Company

€65,000

Insufficient technical and organisational measures to ensure information security

決定日期

2020年1月1日

權限

Data Protection Authority of Niedersachsen

DE

部門

Industry and Commerce

國家

HU

法律

GDPR

狀態

FINAL

說明

The DPA of Lower Saxony has imposed a fine of EUR 65,000 on a company. The reason for the proceedings was a report by the company to the authority regarding a data breach pursuant to Art. 33 GDPR. As a result, the DPA conducted an audit of the company's web presence. In the process, the DPA discovered that an outdated web store application was used on the site, which was no longer provided with security updates. The developer had explicitly warned against further use of this version, as it contained significant security vulnerabilities. The investigations of the DPA further revealed that the passwords stored in the database were not sufficiently secured. The DPA concluded that the technical measures taken by the responsible party were not adequate for the protection requirements of the GDPR, resulting in a violation of Art. 32 GDPR.

法律引文

Art. 32

問題與違規

Insufficient technical and organisational measures to ensure information security

保持最新的隱私權執法資訊

我們尊重您的隱私。每月一封電子郵件,無垃圾郵件,可隨時取消訂閱。