Datatilsynet (Norway) · 9 January 2023
PostNord AS
About: Data security
FineNo fineViolation found
- Regulator
- Datatilsynet (Norway)
- Decided
- 9 January 2023
- Country
- Norway
- Sector
- Not given
- Regulator’s reference
- 20/02144
- Fino case number
- 2023/NO/005
What happened
The Norwegian DPA held that a courier and logistics company violated Article 32 GDPR for insufficient risk assessment and the lack of security measures in the app MyPostNord, which used phone numbers as the only means of authentication to access a customer profile.
Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2023/NO/005.