EVERIS SPAIN S.L

€64,000

Non-compliance with general data processing principles

Datum odločitve

9. oktober 2022

Organ

Spanish Data Protection Authority (aepd)

ES

Sektor

Finance, Insurance and Consulting

Država

ES

Zakon

GDPR

Status

FINAL

Opis

The Spanish DPA has imposed a fine on EVERIS SPAIN S.L.. Everis had published information on sold data of users of an insurance company as well as records with personal data of Spanish customers of the insurance company. The DPA considered this a violation of the confidentiality of the data. The DPA also found that the unlawful publication of the data had been possible due to, among other things, a lack of technical and organizational measures to protect personal data at the time of the data breach. The original fine of EUR 80,000 was reduced to EUR 64,000 due to voluntary payment.

Pravne navedbe

Art. 5 (1)Art. 32

Vprašanja in kršitve

Non-compliance with general data processing principles

Spremljajte novice o uveljavljanju zasebnosti

Spoštujemo vašo zasebnost. Eno e-poštno sporočilo na mesec, brez neželene pošte, odjava kadar koli.