The Norwegian Parliament (Stortinget) – €174,000 Fine (Norway, 2022)

€174,000Datatilsynet (Norway)13 January 2022Norway
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Norway's data protection authority fined the Norwegian Parliament €174,000 for not securing employees' email accounts, leading to a data breach. The Parliament failed to implement two-factor authentication, despite knowing the risks. This case underlines the importance of following through on security plans to protect sensitive data.

What happened

The Norwegian Parliament experienced a data breach due to not implementing two-factor authentication for email accounts.

Who was affected

Employees of the Norwegian Parliament whose personal data, including bank and health information, was compromised.

What the authority found

The Norwegian authority found the Parliament negligent for not implementing identified security measures, violating GDPR's security requirements.

Why this matters

This ruling stresses the need for organizations to act on identified security risks promptly. It serves as a reminder to prioritize data protection measures like two-factor authentication.

GDPR Articles Cited

AI-verified

Art. 5(1)(f) GDPR
Art. 32(1)(b) GDPR
Art. 32(1)(d) GDPR
View original scraped data
Art. 5(1)(f) GDPR
Art. 5(2) GDPR
Art. 32(1)(b) GDPR
Art. 32(1)(d) GDPR

Original data from scraper before AI verification against source document.

Source verified 6 March 2026
amount discrepancy
Full Legal Summary
Detailed

In the fall of 2020, the Norwegian Parliament (Stortinget) had a personal data breach related to employees' email accounts, discovered after an employee had been contacted by their bank about an attempt of misuse of their payment card abroad. The Parliament discovered that the perpetrators had downloaded various data, including personal data information about their bank accounts, birth dates and health-related data. The Parliament had not enabled two-factor authentication in their email system, despite having identified the lack of such as a "high risk" in their risk analysis of March 2020. They had also identified a lack of security culture, low competency and little focus on data protection as very high risks. When the DPA reviewed the risk analysis in May 2021, two-factor authentication was still not fully implemented. In their notification of a decision, the DPA noted that the Parliament's administration, represented by the Secretary General, was grossly negligent. The DPA found that the Parliament, despite having identified several risks, lacked sufficient technical and organizational measures, including two-factor authentication, thus breaching Article 32(1)(b) GDPR and Article 32(1)(d), cf. Article 5(1)(f) GDPR. For this, the DPA fined the Parliament about €196,400 (NOK 2 million).

Related Enforcement Actions (0)

No other enforcement actions found for The Norwegian Parliament (Stortinget) in NO

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

13 January 2022

Authority

Datatilsynet (Norway)

Fine Amount

€174,000

2,000,000 NOK

GDPRhub ID

gdprhub-4544

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. The Norwegian Parliament (Stortinget) - Norway (2022). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: