The Netherlands The Netherlands

UWV (Dutch employee insurance service provider)

450,000 €

GDPR enforcement action by Dutch Supervisory Authority for Data Protection (AP) on 2021-05-31.

Rank · Sector
#46
of 322 in Finance, Insurance and Consulting
Rank · The Netherlands
#19
of 43
Rank · All fines
#257
of 3,050

Case details

Authority
Dutch Supervisory Authority for Data Protection (AP)
Date
2021-05-31
Controller / Processor
UWV (Dutch employee insurance service provider)
Sector
Finance, Insurance and Consulting
Quoted Articles
Art. 32 GDPR
Type of violation
Insufficient technical and organisational measures to ensure information security

Summary

The Dutch DPA (AP) has fined UWV (the Dutch employee insurance service provider - 'Uitvoeringsinstituut Werknemersverzekeringen) EUR 450,000. The UWV had not properly secured the sending of group messages via the "My Workbook" environment. This is a personal environment on the UWV website where job seekers have contact with the UWV. As a result, there were multiple data leaks of personal information, including health information, from a total of more than 15,000 individuals.

Open original source Links to the regulator's original publication or another source.

Related fines