Datainspektionen (Sweden) · 10 December 2020
Umeå University
About: Data breach, Data principles, Data security
- Regulator
- Datainspektionen (Sweden)
- Decided
- 10 December 2020
- Country
- Sweden
- Sector
- Not given
- Regulator’s reference
- DI-2019-9432
- Fino case number
- 2020/SE/024
What happened
The Swedish DPA (Integritetsskyddsmyndigheten) fined a university ~€54,483 for disclosing and storing special category personal data from criminal investigations in breach of Article 5(1)(f) and Article 32. The Authority also highlighted that the controller failed to report the matter to the DPA as provided for by Article 33. For instance, one investigation report was sent in an unencrypted email, while another 108 reports were stored with a US cloud provider without proper safeguards.
Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1)(f)Read →
- Art. 32Security of processing32(1) · 32(2)Read →
- Art. 33Notification of a personal data breach to the supervisory authority33(1) · 33(5)Read →
- Data breach
- Data principles
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2020/SE/024.