The Cypriot DPA has imposed a fine of EUR 3,500 on Universal life-time indemnity public Co Ltd. The processor of the data controller had suffered a data breach in which personal data of customers were mistakenly disclosed to other customers. During its investigation, the DPA found that the controller had failed to contractually govern the relationship with its processor. The DPA concluded that the controller had contracted a processor without ensuring that the processor provided sufficient guarantees for the implementation of seize technical and organizational measures to protect personal data.