Data Protection Authority of Ireland · 23 March 2021
Irish Credit Bureau DAC
Insufficient technical and organisational measures to ensure information security
- Regulator
- Data Protection Authority of Ireland
- Decided
- 23 March 2021
- Country
- Ireland
- Sector
- Finance, Insurance and Consulting
- Regulator’s reference
- Not recorded
- Fino case number
- 2021/IE/007
What happened
The Irish DPA fined the Irish Credit Bureau (ICB) €90,000 regarding a technical error in its database which lead to the disclosure of incorrect account records. The ICB violated Article 25(1) GDPR by failing to take measures designed to implement the accuracy principle in the database, and Articles 5(2) and 24(1) GDPR by failing to undertake appropriate testing of coding changes.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(2)Read →
- Art. 24Responsibility of the controller24(1)Read →
- Art. 25Data protection by design and by default25(1)Read →
- Accountability
- Data principles
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2021/IE/007.