Fino

Norwegian Supervisory Authority (Datatilsynet) · 28 May 2021

BRAbank ASA

Insufficient technical and organisational measures to ensure information security

Fine€39,700Fine issued
Regulator
Norwegian Supervisory Authority (Datatilsynet)
Decided
28 May 2021
Country
Norway
Sector
Finance, Insurance and Consulting
Regulator’s reference
Not recorded
Fino case number
2021/NO/013
Export as PDF

What happened

The Norwegian DPA (Datatilsynet) fined a bank NOK 400,000 (€ 39,700) for failing to assess risks, conduct sufficient testing and implement appropriate technical measures when launching a new customer portal, thus breaching Articles 24 and 32 GDPR.

Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Accountability
  • Data security

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2021/NO/013.