Lillestrøm municipality – €26,100 Fine (Norway, 2022)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Lillestrøm municipality in Norway accidentally published sensitive information about a student on their website. This mistake happened because they didn't properly check the document before posting it. The Norwegian Data Protection Authority fined them EUR 26,100 for not having enough safeguards and for sharing personal data without a valid reason.
What happened
Lillestrøm municipality published a document online containing sensitive personal data about a student without proper checks or legal grounds.
Who was affected
A student whose personal information, including educational and health details, was mistakenly made public on the municipality's website.
What the authority found
The Norwegian Data Protection Authority found that Lillestrøm municipality failed to use adequate security measures and shared personal data without a valid legal basis.
Why this matters
This case highlights the importance of thorough document checks and having strong security measures to protect personal data. It serves as a reminder for organizations to ensure they have proper systems in place to prevent such breaches.
GDPR Articles Cited
National Law Articles
Lillestrom municipality notified the Norwegian DPA about a personal data breach concerning a document they had published on their website, where they had forgotten to classify the appendices as exempt from public disclosure. The caseworker also failed to notice the error. The document then went through two additional manual quality controls without the error being detected and it was only discovered after a local journalist notified them. The document contained information and personal data about a pupil, including name, birth date, name and address of their parents and their description of their child, description and assessment of the pupil's behaviour and educational challenges from both the school and other public authorities, as well as a concrete assessment of how much special needs tutoring the pupil needs, the pupil's own description of their well-being at home and at school, their tests and assessments and potential diagnoses like dyslexia or ADHD. The document was available online for about two days and was accessed by four different IP addresses before the municipality managed to remove it. The Norwegian DPA fined the controller €29,880 for lack of sufficient technical and organisational measures under Article 32(1)(b) GDPR and Article 5 GDPR, and for having published personal data on their website without lawful grounds under Article 6 GDPR and Article 5 GDPR.
Related Enforcement Actions (0)
No other enforcement actions found for Lillestrøm municipality in NO
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
2 February 2022
Authority
Datatilsynet (Norway)
Fine Amount
€26,100
300,000 NOK
GDPRhub ID
gdprhub-4915About this data
Cite as: Cookie Fines. Lillestrøm municipality - Norway (2022). Retrieved from cookiefines.eu
Last updated: