Datatilsynet (Denmark) · 23 June 2023
Digitaliseringsstyrelsen (Agency for Digital Government)
About: Data security
FineNo fineViolation found
- Regulator
- Datatilsynet (Denmark)
- Decided
- 23 June 2023
- Country
- Denmark
- Sector
- Not given
- Regulator’s reference
- 2022-432-0079
- Fino case number
- 2023/DK/007
What happened
Due to an error within a digital identity solution used nationwide, several citizens accidentally gained access to bank accounts of another person. The Danish DPA held that only recommending and not requiring a mandatory validation of tokens for the safe use, which would eliminate the error, the solution violated Article 32 GDPR.
Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2023/DK/007.