Persónuvernd (Iceland) · 27 September 2021
Directorate of Labor of Iceland
About: Data breach, Data principles, Unlawful processing
FineNo fineViolation found
- Regulator
- Persónuvernd (Iceland)
- Decided
- 27 September 2021
- Country
- Iceland
- Sector
- Not given
- Regulator’s reference
- 2021061419
- Fino case number
- 2021/IS/024
What happened
The Icelandic DPA ruled that disclosing by mistake the email addresses of recipients of a bulk email was contrary to the GDPR. Given however that the controller took corrective measures to prevent such incident from happening again, no fine was imposed.
Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal dataRead →
- Art. 6Lawfulness of processingRead →
- Art. 33Notification of a personal data breach to the supervisory authorityRead →
- Data breach
- Data principles
- Unlawful processing
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2021/IS/024.