Enforcement · Data Protection Authority of Baden-Wuerttemberg EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Food company: Insufficient technical and organisational measures to ensure information security
The company had set up an applicant portal on its website where interested parties could submit their application documents online.
Full text
The company had set up an applicant portal on its website where interested parties could submit their application documents online. However, the company did not offer an encrypted transmission of the data, nor did it store the applicant data in an encrypted or password-protected manner. In addition, the unsecured applicant data was linked to Google, so that anyone searching for the respective applicant names on Google could find their application documents and retrieve them without access restrictions.
Industry: Accomodation and Hospitality
How it connects
Related across sources
C-169/23 Nemzeti Adatvédelmi és Információszabadság Hatóság v UC In Case C-169/23, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Kúria (Hungary) concerning whether the Budapest Metropolitan… CJEU ·Third Chamber Nov 28, 2024 Personal Data Legitimate Interest Supervision
Guidelines 4/2019 Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 Guidelines on data protection by design and by default Guidelines ·EDPB Oct 20, 2020 Privacy by Design & Default Privacy by Default Privacy by Design
2026 Report on stakeholder event on anonymisation and pseudonymisation of 12 December 2025 EDPB Feb 18, 2026 Anonymization Pseudonymization Security
Guidelines 2/2020 articles 46 (2) (a) and 46 (3) (b) of Regulation 2016/679 for transfers of personal data between EEA and non-EEA public authorities and bodies Guidelines ·EDPB Dec 15, 2020 Personal Data Processing Agreement Privacy Shield
C-340/21 VB v Natsionalna agentsia za prihodite C-340/21 (VB v Natsionalna agentsia) CJEU Dec 14, 2023 Integrity and Confidentiality Principle Data Breaches Notification Obligation
Guidelines 01/2022 data subject rights - Right of access Guidelines ·EDPB Apr 17, 2023 Right of Access Personal Data Right to Rectification