Datatilsynet (Denmark) · Date not published
Intervare A/S
About: Data breach
- Regulator
- Datatilsynet (Denmark)
- Decided
- Date not published
- Country
- Denmark
- Sector
- Not given
- Regulator’s reference
- 2019-441-1581
- Fino case number
- ND/DK/001
What happened
The Danish Data Protection Authority (Datatilsynet) decided on two similar cases regarding the notification requirements in the case of a personal data breach, 2019-441-1581 and 2019-441-1578. Both cases regarded insufficient access controls on a web based reporting service. In both cases, the information regarding customers’ orders were freely available online. The Danish DPA emphasized that the decision to not inform data subjects about a personal data breach pursuant to Article 34 was based on an insufficient assessment. The controller was ordered to notify the affected data subjects.
Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Data breach
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote ND/DK/001.