Search results

From GDPRhub
  • Article 32 GDPR (category GDPR Articles) (section (1) Measures appropriate to the risk)
    non-material damage. Article 32(1) GDPR reflects the principle of integrity and confidentiality enshrined in Article 5(1)(f) GDPR. The controller and the
    41 KB (5,197 words) - 12:17, 17 April 2024
  • requirements of data minimization (Article 5(1)(c) GDPR) and storage limitation (Article 5(1)(e) GDPR). Under Article 30(1)(f) GDPR, where possible, the controller
    31 KB (3,327 words) - 15:31, 5 June 2023
  • (e.g. Article 25 (1) and (2), Article 28(1), Article 32(1) GDPR, Article 89(1) GDPR). These measures can also be regarded as measures under Article 24(1)
    30 KB (3,458 words) - 10:31, 25 April 2024
  • limited to, security of processing (Article 32(1) GDPR) and the general principles of processing set out in Article 5 GDPR. In confirming the above interpretation
    20 KB (1,854 words) - 16:32, 8 March 2024
  • Article 82 GDPR (category GDPR Articles) (section (1) Right to receive compensation)
    specific rules. Article 82 GDPR introduces a right to compensation for damage caused as a result of an infringement of the GDPR. Article 82(1) contains the
    33 KB (4,215 words) - 09:57, 19 March 2024
  • Ordinance Article 5, paragraph Article 5 (2) 1, letter c and letter f., Article 5, paragraph Article 6 (1) (a) Article 32 (1), (1), (33) 1 and 35, para. 1. Below
    48 KB (7,442 words) - 10:24, 12 September 2022
  • CNIL (France) - SAN-2019-005 (category Article 32(1) GDPR)
    violates Article 32 GDPR. Retaining personal data of an applicant for a lease after another applicant has been selected also violates Article 5(1)(e) GDPR
    41 KB (6,558 words) - 17:09, 6 December 2023
  • to the data. The infringement of Article 32 of the GDPR led to a €10,000 fine (RON 48,748). The infringement of Article 3 of Law 506/2004 led to a fine
    7 KB (900 words) - 15:18, 13 December 2023
  • least one of the conditions set out in Article 6(1) GDPR? On the topic of non-material damages 4) Does Article 82(1) GDPR have a specific or general preventive
    14 KB (1,916 words) - 16:03, 2 February 2024
  • Article 4 GDPR (category GDPR Articles) (section (1) Personal data)
    required under the GDPR (e.g. from a security perspective under Article 32 GDPR or as a means of data minimisation under Article 5(1)(c) GDPR) can get confused
    125 KB (16,328 words) - 16:01, 8 March 2024
  • AP (The Netherlands) - 26.11.2020 (category Article 32(1) GDPR)
    pursuant to article 32(1) of the GDPR. The AP disagrees. The conclusion of the AP that OLVG does not comply with article 32(1) of the GDPR by not meeting
    67 KB (11,415 words) - 17:15, 12 December 2023
  • UODO (Poland) - ZSPR.421.2.2019 (category Article 32(1)(b) GDPR)
    (f), Article 5(2), Article 6(1), Article 7(1), Article 24(1), Article 25(1), Article 32(1)(b), Article 32(1)(c) and Article 32(1)(b), Article 32(1)(c) and
    71 KB (11,304 words) - 10:01, 17 November 2023
  • AEPD (Spain) - EXP202201721 (category Article 32(1) GDPR)
    violated Article 6 and Article 32 GDPR. The DPA seems to consider the authentication procedure itself as "processing" and therefore Article 32 GDPR applies
    79 KB (12,408 words) - 13:24, 13 December 2023
  • Datatilsynet (Denmark) - 2021-442-12980 (category Article 32(1) GDPR)
    In an Article 60 GDPR procedure, the Danish DPA reprimanded Danske bank for a violation of Article 32(1) GDPR. A technical error resulted in the unauthorised
    10 KB (1,214 words) - 11:39, 22 March 2024
  • ANSDPCP (Romania) - Fan Courrier Express SRL (category Article 32(1) GDPR)
    fined € 11.000 Fan Courrier Express SRL for violations of f Article 32 paragraphs (1) and (2) GDPR. The controller Fan Courrier Express SRL was sanctioned
