Jimmy Orucevic’s Post

View profile for Jimmy Orucevic, graphic

Privacy Professional | Data Protection | Cybersecurity | Technology | CIPP/E | LLM

Spanish DPA fines company due to lack of information about compromised personal data after Brute Force Attack / inadequate Risk Assessment --> € 360'000 The Spanish #data protection authority investigated a report of a #security incident at 4FINANCE SPAIN FINANCIAL SERVICES (VIVUS). In the incident, personal data of the company's customers had been compromised by means of a Bruce Force attack. The #dataprotection officer of VIVUS considered the potential #risk to be too low to have to inform those affected. The AEPD instructed 4FINANCE SPAIN FINANCIAL SERVICES to do so. In addition, there were several complaints from private individuals indicating that there had been cases of identity theft in connection with the incident. The AEPD's investigation revealed that the risk assessment carried out by 4FINANCE SPAIN FINANCIAL SERVICES on its #web portal considered the risk to be significantly too low. There was no assessment of the risk for those affected by the specific security incident. The original fine of EUR 600,000, consisting of two penalties of EUR 200,000 (Art. 5 i f GDPR) and EUR 400,000 (Art 32 GDPR) respectively, was reduced to EUR 360,000 due to voluntary payment and admission of guilt. #gdpr #compliance

To view or add a comment, sign in

Explore topics