Details:

Summary The Hellenic DPA has imposed a fine of EUR 10,000 on IDIKA SA. IDIKA was operating in the context of providing free COVID-19 tests. The DPA found that IDIKA, in the course of its processing activities, did not sufficiently inform data subjects about the processing of their personal data. In addition, IDIKA stored personal data longer than necessary and had failed to implement sufficient technical and organizational measures to protect personal data.
Link: link
Related articles:  Art. 5 (1) e) GDPR, Art. 25 GDPR
Type: Non-compliance with general data processing principles
Fine: EUR 5,000
Sector Industry and Commerce

 

All data is based on The CMS’s Law GDPR Enforcement Tracker Source: https://www.enforcementtracker.com/

Tags: case law