Enforcement · Slovak Data Protection Office EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Slovak Telekom: Insufficient technical and organisational measures to ensure information security
The controller did not take adequate security measures when processing personal data, thereby breaching the obligation to protect the processed personal data.
Full text
The controller did not take adequate security measures when processing personal data, thereby breaching the obligation to protect the processed personal data.
Industry: Media, Telecoms and Broadcasting
How it connects
References
Related across sources
C-119/12 Judgment of the Court (Third Chamber), 22 November 2012.#Josef Probst v mr.nexnet GmbH.#Reference for a preliminary ruling from the Bundesgerichtshof.#Electronic communications — Directive 2002/58/EC — Article 6(2) and (5) — Processing of personal data — Traffic data necessary for billing and debt collection — Debt collection by a third company — Persons acting under the authority of the providers of public communications networks and electronic communications services.#Case C‑119/12. In Case C-119/12, the Court of Justice of the European Union interpreted Article 6(2) and (5) of Directive 2002/58/EC (the ePrivacy Directive) in proceedings between Josef Probst… CJEU Nov 22, 2012 Personal Data Processing Telecommunications
C-175/20 SIA 'SS' v Valsts ieņēmumu dienests In Case C-175/20, the Court of Justice of the EU interpreted GDPR Articles 5 and 6 in response to a preliminary ruling from the Latvian Regional Administrative Court concerning a… CJEU ·Fifth Chamber Feb 24, 2022 Retention Period Personal Data Legitimate Interest
Us I-4772/2023-10 A utility and municipal services enterprise, Zagrebački Holding d.o.o (the controller) provided users of its services with the option to request a copy of their bill via email. Where the name appearing in the email address differed from the user’s… US Zagreb - Us I-4772/2023-10 ·Administrative Court of Zagreb Jul 22, 2026 Personal Data Retention Period Controllers
C-623/17 Privacy International v Secretary of State C-623/17 (Privacy International) CJEU Oct 6, 2020 IP Address Material scope (GDPR) Legitimate Interest
C-492/23 X v Russmedia Digital SRL and Inform Media Press SRL In Case C-492/23, the Court of Justice of the European Union (Grand Chamber) addressed a preliminary reference from the Curtea de Apel Cluj concerning whether an online… CJEU ·Grand Chamber Dec 2, 2025 Controllers Accountability Personal Data
3 O 762/19 LG Rostock: Pre-ticked cookie consent boxes invalid under Art 6(1)(a) GDPR The German consumer organisation Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband e.V. (vzbv, the claimant) filed a lawsuit… Sep 15, 2020 Consent Legitimate Interest Controllers