United Kingdom United Kingdom

Central Young Men’s Christian Association

8,700 €

GDPR enforcement action by Information Commissioner (ICO) on 2024-04-30.

Rank · Sector
#50
of 351 in Individuals and Private Associations
Rank · United Kingdom
#27
of 28
Rank · All fines
#1,489
of 3,050

Case details

Authority
Information Commissioner (ICO)
Date
2024-04-30
Controller / Processor
Central Young Men’s Christian Association
Sector
Individuals and Private Associations
Quoted Articles
Art. 5 (1) f) GDPR, Art. 32 (1), (2) GDPR
Type of violation
Insufficient technical and organisational measures to ensure information security

Summary

The UK DPA (ICO) has fined the Central Young Men’s Christian Association EUR 8,700. The controller had sent an email to individuals participating in a program for individuals suffering from HIV without using the blind copy option, which made the email addresses of all recipients known to other recipients. 166 individuals could be identified or potentially identified based on their email addresses. From this it could be concluded that these people were probably living with HIV.

Open original source Links to the regulator's original publication or another source.

Related fines