AIO E-COMMERCE, S.L.

€6,400

Non-compliance with general data processing principles

Data della decisione

26 ottobre 2022

Autorità

Spanish Data Protection Authority (aepd)

ES

Settore

Industry and Commerce

Paese

ES

Legge

GDPR

Stato

FINAL

Descrizione

The Spanish DPA has imposed a fine on AIO E-COMMERCE, S.L.. The controller had suffered a data breach resulting in personal data such as bank details being siphoned off and subsequently sold on the internet. As part of its investigation, the DPA found that the controller had failed to implement appropriate technical and organizational measures to protect personal data. The DPA also found that the controller had violated the principle of data minimization by storing all digits of the affected credit card numbers rather than just the last four. The original fine of EUR 8,000 was reduced to EUR 6,400 due to voluntary payment.

Citazioni legali

Art. 5 (1)

Problemi e violazioni

Non-compliance with general data processing principles

Rimanete aggiornati sull'applicazione della privacy

Rispettiamo la vostra privacy. Un'email al mese, niente spam, cancellazione in qualsiasi momento.