Permanent TSB Group Holdings plc
Approved Evidence
Permanent TSB GDPR security and breach-notification failures
Ireland's Data Protection Commission found that Permanent TSB failed to implement appropriate technical and organisational security measures in its Open24 Contact Centre and failed to notify personal-data breaches within the GDPR's required timeframe. The breaches involved malicious actors impersonating customers, gaining access to accounts and changing account details; some customers suffered financial loss. In April 2026 the DPC reprimanded PTSB and imposed fines totalling EUR 277,500. Because Irish DPC fines require court confirmation and the DPC's current fines register lists the fine as not confirmed, this record is marked unresolved pending final confirmation. Sources: https://www.dataprotection.ie/en/dpc-guidance/decisions/inquiry-permanent-TSB-april-2026 and https://www.dataprotection.ie/en/dpc-guidance/decisions/fines
Permanent TSB EUR 21 million tracker-mortgage enforcement
The Central Bank of Ireland reprimanded and fined Permanent TSB p.l.c., the banking entity within Permanent TSB Group Holdings, EUR 21 million for 42 admitted regulatory breaches affecting 2,007 tracker-mortgage customer accounts between August 2004 and October 2018. The Central Bank found serious failures that caused prolonged overcharging and significant customer harm, including the loss of 12 family homes and 19 buy-to-let properties. The regulator said the firm failed to adequately protect customers' contractual tracker-mortgage rights and suffered systemic weaknesses in management systems and internal controls. The enforcement action is concluded. Source: https://www.centralbank.ie/news/article/press-release-enforcement-action-permanent-tsb-30-may-2019