Unknown
- Country
- Turkey
- Fine
- Unknown
- Date
- 2018-08-02
- Sector
- Business Sector
- Articles
- Art. 12 of the DPL
Insufficient technical and organisational measures to ensure information security
A Data Controller has submitted a document including the personal data of one of its customers, to another individual that bears the same name as the customer. Also, one the Data Controller's employees has performed query on the data for personal purposes, without the consent of the data subject. The Authority has pointed out a vulnerability in the system, and ruled on administrative fine. Authority: Turkish Data Protection Authority (KVKK)
