Moss municipality – €49,200 Fine (Norway, 2021)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Datatilsynet fined Moss municipality for not securing personal data during a merger of IT systems. Errors in health records could have led to incorrect medical treatments. This case emphasizes the need for strong data protection during system changes.
What happened
Moss municipality inadequately secured personal data during an IT system merger, leading to errors in health records.
Who was affected
Residents of Moss municipality who used health services and had their data processed during the merger.
What the authority found
The authority found Moss municipality failed to implement adequate security measures, violating GDPR requirements.
Why this matters
This case stresses the importance of implementing robust security measures during IT system mergers to protect sensitive data. It serves as a warning for organizations to prioritize data protection to prevent similar breaches.
GDPR Articles Cited
The Norwegian DPA (Datatilsynet) has fined the municipality of Moss EUR 49,200 for inadequately securing personal data. In January, the municipality of Rygge was annexed to the municipality of Moss. For this reason, several IT systems from both municipalities were combined. Due to inadequate security measures, a data breach occurred in a productive system used in the municipality's health service. This system processed personal and health data and affected people who live in the municipality and use the health center. The system is used for services related to immunization programs in the municipality, as well as for other health checks and follow-ups of pregnant women. About 2000 people were potentially affected by the breach. Due to the data breach, errors had occurred in vaccine registration. As a result, the data subjects were at risk of receiving the wrong vaccines. There was also a potential for their immunization data to be misfiled in the national immunization registry. Furthermore, errors occurred in follow-ups for pregnant women, including information on the week of pregnancy or the mother's drug use. Also, patient information was provided to health workers in a health service ward without being required and without access being documented.
Related Enforcement Actions (0)
No other enforcement actions found for Moss municipality in NO
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
4 June 2021
Authority
Datatilsynet (Norway)
Fine Amount
€49,200
Enforcement Tracker ID
ETid-738
About this data
Cite as: Cookie Fines. Moss municipality - Norway (2021). Retrieved from cookiefines.eu
Last updated: