Information Commissioner (ICO) · 5 July 2021
Mermaids
Insufficient technical and organisational measures to ensure information security
- Regulator
- Information Commissioner (ICO)
- Decided
- 5 July 2021
- Country
- United Kingdom
- Sector
- Individuals and Private Associations
- Regulator’s reference
- Not recorded
- Fino case number
- 2021/GB/003
What happened
The UK DPA fined a transgender charity approximately €29,250 (£25,000) for infringing Article 5(1)(f), 32(1) and 32(2) GDPR. Internal emails containing special categories data sent by the charity, which supports gender non-conforming children and their families, were publicly available online for over a year.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Data principles
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2021/GB/003.