Spanish Data Protection Authority (AEPD) · 10 December 2024
GENERALI ESPAÑA, SOCIEDAD ANONIMA DE SEGUROS Y REASEGUROS
Insufficient technical and organisational measures to ensure information security
Fine€4,000,000Fine issued
- Regulator
- Spanish Data Protection Authority (AEPD)
- Decided
- 10 December 2024
- Country
- Spain
- Sector
- Finance, Insurance and Consulting
- Regulator’s reference
- Not recorded
- Fino case number
- 2024/ES/019
What happened
The DPA fined an insurance company €4,000,000 after an unauthorised third party was able to access the data of over 25,000 former clients of the controller due to inadequate security measures.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1)(f)Read →
- Art. 25Data protection by design and by defaultRead →
- Art. 32Security of processingRead →
- Art. 35Data protection impact assessmentRead →
- Accountability
- DPIA
- Data principles
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2024/ES/019.