Global Business Travel Spain SLU

€5,000

Insufficient technical and organisational measures to ensure information security

Fecha de la decisión

10 de julio de 2020

Autoridad

Spanish Data Protection Authority (aepd)

ES

Sector

Transportation and Energy

País

ES

Ley

GDPR

Estado

FINAL

Descripción

The fine was preceded by an employee's access to health data of a person concerned. In the course of its investigations, the Data Protection Authority found that Global Business Travel Spain, as data controller, had infringed Article 32(2) and (4) of the GDPR by failing to take adequate technical and organisational measures to protect the data from unauthorised disclosure.

Citas legales

Art. 32

Problemas e infracciones

Insufficient technical and organisational measures to ensure information security

Manténgase al día sobre la aplicación de las normas de protección de la intimidad

Respetamos su intimidad. Un correo electrónico al mes, sin spam, darse de baja en cualquier momento.