Qatar Financial Centre issues fine for data breach violations
The Peninsula
Doha, Qatar: The Data Protection Office (DPO) of Qatar Financial Centre (QFC), a leading onshore financial and business centre in the region, has impo...
Doha, Qatar: The Data Protection Office (DPO) of Qatar Financial Centre (QFC), a leading onshore financial and business centre in the region, has imposed a reprimand and financial penalty of USD 150,000 on a QFC-licensed firm, following a significant data breach.
These measures, the first of its kind in Qatar, underscores the QFC's commitment to upholding robust data protection standards and holding firms accountable for breaches that compromise the security of the personal information of data subjects.
The firm experienced a data breach that allowed unauthorized access to personal data. The investigation revealed several infringements of the QFC Data Protection Regulations 2021, including late notification, security failures, and inadequate oversight.
The firm failed to report the breach within the required 72-hour window, delaying notification by ten days; it failed to adequately protect the integrity, confidentiality, and availability of personal data and did not effectively ensure the proper implementation of its own security policies.
The DPO opted not to issue a public censure, acknowledging the firms full cooperation throughout the investigation and its substantial efforts to strengthen its data security measures.