Indre Østfold kommune (municipality) – €17,400 Fine (Norway, 2020)

€17,400Datatilsynet (Norway)16 November 2020Norway
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

A Norwegian municipality accidentally published a student's school folder online, making it accessible to the public. This was a breach of GDPR because the information was confidential and should have been protected. The municipality was fined for not securing the data properly.

What happened

A student's confidential school folder was mistakenly published on a Norwegian municipality's website.

Who was affected

A former student whose school folder was made publicly accessible online.

What the authority found

The Norwegian data protection authority fined the municipality for failing to secure the student's data, violating GDPR's requirements for data protection and confidentiality.

Why this matters

This case emphasizes the need for strict data security measures in educational institutions. It warns against the risks of mishandling sensitive student information.

GDPR Articles Cited

Art. 5 GDPR
Art. 6 GDPR
Art. 32(1)(b) GDPR

National Law Articles

The Education Act § 15(1)
Public Administration Act § 13 no. 1
Full Legal Summary
Detailed

A former student asked a school to share their school folder. The municipality's routine is to keep records for access requests, which meant, in this case, that the folder was scanned and made available for access. It was, however, made openly available on their website and a local journalist was able to download the entire folder with its contents. The information was confidential, cf. the Education Act. When the error was discovered, the folder was removed and the municipality notified the DPA of the personal data breach, as well as the affected data subject. Was publishing the student's school folder online a breach of Article 32? The DPA concluded that the municipality had breached the required information security requirements as per Article 32(1)(b), cf. Article 5, and that they didn't have any legal grounds for this processing as per Article 6, cf. Article 5 (the latter because the information was confidential and should never have been published openly). The municipality was fined €18,860.

Related Enforcement Actions (0)

No other enforcement actions found for Indre Østfold kommune (municipality) in NO

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

16 November 2020

Authority

Datatilsynet (Norway)

Fine Amount

€17,400

200,000 NOK

GDPRhub ID

gdprhub-2966

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Indre Østfold kommune (municipality) - Norway (2020). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: