Bookstore employee
€4,000
Insufficient technical and organisational measures to ensure information security
Decision Date
July 19, 2022
Authority
Spanish Data Protection Authority (aepd)
ES
Sector
Industry and Commerce
Country
ES
Law
GDPRStatus
FINALDescription
The Spanish Data Protection Agency has imposed a fine of EUR 4,000 on an employee of a bookstore. An individual had filed a complaint with the DPA because he had received an invoice from another person containing that person's personal data. The employee had inadvertently sent the invoice to the wrong recipient.
Legal Citations
Art. 5 (1)Art. 32
Issues & Violations
Insufficient technical and organisational measures to ensure information security