Robinson Tours Ltd. (Robinson Tours Idegenforgalmi és Szolgáltató Kft.) – €55,400 Fine (Hungary, 2020)

€55,400Nemzeti Adatvédelmi és Információszabadság Hatóság16 December 2020Hungary
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Robinson Tours Ltd. was fined for leaving customer data unprotected in their reservation system, which was accessible online. This breach exposed sensitive personal information, and the company failed to inform affected customers. The case underscores the need for strong data security measures and timely breach notifications.

What happened

Robinson Tours Ltd. left customer data unprotected in their reservation system, making it accessible online.

Who was affected

Customers of Robinson Tours Ltd. whose personal data, including IDs and passport numbers, were exposed online.

What the authority found

The Hungarian DPA ruled that Robinson Tours failed to protect customer data and did not notify affected individuals about the breach.

Why this matters

This case highlights the importance of securing customer data and promptly informing individuals of breaches. Companies should regularly assess their security practices to prevent unauthorized access.

GDPR Articles Cited

Art. 25(1) GDPR
Art. 32(1)(b) GDPR
Art. 34(1) GDPR
Full Legal Summary
Detailed

The Hungarian DPA (NAIH) imposed a fine of HUF 20,500,000 (EUR 55,400) on Robinson Tours Idegenforgalmi és Szolgáltató Kft. (Robinson Tours Ltd.) The travel agent's reservation system contained unprotected data of customers, which could be viewed by anyone and found via Google. The data contained, among others, names, contact and address data, copies of personal IDs and passport numbers. During the DPA's investigation, it turned out that the data in question was from a test database created by Next Time Media Agency Ltd, the web agency contracted to develop and operate the database, which was supplemented not only with test data but also with real data of Robinson Tours' customers. In total, the data of 781 individuals was affected, which was accessible by anyone in the period from November 13, 2019 to February 4, 2020. The NAIH also notes that Robinson Tours did not conduct regular security risk screenings. Robinson Tours also failed to notify the data subjects about the data breach.

Related Enforcement Actions (0)

No other enforcement actions found for Robinson Tours Ltd. (Robinson Tours Idegenforgalmi és Szolgáltató Kft.) in HU

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

16 December 2020

Authority

Nemzeti Adatvédelmi és Információszabadság Hatóság

Fine Amount

€55,400

Enforcement Tracker ID

ETid-494

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Robinson Tours Ltd. (Robinson Tours Idegenforgalmi és Szolgáltató Kft.) - Hungary (2020). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: