Private individual
€900
Insufficient technical and organisational measures to ensure information security
Decision Date
October 9, 2022
Authority
Spanish Data Protection Authority (aepd)
ES
Sector
Individuals and Private Associations
Country
ES
Law
GDPRStatus
FINALDescription
The Spanish DPA has imposed a fine on a private individual. The individual unauthorizedly sent e-mails with personal data to several recipients in an open distribution list. This made it possible for the recipients to view the e-mail addresses of all other recipients. The original fine of EUR 1,200 was reduced to EUR 900 due to voluntary payment and admission of responsibility.
Legal Citations
Art. 5 (1)Art. 32 (1)
Issues & Violations
Insufficient technical and organisational measures to ensure information security