MOVE Ireland – €1,500 Fine (Ireland, 2021)

€1,500Data Protection Commission20 August 2021Ireland
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

MOVE Ireland was fined €1,500 for losing SD cards that contained sensitive recordings of group sessions discussing domestic violence. This breach could affect the privacy of 80 to 120 men who participated in these sessions. This situation stresses the importance of safeguarding personal data, especially in sensitive environments.

What happened

MOVE Ireland lost eighteen SD cards that may have contained personal recordings of group sessions with participants discussing their behaviors related to domestic violence.

Who was affected

The men who participated in the group sessions and may have had their personal information exposed due to the lost SD cards.

What the authority found

The Irish Data Protection Commission found that MOVE Ireland failed to implement adequate security measures to protect personal data, violating GDPR.

Why this matters

This ruling serves as a warning to organizations handling sensitive information to strengthen their data security practices. Nonprofits and charities should take extra care to protect the privacy of their participants.

GDPR Articles Cited

Art. 5(1)(f) GDPR
Art. 32(1) GDPR
Full Legal Summary
Detailed

The Irish DPA (DPC) has fined the organization MOVE (Men Overcoming Violence) EUR 1,500. MOVE is a charity working in the field of domestic violence. The organization aims to support the safety and well-being of women and their children who have experienced violence in relationships. For this purpose, participants (men) come to weekly sessions in order to change their behavior. On February 3, 2021, the organization reported a data breach in accordance with Art. 33 GDPR. The organization stated that eighteen SD cards had been lost, which may have contained recordings of group sessions of the MOVE program, in which participants discuss their behavior and attitudes regarding domestic violence with a group leader. Some of the participants could be seen and heard on the recordings. In addition, the recordings included footage of participants discussing their behaviors and feelings regarding current or former partners, other family members, and friends who may have been named. Approximately 80-120 participants could have been affected by the data breach, as well as at least one group leader per recorded session. The DPC found that MOVE had breached its obligation under Art. 32 (1) GDPR by failing to implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk presented by the processing of personal data through the recording of group sessions.

Related Enforcement Actions (0)

No other enforcement actions found for MOVE Ireland in IE

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

20 August 2021

Authority

Data Protection Commission

Fine Amount

€1,500

Enforcement Tracker ID

ETid-893

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. MOVE Ireland - Ireland (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: