Skip to content
Enforcement · Lithuanian Data Protection Authority (VDAI) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

UAB Prime Leasing: Insufficient technical and organisational measures to ensure information security

The Lithuanian DPA has fined UAB Prime Leasing, the operator of the short-term car rental platform CityBee, EUR 110,000.

€110,000 Fine
UAB Prime Leasing
LITHUANIA
Art. 32 GDPR

Full text 2 findings

Paragraphs carrying a topic or an applied provision show those connections inline
§

The Lithuanian DPA has fined UAB Prime Leasing, the operator of the short-term car rental platform CityBee, EUR 110,000. The DPA conducted the investigation on its own initiative after information about a possible personal data breach (Art. 33 GDPR) of the company's customers became public in February 2021. According to the company, they learned about the security breach from another cybersecurity service provider who informed them that the customer data of 110,302 CityBee users had been published on the website of the hacking forum RaidForums.com. This included data such as names, addresses, phone numbers, email addresses, personal identification numbers, driver's license numbers, type of payment card and the last four digits of the card number of the data subjects. The DPA's investigation revealed that the published data originated from an unsecured backup copy of a database. The DPA found that the data breach occurred due to the company's failure to comply with its obligation to implement technical and organizational measures to ensure a level of security appropriate to the risk to data subjects.

§

The company had, for example, failed to appoint a person with appropriate competence to be responsible for security and risk management. It had also failed to ensure that accesses to database files were logged and evaluated. In addition, the company had stored the database unencrypted, so that a person with technical knowledge could have had full access to the data in the file after downloading it. The personal codes in the database were furthermore stored unprotected and the passwords in the database were only encrypted with an encryption algorithm that was considered insecure. GDPR Articles: Art. 32 (1) b), d) GDPR Industry: Industry and Commerce

How it connects

2 of 2 paragraphs apply legislation or carry a topic — see them in the full text ↓
C-687/21 BL v MediaMarktSaturn Hagen-Iserlohn GmbH In Case C-687/21, the Court of Justice of the European Union interpreted Articles 5, 24, 32, and 82 of the GDPR in response to a preliminary ruling request from the Amtsgericht… CJEU ·Third Chamber Jan 25, 2024 Liability Integrity and Confidentiality Principle Data Breaches
14/2021 Cypriot court backs DPA fines of €40,000 each on football clubs and €25,000 on processor On 26 July 2021, a journalist informed the Cypriot DPA of a security vulnerability on an online platform. This online platform hosted ticket purchase sites of two Cypriot football… Administrative Court of Cyprus May 12, 2026 Controllers Processors Supervisory Authorities
C-77/21 Digi Távközlési és Szolgáltató Kft. v Nemzeti Adatvédelmi és Információszabadság Hatóság In this preliminary ruling, the CJEU interpreted Articles 5(1)(b) and 5(1)(e) GDPR in proceedings between Digi Távközlési és Szolgáltató Kft. and the Hungarian National Authority… CJEU ·First Chamber Oct 20, 2022 Retention Period Storage Limitation Personal Data
S 5 SF 65/24 DS SG Nürnberg: MOVEit zero-day cyberattack via processor did not breach Art. 32 GDPR The data subject (a child born in 2018), represented by her parents, was insured with the controller (a statutory health insurance provider) and participated in its digital bonus… Social Court Nuremberg Jun 10, 2026 Processors Controllers Integrity and Confidentiality Principle