telecom

French Telecom Operator Pays the GDPR Fine

The French Data Protection Authority (the “CNIL”) was not in a festive mood when right after Christmas, on the 27th of December, announced and imposed the fine of €250,000 to French telecom operator Bouygues Telecom after they failed to protect their customers‘ personal data.

Personal data of customers was compromised when due to the security vulnerability and the human mistake. According to the Lexology,  the computer code, which requires user authentication on the company’s website, had been deactivated during a test phase but not re-activated once the tests were completed. Documents containing customers’ personal data were accessible for anyone. The company quickly blocked the data from improper access, but it took 4 days for  Bouygues Telecom notice, identify and report the infringement.

LEARNING TIP:  Human error causes 4 out of 5 data breaches (in UK). Lack of training,  unclear responsibilities or improdence, can give rise to error (confidential data emailed to the incorrect recipient, loss or theft of paperwork, data left in an insecure location and others). In order to avoid possible human errors, clear directions should be given to each employee about their responsibilities. Also, training should take a place after addapting new technical or organizational security measure. Emploees must be well informed how to recognise a threat and what to do in case of an accident.

Read more about the most common causes of data breaches.

Subscribe to our Newsletter

Your e-mail address is only used to send you our newsletter and information about the activities of GDPR Register. You can always use the unsubscribe link included in the mail.

Share on facebook
Share on google
Share on twitter
Share on linkedin
Share on pinterest
Share on print
Share on email

Latest Blog Posts

dpa gdpr

Data Protection Authorities (DPA)

Data Protection Authorities (DPA) Data Protection Authorities (DPA) are independent public authorities that supervise, through investigative and corrective powers, the application of the GDPR. They

Read More »

Zpracovává vaše společnost osobní údaje?


Zpracovávat vaše společnost osobní údaje fyzických osob, jako jsou:

  • Údaje zaměstnanců, zákazníků, uchazečů o zaměstnání nebo pacientů včetně:
    • Jméno nebo osobní identifikační číslo
    • Kontaktní údaje (e-mailová adresa, telefonní číslo, adresa)
    • Bankovní údaje, plat, údaje o pasu nebo jiné osobní údaje

 

Ar Jūsų įmonė renka ir tvarko fizinių asmenų asmens duomenis? 


Asmens duomenys gali būti:

  • Kliento, darbuotojo. paciento, kandidato į darbo vietą ir kt. 
    • Vardas ar asmens  numeris 
    • Kontaktinė informacija (el.pašto adresas, telefono numeris, adresas ir kt)
    • Banko sąskaitos  duomenys, atlyginimo dydis, paso duomenys ar bet kokia kita asmeninė informacija. 

Onko yrityksessäsi enemmän, kuin 250 työntekijää?


Kas teie ettevõte kogub ja töötleb isikuandmeid?


Kas teie ettevõte kogub ja töötleb füüsiliste isikutega seotud andmeid nagu näiteks:

Töötajate, klientide, tööle kandideerijate, patsientide:

  • Nimi, isikukood
  • E-posti aadress, telefoninumber, kodune aadress
  • Pangakontonumber, palgasumma, krediitkaardiandmed või mõnda muut tüüpi isiklikud andmed

Does your company collect any personal data?


Does your company collect and process any personal data of natural persons such as:

  • Employees, Customers, Job Applicants or Patients including:
    • Name or personal ID number
    • Contact details (Email address, Phone number, Address)
    • Bank details, Salary amounts, Passport details or any other personal data