Air Europa Lineas Aereas, SA.

€600,000

Insufficient technical and organisational measures to ensure information security

Data della decisione

15 marzo 2021

Autorità

Spanish Data Protection Authority (aepd)

ES

Settore

Industry and Commerce

Paese

ES

Legge

GDPR

Stato

FINAL

Descrizione

The Spanish DPA (AEPD) fined Air Europa Lineas Aereas, SA. EUR 600,000 after a serious data breach involving unauthorized access to contact details and bank accounts was reported to the AEPD. Approximately 489,000 individuals and 1,500,000 records were affected. The AEPD announced that it had fined the controller EUR 500,000 for a breach of Art. 32 (1) GDPR due to the failure to take appropriate technical and organizational measures to ensure an adequate level of security, and EUR 100,000 for a breach of Art. 33 GDPR for notifying the AEPD of the security breach 41 days late. In determining the amount of the fine, the fact that the incident was not limited to a local area, but affected a large number of people not only in Spain, but also worldwide, and that sensitive banking and financial data were affected, harming several thousand people, was taken into account as an aggravating factor.

Citazioni legali

Art. 32 (1)Art. 33

Problemi e violazioni

Insufficient technical and organisational measures to ensure information security

Rimanete aggiornati sull'applicazione della privacy

Rispettiamo la vostra privacy. Un'email al mese, niente spam, cancellazione in qualsiasi momento.