Enforcement · Data Protection Authority of Sweden EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
CDON AB: Insufficient technical and organisational measures to ensure information security
How it connects
Related across sources
Case Law HvJ EU: Privacy Shield ongeldig verklaard (Schrems II) Case Law Data Protection Commissioner v Facebook Ireland and Maximillian Schrems Case Law Maximillian Schrems v Data Protection Commissioner Literature If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation Literature Tracing the Impact of GDPR on Global Data Privacy Guidance EDPB Annual Report 2022
Full text
The Swedish DPA has imposed a fine of EUR 25,000 on CDON AB. The Austrian organization None of your Business (NOYB) had filed a complaint against the company in light of the Schrems II judgment, stating that the company was unlawfully transferring personal data to the US. The company had used Google Analytics for visitor statistics and based the data processing by the statistics tool on the EU standard contractual clauses in the absence of an EU Commission adequacy decision for the USA. In the course of its investigation, the DPA determined that the use of the standard contractual clauses was not sufficient to guarantee a level of protection equivalent to that of the EU.
Industry: Industry and Commerce
Original document at the source www.imy.se