Private individual
€900
Insufficient technical and organisational measures to ensure information security
Decision Date
9 de outubro de 2022
Authority
Spanish Data Protection Authority (aepd)
ES
Sector
Individuals and Private Associations
Country
ES
Law
GDPRStatus
FINALDescription
The Spanish DPA has imposed a fine on a private individual. The individual unauthorizedly sent e-mails with personal data to several recipients in an open distribution list. This made it possible for the recipients to view the e-mail addresses of all other recipients. The original fine of EUR 1,200 was reduced to EUR 900 due to voluntary payment and admission of responsibility.
Legal Citations
Art. 5 (1)Art. 32 (1)
Issues & Violations
Insufficient technical and organisational measures to ensure information security