Tusla Child and Family Agency
€85,000
Insufficient technical and organisational measures to ensure information security
Datum der Entscheidung
12. August 2020
Behörde
Data Protection Authority of Ireland
IE
Sektor
Public Sector and Education
Land
IE
Recht
GDPRStatus
FINALBeschreibung
The Irish DPA (DPC) fined Tusla Child and Family Agency EUR 85,000. The controller had reported 71 data breaches to the Irish DPA that occurred between May 25 and November 16, 2018, and concerned the unauthorized access of personal data processed by the controller. After a broad investigation, the DPA concluded that the controller failed to implement adequate technical and organizational measures to protect the data processing and thus violated Art. 32 (1) of the GDPR.
Juristische Zitate
Art. 32 (1)
Probleme und Verstöße
Insufficient technical and organisational measures to ensure information security