Moss municipality – €49,200 Fine (Norway, 2021)

€49,200Datatilsynet (Norway)4 June 2021Norway
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Datatilsynet fined Moss municipality for not securing personal data during a merger of IT systems. Errors in health records could have led to incorrect medical treatments. This case emphasizes the need for strong data protection during system changes.

What happened

Moss municipality inadequately secured personal data during an IT system merger, leading to errors in health records.

Who was affected

Residents of Moss municipality who used health services and had their data processed during the merger.

What the authority found

The authority found Moss municipality failed to implement adequate security measures, violating GDPR requirements.

Why this matters

This case stresses the importance of implementing robust security measures during IT system mergers to protect sensitive data. It serves as a warning for organizations to prioritize data protection to prevent similar breaches.

GDPR Articles Cited

Art. 32(1)(b) GDPR
Full Legal Summary
Detailed

The Norwegian DPA (Datatilsynet) has fined the municipality of Moss EUR 49,200 for inadequately securing personal data. In January, the municipality of Rygge was annexed to the municipality of Moss. For this reason, several IT systems from both municipalities were combined. Due to inadequate security measures, a data breach occurred in a productive system used in the municipality's health service. This system processed personal and health data and affected people who live in the municipality and use the health center. The system is used for services related to immunization programs in the municipality, as well as for other health checks and follow-ups of pregnant women. About 2000 people were potentially affected by the breach. Due to the data breach, errors had occurred in vaccine registration. As a result, the data subjects were at risk of receiving the wrong vaccines. There was also a potential for their immunization data to be misfiled in the national immunization registry. Furthermore, errors occurred in follow-ups for pregnant women, including information on the week of pregnancy or the mother's drug use. Also, patient information was provided to health workers in a health service ward without being required and without access being documented.

Related Enforcement Actions (0)

No other enforcement actions found for Moss municipality in NO

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

4 June 2021

Authority

Datatilsynet (Norway)

Fine Amount

€49,200

Enforcement Tracker ID

ETid-738

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Moss municipality - Norway (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: