Open University of Cyprus
bd_0992529b1abba416 · schema v1 · pii pii-v1
Full breach record for Open University of Cyprus →Regulator's decision — not a breach notification
This record is a regulator's decision, not the organisation's own breach notice. Breach-notification fields (discovery date, notification clock) are structurally absent — what this source establishes is the outcome and the provisions the decision cites.
The Commissioner (Cyprus) issued a complaint regarding Open University of Cyprus. A fine of EUR 45,000 was imposed. Outcome: Upheld. GDPR articles: Article 5(2) GDPR, Article 32 GDPR, Article 83 GDPR.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Nov 27, 2023
Filed
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a breach filing is linked. This record is the regulator's action, not a breach notice. Dashed segments fill in automatically when corroboration arrives.
Linked disclosures
Why this link?Ransomware claims (2)
- Leak Sitemedusabd_3f9fdbdb24ee2bde2023-04-21 · +220dVerified by operator
- Leak Sitemedusabd_ab9341226ba76aef2023-04-06 · +235dCandidate
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- data categories
- cross-border scope
- outcome + articles (decisions)
- discovery date
- affected count
- notification clock
See the underlying breach notice, if filed.