Fino

Datainspektionen (Sweden) · 10 December 2020

Umeå University

About: Data breach, Data principles, Data security

FineSEK550,000≈ €53,700Violation found
Regulator
Datainspektionen (Sweden)
Decided
10 December 2020
Country
Sweden
Sector
Not given
Regulator’s reference
DI-2019-9432
Fino case number
2020/SE/024
Export as PDF

What happened

The Swedish DPA (Integritetsskyddsmyndigheten) fined a university ~€54,483 for disclosing and storing special category personal data from criminal investigations in breach of Article 5(1)(f) and Article 32. The Authority also highlighted that the controller failed to report the matter to the DPA as provided for by Article 33. For instance, one investigation report was sent in an unencrypted email, while another 108 reports were stored with a US cloud provider without proper safeguards.

Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Data breach
  • Data principles
  • Data security

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2020/SE/024.