Trumf – €435,000 Fine (Norway, 2021)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Norway's Datatilsynet fined Trumf for not fixing a security flaw that let people see others' purchase histories. This is important because it shows companies must take security seriously and report breaches. Trumf's failure to act led to a significant fine.
What happened
Trumf failed to address a security issue that exposed users' purchase histories and didn't report the breaches.
Who was affected
Trumf loyalty program users whose purchase histories could be accessed by others.
What the authority found
The Norwegian authority ruled that Trumf violated GDPR by not securing user data and failing to report breaches.
Why this matters
This case highlights the need for companies to promptly address security issues and report data breaches. It warns businesses that ignoring these responsibilities can lead to hefty fines.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
"Trumf" is a customer loyalty program owned and run by the company with the same name (the controller). Users can register their Trumf card at various stores, gas stations, airlines and other Trumf partners to collect bonus points, which can then be used to purchase goods or be withdrawn as cash. In 2016, it was discovered that people could register other people's bank account numbers to get access to their detailed purchase history. At the time, the Norwegian DPA (Datatilsynet) instructed the controller to mitigate this security risk. The controller confirmed that this would be dealt with promptly by implementing a verification mechanism which would solve the problem. However, in 2020, the DPA, through various news stories, became aware that the security issue was still unresolved. The controller explained that it had been too challenging to resolve it and, further, that they did not report these breaches because they thought they did not have to. Consequently, they did not adhere to Article 33(5) GDPR, nor Article 33(1). The Norwegian DPA held that Trumf had breached Article 33(1) for failing to notify them of repeated personal data breaches, Article 33(5) for failing to document these breaches, and Article 32 for failing to implement sufficient technical and organizational measures. For these violations, the DPA fined the controller €500,185 (NOK 5,000,000).
Related Enforcement Actions (0)
No other enforcement actions found for Trumf in NO
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
6 December 2021
Authority
Datatilsynet (Norway)
Fine Amount
€435,000
5,000,000 NOK
GDPRhub ID
gdprhub-4506About this data
Cite as: Cookie Fines. Trumf - Norway (2021). Retrieved from cookiefines.eu
Last updated: