Advertisement
CNIL Fines a Data Controller and Its Processor 225,000 Euros for Security Violation in Connection with Credential Stuffing Friday, January 29, 2021
On January 27, 2021, the French Data Protection Authority (the “CNIL”) announced (in French) that it imposed a fine of €150,000 on a data controller, and a fine of €75,000 on its data processor, for failure to implement adequate security measures to protect customers’ personal data against credential stuffing attacks on the website of the data controller. The CNIL decided not to make its decisions public, thereby not disclosing the name of the companies sanctioned.
Background
Between June 2018 and January 2020, the CNIL received several dozen personal data breach notifications concerning a website from which several million customers regularly make purchases online. The CNIL decided to investigate not only the company responsible for the data processing activities through the website (
Österreich bei DSGVO-Verstößen auf Platz 14 – Italien bei Bußgeldern top
computerwelt.at - get the latest breaking news, showbiz & celebrity photos, sport news & rumours, viral videos and top stories from computerwelt.at Daily Mail and Mail on Sunday newspapers.
Über 2 500 Strafen wegen Datenschutz-Verstößen in Österreich
trend.at - get the latest breaking news, showbiz & celebrity photos, sport news & rumours, viral videos and top stories from trend.at Daily Mail and Mail on Sunday newspapers.