Favrskov municipality – €10,000 Fine (Denmark, 2021)

€10,000Datatilsynet (Denmark)16 September 2021Denmark
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Favrskov municipality in Denmark was fined EUR 10,000 after a laptop containing sensitive personal data was stolen during a break-in. The laptop's hard drive was not encrypted, which led to a security breach. This case highlights the importance of encrypting sensitive data to protect it from unauthorized access.

What happened

A laptop containing sensitive personal data was stolen from Favrskov municipality, and the data was not encrypted.

Who was affected

Approximately 100 individuals with physical or mental disabilities whose personal data was stored on the stolen laptop.

What the authority found

The Danish DPA found that the municipality failed to implement adequate security measures, such as encryption, to protect sensitive data.

Why this matters

This case emphasizes the need for strong data protection measures, like encryption, to prevent unauthorized access, especially for organizations handling sensitive information.

GDPR Articles Cited

Art. 32 GDPR
Full Legal Summary
Detailed

The Danish DPA has imposed a fine of EUR 10,000 on Favrskov municipality. On August 19, 2020, the DPA received a notification from Favrskov Municipality of a personal data breach under Art. 33 GDPR. The notification stated that during a break-in at the municipality's premises, a laptop was stolen which contained a program that provided an overview of the municipality's care facilities and thus information on the names and personal identity numbers of approximately 100 individuals with physical or mental disabilities. The computer hard drive in question was not encrypted and the program in question, which contained confidential and sensitive personal data, was not equipped with security measures. In reviewing the case, the DPO found that Favrskov Municipality had not ensured the encryption of the hard drives of the municipality's laptops for a long period of time prior to August 12, 2020, resulting in an inadequate level of security. The DPA considered this to be a violation of Art. 32 GDPR, as the municipality had failed to implement appropriate technical and organizational measures to ensure a level of protection commensurate with the risk.

Related Enforcement Actions (0)

No other enforcement actions found for Favrskov municipality in DK

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

16 September 2021

Authority

Datatilsynet (Denmark)

Fine Amount

€10,000

Enforcement Tracker ID

ETid-836

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Favrskov municipality - Denmark (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: