GDPR Fines

A public record of GDPR enforcement across Europe — compiled by INPLP members

Municipality Bratislava - Ruzinov district

Country
Slovakia
Fine
The Authority did not impose a measure to remedy the identified deficiencies
Date
2019-05-02
Sector
The basic role of the municipality in the exercise of self-government is to care for the versatile development of its territory and the needs of its inhabitants
Articles
Article 5 section 1 letter f) GDPR

Bratislava Ruzinov City District delivered the decision to the applicant, while the applicant was not an authorized entity to deliver the decision.

Proceedings on presumed violation of the GDPR provisions, which happened because the data controller, the Municipality of Bratislava - Ružinov, delivered to an electronic mailbox of Owl & Crow Association Limited, l.l.c., a decision containing personal data in the scope of surname, first name, address, information about the fact that and with what content he made a request for information, although the applicant was not entitled to deliver the decision in question. The decision of the Controller, Bratislava - Municipality of Ružinov, in the proceedings on free access to information was delivered by the Operator to the electronic mailbox of Owl & Crow Association Limited, l.l.c., to which the applicant in the position of managing partner had access. As there were two managing directors in this company, and therefore two natural persons as statutory bodies, this procedure infringed Article 5(1)(f) of the GDPR, as the personal data were not processed in a manner that ensured adequate security and were subject to unauthorised processing. In the course of the proceedings, the Office also examined whether it was appropriate to impose a fine for the established breach of the GDPR. The Office concluded that it would not impose a fine, in particular in view of the seriousness and number of persons concerned.

Additional information

The decision of the controller, Bratislava - city district of Ružinov, in proceedings on free access to information was delivered by the operator to the electronic mailbox of Owl & Crow Association Limited, l.l.c., to which had access the applicant for disclosure of information in the position of managing partner. Since there were two directors and thus two natural persons as the statutory body in that company, those proceedings infringed Article 5 section 1 letter f of the GDPR, since the personal data were not processed in a manner guaranteeing adequate security and were exposed to unauthorized processing. In the proceedings, the Office also assessed whether it is appropriate to impose a fine for the violation of GDPR found. Office concluded that, having regard in particular to the gravity and the number of persons concerned, Office won't impose a fine.