CENTROS COMERCIALES CARREFOUR, S.A.

€3,200,000

Insufficient technical and organisational measures to ensure information security

Date de décision

14 mars 2025

Autorité

Spanish Data Protection Authority (aepd)

ES

Secteur

Industry and Commerce

Pays

ES

Droit

GDPR

Statut

FINAL

Description

The Spanish DPA imposed a fine of EUR 3,200,000 on CENTROS COMERCIALES CARREFOUR, S.A. The controller suffered a cyberattack, resulting in the leak of a large amount of personal data. The controller failed to implement sufficient technical and organizational measures to ensure data security. Additionally, the notification of the data subjects in regards to the data breach was insufficient.

Citations légales

Art. 5 (1)Art. 32Art. 34

Questions et violations

Insufficient technical and organisational measures to ensure information security

Restez informé sur l'application de la législation en matière de protection de la vie privée

Nous respectons votre vie privée. Un courriel par mois, pas de spam, désabonnement à tout moment.