Skip to content
Enforcement
EN

Lands Authority: Insufficient technical and organisational measures to ensure information security

€5,000 fine - Data Protection Commissioner of Malta

€5,000 Fine
Lands Authority
MALTA
Insufficient technical and organisational measures to ensure information security

Content

As a result of the lack of appropriate security measures on the Lands Authority website, over 10 gigabytes of personal data became easily accessible to the public via a simple google search. The majority of the leaked data contained highly-sensitive information and correspondence between individuals and the Authority itself. The Lands Authority chose not to appeal. In Malta, in the case of a breach by a public authority or body, the Data Protection Commissioner may impose an administrative fine of up to €25,000 for each violation and may additionally impose a daily fine of €25 for each day such violation persists.

GDPR Articles: Art. 5 GDPR, Art. 32 GDPR
Industry: Public Sector and Education