Norway Norway

Municipality of Rælingen

46,660 €

GDPR enforcement action by Norwegian Supervisory Authority (Datatilsynet) on 2020-07-10.

Rank · Sector
#70
of 357 in Public Sector and Education
Rank · Norway
#21
of 53
Rank · All fines
#759
of 3,050

Case details

Authority
Norwegian Supervisory Authority (Datatilsynet)
Date
2020-07-10
Controller / Processor
Municipality of Rælingen
Sector
Public Sector and Education
Quoted Articles
Art. 32 GDPR, Art. 35 GDPR
Type of violation
Insufficient technical and organisational measures to ensure information security

Summary

Fine for the processing of children's health data in connection with disability through the digital learning platform "Showbie". The Municipality had failed to carry out a Data Protection Impact Assessment ("DPIA") in accordance with Article 35 of the General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR") prior to the start of the processing and had not taken adequate technical and organisational measures in accordance with Article 32 of the GDPR, resulting in an increased risk of unauthorised access to the personal data of the pupils.

Open original source Links to the regulator's original publication or another source.

Related fines