Skip to content
Enforcement · Autoriteit Persoonsgegevens EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Transavia: Insufficient technical and organisational measures to ensure information security

The Dutch DPA has fined airline Transavia EUR 400,000.

€400,000 Fine
Transavia
THE NETHERLANDS
Art. 32 GDPR

Full text 2 findings

Paragraphs carrying a topic or an applied provision show those connections inline
§

The Dutch DPA has fined airline Transavia EUR 400,000. In 2019, the airline suffered a data breach, in which a hacker gained access to Transavia's systems through two accounts held by the company's IT department. This could have potentially allowed the hacker to access data such as names, dates of birth, gender, email addresses, phone numbers, flight information and booking numbers of 25 million passengers. It was found that the hacker actually downloaded the personal data of 83,000 people. In 367 cases, the data included medical information of people who had requested, for example, wheelchair transportation or additional services because they were blind or deaf. The DPA noted that a lack of security measures allowed the hacker to access the systems. Thus, it was possible to access the airline's systems simply by entering the password. The systems did not incorporate multi-factor authentication.

§

Furthermore, the access rights of the accounts were not limited to necessary systems, allowing the hacker to use them to gain access to multiple Transavia systems. The DPA found that Transavia had breached its duty to implement technical and organizational measures to ensure a level of security appropriate to the risk to data subjects. GDPR Articles: Art. 32 (1), (2) GDPR Industry: Transportation and Energy

How it connects

2 of 2 paragraphs apply legislation or carry a topic — see them in the full text ↓
2022 EDPB Annual Report 2021 Enhancing the depth and breadth of data protection 2 EDPB Annual Report 2021 2 ENHANCING THE DEPTH AND BREADTH OF DATA PROTECTION An Executive Summary of this report, which… May 12, 2022 Privacy Shield Processing Agreement International Transfer
2020 EDPB Annual Report 2019 EDPB Annual Report 2019 1 EDPB Annual Report 2019 1 European Data Protection Board 2019 Annual Report WORKING TOGETHER FOR STRONGER RIGHTS An Executive Summary of this report,… May 18, 2020 Privacy by Design & Default Privacy by Default Supervision
C-768/21 TR v Land Hessen In Case C-768/21, the Court of Justice of the European Union (First Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden concerning TR's challenge of… CJEU ·First Chamber Sep 26, 2024 Supervision Data Breaches Integrity and Confidentiality Principle