# Legal Entity: Insufficient technical and organisational measures to ensure information security

- Type: Enforcement
- Source: Slovenian Supervisory Authority (Informacijski pooblaščenec)
- Date: 2025-12-04
- Original: https://www.enforcementtracker.com/ETid-3010
- Canonical: https://overview.legal/posts/52364
- Topics: Encryption, Security, Controllers, Personal Data, Processing Agreement, Supervisory Authorities, Data Controller, Supervision

## Summary

The Slovenian DPA has imposed a fine of EUR 1,300 on a legal entity. An employee of the controller stored personal data on her work laptop without securing it, for example by encrypting it, and took the laptop outside of the secured workspace, thereby allowing third parties to gain access to the data. The entity was fined EUR 1,000, and the person responsible was fined EUR 300.

## Full text

The Slovenian DPA has imposed a fine of EUR 1,300 on a legal entity. An employee of the controller stored personal data on her work laptop without securing it, for example by encrypting it, and took the laptop outside of the secured workspace, thereby allowing third parties to gain access to the data. The entity was fined EUR 1,000, and the person responsible was fined EUR 300.

GDPR Articles: Art. 32 (1) a), b) GDPR
Industry: Not assigned

---
Generated by overview.legal · https://overview.legal/posts/52364 · 2026-08-22
