# Maynooth University: Insufficient technical and organisational measures to ensure information security

- Type: Enforcement
- Source: Data Protection Authority of Ireland
- Date: 2024-11-22
- Original: https://www.enforcementtracker.com/ETid-2780
- Canonical: https://overview.legal/posts/48895
- Topics: Security, Controllers, Public Authority, Public Sector, Education, IP Address, Processing Agreement, Law Enforcement, Supervisory Authorities, Data Controller

## Summary

The Irish DPA has imposed a fine of EUR 40,000 on Maynooth University. The controller failed to implement adequate technical and organisational measures, resulting in an unauthorised third party gaining access to multiple employees' email accounts, which the third party then used for fraudulent purposes.

## Full text

The Irish DPA has imposed a fine of EUR 40,000 on Maynooth University. The controller failed to implement adequate technical and organisational measures, resulting in an unauthorised third party gaining access to multiple employees' email accounts, which the third party then used for fraudulent purposes.

GDPR Articles: Art. 5 (1) f) GDPR, Art. 32 (1) GDPR, Art. 33 (1) GDPR
Industry: Public Sector and Education

---
Generated by overview.legal · https://overview.legal/posts/48895 · 2026-08-22
