CARTONAJES BAÑERES, S.A

€220,000

Insufficient technical and organisational measures to ensure information security

Date de décision

22 novembre 2024

Autorité

Spanish Data Protection Authority (aepd)

ES

Secteur

Employment

Pays

ES

Droit

GDPR

Statut

FINAL

Description

The Spanish DPA has fined CARTONAJES BAÑERES, S.A. EUR 220,000. During its investigation, the DPA found that the controller had failed to grant a former employee access to their personal data. The DPA also found that the controller had failed to carry out a data protection impact assessment regarding the operation of a biometric facial recognition system installed to track working hours.

Citations légales

Art. 15Art. 35

Questions et violations

Insufficient technical and organisational measures to ensure information security

Restez informé sur l'application de la législation en matière de protection de la vie privée

Nous respectons votre vie privée. Un courriel par mois, pas de spam, désabonnement à tout moment.