Alesund municipality – €4,350 Fine (Norway, 2021)

€4,350Datatilsynet (Norway)15 March 2021Norway
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Alesund municipality in Norway was fined EUR 4,350 for using the Strava app in schools without proper data protection checks. Teachers asked students to use the app for gym classes, but the municipality failed to assess the privacy risks. This case shows the importance of evaluating privacy impacts before using apps in educational settings.

What happened

Alesund municipality used the Strava app in schools without conducting a privacy risk assessment.

Who was affected

Students at two junior high schools who were required to use the Strava app for gym classes.

What the authority found

The Norwegian authority found Alesund municipality violated GDPR by not assessing privacy risks or ensuring data protection when using the app.

Why this matters

This case highlights the need for schools and municipalities to conduct privacy assessments before using digital tools, especially those tracking personal data. It serves as a caution for educational institutions to prioritize data protection.

GDPR Articles Cited

Art. 5 GDPR
Art. 35 GDPR
Art. 24(1) GDPR
Art. 32(1)(b) GDPR
Full Legal Summary
Detailed

Teachers at two junior high schools in Alesund municipality required their students to download the fitness app Strava for use in gym classes during the COVID-19 pandemic. The teachers used the app's tracking capabilities to validate that the students had conducted required exercises at home, for example bicycling a certain distance. The teachers, schools, nor the municipality, conducted a risk assessment or a Data Protection Impact Assessment (DPIA) before deciding to use Strava in this way. Was this use of Strava a breach of the GDPR? The DPA (Datatilsynet) held that the municipality had several breaches as per the GDPR: 1) For the lack of routines for technical and organisational security measures necessary to secure and demonstrate that the processing was in line with the GDPR, cf. Article 24(1). 2) For not having sufficient technical and organisational security measures in place to achive a level of protection suitable for ensuring confidentiality, integrity and robustness, and for not having conducted a risk assessment for the use of the app, cf. Article 32(1)(b), cf. Article 5. 3) For not conducting a Data Protection Impact Assessment (DPIA), cf. Article 35 (which the DPA assessed was necessary for this specific case). For these breaches, the municipality was fined NOK 50 000,-.

Related Enforcement Actions (0)

No other enforcement actions found for Alesund municipality in NO

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

15 March 2021

Authority

Datatilsynet (Norway)

Fine Amount

€4,350

50,000 NOK

GDPRhub ID

gdprhub-3294

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Alesund municipality - Norway (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: