HEP-Toplinarstvo – €320,000 Fine (Croatia, 2025)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
HEP-Toplinarstvo was fined €320,000 for not keeping customer data secure. They mistakenly sent old passwords instead of new ones and stored passwords in a readable format. This case highlights the importance of strong security measures for businesses handling personal information.
What happened
HEP-Toplinarstvo failed to implement proper security measures, leading to the mishandling of customer passwords.
Who was affected
Customers of HEP-Toplinarstvo who requested password resets and had their old passwords sent to them.
What the authority found
The Croatian DPA found that HEP-Toplinarstvo did not take adequate steps to protect personal data, violating GDPR's requirements for data security.
Why this matters
This ruling emphasizes that companies must prioritize data security to protect customer information. Other businesses should review their security practices to avoid similar penalties.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
Insufficient technical and organisational measures to ensure information security
Related Enforcement Actions (0)
No other enforcement actions found for HEP-Toplinarstvo in HR
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
22 July 2025
Authority
Agencija za zaštitu osobnih podataka
Fine Amount
€320,000
Enforcement Tracker ID
3100
About this data
Cite as: Cookie Fines. HEP-Toplinarstvo - Croatia (2025). Retrieved from cookiefines.eu
Last updated: