DSK Bank
€511,000
Insufficient technical and organisational measures to ensure information security
Decision Date
28 de agosto de 2019
Authority
Data Protection Commision of Bulgaria (KZLD)
BG
Sector
Finance, Insurance and Consulting
Country
BG
Law
GDPRStatus
FINALDescription
Leakage of personal data due to inadequate technical and organisational measures to ensure the protection of information security. Third parties had access to over 23000 credit records relating to over 33000 bank customers including personal data such as names, citizenships, identification numbers, adresses, copies of identity cards and biometric data.
Legal Citations
Art. 32
Issues & Violations
Insufficient technical and organisational measures to ensure information security