Enforcement · Spanish Data Protection Authority (aepd) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
CAJA RURAL DE EXTREMADURA S.C.C.: Non-compliance with general data processing principles
How it connects
Related across sources
Case Law Deutsche Wohnen SE v Staatsanwaltschaft Berlin News Danish SA Declares Use of Google Analytics Unlawful Without Supplementary Measures Guidance Guidelines 07/2020 on the concepts of controller and processor in the GDPR Guidance Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 Literature GDPR Implementation Series ∙ Hungary: Introduction to the GDPR Application and a Brief History of Data Protection Literature GDPR Implementation Series ∙ Netherlands: The GDPR Implementation Act
Full text
The Spanish DPA has imposed a fine on CAJA RURAL DE EXTREMADURA S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a security vulnerability in its systems. The DPA found that the company had failed to implement the necessary security measures that could have prevented such an incident. The original fine of EUR 110,000 was reduced to EUR 88,000 due to voluntary payment.
Industry: Finance, Insurance and Consulting
Original document at the source www.aepd.es