Fino

IMY (Sweden) · 19 January 2023

If Skadeförsäkring AB

About: Data security, Special categories

FineNo fineViolation found
Regulator
IMY (Sweden)
Decided
19 January 2023
Country
Sweden
Sector
Not given
Regulator’s reference
DI-2021-4355
Fino case number
2023/SE/013
Export as PDF

What happened

Sending an e-mail containing sensitive data with enforced TLS-encryption instead of end-to-end encryption was deemed insufficient secured under Article 32(1) GDPR. The controller received a reprimand instead of a fine as it had increased the security of its communication solutions.

Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Data security
  • Special categories

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2023/SE/013.