Maynooth University
€40,000
Insufficient technical and organisational measures to ensure information security
Decision Date
November 22, 2024
Authority
Data Protection Authority of Ireland
IE
Sector
Public Sector and Education
Country
IE
Law
GDPRStatus
FINALDescription
The Irish DPA has imposed a fine of EUR 40,000 on Maynooth University. The controller failed to implement adequate technical and organisational measures, resulting in an unauthorised third party gaining access to multiple employees' email accounts, which the third party then used for fraudulent purposes.
Legal Citations
Art. 5 (1)Art. 32 (1)Art. 33 (1)
Issues & Violations
Insufficient technical and organisational measures to ensure information security