Spain Spain

Private individual

900 €

GDPR enforcement action by Spanish Data Protection Authority (aepd) on 2022-10-09.

Rank · Sector
#194
of 351 in Individuals and Private Associations
Rank · Spain
#866
of 1,075
Rank · All fines
#2,735
of 3,050

Case details

Authority
Spanish Data Protection Authority (aepd)
Date
2022-10-09
Controller / Processor
Private individual
Sector
Individuals and Private Associations
Quoted Articles
Art. 5 (1) f) GDPR, Art. 32 (1) GDPR
Type of violation
Insufficient technical and organisational measures to ensure information security

Summary

The Spanish DPA has imposed a fine on a private individual. The individual unauthorizedly sent e-mails with personal data to several recipients in an open distribution list. This made it possible for the recipients to view the e-mail addresses of all other recipients. The original fine of EUR 1,200 was reduced to EUR 900 due to voluntary payment and admission of responsibility.

Open original source Links to the regulator's original publication or another source.

Related fines