Data Protection Authority of Ireland · 2 December 2021
Irish Teacher Council
Insufficient technical and organisational measures to ensure information security
Fine€60,000Fine issued
- Regulator
- Data Protection Authority of Ireland
- Decided
- 2 December 2021
- Country
- Ireland
- Sector
- Public Sector and Education
- Regulator’s reference
- Not recorded
- Fino case number
- 2021/IE/002
What happened
The Irish DPC fined a teaching council €60,000 for violations of Articles 5(1)(f), 32(1) and 33(1) GDPR by failing to notify a data breach in due time, and lacking appropriate technical and organisational measures to secure processing.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1)Read →
- Art. 32Security of processing32(1)Read →
- Art. 33Notification of a personal data breach to the supervisory authorityRead →
- Data breach
- Data principles
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2021/IE/002.