Reykjanesbær municipality

€16,600

Non-compliance with general data processing principles

Datum rozhodnutí

6. prosince 2023

Úřad

Icelandic data protection authority ('Persónuvernd')

IS

Sektor

Public Sector and Education

Země

IS

Právo

GDPR

Stav

FINAL

Popis

The Icelandic DPA has imposed a fine of EUR 16,600 on the municipality of Reykjanesbær. The municipality had used the Google Education system without sufficiently complying with data protection regulations. In particular, the municipality did not fulfill its obligations when selecting Google as a processor and the processing agreement with Google did not comply with data protection requirements. Furthermore, the municipality did not ensure that the student data was not processed for purposes other than those specified by the municipality. Furthermore, the retention period was not considered appropriate but rather too extensive. In imposing the fine, particular consideration was given to the protection of sensitive children's data. Although no demonstrable damage had occurred, it was criticized that Reykjanesbær had not sufficiently ensured the secure transfer of data to the US in the past. However, the municipality cooperated transparently with the data protection authority and revised its data protection practices.

Právní citace

Art. 5 (1)Art. 24 (1)Art. 28

Problémy a porušení

Non-compliance with general data processing principles

Aktualizujte informace o prosazování ochrany osobních údajů

Respektujeme vaše soukromí. Jeden e-mail měsíčně, žádný spam, kdykoli se můžete odhlásit.