APOEL FC

€40,000

Insufficient technical and organisational measures to ensure information security

Decision Date

6 de setembro de 2021

Authority

Cypriot Data Protection Commissioner

CY

Sector

Individuals and Private Associations

Country

CY

Law

GDPR

Status

FINAL

Description

The Cypriot DPA has imposed a fine of EUR 40,000 on the soccer club APOEL FC. Due to a lack of security measures in the club's ticket sales system, it was possible for an unauthorized person to access and disclose personal data of fans on the club's website. This data involved the name, the fan card number and the ID number of the data subjects. The DPA concluded that the club failed to implement adequate technical and organizational security measures. In separate proceedings, the DPA fined AC Omonia and Hellenic Technical Enterprises Ltd. for the same violations.

Legal Citations

Art. 32

Issues & Violations

Insufficient technical and organisational measures to ensure information security

Stay Updated on Privacy Enforcement

We respect your privacy. One email per month, no spam, unsubscribe anytime.