Datatilsynet (Denmark) · 15 July 2022
Salling Group
About: Data security
FineNo fineViolation found
- Regulator
- Datatilsynet (Denmark)
- Decided
- 15 July 2022
- Country
- Denmark
- Sector
- Not given
- Regulator’s reference
- 2022-441-12449
- Fino case number
- 2022/DK/042
What happened
The Danish DPA reprimanded the largest Danish retail group for violating Article 32(1) GDPR by storing passwords in plain text which made personal data accessible to unauthorised persons. It also ordered the controller to inform the affected data subjects about the data breach.
Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2022/DK/042.