AEPD (Spain) · 29 January 2024
Ayuntamiento de Llucmajor
About: Data principles, Data protection officer, Data security
FineNo fineViolation found
- Regulator
- AEPD (Spain)
- Decided
- 29 January 2024
- Country
- Spain
- Sector
- Not given
- Regulator’s reference
- EXP202204501
- Fino case number
- 2024/ES/117
What happened
The DPA found that a public institution violated security measure obligations when it stored a document with employees' personal data, including names and use of sick leave, in an intranet folder that was accessible to unintended recipients.
Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1)(f)Read →
- Art. 32Security of processingRead →
- Art. 37Designation of the data protection officerRead →
- Data principles
- Data protection officer
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2024/ES/117.