The privacy notice in the banking relationship

Contenido

Recent decisions by the Italian Data Protection Authority (Garante per la protezione dei dati personali) in the Isybank and BBVA cases have brought renewed attention to the principle of transparency in the processing of personal data, highlighting its implications for banking and financial institutions.

Although the two cases concern different circumstances, they demonstrate that transparency cannot be limited to the formal completeness of privacy notices. Instead, it must be ensured throughout the entire data processing lifecycle: from the correct identification of the legal basis for processing to the selection of appropriate communication channels and timing, and ultimately to the effective exercise of data subjects’ rights.

The decisions also emphasize the need to ensure consistency between the information provided to customers and the procedures, systems, and operational practices implemented by financial institutions.

In this context, legal design plays an increasingly important role as a means of making legal information not only available but also accessible and understandable, while preserving its legal accuracy and meaning.

Aurora Agostini, Partner at LEXIA, explores these issues in an article published by Diritto Bancario, examining the key findings emerging from the two decisions and their implications for data protection compliance in the banking sector.

Read the full article on Diritto Bancario >

Fecha