PHARMA TALENTS, S.L.U.

€2,400

Insufficient technical and organisational measures to ensure information security

Datum der Entscheidung

14. Januar 2022

Behörde

Spanish Data Protection Authority (aepd)

ES

Sektor

Industry and Commerce

Land

ES

Recht

GDPR

Status

FINAL

Beschreibung

The Spanish DPA has imposed a fine against PHARMA TALENTS, S.L.U. A data subject had filed a complaint against the company after he found a database on one of the company's websites containing personal data about himself and other hundreds of health sector professionals, including email address and telephone number. Both the website and the database were freely accessible. The DPA found that the company had failed to implement adequate technical and organizational measures to ensure a level of security appropriate to the risk to data subjects, since not even a username and password were required to access the database. The original fine of EUR 4,000 was reduced to EUR 2,400 due to voluntary payment and admission of guilt.

Juristische Zitate

Art. 5 (1)Art. 32

Probleme und Verstöße

Insufficient technical and organisational measures to ensure information security

Bleiben Sie auf dem Laufenden über die Durchsetzung des Datenschutzes

Wir respektieren Ihre Privatsphäre. Eine E-Mail pro Monat, kein Spam, jederzeit abbestellbar.