Fortum Marketing and Sales Polska S.A.

€1,000,000

Insufficient technical and organisational measures to ensure information security

Datum der Entscheidung

19. Januar 2022

Behörde

Polish National Personal Data Protection Office (UODO)

PL

Sektor

Transportation and Energy

Land

PL

Recht

GDPR

Status

FINAL

Beschreibung

The Polish DPA has imposed a fine of EUR 1 million on Fortum Marketing and Sales Polska S.A.. The company had reported a data breach to the DPA in accordance with Art. 33 GDPR. During its investigation, the DPA found that unauthorized persons had managed to access and siphon off customer data. The data breach occurred at the time of the introduction of a change in the company's IT environment. The change was made by a processing agent. As part of the change, an additional Fortum customer database was created. However, the server on which the database was stored did not have sufficient security measures, which is why the unauthorized persons succeeded in accessing the data. The DPA also found that the processor failed to pseudonymize and encrypt the data. In addition, the processing agent had been using real customer data, rather than test data, to test the changes to the system. For this reason, the DPA concluded that the controller failed to take appropriate technical and organizational measures to ensure the protection of personal data. In addition, the DPA found that the controller would have been required to monitor the work of the processor to ensure that the protection of personal data is continuously guaranteed.

Juristische Zitate

Art. 5 (1)Art. 24 (1)Art. 25 (1)Art. 28 (1)Art. 32 (1)

Probleme und Verstöße

Insufficient technical and organisational measures to ensure information security

Bleiben Sie auf dem Laufenden über die Durchsetzung des Datenschutzes

Wir respektieren Ihre Privatsphäre. Eine E-Mail pro Monat, kein Spam, jederzeit abbestellbar.