Persónuvernd (Island) · 21 December 2023
Not named in the source
About: Data security, Data subject rights
FineNo fineViolation found
- Regulator
- Persónuvernd (Island)
- Decided
- 21 December 2023
- Country
- Iceland
- Sector
- Not given
- Regulator’s reference
- 2023030483
- Fino case number
- 2023/IS/026
What happened
The Icelandic DPA held that a controller acted in violation of Article 32 GDPR by failing to locate all personal data requested by a data subject in the context of an access request under Article 15(3) GDPR.
Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 15Right of access by the data subject15(3)Read →
- Art. 32Security of processing32(1) · 32(2)Read →
- Data security
- Data subject rights
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2023/IS/026.