
The Irish Data Protection Commissioner has imposed a fine of EUR 125,000 because a controller (the City of Dublin) disclosed personal data of approximately 13,000 people without authorisation after a server was attacked with malware. In addition to the master data of the data subjects, account data and special categories of data were also affected, in particular information on ethnic origin and health data.
It was particularly significant that the city did not report the data breach to the supervisory authority without delay and that the data subjects were not informed.
Recommended actions
- When making changes to ICT systems, carry out appropriate risk assessments to determine whether personal data could be affected and to ensure that appropriate organisational and technical measures are taken.
- Report data breaches to the data protection supervisory authority without delay and carefully, and inform the data subjects if necessary. Do not wait for the results of investigations by third parties (e.g. processors).
- The Controller must comply with the reporting obligation in a timely manner.
- If a supervisory authority expressly instructs that a breach must be reported to the data subjects (Art. 34(4) GDPR), as in the present case, you should take action without delay as the Controller.
Do you require assistance in implementing data protection rights or have specific questions? Then please feel free to contact us: consulting@AdOrgaSolutions.de


