Croatian Data Protection Authority (AZOP) · 26 September 2023
Hotel
Insufficient legal basis for data processing
Fine€15,000Fine issued
- Regulator
- Croatian Data Protection Authority (AZOP)
- Decided
- 26 September 2023
- Country
- Croatia
- Sector
- Accommodation and Hospitality
- Regulator’s reference
- Not recorded
- Fino case number
- 2023/HR/004
What happened
The Croatian DPA imposed an administrative fine in the amount of €15,000 on a controller due to multiple GDPR violations in the context of its online booking system.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 6Lawfulness of processing6(1)Read →
- Art. 32Security of processing32(4)Read →
- Art. 38Position of the data protection officer38(6)Read →
- Data protection officer
- Data security
- Unlawful processing
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2023/HR/004.