    3 KB (197 words) - 15:10, 13 December 2023
  • AEPD (Spain) - PS/00064/2021 (category Article 32(1) GDPR)
    constituted a data breach and were therefore a violation of Article 32(1), and additionally Article 5(1)(f) for violating the confidentiality principle. The AEPD
    2 KB (174 words) - 13:55, 13 December 2023
  • Finnish DPA found a healthcare provider to have breached Article 32(1) GDPR and Article 32(2) GDPR for not implementing appropriate technical and organisational
    14 KB (1,978 words) - 16:09, 21 February 2024
  • AZOP (Croatia) - Decision 22-02-2021 (category Article 32(1)(b) GDPR)
    Jurisdiction: Croatia Relevant Law: Article 32(1)(b) GDPR Article 32(1)(d) GDPR Article 32(2) GDPR Article 32(4) GDPR Type: Complaint Outcome: Upheld Started:
    2 KB (197 words) - 15:52, 30 October 2023
  • level of security appropriate to the risk of processing according to Article 32(1) GDPR? The ANSPDCP found that the controller did not implement adequate
    5 KB (547 words) - 15:18, 13 December 2023
  • Commissioner (Cyprus) - 11.17.001.008.029 (category Article 32(1) GDPR)
    Commissioner held that CYTA violated articles 5 (1), 24 (1) and (2), 25 (1) and (2) and 32 of the GDPR and instructed CYTA to establish such security measures
    3 KB (193 words) - 16:52, 6 December 2023
  • regarding the security of processing, respectively art. 32 para. (4) in conjunction with art. 32 para. (1) and para. (2) of the General Data Protection Regulation
    4 KB (422 words) - 15:16, 13 December 2023
  • Datatilsynet (Norway) - 20/02137 (category Article 32(1) GDPR)
    Norge violated Article 33 GDPR by failing to notify the Datatilsynet of the data breach? Had Telenor Norge violated Article 32(1) GDPR by failing to implement
    5 KB (684 words) - 08:06, 7 May 2022
  • that the controller had breached its obligations under Articles 5(1)(f), as well as 32(1) and (2). As a consequence, the ANSPDCP issued an administrative
    4 KB (422 words) - 15:20, 13 December 2023
  • Datatilsynet (Denmark) - 2021-431-0138 (category Article 32(1) GDPR)
    there was a personal data breach pursuant to Article 4(12) GDPR. Moreover, it stated that Article 32(1) GDPR obliges controllers to take appropriate technical
    16 KB (2,496 words) - 15:23, 24 March 2022
  • Commissioner (Cyprus) - 11.17.001.007.251 (category Article 32(1)(b) GDPR)
    reason, claimed that she shall receive the medical report under the veil of GDPR. The Cypriot Office of the Commissioner for Personal Data Protection disagreed
    4 KB (448 words) - 16:52, 6 December 2023
  • concluded that the controller violated Article 32(1)(b), Article 32(1)(d), Article 32(2), and Article 32(4) GDPR. Therefore, the DPA decided to impose a
    6 KB (730 words) - 15:49, 30 October 2023
  • DPC - Health Service Executive (IN-19-9-2) (category Article 32(1) GDPR)
    garden. The decision found that the HSE infringed Articles 5(1)(f) and 32(1) of the GDPR by failing to implement appropriate technical and organisational
    3 KB (240 words) - 09:18, 3 March 2021
  • Datatilsynet (Denmark) - 2021-442-12425 (category Article 32(1) GDPR)
    in accordance with the rules in the Data Protection Regulation [1], Article 32 (1). 1. Below is a more detailed review of the case and a justification
    15 KB (2,304 words) - 15:24, 24 March 2022
  • AZOP (Croatia) - Decision 05-07-2021 (category Article 32(1)(b) GDPR)
    activities further violated Article 32(1)(b) and (d) GDPR. Accordingly, the DPA, in accordance with its powers under Article 58 (2) GDPR, imposed an administrative
    5 KB (599 words) - 15:38, 30 October 2023
  • provisions of Article 32 paragraph (4) in conjunction with Article 32 paragraph (1) and paragraph (2) of the GDPR, as well as of Article 33 paragraph (1) of the
