Rotten Company

Permanent TSB GDPR security and breach-notification failures

Company: Permanent TSB Group Holdings plc

Summary

Ireland's Data Protection Commission found that Permanent TSB failed to implement appropriate technical and organisational security measures in its Open24 Contact Centre and failed to notify personal-data breaches within the GDPR's required timeframe. The breaches involved malicious actors impersonating customers, gaining access to accounts and changing account details; some customers suffered financial loss. In April 2026 the DPC reprimanded PTSB and imposed fines totalling EUR 277,500. Because Irish DPC fines require court confirmation and the DPC's current fines register lists the fine as not confirmed, this record is marked unresolved pending final confirmation. Sources: https://www.dataprotection.ie/en/dpc-guidance/decisions/inquiry-permanent-TSB-april-2026 and https://www.dataprotection.ie/en/dpc-guidance/decisions/fines