Ireland Ireland

Maynooth University

40,000 €

GDPR enforcement action by Data Protection Authority of Ireland on 2024-11-22.

Rank · Sector
#78
of 357 in Public Sector and Education
Rank · Ireland
#30
of 36
Rank · All fines
#842
of 3,050

Case details

Authority
Data Protection Authority of Ireland
Date
2024-11-22
Controller / Processor
Maynooth University
Sector
Public Sector and Education
Quoted Articles
Art. 5 (1) f) GDPR, Art. 32 (1) GDPR, Art. 33 (1) GDPR
Type of violation
Insufficient technical and organisational measures to ensure information security

Summary

The Irish DPA has imposed a fine of EUR 40,000 on Maynooth University. The controller failed to implement adequate technical and organisational measures, resulting in an unauthorised third party gaining access to multiple employees' email accounts, which the third party then used for fraudulent purposes.

Open original source Links to the regulator's original publication or another source.

Related fines