Krokatjønnvegen 15 AS – €26,100 Fine (Norway, 2022)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Norway's data protection authority fined a property management company for conducting unauthorized credit checks on two people. The company failed to prove it had proper controls over its credit rating process. This case highlights the need for businesses to ensure they have clear policies and controls for handling personal data.
What happened
Krokatjønnvegen 15 AS conducted unauthorized credit checks on individuals without a valid reason.
Who was affected
Two individuals who were credit rated by the company without any existing relationship.
What the authority found
The Norwegian DPA found that the company unlawfully conducted credit checks and lacked sufficient internal controls, violating GDPR.
Why this matters
This ruling underscores the importance of having robust data handling procedures and internal controls, especially when accessing sensitive information like credit data.
GDPR Articles Cited
The Norwegian DPA (Datatilsynet) received a complaint from two data subjects who had been credit rated by a property management company they had no relationship with. The first data subject (data subject 1) recognized, however, the name of a person from the company, as he was the general manager for another company that her friend (data subject 2) had a rental agreement and dispute with. Both data subjects lodged complaints with the DPA and, consequently, the DPA launched an investigation. The DPA unraveled that several companies were involved in the corporate structure, but mainly the case pertained to "Krokatjønnveien 15 AS" (company 1) and "Bildøy Marina AS" (company 2). The companies claimed they shared the subscription for and access to the credit rating system and that it, by accident, had conducted the credit ratings from the incorrect company 1. They also claimed they had policies and procedures for credit ratings in place. They failed, however, to sufficiently demonstrate and convince the DPA that this was indeed the case. The DPA held that company 1 was the controller for the unlawful credit ratings, in violation of Article 6(1)(f) GDPR, issued a €30,500 fine and ordered them to implement internal controls of their credit rating process in line with Article 24 GDPR.
Related Enforcement Actions (1)
Other enforcement actions involving Krokatjønnvegen 15 AS in NO
Details
Fine Date
27 May 2022
Authority
Datatilsynet (Norway)
Fine Amount
€26,100
300,000 NOK
GDPRhub ID
gdprhub-5159About this data
Cite as: Cookie Fines. Krokatjønnvegen 15 AS - Norway (2022). Retrieved from cookiefines.eu
Last updated: