Germany Germany

Restaurant

50,100 €

GDPR enforcement action by Data Protection Authority of Hamburg on 2020.

Rank · Sector
#11
of 100 in Accomodation and Hospitality
Rank · Germany
#42
of 116
Rank · All fines
#684
of 3,042

Case details

Authority
Data Protection Authority of Hamburg
Date
2020
Controller / Processor
Restaurant
Sector
Accomodation and Hospitality
Quoted Articles
Art. 32 GDPR
Type of violation
Insufficient technical and organisational measures to ensure information security

Summary

In order to combat the Covid 19 pandemic, a restaurant had put out an open list in which visitors had to enter their contact data. The fact that the list was openly displayed would have made it possible for unauthorized third parties to gain access to the data.

Open original source Links to the regulator's original publication or another source.

Related fines