The Agency for the Protection of Personal Data has imposed two monetary fines totaling 2.18 million kuna due to failures in the protection of personal data, with the majority of this amount, or 2.15 million kuna, relating to a fine against the “data controller-telecommunications service provider,” as reported by AZOP.
Without specifying which telecommunications service provider it concerns, AZOP emphasizes that the fine was imposed due to the failure to take appropriate technical and organizational security measures for the processing of personal data, which led to the unauthorized processing of personal data of about 100 thousand respondents, or unauthorized access to personal data by an attacker.
“The data controller did not take the necessary measures to achieve an appropriate level of security in accordance with existing foreseeable risks, which is contrary to the General Data Protection Regulation,” AZOP states, adding that they learned of the breach from the data controller through a report on the personal data breach, and the data controller also informed service users about the incident.
They also established that this data controller implements certain organizational and technical measures in the processing of personal data, but in this case, they were insufficient, and the data controller made multiple failures in designing the processing system, for which administrative monetary fines of up to 10 million euros are foreseen, or in the case of entrepreneurs, up to 2% of total annual turnover worldwide for the previous financial year, depending on which is higher.
