Company in the financial sector
€80K($86K USD)final
Date Issued
2019-04-04
Regulation
Authority
Data Protection Authority of Baden-Wuerttemberg
Country
Germany
Violation Type
Failure to implement sufficient measures to ensure information security
Currency
EUR
Violation Summary
The fine was issued because, in April 2019, the company hadn’t taken the necessary measures to ensure the integrity and confidentiality of information (as per Art. 5 para. 1 lit. f GDPR) when it disposed of documents that contained personal information of two clients. We should mention that the documents were simply disposed of in the general waste recycling system where they were found by a neighbor.
Articles Violated
Art. 5 GDPRArt. 32 GDPR