Datatilsynet (Denmark) · 5 March 2020
Not named in the source
About: Data breach, Data security
- Regulator
- Datatilsynet (Denmark)
- Decided
- 5 March 2020
- Country
- Denmark
- Sector
- Not given
- Regulator’s reference
- 2019-441-3399
- Fino case number
- 2020/DK/009
What happened
The Danish Data Protection Authority (Datatilsynet) expressed serious criticism regarding the lack of appropriate measures to ensure the identity of the natural person making a request according to Articles 15-21 GDPR. Datatilsynet ordered the conduction of a new assessment of the breach for the required communication of a data breach according to Article 34 (1), (2) GDPR not only dealing with the incident but also with possible risks to the rights of the data subjects in case the information is provided to the wrong customer.
Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 32Security of processingRead →
- Art. 33Notification of a personal data breach to the supervisory authority33(2)Read →
- Art. 34Communication of a personal data breach to the data subject34(1)Read →
- Data breach
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2020/DK/009.