IMY (Sweden) · 28 August 2023
Trygg-Hansa
About: Data principles, Data security
FineSEK35,000,000≈ €2,940,000Violation found
- Regulator
- IMY (Sweden)
- Decided
- 28 August 2023
- Country
- Sweden
- Sector
- Not given
- Regulator’s reference
- DI-2021-1905
- Fino case number
- 2023/SE/019
What happened
The Swedish DPA issued a penalty fee of SEK 35 million (around €3 million) against Trygg-Hansa. The insurance company had serious security flaws via faulty URLs resulting in a data breach of 650,000 customers' data over a period of two years.
Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1)(f)Read →
- Art. 32Security of processing32(1)Read →
- Art. 58Powers58(2)Read →
- Art. 83General conditions for imposing administrative finesRead →
- Data principles
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2023/SE/019.