Fino

Datatilsynet (Denmark) · Date not published

Intervare A/S

About: Data breach

FineNo fineOrder
Regulator
Datatilsynet (Denmark)
Decided
Date not published
Country
Denmark
Sector
Not given
Regulator’s reference
2019-441-1581
Fino case number
ND/DK/001
Export as PDF

What happened

The Danish Data Protection Authority (Datatilsynet) decided on two similar cases regarding the notification requirements in the case of a personal data breach, 2019-441-1581 and 2019-441-1578. Both cases regarded insufficient access controls on a web based reporting service. In both cases, the information regarding customers’ orders were freely available online. The Danish DPA emphasized that the decision to not inform data subjects about a personal data breach pursuant to Article 34 was based on an insufficient assessment. The controller was ordered to notify the affected data subjects.

Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Data breach

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote ND/DK/001.