3 ms·
There can indeed be lots of magic going on in a backend and various ways GDPR violations may or may not be discovered. Here's an amusing 320k euro fine https:/
by janto 5y ago
There can indeed be lots of magic going on in a backend and various ways GDPR violations may or may not be discovered.
Here's an amusing 320k euro fine
https://ico.org.uk/media/action-weve-taken/enforcement-notices/2616741/doorstop-en-20191217.pdf https://ico.org.uk/media/action-weve-taken/enforcement-notic...
On 24 July 2018 the MHRA had executed a search warrant at the premises of
Doorstep Dispensaree under the Human Medicines Regulations. In
the course of its search, the MHRA discovered, stored in a rear
courtyard, 47 crates, 2 disposal bags and 1 cardboard box full of
documents containing personal data. MHRA estimated
approximately 500,000 documents but cannot estimate the
number of data subjects.
MHRA have inspected the crates and the information contains:
a. Names
b. Addresses
c. Dates of Birth
d. NHS Numbers
e. Medical Information
f. Prescriptions
The dates on the documents range from January 2016 - June 2018.
The documents were not secure and they were not marked as
confidential waste. Some of the documents were soaking wet,
indicating that they had been stored in this way for some time.
I doubt there is a purely technical solution to finding this kind of problem :)
Edit: to be clear, the violation type here seems to have been "Insufficient technical and organisational measures to ensure information security"