Fino

Persónuvernd (Iceland) · 10 March 2023

City of Reykjavik

About: Data security

FineNo fineViolation found
Regulator
Persónuvernd (Iceland)
Decided
10 March 2023
Country
Iceland
Sector
Not given
Regulator’s reference
2022081293
Fino case number
2023/IS/013
Export as PDF

What happened

According to the Icelandic DPA, a controller violated Article 32 GDPR by sending a health report per e-mail to an unauthorised party, along with another e-mail containing the password to unlock the document.

Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Data security

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2023/IS/013.