Regulatory Watch  /  DE-HE  /  Investigation
Low impactInvestigationFiled

noyb files GDPR complaint against Amazon for lacking TLS email encryption

The privacy NGO noyb submitted a complaint to the Hessian Data Protection Authority alleging Amazon violates GDPR Article 32 by not using TLS encryption for emails. The complaint may also be handled by Luxembourg's DPA, which could impose fines up to €4.2 billion.

Why it matters: The case could lead to a major GDPR enforcement action against Amazon for inadequate email security.

Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.

Sources
Complaint: Amazon doesn’t allow baseline TLS security
noyb · primary source · Mar 2, 2020
Complaint: Amazon doesn’t allow baseline TLS security
noyb · Mar 2, 2020
Details
JurisdictionDE-HE
RegulatorHessian Data Protection Authority
LawGeneral Data Protection Regulation
StatusFiled
PublishedMarch 2, 2020
Effectivenot stated
PenaltyDPAs can fine Amazon up to 2% of its global turnover, which would be up to € 4,2 billion.
OrganisationsAmazon
Topicssecurity, privacy
Datapersonal