Trumf – €435,000 Fine (Norway, 2021)

€435,000Datatilsynet (Norway)6 December 2021Norway
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Norway's Datatilsynet fined Trumf for not fixing a security flaw that let people see others' purchase histories. This is important because it shows companies must take security seriously and report breaches. Trumf's failure to act led to a significant fine.

What happened

Trumf failed to address a security issue that exposed users' purchase histories and didn't report the breaches.

Who was affected

Trumf loyalty program users whose purchase histories could be accessed by others.

What the authority found

The Norwegian authority ruled that Trumf violated GDPR by not securing user data and failing to report breaches.

Why this matters

This case highlights the need for companies to promptly address security issues and report data breaches. It warns businesses that ignoring these responsibilities can lead to hefty fines.

GDPR Articles Cited

AI-verified

Art. 32 GDPR
Art. 33(1) GDPR
Art. 33(5) GDPR
View original scraped data
Art. 32 GDPR
Art. 33(1) GDPR
Art. 33(5) GDPR

Original data from scraper before AI verification against source document.

Source verified 6 March 2026
amount discrepancy
Full Legal Summary
Detailed

"Trumf" is a customer loyalty program owned and run by the company with the same name (the controller). Users can register their Trumf card at various stores, gas stations, airlines and other Trumf partners to collect bonus points, which can then be used to purchase goods or be withdrawn as cash. In 2016, it was discovered that people could register other people's bank account numbers to get access to their detailed purchase history. At the time, the Norwegian DPA (Datatilsynet) instructed the controller to mitigate this security risk. The controller confirmed that this would be dealt with promptly by implementing a verification mechanism which would solve the problem. However, in 2020, the DPA, through various news stories, became aware that the security issue was still unresolved. The controller explained that it had been too challenging to resolve it and, further, that they did not report these breaches because they thought they did not have to. Consequently, they did not adhere to Article 33(5) GDPR, nor Article 33(1). The Norwegian DPA held that Trumf had breached Article 33(1) for failing to notify them of repeated personal data breaches, Article 33(5) for failing to document these breaches, and Article 32 for failing to implement sufficient technical and organizational measures. For these violations, the DPA fined the controller €500,185 (NOK 5,000,000).

Related Enforcement Actions (0)

No other enforcement actions found for Trumf in NO

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

6 December 2021

Authority

Datatilsynet (Norway)

Fine Amount

€435,000

5,000,000 NOK

GDPRhub ID

gdprhub-4506

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Trumf - Norway (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: