English School staff union (ESSA)

€5,000

Insufficient technical and organisational measures to ensure information security

Fecha de la decisión

21 de marzo de 2022

Autoridad

Cypriot Data Protection Commissioner

CY

Sector

Public Sector and Education

País

CY

Ley

GDPR

Estado

FINAL

Descripción

The Cypriot DPA has imposed a fine of EUR 5,000 on the English School staff union (ESSA). The school had notified the DPA of a data breach under Art. 33 GDPR. A teacher, also a member of the staff union, had used the email addresses of the parents of the students for a purpose other than the one for which the email addresses had originally been collected. The DPA found that the staff union had failed to take appropriate technical and organizational measures to ensure the protection of personal data and to prevent such incidents.

Citas legales

Art. 32

Problemas e infracciones

Insufficient technical and organisational measures to ensure information security

Manténgase al día sobre la aplicación de las normas de protección de la intimidad

Respetamos su intimidad. Un correo electrónico al mes, sin spam, darse de baja en cualquier momento.