National Revenue Agency

€2.6M($2.8M USD)final

Date Issued

2019-08-28

Regulation

Authority

Data Protection Commission of Bulgaria (KZLD)

Country

Bulgaria

Violation Type

Failure to implement sufficient measures to ensure information security

Currency

EUR

Violation Summary

Because of the inappropriate handling of personal data, more than 6 million individuals had their data hacked. This informational leak was a direct cause of the company’s security laxity.

Articles Violated

Art. 32 GDPR

Other Fines for National Revenue Agency

DateRegulationAmount (USD)Type
2019-09-03GDPR$30,348Non-compliance with lawful basis for data processing
2019-09-03GDPR$30,348Non-compliance with lawful basis for data processing
2019-08-28GDPR$2,808,000Failure to implement sufficient measures to ensure information security