    5 KB (568 words) - 15:10, 13 December 2023
  • Commissioner (Cyprus) - Α/Π 68/2017 (category Article 32(1)(d) GDPR)
    that Cyprus Police was responsible for a violation of Article 32 par.1(b) & (d) and par.(4) GDPR, as a result of the acts and/or omissions of the Police
    6 KB (649 words) - 16:51, 6 December 2023
  • Romanian DPA (ANSPDCP) fined leasing company €15,000 for violation of Article 32(1) and (2) GDPR after investigating a data breach reported by the company, where
    6 KB (732 words) - 15:17, 13 December 2023
  • AEPD (Spain) - E/03003/2020 (category Article 32(1) GDPR)
    this data breach a violation of Article 32(1) GDPR? The AEPD concluded that there was no violation of Article 32(1) GDPR, because the company had implemented
    21 KB (3,039 words) - 13:39, 13 December 2023
  • €283,000). It held that the controller violated Articles 25(1), 32(1)(b), 32(1)(d) and 32(2) GDPR by not taking appropriate technical and organizational security
    7 KB (855 words) - 15:30, 30 October 2023
  • violated Article 5(1)(f) GDPR and proved the ineffectivness of the controller's employee compliance training, in violation of Article 32 GDPR. The DPA
    7 KB (845 words) - 15:17, 13 December 2023
  • VDAI - VDAI vs VĮ Registrų centras (category Article 32(1)(b) GDPR)
    SE Register Center 15 thousand. A fine of EUR 1 million was imposed for infringements of Article 32 (1) (b) and (c) of the BDAR, ie failure to ensure
    8 KB (999 words) - 09:16, 17 November 2023
  • IMY (Sweden) - DI-2021-4355 (category Article 32(1) GDPR)
    6 November 2020, has processed personal data in violation of Article 32(1) 1 of the GDPR by sending sensitive personal data to the complainant in an e-mail
    28 KB (3,101 words) - 09:49, 7 June 2023
  • AEPD (Spain) - PS/00054/2021 (category Article 32(1) GDPR)
    infringement of article 32.1 of the RGPD, typified in article 83.4.a) of the RGPD, a fine of € 3,000 (three thousand euros), in accordance with article 73.g) of
    27 KB (3,993 words) - 13:52, 13 December 2023
  • AP (The Netherlands) - 19.01.2023 (category Article 32(1) GDPR)
    assessed if it ensured an appropriate level of security under Articles 32(1) and 32(2) GDPR. The DPA held that the controller did not make a proper risk assessment
    10 KB (1,351 words) - 17:05, 12 December 2023
  • VDAI (Lithuania) - VDAI vs UAB Prime Leasing (category Article 32(1)(a) GDPR)
    data. Hence, it considered Article 32(1)(a), Article 32(1)(b), Article 32(1)(d) GDPR to be breached. Pursuant to Article 82(2) GDPR, the DPA took several aggravating
    37 KB (4,319 words) - 09:20, 17 November 2023
  • AZOP (Croatia) - Decision 04-05-2023 (category Article 32(1) GDPR)
    organizational measures when processing personal data, as requested by Article 32(1)(b) and (d) GDPR. This implied a risk for the security of the personal data of
    12 KB (1,626 words) - 15:22, 30 October 2023
  • implement sufficient security measures, in breach of Articles 32 (1) b), d) and 32 (2) GDPR. NN Pensii Societate de Administrare a unui Fond de Pensii Administrat
    8 KB (1,064 words) - 08:35, 31 May 2023
  • AZOP (Croatia) - Decision 26-09-2023 (category Article 32(1) GDPR)
    accomodation via its web form and via e-mail, acting contrary to Article 13(1) GDPR and Article 13(2) GDPR. Further, the AZOP held that the controller failed to adopt
    12 KB (1,634 words) - 17:02, 6 November 2023
  • IMY (Sweden) - DI-2019-9457 (category Article 32(1) GDPR)
    administrative bodies, researchers and physicians in violation of Article 32(1) GDPR. Uppsala regional authorities notified the Swedish DPA (Integritetsskyddsmyndigheten
    43 KB (4,600 words) - 17:08, 23 March 2022
  • AEPD (Spain) - PS/00464/2020 (category Article 32(1) GDPR)
