Skip to content
Enforcement · Cypriot Data Protection Commissioner EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

AC Omonia: Insufficient technical and organisational measures to ensure information security

€40,000 Fine
AC Omonia
CYPRUS
Art. 32 GDPR

How it connects

Full text

The Cypriot DPA has imposed a fine of EUR 40,000 on the soccer club AC Omonia. Due to a lack of security measures in the club's ticket sales system, it was possible for an unauthorized person to access and disclose personal data of fans on the club's website. This data involved the name, the fan card number and the ID number of the data subjects. The DPA concluded that the club failed to implement adequate technical and organizational security measures. In separate proceedings, the DPA fined APOEL FC and Hellenic Technical Enterprises Ltd. for the same violations.

Industry: Individuals and Private Associations

Similar Content