Open University of Cyprus – €45,000 Fine (Cyprus, 2023)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
The Open University of Cyprus faced a fine after a data breach leaked personal information. The university didn't have proper security measures in place to protect student and alumni data. This case is important because it emphasizes the need for strong data protection practices in educational institutions.
What happened
The Open University of Cyprus was fined €45,000 for failing to implement adequate security measures after a data breach.
Who was affected
Students, alumni, and partners of the Open University of Cyprus were affected by the data breach.
What the authority found
The data protection authority concluded that the university violated GDPR by not ensuring proper security for personal data.
Why this matters
This ruling serves as a warning to educational institutions about the importance of data security. It shows that failing to protect personal information can lead to significant financial penalties.
GDPR Articles Cited
On 30 March 2023, the Open University of Cyprus, the controller, notified a personal data breach to the Cypriot DPA (Commissioner for Personal Data Protection, DPC) in accordance with Article 33 GDPR. In addition to this, 11 complaints were filed with the DPC by data subjects stating that their data had been leaked following the incident. Accordingly, the DPC started investigating the case and asserted that the leaked data related to students, alumni and other partners of the controller and it was cached on the controller's servers and generally processed by its employees. In its submissions, the controller sent to the DPC a list of actions it intends to implement by 2026 in order to improve the security of its processing operations. After further investigations, the DPC concluded that the controller had failed to implement appropriate technical and security measures, thereby violating Article 32 GDPR and the principle of accountability under Article 5(2) GDPR. In light of Article 83 GDPR and taking all the above into account and also the fact that the controller is part of the wider public sector, the DPC considered it appropriate to impose a fine in the amount of €45,000 on the controller.
Related Enforcement Actions (0)
No other enforcement actions found for Open University of Cyprus in CY
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
27 November 2023
Authority
DPA Commissioner
Fine Amount
€45,000
Enforcement Tracker ID
ETid-2144
GDPRhub ID
gdprhub-7590About this data
Cite as: Cookie Fines. Open University of Cyprus - Cyprus (2023). Retrieved from cookiefines.eu
Last updated: