Elektro & Automasjon Systemer AS – €17,400 Fine (Norway, 2021)

€17,400Datatilsynet (Norway)13 December 2021Norway
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Norway's Datatilsynet fined Elektro & Automasjon Systemer AS for running a credit check on a person without a valid reason. The company didn't have proper systems in place to prevent this mistake, which is important because credit checks involve sensitive financial data. This fine highlights the need for businesses to understand and properly manage their data tools.

What happened

Elektro & Automasjon Systemer AS conducted an unauthorized credit check on an individual without a valid reason.

Who was affected

The person affected was an owner of another company who had no business relationship with Elektro & Automasjon Systemer AS.

What the authority found

The Norwegian DPA found that the company lacked proper measures to prevent unauthorized data processing and had no legal basis for the credit check.

Why this matters

This case underscores the importance of companies ensuring they have proper systems and legal grounds for processing sensitive data like credit reports. It serves as a reminder for businesses to familiarize themselves with the tools they use and the legal frameworks governing them.

GDPR Articles Cited

Art. 24 GDPR
Art. 6(1) GDPR

National Law Articles

Personopplysningsforskriften § 4-3
Full Legal Summary
Detailed

Controller is a company that conducts credit checks. Controller mistakenly conducted a credit check on one of the owners of another company. There was no existing collaboration or customer/vendor relationship between the companies. After finding out about the credit check, this owner (the data subject) lodged a complaint with the Norwegian DPA. In their defence, the controller explained that the credit check had happened on accident and that it had been caused by their lack of familiarity with the system they used for requesting credit reports. First, the Norwegian DPA held that the controller had not implemented appropriate technical and organisational measures to prevent unlawful processing, in violation of Article 24 GDPR. Even though the controller had internal procedures in place regarding its processing of personal data in general, none of these were specifically aimed at conducting credit checks. The DPA held that any company that uses a credit report tool has an obligation to familiarise themselves with the tool and the legal framework to prevent errors from happening. Second, the DPA held that the controller lacked legal basis for the processing, in violation of Article 6(1) GDPR. As a result of the above infringements, the DPA imposed a fine of 200 000 NOK. When determining the size of the fine, the DPA highlighted that credit reports usually contain information about an individual's financial situation, such as information about salary and debt, which especially deserves a high level of protection. As mitigating factors, however, the DPA noted that the breach had only affected one data subject for a short duration.

Related Enforcement Actions (1)

Other enforcement actions involving Elektro & Automasjon Systemer AS in NO

Details

Fine Date

13 December 2021

Authority

Datatilsynet (Norway)

Fine Amount

€17,400

200,000 NOK

GDPRhub ID

gdprhub-4502

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Elektro & Automasjon Systemer AS - Norway (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: