The Spanish authority sanctions the Consellería de Medio Ambiente of the Xunta de Galicia for a GDPR violation related to a personal data breach
Facts and context
The case originated from a personal data breach notification made by the Council on 20 September 2023, following an alert issued by the National Cryptologic Center (CCN) on 13 and 14 September 2023 concerning massive and suspicious accesses.
Grounds for the decision
- Obligation of integrity and confidentiality (Article 5(1)(f) of the GDPR): The authority found that a data breach occurring between 8 and 22 September 2023 allowed the exfiltration of more than 40,000 records following the impersonation of the credentials of seven legitimate users. The compromised data included identification information, contact details, data related to licenses and insurance policies, as well as scanned documents such as identity cards. The authority concluded that the Council had not implemented appropriate technical and organizational measures to ensure a level of security appropriate to the risk. It noted the absence of a password expiration or change policy, the lack of a two-factor authentication system, poor management of inactive profiles, and insufficient incident detection measures, which allowed prolonged unauthorized access and constituted a breach of the confidentiality principle.
Authority's decision
Consequently, the authority declared that the Council of Environment, Territory and Housing of the Xunta de Galicia committed an infringement of Article 5(1)(f) of the GDPR. In accordance with Spanish legislation (Article 77(2) of Organic Law 3/2018), which provides for the possibility of not imposing a financial penalty on public administrations, no fine was imposed.
Furthermore, the authority ordered that its decision be communicated to the Ombudsman.
Lessons learned
This decision confirms / specifies / recalls that:- The absence of a multi-factor authentication system to access information systems processing a large volume of personal data is considered an insufficient security measure.
- Organizations must have proactive monitoring and detection mechanisms to identify abnormal activities, such as massive accesses from public IP addresses, in order to respond quickly to a security incident.
- The implementation of basic IT security policies, such as password lifecycle management and deactivation of inactive accounts, is a fundamental requirement to ensure data confidentiality.
- Corrective measures implemented after the discovery of a breach, although positively taken into account by the authority, do not exempt the data controller from liability for the infringement already committed.
- Public entities, even if they may be exempt from financial penalties in some Member States, are required to comply with the same security obligations as private entities and may be subject to a formal declaration of infringement.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire