Norwegian Supervisory Authority (Datatilsynet) · 20 September 2021
Høylandet Municipality
Insufficient technical and organisational measures to ensure information security
- Regulator
- Norwegian Supervisory Authority (Datatilsynet)
- Decided
- 20 September 2021
- Country
- Norway
- Sector
- Public Sector and Education
- Regulator’s reference
- Not recorded
- Fino case number
- 2021/NO/008
What happened
The Norwegian DPA fined a municipality €40,478 (NOK 400,000) for not managing a breach in which people with no affiliation to the municipality had their highly sensitive personal data exposed, thus breaching Article 32(1)(b) GDPR and Article 32(2), cf. Article 24.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
The source doesn’t list which GDPR articles were involved.
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2021/NO/008.