IBERDROLA, S.A.

€3,000,000

Non-compliance with general data processing principles

決定日期

2024年2月7日

權限

Spanish Data Protection Authority (aepd)

ES

部門

Transportation and Energy

國家

ES

法律

GDPR

狀態

FINAL

說明

The Spanish DPA has fined IBERDROLA, S.A. EUR 3 million following a cyberattack on I-DE Redes, which led to the compromise of customer data from millions of individuals. Although the cyberattack targeted the GEA web application of I-DE Redes, Iberdrola, as the entity responsible for managing the group's IT systems and security infrastructure, was found to have failed in implementing sufficient security measures to prevent the incident.

法律引文

Art. 5 (1)Art. 32

問題與違規

Non-compliance with general data processing principles

保持最新的隱私權執法資訊

我們尊重您的隱私。每月一封電子郵件,無垃圾郵件,可隨時取消訂閱。