Lillestrøm municipality – €26,100 Fine (Norway, 2022)

€26,100Datatilsynet (Norway)2 February 2022Norway
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Lillestrøm municipality in Norway accidentally published sensitive information about a student on their website. This mistake happened because they didn't properly check the document before posting it. The Norwegian Data Protection Authority fined them EUR 26,100 for not having enough safeguards and for sharing personal data without a valid reason.

What happened

Lillestrøm municipality published a document online containing sensitive personal data about a student without proper checks or legal grounds.

Who was affected

A student whose personal information, including educational and health details, was mistakenly made public on the municipality's website.

What the authority found

The Norwegian Data Protection Authority found that Lillestrøm municipality failed to use adequate security measures and shared personal data without a valid legal basis.

Why this matters

This case highlights the importance of thorough document checks and having strong security measures to protect personal data. It serves as a reminder for organizations to ensure they have proper systems in place to prevent such breaches.

GDPR Articles Cited

Art. 5 GDPR
Art. 6 GDPR
Art. 32(1)(b) GDPR

National Law Articles

The Public Administration Act § 13(1)
Full Legal Summary
Detailed

Lillestrom municipality notified the Norwegian DPA about a personal data breach concerning a document they had published on their website, where they had forgotten to classify the appendices as exempt from public disclosure. The caseworker also failed to notice the error. The document then went through two additional manual quality controls without the error being detected and it was only discovered after a local journalist notified them. The document contained information and personal data about a pupil, including name, birth date, name and address of their parents and their description of their child, description and assessment of the pupil's behaviour and educational challenges from both the school and other public authorities, as well as a concrete assessment of how much special needs tutoring the pupil needs, the pupil's own description of their well-being at home and at school, their tests and assessments and potential diagnoses like dyslexia or ADHD. The document was available online for about two days and was accessed by four different IP addresses before the municipality managed to remove it. The Norwegian DPA fined the controller €29,880 for lack of sufficient technical and organisational measures under Article 32(1)(b) GDPR and Article 5 GDPR, and for having published personal data on their website without lawful grounds under Article 6 GDPR and Article 5 GDPR.

Related Enforcement Actions (0)

No other enforcement actions found for Lillestrøm municipality in NO

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

2 February 2022

Authority

Datatilsynet (Norway)

Fine Amount

€26,100

300,000 NOK

GDPRhub ID

gdprhub-4915

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Lillestrøm municipality - Norway (2022). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: