Global Business Travel Spain SLU

€5,000

Insufficient technical and organisational measures to ensure information security

Lēmuma datums

2020. gada 10. jūlijs

Iestāde

Spanish Data Protection Authority (aepd)

ES

Nozare

Transportation and Energy

Valsts

ES

Likums

GDPR

Statuss

FINAL

Apraksts

The fine was preceded by an employee's access to health data of a person concerned. In the course of its investigations, the Data Protection Authority found that Global Business Travel Spain, as data controller, had infringed Article 32(2) and (4) of the GDPR by failing to take adequate technical and organisational measures to protect the data from unauthorised disclosure.

Juridiskās atsauces

Art. 32

Jautājumi un pārkāpumi

Insufficient technical and organisational measures to ensure information security

Atjauniniet informāciju par konfidencialitātes ieviešanu

Mēs respektējam jūsu konfidencialitāti. Viens e-pasts mēnesī, bez surogātpasta, jebkurā laikā varat atteikties no abonēšanas.