Data Protection Commissioner of Malta · 17 January 2022
C-Planet (IT Solutions) Limited
Insufficient technical and organisational measures to ensure information security
- Regulator
- Data Protection Commissioner of Malta
- Decided
- 17 January 2022
- Country
- Malta
- Sector
- Industry and Commerce
- Regulator’s reference
- Not recorded
- Fino case number
- 2022/MT/004
What happened
The Maltese DPA imposed a fine of €65,000 on the IT company C-Planet for not notifying a data breach and not implementing appropriate technical measures to prevent the breach in violation of Article 5(1)(f), Article 33 and Article 34 GDPR. The data breach also revealed that personal and special categories of data were processed without a proper legal basis under Article 6 and Article 9 GDPR, and that the information required under Article 14 GDPR was not provided to the data subjects.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1)(f)Read →
- Art. 6Lawfulness of processing6(1)Read →
- Art. 14Information to be provided where personal data have not been obtained from the data subjectRead →
- Art. 32Security of processingRead →
- Art. 33Notification of a personal data breach to the supervisory authorityRead →
- Art. 34Communication of a personal data breach to the data subjectRead →
- Data breach
- Data principles
- Data security
- Transparency
- Unlawful processing
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2022/MT/004.