Fortum Marketing and Sales Polska S.A.

€1,000,000

Insufficient technical and organisational measures to ensure information security

Ημερομηνία απόφασης

19 Ιανουαρίου 2022

Αρχή

Polish National Personal Data Protection Office (UODO)

PL

Τομέας

Transportation and Energy

Χώρα

PL

Νόμος

GDPR

Κατάσταση

FINAL

Περιγραφή

The Polish DPA has imposed a fine of EUR 1 million on Fortum Marketing and Sales Polska S.A.. The company had reported a data breach to the DPA in accordance with Art. 33 GDPR. During its investigation, the DPA found that unauthorized persons had managed to access and siphon off customer data. The data breach occurred at the time of the introduction of a change in the company's IT environment. The change was made by a processing agent. As part of the change, an additional Fortum customer database was created. However, the server on which the database was stored did not have sufficient security measures, which is why the unauthorized persons succeeded in accessing the data. The DPA also found that the processor failed to pseudonymize and encrypt the data. In addition, the processing agent had been using real customer data, rather than test data, to test the changes to the system. For this reason, the DPA concluded that the controller failed to take appropriate technical and organizational measures to ensure the protection of personal data. In addition, the DPA found that the controller would have been required to monitor the work of the processor to ensure that the protection of personal data is continuously guaranteed.

Νομικές παραπομπές

Art. 5 (1)Art. 24 (1)Art. 25 (1)Art. 28 (1)Art. 32 (1)

Θέματα & Παραβάσεις

Insufficient technical and organisational measures to ensure information security

Μείνετε ενημερωμένοι για την επιβολή του απορρήτου

Σεβόμαστε την ιδιωτικότητά σας. Ένα email ανά μήνα, χωρίς spam, διαγραφή ανά πάσα στιγμή.