Municipality of Frederiksberg
Insufficient technical and organisational measures to ensure information security
Ημερομηνία απόφασης
16 Δεκεμβρίου 2021
Αρχή
Danish Data Protection Authority (Datatilsynet)
DK
Τομέας
Public Sector and Education
Χώρα
DK
Νόμος
GDPRΚατάσταση
FINALΠεριγραφή
The Danish DPA has fined the municipality of Frederiksberg EUR 13,450. On March 1, 2021, the municipality reported a data breach under Art. 33 GDPR. The municipality's dental care service had operated a system through which parents could access their children's dental care letters online. The municipality then extended this access to parents with joint custody. As a result, in several cases, parents gained access to information about the other parent and the child's address, even though the affected parent and child were registered with name and address protection. The DPA considered this to be a breach of the municipality's duty to implement adequate technical and organizational measures to ensure a level of security appropriate to the risk to the data subjects.