Dutch Foreign Ministry

€565,000

Insufficient technical and organisational measures to ensure information security

결정 날짜

2022년 2월 24일

권한

Dutch Supervisory Authority for Data Protection (AP)

NL

섹터

Public Sector and Education

국가

NL

법률

GDPR

상태

FINAL

설명

The Dutch DPA has imposed a fine of EUR 565,000 on the Dutch Foreign Ministry. As part of its investigation, the DPA found that the National Visa Information System (NVIS) suffered from significant security deficiencies. This is particularly serious as the Foreign Ministry has processed an average of 530,000 visa applications per year over the last three years and the personal data processed in the course of the applications was therefore inadequately secured. The data included sensitive information such as fingerprints, name, address, place of residence, country of birth, purpose of travel and nationality. Due to the inadequate security measures, it would have been possible for unauthorized persons to access the data. According to DPA, the Foreign Ministry had been aware of the security flaws in the visa system for some time. Despite this knowledge, the Ministry did not adjust the security measures in time. For this reason, the DPA finds that the Ministry acted with gross negligence. The DPA also found that the Foreign Ministry did not adequately inform individuals who applied for visas that their personal information would be shared with other parties.

법적 인용

Art. 13 (1)Art. 32 (1)

문제 및 위반 사항

Insufficient technical and organisational measures to ensure information security

개인정보 보호 정책 시행에 대한 최신 정보

당사는 사용자의 개인정보를 존중합니다. 한 달에 한 번, 스팸 없이, 언제든지 구독을 취소할 수 있습니다.