Fino

Information Commissioner (ICO) · 5 July 2021

Mermaids

Insufficient technical and organisational measures to ensure information security

Fine€29,000Fine issued
Regulator
Information Commissioner (ICO)
Decided
5 July 2021
Country
United Kingdom
Sector
Individuals and Private Associations
Regulator’s reference
Not recorded
Fino case number
2021/GB/003
Export as PDF

What happened

The UK DPA fined a transgender charity approximately €29,250 (£25,000) for infringing Article 5(1)(f), 32(1) and 32(2) GDPR. Internal emails containing special categories data sent by the charity, which supports gender non-conforming children and their families, were publicly available online for over a year.

Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Data principles
  • Data security

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2021/GB/003.