PHARMA TALENTS, S.L.U.

€2,400

Insufficient technical and organisational measures to ensure information security

Date de décision

14 janvier 2022

Autorité

Spanish Data Protection Authority (aepd)

ES

Secteur

Industry and Commerce

Pays

ES

Droit

GDPR

Statut

FINAL

Description

The Spanish DPA has imposed a fine against PHARMA TALENTS, S.L.U. A data subject had filed a complaint against the company after he found a database on one of the company's websites containing personal data about himself and other hundreds of health sector professionals, including email address and telephone number. Both the website and the database were freely accessible. The DPA found that the company had failed to implement adequate technical and organizational measures to ensure a level of security appropriate to the risk to data subjects, since not even a username and password were required to access the database. The original fine of EUR 4,000 was reduced to EUR 2,400 due to voluntary payment and admission of guilt.

Citations légales

Art. 5 (1)Art. 32

Questions et violations

Insufficient technical and organisational measures to ensure information security

Restez informé sur l'application de la législation en matière de protection de la vie privée

Nous respectons votre vie privée. Un courriel par mois, pas de spam, désabonnement à tout moment.