Fino

APD/GBA (Belgium) · Date not published

Not named in the source

About: Data breach, Data principles, Data security, Data subject rights, Unlawful processing

FineNo fineViolation found
Regulator
APD/GBA (Belgium)
Decided
Date not published
Country
Belgium
Sector
Not given
Regulator’s reference
07/2021
Fino case number
ND/BE/003
Export as PDF

What happened

The Belgian DPA (APD/GBA) held that intent is not a criterium to assess processing and that mistakenly sending an e-mail does not necessarily constitute a data breach as a human error does not always mean the technical and organisational measures are not adequate. Finally, the DPA held that merely receiving an e-mail is not processing.

Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Data breach
  • Data principles
  • Data security
  • Data subject rights
  • Unlawful processing

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote ND/BE/003.