Details:

Summary The Spanish DPA has imposed a fine on a private individual. The individual unauthorizedly sent e-mails with personal data to several recipients in an open distribution list. This made it possible for the recipients to view the e-mail addresses of all other recipients. The original fine of EUR 1,200 was reduced to EUR 900 due to voluntary payment and admission of responsibility.
Link: link
Related articles:  Art. 5 (1) f) GDPR, Art. 32 (1) GDPR
Type: Insufficient technical and organisational measures to ensure information security
Fine: EUR 900
Sector Individuals and Private Associations

 

All data is based on The CMS’s Law GDPR Enforcement Tracker Source: https://www.enforcementtracker.com/

Tags: case law