Fino

Norwegian Supervisory Authority (Datatilsynet) · 20 September 2021

Høylandet Municipality

Insufficient technical and organisational measures to ensure information security

Fine€40,200Fine issued
Regulator
Norwegian Supervisory Authority (Datatilsynet)
Decided
20 September 2021
Country
Norway
Sector
Public Sector and Education
Regulator’s reference
Not recorded
Fino case number
2021/NO/008
Export as PDF

What happened

The Norwegian DPA fined a municipality €40,478 (NOK 400,000) for not managing a breach in which people with no affiliation to the municipality had their highly sensitive personal data exposed, thus breaching Article 32(1)(b) GDPR and Article 32(2), cf. Article 24.

Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

The source doesn’t list which GDPR articles were involved.

  • Data security

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2021/NO/008.