Favrskov municipality – €10,000 Fine (Denmark, 2021)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Favrskov municipality in Denmark was fined EUR 10,000 after a laptop containing sensitive personal data was stolen during a break-in. The laptop's hard drive was not encrypted, which led to a security breach. This case highlights the importance of encrypting sensitive data to protect it from unauthorized access.
What happened
A laptop containing sensitive personal data was stolen from Favrskov municipality, and the data was not encrypted.
Who was affected
Approximately 100 individuals with physical or mental disabilities whose personal data was stored on the stolen laptop.
What the authority found
The Danish DPA found that the municipality failed to implement adequate security measures, such as encryption, to protect sensitive data.
Why this matters
This case emphasizes the need for strong data protection measures, like encryption, to prevent unauthorized access, especially for organizations handling sensitive information.
GDPR Articles Cited
The Danish DPA has imposed a fine of EUR 10,000 on Favrskov municipality. On August 19, 2020, the DPA received a notification from Favrskov Municipality of a personal data breach under Art. 33 GDPR. The notification stated that during a break-in at the municipality's premises, a laptop was stolen which contained a program that provided an overview of the municipality's care facilities and thus information on the names and personal identity numbers of approximately 100 individuals with physical or mental disabilities. The computer hard drive in question was not encrypted and the program in question, which contained confidential and sensitive personal data, was not equipped with security measures. In reviewing the case, the DPO found that Favrskov Municipality had not ensured the encryption of the hard drives of the municipality's laptops for a long period of time prior to August 12, 2020, resulting in an inadequate level of security. The DPA considered this to be a violation of Art. 32 GDPR, as the municipality had failed to implement appropriate technical and organizational measures to ensure a level of protection commensurate with the risk.
Related Enforcement Actions (0)
No other enforcement actions found for Favrskov municipality in DK
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
16 September 2021
Authority
Datatilsynet (Denmark)
Fine Amount
€10,000
Enforcement Tracker ID
ETid-836
About this data
Cite as: Cookie Fines. Favrskov municipality - Denmark (2021). Retrieved from cookiefines.eu
Last updated: