UWV (Dutch employee insurance service provider)

€900,000

Insufficient technical and organisational measures to ensure information security

Дата на решението

31 октомври 2019 г.

Орган

Dutch Supervisory Authority for Data Protection (AP)

NL

Сектор

Finance, Insurance and Consulting

Държава

NL

Право

GDPR

Статус

FINAL

Описание

As the UWV (the Dutch employee insurance service provider - 'Uitvoeringsinstituut Werknemersverzekeringen') did not use multi-factor authentication when accessing the online employer portal, security was inadequate. Employers and health and safety services were able to collect and display health data from employees in an absence system.

Правни цитати

Art. 32

Въпроси и нарушения

Insufficient technical and organisational measures to ensure information security

Бъдете информирани за прилагането на поверителността

Уважаваме поверителността ви. Един имейл на месец, без спам, отпишете се по всяко време.