President of the Zgierz District Court

€2,200

Insufficient technical and organisational measures to ensure information security

決定日期

2021年8月13日

權限

Polish National Personal Data Protection Office (UODO)

PL

部門

Public Sector and Education

國家

PL

法律

GDPR

狀態

FINAL

說明

The Polish DPA (UODO) has imposed a fine of EUR 2,200 on the president of the Zgierz District Court. The president had reported a data breach involving the loss of an unencrypted USB stick by a probation officer. The data medium stored the data of 400 persons under probation supervision. The lost and at the same time unsecured data carrier has not yet been found, so that unauthorized persons could still have access to the personal data it contained. The president had assumed that the duty to secure the data did not lie with himself, but with the respective probation officers who had these data in use. However, the DPA found that the president himself should have secured the USB sticks.

法律引文

Art. 5 (1)Art. 25 (1)Art. 32 (1)

問題與違規

Insufficient technical and organisational measures to ensure information security

保持最新的隱私權執法資訊

我們尊重您的隱私。每月一封電子郵件,無垃圾郵件,可隨時取消訂閱。