Datatilsynet (Denmark) · Date not published
KMD A/S
About: Data security
FineNo fineReprimand
- Regulator
- Datatilsynet (Denmark)
- Decided
- Date not published
- Country
- Denmark
- Sector
- Not given
- Regulator’s reference
- 2019-431-0036
- Fino case number
- ND/DK/003
What happened
The Danish Data Protection Authority (Datatilsynet) issued a reprimand concerning the use of an acquired development and testing environment without implementing the appropriate security measures as required by Article 32 GDPR. The server was internally classified as an internal developer box and was not under review for the ordinary patching and security policy.
Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote ND/DK/003.