Enea S.A.

€30,000

Insufficient fulfilment of data breach notification obligations

決定日

2021年1月11日

権威

Polish National Personal Data Protection Office (UODO)

PL

セクター

Transportation and Energy

国名

PL

法律

GDPR

ステータス

FINAL

説明

The Polish DPA (UODO) fined Enea S.A. EUR 30,000 for the controller's failure to report a personal data breach, in violation of Art. 33 (1) GDPR. The DPA received information about a personal data breach from a person who had become an unauthorized recipient of personal data. The breach consisted of sending an email with an unencrypted, non-password protected attachment that contained personal data of several hundred individuals. The sender of the email was an employee of the sanctioned controller.

法的引用

Art. 33 (1)

問題と違反

Insufficient fulfilment of data breach notification obligations

プライバシー保護に関する最新情報

あなたのプライバシーを尊重します。メール配信は月1回、迷惑メールはありません。