Persónuvernd (Iceland) · 29 September 2020
Municipality
Name not published.
About: Data principles, Data security, Special categories, Unlawful processing
FineNo fineViolation found
- Regulator
- Persónuvernd (Iceland)
- Decided
- 29 September 2020
- Country
- Iceland
- Sector
- Not given
- Regulator’s reference
- 2020010628
- Fino case number
- 2020/IS/023
What happened
The Icelandic DPA (Persónuvernd) held that while a public institution had lawfully collected a data subject's health information and disseminated it to a municipality, the municipality did not act lawfully in publishing the information on its website.
Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal dataRead →
- Art. 6Lawfulness of processing6(1)(c)Read →
- Art. 9Processing of special categories of personal data9(1) · 9(2) · 9(2)(b)Read →
- Art. 32Security of processingRead →
- Data principles
- Data security
- Special categories
- Unlawful processing
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2020/IS/023.