„ROBINSON-TOURS” Tourism and Service Ltd. – €51,250 Fine (Hungary, 2020)

€51,250Nemzeti Adatvédelmi és Információszabadság Hatóság9 December 2020Hungary
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

A Hungarian travel agency was fined over €51,000 for failing to protect customer data. Personal information was exposed online due to poor security measures. This case highlights the importance of strong data protection practices for businesses handling sensitive information.

What happened

Robinson-Tours exposed customer data online due to inadequate security measures, leading to a significant fine.

Who was affected

The data breach affected 781 customers of Robinson-Tours, whose personal information was exposed online.

What the authority found

The authority found that Robinson-Tours and its partner failed to implement necessary security measures, violating GDPR's data protection requirements.

Why this matters

This case underscores the need for businesses to adopt robust security measures to protect customer data. It serves as a warning that inadequate data protection can lead to severe penalties.

GDPR Articles Cited

Art. 25(1) GDPR
Art. 25(2) GDPR
Art. 32(1)(b) GDPR
Art. 34(1) GDPR

Entities Involved

„ROBINSON-TOURS” Tourism and Service Ltd.
Next Time Media Agency Ltd.
Full Legal Summary
Detailed

While browsing on the Internet, a complainant typed his father's name into Google search and through one of the results managed to open a database without any authorization check. The DPA initiated an investigation. It concluded that the database included personal data of clients of a travel agency Robinson-Tours, such as names, dates of booking, reservation status, address, ID card details, passport numbers with date of issue and expiry, date of conclusion of the travel contract. On the website, it was also possible to filter people by destination and date. In some of the cases, it was possible to upload a passport photo or freely download individual customers' travel contracts. As it turned out during the investigation, Robinson-Tours assigned Next Time Media Agency as a data processor with a task to implement appropriate security measures: firewall, anti-virus, multi-level authentication and access control, strong use and forced exchange of passwords, daily backup. Exposed data came from a test database which was filled with data of 781 real customers. They were available to anyone from November 13, 2019 to February 4, 2020. The controller did not communicate data breach to data subjects. It did not carry out regular checks for security risks. What constitutes appropriate technical and organizational measures to ensure data protection by design and by default (Article 25 GDPR)? The DPA held that Robinsons-Tour and Next Time Media Agency did not implement appropriate technical and organisational measures to ensure security of personal data of its customers. Hence, they failed to comply with provisions of Article 25 GDPR introducing a principle of data protection by default and by design. Robinsons-Tour and Next Time Media Agency were fined respectively 20 000 000 HUF and 500 000 HUF .

Related Enforcement Actions (0)

No other enforcement actions found for „ROBINSON-TOURS” Tourism and Service Ltd. in HU

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

9 December 2020

Authority

Nemzeti Adatvédelmi és Információszabadság Hatóság

Fine Amount

€51,250

20,500,000 HUF

GDPRhub ID

gdprhub-2998

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. „ROBINSON-TOURS” Tourism and Service Ltd. - Hungary (2020). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: