PHARMA TALENTS, S.L.U.

€2,400

Insufficient technical and organisational measures to ensure information security

Fecha de la decisión

14 de enero de 2022

Autoridad

Spanish Data Protection Authority (aepd)

ES

Sector

Industry and Commerce

País

ES

Ley

GDPR

Estado

FINAL

Descripción

The Spanish DPA has imposed a fine against PHARMA TALENTS, S.L.U. A data subject had filed a complaint against the company after he found a database on one of the company's websites containing personal data about himself and other hundreds of health sector professionals, including email address and telephone number. Both the website and the database were freely accessible. The DPA found that the company had failed to implement adequate technical and organizational measures to ensure a level of security appropriate to the risk to data subjects, since not even a username and password were required to access the database. The original fine of EUR 4,000 was reduced to EUR 2,400 due to voluntary payment and admission of guilt.

Citas legales

Art. 5 (1)Art. 32

Problemas e infracciones

Insufficient technical and organisational measures to ensure information security

Manténgase al día sobre la aplicación de las normas de protección de la intimidad

Respetamos su intimidad. Un correo electrónico al mes, sin spam, darse de baja en cualquier momento.