Company

€8,900

Insufficient technical and organisational measures to ensure information security

Data decyzji

1 stycznia 2022

Władza

Data Protection Authority of Niedersachsen

DE

Sektor

Industry and Commerce

Kraj

HU

Prawo

GDPR

Status

FINAL

Opis

The DPA of Niedersachsen imposed a fine of EUR 8,900 on a company. The company had a customer database on the Internet with thousands of entries. During its investigation, the DPA found that the only access protection the company had implemented was a long-form web address but not additional measures such as password-protected access. The controller relied on the fact that the web would not become known.

Cytaty prawne

Art. 32

Problemy i naruszenia

Insufficient technical and organisational measures to ensure information security

Bądź na bieżąco z egzekwowaniem przepisów dotyczących prywatności

Szanujemy Twoją prywatność. Jeden e-mail miesięcznie, bez spamu, zrezygnuj z subskrypcji w dowolnym momencie.