AZOP (Croatia) - Fine against an information and communications company

From GDPRhub
AZOP - Fine against an information and communications company
Authority: AZOP (Croatia)
Jurisdiction: Croatia
Relevant Law: Article 32(1) GDPR
Type: Investigation
Outcome: Violation Found
Started:
Decided:
Published:
Fine: 50,000 EUR
Parties: n/a
National Case Number/Name: Fine against an information and communications company
European Case Law Identifier: n/a
Appeal: Unknown
Original Language(s): Croatian
Original Source: AZOP (in HR)
Initial Contributor: ap

The DPA fined an information and communication company €50,000 following a data breach for not implementing sufficient security measures when processing personal data.

English Summary

Facts

An information and communication company (the controller) reported a data breach to the DPA, who began an investigation. The data breach resulted from a hacking attack, in which a third party was able to access and move the entire information system. This gave them access to personal data of data subjects in the controller’s servers.

The controller took measures immediately after learning of the data breach, including initiating steps to recover the IT system.

Holding

The DPA found a violation of Article 32(1) GDPR. During its investigations the DPA found that the controller had multiple flaws in the design of the processing system. Overall, the controller had not implemented appropriate technical and organizational measures to ensure security of processing.

The DPA fined the controller €50,000

Comment

This summary is based on a press release of the DPA. The press release has no date, however, other websites mention this fine on 22.07.2025.

Further Resources

This case was mentioned in this website.

English Machine Translation of the Decision

The decision below is a machine translation of the Croatian original. Please refer to the Croatian original for more details.

Information and communication company fined EUR 50,000.00

The Agency received a Personal Data Breach Report (pursuant to Article 33 of the General Data Protection Regulation) from the controller, i.e. the information and communication company, stating that the personal data of the company's users were exposed by a hacker attack.

After the supervisory procedure, it was determined that the controller failed to timely implement appropriate technical security measures for the processing of personal data in relation to the existing and foreseeable risks, which could have prevented the breach or reduced the risk to the minimum possible extent. Specifically, the controller failed to protect personal data from destruction, alteration, prohibited disclosure and unauthorized access, which resulted in the attacker, once he had gained access to the system, being able to move freely throughout the entire information system, thereby completely compromising it and gaining access to the personal data of the respondents on the servers. Upon learning of the breach, the controller immediately began to resolve the security issue and, after determining all the circumstances, initiated steps to repair the entire IT system.

In this specific case, the controller made multiple failures in the design of the processing system, including appropriate corrective actions in the system. Specifically, by failing to take appropriate technical security measures for the processing of personal data in relation to ensuring the permanent confidentiality, integrity, availability and resilience of the system, a process for regularly testing, evaluating and assessing the effectiveness of technical and organizational measures to ensure the security of processing, and taking into account the risks posed by the processing, the risks of accidental or unlawful destruction, loss, alteration, unauthorized disclosure of personal data or unauthorized access to personal data by the controller, there was a violation of Article 32, paragraph 1, items b) and d) and paragraph 2 of the General Data Protection Regulation.

Due to the aforementioned violation of the General Data Protection Regulation, the controller was fined EUR 50,000.00.