The legislative commission concluded that the Central Bank of Costa Rica violated data protection laws by requesting sensitive financial information from bank customers without the required explicit consent. Although the institution argued that the purpose was statistical, aimed at designing public policies, lawmakers determined that the necessary criteria of accuracy, confidentiality, and security were not met. It was emphasized that, although such data are crucial for state policies, the Central Bank acts solely as a custodian and not as the owner of the information, and is therefore obligated to fully comply with privacy regulations. The analysis highlights that the opinion issued by the Office of the Attorney General, which the Central Bank relied on as legal backing, was insufficient because it was limited to basic credit data. It overlooked the reality that the access covered a much broader range of socioeconomic details, such as salaries, taxes, and payment histories. This critical omission means that the legal justification presented does not reflect the true extent of the information collected, raising serious doubts about the validity of the defense used and its impact on the overall perception of privacy. This report is relevant to the open data community because it establishes a precedent regarding the legal limits on data collection and transfer, even for statistical purposes. It reinforces the importance of ensuring that transparency and access to public information do not conflict with the protection of individual rights and privacy. For open data advocates, this case underscores the need for strict anonymization protocols and consent mechanisms, demonstrating that regulatory compliance is essential to maintaining legitimacy and ethics in the management of public data.

Source:
Published on 2024-04-13