VIEC Limited
Non-compliance with general data processing principles
決定日
2022年12月22日
権威
Data Protection Authority of Ireland
IE
セクター
Industry and Commerce
国名
IE
法律
GDPRステータス
FINAL説明
The Irish DPA has imposed a fine of EUR 100,000 on the nursing home operator VIEC Limited. The controller had notified the DPA of a data breach pursuant to Art. 33 GDPR. The controller had suffered a phishing attack in which an unauthorized third party gained access to an email account of a VIEC manager. As a result, the unknown third party also managed to access personal data such as health and biometric data of home residents. The DPA found this to be a breach of the principle of integrity and confidentiality. The DPA also found that the controller had failed to implement appropriate technical and organizational measures to protect personal data.