# Cyprus Police: Insufficient technical and organisational measures to ensure information security

- Type: Enforcement
- Source: Cypriot Data Protection Commissioner
- Date: 2020-10-22
- Original: https://www.enforcementtracker.com/ETid-432
- Canonical: https://overview.legal/posts/46547
- Topics: Data Breaches, Integrity and Confidentiality Principle, Security, Privacy by Design & Default, Personal Data, Public Authority, Education, Public Sector, Law Enforcement

## Summary

A police officer had unauthorized access to a database holding personal data about vehicle owners and used the database for non-official purposes to pass information from the database to a third party. In this respect, the organizational and technical measures taken by the police to prevent unauthorized access to the database were insufficient to prevent the unauthorized disclosure of personal data to third parties.

## Full text

A police officer had unauthorized access to a database holding personal data about vehicle owners and used the database for non-official purposes to pass information from the database to a third party. In this respect, the organizational and technical measures taken by the police to prevent unauthorized access to the database were insufficient to prevent the unauthorized disclosure of personal data to third parties.

GDPR Articles: Art. 32 GDPR
Industry: Public Sector and Education

---
Generated by overview.legal · https://overview.legal/posts/46547 · 2026-08-22