    data is regulated in articles 32, 33 and 34 of the GDPR. Article 32 of the RGPD "Security of treatment", establishes that: "1. Taking into account the state
    29 KB (4,300 words) - 14:41, 13 December 2023
  • LG München - 31 O 16606/20 (category Article 32(1) GDPR)
    subject pursuant to Article 82(1) GDPR, for a theft of their personal identity and financial data, because it violated Article 32(1) GDPR which led to a data
    25 KB (4,028 words) - 07:10, 8 February 2022
  • judicial remedy against the controller under Article 79(1) GDPR. Having said that, Article 32(1) and (2) GDPR make it clear that national courts must assess
    13 KB (1,963 words) - 11:04, 5 January 2024
  • Datatilsynet (Denmark) - 2019-431-0044 (category Article 32(1) GDPR)
    personal data did not comply with the rules of Article 5 (1) of the Data Protection Regulation. 1 (f) and Article 32 (1) of the Data Protection Regulation. First
    16 KB (2,399 words) - 16:34, 6 December 2023
  • AEPD (Spain) - E/07796/2020 (category Article 32(1) GDPR)
    certain level of security. Therefore, they did not find a violation of Article 32(1) and decided not to fine the controller. Share your comments here! Share
    18 KB (2,698 words) - 13:41, 13 December 2023
  • AEPD (Spain) - PS/00104/2020 (category Article 32(1) GDPR)
    violation of articles 5.1.f, of the RGPD -as set out in Article 83(5)(a) of the said regulation and 5(1)(f) in relation to Article 32(1)(b) and (c) - specified
    36 KB (6,022 words) - 13:59, 13 December 2023
  • Datatilsynet (Norway) - 19/02985 (category Article 32(1)(b) GDPR)
    implemented sufficient technical and organisational measures pursuant to Article 32 GDPR in relation to the leakage of pupils personal data to third-parties
    3 KB (253 words) - 18:52, 5 March 2022
  • could not be considered appropriate in accordance with Article 32(1) GDPR and Article 32(2) GDPR regarding the online appointment booking system. As a result
    25 KB (3,734 words) - 19:37, 27 March 2024
  • LG Bonn - 29 OWi 1/20 (category Article 32(1) GDPR)
    83(4)(a) GDPR in conjunction with [Article 32(1) GDPR. Article 32 (1) GDPRby failing, at least with gross negligence, to ensure processes for sufficient authentication
    58 KB (9,577 words) - 08:06, 16 September 2021
  • Datatilsynet (Denmark) - 2020-442-8866 (category Article 32(1) GDPR)
    of for shredding. 4.1. Article 32 of the Data Protection Regulation Pursuant to Article 32 (1) of the Data Protection Regulation 1, the data controller
    20 KB (3,045 words) - 16:40, 6 December 2023
  • ANSPDCP (Romania) - SC Medicover SRL (category Article 32(1)(b) GDPR)
    address. The Romanian DPA found a violation of Article 32(1)(b), Article 32(2) and Article 32(4) of the GDPR and fined SC Medicover SRL €2,000. Share your
    5 KB (575 words) - 15:21, 13 December 2023
  • ANSPDCP (Romania) - 04.01.2023 (category Article 32(1)(b) GDPR)
    violation of Article 32 GDPR, the "Security of processing". More specifically, the controller violated Article 32(1)(b), 32(2), and 32(4) GDPR. For its breaches
    4 KB (471 words) - 15:15, 13 December 2023
  • violating Article 32 GDPR. The DPA took also the corrective measure to order the operator to bring its processing operations into compliance with the GDPR according
    4 KB (456 words) - 15:18, 13 December 2023
  • Datatilsynet (Norway) - 20/01984 (category Article 32(1)(b) GDPR)
    breach of Article 32? The DPA concluded that the municipality had breached the required information security requirements as per Article 32(1)(b), cf. Article
    6 KB (653 words) - 18:55, 5 March 2022
  • Datatilsynet (Norway) - 18/02579 (category Article 32(1)(b) GDPR)
    subsequent violations of Article 32(1)(b) GDPR and Article 32(1)(d) GDPR and of the principle of accountability as foreseen in Article 5(2) GDPR read in conjunction
