Fino

Norwegian Supervisory Authority (Datatilsynet) · 18 October 2021

Østre Toten municipality

Insufficient technical and organisational measures to ensure information security

Fine€412,000Fine issued
Regulator
Norwegian Supervisory Authority (Datatilsynet)
Decided
18 October 2021
Country
Norway
Sector
Public Sector and Education
Regulator’s reference
Not recorded
Fino case number
2021/NO/005
Export as PDF

What happened

The Norwegian DPA fined a municipality €409,768 (NOK 4,000,000) for breaches of Article 5(1)(f) GDPR, Article 24 GDPR and Article 32 GDPR after a serious ransomware attack led to highly sensitive personal data being irreparably lost and sold on the dark web.

Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Data principles
  • Data security

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2021/NO/005.