Norwegian Supervisory Authority (Datatilsynet) · 15 March 2021
Asker Municipality
Insufficient technical and organisational measures to ensure information security
- Regulator
- Norwegian Supervisory Authority (Datatilsynet)
- Decided
- 15 March 2021
- Country
- Norway
- Sector
- Public Sector and Education
- Regulator’s reference
- Not recorded
- Fino case number
- 2021/NO/019
What happened
The Norwegian DPA investigated a personal data breach notified by a municipality. The DPA found that the municipality had violated Articles 5, 6, and 32(1)(b) GDPR by publishing personal data on their webpage without a legal basis, without appropriate measures and without implementing proper routines when revealing information to the public.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal dataRead →
- Art. 6Lawfulness of processingRead →
- Art. 24Responsibility of the controllerRead →
- Art. 32Security of processing32(1)(b)Read →
- Accountability
- Data principles
- Data security
- Unlawful processing
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2021/NO/019.