Skip to content
Enforcement · Czech DPA (UOOU) NL LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Zelfstandig ondernemer - geen verdere details gepubliceerd: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen.

Boete van €980 - Tsjechische Autoriteit voor Gegevensbescherming (UOOU).

Boete van €980 - Tsjechische Autoriteit voor Gegevensbescherming (UOOU).

€980 Fine
Individual entrepreneur - no further details published
CZECH REPUBLIC
Insufficient technical and organisational measures to ensure information security
Art. 32 GDPR
Individuen en particuliere verenigingen.

Full text

De beheerder van een online spel is het slachtoffer geworden van meerdere DDoS-aanvallen, wat leidde tot storingen in de servers. De aanvaller chanteerde de beheerder en dreigde de aanvallen voort te zetten tenzij er geld werd betaald. Als onderdeel van de chantage bood de aanvaller aan om een verbeterde en betere firewallbescherming voor de servers van de beheerder te implementeren. De beheerder stemde ermee in en betaalde de aanvaller. De beheerder implementeerde de nieuwe code van de aanvaller, die bleek beter te zijn dan de oude, maar er zat een "achterdeur" in de code. De aanvaller gebruikte deze achterdeur om alle gegevens van de server over de spelers te stelen en deze details te uploaden naar zijn website. Het Bureau voor Persoonsgegevens concludeerde dat de beheerder geen adequate beveiligingsmaatregelen had genomen.

GDPR-artikelen: Artikel 32 GDPR


Deze inhoud is automatisch vertaald met behulp van machinevertaling. De originele versie is beschikbaar in de brontaal.

How it connects

Us I-4772/2023-10 A utility and municipal services enterprise, Zagrebački Holding d.o.o (the controller) provided users of its services with the option to request a copy of their bill via email. Where the name appearing in the email address differed from the user’s… US Zagreb - Us I-4772/2023-10 ·Administrative Court of Zagreb Jul 22, 2026 Personal Data Retention Period Controllers
14/2021 Cypriot court backs DPA fines of €40,000 each on football clubs and €25,000 on processor On 26 July 2021, a journalist informed the Cypriot DPA of a security vulnerability on an online platform. This online platform hosted ticket purchase sites of two Cypriot football… Administrative Court of Cyprus May 12, 2026 Controllers Processors Supervisory Authorities
15625/2026 Cass.Civ. - 15625/2026 Istituto nazionale della previdenza sociale (INPS, the controller) is the Italian National Institute for Social Security. In 2021, the DPA fined the controller €300,000 for its… Supreme Court May 21, 2026 Privacy by Design & Default Privacy by Design DPIA
C-741/21 GP v juris GmbH In Case C-741/21, the Court of Justice of the European Union (Third Chamber) addressed a preliminary reference from the Landgericht Saarbrücken in proceedings between data subject… CJEU ·Third Chamber Apr 11, 2024 Liability Personal Data Integrity and Confidentiality Principle