Persónuvernd (Iceland) · 10 March 2023
City of Reykjavik
About: Data security
FineNo fineViolation found
- Regulator
- Persónuvernd (Iceland)
- Decided
- 10 March 2023
- Country
- Iceland
- Sector
- Not given
- Regulator’s reference
- 2022081293
- Fino case number
- 2023/IS/013
What happened
According to the Icelandic DPA, a controller violated Article 32 GDPR by sending a health report per e-mail to an unauthorised party, along with another e-mail containing the password to unlock the document.
Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2023/IS/013.