Asker municipality – €87,000 Fine (Norway, 2021)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Asker municipality in Norway was fined EUR 87,000 for publishing personal ID numbers in public record titles online. The Norwegian data protection authority found they lacked a legal basis and proper security measures. This case emphasizes the need for careful handling of personal data in public records.
What happened
Asker municipality published personal ID numbers in the titles of public records on their website without a legal basis.
Who was affected
Individuals whose personal ID numbers were exposed in public record titles.
What the authority found
The Norwegian authority found that Asker municipality violated GDPR by publishing personal data without a legal basis and failing to secure it properly.
Why this matters
This case serves as a warning to public authorities about the risks of mishandling personal data. It stresses the importance of having clear procedures and security measures in place when dealing with sensitive information.
GDPR Articles Cited
Datatilsynet received a notification of a personal data breach from Asker municipality. The municipality had published 127 counts of personal ID numbers and information deemed confidential under the Public Administration Act in the title of the public records. The documents themselves were not published. The DPA found that the municipality had violated Articles 5 and 6 GDPR by publishing personal data on their webpage without a legal basis, and Articles 5 and 32(1)(b) by failing to implement appropriate technical and organisational measures to ensure ongoing confidentiality and integrity in their systems, and Article 24 GDPR for not implementing proper routines when handling the public records of mail. Datatilsynet held that publishing the title of documents containing sensitive information was a breach of Article 32(1)(b) GDPR, highlighting that the breach was reported to the municipality by a private individual and not noticed by the municipality itself. Datatilsynet highlighted that the personal data in question was not covered by the Public Administration Act. As such, the municipality did not have a legal basis cf. Article 6 GDPR. In addition, Datatilsynet found that the municipality lacked routines for publishing information to the public, violating Article 24 GDPR.
Related Enforcement Actions (0)
No other enforcement actions found for Asker municipality in NO
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
15 March 2021
Authority
Datatilsynet (Norway)
Fine Amount
€87,000
1,000,000 NOK
GDPRhub ID
gdprhub-3426About this data
Cite as: Cookie Fines. Asker municipality - Norway (2021). Retrieved from cookiefines.eu
Last updated: