English School staff union (ESSA)
Insufficient technical and organisational measures to ensure information security
Decision Date
21 de março de 2022
Authority
Cypriot Data Protection Commissioner
CY
Sector
Public Sector and Education
Country
CY
Law
GDPRStatus
FINALDescription
The Cypriot DPA has imposed a fine of EUR 5,000 on the English School staff union (ESSA). The school had notified the DPA of a data breach under Art. 33 GDPR. A teacher, also a member of the staff union, had used the email addresses of the parents of the students for a purpose other than the one for which the email addresses had originally been collected. The DPA found that the staff union had failed to take appropriate technical and organizational measures to ensure the protection of personal data and to prevent such incidents.