GDPR Fines

A public record of GDPR enforcement across Europe — compiled by INPLP members

CYTA Ltd, Social Insurance Services of the Ministry of the Ministry of Labour, Welfare and Social Insurance of Cyprus, Cyprus Police

Country
Cyprus
Fine
10,000 EUR
Date
2017(First decision from 2017, the second in 2019 and finally in 2020)
Sector
(1) Telecommunications provider (2) The Social Insurance department of the Republic of Cyprus (3) The Police
Articles
Article 32

Unauthorised access to data and lack of security of processing

A series of media publications (printed and online press) mentioned the telecommunications company CYTA, the Social Insurance Services of the Ministry of the Ministry of Labour, Welfare and Social Insurance of Cyprus, and the Cyprus Police as data processors (due to their role regarding the mechanised system of the Social Insurance Services) involved in a scandal of leakage and/or violation of personal data of natural persons via this database, leading to the initiation of an investigation by the Office of the Commissioner for Personal Data Protection of Cyprus. The publications suggested that a member of the Police proceeded with searching for, printing and forwarding to a non-authorised recipient/third party of documents from the database. The Commissioner brought the publications to the Police's knowledge and requested a detailed statement on its behalf regarding the alleged violations. In its statement, the Cyprus Police acknowledged that one of its members, whose professional duties included his ability to have access to the Mechanised Database on vehicle owners, acting beyond the orders of the Police, proceeded with specific searches (within the database), located and printed documents (from the database), and then passed them on to a third party (a retired Police Officer).The Commissioner held that the existing supervising mechanisms of the Police were not operating properly at that time or at least they did not operate as efficiently as they should and, thus, were considered insufficient. The organisational and technical measures that the Police had taken were not effective and they proved themselves insufficient and unable to prevent the non-authorised forwarding of personal data to third-parties. The undertaking of further organisational measures and the frequent undertaking of internal controls of the tracking archives/history was deemed necessary. Thus, the Commissioner concluded that Cyprus Police was responsible for a violation of Article 32 par.1(b) & (d) and par.(4) GDPR, as a result of the acts and/or omissions of the Police, whose member proceeded with a non-authorised forwarding of personal data found within the Police's database of vehicle owners to a third party, thus exceeding their authority and the orders of the Police. Additionally, the Comissioner fined the Cyprus Telecommunications Authority ('CYTA') for failing to prevent an employee from leaking the personal data of 249 customers to a third party. In particular, the Commissioner highlighted that the employee's access to customer data should have been revoked following their transfer from the customer services department and that following internal policies and procedures in this regard could have prevented the leak. Furthermore, the Commissioner fined the Social Insurance department for allowing the police to have access to personal information data and failing to take adequate measures to secure data, despite warnings of the data protection officer.