Syddansk Universitet – Violation Found (Denmark, 2022)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
The University of Southern Denmark accidentally gave all its employees access to sensitive data for 14 days due to a system update error. The Danish DPA reprimanded the university for not testing the update properly. This incident underscores the need for thorough testing of software updates.
What happened
A system update error at the University of Southern Denmark gave all employees access to sensitive data.
Who was affected
Applicants whose personal data, including social security numbers and health information, were exposed to unauthorized university employees.
What the authority found
The Danish DPA held that the university did not implement adequate security measures, like proper testing of software updates, to protect personal data.
Why this matters
This reprimand serves as a warning to organizations about the importance of thoroughly testing software updates. It highlights the need for robust security practices to prevent unauthorized data access.
GDPR Articles Cited
In August 2021, the University of Southern Denmark (Syddansk Universitet) reported a personal data breach to the Danish DPA. The University uses an HR system where employees are assigned to roles so that they can access applications. Due to an update of the system, the role management was reset completely, so that all 7011 employees of the university had access to more than 400 applications for a period of 14 days. These applications contained personal data such as name, social security number and health data of the applicants. Normally only about 400 employees have access to this kind of information. The university had not performed an adequate testing of the software update before it was implemented. It claimed that they had no knowledge that the update would make a change in the role management. The university also did not keep access logs, so that it was not able to see whether unauthorised employees accessed the data in that time period or not. The Danish DPA held that the controller did not implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk under Article 32 GDPR. The DPA was of the opinion that controllers must perform adequate testing in order to be able to identify and assess conditions that may, for example, lead to changes or reset previously selected settings. The controller's liability cannot lapse simply because the software provider had not adequately disclosed the extent of the update. The Danish DPA therefore issued a serious reprimand.
Outcome
Violation Found
The DPA found a violation but did not impose a fine.
Related Enforcement Actions (0)
No other enforcement actions found for Syddansk Universitet in DK
This is the only recorded action for this entity in this jurisdiction.
Details
About this data
Cite as: Cookie Fines. Syddansk Universitet - Denmark (2022). Retrieved from cookiefines.eu
Last updated: