The Norwegian Parliament (Stortinget) – €174,000 Fine (Norway, 2022)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Norway's data protection authority fined the Norwegian Parliament €174,000 for not securing employees' email accounts, leading to a data breach. The Parliament failed to implement two-factor authentication, despite knowing the risks. This case underlines the importance of following through on security plans to protect sensitive data.
What happened
The Norwegian Parliament experienced a data breach due to not implementing two-factor authentication for email accounts.
Who was affected
Employees of the Norwegian Parliament whose personal data, including bank and health information, was compromised.
What the authority found
The Norwegian authority found the Parliament negligent for not implementing identified security measures, violating GDPR's security requirements.
Why this matters
This ruling stresses the need for organizations to act on identified security risks promptly. It serves as a reminder to prioritize data protection measures like two-factor authentication.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
In the fall of 2020, the Norwegian Parliament (Stortinget) had a personal data breach related to employees' email accounts, discovered after an employee had been contacted by their bank about an attempt of misuse of their payment card abroad. The Parliament discovered that the perpetrators had downloaded various data, including personal data information about their bank accounts, birth dates and health-related data. The Parliament had not enabled two-factor authentication in their email system, despite having identified the lack of such as a "high risk" in their risk analysis of March 2020. They had also identified a lack of security culture, low competency and little focus on data protection as very high risks. When the DPA reviewed the risk analysis in May 2021, two-factor authentication was still not fully implemented. In their notification of a decision, the DPA noted that the Parliament's administration, represented by the Secretary General, was grossly negligent. The DPA found that the Parliament, despite having identified several risks, lacked sufficient technical and organizational measures, including two-factor authentication, thus breaching Article 32(1)(b) GDPR and Article 32(1)(d), cf. Article 5(1)(f) GDPR. For this, the DPA fined the Parliament about €196,400 (NOK 2 million).
Related Enforcement Actions (0)
No other enforcement actions found for The Norwegian Parliament (Stortinget) in NO
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
13 January 2022
Authority
Datatilsynet (Norway)
Fine Amount
€174,000
2,000,000 NOK
GDPRhub ID
gdprhub-4544About this data
Cite as: Cookie Fines. The Norwegian Parliament (Stortinget) - Norway (2022). Retrieved from cookiefines.eu
Last updated: