Company
€8,900
Insufficient technical and organisational measures to ensure information security
Data della decisione
1 gennaio 2022
Autorità
Data Protection Authority of Niedersachsen
DE
Settore
Industry and Commerce
Paese
HU
Legge
GDPRStato
FINALDescrizione
The DPA of Niedersachsen imposed a fine of EUR 8,900 on a company. The company had a customer database on the Internet with thousands of entries. During its investigation, the DPA found that the only access protection the company had implemented was a long-form web address but not additional measures such as password-protected access. The controller relied on the fact that the web would not become known.
Citazioni legali
Art. 32
Problemi e violazioni
Insufficient technical and organisational measures to ensure information security