Technical IT deficiencies prior to ransomware attack result in GDPR fines
Ransomware
The Irish data protection supervisory authority was not previously known for its overly strict application of the GDPR requirements. In many cases, it has been surprisingly lenient, especially towards large tech companies based in Ireland. This makes the authority's latest decision, which involves a fine of half a million euros and could have an impact on IT security and the technical data protection requirements of companies, all the more surprising. The authority states that even supposedly minor failures in IT security can result in large fines, even without any additional circumstances.