    41 KB (6,337 words) - 18:52, 5 March 2022
  • Datatilsynet (Denmark) - 2020-31-4131 (category Article 32(1) GDPR)
    the rules on e.g. data protection. It follows from Article 32 (1) of the Data Protection Regulation 1, that data controllers and data processors, taking
    24 KB (3,651 words) - 16:38, 6 December 2023
  • ANSPDCP (Romania) - 12.01.2023 (category Article 32(1)(b) GDPR)
    data. Hence, the controller violated Articles 32(1)(b) and 32(2) GDPR. Pursuant to its Article 58(2) GDPR statutory powers, the DPA ordered the controller
    5 KB (613 words) - 15:13, 13 December 2023
  • IMY (Sweden) - DI-2021-5595 (category Article 32(1) GDPR)
    of approximately €150,000 (1,600,000 SEK) on the University Hospital Board for the violation of Articles 5(1)(f) and 32(1) GDPR. The data breach notification
    47 KB (5,207 words) - 18:51, 21 March 2022
  • ANSPDCP (Romania) - 27.12.2022 (category Article 32(1)(b) GDPR)
    would have been required by Article 29 GDPR. Moreover, in violation of Article 32(1)(b), Article 32(2), and Article 34(4) GDPR, the controller had not implemented
    6 KB (790 words) - 15:13, 13 December 2023
  • CNIL (France) - SAN-2020-015 (category Article 32(1) GDPR)
    obligation of Article 32 GDPR? Does the fact that this health data is not encrypted constitute a breach of the security obligation under Article 32 GDPR? Does
    29 KB (4,374 words) - 16:03, 19 January 2024
  • AEPD (Spain) - PS/00287/2020 (category Article 32(1) GDPR)
    Online Levante, S.L.: for the infringement of Article 5(1)(f), €2,000. for the infringement of Article 32(1), €1,000. Share your comments here! Share blogs
    32 KB (4,837 words) - 14:26, 13 December 2023
  • AEPD (Spain) - PS/00483/2020 (category Article 32(1) GDPR)
    Asesoria Alpi Clua: for the infringement of Article 5(1)(f), €2,000. for the infringement of Article 32(1), €1,000. Share your comments here! Share blogs
    32 KB (4,834 words) - 14:43, 13 December 2023
  • UODO (Poland) - DKN.5130.2815.2020 (category Article 32(1) GDPR)
    and Article 58(2)(b) in connection with Article 5(1)(f), Article 24(1), Article 25(1), Article 32(1) and (2) of 2 of Regulation EU 2016/679 of the European
    37 KB (5,819 words) - 09:58, 17 November 2023
  • Articles 5(1)(a), (d) and (f), 9 and 32(1)(b) GDPR.” Pursuant to Article 58(2)(i), the DPA hence imposed an administrative fine as per Article 83(4) and
    10 KB (1,206 words) - 15:54, 6 December 2023
  • CNPD (Portugal) - Deliberação 984/2018 (category Article 32(1)(b) GDPR)
    the combined provisions of article 32, paragraph 1, subparagraphs b) and d) and article 83, paragraph 4, al.a), of the GDPR, with a fine of € 0.00 to €
    40 KB (5,935 words) - 16:55, 6 December 2023
  • Datatilsynet (Norway) - 20/01879 (category Article 32(1)(b) GDPR)
    highly sensitive personal data exposed, thus breaching Article 32(1)(b) GDPR and Article 32(2), cf. Article 24. An employee in a municipal health care center
    30 KB (4,302 words) - 18:53, 5 March 2022
  • LfDI (Baden-Württemberg) - O 1018/115 (category Article 32(1)(a) GDPR)
    for infringement of Article 32 (1) lit. a DSGVO [German Penal Code]. (Storage of unhashed passwords) here: Fine notice Enclosure: 1 transfer form, cash
    13 KB (1,926 words) - 10:22, 17 November 2023
  • Datatilsynet (Denmark) - 2020-432-0037 (category Article 32(1) GDPR)
    life and health. 5.1. Article 32 of the Data Protection Regulation It follows from Article 32 (1) of the Data Protection Regulation 1, that the data controller
    46 KB (7,343 words) - 16:39, 6 December 2023
  • (possible) fraud. This resulted in a breach of Article 5(1)(a) GDPR and Article 6(1) GDPR in conjunction with Article 8 of the Dutch Personal Data Protection
