GDPR Fines

A public record of GDPR enforcement across Europe — compiled by INPLP members

Dutch DPA

Country
Netherlands
Fine
450,000 EUR
Date
2021-07-07
Sector
Public Sector
Articles
Art. 32(1)(2) GDPR

Insufficient security measures, even after several data breaches. The UWV has insufficiently checked and evaluated its own security measures.

UWV fined for poor security when sending group messages. The Dutch Data Protection Authority (AP) imposes a fine of € 450,000 on the Employee Insurance Agency (UWV). The UWV had not properly secured the sending of group messages via the so-called 'My Work Folder' environment. This is a personal environment on the UWV website, where job seekers have contact with the UWV. As a result, there were several data breaches of personal data, including health data.<br /><br />Between August 2016 and the end of 2018, the process for sending group messages via the My Workbook environment was not properly secured. The data leaks happened 9 times in that period, with a total of the data of more than 15,000 people ending up with the wrong recipients. As a result, files containing a multitude of personal data of job seekers ended up with the wrong recipients, namely in the My Work Folder environment of other job seekers.