UWV (Dutch employee insurance service provider)

€900,000

Insufficient technical and organisational measures to ensure information security

Date de décision

31 octobre 2019

Autorité

Dutch Supervisory Authority for Data Protection (AP)

NL

Secteur

Finance, Insurance and Consulting

Pays

NL

Droit

GDPR

Statut

FINAL

Description

As the UWV (the Dutch employee insurance service provider - 'Uitvoeringsinstituut Werknemersverzekeringen') did not use multi-factor authentication when accessing the online employer portal, security was inadequate. Employers and health and safety services were able to collect and display health data from employees in an absence system.

Citations légales

Art. 32

Questions et violations

Insufficient technical and organisational measures to ensure information security

Restez informé sur l'application de la législation en matière de protection de la vie privée

Nous respectons votre vie privée. Un courriel par mois, pas de spam, désabonnement à tout moment.