Coop Danmark A/S – Violation Found (Denmark, 2021)

Violation Found
Datatilsynet (Norway)4 November 2021Denmark
final
Violation Found

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Coop Danmark A/S was found to have stored sensitive employee data on a shared drive without proper access controls. This included health and financial information, which was accessible to unauthorized staff. The case underscores the need for strict data security measures, especially for sensitive information.

What happened

Coop Danmark A/S stored sensitive employee data on a shared drive without adequate access controls.

Who was affected

Employees and external consultants whose sensitive data was stored insecurely by Coop Danmark A/S.

What the authority found

The DPA determined that Coop Danmark A/S failed to implement sufficient security measures for sensitive data.

Why this matters

This case highlights the importance of securing sensitive data and ensuring only authorized personnel have access. Companies should regularly audit their data storage practices to prevent breaches.

GDPR Articles Cited

Art. 32(1) GDPR
Art. 33(1) GDPR
Art. 4(12) GDPR
Full Legal Summary
Detailed

When testing a new scanning tool, Coop Danmark A/S had become aware that it was storing personal information on the company's shared drive without sufficient access control. The information concerned 477 employees and external consultants. It included, among other things, health information, financial information, and social security numbers. Some information was placed in the folders by the data subjects themselves, and the controller saved other information as part of the employment processes. The personal data related to the time period from 2013 until 2017, when there was not the same policy for user management as the company has today. On 12 June 2021, the controller reported the data breach to the supervisory authority. After three months, it initiated the notification of affected data subjects. At the same time, it also started moving the information to a more secure solution with better user management and logging. The DPA held that in systems with a large amount of sensitive information about many users, controllers must have more stringent measures in place to ensure that only authorized people have access to it. The DPA emphasized that a controller the size of Coop Danmark A/S should have previously been aware that employees may have erroneously placed personal information on the company's joint drive. Therefore, it should have checked and cleaned up that data and introduced relevant security measures earlier.

Outcome

Violation Found

The DPA found a violation but did not impose a fine.

Related Enforcement Actions (0)

No other enforcement actions found for Coop Danmark A/S in DK

This is the only recorded action for this entity in this jurisdiction.

Details

Decision Date

4 November 2021

Authority

Datatilsynet (Norway)

GDPRhub ID

gdprhub-4913

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Coop Danmark A/S - Denmark (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: