English School staff union (ESSA)
Insufficient technical and organisational measures to ensure information security
Karar Tarihi
21 Mart 2022
Otorite
Cypriot Data Protection Commissioner
CY
Sektör
Public Sector and Education
Ülke
CY
Hukuk
GDPRDurum
FINALAçıklama
The Cypriot DPA has imposed a fine of EUR 5,000 on the English School staff union (ESSA). The school had notified the DPA of a data breach under Art. 33 GDPR. A teacher, also a member of the staff union, had used the email addresses of the parents of the students for a purpose other than the one for which the email addresses had originally been collected. The DPA found that the staff union had failed to take appropriate technical and organizational measures to ensure the protection of personal data and to prevent such incidents.