    49 KB (7,201 words) - 17:06, 12 December 2023
  • considered appropriate in accordance with Article 31(1)(b) GDPR and Article 32(2) GDPR. Pursuant to Article 58(2)(d) GDPR, the DPA ordered the controller to identify
    17 KB (2,339 words) - 13:39, 12 January 2024
  • controller had violated Article 5(1)(f) GDPR, Article 17(1) GDPR, Article 25(1) GDPR, Article 32(1) GDPR and Article 32(2) GDPR. As a result, the DPA issued
    56 KB (8,980 words) - 08:47, 4 March 2024
  • AEPD (Spain) - EXP202104875 (category Article 32(1) GDPR)
    A., with NIF A28157360, for a violation of article 32.1 of the GDPR, typified in article 83.4, a) of the GDPR, with a fine of €40,000 (forty thousand euros)
    54 KB (8,451 words) - 13:35, 13 December 2023
  • Court of Appeal of Brussels - 2020/AR/1333 (category Article 32(1) GDPR)
    5- □ 1-i; -J L ..J Brussels-2020 Court of Appeal / AR / 1333 p. 3 breach of articles 5.1.a} and 5.1.b), 6.1, 25.1 and 25.2, 32.1 and 32.4 of the GDPR read
    51 KB (7,792 words) - 11:43, 24 January 2022
  • Datatilsynet (Norway) - 20/01516 (category Article 32(1)(b) GDPR)
    title of documents containing sensitive information was a breach of Article 32(1)(b) GDPR, highlighting that the breach was reported to the municipality by
    26 KB (3,885 words) - 08:43, 7 May 2022
  • AP (The Netherlands) - 23.09.2021 (category Article 32(1) GDPR)
    which led to a (sensitive) data breach, in violation of Article 32(1) and Article 32(2) GDPR In Oktober 2019, a malicious third party gained unauthorized
    66 KB (8,861 words) - 17:08, 12 December 2023
  • Datatilsynet (Norway) - 20/02191 (category Article 32(1)(b) GDPR)
    processing special categories of data, cf. Article 32(1)(b) GDPR, Article 32(1)(d), Article 24 and Article 35, cf. Article 5. In May 2019, a municipality reported
    38 KB (5,967 words) - 11:48, 7 May 2022
  • Datatilsynet (Norway) - 20/02147 (category Article 32(1)(b) GDPR)
    the lack of security routines, thus breaching Article 32(1)(b) cf. Article 5 GDPR, Article 35 and Article 24(1), respectively. Teachers at two junior high
    24 KB (3,591 words) - 18:57, 5 March 2022
  • CNIL (France) - SAN-2020-003 (category Article 32(1) GDPR)
    principle, namely the breaches of articles 5-1-c), 5 -1 e), 13, 32 and 35-1 of the GDPR; no breach of Article 6 of the GDPR and of Directive 2002/58 / EC of the
    61 KB (10,028 words) - 17:09, 6 December 2023
  • UODO (Poland) - DKN.5130.1354.2020 (category Article 32(1)(b) GDPR)
    expressed in Article 5 (1 ) (a)) f, and reflected in the obligations set out in Article 24 (1), Article 25 (1), Article 32 (1 ) (b ) and (d) and Article 32 (2)
    74 KB (11,513 words) - 09:58, 17 November 2023
  • UODO (Poland) - DKN.5130.2024.2020 (category Article 32(1) GDPR)
    provisions of Regulation art. 5 sec. 1 lit. f), art. 24 sec. 1, art. 25 sec. 1, art. 28 sec. 1 and 3 and article. 32 sec. 1 and 2. In addition, by letters of
    75 KB (12,104 words) - 09:58, 17 November 2023
  • AEPD (Spain) - PS/00179/2020 (category Article 32(1) GDPR)
    as established in article 5 of the GDPR. The security of personal data is regulated in articles 32, 33 and 34 of the GDPR. III The GDPR defines personal
    100 KB (16,401 words) - 14:07, 13 December 2023
  • UODO (Poland) - DKN.5101.25.2020 (category Article 32(1)(d) GDPR)
    with Art. 5 sec. 1 lit. f, art. 24 sec. 1, art. 25 sec. 1, art. 32 sec. 1 lit. d, art. 32 sec. 2, art. 33 paragraph. 1 and art. 34 sec. 1 of the Regulation
    63 KB (10,088 words) - 09:52, 17 November 2023
  • NAIH (Hungary) - NAIH/2020/66/21 (category Article 32(1)(b) GDPR)
    regard to Client 1 that data management - infringed Article 25 (1) to (2) of the General Data Protection Regulation, - infringed Article 32 (1) (b) of the General
