Municipality of Frederiksberg: Insufficient technical and organisational measures to ensure information security
€13,450 fine - Danish Data Protection Authority (Datatilsynet)
Content
The Danish DPA has fined the municipality of Frederiksberg EUR 13,450. On March 1, 2021, the municipality reported a data breach under Art. 33 GDPR. The municipality's dental care service had operated a system through which parents could access their children's dental care letters online. The municipality then extended this access to parents with joint custody. As a result, in several cases, parents gained access to information about the other parent and the child's address, even though the affected parent and child were registered with name and address protection. The DPA considered this to be a breach of the municipality's duty to implement adequate technical and organizational measures to ensure a level of security appropriate to the risk to the data subjects.
GDPR Articles: Art. 32 GDPR
Industry: Public Sector and Education