GDPR Fines

A public record of GDPR enforcement across Europe — compiled by INPLP members

Natural person (enterpreneur)

Country
Czech Republic
Fine
25,000 CZK
Date
2019
Sector
Private Sector
Articles
Art. 5(1) f) GDPRArt. 5 (2) GDPRArt. 28 (3) GDPRArt. 32 GDPR

Insufficient technical and organisational measures to ensure information security

The operator of an online game was exposed to multiple DDoS attacks which triggered the malfunctioning of the servers. The attacker blackmailed the operator stating that the attacks will not stop unless he pays money. As component of the blackmail, the attacker offered the operator that he will create an upgraded and better firewall protection to the servers of the operator. The operator agreed and paid the attacker. The operator implemented the new code from the attacker which proved better than the old one but there was a "backdoor" in the code. The attacker used the backdoor to steal all the data from the server about the players and uploaded these details to his website. The Czech Data Protection Authority concluded that the operator did not take proper security measures.