Private individual

€3,000

Non-compliance with general data processing principles

Date de décision

6 juin 2023

Autorité

Spanish Data Protection Authority (aepd)

ES

Secteur

Individuals and Private Associations

Pays

ES

Droit

GDPR

Statut

FINAL

Description

The Spanish DPA has fined a private individual EUR 3,000. An individual had filed a complaint with the DPA against the controller due to the fact that the controller had provided them with a false receipt that contained another customer's data and not their own. During its investigation, the DPA found that the controller had failed to implement adequate technical and organizational measures to protect personal data.

Citations légales

Art. 5 (1)Art. 32 (1)

Questions et violations

Non-compliance with general data processing principles

Restez informé sur l'application de la législation en matière de protection de la vie privée

Nous respectons votre vie privée. Un courriel par mois, pas de spam, désabonnement à tout moment.