Fino

Datatilsynet (Denmark) · 23 June 2023

Digitaliseringsstyrelsen (Agency for Digital Government)

About: Data security

FineNo fineViolation found
Regulator
Datatilsynet (Denmark)
Decided
23 June 2023
Country
Denmark
Sector
Not given
Regulator’s reference
2022-432-0079
Fino case number
2023/DK/007
Export as PDF

What happened

Due to an error within a digital identity solution used nationwide, several citizens accidentally gained access to bank accounts of another person. The Danish DPA held that only recommending and not requiring a mandatory validation of tokens for the safe use, which would eliminate the error, the solution violated Article 32 GDPR.

Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Data security

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2023/DK/007.