Norwegian Supervisory Authority (Datatilsynet) · 4 June 2021
Moss municipality
Insufficient technical and organisational measures to ensure information security
- Regulator
- Norwegian Supervisory Authority (Datatilsynet)
- Decided
- 4 June 2021
- Country
- Norway
- Sector
- Health Care
- Regulator’s reference
- Not recorded
- Fino case number
- 2021/NO/011
What happened
The Norwegian DPA fined a municipality approximately €47,700 (NOK 500,000) for breaching Article 32(1)(b) and (d) GDPR by merging two IT systems for health records. This led to, among other things, incorrect information about vaccines and substance abuse during pregnancy.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
The source doesn’t list which GDPR articles were involved.
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2021/NO/011.