SLIMPAY

€180,000

Insufficient technical and organisational measures to ensure information security

결정 날짜

2021년 12월 28일

권한

French Data Protection Authority (CNIL)

FR

섹터

Finance, Insurance and Consulting

국가

FR

법률

GDPR

상태

FINAL

설명

The French DPA (CNIL) has imposed a fine of EUR 180,000 on the payment institution SLIMPAY. In 2015, SLIMPAY conducted an internal research project in which it processed personal data in its databases. When the research project ended in July 2016, the data remained stored on a server, without any security measures and freely accessible on the Internet. The data breach affected about 12 million people. During its investigation, the CNIL found that the company had failed to implement appropriate technical and organizational measures to ensure a level of security commensurate with the risk to data subjects. Thus, the server access was not subject to any security measures, so that it was possible to access it via the Internet between November 2015 and February 2020 In addition, the DPA found that the company had failed to inform the data subjects about the data breach. The CNIL also found that in several cases, contracts the company had concluded with processors were inadequately drafted, as they did not include certain envisaged clauses obliging the processors to process personal data in accordance with the requirements of the GDPR.

법적 인용

Art. 28Art. 32Art. 34

문제 및 위반 사항

Insufficient technical and organisational measures to ensure information security

개인정보 보호 정책 시행에 대한 최신 정보

당사는 사용자의 개인정보를 존중합니다. 한 달에 한 번, 스팸 없이, 언제든지 구독을 취소할 수 있습니다.