UWV (Dutch employee insurance service provider)

€450,000

Insufficient technical and organisational measures to ensure information security

Date de décision

31 mai 2021

Autorité

Dutch Supervisory Authority for Data Protection (AP)

NL

Secteur

Finance, Insurance and Consulting

Pays

NL

Droit

GDPR

Statut

FINAL

Description

The Dutch DPA (AP) has fined UWV (the Dutch employee insurance service provider - 'Uitvoeringsinstituut Werknemersverzekeringen) EUR 450,000. The UWV had not properly secured the sending of group messages via the 'My Workbook' environment. This is a personal environment on the UWV website where job seekers have contact with the UWV. As a result, there were multiple data leaks of personal information, including health information, from a total of more than 15,000 individuals.

Citations légales

Art. 32

Questions et violations

Insufficient technical and organisational measures to ensure information security

Restez informé sur l'application de la législation en matière de protection de la vie privée

Nous respectons votre vie privée. Un courriel par mois, pas de spam, désabonnement à tout moment.