Belgian Data Protection Authority (APD) · 26 April 2021
Financial company
Insufficient technical and organisational measures to ensure information security
Fine€100,000Fine issued
- Regulator
- Belgian Data Protection Authority (APD)
- Decided
- 26 April 2021
- Country
- Belgium
- Sector
- Finance, Insurance and Consulting
- Regulator’s reference
- Not recorded
- Fino case number
- 2021/BE/003
What happened
The Belgian DPA fined a financial institution €100,000 for failing to implement adequate security measures to control employee access to the Belgian Central Credit Register in violation of Articles 32, 25, 24, and 5(2) GDPR.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1)(f)Read →
- Art. 32Security of processingRead →
- Data principles
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2021/BE/003.