Skip to content
Enforcement · Czech DPA (UOOU) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Individual entrepreneur - no further details published: Insufficient technical and organisational measures to ensure information security

The operator of an online game was exposed to several DDoS attacks which caused the malfunctioning of the servers.

€980 Fine
Individual entrepreneur - no further details published
CZECH REPUBLIC
Art. 32 GDPR

Full text

The operator of an online game was exposed to several DDoS attacks which caused the malfunctioning of the servers. The attacker blackmailed the operator stating that the attacks will not stop unless he pays money. As part of the blackmail, the attacker offered the operator that he will create an upgraded and better firewall protection to the servers of the operator. The operator agreed and paid the attacker. The operator implemented the new code from the attacker which proved better than the old one but there was a 'backdoor' in the code. The attacker used the backdoor to steal all the data from the server about the players and uploaded these details to his website. The Office for Personal Data Protection concluded that the operator did not take apropriate security measures.

Industry: Individuals and Private Associations

How it connects

C-755/21 Marián Kočner v European Union Agency for Law Enforcement Cooperation (Europol) In Case C-755/21 P, Marián Kočner appealed a General Court judgment dismissing his claim for compensation against Europol for alleged damage arising from Europol's disclosure of… Grand Chamber Mar 5, 2024 Supervision Liability Personal Data
C-175/20 SIA 'SS' v Valsts ieņēmumu dienests In Case C-175/20, the Court of Justice of the EU interpreted GDPR Articles 5 and 6 in response to a preliminary ruling from the Latvian Regional Administrative Court concerning a… Fifth Chamber Feb 24, 2022 Retention Period Personal Data Legitimate Interest
C-740/22 Endemol Shine Finland Oy In Case C-740/22, the Court of Justice of the European Union (Sixth Chamber) ruled on a preliminary reference from the Itä-Suomen hovioikeus (Court of Appeal, Eastern Finland)… Sixth Chamber Mar 7, 2024 Criminal Data Personal Data Types of Special Categories of Personal Data
C-268/21 Norra Stockholm Bygg AB v Per Nycander AB In Case C-268/21, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Swedish Supreme Court in proceedings between Norra Stockholm… Third Chamber Mar 2, 2023 Retention Period Anonymization Personal Data