Enforcement · Spanish Data Protection Authority (aepd) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
THE PHONE HOUSE SPAIN, S.L.: Insufficient technical and organisational measures to ensure information security
How it connects
Related across sources
News De Autoriteit Persoonsgegevens publiceert een rapport over de risicoanalyse van de AVG (Algemene Verordening Gegevensbescherming). News De Deense beschermingsautoriteit (SA) heeft verklaard dat het gebruik van Google Analytics onrechtmatig is zonder aanvullende maatregelen. News Danish SA Declares Use of Google Analytics Unlawful Without Supplementary Measures Guidance EDPB Annual Report 2021 Guidance Guidelines 07/2020 on the concepts of controller and processor in the GDPR Guidance EDPB Annual Report 2019
Full text
The Spanish DPA has imposed a fine of EUR 6.5 million on THE PHONE HOUSE SPAIN, S.L. The controller had suffered a ransomware attack affecting personal data of 13 million individuals (e.g. customers and employees), which was exfiltrated and published on the deep web. The DPA's investigation revealed that the controller had failed to implement appropriate technical and organisational measures to protect personal data, in order to prevent such an incident.
Industry: Media, Telecoms and Broadcasting
Original document at the source www.aepd.es