Danske Bank – Violation Found (Denmark, 2022)

Violation Found
Datatilsynet (Norway)13 June 2022Denmark
final
Violation Found

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Danske Bank had a security flaw that let users see other people's invoices on its platform. The Norwegian DPA found this violated GDPR rules on data protection, showing the need for strong security measures.

What happened

A technical error in Danske Bank's system allowed users to view 132 invoices not meant for them.

Who was affected

371 Finnish users who accessed invoices they shouldn't have been able to see.

What the authority found

The Norwegian DPA found that Danske Bank failed to ensure adequate security measures, violating GDPR's data protection requirements.

Why this matters

This case highlights the importance of implementing robust security checks in systems handling sensitive data, reminding businesses to regularly test and evaluate their data protection measures.

GDPR Articles Cited

Art. 32(1) GDPR
Full Legal Summary
Detailed

Danske Bank (controller) had developed an electronic registry database for invoices, which was connected to the controller's 'District platform' application. This application was developed by the controller to, among other things, allow its business customers to search for their own invoices. On 5 May 2021, 132 electronic invoices were uploaded to the database but no information about the "receiver" of such invoices was included. Due to a technical error, this lack of information on the invoices allowed other users of the application to search for these 132 invoices by performing a search in the application without typing anything in the 'receiver' field (performing a blank search). These invoices without receiver information were searchable and visible between 5 May 2021 and 10 May 2021. The controller's own investigation into the matter showed that 371 Finish users had accessed these electronic invoices in this period. On 10 May 2021, the information regarding the recipients was added manually to these 132 invoices. The controller notified the Danish DPA of this personal data breach on 12 May 2021. On 20 May 2021, the controller implemented a safety mechanism to ensure it was no longer possible to perform a blank search when searching for invoices. The DPA stated that Article 32 GDPR normally implies that when a controller is using systems with a large amount of confidential information concerning a large number of users, the controller has to comply with higher diligence to ensure that there is no unauthorised access to or disclosure of personal data. In this case, it meant that the controller should have assessed all likely out-comes in the context of the development of software used to process personal data. The DPA specifically referred to Article 32(1)(d) GDPR, which states that the controller should implement a procedure for the regular testing, assessment and evaluation of the effectiveness of the technical and organisational measures to en

Outcome

Violation Found

The DPA found a violation but did not impose a fine.

Details

Decision Date

13 June 2022

Authority

Datatilsynet (Norway)

GDPRhub ID

gdprhub-5631

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Danske Bank - Denmark (2022). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: