Datatilsynet (Denmark) · 9 November 2023
Digitaliseringsstyrelsens
About: Accountability, Data principles, Data security
FineNo fineViolation found
- Regulator
- Datatilsynet (Denmark)
- Decided
- 9 November 2023
- Country
- Denmark
- Sector
- Not given
- Regulator’s reference
- 2023-432-0025
- Fino case number
- 2023/DK/014
What happened
The Danish DPA reprimanded the Agency for Digital Government for having used JavaScript in connection with MitID, the Danish digital ID. Even though there were widely known concerns with the programming language, the Agency utilised it without conducting a prior risk assessment, breaching, among others, Article 32(1) GDPR.
Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1)(f) · 5(2)Read →
- Art. 24Responsibility of the controller24(1)Read →
- Art. 32Security of processing32(1)Read →
- Accountability
- Data principles
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2023/DK/014.