Unknown

€358,000

Insufficient technical and organisational measures to ensure information security

결정 날짜

2024년 11월 20일

권한

Polish National Personal Data Protection Office (UODO)

PL

섹터

Not assigned

국가

CZ

법률

GDPR

상태

FINAL

설명

The Polish DPA has imposed a fine of EUR 358,000 on a company. The company had inadvertently published customer data (first name, last name, email address, home address, encrypted passwords) in the process of redesigning its website. The incident affected approximately 20,000 data subjects. The DPA found that the controller had not sufficiently ensured the security of personal data during the process, for example, by conducting regular tests and risk assessments. Instead, it relied on information provided by the hired subcontractor without proper oversight.

법적 인용

Art. 5 (1)Art. 5 (2)Art. 25 (1)Art. 28 (1)Art. 32 (1)

문제 및 위반 사항

Insufficient technical and organisational measures to ensure information security

개인정보 보호 정책 시행에 대한 최신 정보

당사는 사용자의 개인정보를 존중합니다. 한 달에 한 번, 스팸 없이, 언제든지 구독을 취소할 수 있습니다.