Bookstore employee

€4,000

Insufficient technical and organisational measures to ensure information security

Fecha de la decisión

19 de julio de 2022

Autoridad

Spanish Data Protection Authority (aepd)

ES

Sector

Industry and Commerce

País

ES

Ley

GDPR

Estado

FINAL

Descripción

The Spanish Data Protection Agency has imposed a fine of EUR 4,000 on an employee of a bookstore. An individual had filed a complaint with the DPA because he had received an invoice from another person containing that person's personal data. The employee had inadvertently sent the invoice to the wrong recipient.

Citas legales

Art. 5 (1)Art. 32

Problemas e infracciones

Insufficient technical and organisational measures to ensure information security

Manténgase al día sobre la aplicación de las normas de protección de la intimidad

Respetamos su intimidad. Un correo electrónico al mes, sin spam, darse de baja en cualquier momento.