„ROBINSON-TOURS” Tourism and Service Ltd. – €51,250 Fine (Hungary, 2020)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
A Hungarian travel agency was fined over €51,000 for failing to protect customer data. Personal information was exposed online due to poor security measures. This case highlights the importance of strong data protection practices for businesses handling sensitive information.
What happened
Robinson-Tours exposed customer data online due to inadequate security measures, leading to a significant fine.
Who was affected
The data breach affected 781 customers of Robinson-Tours, whose personal information was exposed online.
What the authority found
The authority found that Robinson-Tours and its partner failed to implement necessary security measures, violating GDPR's data protection requirements.
Why this matters
This case underscores the need for businesses to adopt robust security measures to protect customer data. It serves as a warning that inadequate data protection can lead to severe penalties.
GDPR Articles Cited
Entities Involved
While browsing on the Internet, a complainant typed his father's name into Google search and through one of the results managed to open a database without any authorization check. The DPA initiated an investigation. It concluded that the database included personal data of clients of a travel agency Robinson-Tours, such as names, dates of booking, reservation status, address, ID card details, passport numbers with date of issue and expiry, date of conclusion of the travel contract. On the website, it was also possible to filter people by destination and date. In some of the cases, it was possible to upload a passport photo or freely download individual customers' travel contracts. As it turned out during the investigation, Robinson-Tours assigned Next Time Media Agency as a data processor with a task to implement appropriate security measures: firewall, anti-virus, multi-level authentication and access control, strong use and forced exchange of passwords, daily backup. Exposed data came from a test database which was filled with data of 781 real customers. They were available to anyone from November 13, 2019 to February 4, 2020. The controller did not communicate data breach to data subjects. It did not carry out regular checks for security risks. What constitutes appropriate technical and organizational measures to ensure data protection by design and by default (Article 25 GDPR)? The DPA held that Robinsons-Tour and Next Time Media Agency did not implement appropriate technical and organisational measures to ensure security of personal data of its customers. Hence, they failed to comply with provisions of Article 25 GDPR introducing a principle of data protection by default and by design. Robinsons-Tour and Next Time Media Agency were fined respectively 20 000 000 HUF and 500 000 HUF .
Related Enforcement Actions (0)
No other enforcement actions found for „ROBINSON-TOURS” Tourism and Service Ltd. in HU
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
9 December 2020
Authority
Nemzeti Adatvédelmi és Információszabadság Hatóság
Fine Amount
€51,250
20,500,000 HUF
GDPRhub ID
gdprhub-2998About this data
Cite as: Cookie Fines. „ROBINSON-TOURS” Tourism and Service Ltd. - Hungary (2020). Retrieved from cookiefines.eu
Last updated: