Krokatjønnvegen 15 AS – €26,100 Fine (Norway, 2022)

€26,100Datatilsynet (Norway)27 May 2022Norway
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Norway's data protection authority fined a property management company for conducting unauthorized credit checks on two people. The company failed to prove it had proper controls over its credit rating process. This case highlights the need for businesses to ensure they have clear policies and controls for handling personal data.

What happened

Krokatjønnvegen 15 AS conducted unauthorized credit checks on individuals without a valid reason.

Who was affected

Two individuals who were credit rated by the company without any existing relationship.

What the authority found

The Norwegian DPA found that the company unlawfully conducted credit checks and lacked sufficient internal controls, violating GDPR.

Why this matters

This ruling underscores the importance of having robust data handling procedures and internal controls, especially when accessing sensitive information like credit data.

GDPR Articles Cited

Art. 24 GDPR
Art. 6(1)(f) GDPR
Art. 58(2)(i) GDPR
Full Legal Summary
Detailed

The Norwegian DPA (Datatilsynet) received a complaint from two data subjects who had been credit rated by a property management company they had no relationship with. The first data subject (data subject 1) recognized, however, the name of a person from the company, as he was the general manager for another company that her friend (data subject 2) had a rental agreement and dispute with. Both data subjects lodged complaints with the DPA and, consequently, the DPA launched an investigation. The DPA unraveled that several companies were involved in the corporate structure, but mainly the case pertained to "Krokatjønnveien 15 AS" (company 1) and "Bildøy Marina AS" (company 2). The companies claimed they shared the subscription for and access to the credit rating system and that it, by accident, had conducted the credit ratings from the incorrect company 1. They also claimed they had policies and procedures for credit ratings in place. They failed, however, to sufficiently demonstrate and convince the DPA that this was indeed the case. The DPA held that company 1 was the controller for the unlawful credit ratings, in violation of Article 6(1)(f) GDPR, issued a €30,500 fine and ordered them to implement internal controls of their credit rating process in line with Article 24 GDPR.

Details

Fine Date

27 May 2022

Authority

Datatilsynet (Norway)

Fine Amount

€26,100

300,000 NOK

GDPRhub ID

gdprhub-5159

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Krokatjønnvegen 15 AS - Norway (2022). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: