Datatilsynet (Norway) · 15 March 2021
Alesund municipality
About: Accountability, DPIA, Data principles, Data security
FineNOK50,000≈ €4,950Violation found
- Regulator
- Datatilsynet (Norway)
- Decided
- 15 March 2021
- Country
- Norway
- Sector
- Not given
- Regulator’s reference
- 20/02147
- Fino case number
- 2021/NO/036
What happened
The Norwegian DPA (Datatilsynet) fined a municipality €4,900 for requiring students to use the fitness app Strava in gym classes without conducting a risk assessment and a DPIA first, and for the lack of security routines, thus breaching Article 32(1)(b) cf. Article 5 GDPR, Article 35 and Article 24(1), respectively.
Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal dataRead →
- Art. 24Responsibility of the controller24(1)Read →
- Art. 32Security of processing32(1)(b)Read →
- Art. 35Data protection impact assessmentRead →
- Accountability
- DPIA
- Data principles
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2021/NO/036.