Norwegian Supervisory Authority (Datatilsynet) · 18 October 2021
Østre Toten municipality
Insufficient technical and organisational measures to ensure information security
Fine€412,000Fine issued
- Regulator
- Norwegian Supervisory Authority (Datatilsynet)
- Decided
- 18 October 2021
- Country
- Norway
- Sector
- Public Sector and Education
- Regulator’s reference
- Not recorded
- Fino case number
- 2021/NO/005
What happened
The Norwegian DPA fined a municipality €409,768 (NOK 4,000,000) for breaches of Article 5(1)(f) GDPR, Article 24 GDPR and Article 32 GDPR after a serious ransomware attack led to highly sensitive personal data being irreparably lost and sold on the dark web.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1)(f)Read →
- Art. 32Security of processingRead →
- Data principles
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2021/NO/005.