Back to the blog
Danni Sigurnost E1585319226393

Harm from a breach of personal data security

Personal Data
28.08.2019

Is it possible to claim damages for a breach of your data security? The NRA case from the summer of 2019 raised many questions about how and who processes and stores our data.

This article aims to clarify the main points regarding citizens' personal data.

1. What is personal data?

As defined in Regulation 2016/679 (GDPR) Personal data (or PD for short) is any information relating to an identified or identifiable individual. The latter includes any data such as name, personal identification number, location, genetic, mental, physical, etc. identity of that individual (PD subject).

Gdpr 3518254 1280 300x200
The General Data Protection Regulation (GDPR) applies from 25.05.2018.

2. What protection do LDs enjoy?

Individuals provide their personal data for processing to various private and public entities. In this case, the entities (institutions/legal entities, and in some cases other individuals) are Data Controllers or Data Processors. The collection and processing they carry out must be in accordance with one of the grounds in the Regulation. In general, these are:

– explicit consent of the subject;

– conclusion of a contract;

– compliance with a legal obligation;

– protection of vital interests of the subject;

– performance of a task of public interest or exercise of official authority;

– legitimate interest of the administrator, respectively of a third party.

In addition to the need for a basis for collecting and processing personal data, controllers are also required to comply with the requirements regarding the manner and conditions of storage of personal data, their accessibility and their deletion. The controller must implement appropriate technical and organizational measures to ensure lawful processing. In particular, such measures ensure that, by default, without the intervention of the individual, personal data are not accessible to an unlimited number of individuals.

This is a legal obligation of data controllers. Failure to comply or inadequate compliance is considered a violation of the Regulation.

3. What are the consequences if administrators process personal data in violation of the requirements?

A good example of this is the recent „leak“ of personal data from the National Revenue Agency (NRA) system. Insufficient technical and organizational measures for data protection led to external intrusion into the system and unauthorized access to these data by third parties. The mere fact that the administrator can no longer exercise control violates the interest of the data subject and the former is liable.

4. Can I claim compensation for the unlawful processing/access to my personal data?

According to Art. 82 of the Regulation, individuals have the right to compensation from the controller, respectively from the processor of the personal data for damages resulting from a violation of the requirements of the Regulation. Damages can be both material and non-material, and they are subject to proof. Non-material damages represent the physical and emotional suffering, as well as all other negative experiences that you have gone through as a result of the damage. The compensation for them is determined by the court in equity.

Judicial Protection of Personal Data 1024x576
Legal protection in case of violation of the security of personal data is possible!
logo
The website Delikti.bg is a specialized platform that provides consultations and assistance in securing fair compensation for various types of damages. The focus is on supporting victims of work accidents, traffic accidents, medical errors and other cases of unlawful actions. The website offers detailed information about the rights of victims and guidelines for taking steps towards receiving compensation. The team of professionals provides personalized consultations and legal assistance for the most effective resolution of cases.
This article does not constitute legal advice and aims to address some aspects of the liability for compensation for property and/or non-property damages. For more information on the above issues or if you need a consultation, please contact the delikti.bg team or submit your inquiry on the website of the Georgiev & Petrov Law Firm.

Have you been involved in an accident and entitled to compensation?

You can reach us by phone at: +359 883 333 797 or by booking an appointment.
If our team is able to take on your matter, you will be notified in writing by email and your consultation request will be confirmed. Free legal aid is provided only in cases where the injured parties meet the requirements under the Bar Act..
1 / 3
Floating element