Enforcement · Cypriot Data Protection Commissioner EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Cypriot Ministry of Defense: Insufficient technical and organisational measures to ensure information security
How it connects
Related across sources
News What Happened to the Risk-Based Approach to Data Transfers? Literature General Data Protection Regulation (GDPR) ambiguity, national diversity and data protection officer certification: Implementing Art. 39(1) GDPR in France, Italy, Luxembourg and Spain Guidance Guidelines 07/2020 on the concepts of controller and processor in the GDPR Guidance EDPB Annual Report 2021 Case Law HvJ EU: Privacy Shield ongeldig verklaard (Schrems II) Case Law Data Protection Commissioner v Facebook Ireland and Maximillian Schrems
Full text
The Cypriot DPA has imposed a fine of EUR 5,000 on the Cypriot Ministry of Defense. The controller had suffered a cyber attack which, according to the DPA, had been caused due to a lack of technical and organizational measures for the protection of personal data and a lack of supervision of a processor.
Industry: Public Sector and Education
Original document at the source www.dataprotection.gov.cy