Alesund municipality – €4,350 Fine (Norway, 2021)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Alesund municipality in Norway was fined EUR 4,350 for using the Strava app in schools without proper data protection checks. Teachers asked students to use the app for gym classes, but the municipality failed to assess the privacy risks. This case shows the importance of evaluating privacy impacts before using apps in educational settings.
What happened
Alesund municipality used the Strava app in schools without conducting a privacy risk assessment.
Who was affected
Students at two junior high schools who were required to use the Strava app for gym classes.
What the authority found
The Norwegian authority found Alesund municipality violated GDPR by not assessing privacy risks or ensuring data protection when using the app.
Why this matters
This case highlights the need for schools and municipalities to conduct privacy assessments before using digital tools, especially those tracking personal data. It serves as a caution for educational institutions to prioritize data protection.
GDPR Articles Cited
Teachers at two junior high schools in Alesund municipality required their students to download the fitness app Strava for use in gym classes during the COVID-19 pandemic. The teachers used the app's tracking capabilities to validate that the students had conducted required exercises at home, for example bicycling a certain distance. The teachers, schools, nor the municipality, conducted a risk assessment or a Data Protection Impact Assessment (DPIA) before deciding to use Strava in this way. Was this use of Strava a breach of the GDPR? The DPA (Datatilsynet) held that the municipality had several breaches as per the GDPR: 1) For the lack of routines for technical and organisational security measures necessary to secure and demonstrate that the processing was in line with the GDPR, cf. Article 24(1). 2) For not having sufficient technical and organisational security measures in place to achive a level of protection suitable for ensuring confidentiality, integrity and robustness, and for not having conducted a risk assessment for the use of the app, cf. Article 32(1)(b), cf. Article 5. 3) For not conducting a Data Protection Impact Assessment (DPIA), cf. Article 35 (which the DPA assessed was necessary for this specific case). For these breaches, the municipality was fined NOK 50 000,-.
Related Enforcement Actions (0)
No other enforcement actions found for Alesund municipality in NO
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
15 March 2021
Authority
Datatilsynet (Norway)
Fine Amount
€4,350
50,000 NOK
GDPRhub ID
gdprhub-3294About this data
Cite as: Cookie Fines. Alesund municipality - Norway (2021). Retrieved from cookiefines.eu
Last updated: