Bank

Δεν είναι διαθέσιμο

Insufficient technical and organisational measures to ensure information security

Ημερομηνία απόφασης

1 Ιανουαρίου 2022

Αρχή

Data Protection Authority of Brandenburg

DE

Τομέας

Finance, Insurance and Consulting

Χώρα

BG

Νόμος

GDPR

Κατάσταση

FINAL

Περιγραφή

The DPA of Brandenburg has imposed a five-digit fine on a bank. The bank had installed a video surveillance system that covered parts of the foyer of the branch with ATMs, the entrance area and the sidewalk and parking spaces in front of it. The transmission of the images as well as the commands to access the camera were carried out unencrypted via the Internet. The bank suffered a data breach in which unknown third parties compromised the video cameras and then posted the images on the Internet. They were also able to control the cameras to a limited extent. During its investigation, the DPA found that the bank had failed to implement adequate technical and organizational measures to protect personal data, which facilitated such a breach. In addition, the DPA found that the bank failed to enter into a processing agreement with its processors, that also had access to cameras and images.

Νομικές παραπομπές

Art. 28 (3)Art. 32

Θέματα & Παραβάσεις

Insufficient technical and organisational measures to ensure information security

Μείνετε ενημερωμένοι για την επιβολή του απορρήτου

Σεβόμαστε την ιδιωτικότητά σας. Ένα email ανά μήνα, χωρίς spam, διαγραφή ανά πάσα στιγμή.