Robinson Tours Ltd. (Robinson Tours Idegenforgalmi és Szolgáltató Kft.) – €55,400 Fine (Hungary, 2020)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Robinson Tours Ltd. was fined for leaving customer data unprotected in their reservation system, which was accessible online. This breach exposed sensitive personal information, and the company failed to inform affected customers. The case underscores the need for strong data security measures and timely breach notifications.
What happened
Robinson Tours Ltd. left customer data unprotected in their reservation system, making it accessible online.
Who was affected
Customers of Robinson Tours Ltd. whose personal data, including IDs and passport numbers, were exposed online.
What the authority found
The Hungarian DPA ruled that Robinson Tours failed to protect customer data and did not notify affected individuals about the breach.
Why this matters
This case highlights the importance of securing customer data and promptly informing individuals of breaches. Companies should regularly assess their security practices to prevent unauthorized access.
GDPR Articles Cited
The Hungarian DPA (NAIH) imposed a fine of HUF 20,500,000 (EUR 55,400) on Robinson Tours Idegenforgalmi és Szolgáltató Kft. (Robinson Tours Ltd.) The travel agent's reservation system contained unprotected data of customers, which could be viewed by anyone and found via Google. The data contained, among others, names, contact and address data, copies of personal IDs and passport numbers. During the DPA's investigation, it turned out that the data in question was from a test database created by Next Time Media Agency Ltd, the web agency contracted to develop and operate the database, which was supplemented not only with test data but also with real data of Robinson Tours' customers. In total, the data of 781 individuals was affected, which was accessible by anyone in the period from November 13, 2019 to February 4, 2020. The NAIH also notes that Robinson Tours did not conduct regular security risk screenings. Robinson Tours also failed to notify the data subjects about the data breach.
Related Enforcement Actions (0)
No other enforcement actions found for Robinson Tours Ltd. (Robinson Tours Idegenforgalmi és Szolgáltató Kft.) in HU
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
16 December 2020
Authority
Nemzeti Adatvédelmi és Információszabadság Hatóság
Fine Amount
€55,400
Enforcement Tracker ID
ETid-494
About this data
Cite as: Cookie Fines. Robinson Tours Ltd. (Robinson Tours Idegenforgalmi és Szolgáltató Kft.) - Hungary (2020). Retrieved from cookiefines.eu
Last updated: