InfoMentor ehf – €23,100 Fine (Iceland, 2021)

€23,100Persónuvernd29 April 2021Iceland
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

InfoMentor ehf was fined EUR 23,100 by the Icelandic DPA for not having strong enough security measures, which led to a data breach. The breach exposed personal data of 424 children using their online system. This case shows how crucial it is to protect personal data, especially when dealing with sensitive information about children.

What happened

A security flaw in InfoMentor's online system exposed personal data of 424 children due to inadequate security measures.

Who was affected

Children whose personal data was exposed due to a security breach in the online system used by schools.

What the authority found

The authority determined that InfoMentor failed to implement adequate security measures, leading to unauthorized access to personal data.

Why this matters

This case highlights the importance of robust security measures to protect personal data, especially in systems used by schools. Companies should regularly assess and update their security protocols to prevent data breaches.

GDPR Articles Cited

Art. 32(1)(b) GDPR
Full Legal Summary
Detailed

The Icelandic DPA (Persónuvernd) has imposed a fine of EUR 23,100 on InfoMentor ehf. Previously, the controller had reported a data breach according to Art. 33 GDPR. The incident concerned the company's online system, which is mainly used by schools and other institutions for communication and information purposes. In the course of its investigations, the DPA determined that inadequate technical and organizational security measures on the part of the controller led to the breach. Due to a security leak that resulted in the six-digit system number of each user being visible in the URL address of a specific page within the mentor system, unauthorized persons gained access to the personal data of 424 children.

Related Enforcement Actions (0)

No other enforcement actions found for InfoMentor ehf in IS

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

29 April 2021

Authority

Persónuvernd

Fine Amount

€23,100

Enforcement Tracker ID

ETid-669

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. InfoMentor ehf - Iceland (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: