CENTROS COMERCIALES CARREFOUR, S.A.

€3,200,000

Insufficient technical and organisational measures to ensure information security

Datum odločitve

14. marec 2025

Organ

Spanish Data Protection Authority (aepd)

ES

Sektor

Industry and Commerce

Država

ES

Zakon

GDPR

Status

FINAL

Opis

The Spanish DPA imposed a fine of EUR 3,200,000 on CENTROS COMERCIALES CARREFOUR, S.A. The controller suffered a cyberattack, resulting in the leak of a large amount of personal data. The controller failed to implement sufficient technical and organizational measures to ensure data security. Additionally, the notification of the data subjects in regards to the data breach was insufficient.

Pravne navedbe

Art. 5 (1)Art. 32Art. 34

Vprašanja in kršitve

Insufficient technical and organisational measures to ensure information security

Spremljajte novice o uveljavljanju zasebnosti

Spoštujemo vašo zasebnost. Eno e-poštno sporočilo na mesec, brez neželene pošte, odjava kadar koli.