UWV (Dutch employee insurance service provider)

€900,000

Insufficient technical and organisational measures to ensure information security

Otsuse kuupäev

31. oktoober 2019

Ametiasutus

Dutch Supervisory Authority for Data Protection (AP)

NL

Sektor

Finance, Insurance and Consulting

Riik

NL

Seadus

GDPR

Staatus

FINAL

Kirjeldus

As the UWV (the Dutch employee insurance service provider - 'Uitvoeringsinstituut Werknemersverzekeringen') did not use multi-factor authentication when accessing the online employer portal, security was inadequate. Employers and health and safety services were able to collect and display health data from employees in an absence system.

Õiguslikud viited

Art. 32

Probleemid ja rikkumised

Insufficient technical and organisational measures to ensure information security

Privaatsuse jõustamise kohta ajakohastatud teave

Me austame teie privaatsust. Üks e-kiri kuus, ei ole rämpsposti, loobuda tellimusest igal ajal.