Asker municipality – €87,000 Fine (Norway, 2021)

€87,000Datatilsynet (Norway)15 March 2021Norway
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Asker municipality in Norway was fined EUR 87,000 for publishing personal ID numbers in public record titles online. The Norwegian data protection authority found they lacked a legal basis and proper security measures. This case emphasizes the need for careful handling of personal data in public records.

What happened

Asker municipality published personal ID numbers in the titles of public records on their website without a legal basis.

Who was affected

Individuals whose personal ID numbers were exposed in public record titles.

What the authority found

The Norwegian authority found that Asker municipality violated GDPR by publishing personal data without a legal basis and failing to secure it properly.

Why this matters

This case serves as a warning to public authorities about the risks of mishandling personal data. It stresses the importance of having clear procedures and security measures in place when dealing with sensitive information.

GDPR Articles Cited

Art. 5 GDPR
Art. 6 GDPR
Art. 24 GDPR
Art. 32(1)(b) GDPR
Full Legal Summary
Detailed

Datatilsynet received a notification of a personal data breach from Asker municipality. The municipality had published 127 counts of personal ID numbers and information deemed confidential under the Public Administration Act in the title of the public records. The documents themselves were not published. The DPA found that the municipality had violated Articles 5 and 6 GDPR by publishing personal data on their webpage without a legal basis, and Articles 5 and 32(1)(b) by failing to implement appropriate technical and organisational measures to ensure ongoing confidentiality and integrity in their systems, and Article 24 GDPR for not implementing proper routines when handling the public records of mail. Datatilsynet held that publishing the title of documents containing sensitive information was a breach of Article 32(1)(b) GDPR, highlighting that the breach was reported to the municipality by a private individual and not noticed by the municipality itself. Datatilsynet highlighted that the personal data in question was not covered by the Public Administration Act. As such, the municipality did not have a legal basis cf. Article 6 GDPR. In addition, Datatilsynet found that the municipality lacked routines for publishing information to the public, violating Article 24 GDPR.

Related Enforcement Actions (0)

No other enforcement actions found for Asker municipality in NO

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

15 March 2021

Authority

Datatilsynet (Norway)

Fine Amount

€87,000

1,000,000 NOK

GDPRhub ID

gdprhub-3426

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Asker municipality - Norway (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: