Skip to content
News · noyb - European Center for Digital Rights EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

noyb files two complaints against EU Parliament over massive data breach

Data Security In early May 2024, the European Parliament informed its staff of a massive data breach in the institution’s recruiting platform (called “PEOPLE”).

Full text

Data Security In early May 2024, the European Parliament informed its staff of a massive data breach in the institution’s recruiting platform (called “PEOPLE”). The breach affected the personal data of more than 8,000 staff. This included ID cards and passports, criminal record extracts, residence documents and even sensitive data such as marriage certificates that reveal a person’s sexual orientation. The Parliament only found out about the breach months after it happened, and still doesn’t seem to know the cause. This is particularly worrying as the Parliament has long been aware of vulnerabilities in its cybersecurity system. EU institutions are naturally high up on the list of hackers and foreign adversaries. noyb has now lodged two complaints with the European Data Protection Supervisor on behalf of four parliament employees. Complaint against the European Parliament #1Complaint against the European Parliament #2The data of all applicants in one place. Before you can apply for a j

How it connects

C-77/21 Digi Távközlési és Szolgáltató Kft. v Nemzeti Adatvédelmi és Információszabadság Hatóság In this preliminary ruling, the CJEU interpreted Articles 5(1)(b) and 5(1)(e) GDPR in proceedings between Digi Távközlési és Szolgáltató Kft. and the Hungarian National Authority… CJEU ·First Chamber Oct 20, 2022 Retention Period Storage Limitation Personal Data
C-687/21 BL v MediaMarktSaturn Hagen-Iserlohn GmbH In Case C-687/21, the Court of Justice of the European Union interpreted Articles 5, 24, 32, and 82 of the GDPR in response to a preliminary ruling request from the Amtsgericht… CJEU ·Third Chamber Jan 25, 2024 Liability Integrity and Confidentiality Principle Data Breaches
14/2021 Cypriot court backs DPA fines of €40,000 each on football clubs and €25,000 on processor On 26 July 2021, a journalist informed the Cypriot DPA of a security vulnerability on an online platform. This online platform hosted ticket purchase sites of two Cypriot football… Administrative Court of Cyprus May 12, 2026 Controllers Processors Supervisory Authorities