Iceland Iceland

City of Reykjavik

13,300 €

GDPR enforcement action by Icelandic data protection authority ('Persónuvernd') on 2023-12-06.

Rank · Sector
#158
of 357 in Public Sector and Education
Rank · Iceland
#17
of 22
Rank · All fines
#1,245
of 3,051

Case details

Authority
Icelandic data protection authority ('Persónuvernd')
Date
2023-12-06
Controller / Processor
City of Reykjavik
Sector
Public Sector and Education
Quoted Articles
Art. 5 (1) GDPR, Art. 24 (1) GDPR, Art. 28 GDPR
Type of violation
Non-compliance with general data processing principles

Summary

The Icelandic DPA has imposed a fine of EUR 13,300 on the city of Reykjavik. The city had used the Google Education system in schools without sufficiently complying with data protection regulations.

In particular, the city did not fulfill its obligations when selecting Google as a processor and the processing agreement with Google did not comply with data protection requirements.

Furthermore, the city did not ensure that the student data was not processed for purposes other than those specified by the city.


In imposing the fine, particular consideration was given to the protection of sensitive children's data. Although no demonstrable damage had occurred, it was criticized that the city had not sufficiently ensured the secure transfer of data to the US in the past. However, the municipality cooperated transparently with the data protection authority and revised its data protection practices.

Open original source Links to the regulator's original publication or another source.

Related fines