UWV (Dutch employee insurance service provider)

€900,000

Insufficient technical and organisational measures to ensure information security

Data della decisione

31 ottobre 2019

Autorità

Dutch Supervisory Authority for Data Protection (AP)

NL

Settore

Finance, Insurance and Consulting

Paese

NL

Legge

GDPR

Stato

FINAL

Descrizione

As the UWV (the Dutch employee insurance service provider - 'Uitvoeringsinstituut Werknemersverzekeringen') did not use multi-factor authentication when accessing the online employer portal, security was inadequate. Employers and health and safety services were able to collect and display health data from employees in an absence system.

Citazioni legali

Art. 32

Problemi e violazioni

Insufficient technical and organisational measures to ensure information security

Rimanete aggiornati sull'applicazione della privacy

Rispettiamo la vostra privacy. Un'email al mese, niente spam, cancellazione in qualsiasi momento.