MOVE Ireland – €1,500 Fine (Ireland, 2021)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
MOVE Ireland was fined €1,500 for losing SD cards that contained sensitive recordings of group sessions discussing domestic violence. This breach could affect the privacy of 80 to 120 men who participated in these sessions. This situation stresses the importance of safeguarding personal data, especially in sensitive environments.
What happened
MOVE Ireland lost eighteen SD cards that may have contained personal recordings of group sessions with participants discussing their behaviors related to domestic violence.
Who was affected
The men who participated in the group sessions and may have had their personal information exposed due to the lost SD cards.
What the authority found
The Irish Data Protection Commission found that MOVE Ireland failed to implement adequate security measures to protect personal data, violating GDPR.
Why this matters
This ruling serves as a warning to organizations handling sensitive information to strengthen their data security practices. Nonprofits and charities should take extra care to protect the privacy of their participants.
GDPR Articles Cited
The Irish DPA (DPC) has fined the organization MOVE (Men Overcoming Violence) EUR 1,500. MOVE is a charity working in the field of domestic violence. The organization aims to support the safety and well-being of women and their children who have experienced violence in relationships. For this purpose, participants (men) come to weekly sessions in order to change their behavior. On February 3, 2021, the organization reported a data breach in accordance with Art. 33 GDPR. The organization stated that eighteen SD cards had been lost, which may have contained recordings of group sessions of the MOVE program, in which participants discuss their behavior and attitudes regarding domestic violence with a group leader. Some of the participants could be seen and heard on the recordings. In addition, the recordings included footage of participants discussing their behaviors and feelings regarding current or former partners, other family members, and friends who may have been named. Approximately 80-120 participants could have been affected by the data breach, as well as at least one group leader per recorded session. The DPC found that MOVE had breached its obligation under Art. 32 (1) GDPR by failing to implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk presented by the processing of personal data through the recording of group sessions.
Related Enforcement Actions (0)
No other enforcement actions found for MOVE Ireland in IE
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
20 August 2021
Authority
Data Protection Commission
Fine Amount
€1,500
Enforcement Tracker ID
ETid-893
About this data
Cite as: Cookie Fines. MOVE Ireland - Ireland (2021). Retrieved from cookiefines.eu
Last updated: