Fino

Commissioner (Cyprus) · 4 October 2023

Not named in the source

About: Data breach, Data principles, Data subject rights

FineNo fineViolation found
Regulator
Commissioner (Cyprus)
Decided
4 October 2023
Country
Cyprus
Sector
Not given
Regulator’s reference
11.17.001.010.007
Fino case number
2023/CY/012
Export as PDF

What happened

In the context of an Article 60 GDPR procedure, the Cypriot DPA reprimanded a controller for unlawfully asking a data subject’s ID when addressing an access request and for failing to inform its users properly about a data breach.

Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Data breach
  • Data principles
  • Data subject rights

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2023/CY/012.