Enforcement · Cypriot Data Protection Commissioner EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Universal Life Insurance Public Co Ltd.: Insufficient data processing agreement
The Cypriot DPA has imposed a fine of EUR 3,500 on Universal Life Insurance Public Co Ltd.
Full text
The Cypriot DPA has imposed a fine of EUR 3,500 on Universal Life Insurance Public Co Ltd. The processor of the data controller had suffered a data breach in which personal data of customers were mistakenly disclosed to other customers. During its investigation, the DPA found that the controller had failed to contractually regulate the relationship with its processor. The DPA concluded that the controller had contracted a processor without ensuring that the processor provided sufficient guarantees for the implementation of appropriate technical and organizational measures to protect personal data.
Industry: Finance, Insurance and Consulting
How it connects
References
Related across sources
Guidelines 07/2020 concepts of controller and processor in the GDPR Guidelines ·EDPB Jul 7, 2021 Controllers Processors IP Address
14/2021 Cypriot court backs DPA fines of €40,000 each on football clubs and €25,000 on processor On 26 July 2021, a journalist informed the Cypriot DPA of a security vulnerability on an online platform. This online platform hosted ticket purchase sites of two Cypriot football… Administrative Court of Cyprus May 12, 2026 Controllers Processors Supervisory Authorities
C-311/18 Data Protection Commissioner v Facebook Ireland and Maximillian Schrems C-311/18 (Schrems II) CJEU Jul 16, 2020 Privacy Shield Processing Agreement International Transfer
Opinion 15/2025 certification criteria of BDO Consulting GmbH ·Opinion ·EDPB Jul 14, 2025 Certification Supervision Supervisory Authorities
S 5 SF 65/24 DS SG Nürnberg: MOVEit zero-day cyberattack via processor did not breach Art. 32 GDPR The data subject (a child born in 2018), represented by her parents, was insured with the controller (a statutory health insurance provider) and participated in its digital bonus… Social Court Nuremberg Jun 10, 2026 Processors Controllers Integrity and Confidentiality Principle
C-741/21 GP v juris GmbH In Case C-741/21, the Court of Justice of the European Union (Third Chamber) addressed a preliminary reference from the Landgericht Saarbrücken in proceedings between data subject… CJEU ·Third Chamber Apr 11, 2024 Liability Personal Data Integrity and Confidentiality Principle