Enforcement · Norwegian Supervisory Authority (Datatilsynet) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Grue municipality: Insufficient technical and organisational measures to ensure information security
How it connects
Related across sources
Literature General Data Protection Regulation (GDPR) ambiguity, national diversity and data protection officer certification: Implementing Art. 39(1) GDPR in France, Italy, Luxembourg and Spain Guidance Guidelines 07/2020 on the concepts of controller and processor in the GDPR Guidance Guidelines 05/2022 on the use of facial recognition technology in the area of law enforcement News What Happened to the Risk-Based Approach to Data Transfers? Case Law HvJ EU: Privacy Shield ongeldig verklaard (Schrems II) Literature GDPR Implementation Series ∙ Hungary: Introduction to the GDPR Application and a Brief History of Data Protection
Full text
The Norwegian DPA fined Grue municipality EUR 20,800 following the municipality's notification of a data breach. The municipality reported that personal data of students had been unlawfully published on a public portal. During its investigation, the DPA found that the municipality had not taken sufficient technical and organizational measures to ensure the protection of personal data.
Industry: Public Sector and Education
Original document at the source www.datatilsynet.no