Deputy Data Protection Ombudsman · 16 December 2021
Travel agency
Insufficient technical and organisational measures to ensure information security
Fine€6,500Fine issued
- Regulator
- Deputy Data Protection Ombudsman
- Decided
- 16 December 2021
- Country
- Finland
- Sector
- Industry and Commerce
- Regulator’s reference
- Not recorded
- Fino case number
- 2021/FI/003
What happened
The Finnish DPA imposed a fine of €6,500 on a travel agency for failing to adequately secure the personal data and for failing to comply with the data subject's request to erase their personal data.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1)(f)Read →
- Art. 17Right to erasure (‘right to be forgotten’)Read →
- Art. 25Data protection by design and by defaultRead →
- Art. 32Security of processingRead →
- Accountability
- Data principles
- Data security
- Data subject rights
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2021/FI/003.