Enforcement · Cypriot Data Protection Commissioner EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Bank of Cyprus Public Company Ltd: Insufficient technical and organisational measures to ensure information security
How it connects
Related across sources
Guidance Statement 1/2025 on Age Assurance Guidance Guidelines 01/2021 Guidance Guidelines 10/2020 on restrictions under Article 23 GDPR Case Law SG Nürnberg - S 5 SF 65/24 DS News The Italian SA fined Poste Vita for data breach Guidance Report on stakeholder event on anonymisation and pseudonymisation of 12 December 2025
Full text
The data subject made a claim for access to information according to Art. 15 GDPR, which could not be answered, since the insurance contract of the data subject could not be found and has been lost. This constituted a violation of the rights of the data subject under Art. 15 GDPR as well as a violation of the obligations to protect personal data according to Art. 5 (1) f) GDPR and Art. 32 GDPR. In addition, the Data Breach Notification Obligations pursuant to Art. 33 f. GDPR have also been violated, as the data subject was not informed about the security incident in due time.
Industry: Finance, Insurance and Consulting
Original document at the source www.dataprotection.gov.cy