GDPR Fines

A public record of GDPR enforcement across Europe — compiled by INPLP members

Ready-wear Company

Country
Turkey
Fine
Unknown, also Instructed the Data Controller
Date
Sector
Business Sector
Articles
26.07.2018

Insufficient technical and organisational measures to ensure information security

A data subject requested the Data Controller to delete and destroy its data, since the data has become available to third party accessing. The response it received from the company has been found insufficient. The Authority ruled administrative fine on the company that failed to provide sufficient measures to ensure the data, and granted it a term of 30 days to notify the customer pertaining to the transactions made regarding the matter. Authority: Turkish Data Protection Authority (KVKK)