# Bank of Cyprus Public Company Ltd: Insufficient technical and organisational measures to ensure information security

- Type: Enforcement
- Source: Cypriot Data Protection Commissioner
- Date: 2020-10-19
- Original: https://www.enforcementtracker.com/ETid-422
- Canonical: https://overview.legal/posts/46537
- Topics: Notification Obligation, Data Breaches, Article 19 GDPR - Notification of Rectification, Erasure or Restriction, Notified Body Reporting and Notification Obligations, Personal Data, Security, Insurance

## Summary

The data subject made a claim for access to information according to Art. 15 GDPR, which could not be answered, since the insurance contract of the data subject could not be found and has been lost. This constituted a violation of the rights of the data subject under Art. 15 GDPR as well as a violation of the obligations to protect personal data according to Art. 5 (1) f) GDPR and Art. 32 GDPR. In addition, the Data Breach Notification Obligations pursuant to Art. 33 f. GDPR have also been viola

## Full text

The data subject made a claim for access to information according to Art. 15 GDPR, which could not be answered, since the insurance contract of the data subject could not be found and has been lost. This constituted a violation of the rights of the data subject under Art. 15 GDPR as well as a violation of the obligations to protect personal data according to Art. 5 (1) f) GDPR and Art. 32 GDPR. In addition, the Data Breach Notification Obligations pursuant to Art. 33 f. GDPR have also been violated, as the data subject was not informed about the security incident in due time.

GDPR Articles: Art. 5 (1) f) GDPR, Art. 5 (2) GDPR, Art. 15 GDPR, Art. 32 GDPR, Art. 33 GDPR
Industry: Finance, Insurance and Consulting

---
Generated by overview.legal · https://overview.legal/posts/46537 · 2026-08-22
