Østre Toten municipality – Court Ruling (Norway, 2023)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
The Privacy Appeals Board in Norway upheld a decision against Østre Toten municipality after a ransomware attack led to the loss and sale of sensitive data. The Board agreed with the Data Protection Authority that the municipality had inadequate security measures, but found the DPA's legal interpretation regarding responsibility was incorrect. This case emphasizes the importance of maintaining strong IT security over time.
What happened
Østre Toten municipality experienced a ransomware attack that resulted in the loss and sale of sensitive personal data.
Who was affected
Individuals whose sensitive personal data was lost and sold on the dark web due to the municipality's security shortcomings.
What the authority found
The Privacy Appeals Board agreed that the municipality had fundamental security shortcomings but disagreed with the DPA's interpretation of responsibility.
Why this matters
This ruling highlights the necessity for continuous focus on IT security and clarifies the interpretation of responsibility in data breaches. It serves as a lesson for public entities to prioritize data protection and security measures.
GDPR Articles Cited
National Law Articles
This case is an appeal of a decision in which the DPA fined a municipality (the controller) about €352,555 (NOK 4,000,000) for violating Article 5(1)(f) GDPR, Article 24 GDPR and Article 32 GDPR after a serious ransomware attack led to highly sensitive personal data being irreparably lost and sold on the dark web. The controller disagreed with the DPA on the part of the decision pertaining to the fine and asked them to reconsider their position. After the DPA had reviewed the case again, they found no grounds to change their decision and so, as per Norwegian procedures, referred the case to the Privacy Appeals Board. In their comments to the Privacy Appeals Board, the controller argued that the grounds for an administrative fine were non-existent. They also held that they had implemented sufficient technical and organisational measures available to them as per their internal resources and in line with Article 24 GDPR and Article 32 GDPR. The Privacy Appeals Board reviewed the case, both parties' arguments, grounds for imposing an administrative fine as per the GDPR, as well as the objective and subjective grounds for assessing if personal data breaches took place. After assessing the controller's personal data practices, the Privacy Appeals Board held that they agreed with the DPA in that the various deficiencies represented fundamental shortcomings in the controller's information security, resulting in violations of Article 24 GDPR and Article 32 GDPR. When assessing the subjective grounds, however, the Privacy Appeals Board noted that the DPA had taken an incorrect legal standpoint and interpreted the legality inaccurately. They disagreed with the DPA's interpretation that the Chief Municipal Executive was objectively responsible for the personal data breaches, regardless of him acting negligent. In the Privacy Appeals Board's view, the insufficient IT security must be sees against a lack of focus over time, long before the Chief Municipal Executive was employed
Outcome
Court Ruling
A ruling by a national court on a data-protection matter.
Related Cases (2)
Other cases involving Østre Toten municipality in NO
Court Ruling
Details
About this data
Cite as: Cookie Fines. Østre Toten municipality - Norway (2023). Retrieved from cookiefines.eu
Last updated: