# VIEC Limited: Non-compliance with general data processing principles

- Type: Enforcement
- Source: Data Protection Authority of Ireland
- Date: 2022-12-22
- Original: https://www.enforcementtracker.com/ETid-1564
- Canonical: https://overview.legal/posts/47679
- Topics: Data Breaches, Integrity and Confidentiality Principle, Security, Professional Secrecy, IP Address, Healthcare, Personal Data, Processing Agreement, Controllers, Privacy by Design & Default

## Summary

The Irish DPA has imposed a fine of EUR 100,000 on the nursing home operator VIEC Limited. The controller had notified the DPA of a data breach pursuant to Art. 33 GDPR. The controller had suffered a phishing attack in which an unauthorized third party gained access to an email account of a VIEC manager. As a result, the unknown third party also managed to access personal data such as health and biometric data of home residents. The DPA found this to be a breach of the principle of integrity and

## Full text

The Irish DPA has imposed a fine of EUR 100,000 on the nursing home operator VIEC Limited. The controller had notified the DPA of a data breach pursuant to Art. 33 GDPR. The controller had suffered a phishing attack in which an unauthorized third party gained access to an email account of a VIEC manager. As a result, the unknown third party also managed to access personal data such as health and biometric data of home residents. The DPA found this to be a breach of the principle of integrity and confidentiality. The DPA also found that the controller had failed to implement appropriate technical and organizational measures to protect personal data.

GDPR Articles: Art. 5 (1) f) GDPR, Art. 32 (1) GDPR
Industry: Industry and Commerce

---
Generated by overview.legal · https://overview.legal/posts/47679 · 2026-08-22
