Fino

Datatilsynet (Norway) · 9 January 2023

PostNord AS

About: Data security

FineNo fineViolation found
Regulator
Datatilsynet (Norway)
Decided
9 January 2023
Country
Norway
Sector
Not given
Regulator’s reference
20/02144
Fino case number
2023/NO/005
Export as PDF

What happened

The Norwegian DPA held that a courier and logistics company violated Article 32 GDPR for insufficient risk assessment and the lack of security measures in the app MyPostNord, which used phone numbers as the only means of authentication to access a customer profile.

Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Data security

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2023/NO/005.