# Restaurant: Insufficient technical and organisational measures to ensure information security

- Type: Enforcement
- Source: Data Protection Authority of Hamburg
- Date: 2020-01-01
- Original: https://www.enforcementtracker.com/ETid-1048
- Canonical: https://overview.legal/posts/47163
- Topics: Security, Healthcare, Supervisory Authorities

## Summary

In order to combat the Covid 19 pandemic, a restaurant had put out an open list in which visitors had to enter their contact data. The fact that the list was openly displayed would have made it possible for unauthorized third parties to gain access to the data.

## Full text

In order to combat the Covid 19 pandemic, a restaurant had put out an open list in which visitors had to enter their contact data. The fact that the list was openly displayed would have made it possible for unauthorized third parties to gain access to the data.

GDPR Articles: Art. 32 GDPR
Industry: Accomodation and Hospitality

---
Generated by overview.legal · https://overview.legal/posts/47163 · 2026-08-22
