Enforcement · Norwegian Supervisory Authority (Datatilsynet) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
University of Agder: Insufficient technical and organisational measures to ensure information security
How it connects
Related across sources
News What Happened to the Risk-Based Approach to Data Transfers? News UK data protection reform: How the UK's GDPR may change News Hervorming van de privacywetgeving in het Verenigd Koninkrijk: Hoe de GDPR van het VK mogelijk zal veranderen. Guidance Guidelines 07/2020 on the concepts of controller and processor in the GDPR Literature GDPR Implementation Series ∙ Hungary: Introduction to the GDPR Application and a Brief History of Data Protection Case Law Unabhängiges Landeszentrum für Datenschutz v Wirtschaftsakademie Schleswig-Holstein
Full text
The Norwegian DPA has fined the University of Agder (UiA) EUR 12,700. An employee of UiA had discovered that documents containing personal data of employees, students and external individuals were stored in open Microsoft Teams foldersand that employees with no business need were able to access them. During its investigation, the DPA found that UiA had failed to implement appropriate technical and organisational measures to protect personal data.
Industry: Public Sector and Education
Original document at the source www.datatilsynet.no