Air Europa Lineas Aereas, SA.

€600,000

Insufficient technical and organisational measures to ensure information security

決定日

2021年3月15日

権威

Spanish Data Protection Authority (aepd)

ES

セクター

Industry and Commerce

国名

ES

法律

GDPR

ステータス

FINAL

説明

The Spanish DPA (AEPD) fined Air Europa Lineas Aereas, SA. EUR 600,000 after a serious data breach involving unauthorized access to contact details and bank accounts was reported to the AEPD. Approximately 489,000 individuals and 1,500,000 records were affected. The AEPD announced that it had fined the controller EUR 500,000 for a breach of Art. 32 (1) GDPR due to the failure to take appropriate technical and organizational measures to ensure an adequate level of security, and EUR 100,000 for a breach of Art. 33 GDPR for notifying the AEPD of the security breach 41 days late. In determining the amount of the fine, the fact that the incident was not limited to a local area, but affected a large number of people not only in Spain, but also worldwide, and that sensitive banking and financial data were affected, harming several thousand people, was taken into account as an aggravating factor.

法的引用

Art. 32 (1)Art. 33

問題と違反

Insufficient technical and organisational measures to ensure information security

プライバシー保護に関する最新情報

あなたのプライバシーを尊重します。メール配信は月1回、迷惑メールはありません。