Private individual
€3,000
Non-compliance with general data processing principles
Fecha de la decisión
6 de junio de 2023
Autoridad
Spanish Data Protection Authority (aepd)
ES
Sector
Individuals and Private Associations
País
ES
Ley
GDPREstado
FINALDescripción
The Spanish DPA has fined a private individual EUR 3,000. An individual had filed a complaint with the DPA against the controller due to the fact that the controller had provided them with a false receipt that contained another customer's data and not their own. During its investigation, the DPA found that the controller had failed to implement adequate technical and organizational measures to protect personal data.
Citas legales
Art. 5 (1)Art. 32 (1)
Problemas e infracciones
Non-compliance with general data processing principles