Indre Østfold kommune (municipality) – €17,400 Fine (Norway, 2020)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
A Norwegian municipality accidentally published a student's school folder online, making it accessible to the public. This was a breach of GDPR because the information was confidential and should have been protected. The municipality was fined for not securing the data properly.
What happened
A student's confidential school folder was mistakenly published on a Norwegian municipality's website.
Who was affected
A former student whose school folder was made publicly accessible online.
What the authority found
The Norwegian data protection authority fined the municipality for failing to secure the student's data, violating GDPR's requirements for data protection and confidentiality.
Why this matters
This case emphasizes the need for strict data security measures in educational institutions. It warns against the risks of mishandling sensitive student information.
GDPR Articles Cited
National Law Articles
A former student asked a school to share their school folder. The municipality's routine is to keep records for access requests, which meant, in this case, that the folder was scanned and made available for access. It was, however, made openly available on their website and a local journalist was able to download the entire folder with its contents. The information was confidential, cf. the Education Act. When the error was discovered, the folder was removed and the municipality notified the DPA of the personal data breach, as well as the affected data subject. Was publishing the student's school folder online a breach of Article 32? The DPA concluded that the municipality had breached the required information security requirements as per Article 32(1)(b), cf. Article 5, and that they didn't have any legal grounds for this processing as per Article 6, cf. Article 5 (the latter because the information was confidential and should never have been published openly). The municipality was fined €18,860.
Related Enforcement Actions (0)
No other enforcement actions found for Indre Østfold kommune (municipality) in NO
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
16 November 2020
Authority
Datatilsynet (Norway)
Fine Amount
€17,400
200,000 NOK
GDPRhub ID
gdprhub-2966About this data
Cite as: Cookie Fines. Indre Østfold kommune (municipality) - Norway (2020). Retrieved from cookiefines.eu
Last updated: