Sanction RGPD Croatian Data Protection Authority (azop) — HEP-Toplinarstvo : 320 k€ (2025)
- Autorité de contrôle
- Croatian Data Protection Authority (azop)
- Pays
- Croatie
- Entreprise / secteur
- HEP-Toplinarstvo
- Montant de l'amende
- 320 k€
- Date de la décision
- 22 juillet 2025
- Fondement juridique
- Art. 31, Art. 32
- Manquement
- Mesures techniques et organisationnelles insuffisantes
Résumé des faits
The Croatian DPA has imposed a fine of EUR 320,000 on HEP-Toplinarstvo. The controller failed to implement sufficient technical and organisational measures to ensure data security. When a data subject requested a new password for the controller's online platform, the controller transmitted the old password rather than a new, temporary password. Additionally, the controller stored their customers' passwords in readable form without encryption. Furthermore, the controller failed to cooperate adequately with the supervisory authority.