Standard Chartered Bank Côte d'Ivoire S.A
Warning + formal notice; 60 days to cure and to apply authorisation prescriptions. ARTCI (Autorité de Protection), 23 August 2023.
The facts
A control of Standard Chartered Bank Cote d'Ivoire found the bank using business software including ASTRA for cheque scanning and validation, EBBS for customer payments and account operations, SIGUP for signature verification, M7 for data-breach risk handling and the EBranch application, all of which involved new processing of identifier data that had never been authorised by the Autorite de Protection, raising questions of legitimacy, proportionality, retention and security. Earlier recommendations on its procedures had not been fully implemented and no steps had been taken to seek the required authorisations.
Orders and outcome
The Autorite de Protection issued a warning for non-compliance with the data protection law, a formal notice to cease all observed breaches within sixty days of receipt, and a further formal notice to apply all prescriptions contained in its processing authorisation within the same sixty days, failing which one of the sanctions provided by the law would be pronounced. Sworn agents were directed to verify compliance. Dated 23 August 2023.
Cite this decision
Track Côte d'Ivoire enforcement
Tell us your jurisdictions and we email you when a regulator's decision passes verification. Privacy.