Mermaids

€29,000

Insufficient technical and organisational measures to ensure information security

Päätöspäivä

5. heinäkuuta 2021

Viranomainen

Information Commissioner (ICO)

GB

Ala

Individuals and Private Associations

Maa

GB

Laki

GDPR

Tila

FINAL

Kuvaus

The ICO has fined transgender charity Mermaids EUR 29,000 for failing to protect the personal data of its users, in breach of Art. 5 (1) f) UK GPDR and Art. 32 (1), (2) UK GDPR. The ICO conducted an investigation after it received a report of a data breach relating to an internal email group. During the investigation, the ICO found that the group was created with insufficiently secure settings, resulting in approximately 780 pages of confidential emails being viewable online for nearly three years. This resulted in personal information, such as names and email addresses, of 550 people being online. The ICO concludes that Mermaids should have restricted access to its email group and could have considered pseudonymization or encryption to provide additional protection for the personal data. Organizations responsible for personal data must ensure that they take the appropriate technical and organizational measures to ensure the security of personal data.

Oikeudelliset viittaukset

Art. 5 (1)Art. 32 (1)

Asiat ja rikkomukset

Insufficient technical and organisational measures to ensure information security

Pysy ajan tasalla yksityisyyden suojan valvonnasta

Kunnioitamme yksityisyyttäsi. Yksi sähköpostiviesti kuukaudessa, ei roskapostia, peruuta tilaus milloin tahansa.