KMD A/S โ€“ Violation Found (Denmark, 2022)

Violation Found
Datatilsynet (Norway)25 August 2022Denmark
final
Violation Found

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

The Norwegian data authority found that KMD A/S failed to test a system update properly, which led to unauthorized access to children's data. This matters because it shows the importance of testing updates to prevent data breaches.

What happened

KMD A/S did not adequately test a system update, resulting in unauthorized access to sensitive children's data.

Who was affected

Children whose information was processed on the AULA platform.

What the authority found

The authority concluded that KMD A/S violated GDPR by not ensuring the security of personal data during system updates.

Why this matters

This decision emphasizes the responsibility of IT service providers to thoroughly test updates and maintain data security. It serves as a warning for companies to evaluate their update processes to avoid similar breaches.

GDPR Articles Cited

Art. 32(1) GDPR
Full Legal Summary
Detailed

KMD A/S (processor) is a Danish IT service provider offering digital solutions for various industries, including the public sector. Between 19 and 21 January 2021, several municipalities complained to the DPA about a data breach caused by the KMD, which the DPA decided to investigate. The breach involved the AULA platform used to process children's information from schools and daycares and controlled by another processor, namely KOMBIT A/S. As a result of an update run by KMD in its systems, the information about foster parents was sent to AULA, giving them access to foster children's information which they were not supposed to have. However, the KMD denied its responsibility during the breach investigation, suggesting that it could not test how the update worked with the recipient's system AULA. The DPA held that when developing new functionality for an IT system, the processor must consider the potential consequences of an update and conduct appropriate tests. That way, the processor must ensure that the changes do not compromise the existing security requirements. Additionally, the processor must create an overview of its own IT architecture and environment, including the systems integrated with other systems by delivering or receiving data, and ensure mapping of the integrations and associated dependencies. As a result, the processor must report code changes in integrated systems to relevant controllers and processors before they go into production. These requirements must ensure that external controllers and processors are informed of the planned changes on time and can carry out appropriate tests of the integrity of personal data exchanged between the integrated systems. Consequently, the DPA considered that KMD had a duty and a possibility to test the interaction of its new functionality with AULA and therefore violated Article 32(1) GDPR by not doing so.

Outcome

Violation Found

The DPA found a violation but did not impose a fine.

Related Enforcement Actions (0)

No other enforcement actions found for KMD A/S in DK

This is the only recorded action for this entity in this jurisdiction.

Details

Decision Date

25 August 2022

Authority

Datatilsynet (Norway)

GDPRhub ID

gdprhub-5248

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. KMD A/S - Denmark (2022). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: