UAB Prime Leasing – €110,000 Fine (Lithuania, 2021)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
The Lithuanian privacy authority fined UAB Prime Leasing EUR 110,000 for a data breach that exposed over 110,000 CityBee users' personal information. The breach happened because the company didn't secure its database properly. This case shows how crucial it is for businesses to protect customer data with strong security measures.
What happened
UAB Prime Leasing suffered a data breach that exposed personal data of over 110,000 CityBee users due to inadequate security measures.
Who was affected
CityBee users whose personal information, including names and contact details, was leaked.
What the authority found
The Lithuanian DPA found that UAB Prime Leasing failed to implement adequate security measures, violating GDPR's requirements for data protection.
Why this matters
This fine highlights the necessity for companies to prioritize data security and implement robust measures to protect personal information. It serves as a warning to businesses about the financial and reputational risks of neglecting data protection.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
The Lithuanian DPA has fined UAB Prime Leasing, the operator of the short-term car rental platform CityBee, EUR 110,000. The DPA conducted the investigation on its own initiative after information about a possible personal data breach (Art. 33 GDPR) of the company's customers became public in February 2021. According to the company, they learned about the security breach from another cybersecurity service provider who informed them that the customer data of 110,302 CityBee users had been published on the website of the hacking forum RaidForums.com. This included data such as names, addresses, phone numbers, email addresses, personal identification numbers, driver's license numbers, type of payment card and the last four digits of the card number of the data subjects. The DPA's investigation revealed that the published data originated from an unsecured backup copy of a database. The DPA found that the data breach occurred due to the company's failure to comply with its obligation to implement technical and organizational measures to ensure a level of security appropriate to the risk to data subjects. The company had, for example, failed to appoint a person with appropriate competence to be responsible for security and risk management. It had also failed to ensure that accesses to database files were logged and evaluated. In addition, the company had stored the database unencrypted, so that a person with technical knowledge could have had full access to the data in the file after downloading it. The personal codes in the database were furthermore stored unprotected and the passwords in the database were only encrypted with an encryption algorithm that was considered insecure.
Related Enforcement Actions (0)
No other enforcement actions found for UAB Prime Leasing in LT
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
29 November 2021
Authority
Valstybine duomenu apsaugos inspekcija
Fine Amount
€110,000
Enforcement Tracker ID
ETid-927
About this data
Cite as: Cookie Fines. UAB Prime Leasing - Lithuania (2021). Retrieved from cookiefines.eu
Last updated: