Home / Business and Politics / AZOP Imposed Two Fines Totaling 2.18 Million Kuna for Personal Data Breach

AZOP Imposed Two Fines Totaling 2.18 Million Kuna for Personal Data Breach

The Agency for the Protection of Personal Data has imposed two monetary fines totaling 2.18 million kuna due to failures in the protection of personal data, with the majority of this amount, or 2.15 million kuna, relating to a fine against the “data controller-telecommunications service provider,” as reported by AZOP.

Without specifying which telecommunications service provider it concerns, AZOP emphasizes that the fine was imposed due to the failure to take appropriate technical and organizational security measures for the processing of personal data, which led to the unauthorized processing of personal data of about 100 thousand respondents, or unauthorized access to personal data by an attacker.

“The data controller did not take the necessary measures to achieve an appropriate level of security in accordance with existing foreseeable risks, which is contrary to the General Data Protection Regulation,” AZOP states, adding that they learned of the breach from the data controller through a report on the personal data breach, and the data controller also informed service users about the incident.

They also established that this data controller implements certain organizational and technical measures in the processing of personal data, but in this case, they were insufficient, and the data controller made multiple failures in designing the processing system, for which administrative monetary fines of up to 10 million euros are foreseen, or in the case of entrepreneurs, up to 2% of total annual turnover worldwide for the previous financial year, depending on which is higher.

As a mitigating circumstance, AZOP notes that the “data controller is one of the leading telecommunications service providers in Croatia and it was to be expected that due to the large volume of personal data it processes, it would apply more complex organizational and technical protection measures.

The second fine is significantly smaller, amounting to 30 thousand kuna, and was imposed for failing to mark the object under video surveillance, which AZOP determined through direct unannounced supervision.

It was established that the data controller – a sales-service center for automobiles based in Zagreb did not mark that certain premises, as well as external surfaces of the object, were under video surveillance, which is contrary to the General Data Protection Regulation.

AZOP also adds that both fines are paid into the state budget.

Earlier imposed administrative monetary fines this year, in early March, totaling 1.6 million kuna related to a fine of 940 thousand kuna against a company from the energy sector, while 675 thousand kuna was imposed on a retail chain.

Neither then, nor today, did AZOP specify the names of the companies that received the fines, interpreting this as the implementation of the Law on the Implementation of the General Data Protection Regulation.