# Legal Entity: Insufficient technical and organisational measures to ensure information security

- Type: Enforcement
- Source: Slovenian Supervisory Authority (Informacijski pooblaščenec)
- Date: 2025-07-25
- Original: https://www.enforcementtracker.com/ETid-3005
- Canonical: https://overview.legal/posts/52359
- Topics: Data Breaches, Security, Privacy by Design & Default, Processing Agreement, Controllers, Personal Data, Law Enforcement, Supervisory Authorities, Data Controller, Supervision

## Summary

The Slovenian DPA has imposed a fine of EUR 5,020 on a legal entity. The controller had developed an application that allowed the exchange of personal data, but failed to implement technical measures to protect the programming interface when switching from the test environment to the production environment. This resulted in a data breach affecting approximately 100,000 users. The entity was fined EUR 4,820, and the person responsible was fined EUR 200.

## Full text

The Slovenian DPA has imposed a fine of EUR 5,020 on a legal entity. The controller had developed an application that allowed the exchange of personal data, but failed to implement technical measures to protect the programming interface when switching from the test environment to the production environment. This resulted in a data breach affecting approximately 100,000 users. The entity was fined EUR 4,820, and the person responsible was fined EUR 200.

GDPR Articles: Art. 32 GDPR
Industry: Not assigned

---
Generated by overview.legal · https://overview.legal/posts/52359 · 2026-08-22
