UNICREDIT BANK SA

€130,000

Insufficient technical and organisational measures to ensure information security

Date de décision

27 juin 2019

Autorité

Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP)

RO

Secteur

Finance, Insurance and Consulting

Pays

RO

Droit

GDPR

Statut

FINAL

Description

The fine was issued as a result of the failure to implement appropriate technical and organisational measures (related to (1) the determination of the processing means/operations, and (2) the integration the necessary safeguards) resulting in the online-disclosure of IDs and addresses (interla/external transactions) of 337,042 data subjects to their respective beneficiary (between 25.05.2018 -10.12.2018).

Citations légales

Art. 25 (1)Art. 5 (1)

Questions et violations

Insufficient technical and organisational measures to ensure information security

Restez informé sur l'application de la législation en matière de protection de la vie privée

Nous respectons votre vie privée. Un courriel par mois, pas de spam, désabonnement à tout moment.