Details:

Summary The Spanish DPA has imposed a fine on EVERIS SPAIN S.L.. Everis had published information on sold data of users of an insurance company as well as records with personal data of Spanish customers of the insurance company. The DPA considered this a violation of the confidentiality of the data. The DPA also found that the unlawful publication of the data had been possible due to, among other things, a lack of technical and organizational measures to protect personal data at the time of the data breach. The original fine of EUR 80,000 was reduced to EUR 64,000 due to voluntary payment.
Link: link
Related articles:  Art. 5 (1) f) GDPR, Art. 32 GDPR
Type: Non-compliance with general data processing principles
Fine: EUR 64,000
Sector Finance, Insurance and Consulting

 

All data is based on The CMS’s Law GDPR Enforcement Tracker Source: https://www.enforcementtracker.com/

Tags: case law