The Spanish authority sanctions ALKORA EBS CORREDURIA DE SEGUROS Y REASEGUROS SAU for GDPR breaches following a security breach affecting 40,000 people

The Spanish Data Protection Agency (AEPD) has sanctioned an insurance broker for insufficient security measures leading to a ransomware cyberattack, and for the absence of a data protection impact assessment despite processing health data and data of minors.

Facts and context

The Spanish Data Protection Agency (AEPD) today published a sanction decision against the insurance brokerage company ALKORA EBS CORREDURIA DE SEGUROS Y REASEGUROS SAU, including the imposition of a €200,000 fine for breaches related to data security and the absence of a DPIA.

The procedure was initiated following the notification of a data breach by the company on April 22, 2023, supplemented by a complaint from a data subject filed on December 27, 2023.

Grounds for the decision

  • Integrity and confidentiality obligation (Article 5(1)(f) of the GDPR): The authority found that the security measures implemented by the company before the incident were insufficient given the risks. An internal audit in February 2022 had already identified an "Extreme" risk of suffering a cyberattack. Furthermore, a post-incident penetration test revealed eight "high" level vulnerabilities and ten "medium" level vulnerabilities. The investigation showed that attackers were able to move freely within the infrastructure, exfiltrate 3.5 to 4 TB of data, and encrypt the servers, as personal data was not encrypted at rest. The authority concluded that the company, although aware of the high risks, had not adopted appropriate technical and organizational measures to ensure an adequate level of security.
  • Obligation to carry out a data protection impact assessment (Article 35 of the GDPR): The authority considered that the company should have conducted an impact assessment before the incident. Its activities involved processing special categories of data (health data of clients and employees) and data concerning vulnerable persons (minors in the context of claims files). The authority emphasized that processing these types of data is likely to result in a high risk to the rights and freedoms of individuals, triggering the obligation to carry out an impact assessment. The company had initially concluded in 2019 that such an assessment was not necessary, an evaluation the authority deemed incorrect given the nature of the processing.

Authority's decision

Consequently, the authority imposed a total fine of €250,000 on ALKORA EBS CORREDURIA DE SEGUROS Y REASEGUROS SAU, reduced to €200,000 following a voluntary payment.

Furthermore, the authority ordered the company to carry out and submit to it, within three months, the data protection impact assessments for the relevant processing activities.

Lessons learned

This decision confirms that:

  • Awareness of an "extreme" risk following an internal audit, not followed by sufficient corrective measures, constitutes a breach of the security obligation, as the mere existence of formal measures is insufficient.
  • The combined processing of special categories of data (health data) and data relating to vulnerable persons (minors) makes the carrying out of an impact assessment mandatory, even if the controller initially considers the risk not to be high.
  • The responsibility of the controller relies on a proactive and continuous risk management approach, not merely a reaction to a security incident.
  • The absence of encryption of personal data at rest, notably special categories, is a determining factor in assessing the insufficiency of security measures in the event of a cyberattack.
  • It is incumbent upon the controller to demonstrate the adequacy and effectiveness of its security measures, a purely formal or documentary demonstration being insufficient to prove compliance.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire