Open University of Cyprus – €45,000 Fine (Cyprus, 2023)

€45,000DPA Commissioner27 November 2023Cyprus
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

The Open University of Cyprus faced a fine after a data breach leaked personal information. The university didn't have proper security measures in place to protect student and alumni data. This case is important because it emphasizes the need for strong data protection practices in educational institutions.

What happened

The Open University of Cyprus was fined €45,000 for failing to implement adequate security measures after a data breach.

Who was affected

Students, alumni, and partners of the Open University of Cyprus were affected by the data breach.

What the authority found

The data protection authority concluded that the university violated GDPR by not ensuring proper security for personal data.

Why this matters

This ruling serves as a warning to educational institutions about the importance of data security. It shows that failing to protect personal information can lead to significant financial penalties.

GDPR Articles Cited

Art. 32 GDPR
Art. 5(2) GDPR
Art. 83 GDPR
Full Legal Summary
Detailed

On 30 March 2023, the Open University of Cyprus, the controller, notified a personal data breach to the Cypriot DPA (Commissioner for Personal Data Protection, DPC) in accordance with Article 33 GDPR. In addition to this, 11 complaints were filed with the DPC by data subjects stating that their data had been leaked following the incident. Accordingly, the DPC started investigating the case and asserted that the leaked data related to students, alumni and other partners of the controller and it was cached on the controller's servers and generally processed by its employees. In its submissions, the controller sent to the DPC a list of actions it intends to implement by 2026 in order to improve the security of its processing operations. After further investigations, the DPC concluded that the controller had failed to implement appropriate technical and security measures, thereby violating Article 32 GDPR and the principle of accountability under Article 5(2) GDPR. In light of Article 83 GDPR and taking all the above into account and also the fact that the controller is part of the wider public sector, the DPC considered it appropriate to impose a fine in the amount of €45,000 on the controller.

Related Enforcement Actions (0)

No other enforcement actions found for Open University of Cyprus in CY

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

27 November 2023

Authority

DPA Commissioner

Fine Amount

€45,000

Enforcement Tracker ID

ETid-2144

GDPRhub ID

gdprhub-7590

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Open University of Cyprus - Cyprus (2023). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: