UWV (Dutch employee insurance service provider)
€450,000
Insufficient technical and organisational measures to ensure information security
결정 날짜
2021년 5월 31일
권한
Dutch Supervisory Authority for Data Protection (AP)
NL
섹터
Finance, Insurance and Consulting
국가
NL
법률
GDPR상태
FINAL설명
The Dutch DPA (AP) has fined UWV (the Dutch employee insurance service provider - 'Uitvoeringsinstituut Werknemersverzekeringen) EUR 450,000. The UWV had not properly secured the sending of group messages via the 'My Workbook' environment. This is a personal environment on the UWV website where job seekers have contact with the UWV. As a result, there were multiple data leaks of personal information, including health information, from a total of more than 15,000 individuals.
법적 인용
Art. 32
문제 및 위반 사항
Insufficient technical and organisational measures to ensure information security