were reported in May 2022, but not within the required time.
  • In addition, a formal reprimand under Art. 58(2)(b).
27,500EUR
for the notification delay alone

Why the second amount matters more than the first

Security measures are debatable: appropriateness, state of the art and cost of implementation are relative notions, and the controller has room to argue. The 72-hour deadline is not: either the notification arrived in time, or it did not. It is an infringement established with a calendar, not an expert report. That is why, in the practice of a firm serving several clients, controlling the deadline is the investment with the best ratio of cost to risk avoided.

The subtle point is that the 72 hours run from when the controller becomes aware of the breach, and in cases like this awareness builds up by accumulation: first one isolated customer report, then another, then the suspicion that there is a pattern. The moment that suspicion becomes 'awareness' is a judgement that has to be written down when it is made, not reconstructed months later in front of the authority.

What to do now, in practice

1) For every client with a phone channel to end customers, ask for the identity verification procedure and try to pass it using the information you would find in a data leak. 2) Check whether changing an email address or phone number requires confirmation through a second channel: that single control breaks the account takeover chain. 3) In the breach register, for every event record the date and time at which the controller became aware and who determined it: that field decides whether notification was timely. 4) If several similar reports arrive over a period of weeks, assess whether they constitute a single continuing breach: it is a decision to be justified in writing either way.

Official source:Data Protection Commission - Final decision following the Permanent TSB inquiry (8 May 2026)Official source:Law Society Gazette - DPC fines Permanent TSB for GDPR breaches

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Enforcement

The vendor's bug turned into a criminal conviction

On 7 September 2026, before the Dublin Metropolitan District Court, Brown Thomas Arnotts Limited pleaded guilty to five sample charges out of twenty-one for breaches of the Irish ePrivacy Regulations. Three concerned the absence of a valid opt-out address, two the sending of marketing without valid consent. The sum paid is two thousand euro. The sum is not the point: this was a criminal prosecution.

Sep 07, 2026New 5 min
Enforcement
403million euro, and six months to comply

Google, €403 million: half the findings live in your register

On 21 September 2026 the Irish Data Protection Commission closed the inquiry it opened into Google Ireland in February 2020. Its subject: location data in three features — Web & App Activity, Location History, Location Accuracy — between 25 May 2018 and 4 February 2020. Fines totalling €403 million and six months to come into compliance. The number makes the headlines; for practitioners, the interesting part is elsewhere.

Sep 23, 2026New 6 min
Enforcement
24.000euros for an access authorised by the medical management

«Not unlawful, the medical management authorised it»: the Italian DPA says no, EUR 24,000

The case is small and the lesson is not. A hospital is at once a place of care and the employer of the same person, and when the two capacities touch, the health record becomes the handiest and most wrong tool. The employer had put it in writing to the prosecutor: that access was not unlawful, it was «carried out on the instructions of the medical management» «for the performance of the work». That is precisely the sentence the authority takes apart.

Sep 22, 2026New 6 min