Restaurant

Non disponible

Insufficient technical and organisational measures to ensure information security

Date de décision

1 janvier 2021

Autorité

Data Protection Authority of Saarland

DE

Secteur

Accomodation and Hospitality

Pays

DE

Droit

GDPR

Statut

FINAL

Description

A restaurant had disposed of 120 completed guest registration forms for contact tracing purposes during the Covid-19 pandemic in a publicly-accessible dumpster. During its investigation, the DPA also found that already during the restaurant's operation, the restaurant had not implemented adequate safeguards to protect the data processed during the guest registration process. For example, the completed guest registration forms were kept in an adjoining room accessible to all employees without special security measures, such as a locked cabinet.

Citations légales

Art. 24Art. 32

Questions et violations

Insufficient technical and organisational measures to ensure information security

Restez informé sur l'application de la législation en matière de protection de la vie privée

Nous respectons votre vie privée. Un courriel par mois, pas de spam, désabonnement à tout moment.