English School Cyprus

€4,000

Insufficient technical and organisational measures to ensure information security

Datum för beslut

22 mars 2022

Myndighet

Cypriot Data Protection Commissioner

CY

Sektor

Public Sector and Education

Land

CY

Lag

GDPR

Status

FINAL

Beskrivning

The Cypriot DPA has imposed a fine of EUR 4,000 on the English School in Cyprus. The school had reported a data breach to the DPA under Art. 33 GDPR. A teacher had used the email address of the students' parents for a purpose other than that for which the email addresses were originally collected. The DPA found that the school had failed to take adequate technical and organizational measures to ensure the protection of personal data and to prevent such incidents.

Rättsliga hänvisningar

Art. 32

Frågor och överträdelser

Insufficient technical and organisational measures to ensure information security

Håll dig uppdaterad om efterlevnaden av sekretessreglerna

Vi respekterar din integritet. Ett e-postmeddelande per månad, ingen skräppost, avsluta prenumerationen när som helst.