Fino

Datatilsynet (Denmark) · 22 September 2020

Kombit A/S

About: Data security, Processor obligations

FineNo fineViolation found
Regulator
Datatilsynet (Denmark)
Decided
22 September 2020
Country
Denmark
Sector
Not given
Regulator’s reference
2019-431-0037
Fino case number
2020/DK/012
Export as PDF

What happened

The Danish DPA expressed serious criticism against the processor 'Kombit A/S', for violating Article 28(1) GDPR by allowing 84 Danish municipalities to wrongfully gain access to the social security numbers and employment information of 4.2 million Danish citizens due to a technical error.

Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Data security
  • Processor obligations

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2020/DK/012.