Data protection authority imposed a 0.9 MEUR fine on Aktia
Summary
- Aktia was fined 0.9 MEUR by the data protection authority due to a data breach in January 2023, affecting approximately 350 customers.
- The bank plans to appeal the decision, arguing that the authority's interpretations are incorrect, but will likely record a provision for the fine in its Q4 results.
- The financial impact of the fine is expected to be minimal, affecting less than one percent of the projected full-year EBIT, and the incident is not deemed significant for Aktia's business development.
This content is generated by AI. You can give feedback on it in the Inderes forum.
Translation: Original published in Finnish on 10/29/2025 at 9:20 am EET.
The sanction is due to an error in Aktia's identification service resulting in the bank's customers temporarily being able to see the data of other customers. The data breach occurred in January 2023, lasted approximately one hour, and concerned approximately 350 people. According to Aktia, the error was resolved instantly, and the software product that caused it was disabled.
Aktia considers the authority's interpretations underlying the sanction to be incorrect and has therefore stated that it will appeal against the decision to the administrative court. However, we estimate that Aktia will record a provision equal to the amount of the sanction in its Q4 result. This will have a fairly limited impact on earnings — less than one percent of our projected full-year EBIT. Additionally, we do not consider the incident to be significant in terms of the bank's business development because its scope was ultimately small and the funds held by customers at the bank were not at risk.
