Moss municipality (kommune) – €43,500 Fine (Norway, 2021)

€43,500Datatilsynet (Norway)4 June 2021Norway
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Norway's Datatilsynet fined Moss municipality for not securing health records properly during a merger. Errors in vaccine and pregnancy records could have led to serious consequences for residents. This case highlights the importance of strong data security measures when merging IT systems.

What happened

Moss municipality failed to secure health records during a merger, leading to errors in vaccine and pregnancy data.

Who was affected

Residents of Moss municipality whose health records were transferred during the IT system merger.

What the authority found

The authority found Moss municipality violated GDPR by not having adequate security measures in place during the IT system merger.

Why this matters

This case underscores the need for municipalities and companies to conduct thorough data protection assessments and testing when merging IT systems. It serves as a reminder that proper data security is crucial to prevent errors that could impact people's health and safety.

GDPR Articles Cited

Art. 5 GDPR
Art. 32(1)(b) GDPR
Art. 32(1)(d) GDPR

National Law Articles

Health Records Act §22 (pasientjournalloven)
Full Legal Summary
Detailed

The two municipalities Rygge and Moss merged in January 2020. In the process of merging their IT systems for health records, several errors occurred: * Incorrect registration of vaccines. Some people were registered as having received vaccines, when they in reality had not, and others were incorrectly registered as not having been given a vaccine, when they in fact had. * Errors in health records for pregnant women, including error in the number of weeks into the pregnancy and related to information about the mother’s use of drugs/alcohol/nicotine. * Patient health data was made accessible to unauthorized healthcare personnel and it was not possible to trace any unauthorized access (in Norway a patient has the opportunity and right to view who has accessed their medical information). * Errors relating to daily operations (administration), such as appointment books. 28,000 people were transferred during the merger of the IT systems and about 2,000 could potentially have been affected by errors. However, no one were actually affected and the errors were rectified and are under control. Moss municipality notified the DPA themselves about the personal data security breaches. The DPA found, in the end, that the municipality had breached § 22 of the Norwegian Health Records Act (pasientjournalloven) and Article 32(1)(b) and (d) GDPR (cf. Article 5 GDPR). The DPA fined Moss municipality NOK 500,000 (€47,700) for insufficient technical and organisational measures to ensure a sufficient level of security when merging the IT systems. The DPA commented that the breaches were very serious and that the municipality should have conducted a data protection impact assessment (DPIA), as well as more testing before making the changes.

Related Enforcement Actions (0)

No other enforcement actions found for Moss municipality (kommune) in NO

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

4 June 2021

Authority

Datatilsynet (Norway)

Fine Amount

€43,500

500,000 NOK

GDPRhub ID

gdprhub-3684

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Moss municipality (kommune) - Norway (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: