English School staff union (ESSA)
Insufficient technical and organisational measures to ensure information security
Päätöspäivä
21. maaliskuuta 2022
Viranomainen
Cypriot Data Protection Commissioner
CY
Ala
Public Sector and Education
Maa
CY
Laki
GDPRTila
FINALKuvaus
The Cypriot DPA has imposed a fine of EUR 5,000 on the English School staff union (ESSA). The school had notified the DPA of a data breach under Art. 33 GDPR. A teacher, also a member of the staff union, had used the email addresses of the parents of the students for a purpose other than the one for which the email addresses had originally been collected. The DPA found that the staff union had failed to take appropriate technical and organizational measures to ensure the protection of personal data and to prevent such incidents.