    67 KB (10,492 words) - 10:11, 17 November 2023
  • UODO (Poland) - ZSOŚS.421.25.2019 (category Article 32(1)(b) GDPR)
    5 sec. 1 lit. f, art. 5 sec. 2, art. 25 sec. 1, art. 32 sec. 1 lit. b, art. 32 sec. 1 lit. d, art. 32 sec. 2, art. 38 sec. 1, art. 39 sec. 1 lit. b and
    156 KB (25,012 words) - 10:01, 17 November 2023
  • Datatilsynet (Denmark) - 2018-423-0018 (category Article 5(1) GDPR)
    responsibility under Article 26 GDPR. Categories of data subjects and categories of personal data Pursuant to Article 30 (I) (1) (c) GDPR, a list must contain
    21 KB (3,119 words) - 16:22, 6 December 2023
  • ICO - Monetary Penalty on Ticketmaster UK Limited (category Article 32(1)(d) GDPR)
    failed to comply with the requirements of Article 32(1) and (2) GDPR. In particular: 6.12.1 Article 32(1)(b) GDPR required Ticketmaster to ensure the ongoing
    130 KB (21,195 words) - 13:52, 25 April 2021
  • AEPD (Spain) - EXP202105923 (category Article 5(1)(d) GDPR)
    controller violated Article 5(1)(d) GDPR ("accuracy"), but a more natural conclusion would be to find a violation of Article 32(1)(d) GDPR ("adoption of adequate
    26 KB (3,846 words) - 12:42, 13 December 2023
  • DPC (Ireland) - IN-20-7-1 (category Article 32(1) GDPR)
    measures when recording group sessions in violation of Article 5(1)(f) GDPR and Article 32(1) GDPR. The controller is Men Overcoming Violence Ireland ("MOVE")
    4 KB (352 words) - 10:00, 8 March 2022
  • Datatilsynet (Denmark) - 2021-423-0241 (category Article 32(1) GDPR)
    DPA found no violation of Article 32(1) GDPR. The elements that the DPA took into account to exclude the existence of a GDPR infringement were the following
    14 KB (1,916 words) - 12:07, 11 October 2023
  • Datatilsynet (Denmark) - 2021-423-0236 (category Article 32(1) GDPR)
    The Danish DPA found that the Høje-Taastrup Municipality violated Article 32(1) GDPR because it did not have guidelines or objective criteria in place
    13 KB (1,970 words) - 16:12, 22 March 2022
  • AP (The Netherlands) - 24.02.2022 (category Article 13(1)(e) GDPR)
    requirements of article 24 and 32, paragraph 1, AVG and further elaborated in article32, paragraph2, preamble, FISHOrdinancesBIO standards5.1.1,5.1.1.1and5.1.2.1.
    179 KB (22,957 words) - 17:07, 12 December 2023
  • Datatilsynet (Denmark) - 2021-31-5743 (category Article 32(1) GDPR)
    wall. The DPA held that the controller violated Article 32(1) GDPR. The obligation under Article 32(1) GDPR to implement appropriate technical and organisational
    16 KB (2,304 words) - 09:50, 7 September 2022
  • ANSPDCP (Romania) - Banca Comercială Română SA (category Article 32(1)(b) GDPR)
    This amounted to a violation of Article 25(1) GDPR, Article 32(1)(b) GDPR, Article 32(1)(d) GDPR, Article 32(2) GDPR. Consequently, the DPA fined the
    5 KB (558 words) - 08:06, 26 September 2022
  • ANSPDCP (Romania) - 24.10.2023 (category Article 32(1)(b) GDPR)
    Romanian DPA found that the controller had violated Articles 32(1)(b), 32(1)(d) and 32(2) GDPR, as they had failed to implement adequate technical and organisational
    4 KB (461 words) - 14:26, 6 November 2023
  • DPC (Ireland) - IN-21-6-2 (category Article 32(1) GDPR)
    implement appropriate technical and organisational measures pursuant to Article 32(1) GDPR applies equally to controllers and processors. As the Controller identified
    8 KB (1,091 words) - 09:46, 23 March 2023
  • IMY (Sweden) - DI-2021-4664 (category Article 32(1) GDPR)
    in Article 5 GDPR. One of these principles is the requirement of security under Article 5(1)(f) GDPR (‘integrity and confidentiality’). Article 32 GDPR
    21 KB (2,284 words) - 14:03, 9 November 2022
View (previous 100 | ) (20 | 50 | 100 | 250 | 500)